What happened?
Build a reliable chronology from source material, identify points of agreement and conflict and locate the gaps that prevent a supported account.
Forensic investigations
Audit Corridor develops and tests facts for boards, founders, investors, counsel and control functions when the known narrative is incomplete, internally contested or unsupported by a reliable evidence map.
Updated: 25 August 2026
A forensic investigation is a scope-defined process that develops and tests facts using records, interviews, financial data and corroborating material. A defensible output separates evidence, inference, limitation and unknown.
Decision questions
The work begins with the decision that must be made, not with a generic checklist. Typical questions concern the event, the people involved and the evidentiary strength of the available account.
Build a reliable chronology from source material, identify points of agreement and conflict and locate the gaps that prevent a supported account.
Examine roles, authority, communications, approvals, relationships and conduct without treating association alone as proof.
Test the leading explanation against alternatives, contradictions, provenance, reliability and information that remains unavailable.
Evidence architecture
The evidence set is defined by the question and lawful access. Collection is kept proportionate, sources remain identifiable and sensitive material is handled under the agreed mandate.
Engagement sequence
Scope, evidence handling, analytical challenge and reporting remain visible throughout the mandate.
At scoping
Set the questions, intended use, parties, time period, independence considerations and standard the conclusion must meet.
At intake
Create source registers, access controls, document families, chronologies and a visible record of missing material.
During analysis
Test evidence through transaction review, relationship analysis, interviews and competing hypotheses.
At conclusion
Present findings, evidentiary basis, alternative explanations, limitations and the next decisions available.
Decision-grade delivery
A decision-grade output should make the reasoning inspectable. It is not a volume dump and it does not convert uncertainty into confidence for presentation.
Scope boundary: Audit Corridor provides investigative and analytical support. Legal advice, statutory audit, digital forensics, expert testimony or specialist work is included only when separately agreed and appropriately qualified.
Common questions
These answers explain the usual architecture. The facts, access, jurisdiction and intended use determine the actual scope.
It should begin when a consequential decision depends on disputed or incomplete facts, evidence may be lost or altered, an allegation requires independent testing or ordinary control processes cannot produce a reliable account.
The scope is built around defined questions, parties, time periods, available information, decision-makers, intended use and known constraints. It can be revised when new evidence changes the question, but changes should be recorded and agreed.
Internal audit ordinarily evaluates governance, risk and controls against an assurance plan. A forensic investigation develops facts about a specific event, allegation or loss and tests competing explanations against evidence. The two disciplines can inform each other but are not interchangeable.
Conflict screening and a limited initial exchange come first. Information access, storage, purpose, reporting lines and communication are then defined in writing. Sensitive evidence should not be sent before those arrangements are agreed.
Connected work
A mandate may require more than one analytical lens. Boundaries and responsibilities are defined at scope.
Loan-lifecycle review, end-use analysis and transaction tracing.
Explore →Financial-trail reconstruction across accounts, entities and layers.
Explore →Evidence architecture and analytical schedules developed with counsel.
Explore →