
So you’re running an investigation across borders. No pressure. Here’s how to handle it without stepping on a legal landmine, in plain English for the people who actually have to make the call.
The short version ● An internal investigation protects your business. Done wrong, it can create more legal exposure than the problem you started with. ● Your US playbook does not fully travel. Firing rules, employee cooperation, and lawyer confidentiality all work differently abroad. ● Two of the biggest traps are data privacy (GDPR fines run up to 20 million euros or 4% of global revenue, whichever is higher) and the instinct to delete files when you are done. Do not delete. Preserve. ● Before you review a single email overseas, get local legal advice. A wrong move can be criminal, not just costly.
|
Nobody builds a company dreaming about internal investigations, least of all the kind that cross borders. But once you have people, contracts, or a factory in another country, they come with the territory. A fraud tip, a harassment complaint, a bribery question: any of these can land on your desk, and how you respond in the first 48 hours often matters more than what actually happened.
The good news is you do not need to be a lawyer to run this well. You need a clear process, the right advice at the right moments, and enough awareness to avoid the mistakes that turn a manageable problem into a regulatory one. Let’s walk through it.
Why this matters more than it looks
An internal investigation is about protecting the business. You are finding out what really happened, confirming you are on the right side of the law, and protecting your company’s reputation and balance sheet.
Here’s the part executives underrate: a problem in one corner of your operation rarely stays there. A compliance gap in one market, left alone, becomes a pattern regulators notice. Handled early and cleanly, most issues stay small. Handled late or sloppily, they compound, and the cleanup costs a multiple of what prevention would have.
Takeaway: The investigation is a risk-control tool, not a box to tick. Treat it like one.
The five stages, and where this guide fits
Responding to suspected wrongdoing has five stages. Think of it as a map:
1. Set the rules. Employees can only be held to standards they actually knew about. Clear policies come first.
2. Give people a way to report. A whistleblower channel is how problems surface before they explode.
3. Triage the report. Not every complaint needs a full investigation. Some are real; some are someone unhappy about their desk chair.
4. Run the investigation. This is the hard part, and it’s what this guide covers.
5. Close it out. Document, decide, and act. Sometimes that includes disclosing to a regulator, which is its own conversation for another day.
This piece lives in stage four: actually running the thing when it crosses borders.
Your US playbook won’t fully travel
As a US company you have habits that work great at home and quietly backfire abroad. It’s like bringing an American football playbook to a soccer match. A few of the biggest surprises:
You can’t always fire at will. In the US, “at-will” employment lets you part ways with most employees without proving cause. That’s largely a US thing, and it barely exists in most other countries. Overseas, terminating someone usually requires a solid, documented legal basis, and getting it wrong can trigger real liability. Assume you need cause, and confirm before you act.
People don’t have to talk to you. In some countries, employees can simply decline to be interviewed, and they’re within their rights to do so. In parts of Europe you may also need to involve a works council, an official employee body, before you monitor emails or start interviews. Cooperation abroad is often earned, not required, so plan for more honey than vinegar.
Lawyer confidentiality may not protect you. In the US, conversations with counsel are usually shielded. In a number of countries that shield is thinner or absent, and in much of Europe emails to and from your in-house lawyers may not be protected at all. If you are used to assuming “legal is looped in, so this is confidential,” recalibrate before you write anything down.
Takeaway: Every core US assumption (fire at will, employees cooperate, legal is confidential) can flip the moment you cross a border. Verify locally first..
Two kinds of cross-border work
Not every international matter is the same size:
1. True cross-border investigations. The big leagues. Say you’re looking into possible bribery at your Nigeria operation that could also violate US law, like the Foreign Corrupt Practices Act (the FCPA, the US anti-bribery statute that can carry penalties running into the millions). Now you’re juggling multiple countries, multiple legal systems, and multiple ways to get it wrong.
2. Local matters that happen to be abroad. The warm-up round. A problem at your Mexico plant that stays in Mexico. Still a foreign country, still foreign rules, but the scope stays contained.
Knowing which one you have tells you how much firepower to bring.
The traps that catch US companies abroad
Local laws are a patchwork, not a rulebook. There’s no single international playbook for investigations. Some countries have specific rules for harassment cases or workplace accidents; many don’t. And some have laws you won’t see coming. A handful of countries, France among them, make it a crime to gather evidence on their soil for use in a foreign lawsuit. Confirm the local requirements before you act, because the downside can be criminal exposure, not just a civil headache.
Data privacy will bite if you rush. The moment you start pulling emails and files, privacy law kicks in. Europe’s GDPR gets the headlines, and for good reason: fines reach up to 20 million euros or 4% of global annual revenue, whichever is higher. Plenty of other countries have their own versions. The rule of thumb is simple: do not start digging through someone’s data until you’ve had local legal advice on how to do it lawfully.
Do not delete the files. This is the one that surprises people most. The instinct to “clean up” when the investigation wraps can be exactly the wrong move. Once a lawsuit or government inquiry is on the horizon, you are legally required to preserve records, and destroying them can turn a small problem into an obstruction problem. Keep the materials under a defined retention schedule, and delete only when your counsel says it’s safe.
Takeaway: The three fastest ways to make things worse are ignoring local law, touching data before you’re cleared to, and deleting files. Avoid all three.
A quick pre-flight checklist
Before you open a cross-border investigation, confirm you can answer yes to these:
● Do we know which country’s laws govern each step?
● Have we cleared how we’ll collect and review data under local privacy rules?
● Do we need to involve a works council or other employee body first?
● Is a legal hold in place so nothing gets deleted?
● Do we know whether this could trigger US laws like the FCPA?
If any answer is “not sure,” that’s your signal to get advice before, not after.
The bottom line
Cross-border investigations are complex, but they’re manageable with the right process and the right advice at the right moments. Move early, respect local rules, protect your data, and preserve your records. Do that, and you keep a contained problem contained. And if it all gets to be a lot, there’s no shame in a fresh cup of coffee before the next step.
Facing a cross-border investigation and not sure where to start?
You don’t have to figure it out alone. United CLO attorneys have helped growing and established US companies across Europe, Latin. America, Africa and Asia work through the legal, cultural, and regulatory twists of investigations abroad, so leadership can protect the business with confidence.



