The finding is usually right. The record is what fails, & it fails on three decisions made in the first week, before anybody feels any urgency about a document nobody will read for years.
Two years after it was closed, the file is handed to someone outside the company. Sixty pages, tabbed, indexed, complete on its face. The finding in it was almost certainly correct. Nobody reading it can tell, because nothing in the sixty pages establishes what the investigation was asked to answer, what the witnesses said as opposed to what the investigator concluded they meant, or in what order any of it happened.
That scene is a composite. It is not an account of any real matter, any real organization, or any engagement of ours.
Nothing in it required anybody to do anything wrong. The investigator was competent, the interviews happened, the conclusion was sound. The record cannot show any of that, & by the time it matters the record is the only thing left in the room.
Fidelity in documentation: every entry recorded as what it is & no more, a statement as a statement, an observation as an observation, a conclusion as a conclusion & what supports it.
An internal investigation has two audiences & only one of them is in the building. The first is the executive who commissioned the inquiry & the leader who closed it, & a finding satisfies that audience. The second arrives years later, has met nobody involved, sat in no room, & reads with an interest in the file failing: a regulator, an arbitrator, opposing counsel, an auditor, a journalist. Everything the file will ever have to do, it has to do for that reader, alone.
That reader is not testing the answer. She is testing whether the paper can produce it, & the clearest published case of one doing that against a documentation rule is not a corporate one. In March 2020 the Justice Department's inspector general examined how one federal agency had executed an internal rule requiring supporting documentation behind every factual assertion in a category of application. Of the 29 applications selected for review, the supporting files for 4 could not be located, & in 3 of those 4 the agency did not know whether they had ever existed. Of the 25 that could be tested against their files, all 25 contained apparent errors or inadequately supported facts. The inspector general stated in the same memorandum that it had made no judgment about whether any of those errors were material, & that caveat travels with the numbers.
Read it for the shape rather than the subject. The rule demanded more than most organizations would attempt of themselves, the institution audits its own work, & the files still could not carry it.
Most of what I know about this I learned as a reader rather than a writer. For the length of a federal career, files reached me closed, built by people I would never get to interview, & all that was left to test was whether the paper stood without them. The ones that held were rarely the ones with the strongest conclusions & poor documentation. They were the ones I could walk end to end without picking up the phone.
Three decisions determine whether a file can be reconstructed. All three are made in the first week, when the matter is still small, the pressure is to resolve it quickly & quietly, & nobody has reason to picture a stranger reading the paper in two years. None of them feels consequential at the time.
One community of investigators has written a documentary standard for itself & published it free. On 15 July 2025 the Council of the Inspectors General on Integrity and Efficiency reissued its Quality Standards for Investigations, superseding the 2011 edition. It governs federal inspectors general & binds no private employer, so read it as a benchmark rather than as an obligation.
The first decision is scope. The question the investigation was asked to answer, written down before any answers exist, is the most consequential page in the file, & it is the page most often written last. The federal standard puts the planned focus & objectives of an investigation among the elements settled at the outset, & requires that a decision not to investigate be documented in the case file rather than simply made.
Scope also moves mid-stream. It widens when something unexpected surfaces & narrows when a line of inquiry goes nowhere, & both are ordinary. What cannot be recovered years later is a change nobody wrote down: who decided it, when, & on what basis. To a reader who was not there, a scope that shifted with no record of the shift is indistinguishable from one written after the answers were known. The remedy is not to avoid changing scope but to record the change while it is happening, when it costs one sentence.
The honest complication is that the standard-setting body moved the other way on one point. The 2011 edition required a formal written investigative plan & suggested noting specific allegations that were not investigated; the 2025 edition dropped both while tightening documentation language elsewhere. So the reason to write the question down is not that a standard demands it. It is that a question the file never records having been asked leaves a reader no way to call the answer right, no way to call it wrong, & no way to tell whether an answer was called for at all.
The second decision is language, & it reduces to one distinction held on every page: what a witness said, & what the investigator concluded she meant. Those are different classes of statement, they age differently, & only one of them is evidence. The federal standard requires that reports state the facts & the rules allegedly violated, that reports be "supported by evidence and documentation in the investigative case file," & that interviews be recorded or documented in writing. Underneath all three sits one test an outsider can run: can she separate the record from the reasoning, & does every conclusion trace to something a witness or a document actually said.
The gap between those two has been measured, though not in a corporate setting. In 2000 Michael Lamb & colleagues compared contemporaneous verbatim notes from 20 forensic interviews with alleged child abuse victims against audio recordings of the same interviews. Of the interviewers' own utterances, 57 percent never appeared in the notes. Of the incident-relevant details the children provided, 25 percent were missing. The notes also misattributed which question had produced which answer, running systematically toward more open prompts than were used. Those were trained investigators writing as fast as they could, in the population that study covered & no other.
The failure that follows is not dishonesty. It is compression. A note recording that a witness was evasive about the timeline has already replaced what she said with the investigator's read of it, & the read cannot be checked once the words are gone. A conclusion word carries weight the evidence may not support, & an allegation recorded without the word allegation attached becomes, on a cold reading two years later, a finding. None of that requires anyone to intend anything.
By the time it matters, the record is the only thing left in the room.
The third decision is sequence. An investigation has its own timeline, that timeline is evidence about the investigation, & it is the part organizations most often cannot reconstruct, because nobody was recording it while it happened.
Interview order is part of that timeline. In 2003 Fiona Gabbert, Amina Memon & Kevin Allan showed paired participants different videos of the same staged event & encouraged some pairs to discuss it beforehand; 71 percent of the witnesses who had discussed the event went on to report, as memory, items they had only heard about. That is a laboratory study using staged events, not a study of workplace investigations. What transfers is narrower: whether the people in a matter had spoken to each other before they were interviewed is knowable while it is happening & almost never in the file. The point is not a prescribed order. It is that an order the file cannot show is an order nobody can establish later.
Preservation belongs to that timeline too, & it comes down to two dates: when the organization first knew there was a matter, & when it first moved to preserve the evidence. The gap between them is a plain fact, countable in days. Federal civil procedure has carried a rule since 2015 for electronic evidence that should have been kept & was not, & whatever that rule requires, the two dates around preservation are not legal questions. They are ordinary facts, & a file either carries them or it does not.
A file containing only the evidence that supports its conclusion is indistinguishable, to a reader who was not there, from a file assembled to reach that conclusion. On paper the two look the same. What separates them is the alternative explanation that was tested & did not hold, written down with what was checked & why it failed.
The mechanism has been described carefully, again outside the corporate setting. In 2013 Saul Kassin, Itiel Dror & Jeff Kukucka set out what they called the forensic confirmation bias, reviewing research indicating that context can taint perception, judgment & behavior, & that participants asked to form an early hypothesis about a likely offender then searched for & read evidence in ways that confirmed it, so that a weak suspect became the prime suspect. That is forensic & criminal justice research, & it transfers as a reason, never as a rate. The federal standard states the duty flatly: the investigator is a fact gatherer with a duty to be receptive to evidence, "including exculpatory and incriminating evidence," & reports must contain exculpatory evidence & relevant mitigating information discovered during the investigation.
Now the counterweight, because there is a real reason this gets skipped & it is not laziness. Doing it properly is slower & more expensive in the first week, the week the matter is smallest, the pressure is to close it quietly, & the benefit is years away & invisible. The cost is real, it lands early, & it lands on the person least positioned to see what it buys. The trade is the organization's to make. What is worth avoiding is making it by default, in the first week, without noticing that it was made at all.
A second counterweight cuts against overclaiming. None of this is process for its own sake. Nobody outside is scoring how elaborately an investigation was run, & a file thick with procedure—memoranda, checklists, sign-offs—that still cannot show what was asked or what a witness said gives an outside reader nothing to work with. The record has one job: to let somebody who was not there follow the work.
Everything above is an accuracy & reconstructability standard for a document. It is not advice on positioning a record, & that distinction is the point. Nothing here tells anyone how to conduct their investigations. What it does demand is fidelity in documentation: that every entry is recorded as what it is & no more; a statement as a statement, an observation as an observation, a conclusion as a conclusion & what supports it.
None of this has to be traded against anything, because the standard & the organization's interest run in the same direction. A record built to be accurate is the only kind that survives a cold reading anyway, & there is no separate craft of building one that merely reads well, at least not one that survives a reader holding the underlying documents.
So here is the read, & it costs an afternoon & nothing else. Pull one closed investigation from the last two years. Not the hard one, an ordinary one. Then hand it to somebody who had no part in it, is already cleared to see it, & has met nobody involved, & watch what they can & cannot rebuild from the paper. It has to be their eyes. Anybody who was in the room fills the gaps from memory without noticing they are doing it, & reads straight past the places where the file establishes nothing. Three questions, answered from the paper alone, without calling anyone:
Whatever comes back is information about a process, not about the people who ran it. The finding is very likely still correct. The only question is whether the file can show it.
That read is free, & it is yours to run first. When you want the outside reader to be a professional you engaged for the purpose, that is work we do at Scopos: independent review of a closed investigation file, & investigations conducted to this standard from the first week.
If you ran that read on one closed file this week, which of the three questions would the paper answer on its own, & which one would need a phone call?
This article was produced with AI assistance. The perspective and security expertise are the author's own.