Stefan Boedeker, Greg Buchanan and Howard Scheck discuss how organizations can identify, investigate and remediate potential misconduct before it develops into regulatory or enforcement action. Topics include proactive risk assessment, analytics and AI, effective governance, investigative independence, regulatory engagement, and readiness for future investigations.

Posted In:


Over the past few years, how have the biggest trends, risks, challenges and opportunities evolved in the way organisations identify and investigate potential issues before they become regulatory or enforcement matters?

Buchanan: Organisations have become more proactive in identifying potential issues, driven by increased regulatory expectations, greater scrutiny of corporate conduct and the growing volume of available data. The biggest shift is from investigating misconduct after the fact to using risk assessments, transaction monitoring and targeted testing to identify red flags earlier. At the same time, issues have become more complex, particularly where transactions, counterparties and employees span multiple jurisdictions. This creates challenges around data quality, fragmented systems and regulatory requirements. For organisations, the opportunity is to combine traditional controls with analytics and targeted forensic reviews to identify anomalies earlier and give management and boards greater visibility into emerging risks.

Scheck: Over the past few years, we have continued to see whistleblowers come forward with respect to a wide range of accounting and disclosure issues. It is important for companies to make an early assessment of the credibility of the allegations and decide how to respond to them. Best practice would be to hire independent counsel and forensic accountants to evaluate the issues and update the audit committee as to the findings. Keeping external auditors informed and in the loop is also essential if there is risk of a material misstatement or management is involved in providing representations or certifying financials.

Boedeker: More recently, proactive and early detection, aided by big data analytics and ever more advanced artificial intelligence (AI) tools, particularly generative AI (genAI), have changed the landscape in identifying, investing and preparing for uncertain emerging risks. Organisations must prepare for technology investments to be vigilant and resilient to anticipate and detect potential issues because regulators and enforcers use similar tools.

What typically distinguishes organisations that detect and address concerns early from those that only discover issues after external scrutiny begins?

Buchanan: Organisations that identify concerns typically have three characteristics: a strong culture of escalation, clearly defined accountability and controls that operate in practice rather than simply existing on paper. They also conduct meaningful risk assessments and regularly test whether key controls are working effectively. Importantly, employees understand where and how to raise concerns, and management takes those concerns seriously. Organisations that struggle often have fragmented information, unclear escalation protocols or a tendency to rationalise anomalies rather than investigate them. Early detection ultimately depends on connecting the dots across compliance, finance, internal audit and other functions, rather than treating potential issues as isolated events.

Scheck: Employees engaging in fraudulent activities are likely circumventing or overriding internal controls, possibly fabricating documents and misleading others in the organisation. Companies that consider how their controls could be evaded and management that brainstorms about schemes that could occur are in a better position to identify risk areas and processes that could be enhanced. This needs to be done with an open mind, and tone from the top can foster the right attitude so any efforts are substantive instead of ‘check the box’. It is important to have a whistleblower programme that quickly addresses concerns so that remediation could potentially occur before external scrutiny begins. Moreover, if errors are found, discontinuing the practice and correcting errors before they become material could also prevent outside scrutiny.

Boedeker: Big data analytics, followed by AI and cognitive technologies and now genAI, have already shaped the landscape. We have observed over the past few years that organisations have shifted from reactive compliance to proactive, technology‑driven risk identification, with a focus on spotting issues before they escalate into regulatory or enforcement matters. By now, it has become clear that organisations that integrate advanced analytics, scenario planning and cross‑functional collaboration are better positioned to spot and address issues before they become enforcement matters, while also turning risk into a driver of innovation and resilience.

How are organisations using data analytics, monitoring tools and targeted reviews to identify potential misconduct or control failures at an earlier stage?

Buchanan: Data analytics are an increasingly important component of effective corporate compliance programmes and play a critical role in supporting internal investigations. Organisations can analyse large volume of transactions to identify trends, unusual patterns, anomalies and other indicators that warrant further investigation. The most effective approach is not simply deploying technology, but focusing on specific risks identified through the organisation’s enterprise risk assessment. Targeted reviews can then determine whether an anomaly reflects legitimate business activity or a potential control failure or misconduct. Combining analytics with traditional forensic accounting procedures allows organisations to move from broad, periodic testing toward more focused, risk-based monitoring.

Scheck: Data analytics, along with AI, are enabling companies to assess issues more frequently and faster than ever before. Instead of relying on internal audits or monthly or quarterly reviews, organisations have the capability to analyse issues sooner. This, however, could be a double-edged sword as the analytic outputs and findings must be monitored and addressed, and they could create risk if there is a failure to follow up. In other words, the government could a company’s own findings against it. So, legal and compliance should make sure that the analytics make sense and are being evaluated and monitored.

Boedeker: Advanced analytics – using statistical detection, network and graph analysis, natural language processing and AI governance – allows companies to sift through vast datasets to identify anomalies, outlier behaviour and weak signals that may indicate compliance risks. By integrating new technologies into their data infrastructure, organisations can trigger deviations from standard protocols while automated systems can flag suspicious transactions, unusual patterns or repeated policy breaches, prompting immediate investigation. This reduces investigation cycles and strengthens evidence for audits or regulatory inquiries.

What are the most common weaknesses you continue to see in governance, escalation and documentation processes when organisations assess potential concerns?

Buchanan: One recurring weakness is the disconnect between identifying a potential issue and determining who is responsible for assessing it. Organisations may have escalation policies, but those policies are not always sufficiently clear about thresholds, timelines or decision makers. Documentation can also be inconsistent, particularly around the rationale for decisions not to investigate or escalate a concern. Another challenge is maintaining appropriate coordination among legal, compliance, internal audit, finance and business personnel. From a forensic perspective, preserving the underlying evidence and documenting investigative steps is critical. A well-designed process should create a clear record of what was identified, how it was assessed, who made key decisions and why.

Scheck: A common issue is whether to investigate issues internally or go to outside counsel and forensic accountants. Organisations sometimes bite off more than they can chew and get in over their heads when they try to investigate themselves. For small issues, internal investigations using management and internal audit may be appropriate. For issues that could create regulatory enforcement actions or a restatement, in my experience, it is best to conduct an independent investigation from the start.

Boedeker: While the wave of new technologies has already led to dramatic changes, there are still too many organisations that are not prepared. One of the main weaknesses is when organisations do not have a data and analytics governance platform. A set of integrated business and technology capabilities – even if it is not state of the art AI – is an absolutely necessary tool that is invaluable in helping business leaders and users to develop and manage a diverse set of governance policies that will then be enforced across business document and data management systems.

When an issue is identified internally, how are organisations balancing the need for speed with the need for independence, privilege considerations and investigative rigour?

Buchanan: The key is having a defined response framework before an issue arises. Organisations need to move quickly to preserve relevant documents and data, understand the basic facts and assess whether there is an immediate regulatory or financial risk. At the same time, they need to determine early who should lead the investigation and whether outside counsel should be involved. Independence is particularly important where senior management may be implicated. Investigations should be appropriately scoped rather than rushed, with procedures designed to establish the facts objectively. The goal is to move quickly on preservation and initial assessment while maintaining sufficient rigour to support defensible conclusions.

Scheck: Companies should have law firms and forensic accounting firms in mind that they could engage quickly if the need arises. Internal legal and compliance should assess the risks and determine whether the issue is best handled internally or through independent professionals. Assessing whether the issue could result in a restatement, enforcement action or reputational harm should be considered.

Boedeker: When an organisation identifies an issue internally, statistical analysis of risk scenarios should be used as a structured way to explore possible future outcomes, assess risks and shape responses. Statistical scenario analysis will enable the organisation to assess the probabilities of outcomes when the challenge lies in balancing speed to act decisively with independence to avoid bias, privilege considerations to protect sensitive information and investigative rigour. Lastly, statistical scenario analysis enables the integration of the aforementioned investigative elements from the beginning, specifically recognising that many factors combine in complex ways to create unexpected outcomes.

To what extent are internal investigations now influencing regulatory engagement, disclosure decisions and eventual enforcement outcomes?

Buchanan: Internal investigations can have a significant influence on how organisations approach regulators and how regulators ultimately assess a matter. A thorough investigation can help an organisation understand the scope of conduct, identify control failures, quantify financial impact and determine whether additional issues exist beyond the initial allegation. It also gives management and counsel a factual basis for making informed decisions about disclosure and remediation. Regulators increasingly expect organisations to understand their own risks and respond appropriately when concerns arise. The quality, independence and credibility of an internal investigation can therefore be important factors in demonstrating that an organisation took the issue seriously and implemented meaningful corrective action.

Scheck: Internal investigations have always influenced regulatory engagement. The seriousness and scope of the findings obviously impact the decision on regulatory engagement. Whether to self-report to the government or other regulator should be made by internal legal counsel, likely with input from external counsel. If the issue requires a restatement, then self-reporting may be useful as it will become public anyway. That said, the Securities and Exchange Commission only investigates a fraction of restatements, so self-reporting is not necessary in every scenario. Counsel can assess materiality issues, the likelihood of cooperation credit and collateral consequences. Remediation and fixing and significant deficiencies or material weaknesses are important.

Boedeker: Internal investigations are no longer just a compliance formality. In fact, they have taken on a strategic dimension in regulatory engagement as well as shaping disclosure decisions and directly influence whether enforcement actions are pursued, reduced or avoided. Organisations that conduct timely, well-executed internal investigations are better positioned to secure favourable outcomes and protect their reputations.

Looking ahead, what developments do you expect will have the greatest impact on investigation readiness and early-stage risk assessment over the next three to five years?

Buchanan: I expect the greatest impact will come from the continued expansion of data analytics, AI and automated monitoring, combined with greater regulatory expectations around compliance programme effectiveness. AI in particular will increasingly enable organisations to move from detecting issues after the fact to identifying emerging risks and anomalies in near real time. Organisations will increasingly be expected to demonstrate not only that they have policies and controls, but that they are using data and technology to assess whether those controls are operating effectively and to identify where risks may be developing. Data quality and integration will therefore become increasingly important. I also expect greater emphasis on continuous, technology-enabled risk assessment rather than periodic compliance reviews. Organisations that invest in AI and analytics capabilities that connect financial, operational and compliance data and establish clear processes for escalating and investigating anomalies will be better positioned to identify and address issues before they become significant. Over time, the organisations that derive the greatest value from AI will be those that combine strong data foundations with effective human oversight and accountability for acting on the insights these tools generate.

Scheck: Clearly, over the next couple of years, AI will likely have the most impact investigation readiness and early-stage risk assessment. Companies will need to make sure AI tools are being used appropriately and are not themselves posing a legal and regulatory risk. We are already seeing examples on both ends of the spectrum – from helpful to harmful, and everywhere in between – so organisations must keep a close eye on their own capabilities and output with AI tools to ensure they are additive, not detrimental.

Boedeker: Organisations that integrate AI, big data analytics and cross‑risk integration into their early‑stage assessment processes must maintain strong governance, audit trails and human oversight. This integration and combination will best position an organisation to detect, respond to and mitigate risks before they escalate. In other words, both technological investment and cultural shifts are necessary to prepare an organisation for upcoming regulatory challenges.

If you have any questions or would like to discuss how StoneTurn can help, reach out to Stefan Boedeker, Greg Buchanan or Howard Scheck.

To receive StoneTurn Insights, sign up for our newsletter.

Disclaimer: The views expressed in this article are those of the author and do not necessarily reflect the views of StoneTurn Group, LLP, Province, LLC, or their affiliates. This article is provided for informational purposes only and does not constitute legal, financial, or other professional advice.

About the Authors

Stefan Boedeker

Stefan Boedeker, a Partner with StoneTurn, has more than three decades of experience in providing economics and damages expertise in prominent litigation cases, specializing in statistical consulting. As a litigation […]

Read Bio
Greg Buchanan

Greg Buchanan

Greg Buchanan, a Partner with StoneTurn, brings almost 25 years of combined experience in forensic accounting, risk management, litigation consulting and auditing. He has extensive experience working on complex corporate […]

Read Bio
Howard Scheck

Howard Scheck

Howard Scheck is a StoneTurn Partner with three decades of experience advising clients concerning complex financial reporting matters. Howard is a former SEC Chief Enforcement Accountant with extensive experience applying […]

Read Bio