New Delhi, 15 September 2026: EY India, a leading professional services firm, and JSA, a leading law firm, today announced the launch of ‘Investigations Readiness for a New Risk Reality’, a practical guide designed to help organizations strengthen their ability to identify, assess and respond to allegations with speed, rigor and confidence.
The guide highlights how investigations are becoming more complex as evidence spreads across cloud environments, mobile devices, collaboration platforms, identity logs and third-party systems. At the same time, heightened regulatory scrutiny, cross-border data considerations and rapid advances in AI are increasing the need for clear governance, defensible evidence handling and coordinated decision-making.
Against this backdrop, the guide calls on organizations to treat investigation readiness as an ongoing capability rather than a crisis response. In an environment where matters can escalate within hours and scrutiny can emerge before all facts are established, preparation often determines the effectiveness of an investigation. By establishing clear governance, preserving critical evidence, defining response protocols and enabling cross-functional coordination in advance, organizations can make faster, more informed decisions while maintaining the confidence of regulators, employees, customers and other stakeholders.
Speaking about the launch, Saguna Sodhi, Partner, EY Forensic & Integrity Services said, “As risks become more interconnected and digital evidence grows in volume and complexity, the ability to investigate effectively will increasingly depend on how well an organization has prepared before an issue arises. Readiness is about creating the right governance, preserving the right evidence and bringing together technology and human judgment in a way that is transparent, defensible and trusted.”
A practical blueprint for investigation readiness
The guide organizes the investigation lifecycle into seven stages: detect, triage, preserve, plan, investigate, decide, and remediate and learn. It also identifies eight readiness checkpoints covering governance and decision rights, legal and regulatory readiness, investigation risk assessment, forensic data readiness, case management and documentation, technology and analytics, people and surge capacity, and learning and remediation. These components are designed to help organizations bring greater consistency, transparency and accountability to the investigation process, while reducing the risk of delays, evidentiary gaps, fragmented decision-making and regulatory scrutiny. As investigations become increasingly data-intensive and cross-functional, a structured framework can help organizations respond more quickly and confidently while maintaining the defensibility of their actions and outcomes.
Providing a legal perspective on the guide, Rupinder Malik, Partner, JSA, and Chapter Leader, World White Collar Crime Defense Association (WWCDA) India Chapter, said, “A well-run investigation is not only about establishing facts. It must be legally structured from the outset, with careful attention to privilege, privacy, evidence integrity, regulatory engagement and cross-border requirements. Early involvement of legal counsel, supported by disciplined documentation and clear decision rights, can help organizations respond consistently while protecting the defensibility of the process and its outcomes.”
Responsible use of AI, with human accountability
The guide highlights how AI and advanced analytics can help investigation teams manage growing volumes of data by accelerating complaint triage, document review, evidence analysis and timeline creation. Recognizing that investigations are becoming increasingly complex, it emphasizes that AI should serve as a controlled accelerator rather than an autonomous investigator, supported by safeguards such as secure environments, source traceability, validation and human oversight to ensure findings remain transparent, reliable and legally defensible.
Sector-specific readiness priorities
The guide notes that a one-size-fits-all approach to investigations is unlikely to work because each sector has distinct risk profiles, evidence sources, operating models, third-party dependencies and regulatory expectations.
Consumer products and retail
Consumer products and retail organizations operate across complex supplier, distributor, logistics and digital commerce networks, making them vulnerable to risks such as third-party fraud, procurement irregularities, vendor collusion, product diversion, inventory manipulation and counterfeit goods. Given that evidence is often fragmented across multiple internal and external systems, the guide emphasizes the need for investigation-ready third-party governance, including clear audit rights, data-access requirements, retention obligations and escalation protocols to enable timely and effective investigations.
Financial services
Financial institutions face a growing range of risks, including fraud, anti-money laundering concerns, sanctions violations, market abuse, cyber incidents and employee misconduct, often requiring investigators to assess large volumes of transaction, communication and surveillance data while navigating parallel regulatory inquiries. The guide highlights fragmented accountability and disconnected evidence across functions as key challenges and recommends an integrated response framework with clear governance, early independence assessments, timely evidence preservation, controlled access to sensitive records and consistent stakeholder disclosures to support effective and defensible investigations.
Advanced manufacturing and infrastructure
Advanced manufacturing and infrastructure organizations operate across geographically dispersed sites, large capital projects and complex contractor ecosystems, exposing them to risks such as procurement fraud, bid-rigging, corruption, inflated contractor claims, safety failures and intellectual property theft. Given that evidence is often spread across project systems, operational technology platforms, physical records and contractor-controlled environments, the guide recommends extending investigation readiness beyond corporate functions to sites, contractors and joint ventures through early evidence preservation, enhanced contractor oversight, stronger data visibility and contractual audit and evidence-access rights.
As investigations become faster, more data-intensive and subject to greater regulatory and stakeholder scrutiny, organizations can no longer rely on reactive approaches. The guide underscores that investigation readiness is emerging as a critical business capability, one that can enable organizations to respond with speed, integrity and confidence while safeguarding trust, ensuring regulatory compliance and strengthening long-term resilience.