[codicts-css-switcher id=”346″]

Global Law Experts Logo
internal investigation switzerland

How to Conduct an Internal Investigation in Switzerland (2026): Step‑by‑step, Privilege & Cross‑border Guidance

By Global Law Experts
– posted 59 minutes ago

Updated: Sep 2026

Internal investigation Switzerland work has become significantly more demanding in 2026, as cross‑border enforcement pressure from the United States and United Kingdom converges with a fast‑moving digital evidence landscape and tighter data protection rules. Companies operating in Switzerland, particularly banks, asset managers and internationally exposed corporates, now need a defensible, procedural framework rather than an ad hoc response to each allegation. This guide sets out the practical steps, privilege considerations, evidence preservation obligations, timelines, indicative costs and the decision framework for cooperating with foreign authorities. It is written for in‑house counsel, compliance officers, executives and external counsel who need to act quickly and correctly. It is general information and not legal advice; contact counsel for case‑specific guidance.

Who this is for: In‑house counsel, compliance officers, corporate executives and external counsel in Switzerland.

What you’ll get: A step‑by‑step method for running an internal investigation in Switzerland, covering privilege, preserving digital evidence, timelines, costs and when to cooperate with foreign authorities, plus a checklist and FAQ.

Overview: running an internal investigation Switzerland companies can defend

A corporate internal investigation in Switzerland is a structured, privileged (where possible) fact‑finding exercise triggered by an allegation of misconduct, typically fraud, money laundering, bribery, sanctions evasion, market abuse, cyber intrusion or data breach. The objective is threefold: establish what happened, contain legal and regulatory exposure, and put the organisation in a position to make informed decisions about remediation and reporting. Done well, an investigation protects the company. Done poorly, it can waive privilege, destroy evidence and hand prosecutors a ready‑made case.

This guide is procedural. It does not replace tailored legal advice, and several judgement calls, particularly on privilege waiver and self‑reporting, require case‑specific counsel. The recurring themes throughout are legal privilege in the digital era, disciplined preservation of electronic evidence, and the increasingly frequent need to manage parallel interest from the Office of the Attorney General of Switzerland (OAG), the Swiss Financial Market Supervisory Authority (FINMA), and foreign enforcement bodies such as the US Department of Justice (DOJ) and the UK Serious Fraud Office (SFO).

Why this matters in 2026

Three forces make an internal investigation Switzerland teams run today materially harder than five years ago. First, enforcement has become genuinely multijurisdictional: a single set of facts can attract simultaneous interest from Swiss prosecutors, FINMA and foreign authorities. Second, digitalisation has multiplied the volume and fragility of relevant data, messaging platforms, cloud stores and ephemeral logs disappear quickly if not preserved. Third, the Federal Act on Data Protection (FADP), which entered into force in its revised form on 1 September 2023, constrains how personal data is handled and transferred abroad during a probe, adding a compliance layer to every cross‑border data movement.

Who should lead the investigation: in‑house versus external counsel

Minor, low‑exposure matters can be handled by in‑house counsel and compliance. However, where privilege matters, where the allegation could lead to criminal or regulatory proceedings, or where foreign authorities may become involved, external counsel should be engaged early. Under Swiss law, communications with an independent, registered external lawyer attract stronger protection under professional secrecy (attorney‑client privilege) than in‑house work product, which does not benefit from the same statutory protection in Switzerland. Engaging external criminal counsel at the outset also signals independence, a factor that Swiss and foreign regulators weigh when assessing the credibility of an investigation.

Eligibility: when to open an internal investigation

Not every complaint warrants a full investigation, but under‑reacting is a common and costly error. The decision to open an internal investigation Switzerland process should be governed by a documented triage standard so that comparable allegations are treated consistently and the rationale for each decision is recorded.

Immediate red flags

  • Whistleblower reports. Internal or anonymous reports alleging fraud, bribery, self‑dealing or falsified records.
  • Unusual transactions. Payments to opaque intermediaries, round‑sum transfers, or activity inconsistent with a client’s profile that may engage anti‑money‑laundering duties under the Anti‑Money Laundering Act (AMLA).
  • Regulator notice. A request for information, enquiry or enforcement contact from FINMA or the OAG.
  • Dawn raid. A search or seizure at company premises, which demands both immediate legal response and a parallel internal review.
  • Media or litigation allegations. Press reporting or civil claims naming the company or its executives.
  • Foreign subpoena or MLA request. Contact indicating that DOJ, SFO or another authority is already active.

Internal triage checklist

Before escalating, the compliance or legal function should record: the source and credibility of the allegation; the potential offences involved; the individuals and business units implicated; the systems likely to hold relevant data; whether volatile data (logs, messaging) is at immediate risk; and whether any statutory or regulatory reporting clock may already be running. Where the allegation touches senior management, involves potential criminal liability, or has any cross‑border dimension, the default should be to escalate to external counsel and treat the matter as privileged from the first hour.

Step‑by‑step internal investigation (HowTo)

The following method sequences an internal investigation Switzerland teams can defend before regulators and courts. Each numbered step contains tactical sub‑steps. Preservation and privilege discipline must run continuously across every phase, they are not one‑off tasks.

  1. Initial intake and triage.

    • Log the allegation with date, source and initial assessment.
    • Preserve volatile data immediately, suspend auto‑deletion, snapshot at‑risk systems, and secure devices of key custodians.
    • Assign an investigation lead and restrict knowledge of the matter to a defined, need‑to‑know group.
    • Assess whether any reporting clock (FINMA, OAG, foreign authority) may already be running.
  2. Engage external counsel and forensics.

    • Retain independent external criminal counsel where privilege and independence are needed.
    • Instruct a certified digital forensics vendor under counsel’s direction, so their work falls within the privileged workstream where lawfully possible.
    • Confirm conflicts checks and engagement scope in writing.
  3. Issue a legal hold and preserve ESI.

    • Send written legal hold notices to all relevant custodians and IT.
    • Preserve mailboxes, cloud data (SharePoint, OneDrive, Google Drive), collaboration tools (Slack, Teams) and relevant device backups.
    • Collect and preserve system and security logs (SIEM, firewall, VPN) before rotation overwrites them.
    • Document the preservation steps taken, with timestamps, to evidence a defensible chain of custody.
  4. Scope and planning.

    • Define the investigation’s scope, key questions and hypotheses.
    • Produce a written investigation plan, budget and reporting lines to the board or a special committee.
    • Map data protection and cross‑border transfer issues under the FADP before any data leaves Switzerland.
  5. Evidence collection and analysis.

    • Take forensic images of servers and workstations under chain‑of‑custody protocols.
    • Collect and de‑duplicate email, documents and messaging data for review.
    • Review financial records, contracts and third‑party agreements, preserving metadata and version history.
    • Segregate privileged material into a separate, access‑controlled workspace.
  6. Witness interviews.

    • Sequence interviews from peripheral to central witnesses, ending with the most implicated individuals.
    • Give an appropriate warning clarifying that counsel acts for the company, not the individual.
    • Decide in advance whether interviews are recorded, and preserve interview notes as privileged work product where possible.
    • Respect employment and data protection rules governing the treatment of employee information.
  7. Internal report and remediation plan.

    • Draft findings carefully, distinguishing established facts from assessment and legal analysis.
    • Assess criminal, regulatory and civil exposure across all relevant jurisdictions.
    • Design remedial measures: control fixes, disciplinary action, policy changes and training.
  8. Decide on reporting and cooperation.

    • Evaluate any mandatory reporting triggers to FINMA, the OAG or the Money Laundering Reporting Office Switzerland (MROS).
    • Assess whether voluntary self‑disclosure to DOJ, SFO or other authorities is advisable.
    • Take a deliberate decision on privilege, what, if anything, to share, and on what terms.
  9. Closure and document retention.

    • Finalise the report and record the decisions taken and their rationale.
    • Apply a defined retention schedule consistent with legal, regulatory and limitation requirements.
    • Preserve privilege designations and maintain access restrictions after closure.

Investigation timeline: step, lead and duration

Step Key actions Who (lead) Typical duration
1. Initial intake & triage Evaluate allegation, preserve volatile data, assign lead In‑house counsel + compliance 24–72 hours
2. Engage external counsel & forensics Retain external criminal counsel and forensics vendor External counsel + IT forensics 24–72 hours
3. Issue legal hold & preserve ESI Legal hold notice; preserve mailboxes, cloud data, logs Legal + IT 1–3 days (then ongoing)
4. Scope & planning Define scope, create investigation plan and budget Investigation lead + external counsel 2–5 days
5. Evidence collection & analysis Forensic imaging, log collection, email and contract review Forensics team + lawyers 1–4 weeks (varies)
6. Witness interviews Prepare questions, conduct interviews with privilege strategy External counsel 1–3 weeks
7. Internal report & remediation Draft findings, risk assessment, remedial measures External counsel + management 1–2 weeks
8. Decide on reporting / cooperation Evaluate self‑reporting to OAG/FINMA/DOJ/SFO Board + external counsel 1–4 weeks (may be longer)
9. Closure & retention Final report, preserve privilege, retention schedule Legal + records Ongoing

These durations are indicative for a mid‑sized matter. Complex, multi‑jurisdictional investigations involving financial institutions routinely run six to twelve months or longer, particularly where large data volumes and cross‑border cooperation are involved.

Required documents and evidence preservation

Evidence preservation is the single most time‑critical part of any internal investigation Switzerland process. Ephemeral data, chat messages, security logs, temporary files, can be lost within days if auto‑deletion and log rotation are not suspended immediately. The Swiss Criminal Procedure Code (CrimPC / StPO) governs how authorities seize and handle evidence; a company that preserves material to an equivalent standard protects both the integrity of its own findings and its credibility with prosecutors.

Two handling rules are fundamental. First, maintain a documented chain of custody for every item collected, recording who accessed it, when and how. Second, rigorously segregate privileged material, legal advice and counsel’s work product, from operational data, storing it separately and marking it privileged, with access limited to the investigation team. Mixing the two is one of the fastest ways to jeopardise privilege.

Document / evidence type Priority Notes on preservation
Forensic images of servers & workstations High Use a certified forensic vendor; preserve chain of custody
Email mailboxes (PST / Exchange / 365) High Preserve unaltered exports; retain metadata
Cloud storage (SharePoint, OneDrive, Google Drive) High Export via admin tools; preserve version history
Messaging (Slack, Teams, WhatsApp) High Preserve workspace exports and mobile backups
System & security logs (SIEM, firewall, VPN) High Collect promptly; volatile logs may be overwritten
HR records (contracts, performance notes) Medium Preserve originals and redacted copies as required
Financial records (transfers, invoices) High Preserve transaction records and payment confirmations
Contracts & third‑party agreements Medium Preserve executed versions and change history
Interview notes & recordings Medium Track attendance; obtain consent where lawful
Legal advice / counsel notes (privileged) High Store separately; mark privileged; restrict access

Where any of this material contains personal data and must be reviewed or transferred outside Switzerland, the FADP applies. Processing must rest on a lawful basis, and cross‑border transfers must satisfy the FADP’s requirements, either a transfer to a country recognised as providing adequate protection, or appropriate safeguards, before data leaves the jurisdiction. Build that assessment into the preservation plan rather than treating it as an afterthought.

Timeline and deadlines: criminal, regulatory and preservation periods

Three distinct clocks run in parallel during an internal investigation, and confusing them is dangerous. The first is the preservation clock, which is the most urgent: volatile logs and ephemeral messages must be preserved within hours, not days, and exported immediately rather than merely left in place. The second is the regulatory clock. FINMA expects supervised institutions to identify, escalate and address serious compliance breaches promptly, and certain financial‑crime suspicions carry their own reporting obligations, including reports to MROS under the AMLA; delay itself can become an aggravating factor.

The third is the criminal clock. Substantive offences under the Swiss Criminal Code (SCC / StGB) are subject to statutory limitation periods that vary by the gravity of the offence, and procedural steps under the CrimPC have their own timing implications for seizure and search. While the internal investigation itself is not bound by a single statutory deadline, its pace must account for these limitation periods and for the reality that regulators and prosecutors judge companies partly on how quickly they acted. A defensible internal process typically takes weeks for containment and initial fact‑finding, and often six to twelve months for a full, complex matter to reach closure.

Costs and fees

Costs vary widely with complexity, data volume and the number of jurisdictions involved. The ranges below are indicative for a Swiss matter in 2026 and should be treated as budgeting guidance, not quotations. The principal cost drivers are the volume of electronic data to be preserved and reviewed, the number of custodians and interviews, translation needs across French, German, Italian and English, and the degree of cross‑border coordination required.

Item Indicative cost range (Switzerland, 2026) Notes
External criminal counsel (small/medium cases) CHF 20,000 – 80,000 Depends on complexity and hours; rates vary by city and firm
External criminal counsel (large/complex/financial institutions) CHF 100,000 – 1,000,000+ Multi‑month investigations with cross‑border coordination
Digital forensics (initial triage) CHF 5,000 – 30,000 Rapid triage and imaging
Digital forensics (full analysis) CHF 30,000 – 200,000+ Large data volumes and complex analysis
Specialist investigators / forensic accountants CHF 5,000 – 50,000 Senior investigators or accounting expertise
Translation & document review CHF 2,000 – 50,000+ Multilingual documents increase cost
Remediation (systems, policies, training) CHF 5,000 – 150,000 Depends on technical fixes and scope

To control costs, define scope tightly at the outset, phase the work so that early triage informs later spend, and use targeted data collection rather than reviewing everything. A disciplined scoping exercise in step four typically saves far more than it costs.

What changes in 2026: regulatory and enforcement updates

Several developments shape how an internal investigation Switzerland teams run must be conducted in 2026. Cross‑border enforcement expectations have intensified: Swiss entities with US or UK nexus increasingly face parallel interest from DOJ and SFO, and both authorities continue to reward prompt, genuine cooperation. Companies can no longer treat a Swiss matter as purely domestic once foreign touchpoints exist.

FINMA maintains clear expectations that supervised institutions detect, escalate and remediate misconduct robustly, and it scrutinises the independence and quality of internal investigations when assessing an institution’s response. Digitalisation continues to test legal privilege: as investigations rely on cloud and messaging data reviewed by external vendors, the boundary of protected work product must be managed deliberately, in line with the professional secrecy framework governing registered lawyers under the Federal Act on the Free Movement of Lawyers (LFMA/BGFA). Finally, the FADP remains central to any cross‑border evidence handling, requiring a lawful basis for processing and compliant safeguards before personal data is transferred out of Switzerland during a probe.

Enforcement bodies continue to prioritise the speed and credibility of a company’s response, making early preservation and independent oversight more important than ever.

Common pitfalls and practical tips

Most damaging errors in an internal investigation are procedural rather than substantive, and nearly all are avoidable with discipline.

  • Failing to preserve ephemeral data. Not suspending auto‑deletion and log rotation in the first hours, allowing critical messaging and log data to vanish.
  • Mixing privileged and non‑privileged workstreams. Storing legal advice alongside operational data, which risks undermining privilege.
  • Poor chain of custody. Collecting evidence without documented handling, undermining its reliability before regulators and courts.
  • Inadequate interview notes. Failing to record who was present, what caution was given, and what was said.
  • Premature disclosure. Volunteering material to regulators or foreign authorities before understanding the facts and the privilege consequences.
  • Ignoring reporting triggers. Overlooking FINMA, OAG or MROS notification obligations, or an already‑running foreign clock.
  • Transferring data abroad without FADP analysis. Moving personal data out of Switzerland for review without a lawful basis or safeguards.

Practical mitigation tips

Build a pre‑drafted legal hold template and preservation checklist so the first response is immediate. Engage independent external counsel early where privilege or cross‑border risk exists. Keep a single, contemporaneous decision log recording key judgement calls and their rationale, it demonstrates good faith and helps if the process is later scrutinised. Rehearse dawn raid procedures so staff know to call counsel, note what is seized and avoid volunteering statements. These quick wins cost little and materially reduce downstream risk.

When to cooperate or self‑report to foreign authorities (DOJ/SFO)

Deciding whether to self‑report is among the most consequential judgement calls in any cross‑border investigation, and it must be taken with counsel on the specific facts. The DOJ’s corporate enforcement approach offers meaningful cooperation credit, including potential reductions in penalties, for genuine voluntary self‑disclosure, timely cooperation and remediation. The SFO similarly encourages early, substantive cooperation and can consider deferred prosecution agreements in appropriate cases, subject to court approval. The OECD Anti‑Bribery Convention reinforces an international expectation of enforcement and mutual assistance in foreign bribery matters, which increases the likelihood that authorities will eventually learn of serious conduct regardless of a company’s choice.

Against those incentives sit real risks. Self‑reporting can require sharing material that touches privileged work product, so any disclosure strategy must be designed to protect privilege as far as possible. Swiss professional secrecy and data protection constraints, and Article 271 of the Swiss Criminal Code, which restricts acts performed in Switzerland for a foreign authority without authorisation, also govern what may lawfully be shared abroad. The right answer turns on the gravity of the conduct, the strength of the evidence, the extent of foreign jurisdictional exposure, and the expectations of the relevant regulators.

Factor Self‑report / cooperate Do not self‑report / limited cooperation
Possible benefits Cooperation credit, mitigation, reduced penalties (DOJ/SFO) Avoids immediate admissions; preserves defence options
Risks Possible privilege waiver if documents are shared; regulatory scrutiny; Art. 271 SCC constraints on providing evidence abroad Risk of harsher penalties, orders or charges if discovered later
Privilege impact Careful strategy needed; involve counsel early Privilege preserved, but silence may later be viewed unfavourably
Practical cost Higher immediate disclosure effort Potentially higher long‑term litigation and regulatory cost

As a practical matter, the decision should never be made reflexively in either direction. Map every jurisdiction with a potential interest, assess the realistic probability of independent discovery, and model the privilege and Swiss‑law consequences of each disclosure route before committing. Where mandatory Swiss reporting to FINMA, the OAG or MROS is triggered, that obligation must be addressed on its own terms, separately from the discretionary question of foreign self‑reporting.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Bruno Ledrappier at CHARLES RUSSELL SPEECHLYS, a member of the Global Law Experts network.

Downloadable resources and checklist

To operationalise this guidance, use a written internal investigation checklist covering intake, immediate preservation, legal hold, scoping, evidence collection, interviews, reporting and closure. A one‑page timeline mapping the nine steps above to responsible owners and durations helps keep multi‑workstream investigations on track. For deeper guidance on specific issues, consider companion material on protecting legal privilege in Swiss internal investigations, on when to self‑report to US/UK authorities from Switzerland, and a practical internal investigation checklist.

A defensible internal investigation Switzerland process is ultimately about discipline: preserve fast, protect privilege, document decisions, and take reporting and cooperation choices deliberately rather than reactively. This article is general information and not legal advice; every serious matter should be handled with case‑specific counsel.

Sources

  1. Swiss Criminal Code (SCC / StGB), Fedlex
  2. Swiss Criminal Procedure Code (CrimPC / StPO), Fedlex
  3. Federal Act on Data Protection (FADP), Fedlex
  4. Anti‑Money Laundering Act (AMLA), Fedlex
  5. Office of the Attorney General of Switzerland (OAG)
  6. Swiss Financial Market Supervisory Authority (FINMA)
  7. Money Laundering Reporting Office Switzerland (MROS)
  8. Federal Office of Justice (FOJ)
  9. OECD Anti‑Bribery Convention, OECD
  10. US Department of Justice, Foreign Corrupt Practices Act
  11. UK Serious Fraud Office
  12. Swiss Bar Association (SAV‑FSA)

FAQs

What triggers an internal investigation in Switzerland?
An internal investigation Switzerland process is typically triggered by a credible whistleblower report, unusual or suspicious transactions, a request or enforcement contact from FINMA or the OAG, a dawn raid, serious media allegations, or a subpoena or mutual legal assistance request from a foreign authority such as DOJ or SFO. The key is a documented triage standard so comparable allegations are handled consistently.
Communications with an independent, registered external lawyer benefit from professional secrecy (attorney‑client privilege) protection, which is generally stronger than protection for purely internal work product, in‑house legal communications do not enjoy the same statutory protection in Switzerland. To preserve privilege, engage external counsel early, direct forensic vendors through counsel, and rigorously segregate privileged advice from operational data. Privilege can be lost through careless handling or voluntary disclosure.
Act within hours. Suspend auto‑deletion and log rotation, issue written legal holds, preserve mailboxes, cloud stores and messaging exports, and collect volatile logs before they are overwritten. Use a certified forensic vendor, maintain a documented chain of custody, and complete an FADP assessment before any personal data is transferred outside Switzerland for review.
Supervised institutions are expected to detect, escalate and address serious compliance breaches promptly, and certain money‑laundering suspicions trigger a duty to report to the Money Laundering Reporting Office Switzerland (MROS) under the Anti‑Money Laundering Act. FINMA scrutinises both the substance of the breach and the speed and credibility of the institution’s response. Where criminal conduct is suspected, the OAG may also be relevant. Assess reporting obligations at intake, because the clock may already be running.
It depends on the gravity of the conduct, the strength of the evidence, the degree of foreign exposure and the privilege consequences. DOJ and SFO both offer cooperation credit for genuine, timely voluntary disclosure, but self‑reporting can require sharing sensitive material and must be structured to protect privilege and comply with Swiss secrecy, data protection and Article 271 SCC rules. Take the decision with counsel on the specific facts.
Costs range from roughly CHF 20,000–80,000 for smaller matters to CHF 100,000 or well over CHF 1,000,000 for large, multi‑jurisdictional financial‑institution investigations. The main drivers are data volume, the number of custodians and interviews, translation across Switzerland’s languages, and cross‑border coordination. Tight scoping and phased work are the most effective cost controls. Figures are indicative and not a quotation.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Conduct an Internal Investigation in Switzerland (2026): Step‑by‑step, Privilege & Cross‑border Guidance

Send welcome message

Custom Message