# Draft Internal Investigation Report

> Agents draft privileged internal investigation reports that address the primary misconduct allegations, assess parallel regulatory and enforcement exposure, evaluate privilege and waiver issues when sharing the report, consider evidence-preservation and retaliation risks, and analyze whether financial exposure should be presented using both baseline and stress-test approaches.

- Skill: `finchipaiorg/draft-internal-investigation-report` (Agent Skill)
- Install (CLI): `npx skillmds@latest add finchipaiorg/draft-internal-investigation-report`
- Raw SKILL.md: https://api.skillmd.com/api/skills/finchipaiorg/draft-internal-investigation-report/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Docs & Writing
- Author: FinchipAIOrg (https://skillmd.com/u/finchipaiorg)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/finchipaiorg/draft-internal-investigation-report

---


# Skill: Privileged Internal Investigation Report for an Audit Committee

## 2. Failure modes the skill is correcting

- The report stays at a narrative level and fails to organize the investigation around distinct allegation areas, responsible actors, time periods, and evidence sources.
- The report addresses the core misconduct but omits parallel exposure that commonly travels with it, including regulatory, enforcement, reporting, employment, and remedial consequences.
- Interview summaries and investigation notes do not confirm that corporate counsel warnings were given and documented, creating avoidable privilege and cooperation risks.
- The report assumes privilege can be shared freely with outsiders and does not flag subject-matter waiver or recommend protective disclosure mechanics.
- The report states a single loss or exposure figure without separating a routine estimate from a more conservative upper-bound view for committee oversight.
- The report identifies possible reporting or reserve issues without tying them to the governing legal standard, the relevant metric, and the downstream disclosure or restatement question.
- The report discusses misconduct but omits preservation failures, retaliation risk, whistleblower protections, and remedial controls.
- The report reaches conclusions without naming the authority or doctrine that supports them.

## 3. Legal frameworks / domain conventions that apply

- **Privilege and interview practice:** Corporate counsel should state that counsel represents the company, not the individual; the company controls privilege and may waive it; the communication is intended to be privileged and work product; and the witness may seek separate counsel. Each interview record should note whether that warning was given and documented.
- **Waiver management:** Before any external sharing of the report or supporting materials, assess subject-matter waiver risk under ordinary attorney-client privilege and work-product principles, and consider a limited-waiver or confidentiality protocol where available.
- **Preservation and spoliation:** Once the duty to preserve attaches, destruction or loss of relevant evidence can support sanctions or adverse inferences under the applicable court’s spoliation framework. Identify custody gaps, auto-delete risks, and collection failures.
- **Retaliation and whistleblower protection:** Reported concerns should be handled under applicable anti-retaliation and whistleblower-protection rules, with protection measures documented for the complainant and key witnesses.
- **Banking, lending, and reporting exposure:** Where misconduct implicates lending practices, underwriting, credit administration, books-and-records, risk management, or disclosures, analyze the issue under the governing banking statutes, regulations, and supervisory guidance implicated by the source record.
- **Materiality and financial reporting:** Apply the reasonable-investor standard, assess whether a misstatement or omission affects a relevant metric or trend, and address whether reserve, disclosure, or restatement analysis is implicated under the applicable securities-law framework.
- **Clawback regimes:** Analyze executive-compensation recovery separately under any financial-restatement-based regime and any broader exchange-listing-based regime, then compare both to the company’s own recovery policy.
- **Voluntary self-disclosure:** Consider whether disclosure to regulators or supervisors is warranted in light of severity, timing, cooperation expectations, remediation, and potential credit for self-reporting.
- **Parallel exposure:** If facts implicate suspicious transactions, AML, government-backed funds, false claims, or other collateral regimes, address those exposures separately rather than folding them into the core misconduct discussion.
- **Authority citation:** Each legal conclusion should be anchored to the governing statute, regulation, rule, or leading doctrine, cited by name and section or part where practicable.

## 4. Analytical scaffolds

- **Scope and methodology:** Define the committee’s charge, the source materials reviewed, the interviews conducted, collection steps taken, and any limitations or unresolved gaps.
- **Documented interview matrix:** For each witness, state the date, role, subject area, and whether the privilege warning was given and memorialized.
- **Issue-by-issue analysis:** Break the misconduct into distinct allegations or conduct streams, then assess facts, intent, controls, harm, and implicated policies for each.
- **Exposure mapping:** For each issue stream, identify parallel regulatory, enforcement, employment, reporting, and civil exposure, with the controlling authority noted for each proposition.
- **Financial exposure range:** Present a standard estimate and a more conservative stress-test estimate, and explain the assumptions that drive the difference.
- **Materiality analysis:** Tie the issue to the relevant accounting or disclosure metric, state the governing materiality test, and explain whether further accounting review or restatement analysis is needed.
- **Clawback analysis:** Identify covered persons under each applicable regime, then compare those regimes to the company policy and note any gaps.
- **Preservation and retaliation review:** State what preservation steps were taken, what was missed, and what protection or non-retaliation measures should be implemented.
- **Remediation and next steps:** End with concrete governance, personnel, reporting, and control recommendations, including ownership and timing.

## 6. Output structure conventions

- Formal memorandum marked **PRIVILEGED AND CONFIDENTIAL — ATTORNEY-CLIENT PRIVILEGE / ATTORNEY WORK PRODUCT** and addressed to the Audit Committee.
- Use conventional sectioning rather than a checklist of rubric labels. A practical structure is:
  - Purpose, Scope, and Methodology
  - Executive Summary
  - Factual Background and Investigation Steps
  - Findings by Allegation Area
  - Legal and Regulatory Exposure
  - Financial Reporting / Materiality / Reserve Implications
  - Privilege, Waiver, Preservation, and Retaliation Considerations
  - Clawback Considerations
  - Recommendations and Remediation Plan
  - Open Questions and Next Steps
- Where multiple allegation areas, time periods, or issue streams exist, address each in a separate subsection rather than aggregating them.
- For every substantive finding, include the governing authority or doctrine supporting the conclusion.
- Use measured conclusions; distinguish confirmed facts, reasonable inferences, and unresolved issues.
- Conclude with an explicit action-oriented recommendations block naming the responsible role and an implementation timing anchor.

