North Point's Thesis on Corporate Investigations

Pamela Harght • September 4, 2026

The Insider-Threat Moment

Occupational fraud—asset misappropriation, corruption, and financial-statement fraud—is on the rise, and rising at a dangerous moment. Distributed work has thinned the controls that once caught it. The AI tools meant to break down silos and speed up work also hand employees far more access than they need. The dark web and social media let outsiders recruit, phish, and co-opt staff, and let insiders quietly sell stolen IP and credentials. Cryptocurrency makes the proceeds easy to move and hard to trace. And insider crime tends to climb in hard times: workers squeezed by debt and rising costs, and emboldened by a mood of anti-corporate grievance, are quicker to rationalize taking from an employer they have come to resent.


All of this points to one conclusion: we are very likely entering a period of more severe occupational fraud and insider threat, not less. There are certainly controls and predictive measures that should be put in place, but they're only as good as the imagination and bandwidth of the people maintaining them. General Counsel, HR, or whoever is nominally responsible will find themselves overwhelmed with potential incidents—especially in situations of asymmetric risk, where an investor bears exposure without full visibility or control.


Investigations That Recover Shareholder Value

A company's value takes four forms: its reputation, its capital, its assets, and its ideas. Each has an obvious guardian. Communications watches reputation, finance watches capital, security and operations watch assets, legal and IT watch IP. While each guardian is trained to see the harm that lands in their column the trouble is that harm rarely lands in one column. Almost every real issue moves across two or three values at once, and for a GP, an LP, or an operating executive, all of them settle into the same number: the multiple you exit at.


  • Inventory shrinkage looks like an assets problem until the falsified records that hid it make it a books-and-records problem too.
  • A padded expense report looks like a rounding error until you notice the same executive approves their own reimbursements — now you have a people and compliance problem.
  • A top salesperson leaving with their client list looks like an ideas problem until the accounts follow them out the door and it becomes lost recurring revenue, the exact line a buyer underwrites.
  • An executive's quiet stake in a vendor looks like an ethics question until you price the inflated invoices and it becomes a related-party transaction that stalls the deal.


In each case the presenting issue is the tip of something larger, and the rest of it — the control that failed, the revenue that walks, the liability that must be disclosed — doesn't go away because no one looked. It surfaces in diligence instead, on someone else's terms. The point of investigating from every facet is to find the second- and third-order effects before the people underwriting the company do.


What an Investigation Is, and How it Works

What is a corporate investigation, and how does one actually work? At its simplest, an investigation is the disciplined effort to establish what happened, why it happened, and — above all — what it means for the business, turning a scattered set of signals into a picture clear enough to act on. It rarely begins with a tidy assignment. More often it starts the moment someone notices something is wrong and doesn't yet know how big it is.



What Triggers an Investigation

An investigation is set in motion by a change in the company's own circumstances, by an acute incident, or often by both at once. Some come from outside the business — a shift in who owns or runs it or an auditor’s question:


  • A leadership or ownership transition — a new CEO, board, investor, or insurer who wants a prior chapter properly closed before they take on the risk.
  • An acquisition or diligence process that surfaces an unresolved issue which, absent explanation and context, could move the deal, the price, or the terms.
  • A regulator or law-enforcement inquiry that touches on something the company handled internally and now has to demonstrate to an outside party.
  • An auditor's question — an internal or external audit surfaces a transaction, estimate, or control that doesn't reconcile, and the finding has to be run to ground before the books can be signed off.


Others come from within — a specific signal that something may be wrong right now:


  • A padded expense report that could be simple carelessness or the visible edge of a scheme, depending on who approved it and what they were saying while they did.
  • A procurement kickback that surfaces as nothing more than an odd vendor in the ledger, with the conflict that explains it scattered across email, entity records, and the org chart.
  • Suspected IP theft by an employee whose access was authorized, where the download logs look clean and the only real question is purpose.
  • A handoff of responsibility — a departing employee's accounts pass to a successor, who discovers a problem was ongoing all along.
  • The grey-area case, the most siloed of all — an employee whose conduct shifts in ways no one can quite name: talking differently, performing differently, maybe a substance question, maybe something else. Not enough to launch a full investigation, too much to ignore. The signals are real but scattered — after-hours badge swipes with security, slipping reviews with HR, a tone shift in comms — and only when laid against each other does the pattern resolve into something you can act on or rule out.


How to Run an Investigation

Investigations tend to fall into three broad buckets, though a single matter often reveals overlap among them:


  • Theft — removing value from the company: embezzlement, expense-reimbursement fraud, theft of physical assets, IP and trade-secret theft, diversion, and the like.
  • Malfeasance — violating corporate policy or legal obligations: conflicts of interest and undisclosed outside interests, bribery and corruption, misuse of material non-public information, regulatory and compliance violations, and falsification of records, credentials, or data.
  • Reputational or erratic conduct — the grey area: off-duty conduct and public statements, fitness-for-duty questions around erratic workplace behavior and substance issues, and problematic associations or affiliations.


Any of the three may call for a workflow drawing on the sources and methods below. The art is in knowing which will matter — you will never have the time or budget to examine every data point — and how to collect and analyze them efficiently.


  • Computer data (the subject's devices and accounts) — usually the richest source, and most of it can be pulled from corporate accounts and managed devices without tipping the subject off. Coordinate with IT and security on preservation before any collection. Email, chat (Slack/Teams), call records, calendar, browser history, AI tool usage and prompts, device and cloud file storage, and removable media.
  • Financial records (from the company) — where most theft, kickback, and expense schemes are both committed and proven. Vendor lists, payment records, expenses, and subscriptions.HR records (from the company) — context and motive. Performance pressure, recent discipline, or a quiet record change often lines up with the timeline. Disciplinary history, performance issues, and record changes (new address, marital status, direct deposit, beneficiaries).
  • Security and facilities data (from the company) — physical-world corroboration for the digital timeline. Badge and access logs, CCTV footage, and inventory logs.
  • Interviews — usually last, once the documentary record is built. Sequence fact witnesses before the subject, and coordinate with counsel and HR on scope and any required warnings.
  • Public records and OSINT — external signal the company can't see from the inside. Living beyond one's means, or visible financial distress, is the single most common outside indicator of internal fraud. Entity formation, litigation and criminal records, social media, and assets and liabilities all help explain the individual and add facts about vendors or counterparties: to whom a payment is going, and why.


Running through all of this are a few cross-cutting disciplines. Every source feed one timeline, because sequence is usually what turns isolated facts into a pattern. Anomalies only mean something against a baseline, so the work begins by establishing what normal looks like before chasing what departs from it. And because any matter can end in a termination, a regulatory referral, or litigation, the investigation is built and documented from the first day to withstand that scrutiny — all of it within the privacy rules and local jurisdictional limits that govern what can be collected, from whom, and how.



What We've Built Here at North Point

Corporate investigations is not one profession but a dozen, each examining the same problem from different perspectives. White-collar defense lawyers see fraud and government exposure. Labor and employment specialists see harassment, discrimination, and wage claims. Compliance and ethics teams see  control that should have caught it. Forensic accountants see the ledger; cybersecurity analysts see the network; the emerging insider-threat discipline sees the human being at the intersection of all of them. Each is excellent within its lane. But harm does not stay in a lane, and a firm that investigates through a single lens will likely mistake the part it can see for the whole.


North Point is built for the space between those disciplines. An ethics complaint about an executive's expenses becomes a securities-disclosure question the moment the numbers are material. A terminated engineer is at once an intellectual-property matter, a cyber matter, and an employment one. The discipline that first notices a problem is rarely the one that can explain it — not because any of them lack skill, but because no single vantage point was ever going to see the whole shape of the harm. North Point's thesis is that anything which deprives a company of value — its reputation, its capital, its assets, or its ideas — must be investigated from every facet at once, because the purpose of an investigation is not to confirm the problem you were handed but to find the one you weren't.


Insider incidents need to be addressed the moment they happen, at scale, without the cost of a big law firm (until an investigation determines they are needed) or the burden of an overstretched in-house team. That is what we built: a multidisciplinary quick-reaction force that moves in early, works every facet of the problem at once, and delivers findings clear enough, and defensible enough, to act on.


About the Author

Naphtali Rivkin is a Managing Director and Head of Investigations at North Point Associates. Over a career spanning the public and private sectors, he has built a reputation for tracing assets, investigating people, and uncovering intelligence across the globe.


Naphtali brings a distinct educational and professional background to North Point beginning his career as a United States Army Intelligence officer and US Government intelligence analyst before transition to the private sector with the following degrees:

BA in Russian Area Studies and English from Washington and Lee University

M.Phil. in International Relations from the University of Cambridge (Clare College)

Fulbright Scholar in Latvia


Naphtali holds the Professional Certified Investigator (PCI) designation from ASIS International, is a licensed private investigator, and was a 2024 Consulting Magazine Rising Star for Excellence in Client Services. 

Financial documents and records symbolizing the paper trail behind asset tracing investigations.
By Naphtali Rivkin August 18, 2026
North Point does not think asset tracing is a last resort and that most value lies before a case is even filed, to answer whether a claim is worth bringing, whom to name, and where to sue.
By Naphtali Rivkin July 21, 2026
North Point welcomed Naphtali Rivkin back to our team in May of this year as a Managing Director and Head of Investigations. As we build out our investigations practice, we will be writing short pieces to help both new and longtime clients understand what this means. For this post, we asked Napthali a few quick questions on what an investigation actually is, what makes our approach different, and why he is doing this work.
Ferson stepped outside his comfort zone to listen and learn from fellow Americans.
By Sophie Renzi July 7, 2026
An open and candid interview with author and CEO of Liberty Square Group about his desire to write a book after an 8 year road tour listening to fellow Americans.
By Pamela Harght June 1, 2026
Media Release: May 30, 2026
By Jon Muñoz May 4, 2026
How is AI changing due diligence? North Point explores the Shy Girl controversy and what it means for fraud prevention, business research and the gray area of AI.
 Brown University, a landmark Ivy League research university located in Providence, RI
By Chloe Woodbine March 19, 2026
Our role as researchers is to not only confirm that a candidate worked somewhere or earned a particular credential but to provide color and context on who this individual is.
Dublin, Ireland-September 23, 2025; The Long Room Library of Trinity College Dublin or Old Library w
By Isaac Garcia-Dale February 17, 2026
Since 1996, the Internet Archive has worked with libraries and partners around the world to build a shared digital library of humanity’s online history.
Composite photo collage of hands holding resumes
By Haley Rist December 9, 2025
Executive due diligence isn’t just about numbers, it’s about people. We are constantly calculating whether we can rely on the people around us.
Solving a Rubik's Cube
By Ross Elwyn November 3, 2025
The Rubik's Cube is a great metaphor for due diligence research we follow every day as we research people and entities to make sense of their presence in the world.
By Isaac Garcia-Dale July 22, 2025
Riding with Team Daisy