Module 4
Fraud Investigation
a. Theft Act Investigate Methods
Delving deeper into theft act investigations unveils a meticulous and strategic
approach aimed at uncovering fraudulent activities while minimizing the risk of wrongful
incrimination and ensuring the integrity of the investigative process. These investigations
encompass a range of activities, from surveillance and covert operations to the gathering
of physical and electronic evidence, all designed to meticulously piece together the
puzzle of fraudulent behavior.
The initial stages of a theft act investigation are characterized by discretion and
subtlety, with investigators employing techniques that are unlikely to arouse suspicion or
prematurely alert potential suspects. It is imperative to proceed cautiously, as wrongful
incrimination can have serious consequences, not only for innocent individuals but also
for the credibility and effectiveness of the investigative process as a whole.
To this end, it is essential to limit the number of individuals involved in the
investigation, thereby minimizing the risk of leaks or breaches of confidentiality.
Additionally, employing terminology such as "audit" or "inquiry" instead of
"investigation" can help maintain a low profile and avoid tipping off potential suspects or
disrupting ongoing operations.
Furthermore, the use of discreet investigative methods, such as covert surveillance
and invigilation, allows investigators to gather valuable intelligence without alerting
suspects to their presence. This may involve monitoring suspect behavior, tracking
movements, and documenting suspicious activities, all while maintaining a careful
balance between gathering evidence and preserving the confidentiality of the
investigation.
As the inquiry progresses, investigative efforts gradually converge towards the
prime suspect, guided by the accumulation of evidence and the narrowing of potential
leads. This methodical approach ensures that investigators are able to build a compelling
case before confronting the primary suspect in an interview or interrogation.
Delaying the interview with the prime suspect until sufficient evidence has been
gathered serves multiple purposes. Firstly, it allows investigators to gather a
comprehensive understanding of the fraudulent activity, including its scope, magnitude,
and impact. This, in turn, enables them to conduct a more focused and targeted interview,
presenting the suspect with irrefutable evidence and compelling them to account for their
actions.
Secondly, delaying the interview minimizes the risk of prematurely alerting the
suspect to the investigation, thereby reducing the likelihood of evidence tampering,
witness intimidation, or flight. By maintaining a discreet and methodical approach,
investigators can maximize the effectiveness of their investigative efforts and increase the
likelihood of securing a successful outcome.
In essence, theft act investigations follow a carefully orchestrated pattern, guided
by the principles of discretion, diligence, and integrity. By employing a strategic
combination of investigative techniques and exercising patience and restraint,
investigators can uncover fraudulent activities while safeguarding the rights and interests
of all parties involved. Ultimately, this approach ensures that justice is served, and
perpetrators are held accountable for their actions, while innocent individuals are
protected from unwarranted suspicion and harm.
Indeed, the covert nature of many investigative steps in theft act investigations
allows them to be conducted discreetly and without raising suspicion. Security personnel,
auditors, and fraud examiners routinely access and examine personnel records during
routine audits or assessments, making it a natural part of their responsibilities. Similarly,
reviewing purchasing records and conducting public records searches are standard
procedures in audits, financial examinations, and due diligence processes, often occurring
without drawing attention.
Moreover, these investigative activities can often be conducted offsite or
remotely, further minimizing the risk of detection. For instance, public records searches
can be performed online or through specialized databases, allowing investigators to
access a wealth of information without physically being present at the target location.
Similarly, searching email files or reviewing electronic records can be done on corporate
servers or centralized backup systems, ensuring confidentiality and reducing the
likelihood of tipping off suspects.
By leveraging centralized resources and utilizing existing protocols and
procedures, investigators can discreetly gather valuable intelligence while maintaining
the confidentiality of their operations. This approach not only reduces the risk of alerting
potential suspects but also enhances the efficiency and effectiveness of the investigative
process.
Furthermore, the use of sophisticated data analysis tools and techniques enables
investigators to sift through vast amounts of information quickly and efficiently,
identifying patterns, anomalies, and potential red flags that may indicate fraudulent
activity. From financial transactions and communication patterns to behavioral indicators
and digital footprints, these tools allow investigators to uncover valuable insights that
may otherwise go unnoticed.
Additionally, collaboration and information-sharing among different departments
and stakeholders within an organization can facilitate the exchange of critical information
and intelligence, further enhancing the effectiveness of theft act investigations. By
pooling resources, expertise, and data, organizations can streamline the investigative
process and maximize their ability to detect and prevent fraudulent activities.
It's important to note that while many investigative steps can be performed
discreetly, investigators must always adhere to legal and ethical guidelines to ensure the
integrity of their actions and protect individuals' rights. This includes obtaining necessary
permissions and authorizations, respecting privacy considerations, and maintaining
confidentiality throughout the investigative process.
In conclusion, the covert nature of many investigative steps in theft act
investigations allows them to be conducted discreetly and without arousing suspicion. By
leveraging existing protocols, utilizing centralized resources, and employing
sophisticated data analysis techniques, investigators can gather valuable intelligence
while minimizing the risk of detection. However, it's essential for investigators to always
operate within the bounds of the law and adhere to ethical standards to ensure the
integrity and effectiveness of their investigative efforts.
Surveillance, as a critical component of theft act investigations, is conducted with
the utmost discretion and secrecy to prevent suspects from becoming aware of the
ongoing investigation. When properly executed, surveillance operations are stealthy and
covert, allowing investigators to gather valuable evidence without alerting potential
suspects to their activities. This covert approach ensures that suspects do not have the
opportunity to cover their tracks or alter their behavior in response to the investigation.
One of the primary objectives of surveillance is to observe suspect behavior and
gather evidence surreptitiously, providing investigators with insights into potential
fraudulent activities without tipping off suspects prematurely. By maintaining a discreet
presence and utilizing advanced surveillance techniques, such as hidden cameras, GPS
tracking, and remote monitoring, investigators can gather valuable intelligence while
minimizing the risk of detection.
Furthermore, the strategic sequencing of interviews is essential to the success of
theft act investigations. Interviews should typically begin with individuals who are
objective and not currently associated with the suspect, gradually working inward until
the suspect is finally interviewed. This approach serves several purposes: it minimizes the
risk of alerting suspects too early to the investigation, avoids creating undue stress or
suspicion among other employees, and protects the target of the investigation.
By starting tangentially and working inward, investigators can methodically
gather evidence and build a compelling case without prematurely revealing their hand.
This approach also helps to mitigate the risk of evidence tampering or witness
intimidation, as suspects are less likely to take evasive action when they are unaware of
the investigation.
Moreover, the careful orchestration of surveillance and investigative activities is
crucial to preserving the integrity of the case and safeguarding the rights of all parties
involved. Once a case is revealed, there is a risk that evidence and individuals may
"disappear," potentially compromising the investigation and impeding efforts to hold
perpetrators accountable.
By adhering to a systematic and strategic approach to surveillance and
investigation, investigators can maximize the effectiveness of their efforts while
minimizing the risk of unintended consequences. This includes conducting thorough
background research, gathering corroborating evidence, and documenting findings
meticulously to build a strong and defensible case.
Ultimately, the goal of surveillance and investigation in theft act cases is to
uncover the truth and ensure that justice is served. By employing a combination of
surveillance techniques, strategic sequencing of interviews, and meticulous
documentation, investigators can navigate the complexities of theft act investigations
with confidence and integrity.
Developing theories and frameworks to guide fraud investigations is crucial for
effectively identifying potential perpetrators, understanding their motivations, and
uncovering the extent of the fraud. One valuable tool in this regard is the use of a
vulnerability chart, which provides a structured approach to analyzing various aspects of
the fraud and establishing hypotheses to guide investigative efforts.
A vulnerability chart serves as a comprehensive framework for organizing and
synthesizing information related to the fraud under investigation. It coordinates multiple
elements of the potential fraud scenario, including the assets involved, individuals with
theft opportunities, possible methods of theft, concealment strategies, conversion
possibilities, observed symptoms, pressures faced by potential perpetrators,
rationalizations they may employ, and key internal controls that may have been
compromised.
By systematically considering each of these elements and their interrelationships,
investigators can develop a holistic understanding of the fraud and generate informed
hypotheses about what may have occurred, who may have been involved, and how the
fraud was perpetrated. This structured approach not only helps investigators identify
potential leads and avenues of inquiry but also ensures that no critical aspects of the fraud
are overlooked.
By systematically analyzing each of these elements within the context of the
alleged fraud, investigators can develop hypotheses about what may have occurred, who
may have been responsible, and how the fraud was executed. These hypotheses can then
guide further investigative efforts, including gathering additional evidence, conducting
interviews, and testing the validity of the theories developed.
Furthermore, the vulnerability chart can serve as a valuable communication tool
for conveying complex fraud scenarios to stakeholders, such as management, legal
counsel, or regulatory authorities. By presenting a structured overview of the fraud and
the investigative hypotheses developed, investigators can facilitate understanding and
collaboration among key stakeholders and enhance the overall effectiveness of the
investigative process.
In summary, the use of a vulnerability chart provides a structured and systematic
approach to developing theories and hypotheses in fraud investigations. By analyzing
various aspects of the fraud and its context, investigators can generate informed
hypotheses about what may have occurred and guide further investigative efforts with
clarity and precision.
As shown in the top section of this vulnerability chart, the assets that may have
been taken included the customer’s deposit. Theft opportunities may have been available
to the teller who processed the transaction, to an operations officer who supervised the
teller, or to the proof operator who processed the credit to the customer’s account.
Movement of the assets was easy and could have occurred by entering a credit in the
wrong account, placing the checks (if the deposit involved checks) in the cash drawer and
withdrawing cash, stealing cash, or falsely endorsing checks. Concealment was possible
by destroying the customer’s deposit slip, creating a new deposit slip, or forging a
signature. Since the stolen funds involved cash, conversion opportunities were unlimited.
Symptoms observed might include changed behavior, an improved lifestyle, or another
customer complaint. Pressures motivating the fraud could have involved a tax lien against
the teller’s property, an expensive new home purchased by the proof operator, or a recent
divorce by the operations officer. Rationalizations could have involved the perpetrator’s
feelings of being underpaid or treated poorly. Key internal controls that would have had
to be overridden could have involved not allowing an employee to enter credits into his
or her own account, use of processing jackets in the proof department, the teller omitting
certification, or restricted access to the computer system.
Surveillance and covert or undercover operations are theft investigation
techniques that rely on the senses, especially hearing and seeing. Surveillance or
observation means watching and recording (on paper, film, or magnetic tape) the physical
facts, acts, and movements, which form part of a fraud. The three types of surveillance
are: (1) stationary or fixed point, (2) moving or tailing, and (3) electronic surveillance.
Some form of surveillance is used in investigating most frauds, including even financial
statement frauds.
Simple fixed-point or stationary observations can be conducted by anyone. In
conducting these observations, the investigator should locate the scene that should be
observed, anticipate the action that is most likely to occur at the scene, and either keep
detailed notes on all activities involving the suspect or record them on film or tape. The
detailed records should include the date and day of observation, the name of the observer,
the names of corroborating witnesses, the position from which the observation was made,
its distance from the scene, and the time the observation began and ended, along with a
detailed time log of all the movements and activities of the suspect. An example of a
surveillance log. The person under surveillance e was suspected of taking kickbacks from
a vendor.
Mobile observation, or tailing, as was used in the McDonald’s fraud, is much
more risky than stationary surveillance. In one case, an internal auditor was shot at while
tailing a suspect. While the potential rewards for this type of surveillance are high and
may include identifying the receiver of stolen goods or the payer of bribes or kickbacks,
the chances of failure are high. Tailing should only be done by professionals.
Electronic surveillance of employees, using video cameras, is frequently used.
Wiretapping, another form of surveillance, is usually only available to law enforcement
officers. Electronic surveillance may have limited value in the investigation of employee
frauds and many other white-collar crimes because of concerns regarding employees’
privacy in the workplace. However, it is useful in kickback-type schemes, such as the
McDonald’s case, where law enforcement is involved. Many corporations have instituted
strict controls over all forms of electronic surveillance, including video and wiretapping.
However, most have policies that state that all data on corporate computers, including
personal e-mail and documents, are property of the corporation and can be used in
investigations. Be sure to check with legal counsel before proceeding with any of these
methods.
Surveillance and covert operations are normally legal as long as they do not
invade a person’s reasonable expectation of privacy under the Fourth Amendment to the
Constitution, which protects the right of a person against unreasonable searches. Again,
legal counsel and human resource personnel should always be consulted before any form
of surveillance takes place. In addition, all corporations and institutions should
implement strict protocols regarding the use of any form of surveillance in order to
ensure that controls are in place and that a “reasonable person” test is given to any
application. The value of surveillance can be more than offset by employee problems
caused by inappropriate or improper application of the techniques.
Undercover operations are both legal and valid, provided they are not used as
fishing expeditions. Undercover operations are extremely costly and time consuming and
should be used with extreme care. Undercover investigations should be used only when
(1) large-scale collusive fraud or crime is likely, (2) other methods of fraud investigation
fail, (3) the investigation can be closely monitored, (4) there is significant reason to
believe that the fraud is occurring or reoccurring, (5) the investigation is in strict
compliance with the laws and ethics of the organization, (6) the investigation can remain
secretive, and (7) law enforcement authorities are informed when appropriate evidence
has been accumulated.
Three illustrations of actual undercover operations highlight some of the risks
involved. In the first instance, which was successful, collusive fraud was suspected. The
undercover agent was able to get valuable evidence that led to the conviction of several
individuals. The other two undercover operations, which were unsuccessful, concerned
suspected drug dealing at manufacturing facilities. Drug dealing is an activity that no
organization can tolerate, because if an employee purchases and uses drugs on the job
and then is involved in an automobile accident on the way home from work, for example,
the organization may be legally liable for damages. In the second operation, the agent
became fearful and quit. In the third operation, the agent became sympathetic to the
suspects and was not helpful.
With developments in technology, many companies are using database searches
and artificial intelligence systems to provide surveillance or filter huge amounts of data
and identify suspicious transactions. Instead of tailing or following individuals, programs
using artificial intelligence now tail or monitor transactions to find transactions that are
unusual or look suspicious. For example, it has been estimated that credit card fraud costs
the industry about $1 billion a year, or 7 cents out of every $100 spent on plastic. But the
estimate is down significantly from its peak about a decade ago. This decrease is due, in
large part, to the use of powerful technology that works like a surveillance camera and
can recognize unusual spending patterns. Many of us have been participants in this credit
card surveillance activity. Have you ever made a large or unusual charge purchase and
had the credit card company contact you to make sure the purchase was made by you? Its
surveillance tracking system likely recognized the transaction that appeared unusual
given your typical spending habits.
Driven by needs ranging from security to fraud protection to quality of service,
applications for monitoring, surveillance, and recording are growing in importance and
sophistication. In telecommunications systems, for example, signaling protocols provide
access to databases and real-time call establishment requests containing highly detailed
and useful information regarding locations, calling patterns, destinations, duration, and
call frequency. These data are often mined for a variety of functions from traditional call-
setup to billing, while signaling traffic can also be monitored for quality of service, fraud
prevention, legal intercept, and billing. These capabilities can greatly enhance service
providers’ efforts to reduce expenses, preserve capital, and retain customers. They can
also provide telecommunications vendors with a vast source of information from which
they can build new applications and revenues.
As a final example of electronic surveillance, consider the tracking system used
by the Financial Industry Regulatory Authority, Inc. (FINRA). FINRA is the largest
securities industry self-regulatory organization in the United States. FINRA develops
rules and regulations, conducts regulatory reviews of members’ activities and designs,
and operates and regulates securities markets all for the benefit and protection of
investors. FINRA is contracted to oversee security firms, professional training, testing,
and licensing on all the major U.S. stock markets. The market regulation department is
responsible for monitoring all activity to ensure compliance with market rules in order to
provide a level playing field for all market participants and investors. An automated
system screens all trades and quotes according to approved, standardized criteria to
identify potential violations for review and, if appropriate, regulatory action.
Fraud detection capabilities are provided through rule and sequence-matching
algorithms, which are used to detect instances in the database that match patterns that
could indicate fraud. The surveillance techniques provide customized visualizations for
depicting the relevant relationships in the data, as well as capabilities for multiple users to
review and manage the alerts that are generated and the patterns that are used. Whether
the surveillance is manual or electronic, observing someone’s activities is a fraud
detection tool that attempts to catch fraud and other types of crime at the theft act stage.
Those who use such methods are not trying to understand the cover-up or concealment of
fraud or even how the money is being spent, unless, of course, the spending of the money
is the actual theft act as it would be with credit card fraud.
Invigilation, as an investigative technique, carries significant implications for
resource allocation, organizational reputation, and legal considerations. Its application
requires careful consideration, prudent decision-making, and adherence to established
protocols to ensure effectiveness, legality, and ethical integrity.
While invigilation can be an expensive undertaking, its potential benefits in
uncovering fraudulent activities and mitigating risks justify its use under certain
circumstances. However, due to the associated costs and implications, invigilation should
only be employed with management's approval and in situations where other
investigative methods are inadequate or ineffective.
One key aspect to consider when deploying invigilation is the selection of the
target area or business unit. It is essential to focus invigilation efforts on discrete and self-
contained areas of the business where the risk of fraudulent activity is high and where
existing controls may be insufficient to prevent or detect such activity. High-risk areas
may include those with expensive inventory, poor controls over the receipt and loading of
goods, or inadequate controls over accounting records.
For example, in retail environments, invigilation may be targeted at areas where
high-value merchandise is stored or handled, such as storerooms, warehouses, or loading
docks. Similarly, in manufacturing facilities, invigilation may be directed towards areas
where raw materials or finished products are vulnerable to theft or misappropriation.
Moreover, the decision to employ invigilation should be guided by a thorough
risk assessment and cost-benefit analysis. While invigilation may provide valuable
insights into fraudulent activities, its implementation must be weighed against the
associated costs, including personnel, equipment, and operational disruptions.
Additionally, legal and ethical considerations must be carefully addressed when
implementing invigilation measures. Depending on the jurisdiction and applicable
regulations, there may be legal requirements regarding the use of surveillance equipment,
privacy considerations, and employee consent. It is imperative to ensure compliance with
relevant laws and regulations and to safeguard the rights and privacy of individuals
involved.
Furthermore, clear policies and procedures should be established regarding the
use of invigilation techniques, including guidelines for data collection, storage, and
access. Transparency and accountability are essential to maintain trust and confidence
among employees and stakeholders and to mitigate the risk of legal challenges or
reputational damage.
In summary, while invigilation can be a valuable investigative tool in uncovering
fraudulent activities and mitigating risks, its use should be approached with caution,
prudence, and adherence to established protocols. By focusing invigilation efforts on
high-risk areas, conducting thorough risk assessments, and addressing legal and ethical
considerations, organizations can leverage this technique effectively while minimizing
costs, risks, and potential pitfalls.
The decision to implement invigilation as a fraud prevention measure requires
careful consideration and planning by management to ensure its effectiveness and
minimize disruptions to business operations. As part of this process, management must
determine the precise nature of the increased temporary controls necessary to remove
fraud opportunities and establish an operating profile for the unit under review.
Analyzing past records is a critical step in developing an operating profile for the
unit under review. By examining historical data, management can gain valuable insights
into the unit's normal operating patterns, typical losses, transaction volumes, and other
key metrics. This information forms the basis for establishing benchmarks and
identifying deviations or anomalies that may indicate fraudulent activity.
To ensure accuracy and reliability, it is generally agreed that the invigilation
period should be at least 14 days in length. This allows sufficient time to capture a
representative sample of the unit's operations and detect any patterns or trends that may
indicate fraudulent activity. However, the optimal duration of invigilation may vary
depending on factors such as the frequency and nature of transactions, the complexity of
operations, and the specific objectives of the investigation.
In addition to establishing an operating profile, management must also determine
the specific controls and measures to be implemented during the invigilation period. This
may include increased surveillance, enhanced access controls, additional documentation
requirements, or other measures designed to minimize fraud opportunities and mitigate
risks.
By conducting a thorough analysis of past records, establishing an operating
profile, and implementing appropriate controls, management can effectively leverage
invigilation as a proactive fraud prevention measure. This approach helps identify and
address vulnerabilities in the unit's operations, deter fraudulent activity, and safeguard the
organization's assets and reputation.
Invigilation should be used wisely and with caution because it can backfire in
some cases. One company, for example, was suffering significant small tool losses from
its manufacturing plant. To determine who was taking the tools, the company decided to
inspect all workers’ lunch boxes as they exited the facility. The practice so upset
employees that it caused a work slowdown that was more expensive than the fraud losses.
Physical evidence can be useful in some cases, especially those involving
inventory where physical stock can be counted and missing inventory can be searched
for. However, in most cases, physical evidence, like a fired bullet or a dead body, is more
associated with nonfraud types of crimes, such as property crimes, murder, rape, and
robbery. Because fraud is rarely seen and has few physical symptoms, physical evidence
can often be difficult to find.
Gathering physical evidence involves analyzing objects such as inventory, assets,
and broken locks; substances such as grease and fluids; traces such as paints and stains;
and impressions such as cutting marks, tire tracks, and fingerprints. Physical evidence
also involves searching computers. For example, physical evidence was used to discover
who was involved in the 1993 bombing of the World Trade Center in New York City.
The vehicle identification number engraved on the axle of the rented van that contained
the explosives made it possible to trace the van to a rental agency. When the perpetrator
came back to the rental agency to recover his deposit and make a claim that the van had
been stolen, the FBI arrested him.
Because of the wide variety of electronic media available today, the process for
gathering electronic evidence may vary from device to device. For example, cell phones
and PDAs have limited solid state memory, while computers have significant amounts of
both memory and hard drives. For this discussion, we’ll assume you are investigating
data on a computer hard drive and give the general process for obtaining electronic
evidence from hard drives. In practice, you can modify this process for each specific
device. You should normally work with IT support personnel and legal counsel to gather
electronic evidence because of the significant amount of technical knowledge it takes to
perform the tasks correctly. For example, if you incorrectly seize a hard drive, you may
damage its data or make it inadmissible in court.
Computer forensics is a fast-growing field with many software vendors. Many
universities now have degrees or specialties in computer forensics. While new software is
constantly being developed for forensics, Guidance Software’s EnCase Forensic Edition
and AccessData’s The Forensic Toolkit (FTK) are in common use today. These software
packages lead the investigator through the entire process described earlier and ensure that
important steps are followed correctly. They support the tasks of cloning, CRC
calculations, and searching using a variety of methods.
Many open source packages are also available for computer forensics. Some of
these, such as e-fense Inc.’s Helix or Remote-Exploit.org’s BackTrack, come as bootable
CDs that support the investigation and searching of computers. For example, Helix was
used to investigate the phone calls made to Puerto Rico in the case described earlier.
Since management was not ready to start a case (i.e., seize the computer, clone the data,
etc.), the investigator used a bootable CD to boot the computer, bypass passwords, and
search the drive without ever starting the normal operating system. These CDs generally
have very advanced tools for password cracking, searching using a method called regular
expressions, and network analysis programs. The open source solutions are generally not
as easy to use as EnCase or FTK, and they do not have the same precedence in court.
However, they are extremely useful in the right hands and in the right circumstances.
E-mail systems often prove to be an incredible repository of communications
between suspects and other people. It is surprising how many people still believe e-mail
to be a secure method of communicating. A single e-mail can become a smoking gun on
which an entire case is based. In today’s world of electronic media, e-mail should nearly
always be considered during investigation. Today, many different communication
methods beyond traditional e-mail—such as text messages—are being analyzed during
investigations. For example, in some countries, more people have cell phones than have
computers. Consequently, text messaging is used much more than traditional e-mail and
provides a better information source for investigations. Regardless of the media being
investigated, the process is generally the same.
E-mail is given special consideration because copies often exist in many places:
on the sending computer, on the two (or more) e-mail servers involved in transmission,
and on the receiving computer. With some e-mail servers, messages only reside on the
server; seizing the client laptop will not allow you to search e-mail. Talk with your IT
support personnel to understand the type of e-mail used in each case and how it can be
searched. One type of e-mail, Web-based e-mail within a user’s browser, is especially
difficult to search. Hotmail, Yahoo! Mail, and Gmail are examples of this type of e-mail.
In these cases, all e-mail is stored at the provider’s site, and you will likely need a
warrant to access it. However, some information may still be on the hard drive in the
form of cached Web pages and can be found with keyword searches. In fact, the user may
have even saved his or her Webmail password—taking the user’s Web browser to his or
her Webmail site may autofill the username and password fields. The legality of this and
all approaches discussed in this varies based on your country and situation. Always check
with legal counsel to ensure that your planned methods are both legal and ethical.
b. A Comprehensive Example of Using Theft Act Investigation Methods
To conclude this and illustrate the value of theft act investigation methods, let’s
review excerpts from an article written by Thomas Buckhoff and James Clifton that
appeared in The CPA Journal entitled “Exotic Embezzling: Investigating Off-Book Fraud
Schemes.” The investigators in this fraud case made extensive use of both surveillance
and invigilation.
Indirect investigative methods were used to test the four possible fraud theories.
Financial statement analysis is one such method that can be used to test all four fraud
theories presented. If employees are indeed stealing cash from the club, then the actual
sales markup-over-cost ratios are expected to be less than the budgeted ratios.
Accordingly, the fraud investigators determined the actual markup-cost ratios for beer
and food sales. Beer was purchased for $0.60 per bottle and then sold to customers for $3
each, a markup of 500 percent. Food items costing $5 were sold to customers for $12.50,
a 250 percent markup. One year’s budgeted revenue was calculated, based on cost of
sales and expected markup ratios, and then compared to one year’s actual revenue. The
significant differences in ratios clearly supported the fraud theories—in fact, food sales
were less than their cost of sales! Using this indirect investigative method, the total
estimated annual fraud loss due to skimming or cash larceny was $379,974.
The investigators now knew that the club had a big problem with fraud;
determining which employees were responsible came next. Undercover surveillance can
be used effectively for identifying dishonest employees. Posing as customers, a team of
six trained fraud investigators (with experience as bartenders and servers) spent a
collective 40-hour week at the club observing the employees’ activities and behavior.
This surveillance revealed that 90 percent of them, including the manager, regularly stole
cash from the club, with little regard to subtlety. The reason that employees never
complained about salary levels, despite low base wages and a lack of raises, became
clear. In fact, several servers and bartenders had been there for years, which is highly
unusual for this type of club. The lead investigators communicated their findings to
Swenson, who, though concerned, was reluctant to take action without more substantive
evidence of employee theft.
To more firmly establish the fraud losses and estimate their amount, the fraud
investigators conducted a weeklong invigilation. As discussed, in invigilation, the cash
received and deposited during the invigilation period is compared to the periods before
and after. As an indirect investigative method, invigilation can be very effective in
estimating fraud losses. The key to invigilation success is making the employees think
that any theft during that period will be detected. Instilling the perception of detection in
this case was accomplished by sending in the same team of six investigators to watch the
employees for one week. The club’s employees and manager were informed that the
investigators were there to make sure that every dollar collected from customers made it
into the bank at the end of the day and that changes in consumable inventories were
properly accounted for. During the invigilation, the investigators conspicuously watched
employees handling cash, conducted surprise cash counts, reconciled changes in
inventory to cash register tapes, monitored end-of-night cash counts, and witnessed the
daily cash deposits.
The first day brought an incident that greatly heightened the perception of
detection. Meals were served downstairs, away from the live entertainment area.
Suspecting the single server working downstairs of skimming money from food sales,
one of the investigators conducted a surprise cash count and reconciled cash rung into the
register to meals prepared by the cooks. The server had skimmed $25 in the first hour she
worked. When confronted with the evidence, the server confessed and was immediately
terminated. News quickly spread to the other employees, who realized that their activities
were indeed under close surveillance. No other employees were caught skimming during
the remainder of the invigilation.
During the invigilation’s first night, a Friday, $8,300 in cash was deposited into
the bank—the largest sum for one night in the entire 15-year history of the club. This
occurred on what was considered a “slow” night—unlike the previous week, which had
seen near-record attendance. The manager and employees all soon realized that setting
such a record on a slow night reflected poorly on them. This convinced Swenson that his
employees were stealing from him, and he wanted to fire everyone on the spot. The
investigators persuaded him to allow the invigilation to continue for the entire week as
planned. The results of the week-long invigilation are summarized as follows:
Gross cash receipts during the invigilation were $30,960, compared with $25,775
the previous week and $22,006 for the annual weekly average. The revenue during the
week of invigilation exceeded the average weekly revenue by $8,954 and the previous
week’s revenue by $5,185, despite being a slow week. The above differences implied that
at least $259,250 and as much as $447,700 was skimmed per year. (After changes were
implemented following the investigation, the remaining nine months’ sales were
$300,000 higher than for the same period in the prior year.) Swenson no longer doubted
that his employees were stealing from him. As noted earlier, Swenson had had difficulty
believing his manager was stealing because of her efforts to exempt the club from the city
ordinance. It became apparent that these efforts were motivated by a desire to protect her
illicit cash flow.
Employee interviews were held during the week of the invigilation. Their purpose
was twofold: to further enhance the perception of detection during the invigilation period
and to provide employees with an opportunity to report any fraudulent activities. Very
specific questions were asked during the interviews, based upon information from the
prior undercover surveillance and the ongoing invigilation. While no one admitted to
stealing, they did implicate fellow employees; many claimed that manager Betsy Smith
was the primary thief.
During her interview, Betsy Smith was confronted with the evidence from the
undercover surveillance, invigilation, and employee interviews. After two hours, she
admitted to stealing almost $100,000 over three years. Her admission was converted to a
written statement, which she ultimately signed. The statement detailed the amounts she
had skimmed, when she had done so, and the various techniques (skimming from liquor
sales, bank deposits, video sales, and food deliveries) she had used. An attached summary
totaled the funds skimmed by source. Since evidence collected in resolving off-book
fraud schemes is mostly indirect and circumstantial, obtaining a signed admission
statement greatly facilitates the filing of employee dishonesty insurance claims or
criminal charges. In this case, such a claim was filed by the fraud investigators on behalf
of Northern Exposure.
The insurance company restituted Northern Exposure for the maximum coverage
amount provided by its policy, $50,000. Clearly, the coverage amount was inadequate
given the exposure to risk for such a cash-intensive business. As required by the
insurance provider, evidence collected during the fraud examination was turned over to
local law enforcement for prosecution.
c. Concealment Investigate Methods
We discuss surveillance and covert operations, invigilation, and physical
evidence, including the searching of computers and social engineering— all of which are
theft investigation methods. After committing a theft, perpetrators must conceal their
fraud by covering their tracks, obscuring evidence, and removing red flags where
possible. Concealment is generally accomplished by manipulating documentary evidence,
such as purchase invoices, sales invoices, credit memos, deposit slips, checks, receiving
reports, bills of lading, leases, titles, sales receipts, money orders, cashier’s checks, or
insurance policies. From an electronic perspective, concealment can also be
accomplished by modifying or deleting records in corporate databases.
Most concealment-based investigative techniques involve ways to discover
physical documents or computer records that have been manipulated or altered. When
faced with a choice between an eyewitness and a good document as evidence, most fraud
experts would choose the document. Unlike witnesses, documents do not forget, they
cannot be cross-examined or confused by attorneys, they cannot commit perjury, and they
never tell inconsistent stories on two different occasions. Documents contain extremely
valuable information for conducting fraud examinations. For example, in addition to
possible fingerprints, the information on the front and back of a cancelled check.
From the time documentary evidence is received, its chain of custody must be
maintained in order for it to be accepted by the courts. Basically, the chain of custody
means that a record must be kept of when a document is received and what has happened
to it since its receipt. Careful records must be maintained anytime the document leaves
the care, custody, or control of the examiner. Contesting attorneys will make every
attempt to introduce the possibility that the document has been altered or tampered with.
A memorandum should be written that describes when the document came into the hands
of the examiner, and subsequent memoranda should be written whenever there is a
change in the status of the document. For computer-based evidence, professional
programs like EnCase and The Forensic Toolkit calculate checksums that support the
chain of evidence. We discussed these and other forensic programs. But even with
electronic evidence, the traditional chain of evidence must be maintained with seized
computers, cellular phones, and other devices.
When documentary evidence is received, it should be uniquely marked so that it
can be identified later. A transparent envelope should be used to store it, with the date
received and the initials of the examiner written on the outside. A copy of the document
should be made, and the original document should be stored in the envelope in a secure
place. Copies of the document should be used during the investigation and trial and
should be kept in the same file where the original is kept. During the trial, the original
can be removed from safekeeping and used.
Fraud cases can create tremendous amounts of documentary evidence. For
example, in one case, 100 people worked full time for over a year to input key words into
a computer so that the documents could be called up on demand during the trial. In this
case, there were literally millions of documents. In the Lincoln Savings and Loan
Association case, the judge created a document depository containing millions of
documents, from which attorneys, FBI agents, and others were able to access evidence
while preparing for trial. It is not uncommon today, especially in large cases, to have
electronic files of all depositions and other testimony of all exhibits coordinated
electronically with the testimony. These kinds of databases are searchable by key word,
by witness, by topic, and by other means. While hard copies of documents and records
are still used, they are rarely used without having electronic copies as well.
This kind of digitization has become quite common in both civil and criminal
cases. There are literally hundreds of organizations whose major business purpose is to
digitize and make searchable documentary evidence. Some of the more popular programs
used to index and store evidence are CaseMap, CaseCentral, ZANTAZ, Ringtail, and
DatiCon. Web searches for “case management archive” and “litigation support” will
reveal further products with many different features. Regardless of the technology or
system utilized, a consistent organization scheme must be used to manage the large
volume of documents in a typical case. Fraud experts use a variety of organization
schemes for their document management. Some organize documents by witness, some
use chronological organization, and others prefer organization by transaction.
Bates numbers are used by attorneys involved in litigation to track all documents.
To illustrate how Bates numbering works, assume that XYZ auditors are being sued by
ABC Corporation’s shareholders. Further assume that the XYZ auditors from two
different offices—New York and New Jersey—worked on the case. Most likely, the
5,000 documents provided (by subpoena, court order, or voluntarily) by XYZ in the New
York office will be numbered XYZ-NY 1000001– 1005000. The documents provided by
ABC Corporation will be labeled ABC 0000001–00100000, etc. This way, the source of
the document is known, and the number provides a unique identifier that can always be
tracked.
Some investigations are simple and involve only a few people. Coordination of
evidence in these circumstances is straightforward. Investigators may decide to share
evidence and plan activities through a series of meetings, and they may use a shared
network drive for coordination. In large cases that involve investigators, legal counsel,
accountants, expert witnesses, and management representatives, coordination can be
more difficult. Investigation analysis software can be useful in these circumstances. Two
popular products in this space are the Analyst’s Notebook from i2, Inc., and Xanalys
Link Explorer. These products allow investigators to quickly understand complex
scenarios and volumes of information in a visual, intuitive way using link analysis. Once
investigators enter their indicators into the centralized database, the software performs
link analysis to find links between people, places, and events. Automatically generated
charts showing links between people, places, and documents make it easy for
investigators to know what objects are most central in a case. These software packages
can do many other types of analyses—from time line analysis to graph analysis.
Most concealment investigative procedures involve accessing and accumulating
documentary evidence. In the remainder of this, we identify several ways to obtain such
evidence. Examiners who have computer, statistics, and accounting backgrounds usually
have an advantage in investigating documentary evidence. You may want to consider
taking further classes in databases, statistics and/or sampling, and accounting documents.
The best way to obtain documentary evidence is through computer-based queries
of accounting and other databases, these methods allow full-population analysis and are
able to pinpoint evidential records within huge populations of millions of total records.
When these methods are used during concealment investigation, the potential scheme has
already been identified. Investigators can focus specifically on Steps 4 (query databases)
and 5 (analyze results) of the data-driven approach to highlight changed or fraudulent
records.
Another useful method of obtaining documentary evidence is through traditional
audits, including discovery sampling. These methods are especially appropriate with
nonelectronic evidence like canceled checks or confirmation letters. These methods are
described in the next section. The least reliable method of obtaining documentary
evidence is by chance, accident, or tips. Once in a while, auditors and others come across
documents that provide evidence of fraudulent activities. Sometimes these documents are
recognized by blatant alterations or forgeries. At other times, informants bring them to an
organization’s attention. In either case, such instances should be considered luck; while
chance evidence often occurs, it should not be seen as a routine method of discovering
documentary evidence.
In general, auditors conduct seven types of tests, each of which yields a form of
evidence. The tests are (1) tests of mechanical accuracy (recalculations), (2) analytical
tests (tests of reasonableness), (3) documentation, (4) confirmations, (5) observations, (6)
physical examinations, and (7) inquiries. Because gathering documentation is a normal
part of their work, auditors can often gather documentary evidence as part of an
investigation without arousing suspicion. Auditors can use manual or computer
procedures to gather documentary evidence.
The limited partnerships case at the beginning of the illustrates how audit
procedures can provide documentary evidence. In this case, auditors sent confirmations
to banks that had placed liens on property the partnerships owned. The return
confirmations contained the amounts of the loans, the dates they were taken out, and the
remaining unpaid balance. Further inquiry of the financial institutions, with the aid of
subpoenas, revealed copies of the loan origination documents with signatures of the
borrowers and other information. Once these original loan documents were available, it
was relatively easy to prove fraud and get a confession.
As another example of how documentary evidence can be helpful, consider again
the fraud at Elgin Aircraft. The defense auditor recognized several symptoms at Elgin,
including (1) the limousine (a lifestyle symptom), (2) never missing a day’s work (a
behavioral symptom), and (3) not verifying claims with employees (a control weakness).
He decided to investigate, suspecting that the manager of the claims department was
committing some kind of fraud. Reasoning that the easiest way for her to be committing
fraud was by setting up phony doctors and billing the company for fictitious claims, the
auditor decided to gather documentary evidence in the form of checks paid to various
doctors to ascertain whether the doctors and claims were legitimate.
The auditor knew it would be impossible to determine conclusively whether fraud
was being perpetrated without looking at every check. He also realized that since there
was no proof of fraud, his suspicions did not justify personally examining the total
population of all 6,000 checks, which were numbered 2000 through 8000. Faced with the
desire to examine the checks but with limited time, the auditor realized he had three
alternatives. He could audit the checks by selecting a few of them to look at, he could
draw a random sample and use statistical sampling techniques to examine the checks, or
he could use a computer and examine certain attributes of all checks.
If the auditor chose the first alternative and analyzed in detail 40 of the checks, he
could conclude that the manager was committing fraud if one or more of the selected
checks had been made out to a fictitious doctor or doctors. However, if his sample of 40
checks did not include payments to fictitious doctors, the only conclusion he could draw
was that there was no fraud in his sample of 40. Without drawing a random sample and
using proper sampling procedures, no conclusions could be made about the total
population. If he happened to find fraud, he would have succeeded. If he did not find
fraud, either he was looking at the wrong sample or there was no fraud.
Sometimes it is necessary to determine whether a document is authentic.
Questioned documents can be genuine, counterfeit, fraudulent, or forged. A specialized
form of investigation that applies forensic chemistry, microscopy, light, and photography
in making determinations about documents is known as document examination.
Document experts can determine whether a document was written by the person whose
signature it bears; whether a document has been forged; whether a document has been
altered by additives, deletions, obliterations, erasures, or photocopying; whether the
handwriting is genuine; whether the entire document was printed on the same machine;
whether a document was printed on the date it bears or before or after; whether two or
more documents are significantly different or substantially the same; and whether pages
have been substituted in a document.
d. Conversion Searches
Conversion searches are performed for two reasons: (1) to determine the extent of
embezzlement and (2) to gather evidence that can be used in interrogations to obtain a
confession. The most common technique used to investigate and resolve fraud is by
interviewing. An interview is a question-and-answer session designed to elicit
information. Early in an interview, effective interviewers can often get suspects to admit
that their only income is earned income (in other words, a statement by the suspect that
he or she has no inherited or non-earned income). Then, by introducing evidence of a
lifestyle and associated expenditures that cannot be supported by the suspect’s earned
income, interviewers make it difficult for the suspect to explain the source of the
unknown income. Cornered suspects sometimes break down and confess.
To become proficient at conversion investigations, fraud examiners need to
understand that information can be gleaned from (1) federal, state, and local agencies and
other organizations that maintain information that can be accessed in searches; (2) private
sources of information; (3) online sources of information; and (4) using the net worth
method of analyzing spending information, which is especially helpful in determining
probable amounts of embezzled funds. Provides a breakdown of the information sources
relevant to investigators. The advent of a large number of online resources has made
conversion investigation activities much more efficient than they used to be. However,
the large number of resources now available can be daunting and even overwhelming.
Keeping up to date on the resources available, paired with careful planning and execution
of investigative tasks, is key to an efficient, effective search.
e. Government Sources of Information
Many federal, state, and local agencies maintain public records in accordance
with various laws. Much of this information can be accessed by anyone who requests it,
but some of it is protected under privacy laws that prevent disclosure to the public.
Federal records are generally not as useful as state and local records in fraud
investigations, but they are helpful in certain situations. Because of the bureaucracies
involved, accessing federal records can be time-consuming and costly.
The Department of Defense maintains records on all military personnel, both
active and inactive. Military information is maintained by branch of service. This
department also contains information on individuals who may be a threat to national
security. The department regularly shares information with other federal agencies, such
as the Federal Bureau of Investigation (FBI) and the Central Intelligence Agency (CIA).
Military records are not confidential and provide valuable information that can help you
trace a person’s whereabouts through changing addresses. Military records are also
helpful in searching for hidden assets, because individuals often buy property and other
assets using previous addresses. The Web site of the U.S. Department of Defense is
www.defense.gov.
The Department of Justice is the federal agency charged with enforcing federal
criminal and civil laws. It maintains records related to the detection, prosecution, and
rehabilitation of offenders. The Department of Justice includes U.S. attorneys, U.S.
marshals, and the FBI. The Drug Enforcement Administration (DEA) is a component of
the Department of Justice and is responsible for enforcing the controlled substances laws
and regulations, including drug trafficking.
The FBI is the principal investigative agency of the Department of Justice.
Criminal matters not assigned to other U.S. agencies are assigned to the FBI. For
example, the FBI normally investigates bank fraud, organized crime, terrorism, and
illegal drug trade. The FBI is responsible for national security within U.S. borders. The
FBI maintains several databases and other records that can be accessed by state and local
law enforcement agencies. The major database maintained by the FBI is the National
Crime Information Center (NCIC). The NCIC contains information on stolen vehicles,
license plates, securities, boats, and planes; stolen and missing firearms; missing persons;
and individuals who are wanted on outstanding warrants. The FBI also maintains the
Interstate Identification Index (III), which is an outgrowth of the NCIC and benefits state
and local law enforcement agencies. The III retains arrest and criminal records on a
nationwide basis.
This agency operates the nationwide system of federal prisons, correctional
institutions, and community treatment facilities. The Bureau is responsible for
maintaining records on those who have been detained in various facilities. Since fraud
perpetrators are often repeat offenders, information on previous incarcerations can often
provide important evidence. The Web site of the Federal Bureau of Prisons is
www.bop.gov.
The Internal Revenue Service (IRS) enforces all internal revenue laws, except
those dealing with alcohol, firearms, tobacco, and explosives, which are handled by the
Bureau of Alcohol, Tobacco, and Firearms. IRS records are not available to the public, so
access to its databases normally requires the involvement of law enforcement officials.
The Web site of the Internal Revenue Service is www.irs.gov.
f. Private Sources of Information
Hundreds of sources of private information are available to those willing to search
for them. Utility records (gas, electric, water, garbage, and sewer), for example, supply
the names of people billed, show whether or not a person lives or owns property in the
service area, and identify the types of utilities a business uses. Another way to gain
financial information is through previous acquaintances. For example, a former spouse of
a suspected fraud perpetrator may have documents—including bank documents—that
turn out to be key in investigations.
A surprising source of valuable financial information is trash cover. Trashing a
suspect involves looking through a person’s trash for possible evidence. Note that
searching trash while it is in the possession of a person is against the law. However, once
the trash leaves the suspect’s home, sidewalk, or fenced area, investigators can usually
freely and legally search the trash. The U.S. Supreme Court case of California vs.
Greenwood in 1988 stated that the Fourth Amendment does not prohibit the warrantless
search and seizure of garbage left for collection outside the curtilage of a home. In the
first months of the year, these searches can uncover valuable tax information. During all
times of the year, it is possible to find credit card information, bank statements, and other
valuable information.
Even shredded documents are not as safe as they were once assumed to be. A
cursory search of the Internet reveals a number of software products that specialize in
piecing shredded documents back together. After scanning in the remains of the
documents, the user simply waits for the software to fit the puzzle back together. Some
law enforcement agencies even employ specialists in manually reassembling shredded
documents. Finally, since most documents are now stored on computers, original files are
often found on one’s personal computer. While users might religiously destroy hard
copies of documents, they often fail to do the same on their computers. Investigators
often find significant sources of evidence in e-mail and other files on seized computers.
g. Online Database
Expanding upon the landscape of online commercial databases provides a deeper
insight into the breadth and depth of available information and its significance in
investigative work. As technology advances and data becomes increasingly digitized, the
accessibility and utility of these databases have become indispensable tools for
investigators across various fields, from law enforcement and legal professionals to
private investigators and corporate security teams.
Firstly, it's important to recognize the diverse range of databases available, each
offering unique datasets and specialized information that can be invaluable in
investigations. These databases may vary in their accessibility models, including
subscription-based platforms, pay-per-use services, or even free-to-access portals. While
some databases may overlap in their offerings, many contain distinct datasets that
complement each other, making it essential for investigators to utilize multiple sources to
gather comprehensive information.
One of the most widely used databases in investigative work is Accurint,
renowned for its extensive collection of public records and background information on
individuals. Accurint provides access to a wealth of data, including criminal records,
property ownership records, professional licenses, and more, making it a valuable
resource for conducting thorough background checks and due diligence.
Another prominent player in the field is AutoTrackXP, formerly owned by
ChoicePoint (now part of LexisNexis), which offers a comprehensive suite of
investigative tools and databases. AutoTrackXP provides access to a wide range of public
records, including motor vehicle records, criminal history reports, and credit information,
empowering investigators to uncover vital information for their cases.
In recent years, the consolidation of major players in the industry, such as
LexisNexis' acquisition of ChoicePoint and its related products, has reshaped the
landscape of commercial databases. While this consolidation has led to single players
gaining access to larger datasets, it's essential for investigators to exercise caution and not
rely solely on one source. Searching multiple databases remains a prudent practice, as
information on individuals may be scattered across different platforms, each offering
unique insights.
The types of information available on these databases are diverse and encompass
various aspects of individuals' financial, legal, and personal histories. From bankruptcy
filings and court records to real estate transactions and tax liens, these databases provide
a wealth of information that can be instrumental in uncovering fraud, conducting
background checks, and supporting legal proceedings. In addition to Accurint and
AutoTrackXP, there are numerous other valuable databases worth mentioning, including:
LexisNexis: A comprehensive platform offering access to a vast array of legal,
business, and public records databases, including court cases, news archives, and
corporate filings.
Thomson Reuters CLEAR: A powerful investigative platform providing access to
a wide range of public and proprietary databases, including criminal records, social media
data, and watchlists.
Dun & Bradstreet: A leading provider of business information and credit reports,
offering insights into companies' financial health, creditworthiness, and business
relationships.
These databases, along with many others, play a crucial role in investigative
work, enabling investigators to gather actionable intelligence, uncover hidden
connections, and build compelling cases. However, it's essential for investigators to
exercise diligence and discretion in utilizing these databases, ensuring compliance with
legal and ethical standards and safeguarding individuals' privacy rights. By leveraging the
wealth of information available through online commercial databases, investigators can
enhance their investigative capabilities and deliver more robust outcomes in their cases.
Indeed, the dynamic nature of the Internet underscores the ever-evolving
landscape of online commercial databases. While the sites mentioned were current at the
time of publication, it's crucial to acknowledge that the online environment is
continuously changing, with databases evolving, new platforms emerging, and existing
ones undergoing updates and revisions. This constant state of flux necessitates a
proactive approach to staying abreast of the latest developments and ensuring that
investigators have access to the most relevant and up-to-date information available.
One significant aspect of the evolving online landscape is the proliferation of new
databases and information sources catering to specific niches or industries. As technology
advances and data analytics capabilities improve, specialized databases are emerging to
cater to the unique needs and requirements of different sectors, from healthcare and
finance to law enforcement and academia. These specialized databases may offer tailored
datasets and advanced analytical tools designed to address specific challenges and
opportunities within their respective domains.
Furthermore, the ongoing consolidation and integration of databases and
information services within larger platforms and conglomerates are reshaping the
competitive landscape of the industry. Mergers and acquisitions among major players,
such as LexisNexis' acquisition of ChoicePoint and Thomson Reuters' acquisition of
Clear, are indicative of the trend towards consolidation and vertical integration within the
industry. This consolidation may result in synergies and efficiencies that benefit users,
such as access to broader datasets and integrated analytical capabilities. However, it also
raises concerns about market concentration and potential monopolistic practices that may
limit competition and innovation in the long run.
Moreover, the advent of new technologies and methodologies, such as artificial
intelligence (AI) and machine learning, is revolutionizing the way data is collected,
analyzed, and utilized within online databases. AI-powered algorithms and predictive
analytics are enabling more advanced and targeted data mining techniques, allowing
investigators to extract actionable insights and uncover hidden patterns and relationships
within vast datasets. Additionally, advancements in data privacy and security protocols
are driving the adoption of enhanced encryption and authentication measures to safeguard
sensitive information and protect users' privacy rights.
In light of these developments, it's essential for investigators to adopt a proactive
and adaptive approach to navigating the ever-changing landscape of online commercial
databases. This entails staying informed about the latest trends and innovations in the
industry, continuously evaluating and updating their toolkits and methodologies, and
leveraging partnerships and collaborations with trusted vendors and service providers to
access the most relevant and reliable information available.
Furthermore, maintaining a robust framework for data governance and
compliance is crucial to ensuring ethical and responsible use of online databases.
Investigators must adhere to legal and regulatory requirements, such as data protection
laws and privacy regulations, and uphold ethical standards and best practices in their
handling and analysis of sensitive information. By embracing a culture of transparency,
accountability, and integrity, investigators can harness the full potential of online
commercial databases while safeguarding individuals' rights and interests in the digital
age.