Internal audits are meant to reduce legal risk, but done without planning, they can create discoverable records that surface later in litigation. Pablo Orozco of Spencer Fane explains why an audit isn’t privileged simply because it’s sensitive or includes counsel on some emails.
Internal audits are an essential tool for identifying and reducing legal risk. But without careful planning, those same audits can create discoverable records that may later be used against companies in litigation or regulatory proceedings. The attorney-client privilege protects sensitive audit-related communications from disclosure, but this often requires structuring and managing the audit with privilege in mind from the outset.
Attorney-client privilege generally protects confidential communications between counsel and the client made for the purpose of seeking or providing legal advice. It does not automatically protect all statements or materials prepared by in-house counsel. As a result, an internal audit is not privileged simply because it involves a sensitive topic, is important to the business or includes counsel on some communications.
Common missteps include assuming all audit data is protected, copying counsel on emails that otherwise involve business advice, circulating audit-related communications too broadly or allowing non-legal teams to drive the project without a clear record of legal direction. These issues are especially acute for large-scale or recurring audits involving compensation, pay equity, compliance, finance, safety or other cross-functional business areas.
The cross-functional audit challenge
Many audits require substantial involvement from non-legal stakeholders. For example, a pay equity audit may depend heavily on compensation, human resources, finance and data analytics teams that understand the company’s pay systems, job architecture, policies and workforce data. From a practical standpoint, those teams may be best positioned to collect information, run analyses and identify operational issues.
The privilege risk arises when the record shows that the audit was primarily business-driven rather than counsel-directed. If counsel is largely absent from project planning, status updates, document review and decision points, it may be harder to establish that key communications were made for the purpose of obtaining legal advice. Similarly, if non-legal teams broadly cascade audit updates through email, chat or collaboration platforms, the company may increase the risk of waiver or create unnecessary discoverable material.
Audit‑Dominated Risk Oversight Leaves Boards Blind to Modern Risks
The solution won’t be found in incremental tweaks to existing compliance templates but in a spirit to change how the board is built
Read moreDetailsPractical steps to help preserve privilege
There is no one-size-fits-all approach, and the right structure will depend on the company, the audit subject matter and the applicable legal risks. However, companies should consider the following steps when planning privileged or potentially privileged audits:
- Define counsel’s role at the outset: Document that the audit is being conducted at the direction of counsel for the purpose of obtaining legal advice, where appropriate.
- Clarify ownership and governance: Establish a core working group or steering committee that includes legal and the key business leaders needed to execute the audit.
- Limit distribution: Share privileged communications and legal advice only with individuals who need the information to support the legal purpose of the audit.
- Use clear communication protocols: Provide project participants with practical guidance on email, chat, document storage, labeling and escalation procedures.
- Separate legal advice from routine business work: Consider whether compliance documentation, business analyses and privileged legal assessments should be maintained separately.
- Manage collaboration platforms carefully: Slack, Teams and other messaging tools can create informal, widely distributed records. As such, audit teams should understand when and how those tools may be used.
Implementation considerations
One approach is to form a central committee made up of the leaders from legal and business functions most relevant to the audit. Counsel can direct the legal aspects of the project, while non-legal committee members coordinate data collection, operational follow-up and issue escalation. This structure can help maintain legal oversight without requiring the legal department to perform every audit task itself.
Companies should also consider adopting written communication and document-handling protocols for audit participants. These protocols may address when to involve counsel, how to label privileged communications, where to store audit materials, who may access them and how to avoid unnecessary discussion of sensitive issues in informal channels.
Internal audits can reduce legal risk only if they are structured to avoid creating new exposure. Companies planning sensitive audits should involve counsel early, define the legal purpose of the work, establish clear governance and train project participants on privilege-preserving communications. These steps will not guarantee protection in every circumstance, but they can significantly improve the company’s ability to defend privilege if the audit is later challenged.


Pablo Orozco is a partner at Spencer Fane. He counsels local, regional and national employers across diverse industries through a wide range of conventional and complex labor and employment matters. 









