The first day is for protecting the company, the evidence and the rights of all parties—not for announcing guilt.
Hours 0–2: Record the alert and contain the risk
Record who raised the concern, when, the transaction or asset involved, and the systems at risk. Separate observed facts from assumptions. If loss may continue, apply a documented and proportionate restriction to the relevant access or process.
Hours 2–6: Preserve before confronting
Secure accounting records, approvals, contracts, email, access logs and available backups. Preserve originals, create controlled working copies and maintain a record of who collected or handled each item.
Hours 6–12: Appoint a small response team
Legal, finance, information technology and human resources may be needed. The mandate should define the questions, period, data sources and reporting line. See the guide to internal investigations.
Hours 12–24: Test hypotheses
Map actual authority, the transaction path, the beneficiary and any control override. A workplace breach is not automatically a financial crime; the distinction is examined in Employee Fraud Against the Company.
Evaluate reporting and liability
Counsel should assess the conduct, evidence, loss, jurisdiction, urgency and any private-right claim. The company should also distinguish the potential liability of the direct actor, assisting persons, managers and the entity itself. See Corporate Crime in Saudi Arabia.