scieee AI-readable full text Open interactive document viewer

The organisation as the cure for its own ailments: Corporate investigators in the Netherlands

Meerts, Clarissa Annemarie

Abstract

EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.

Full text

Meerts, Clarissa Annemarie Article The organisation as the cure for its own ailments: Corporate investigators in the Netherlands Administrative Sciences Provided in Cooperation with: MDPI – Multidisciplinary Digital Publishing Institute, Basel Suggested Citation: Meerts, Clarissa Annemarie (2018) : The organisation as the cure for its own ailments: Corporate investigators in the Netherlands, Administrative Sciences, ISSN 2076-3387, MDPI, Basel, Vol. 8, Iss. 3, pp. 1-15, https://doi.org/10.3390/admsci8030025 This Version is available at: https://hdl.handle.net/10419/239841 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/ administrative sciences Article The Organisation as the Cure for Its Own Ailments: Corporate Investigators in The Netherlands Clarissa Annemarie Meerts Faculty of Law, Criminal Law and Criminology, VU University Amsterdam, 1081 HV Amsterdam, The Netherlands; [email protected] Received: 7 March 2018; Accepted: 6 June 2018; Published: 27 June 2018   Abstract: Public/private relations in the field of security attract considerable academic attention. Usually, the state is central to the analysis, focusing on the diminishing role of a previously dominant state. The role that organisations themselves play in the investigation and settlement of their internal norm violations is, however, much less researched. An emphasis on the role of the state downplays the importance of such actions. This research paper, based on qualitative data from the Netherlands, highlights the role of the organisation as the principal actor in corporate investigations and corporate settlements. The legal constraints upon and day-to-day activities of corporate investigators are considered and the consequences of the distance between public law enforcement actors and corporate security are reflected upon. The paper arrives at the conclusion that the limited insight into the measures taken by organisations in response to internal norm violation can be considered problematic from a democratic, rule-of-law point of view. The freedom of action enjoyed by organisations within the private legal sphere makes oversight and control quite challenging. Keywords: corporate investigations; corporate settlements; internal norm violations; private justice 1. Introduction In a case of theft and fencing of company property, multiple reactions were chosen against the people involved. There have been two reports to the police and two civil actions. In addition, assets were seized through civil measures, settlement agreements were used for the repayment of damages, twelve employees lost their job and eight employees received an official warning. [Case study 11—Meerts 2018] It is not uncommon for instances of corporate and white-collar crime to be settled without the interference of criminal court (see for example Beckers 2017). Organisations tend to take their own measures—either with or without a criminal prosecution or settlement. These ‘corporate settlement measures’ are often based on corporate investigations, conducted by specialised investigators (Meerts 2018) . With corporate settlement measures are meant those “solutions to norm violations, which may be derived from public law (criminal law), private law (contract law, tort or labour regulations) or internal regulations (of specific organisations)” (Meerts 2018, p. 22). This definition of corporate settlement is quite broad and contains both measures that are completely internal to the organisation (such as the official warnings in the case cited above) and measures that are external to the organisation (such as the criminal cases against the two employees in the case cited above). Although the criminal case itself is not a corporate settlement measure—the decision whether or not to prosecute lies with the prosecution office, not with the organisation—the decision to officially report to law enforcement authorities is. Reporting to law enforcement authorities is one of the options available to an organisation faced with internal crime. The aim of this paper is to examine corporate security as an avenue of control exercised by organisations over their employees. The corporate security sector is under-researched: not much is Adm. Sci. 2018,8, 25; doi:10.3390/admsci8030025 www.mdpi.com/journal/admsci Adm. Sci. 2018,8, 25 2 of 15 known about the day-to-day activities of corporate investigators. This is an important gap in our knowledge, especially when we take into account the large and growing involvement of private parties in responding to undesirable behaviour (Walby and Lippert 2014). The paper thus aims to fill the gap in our empirical knowledge about corporate investigations, and to place this in the context of a recurring debate: that of public/private bifurcation (see Section 2for more on this). The corporate security sector is defined here as a highly specialised market for corporate investigation services. 1 Although corporate investigators may be involved in additional activities (such as pre-employment screenings and drafting and implementing integrity codes), the investigative activities of corporate investigators are the focal point of this paper. 2 Investigative activities are mainly constituted by forensic accountancy, (private) investigations more generally, IT investigations, asset tracing, and (assistance with) settlement and prevention tactics (Williams 2005;Meerts 2013). Clients of corporate security may be both commercial and (semi-)public organisations.3This last category of organisations is an important source of clients for corporate investigators: in the Netherlands, the 25 largest municipalities have, over the last five years, ordered the investigation of more than 1900 internal norm violations. 4 In this research the following groups are considered to be part of the corporate security sector: private investigation firms, in-house security departments, forensic accountants and forensic (departments of) legal firms.5 This paper considers the role of corporate investigations in the identification and settlement of internal norm violations within organisations. The fact that the norm violation is internal to the organisation is important, since it provides the organisation with more possibilities to act upon the behaviour than when there is only external involvement. ‘Norm violation’ is a broad-scope concept, which may be used for all types of employee behaviour deemed problematic by an organisation. This ‘problematic behaviour’ may concern (alleged) criminal behaviour such as fraud, but it may just as well be about behaviour that is considered undesirable from the point of view of owners and managers of organisations, for example behaviour that is non-compliant to internal regulations (Richards 2008). All kinds of undesirable behaviour may be investigated by corporate investigators (see also below); however, many incidents that are investigated by corporate investigators have an economic background (theft, fraud, favouritism in the granting of contracts, and the like) (Williams 2006a).6 As a result of the employment relationship between the organisation and the person who is the subject of investigation, corporate investigators have extensive access to information. Although corporate security actors do not possess the formal powers of investigation enjoyed by law enforcement, their possibilities of investigation are extensive: through the (property) rights of the organisation as an employer, they are able to use much information about employees (for example by accessing internal systems). Additionally, the professional backgrounds of corporate investigators makes them adept in investigating open source data and in using investigative tactics (such as interviewing involved persons 7 ). After investigations are concluded, corporate investigators may assist organisations 1 Corporate security is a term that is often used in a much wider sense. In such a definition, all security-related activities of (mostly) in-house security are within the scope. Investigations are then part of corporate security but so are surveillance and other activities relating to physical security. In this paper, the focus is on investigations. 2 Corporate investigators may also be involved in compliance functions. Although compliance may involve investigations, the main aim of compliance is prevention: measures and procedures are put in place to ensure compliance to rules. Corporate investigations, by contrast, focus on the situation in which prevention has failed and norm violations have occurred. 3 In the case of an in-house corporate security department, the ‘client’ and investigator are part of the same organisation: for example the organisation’s management. 4 See NRC 28-02-2018 (https://www.nrc.nl/nieuws/2018/02/28/meer-onderzoek-naar-integriteit-door-gemeentena1594055). 5 Forensic accountants and forensic legal investigators (lawyers) differ from regular accountants and lawyers with regard to their main activity. Regular accountants audit the financial administration of an organisation as part of their legally defined task, and regular lawyers are hired to represent their client in legal procedures. Forensic accountants and forensic legal investigators, by contrast, are hired to investigate as a result of a suspicion of a norm violation. 6 This is not to say that corporate investigations are only conducted with regard to matters of economic crime. Other categories of behaviour which are often investigated internally include, for example, privacy violations and data leaks. 7 An ‘involved person’ or ‘subject’ is what in the context of a criminal justice procedure would be called a ‘suspect’. However, because corporate investigators lack formal powers of investigation and the formal procedural guarantees available in Adm. Sci. 2018,8, 25 3 of 15 in finding a solution, either by ‘going public’ (reporting to law enforcement) or ‘staying private’ (for example settling the incident as a labour dispute). One of the characteristics of corporate investigations and ‘corporate justice’ is the emphasis on confidentiality. This, together with the view held by organisations and corporate investigators that the criminal justice system is inefficient and in most cases will not provide a suitable solution, means that most white-collar crimes that have been investigated by corporate investigators never reach the criminal justice system. It follows that the knowledge of the state about such internal investigations is fairly limited. The above considerations culminate in the following research question: What is the role of corporate investigators in the investigation and settlement of norm violations within organisations? To answer this question, we need to examine (1) the legal frameworks within which corporate investigators operate (sub-question 1), (2) the investigative methods corporate investigators may use (sub-question 2) and (3) the settlements that are possible as a response to the corporate investigations (sub-question 3). These questions are answered with the help of empirical material collected in the context of this research. The theoretical framework that provides the context for the discussion of the empirical findings is discussed in the next section of this paper. This is followed by the explication of the research methods that have been used to collect data. Section 4examines the legal frameworks within which corporate security actors operate (sub-question 1), followed by Sections 5and 6, which discuss the activities of organisations and corporate investigators in this context (sub-question 2 and 3). The paper is concluded by a discussion of some ethical issues and governance limitations of current practices in corporate security. It is concluded that the market for corporate investigations can be seen in the framework of a private/public demarcation: corporate investigators operate quite independently from the criminal justice system. While this situation has its advantages, it is argued that from a democratic, rule-of-law point of view it may be considered problematic. 2. The Theoretical Framework—Public/Private or Private/Public? Traditionally, governments are tasked with the prevention and repression of crime (Van de Bunt and van Swaaningen 2005). The monopoly over legitimate use of force is commonly seen as the essential tool for governance by states (Weber 1946). 8 However, it is now widely recognised that from a historical perspective this situation is rather new (Garland 2001). This realisation has gained much academic attention under the banner of the shift from ‘government’ to ‘governance’ (see for example Lea and Stenson 2007). State actors, private actors and non-governmental organisations are now commonly seen as governing (global) society (see for example Willetts 2011). When it comes to the governance of criminal behaviour, however, the scientific community still seems mostly concerned with state action against crime (Hoogenboom 2007). Over the years, a wide range of publications has emerged, focusing on regulatory agencies (see for example Mascini and van Erp 2014), civilians (see for example Van Steden 2009) and private security professionals (see for example South 1988). Security provision is no longer seen as being the sole responsibility of law enforcement agencies: even within the context of the state, regulatory agencies, special investigative units within ministries and the input of local government are all seen as contributing to the provision of security (Van de Bunt and van Swaaningen 2005). Academic attention for the contribution of private actors usually does not focus on the investigation of norm violations by the organisation within which the norm violation occurred. Rather, the preventative function of private security is researched. In this context, public/private relationships a criminal justice procedure are not present in corporate investigations and settlements, criminal justice terminology is avoided here (see also Meerts 2018). 8With this is meant not just the actual use of force but police powers in general. Adm. Sci. 2018,8, 25 4 of 15 are often conceptualised along the lines of a private sector complementing a dominant state. 9 In this line of reasoning, concepts such as privatisation and responsibilisation are used to indicate that the state involves private parties, either by privatising some of its activities, or by mobilising private actors to get involved in the provision of security (Garland 2001). Relations between the public sector and private security are, then, mostly conceptualised in the context of private parties’ utility within the state agenda through cooperation (Hoogenboom and Muller 2002;Hoogenboom 2009;Dorn and Levi 2009; Cools et al. 2010). A popular theory in this line of reasoning is the junior partner thesis, first introduced by Kakalik and Wildhorn. According to this theory, public actors may use private security actors as a junior partner to advance the goals of the state (Hoogenboom 1988). In this view, private actors fill the void that was created by the inability of law enforcement actors to meet security demands. Private actors are considered to be complementary to public actors and to focus on preventative action. An alternative perspective on public/private relations in this field may be derived from the work of James Williams, who sees the corporate investigations market as a commodification of internal norm violations, through the marketing of a professional service which is directly responsive to organisations’ needs (Williams 2005; see also Meerts 2016). Corporate investigators provide organisations with the means to investigate and settle a norm violation without involving public law enforcement (Meerts 2018) . Instead of thinking in terms of public/private relations, with private security serving as a subsidiary to the state, we should, therefore, take the private sector as our point of departure. This research takes this last approach: the activities of corporate investigators are examined as an independent professional activity, not as a subsidiary of the state. Such an approach sensitises us to the context in which corporate investigators work and opens up a field of research, in which corporate investigations and settlements are considered as distinct and separated from criminal justice investigations and solutions. Insofar as it becomes necessary to bring the state back into the analysis, this may invoke what Dorn and Levi (2009) once referred to as private/public relations, reflecting the leading role of providers of private justice. The empirical data is considered along the lines of the private/public model, in which the state is seen as a supplement to the efforts of the private sector, instead of the other way around (such as is the case in junior partner theory). This does not imply a normative judgement at the onset, either in favour or critical of the corporate security market—although the need for such judgement may present itself once such analysis is done. 3. Methodology The research question posed in the introduction of this paper is answered based on qualitative data gathered between October 2012 and March 2016. 10 The main source of information for the research consists of 59 semi-structured interviews that have been conducted among corporate investigators, clients and law enforcement professionals. This type of interview can be defined as an expert interview (Baarda et al. 1996). One advantage of an expert interview is that respondents are generally well-informed and, as a result, the interview should provide rich information. Additionally, the interview process may be more efficient. A challenge might be that experts, and especially those in management and higher positions, are often pressed for time and difficult to reach because they are shielded by administrative staff. However, the use of gatekeepers mitigated these issues in this research. Respondents were approached through gatekeepers and snowball sampling, making use of previous contacts and previous research by the author. For each group of respondents, a slightly modified topic list was used, so as to take full advantage of the knowledge of the respondent. However, to ensure that the research question and sub-questions can be answered, the following topics were part of every interview: professional background of the respondent; types of cases in which corporate investigators are involved; reasons for corporate investigations/settlements; process 9 This can also be discerned in the literature on the compliance functions of corporate security (see for example Verhage 2015). 10 This research was funded by a NWO (Netherlands Organisation for Scientific Research) Research talent grant. Adm. Sci. 2018,8, 25 5 of 15 of the investigations; process of settlements; regulation; public/private relations; and general opinion regarding the existence of corporate security. At the conclusion of each interview the question was posed whether the respondent felt any important subject had been neglected and whether he or she had suggestions for prospective respondents. The purpose of this is to minimise the possibility that important subjects and respondents are ignored. Interviews had an average duration of one hour and eleven minutes, with outliers of 23 min (the shortest interview) and two hours and fifteen minutes (the longest interview). All interviews were conducted face-to-face. The majority of the interviews was with a single person, however, four were conducted with two respondents at a time. When possible, the interviews were recorded to be transcribed verbatim at a later point in time. Some respondents did not consent to being tape-recorded, in these cases extensive notes were taken. The minority of respondents in this research was female (10), the rest were male (49). Most respondents fall into the age group 40 to 60 years old and have substantial (more than 5 years) work experience in the field of financial crime (this is not the case for the clients, who have, however, substantial work experience with regard to corporate settlements). Most of the professional activities of respondents were conducted in the Randstad, which consists of the four largest Dutch cities (Amsterdam, Rotterdam, The Hague and Utrecht) and their surrounding areas. The activities are not limited to this geographical space, though, as respondents execute their work all over the Netherlands (and abroad). Respondents had a high average education level (academic education), with the exception of police respondents, who generally had a lower education level (being trained within the police organisation itself). Table 1provides an overview of the respondents of this research. Respondents are found among three main groups of professionals: corporate investigators (33), law enforcement professionals (16), and clients (10). Within these groups we can further differentiate. Within the group of corporate investigators, ten respondents work for private investigation firms, eighteen for an in-house security department, five for a forensic accounting department and three for a forensic (department of a) legal firm. As can be derived from Table 1, the forensic legal investigators had a double role, as respondents were investigators in some cases and clients in other cases. 11 The corporate investigators who have been respondents for this research were employed within 22 different organisations. The law enforcement professionals who participated in this research worked for the police (eight), the prosecution office (five) and the investigative department of the Dutch revenue authority, FIOD (three). All law enforcement respondents had a background in financial crime. Clients, finally, were HR personnel (one), labour lawyers within the organisation (four), external lawyers (three) or general management (two). All clients interviewed in this research were employed by a different organisation (ten). These numbers show that respondent groups are not represented to the same extent in this research. The decision was made to focus on corporate investigators for two reasons. First, this group is most important for the research question since the activities of corporate investigators are central to it. Secondly, the wide variety of backgrounds among corporate investigators made it necessary to include more corporate investigators in the research than other respondents. 11 These respondents were approached and interviewed as clients. For this reason, they are counted in this category (which is why the numbers of investigators do not add up to 33). The fact that these respondents switched between the roles of investigator and client in different cases has provided useful insights to this research. At the time of interviewing, the Dutch corporate security sector did not contain many legal investigators, which is why so few legal investigators have been interviewed. Only during the research did this group emerge from the other interviews. Adm. Sci. 2018,8, 25 6 of 15 Table 1. Overview of interviews. Number of interviews 59 Average duration interviews 1 h 11 min Gender Number of people Number of organisations Male Female Corporate investigators 33 22 31 2 Private security firms 10 7 8 2 In-house security 18 12 18 0 Forensic accountants 5 3 5 0 Legal investigators 3 * 3 * 3 0 Law enforcement professionals 16 10 i11 5 Police 8 6 7 1 Prosecution 5 3 1 4 FIOD 3 1 3 0 Clients 10 10 7 3 HR, labour lawyers, management 7 7 4 3 Clients/legal investigators 3 * 3 * 3 0 * These are the same respondents/organisations. They are only ‘counted’ in this table as clients; i There were three law enforcement organisations involved in this research (police, the prosecution office and FIOD), but respondents were part of 10 different parts of these organisations. Respondents indicate that corporate investigators are used to investigate a wide variety of norm violations (both criminal and non-criminal). Many of these have a financial component such as fraud, theft, corruption or embezzlement. 12 Corporate investigators are, however, also enlisted to investigate norm violations that provide no direct financial gain, such as data leakage, breach of privacy, breach of trust, sexual harassment and unauthorised ancillary activities. The norm violations that are investigated by corporate investigators range from small (petty theft or the leakage of minor information) to substantial (millions of euros in fraud). The corporate investigators included in this research work for a wide variety of clients. In addition to (semi-)public organisations (including charities, municipalities and schools), clients may be active in all economic sectors (for example: the financial sector, telecommunications or logistics). Respondents do indicate, however, that most of their clients are medium to large-scale organisations, which respondents attribute to the costs of investigations. All data 13 gathered are treated with utmost confidentiality and have been anonymised to ensure that no information can be traced back to any respondent or his or her employer. No parts of this research were covert and informed consent has been attained at every step (Laenen and O’Gorman 2016) . The paper should not be regarded as generalising to the Netherlands as a whole; the statements made are indicative of the respondents in the research (who, however, do suggest that their statements are more generally applicable). 4. Legal Frameworks and Supervision over the Corporate Security Sector To gain insight into the corporate investigations industry, it is important to start with an examination of the legal frameworks within which the market operates, as specified in sub-question 1 of this research. Respondents indicate that the state has very little insight into what happens in the corporate security sector. One of the reasons for this is the highly fragmented nature of the sector. Multiple actors, all with their own regulations and processes of control, combine to form a ‘corporate security sector’ which is used by organisations to react to norm violations. The most prominent of these 12 For interesting work on corruption and corruption studies, see inter alia Pertiwi (2018) and Gorsira et al. (2018). 13 This research was part of a larger project, in the context of which the additional research methods of observation and the use of case studies were used. Because the information gathered through these methods is not used in this paper, they are not explicated here. However, information about the observations and case studies can be found in (Meerts 2018). Adm. Sci. 2018,8, 25 7 of 15 are private investigation firms, in-house security departments, forensic accountants and, added most recently, investigative (departments within) legal firms. The various investigators use the conceptual differences between them as a commercial advantage over other investigators. You know, an investigation has different dimensions, you have a financial part, a technical part, an operational part. And sometimes you need one type of investigator because he is better at that particular part than others because of his background and experience. [Respondent 13—corporate investigator] This quote of respondent 13 shows that certain investigators are better equipped to investigate a specific matter than others. An in-house investigator may for example be a good choice when complicated internal processes within an organisation are involved, since the in-house investigator knows the organisation. On the other hand, when it is deemed important that an independent party investigates the matter, external investigators may be more suitable. In complicated financial cases a forensic accountant will be the obvious choice. When multiple (international) jurisdictions are involved, a legal investigator with extensive legal knowledge might be chosen. There is, however, a tendency in the market to diversify the background of staff. In this way, corporate investigators may make use of multiple specialisms, according to the specific demands of the case at hand. Most corporate investigation units are, therefore, a mixture of professional backgrounds. Seen in this light, the fragmentation of legal frameworks regulating corporate investigative activities might become somewhat problematic. The legal framework that applies is dependent on the label an investigator wears. Some regulation applies to all: no corporate investigator is allowed to break the (criminal) law during his investigations and all have to take the Data Protection Act) 14 into account. As there are no private formal powers of investigation, the Code of Criminal Procedure, regulating the use of powers of investigation by law enforcement agencies, does not apply. This limits investigative possibilities (corporate investigators may not, for example, enter premises without explicit consent) but it also creates opportunities and flexibility. Within the limits of what is proscribed by law, corporate investigators have considerable room of manoeuvre. The legal framework that is applicable is dependent on the type of investigator. Of the four groups—in-house investigation departments, private investigation firms, forensic accountants and forensic (departments within) legal firms—only private investigation firms need a permit under the law regulating private security and private investigation firms (Wpbr). The control over this permit is located with the police but this is now a purely administrative process (Klerks 2008). As a result of this law, private investigation firms need to implement a Privacy Code of Conduct similar to the one issued by the representative organisation for the Dutch security market (NVb) and declared binding by law to all private investigation firms. The Privacy Code of Conduct provides the most specific regulation for investigative activities. Although forensic accountants and legal investigators are regulated by a general legal framework, these laws are not constructed to deal with investigative activities—rather, they are focused on traditional accounting activities and the traditional role of the lawyer. Both these professional groups do have disciplinary proceedings and in the case of forensic accountants, these disciplinary proceedings are specific to investigative activities (Meerts 2018). For accountants, some general guidelines for person-oriented investigation have been issued, and although these may be used in disciplinary proceedings, they are guidelines and as such not legally binding (NIVRA/NOvAA 2010). When it comes to in-house investigators, these professionals only have the internal guidelines of their company to follow (in addition to the generally applicable laws on criminal behavior and dada protection, as cited above). 14 Per 25 May 2018 the Dutch Data Protection Act (WBP) is replaced by the European General Data Protection Regulation. The effects of this change on the legal requirements for data protection on the corporate security sector are, as of yet, not entirely clear. Adm. Sci. 2018,8, 25 8 of 15 In spite of the differences in legal frameworks, fieldwork does suggest that all groups tend to adhere to the Privacy Code of Conduct for private investigation firms. In the case of forensic accountants, the guidelines for person-oriented investigation specifically refer to the Privacy Code of Conduct to be used as a guideline by forensic accountants (NIVRA/NOvAA 2010). Respondents indicate that they are focused on legal principles, such as proportionality and subsidiarity—principles that are central to the abovementioned guidelines as well. However, as this is largely on a voluntary basis, compliance is not guaranteed. The diversification in the corporate investigations arena and in legal frameworks and control create a fragmented field in which the state has very little knowledge about actual activities. Democratic control over the corporate security sector is very limited. Control over corporate investigations is, for an important part, reliant on the ethics of individual investigators and on the client. This places much responsibility on organisations using the services of corporate investigators (Meerts 2018). 5. Corporate Investigations For an important part, the influence of the organisation is exerted at the start of the investigative process and at its conclusion (by deciding on a settlement), and much less during the investigations. Investigations commonly start with an assignment letter by the organisation that is faced with the norm violation. 15 The client organisation can assert much control over the investigations by framing the assignment in a certain way. Although corporate investigators endeavour to be independent and objective, they are reliant in a large degree on their clients. Partly, this is created by the fact that the investigative possibilities of corporate investigators rely heavily on the rights an organisation has to exert control over its employees (Schaap 2008). Through the employers’ (property) rights in relation to, for example, employees’ work computers, corporate investigators have access to the information stored on these devices. The way in which the assignment is framed determines the scope of the investigations. Respondents indicate that they are aware of the possibility that their investigations could be used for improper purposes and they try to avoid such situations. However, this is not always easy to determine in practice. Imagine that a CEO comes to you and says, ‘look I have Mr. Jones here and he’s in his late fifties, rather expensive, we would like to get rid of him but firing him would be expensive so could you have a look at his expense account and see whether you can’t find something or other’. Well, no, sorry, we don’t do that. [But] it’s not always that straightforward because if the same person contacts us, saying ‘we think that Mr. Jones is fiddling with expense accounts for this or that reason ...’ The story is the same, it’s just told differently. So it’s not always possible to know exactly but you have to try. That’s why an intake [conversation between client and investigator about the case] is so important, to get an impression of the context of the case, what kinds of signals are there, how were they discovered, is it specific enough to warrant investigation? [Respondent 2—corporate investigator] The possibility to have a measure of control over the investigations and over the information that might flow to the public realm is one of the reasons for organisations to enlist the services of corporate investigators (Williams 2005). This means corporate investigators have to find a balance between the interests of clients and their own objectivity and independent position. One way in which corporate investigators try to prevent organisations from unduly influencing the investigations is to 15 In the case of an in-house investigations department, the report of the norm violation is usually enough—the assignment is implied here in the mission statement of the in-house department. In case of in-house departments, the alleged norm violation may also be reported directly to this in-house department by concerned employees or through whistle-blower arrangements (for the latter, see (Loyens and Vandekerckhove 2018). Adm. Sci. 2018,8, 25 15 of 15 Meerts, Clarissa Annemarie. 2016. A world apart? Private investigations in the corporate sector. Erasmus Law Review 9: 162–76. [CrossRef] Meerts, Clarissa Annemarie. 2018. The Semi-Autonomous World of Corporate Investigators. Modus Vivendi, Legality and Control. Rotterdam: Erasmus Universiteit Rotterdam. NIVRA/NOvAA. 2010. NBA-Handreiking 1112. Praktijkhandleiding Persoonsgerichte Onderzoeken voor AccountantsAdministratieconsulenten/Registeraccountants. Amsterdam: Koninklijke Nederlandse Beroepsorganisatie voor Accountants. Pertiwi, Kanti. 2018. Contextualizing Corruption: A Cross-Disciplinary Approach to Studying Corruption in Organizations. Administrative Sciences 8: 12. [CrossRef] Richards, James. 2008. The many approaches to organisational misbehaviour: A review, map and research agenda. Employee Relations 30: 653–78. [CrossRef] Schaap, Cees D. 2008. De Private Forensisch Fraudedeskundige. Een Feitelijke en Juridische Positionering. Nijmegen: Wolf Legal Publishers. South, Nigel. 1988. Policing for Profit: The Private Security Sector. London: Sage. Van de Bunt, Henk G., and Renévan Swaaningen. 2005. Privatisering van de veiligheidszorg. In Privatisering van Veiligheid. Edited by Laurens C. Winkel, Sjaak Jansen, Hendrik O. Kerkmeester, Rob J. P. Kottenhagen and Vincent Mul. Den Haag: Boom Juridische Uitgevers, pp. 5–19. Van de Bunt, Henk G., Judith G. van Erp, Roland J. J. Eshuis, Nina L. Holvast, and Thy Pham. 2013. Bestuurdersaansprakelijkheid in de praktijk. Motieven voor het intern aansprakelijk stellen van bestuurders. In Capita Civilologie. Edited by Willem H. van Boom, Ivo Giesen and Albert J. Verheij. Den Haag: Boom Juridische Uitgevers, pp. 907–28. Van Steden, Ronald. 2009. Burgerparticipatie in lokale veiligheidsnetwerken: Over ‘nodale sturing’ en ‘verankerd pluralisme’. Justitiële Verkenningen 35: 29–42. Van Rooij, Benjamin, and Fine Adam. 2018. Toxic Corporate Culture: Assessing Organizational Processes of Deviancy. Administrative Sciences 8. (Forthcoming). [CrossRef] Verhage, Antoinette. 2015. Global governance = global compliance? The uneven playing field in ant-money laundering. In The Routledge Handbook of White-Collar and Corporate Crime in Europe. Edited by Judith G. Van Erp, Wim Huisman and Gundrun vande Walle. Abingdon: Routledge, pp. 471–85. Walby, Kevin, and Randy Lippert, eds. 2014. Corporate Security in the 21st Century: Theory and Practice in International Perspective. Basingstoke: Palgrave Macmillan. Weber, Max. 1946. Politics as a Vocation. In From Max Weber: Essays in Sociology. Edited by Hans H. Gerth and Charles Wright Mills. New York: Oxford University Press, pp. 77–128. White, Adam. 2014. Beyond the regulatory gaze? Corporate security, (in) visibility, and the modern state. In Corporate Security in the 21st Century. Theory and Practice in International Perspective. Edited by Kevin Walby and Randy Lippert. Basingstoke: Palgrave Macmillan, pp. 39–55. Willetts, Peter. 2011. Non-Governmental Organizations in World Politics. The Construction of Global Governance. Abingdon: Routledge. Williams, James W. 2005. Reflections on the private versus public policing of economic crime. British Journal of Criminology 45: 316–39. [CrossRef] Williams, James W. 2006a. Private legal orders: Professional markets and the commodification of financial governance. Social and Legal Studies 15: 209–35. [CrossRef] Williams, James W. 2006b. Governability matters: The private policing of economic crime and the challenge of democratic governance. Policing and Society 15: 187–211. [CrossRef] Williams, James W. 2014. The Private Eyes of Corporate Culture: The Forensic Accounting and Corporate Investigation Industry and the Production of Corporate Financial Security. In Corporate Security in the 21st Century. Theory and Practice in International Perspective. Edited by Kevin Walby and Randy Lippert. Basingstoke: Palgrave Macmillan, pp. 56–77. © 2018 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).