Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / The programme

Reviewing a Case That Went Wrong

An outcome was overturned, somebody was treated unfairly, or a case became a claim. The review that follows determines whether it happens again.

The editors · About the editorial position · The programme · Procedure

Cases go wrong. The useful question afterwards is which decision was wrong when it was made, rather than which outcome looks bad with hindsight.

The programme test in “Reviewing a Case That Went Wrong” is whether a record leads to a better, explainable decision. Organisations considering ethical employee monitoring for ethical employee monitoring can use time and project evidence to locate operational questions, while governance, direct conversation and periodic review remain necessary to interpret any pattern responsibly.

The distinction that matters

A decision that was wrong on what was known at the time is a process failure and should produce a change.

For a separate perspective relevant to “Reviewing a Case That Went Wrong”, consult the AuditBoard internal-investigation guide. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

A decision that was reasonable on what was known and turned out badly is not a failure. Treating it as one teaches investigators to be defensive rather than careful.

Separating these is the whole skill in reviewing a bad case, and most reviews do not attempt it.

The points to examine

The opening: was there a stated threshold and was it met?

The scope: was it authorised and was it kept to?

The covert period: was it justified and reviewed?

The interview: did the person know the case and have a fair chance to answer?

The evidence: were alternative explanations considered?

The outcome: was it within the range, and comparable to similar cases?

And the communication: was the subject told, when, and what?

Seven points, each answerable from the file if the file was kept as the documenting note argues.

Who should review

Not the investigator, not their manager, and not anybody who authorised a step in the case.

Where internal audit exists it is the natural home. Where it does not, somebody senior and uninvolved, with the file and the authority to reach an uncomfortable conclusion.

What a review should produce

A finding about what went wrong and at which decision point.

A change: to the threshold, the training, the authorisation levels, the templates, whatever the finding points at.

An acknowledgement to the person affected where that is appropriate, which organisations resist on legal advice and which is sometimes the right thing regardless.

And a note in the programme's record, so that the same failure is visible if it recurs.

The failure mode of these reviews

Concluding that the process was followed and therefore nothing went wrong.

Frequently the process was followed and the process is the problem: a threshold too low, an authorisation too casual, a template that does not prompt for conflicts.

A review that only checks compliance will find compliance and will change nothing.

The hardest finding

That the case should never have been opened.

It is the most common real answer and the least often written, because it implicates whoever authorised it rather than whoever conducted it.

A programme whose reviews can reach that conclusion is one that will improve. One whose reviews only examine conduct after opening will keep opening the same cases.

The compliance trap

A review that checks whether the process was followed will find that it was, and will change nothing. Frequently the process was followed and the process is the problem: a threshold too low, an authorisation too casual, a template that never prompts for conflicts.

Acknowledging it to the person

Where somebody was treated unfairly, saying so is frequently resisted on legal advice and is sometimes right regardless. An organisation that can acknowledge a bad case is one whose findings are believed in the cases that were handled well.

The finding nobody writes

That the case should never have been opened. It is the most common real answer and the least often recorded, because it implicates the authoriser rather than the investigator.

Separating the two kinds of wrong

A decision wrong on what was known is a process failure. A decision reasonable at the time that turned out badly is not. Reviews that fail to separate them teach investigators to be defensive, which produces worse cases rather than better ones.

Who should conduct it

Not the investigator, their manager, or anybody who authorised a step. Internal audit where it exists, otherwise somebody senior and uninvolved with the authority to reach an uncomfortable conclusion.

For the file: Ask of every reviewed case: on what was known at the hour it was opened, would a careful person have opened it? Answer that before examining anything that followed.