When your Audit Committee receives a whistleblower complaint late on a Friday, you're likely relying on instinct and past experiences. This is when myths can become dangerous. The assumptions that guided your last investigation in London or New York might not apply in Mumbai. Procedures your legal team used five years ago may conflict with current data protection rules. And the privilege protections you're counting on may not exist under Indian law.
These myths persist because internal investigations are infrequent enough that few organizations build genuine expertise, yet consequential enough that mistakes create lasting regulatory and legal exposure. Here's what you need to unlearn.
Myth 1: Your In-House Counsel Can Lead the Investigation and Preserve Privilege
Reality: Indian law does not extend legal professional privilege to in-house counsel. Only communications with an external advocate enrolled with a Bar Council attract advocate-client privilege under Section 132 of the Indian Evidence Act.
This isn't a technicality. It's a structural difference that changes how you must staff and supervise the entire investigation. If your General Counsel leads the inquiry, every interview note, analysis memo, and draft finding sits outside privilege protection. Those documents become discoverable in subsequent litigation or regulatory proceedings.
Structure the investigation from day one with external counsel leading or directly supervising the work. Retain forensic accountants and technology experts through that external counsel, not through your procurement department. Their work product gains whatever privilege protection is available only if the engagement runs through the advocate relationship.
Don't commingle legal advice with factual investigation records in the same document. Maintain strict separation between what your external counsel analyzes (potentially privileged) and what your internal team compiles (generally not privileged). This separation must be deliberate and documented.
Myth 2: You Can Disclose Parts of Privileged Material Without Waiving the Rest
Reality: Indian law recognizes no concept of partial waiver. Any voluntary disclosure of privileged material, including selective disclosure to a regulator, risks waiving privilege over all communications on the same subject matter.
This creates a binary decision point that many organizations miss. When SEBI or another regulator requests investigation documents, you can't hand over the factual summary while protecting the legal analysis. The moment you voluntarily share one privileged document, you've likely opened the entire file.
Treat every disclosure to a regulator as a privilege decision requiring explicit approval from your Audit Committee or Board. Before you share anything, work with external counsel to map what else sits in the same subject matter category. Understand the full scope of what you're potentially exposing before you click send.
In cross-border investigations, this becomes exponentially more complex. US attorney-client privilege, UK legal professional privilege, and Indian advocate-client privilege operate under different rules. What's protected in one jurisdiction may be discoverable in another. You need jurisdiction-specific counsel assessing each disclosure decision before material crosses borders.
Myth 3: Data Preservation Can Wait Until You Understand the Scope
Reality: You have hours, not days, to issue document preservation notices and suspend automatic deletion routines. By the time you've scoped the investigation, relevant evidence may already be overwritten by routine backup cycles or destroyed through standard retention policies.
Issue a written preservation notice within the first 48 hours of receiving the complaint. Specify the categories of data to be retained, the relevant time period, and the systems covered. This includes email servers, financial systems, collaboration tools, CCTV footage, and access logs.
Suspend automatic deletion, backup overwrites, and routine data purges immediately. Your IT team must confirm compliance in writing. Don't assume this happens automatically because you've opened an investigation. Someone must actively intervene in your organization's normal data lifecycle management.
The Digital Personal Data Protection Act, 2023 adds another layer. Before you transfer investigation data outside India, you need legal advice on data localization requirements and cross-border transfer conditions. The Act applies to a government-notified restricted-country list, and violating these restrictions during an investigation creates a separate compliance failure on top of whatever you're investigating.
Myth 4: Anonymous Complaints Deserve Less Scrutiny
Reality: You cannot dismiss a complaint solely because it's anonymous. The credibility of an allegation depends on its content and verifiability, not the identity of the complainant.
Your preliminary assessment should verify whether the persons, departments, transactions, or documents named in the complaint actually exist. If an anonymous complaint identifies a specific invoice number, a named vendor, and a date range, and those elements check out, you have a credible allegation requiring full investigation.
Anonymous complaints often come from individuals who fear retaliation despite your policy protections. They may have witnessed conduct that implicates senior management or powerful colleagues. Dismissing these complaints creates both a control gap and a cultural signal that undermines your entire whistleblower program.
Conduct the same preliminary credibility assessment you'd apply to a named complaint: do the facts alleged align with your organizational structure and transaction patterns? Are the details specific enough to investigate? Can you identify relevant evidence sources? If yes, proceed with a full investigation.
Myth 5: You Can Interview First and Warn Later
Reality: Before each interview, external counsel must give the interviewee an Upjohn warning stating that counsel represents the company, not the individual; that the interview is confidential and protected by the company's privilege, which the company may waive; and that the employee should not discuss the interview with colleagues.
This isn't a courtesy. It's a legal and ethical requirement that protects both the organization and the individual. Without this warning, employees may reasonably believe your external counsel represents their interests. They may make statements they wouldn't otherwise make. And when the company later takes adverse action based on those statements, you've created an ethical problem and potential grounds for challenge.
The warning must be given before the interview begins, not embedded in follow-up documentation. It must be clear and unambiguous. And it must be documented in your interview protocol records.
Don't offer confidentiality, immunity from disciplinary action, or any protection unless specifically authorized by your Audit Committee and legally permissible. Once offered, you're bound by it.
What to Do Instead
Build investigation readiness before the complaint arrives. Identify key sources of electronic evidence within your IT systems and document data preservation protocols that can be activated within hours. Conduct annual tabletop exercises with your Audit Committee Chair, General Counsel, Chief Compliance Officer, and CFO simulating an investigation scenario under time pressure.
Engage external legal counsel within the first 48 hours of receiving any serious allegation. Issue your investigation mandate in writing before work begins, specifying scope, reporting lines, key milestones, and budget. And assess disclosure obligations at the outset, considering materiality thresholds under SEBI LODR and reporting requirements across all relevant jurisdictions.
The myths persist because investigations are rare. The consequences persist because the legal and regulatory framework doesn't forgive institutional learning curves.



