Same Problem, Different Language: How Investigative Skills Translate to Tech Risk

I remember when I started at a tech company, a colleague sent me a list of past incident reports to read and said, "Welcome to tech. There are a lot of random incidents that pop up out of nowhere affecting our workflow, and sometimes we are left wondering why nobody saw this coming."
I laughed at first, but as I read through those incidents, I realised they looked familiar. Each included what happened, the causal factors, the issue's impact, how long it lasted, and what signs could have been noticed to spot it earlier. Though the terms had changed, the underlying problem remained the same.
As internal auditors, we often face a similar challenge. Whether reviewing control failures, or emerging risks, we are frequently required to piece together incomplete information to understand what happened and why.
This recognition led me to see how investigative skills bridge industries. Just as unexpected risks emerge everywhere, the way investigators think - diagnosing issues and using evidence to solve them - can unlock solutions beyond traditional boundaries. These methods are not just for traditional investigations. They also provide a useful framework for addressing tech incidents, highlighting the overlap between the disciplines.
Same Core Problem
Investigative skills are foundational because they provide a structured way to separate knowns from unknowns and clarify next steps before acting. This measured approach is critical in tech risk management, where acting too quickly can increase the likelihood of error. The discipline of investigation helps prevent premature conclusions and supports effective, evidence-based decision-making under pressure.
The concept is simple: do not make decisions until you have the information you need. Even though the language may differ, this principle applies just as readily to tech incidents. Most importantly, it requires adherence to a process.
Facts vs Assumptions
As investigators, we know the difference between an observation and an inference. An observation is a fact, while an inference is hypothesis or educated assumption. Both have their place, but it is important to distinguish between them.
Overlooked details in high-stress situations can create future risk. Even if a team appears to have resolved a problem, failure to identify the underlying cause may allow it to resurface. Risk management should be approached like an investigation: distinguish facts from assumptions, resist the urge to jump to conclusions, document the rationale behind decisions, and ensure root cause analysis is supported by evidence rather than speculation.
Listening Is a Technical Skill
Stakeholder interviews are one of the most undervalued tools in both audit and tech environments. Internal auditors rely on interviews not only to validate information but also to understand context, challenge assumptions, and uncover risks that may not be immediately visible through documentation alone.
In investigative work, interviews are conducted with careful planning, structured questioning, and active listening. Sometimes, what is said or not said, together with the way it is communicated, reveals the most about what an individual conveys.
In tech and audit environments, interviews are often treated as a precursor to the “real work” - a box to be checked before analysis begins. This framing underestimates their value. The most useful information often emerges from follow-up questions rather than the initial response. Pausing a little longer or asking a question differently can reveal insights that would otherwise remain hidden. When interviews are treated as a primary source of evidence rather than a preliminary exercise, they often uncover far more than expected.
The Paper Trail Isn't Bureaucracy
Documentation is an integral part of any investigation. Everything is recorded because conclusions must be supported by evidence rather than assumptions.
If someone is asked to explain a conclusion, they should be able to point to documented evidence that supports it. In many incidents I have worked on, documentation was either incomplete or created only after the fact. Documentation is often produced at the end of the process rather than maintained as a living record throughout the incident.
While documentation can be consolidated later, incident logs and updates to leadership should begin as soon as the incident occurs. This does not change what actions need to be taken or what conclusions are ultimately reached. What it changes is the quality of the process. Maintaining clear documentation throughout an incident improves transparency, supports decision-making, and creates a stronger foundation for preventing similar issues in the future.
What the Translation Offers
In both investigation and tech risk management, the ability to separate facts from assumptions, remain focused under pressure, and make evidence-based decisions defines effectiveness. These skills directly address uncertainty and risk, making them valuable tools for solving complex problems.
For internal auditors, these same capabilities underpin much of what we do. Whether evaluating controls, investigating anomalies, assessing emerging risks, or providing assurance to stakeholders, the ability to gather evidence, challenge assumptions, and reach balanced conclusions remains essential.
Recognising that many of the same challenges exist across different disciplines highlights the universal value of investigative skills. This shared foundation helps bridge professions, strengthens communication, and turns investigative thinking into a common language for solving complex problems.
Rayson Tan has more than 10 years of experience spanning investigations, risk, and technology operations across both the private and public sectors.

