International Tax Review is part of the Delinian Group, Delinian Limited, 8 Bouverie Street, London, EC4Y 8AX, Registered in England & Wales, Company number 00954730
Copyright © Delinian Limited and its affiliated companies 2023

Accessibility | Terms of Use | Privacy Policy | Modern Slavery Statement

Best practices on corporate investigations in an interconnected world

Sponsored by

The MFSA is committed to improve AML/CFT requirements

Kareena Teh and Catherine Wong of EY assess how corporate protocols to conduct effective internal investigations must be flexible and consider different laws, regulations and enforcement requirements.

We live in an interconnected world where an increasing number of companies are doing more business in different jurisdictions, each with their own laws and regulations. In recent years, an increasing number of governments are enacting laws and regulations, including whistleblower laws, designed to make it easier to gather intelligence and evidence. Many are also taking enforcement actions and cooperating with their counterparts in other jurisdictions, formally as well as informally.

Many companies have policies and procedures in place to encourage ethical behaviour and to detect and stamp out unethical ones. Some also have robust and effective protocols to investigate and deal with compliance issues that arise, including where the issues are not isolated matters, affecting only one jurisdiction, where more than one government has enforcement jurisdiction. For those that do not have investigation protocols, it is time to establish these because they are an important compliance tool to guard against corporate liability and crippling sanctions.

As a general rule, an effective protocol for investigations will include a properly designed plan for:

  • Having a special committee, independent of the issues being investigated, to oversee and manage the investigation;

  • Protecting the integrity and confidentiality of the investigation and its findings;

  • Preserving, collecting and assessing evidence;

  • Interviewing witnesses;

  • Identifying issues, causes and remediation required;

  • Carrying out remediation which may include taking disciplinary action, revising policies and procedures and internal controls, providing training; and

  • Making disclosures (where necessary or appropriate) to authorities (domestic and overseas), shareholders, investors, etc.

The plan needs to be flexible and should take into account the issues being investigated, as well as the likely jurisdictions, government and regulatory authorities involved. Some of the elements are affected by laws, regulations, customs and practices. Others are impacted by the approach adopted by government and regulatory authorities. For example, some laws and regulations may impose secrecy provisions and make it an offence to tip off and prejudice investigations, while some authorities may require the timely and accurate notification of issues uncovered, compulsory preservation of evidence and a full disclosure of findings (without regard to legal professional privilege or confidential obligations). Knowing what to do and having the appropriate professional support is key.

Investigations in mainland China and Hong Kong SAR

As one country with two systems of administration, law and enforcement, mainland China and Hong Kong SAR have their own sophisticated system of laws and regulations targeting criminal activity and robust enforcement regimes.

In mainland China, in a report published during the first quarter of 2019, it was stated that in 2018, there were 26,974 economic crime charges (an increase of 10.9% compared to 2017) and 8,325 patent, copyright and trade secrets charges (an increase of 16.3% compared to 2017). In Hong Kong SAR, the Independent Commission against Corruption prosecuted 58 persons in the first half of 2019, and the Securities and Futures Commission conducted over 1,440 investigations in the first nine months of 2019.

Key differences fundamental to investigations

Some key differences that are fundamental to investigations are in the areas of confidentiality and attorney-client privilege (legal privilege), data protection and privacy, and employee rights. These factors impact the collection and cross-border sharing of evidence.

Confidentiality and legal privilege

Companies in mainland China do not have the right per se to withhold communication between themselves and their lawyers from enforcement authorities on the grounds of legal privilege or confidentiality. This could result in privileged communication being disclosed to Chinese enforcement authorities, as well as overseas authorities who can obtain such documents from their Chinese counterparts through mutual legal assistance agreements.

In contrast, companies in Hong Kong SAR can rely on legal privilege to withhold from enforcement authorities confidential communications passing between lawyers and their clients whereby legal advice is sought or given (lawyer/client communications). In circumstances where litigation is contemplated or has commenced, they can also rely on litigation privilege to withhold such lawyer/client communications, including if they involve third parties such as other professional advisors, experts and witnesses, so long as the communications came into existence after the litigation was contemplated or commenced, and were made for the purpose of the litigation.

Enforcement authorities can and do challenge claims for legal privilege and litigation privilege, particularly on the questions of when litigation was contemplated or whether the purpose of the communication was for the litigation. Both questions continue to be determined on a case-by-case basis and the courts may not necessarily find that litigation is contemplated when an internal investigation commences.

As such, care should be taken in setting up legal privilege protocols for investigations, particularly when communicating with third parties, to secure and preserve legal privilege. Companies should engage lawyers and work with them to carefully manage their communications with their lawyers and third parties involved in the internal investigations. It is recommended to seat the investigation outside mainland China (where possible) and set up legal privilege protocols to protect privileged documents during an internal investigation.

Data protection and data privacy issues

Both mainland China and Hong Kong SAR have personal data protection laws. In mainland China, the personal data protection laws are found in the cybersecurity law while in Hong Kong SAR, they are found in the Personal Data (Privacy) Ordinance. Both regulate the collection, retention and use of personal data, and require consent for the cross-border transfer of personal data, although the Hong Kong SAR laws on cross-border transfers have not yet come into effect.

Mainland China also has other laws and regulations that govern the cross-border transfer of data. More particularly, the cybersecurity law governs the transfer of sensitive data by critical information infrastructure companies while the Law of the People's Republic of China on Guarding State Secrets governs the transfer of state secrets. Both require approval by Chinese authorities. It is important to understand and comply with these requirements at the outset of the investigation, and to comply with them.

Employee rights

In mainland China, the employment contract law provides that employers must establish, perfect and publish regulations and systems in order to protect the employees' labour rights. These requirements and a company's compliance with them may affect the way in which witness interviews are conducted and should be considered at the outset of an investigation. There are no similar requirements in Hong Kong SAR.

Similarities derived from best practices

Notwithstanding the differences, the factors to consider when deciding whether to conduct an internal investigation and the way in which an investigation should be conducted is largely similar in mainland China and in Hong Kong SAR. They derive from best practices that have been developed over time from experience.

Some key best practices to bear in mind are highlighted below:

  • Confidentially, independently and fairly assessing the issues that have come to light, including through whistleblower complaints, and deciding whether to conduct an internal investigation. Factors to consider in such assessments include the identity of the whistleblowers, their relationship with the company and the implicated persons, the motivation for the complaints, the allegations made, and the supporting evidence provided.

  • Setting up a special committee, independent of the issues being investigated, to oversee and manage the investigation, and identifying the roles and responsibilities of its members. Factors to consider when determining its composition include the governance structure of the company, including the bodies and persons with authority and responsibility for making decisions on behalf of the company, applicable policies and procedures, and what the investigation entails, including the nature of the allegations and the persons implicated.

  • Enlisting the assistance of experienced external lawyers, particularly if the issues involve misconduct or regulatory breaches that could result in enforcement action by authorities locally as well as in other jurisdictions. Other professional advisors should be brought in as required. For example, forensic accountants would be helpful for analysing complex accounting treatments or flow of funds.

  • Setting up communications and legal privilege protocols to protect the integrity and confidentiality of the investigation and its findings. These protocols are important even when conducting investigations in mainland China, particularly if the findings are likely to be relevant to operations and enforcement authorities in other jurisdictions.

  • Considering with external lawyers as early as possible if self-disclosure should be made to enforcement authorities, and if so, when and how best to do so, and the extent of cooperation to provide. Factors to consider include disclosure obligations and the possibility of reduced sanctions, leniency and exemptions. If making a self-disclosure, care should be taken to ensure that the disclosure is not misleading, and to preserve legal privilege (where it applies).

  • Having an investigation plan that is tailored to the issues to be investigated. The plan should include the scope and timeline of the investigation, the matters to be investigated, the evidence to be preserved, collected and assessed, the roles and responsibilities of the persons conducting the investigations and the frequency and manner of reporting of findings to the special committee.

  • Setting up protocols for preserving, collecting and analysing the evidence. Factors to consider when setting up the protocols include personal data protection, state secret and other laws that are relevant to the collection, use and cross-border transfer of evidence. Engage computer forensic experts to assist in preserving and collecting relevant electronic evidence, particularly to ensure the integrity of the evidence.

  • Ensuring that witness interviews are conducted in accordance with legal requirements and the policies and procedures of the company.

  • Ensuring that the findings are fully considered, causes are identified and remediation, such as disciplinary action, revision of policies and procedures and internal controls, and training, is undertaken.

  • Ensuring that timely disclosures (where necessary or appropriate) are made to enforcement authorities (domestic and overseas), shareholders, investors, etc.

Click here to read the entire 2020 EY-ITR Asia Pacific Guide

Kareena Teh


T: +852 2629 3207

Kareena Teh is a partner at LC Lawyers. She represents corporations and individuals in governance, regulatory and compliance matters, as well as in corporate and commercial disputes.

Her experience in these areas includes representing clients in investigations into bribery, corruption, fraud, market misconduct, and money laundering and securities fraud issues.

Catherine Wong


T: +852 2675 2173


Catherine Wong is an associate at LC Lawyers. She handles regulatory and government investigations and advises on compliance matters, including corruption, anti-bribery and anti-money laundering.

She also assists international corporations, financial institutions and high-net-worth individuals in complex commercial litigation and arbitration across a broad range of areas, including competition, cyber fraud, product liability and contractual disputes.

more across site & bottom lb ros

More from across our site

The Brazilian government may be about to align the country’s unique system with OECD standards, but this is a long-awaited TP reform and success is uncertain.
Two months since EU political agreement on pillar two and few member states have made progress on new national laws, but the arrival of OECD technical guidance should quicken the pace. Ralph Cunningham reports.
It’s one of the great ironies of recent history that a populist Republican may have helped make international tax policy more progressive.
Lawmakers have up to 120 days to decide the future of Brazil’s unique transfer pricing rules, but many taxpayers are wary of radical change.
Shell reports profits of £32.2 billion, prompting calls for higher taxes on energy companies, while the IMF warns Australia to raise taxes to sustain public spending.
Governments now have the final OECD guidance on how to implement the 15% global minimum corporate tax rate.
The Indian company, which is contesting the bill, has a family connection to UK Prime Minister Rishi Sunak – whose government has just been hit by a tax scandal.
Developments included calls for tax reform in Malaysia and the US, concerns about the level of the VAT threshold in the UK, Ukraine’s preparations for EU accession, and more.
A steady stream of countries has announced steps towards implementing pillar two, but Korea has got there first. Ralph Cunningham finds out what tax executives should do next.
The BEPS Monitoring Group has found a rare point of agreement with business bodies advocating an EU-wide one-stop-shop for compliance under BEFIT.