No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Internal Audit

Is Internal Audit Reducing Risk — or Creating It?

Attorney-client privilege has to be built into an audit’s governance from Day One

by Pablo Orozco
September 22, 2026
in Internal Audit
hand on pile of papers

Internal audits are meant to reduce legal risk, but done without planning, they can create discoverable records that surface later in litigation. Pablo Orozco of Spencer Fane explains why an audit isn’t privileged simply because it’s sensitive or includes counsel on some emails.

Internal audits are an essential tool for identifying and reducing legal risk. But without careful planning, those same audits can create discoverable records that may later be used against companies in litigation or regulatory proceedings. The attorney-client privilege protects sensitive audit-related communications from disclosure, but this often requires structuring and managing the audit with privilege in mind from the outset.

Attorney-client privilege generally protects confidential communications between counsel and the client made for the purpose of seeking or providing legal advice. It does not automatically protect all statements or materials prepared by in-house counsel. As a result, an internal audit is not privileged simply because it involves a sensitive topic, is important to the business or includes counsel on some communications.

Common missteps include assuming all audit data is protected, copying counsel on emails that otherwise involve business advice, circulating audit-related communications too broadly or allowing non-legal teams to drive the project without a clear record of legal direction. These issues are especially acute for large-scale or recurring audits involving compensation, pay equity, compliance, finance, safety or other cross-functional business areas.

The cross-functional audit challenge

Many audits require substantial involvement from non-legal stakeholders. For example, a pay equity audit may depend heavily on compensation, human resources, finance and data analytics teams that understand the company’s pay systems, job architecture, policies and workforce data. From a practical standpoint, those teams may be best positioned to collect information, run analyses and identify operational issues.

The privilege risk arises when the record shows that the audit was primarily business-driven rather than counsel-directed. If counsel is largely absent from project planning, status updates, document review and decision points, it may be harder to establish that key communications were made for the purpose of obtaining legal advice. Similarly, if non-legal teams broadly cascade audit updates through email, chat or collaboration platforms, the company may increase the risk of waiver or create unnecessary discoverable material.

blindfolded statue
Governance

Audit‑Dominated Risk Oversight Leaves Boards Blind to Modern Risks

by Adley John Fisher
August 10, 2026

The solution won’t be found in incremental tweaks to existing compliance templates but in a spirit to change how the board is built

Read moreDetails

Practical steps to help preserve privilege

There is no one-size-fits-all approach, and the right structure will depend on the company, the audit subject matter and the applicable legal risks. However, companies should consider the following steps when planning privileged or potentially privileged audits:

  • Define counsel’s role at the outset: Document that the audit is being conducted at the direction of counsel for the purpose of obtaining legal advice, where appropriate.
  • Clarify ownership and governance: Establish a core working group or steering committee that includes legal and the key business leaders needed to execute the audit.
  • Limit distribution: Share privileged communications and legal advice only with individuals who need the information to support the legal purpose of the audit.
  • Use clear communication protocols: Provide project participants with practical guidance on email, chat, document storage, labeling and escalation procedures.
  • Separate legal advice from routine business work: Consider whether compliance documentation, business analyses and privileged legal assessments should be maintained separately.
  • Manage collaboration platforms carefully: Slack, Teams and other messaging tools can create informal, widely distributed records. As such, audit teams should understand when and how those tools may be used.

Implementation considerations

One approach is to form a central committee made up of the leaders from legal and business functions most relevant to the audit. Counsel can direct the legal aspects of the project, while non-legal committee members coordinate data collection, operational follow-up and issue escalation. This structure can help maintain legal oversight without requiring the legal department to perform every audit task itself.

Companies should also consider adopting written communication and document-handling protocols for audit participants. These protocols may address when to involve counsel, how to label privileged communications, where to store audit materials, who may access them and how to avoid unnecessary discussion of sensitive issues in informal channels.

Internal audits can reduce legal risk only if they are structured to avoid creating new exposure. Companies planning sensitive audits should involve counsel early, define the legal purpose of the work, establish clear governance and train project participants on privilege-preserving communications. These steps will not guarantee protection in every circumstance, but they can significantly improve the company’s ability to defend privilege if the audit is later challenged.

Tags: Internal Investigation
Previous Post

Congress Seems Stalled on AI Regulation. The States Aren’t.

Pablo Orozco

Pablo Orozco

Pablo OrozcoPablo Orozco is a partner at Spencer Fane. He counsels local, regional and national employers across diverse industries through a wide range of conventional and complex labor and employment matters.

Related Posts

meeting with attorney

AI in Investigations: What Courts Are Saying (So Far) About Privilege

by Gorev Ahuja
September 15, 2026

Emerging case law shows how easily AI-assisted investigation work can lose attorney-client privilege

story threads on board with post its

Telling Moments Compliance Leaders May Overlook in Investigations

by Pamela Meyer
August 10, 2026

Understanding how people recount details in an interview is just as important as the words they say

us doj building with flag

Once You’ve Decided to Self-Disclose, Here’s How to Do It Right

by Sean M. Farrell and Thomas F. Rybarczyk
July 29, 2026

Deciding to self-disclose is one thing; doing it well is another, and the difference often shapes whether a company earns...

corporate investigation magnifying glass

When Misconduct Reaches the C-Suite, Who Investigates?

by Carrington Giammittorio, Taryn McDonald and Miles Moody
July 20, 2026

From selecting outside counsel to safeguarding privilege, the decisions in-house counsel makes early determine an independent investigation’s credibility

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights