September 26, 2026
10 Warning Signs your Internal Investigations Program may need a makeover:
The organization’s staff doesn’t know one exists or how to contact it
No posters, outreach, training, informative website, intranet page, etc.
No buy-in or open and evident support from org leadership
(Fine, I couldn’t narrow it down from 11) Program/team does not have regular interface, buy-in, and/or professional working relationships with Legal, HR, IT, and the operational/functional offices of the organization
No system in place for whistleblowers or other complainants to remain anonymous or maintain confidentiality
Hotline is not customized to the organization; seems generic and does not foster confidence…(assuming there is a hotline/confidential way to communicate with the investigations program)
No one answers the phone or responds within 1 business day to messages
Investigators are not dedicated to the program but assigned to it on an as/needed basis from other departments
No dedicated office structure, culture, policies, manual, standard procedures, form templates, etc.
No clearly defined mandate: what does it investigate, what does it not investigate, who can be investigated, what measures are in place to ensure independence
No QA of reports or office peer review (bi-annual, ideally)
September 12, 2026
More good news from USAID OIG. This was one of the last operations I approved before I left that office. Even then, progress was made but progress was slow. There were hurdles and impediments. But this is exactly why that office needs to be the OIG for all American foreign assistance. Expertise and Persistence. I don’t see a Special IG making a case like this over the course of six or seven years.
September 07, 2026
I enjoyed speaking with John Solomon on Just the News last week about U.S. foreign assistance oversight. As I made a few notes to prepare, I remembered just how elite USAID OIG was–and is. I understand there’s a movement afoot to rename that office the “Office of the Inspector General for Foreign Assistance.” It has my vote (which should carry the day). Lots of extraordinary professionals and accomplishments in the IG community, but only USAID OIG has the decades of experience and expertise to ensure that American foreign assistance (which still exists!) is protected to the fullest extent possible. Its staff, posted around the world, knows the programs, players, risks, and responses that work. American foreign assistance is no monolith; it’s as complex as it is critical for the world and the United States itself. Whatever form our foreign assistance takes next, it would be foolhardy not to repurpose the single best law enforcement/foreign assistance officers in the world.
I served as special agent in charge of the USAID OIG for eight years. My team was based in South Africa, Uganda, Egypt, Senegal, Haiti, and Germany - plus DC. We were responsible not only for half of global USAID programming, but all oversight for the Millennium Development Corporation, the Africa Development Foundation, the Inter-American Foundation, and then (then) Overseas Private Investment Corporation. The office’s professionalism, commitment, capability and capacity was a source of pride and its accomplishments and impact were on continuous display. From what I understand, that capacity has developed even more in the years since I left government service.
As always, we need to ensure that those who prey upon America’s programs for the world’s least fortunate are robustly investigated. The loss of USAID was an absurd, unnecessary, and unrecoverable self-inflicted shot in the foot for the U.S. and the world. Now, as the criticality of American foreign aid reemerges in political discourse, we need to ensure that American generosity is protected on a broader basis. Not by reinventing the wheel. Not by creating an ad hoc Special IG. But by properly mandating and funding the only team that can do it starting on Day 1.
https://www.linkedin.com/feed/update/urn:li:activity:7502830886728486913/
August 19, 2026 - When Your Whistleblower is Wrong
An investigation’s sufficiency (thoroughness)–ensuring that all the records, data, forensics, witnesses, experts, analysis, and other components relevant to the matter at hand were fully (or adequately, as appropriate) engaged–may be the most critical component of a strong case. Of course, few investigations offer all the optimal elements. CCTV rarely captures a fraudster in the act and may miss other offenses committed within an office premise; witnesses may not offer probative information; records may be incomplete. But if there is a cooperating whistleblower, an informed victim, someone who was “there” and is willing to provide the details needed, directly or as a guide, that investigation is at least off to a good start.
Generally speaking, whistleblowers (WBs) are courageous people who expose entrenched frauds or inequities and enable needed, positive, change when it was otherwise unlikely to manifest. They often risk their jobs, reputation, financial stability, or more to come forward in the manner they do. But not every WB is a Daniel Ellsberg or Frank Serpico.
WBs, naturally, have their own motivations. Using the term in the broadest sense (that is, to include anyone who comes forward openly to report a crime or serious conduct violation), most WBs in my experience were compelled to report by one of the following:
a desire to do the right thing for its own sake
an inability to unsee or unknow something and a wish to unburden themselves
anger/frustration
personal benefit (qui tams, payouts, reinstatement, vindication, etc.)
Any of these may provide reliable information but it can be helpful to understand where the WB is coming from. When the estranged wife of a businessman told me that she wanted to report on her ex’s multimillion dollar fraud because "he hit her one time too many," I knew there would be a spectrum of credibility to whatever she reported. But regardless of their presumed intent (and remembering that while we may initially accept someone’s motivation as they present it, we sometimes learn otherwise down the road), in such instances it’s not about trust; it’s all verify.
If a WB is themself a victim, the case may rely largely on them - their records, memory, statement, deposition, or testimony. Few single witnesses can make a case alone, especially in an organizational setting. Hopefully, they can direct you to other witnesses and records, explain relevant systems, programs, and events, and provide the necessary historical, cultural, and other context to help make sense of it all.
When working with a WB over an extended period, a professional relationship will form. That’s normal. It can start with rapport building (on both sides, actually) and build from there. A good WB is consistent and may even be likeable or deserving of sympathy. Investigators may come to rely on them for explanations and answers. But if a developed case is supported solely or primarily by the WB’s word, the case may be tenuous and the WB may feel motivated to bolster what they offer.
Things to consider:
Independently verify as much of what the WB reports as possible, no matter who they are. Aim to have other witnesses or records corroborate and/or present the information
If the WB is the sole witness, continuously discuss the matter with them from different angles, akin to a friendly cross examination of sorts (generally not possible when applying a victim centered approach)
Try to have a second investigator present in meetings with the WB and copy another investigator on correspondence. Your relationship matters but a third person’s presence can enhance the primary’s focus on objectivity and reduce a real or perceived over-reliance on a single investigator-source relationship
Remember that the case comes first and the goal is to establish facts. WBs can be wrong - about details or the entirety of what they present
The WB’s credibility is not your credibility. Don’t vouch for or push beyond what the evidence supports.
A whistleblower can be indispensable to an investigation without being infallible. Regardless of whether the WB is presenting inaccurate (unintentional) information or false information (intentional), recognize it and consider next steps. There are times when it’s best not to confront them but it may be a good idea, generally, to confirm your understanding with them and/or ask clarifying questions. A mistake is not a false report. But neither should a compelling whistleblower become an untested source simply because we want to believe them. Test the information from the beginning. The case—and quite possibly the whistleblower—will be better served by it.
August 16, 2026 - Does Your Organization Really Need an Ethics/Whistleblower Hotline…and Will Anyone Actually Use It?
An ethics/whistleblower hotline may be the barest necessity required for an organization to claim that it has a compliance program. Sporting an inhouse Compliance Officer, an Ethics Director, to say nothing of a functioning internal investigative capacity, is beyond the reach of most small–and many midsize–companies. A well considered ethics line, however, can add immeasurably to an organization’s wellbeing. That said, like any afterthought, if the hotline is a band-aid, a cocooning soundbite (Yes, of course we have a hotline!”), or otherwise ill conceived or ignored, it can do more harm than good.
Why?
Because it offers a false sense of security; a misplaced belief that there are no concerns to worry about, let alone address. How do you know the difference? If your organization’s hotline does not regularly receive submissions–or worse: hasn’t received any–that may not be a good thing - persistent silence can itself be a warning sign. I have worked with companies in which the bulk of staff did not even know there was a hotline or did not know if tips submitted would be read, let alone addressed - or done so in confidence.
An ethics hotline is a comparatively inexpensive way to empower your staff, enhance loyalty and morale, and learn of problems that leadership needs to know about (as well as, oftentimes, potential solution options and beneficial ideas submitters prefer to present anonymously). But you have to back it up.
Ethics/WB hotline outsourcing can work well if it is relatable. Be deliberate about designing the questions asked, the order of questions, question tone, and even the number of questions
Ensure multiple ways to contact the hotline, including outside your company's information system
Talk about the Hotline. A lot. From the top. The middle. Put up posters. Include it in onboarding. Add a link to everyone’s signature line. List it in contracts, subawards, partner, supplier, and vendor agreements
Ensure submissions can be fully anonymous and explain how the anonymity works
Find ways to share and discuss aggregate speak-up metrics such as at staff meetings or in semi annual reports
Most importantly, follow through. Respond to complainants - automatically when submitted (if they leave an email address) and with additional questions when appropriate. If the complaint is relevant and actionable, take appropriate action timely. If it is not, revert to the sender and explain why no action will be taken and what other options the reporter may consider. In other words, establish credibility one response at a time.
Hotlines are a comparatively low cost investment and a basic requirement of informed compliance. They can also be a building block to a greater program, to include regularly cadenced ethics training, an IT security program, and general integrity awareness. There is no shortage of nuances that individual organizations can consider for their own hotline but getting the basics right matters for them all.
August 1, 2026 - When Should an Organization Hire an Outside Investigator?
You’re about to meet with your staff/Board/regulators/stockholders/donors/others with a stake or influence in your organization when you get an email from Legal requesting a meeting...
Now.
A harassment complaint signed by four staff members was filed against the HR Director.
Or: a whistleblower reported that the head of Procurement has been receiving kickbacks from out-of-state vendors.
Or: a long term supplier is in the news after being federally charged with false claims and product substitution on government contracts.
Or: the Finance temp covering while the VP is out sick just reported seemingly altered invoices for unusual vendor activity, as well as payments to a company she can’t find a record of.
Or: the deputy head of your IT department was arrested over the weekend for….
Your organization doesn’t have a dedicated compliance or investigations team. Never needed it. Though it’s no longer the scrappy startup it used to be (or: because it operates in an environment of values-based work where integrity is assumed...) the org never developed capacities that the team had considered to be “too corporate.” So now what?
Such scenarios are virtually endless. Small and midsized companies routinely face concerns that can readily and appropriately be assigned to staff with experience in a particular area. But when a development brings enhanced risk that can significantly impact the core business, “other duties as assigned” is no longer adequate. Things to consider:
What are the likely outcomes and impact to your business if the allegations are confirmed? (Hint: consider impact to staff, customers/clients, reputation, legal exposure, etc.)
What are the likely implications if the underlying allegations are true and a proper investigation is not conducted or not conducted timely?
How will staff morale and privacy concerns be impacted when systemic employee interviews start?
What are the reporting requirements? Will the investigative effort and/or findings need to be shared with your oversight office, regulators, or law enforcement? When to contact them? What/how much to share? In what format?
Some organizations rely on their Legal Office for all such concerns. While that is often appropriate, there are times when outsourcing is prudent, such as:
if Legal is a party to the issue or otherwise conflicted out
if the response requires skill sets or expertise (yes, including interviewing staff) the Legal team lacks
even for lesser investigative concerns, it can raise an issue when the Legal team recommends disciplinary or corrective admin action for an allegation that its own investigation substantiated. Matters presenting potentially broader organizational impact benefit from cleaner tasking lanes.
If an allegation may place the organization in legal, reputational, or financial risk, or if the nature of the concern will likely require extensive staff-hours and/or skill sets that do not reside in-house, swift decisioning is often the best way to safely position your organization. It’s a moment no office leader relishes but inaction or the wrong playbook can have consequences equal to if not worse than impact from the concern itself.
There are moments when any organization needs outside help. Some of those occasions are time sensitive. Distinguish problems from risks and get help when needed.
July 9, 2026 - Score one for the good guys
The scourge of social engineering is one of the nastiest, most damaging frauds in society today. It’s global and one is now hard pressed to find a person who does not know someone directly or a couple degrees removed who fell victim to it. Whole retirements are stolen, life savings snatched irreparably at shocking rates. It can be catastrophic. So I’m always delighted to learn of and share some good news on this, Dante’s Eighth Circle of Hell. Interpol coordinated a 97-country operation that netted nearly $300 million and almost 6,000 arrests. As alluded to in the press release, social engineering is a huge business and can be very sophisticated. If a crew has a bogus Brazilian police station, complete with fake uniforms, signage and equipment, they’re no longer classified under “petty.” Score one for the good guys.
Interpol, of course, does not have enforcement authority and is not a police force. But to coordinate an effort like this is indeed impressive and kudos to those involved. With politics and old international relationships being tested as never before, law enforcement coordination remains a potent and reassuring force - including China!
Finally, as satisfying as this is, it is barely a drop in the bucket. There is vast (and generally repetitive) information out there on how to identify such schemes and ways to avoid becoming a victim. Banks, police departments, government agencies, NGOs, Interpol and countless other sources can guide you. Meanwhile, if I recall correctly, the punishment for those sent to the 8th Circle (Fraud) ranged from being whipped by demons to being immersed in boiling pitch for eternity. Sounds about right.
July 8, 2025 Imposters!
https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote
This came out last week. Interesting in its own right but also worth considering from a broader risk basis. Such infiltration events needn’t be exotic or organized by hostile foreign governments. As we continue with remote work - even if on a lesser scale in some fields - the associated risk of imposters gaining access to our systems, data, and other assets remains real. I engaged on a matter in which applicants for IT and other roles, using embellished resumes, had imposters sit for their remote interviews. Once on board, the new insiders continued to have the imposters do aspects of their work they were incapable of doing, themselves. Here are some simple interventions that may help. A few also offer some safeguarding against double dipping schemes. Please add others...!
Don’t assume that only overseas applicants can use imposters; there are always domestic threats
Don’t rely solely on an employment agency to adequately vet applicants. They may be liable to some extent, but once damage is done, that will offer little consolation
Be sure to have the applicant keep their camera on for all interviews. Video record the interview or take a still of their image. (Of course, let them know before doing so.)
Have the applicant hold up a government-issued photo ID on the call itself…and LOOK AT IT
Consider having the hiring/receiving manager participate in at least the final interview so s/he can have a visual of the candidate. (HR may never need to see the person again)
Though it has fallen out of favor in some corners and is a discussion topic in its own right, consider deploying a robust reference checking regimen
Once on board, require that the insider (employee or contractor) activate their camera for at least half (personally, I prefer all) their meetings
Engage staff beyond regularly scheduled meetings. It’s good to just hop on a (video) call every now and then, as busy as you are.
Certainly, general advice will not apply to every circumstance and, as always, check with your legal/leadership team before diverting from your organizational policies/procedures.
January 12, 2025: Other Duties As Assigned
Never ask an untrained employee to conduct an investigation under the rubric of "other duties as assigned." There's too much at stake. Unaddressed and/or inadequately attended internal administrative concerns such as harassment, retaliation, abuse of authority, and other conduct violations can quickly sap team morale and productivity. Insider and external fraud allegations must be handled expeditiously to ensure the overall well-being and integrity of your operations and the safety of staff, customers, beneficiaries, and other stakeholders - not to mention the protection of you and your company.
If your office lacks a dedicated investigation capability, there are ways nonetheless to accommodate this critical need in line with your resources and situation. Standing up a compliance/investigations office may make the most business sense. A better play may be to outsource a risk assessment or investigation. Sometimes, soundboarding is all that's needed initially. In any case, unless they are appropriately trained and experienced, asking your attorney, HR director, or head of cyber security to address such allegations is like asking a great car mechanic to fix a boat. They could do it - maybe do it well - but other issues may come into play.
In some small and medium-sized organizations, multi-tasking and multi-hatting are how things get done. When it comes to certain corporate compliance requirements, that can work. “Legal” is often the shop that handles Ethics training and compliance issues, which usually works well. However, having your attorney or Legal office conduct an internal investigation is generally less optimal. For all the benefits and value-adds of a crack legal team, internal investigations should ideally be conducted by trained and experienced in-house or outsourced investigators.
Why?
In part, because Legal teams are often swamped and allegations should be addressed timely without pausing other important work. Further, Legal is often involved in recommending or even deciding what the administrative remedy will be once findings are in. If the legal team also conducted the inquiry, a perception (minimally) of conflict may attach. If an interview gets heated or emotional, say, or if any testimonial, evidentiary, or procedural steps are questioned, your legal team may find itself poorly positioned to offer the clean, detached counsel it ordinarily would. Moreover, in-house counsel teams are often inexperienced in fundamental investigative concepts, such as applying investigative strategies, plans, and when appropriate, stealth.
Dedicated investigators also bring a broad skillset to the task. Minimally, this should include the ability to:
Balance information gathering with a keen awareness of materiality;
Apply investigative best practices across associated disciplines (planning, research, interviewing, evidence gathering, document review, source development, briefing, report writing);
Combine well-developed social/cultural consciousness and EQ with professional-level active listening skills;
Offer competency in other relevant specialties - legal, audit/accounting, forensic/technical - and have resources available when expertise is required;
Maintain an overarching focus on completing a fair, proportionate, and complete investigation.
Your investigations team, internal or external, should coordinate with your legal team and leadership as appropriate. However, for most internal matters, Legal shouldn't investigate any more than your investigators should give legal advice. Options exist.
January 1, 2025: Regular risk reviews…Initial steps
As I was conducting my annual New Years’ smoke detector inspection at home, it dawned on me that if it wasn’t for the New Year event-marker, I might not check them at all. Similarly, I have come to know that business risks are often left unattended until events strike - and then there is a whole lot of catching up to do on top of the crisis management itself. As such, I thought I’d offer some high-level thoughts, primarily for leaders of small and medium-sized organizations that may not have dedicated in-house compliance and investigative units. Some benefits may also apply for small investigative units and those that support them.
It's one thing to be a start-up; it's another to keep thinking like a start-up when you no longer are one. Same logic applies for small NGOs, values and religious-based organizations, and enterprises of all kinds that employ staff, and utilize suppliers, vendors, partners, clients, or customers. Granted, it can be hard enough to remain mission-focused at times, but if you agree that insurance is fundamental, risk review and mitigation is essential.
So:
When did you last assess your internal risks (even with a simple algorithm such as event likelihood x potential impact)?
How robust is your Ethics and/or compliance program? ESG?
Does your internal training program address ethics, fraud, security, whistleblowing, retaliation, relevant policies, rules, and regulations? Is the training mandatory for all organizational insiders (interns, volunteers, contractors, part-time and full time staff, executives, etc.), and provided at onboarding and annually?
Is your code of conduct current, fully deployed - and certified or agreed to - by your insiders?
Are you set up to field and adequately respond to internal complaints and concerns?
Suffice it to say this list goes on. No points to calculate on the above “test” as organizations are different and nuanced. But answer them honestly, and consider what other steps you need to take to protect yourself and your organization. Don't postpone your risk assessment and never rely on luck, good intentions, or multi-tasking when it comes to risk reduction.