How to Write an Investigation Report
A structure for investigation reports that decision-makers can rely on: scope, method, evidence, findings on each allegation, and conclusions that follow from the evidence.
An investigation report has one job: to let a decision-maker who was not there understand what was alleged, what evidence was found, and what the investigator concluded on each point, and why. A good report is structured around the allegations or questions, separates evidence from conclusions, and shows its reasoning. Whether it is a workplace matter, a private investigation or an internal audit, the structure below works.
1. Summary
Half a page at most. The matter, who commissioned the report, the allegations or questions, and the finding on each in one line: "Allegation 1: upheld. Allegation 2: not upheld. Allegation 3: partly upheld." Many readers stop here, so it must stand alone and must not overstate the body.
2. Scope and terms of reference
What the investigator was asked to establish, and what was outside scope. Quote the terms of reference or attach them. If scope changed during the investigation, say when and why.
3. Method
- Who was interviewed, when, and whether they were accompanied
- Documents, messages, logs, footage or open-source material reviewed
- Anyone who declined to take part, or evidence that could not be obtained, and why
- The standard of proof applied, usually the balance of probabilities in workplace matters; check what applies to your context
4. Background
Only the context needed to understand the findings: roles, reporting lines, relevant policies, the timeline of key events. A short chronology table is often clearer than prose here.
5. Findings, allegation by allegation
This is the body of the report. For each allegation or question, use the same sub-structure:
- The allegation, stated exactly.
- The evidence: what each relevant source said or showed, with references to the appendix. Include evidence that points both ways.
- Analysis: where evidence conflicts, which you prefer and why. Consistency, contemporaneous records, corroboration and plausibility are legitimate reasons; "I found them more credible" alone is not.
- Finding: upheld, not upheld, or partly upheld, and on what basis.
6. Conclusions and, if asked, recommendations
Draw together the findings. Recommendations should only appear if the terms of reference ask for them, and should be clearly separated from findings. Investigators usually find facts; decision-makers decide consequences.
7. Appendices
Signed statements or interview notes, key documents, the chronology, and an evidence list with references. Each piece of evidence referred to in the body should be findable in the appendix by a reference number.
Writing rules that make it hold up
- Separate observation from inference. "The door log shows the badge was used at 22:14" is evidence; "so she was in the office" is inference, and should be labelled as one.
- Neutral language. "The complainant states" and "the respondent states", not "admitted" or "claimed".
- Dates and times in one format throughout.
- No new evidence in the conclusions. Everything relied on must appear in the findings.
- Deal with the other side's points. A report that ignores the respondent's explanation will not survive an appeal.
Before you issue it
Check every reference points to the right appendix item, every quotation matches the source, and the summary matches the findings. Record who received the report and when, and restrict access to those who need it. For the investigation that comes before the report, see a realistic timeline for a workplace investigation; for the statements it relies on, how to take a witness statement that holds up; and for online sources, OSINT notes for investigators.