Treat the six PCI domains as phases of a single investigation you invent on paper. Build one mock case file, then reuse it in every study session: plan the case, collect and document its evidence, run its interviews, test its legal posture, and write its report. Administrative details such as eligibility, scheduling, and fees are not covered here; check ASIS International directly for those.
Running one mock case through all six PCI domains
Instead of studying the six PCI domains as separate silos, treat them as sequential phases of a single invented investigation: plan the case, collect its evidence, interview its people, check its legal limits, and write its report.
Set up the case before studying anything: a paper scenario of, say, recurring inventory shrinkage at a distribution center, with a named complainant, a site, and a rough timeline. Create a case file with a divider for each PCI domain. Every session, you add one phase to the same case, so the plan you wrote last week becomes the foundation for this week's evidence decisions.
The value of this structure is that it exposes cross-domain consequences early. When you reach the interviewing phase, you discover your plan never identified who holds CCTV records. When you write the report, you notice the evidence inventory has no custody entries. Domain-by-domain flashcards hide exactly these seams; a running case file surfaces them while you can still fix your habits.
Writing an investigative plan that holds up when scope changes
A usable investigative plan states the objective as a question, maps the evidence that could answer it, assigns tasks with dates, and names decision points where you pause and reassess before continuing.
Learn the components as distinct items: an objective statement (a question about what happened, not a hunch about who did it), an evidence map (documents, systems, physical items, and people that could bear on the question), a task list with owners and dates, decision points, and escalation rules for when findings widen the scope. Practice writing the objective for your mock case until a stranger could tell what the investigation is and is not trying to establish.
Now apply the decision-point concept in your mock case. Suppose you learn the site's CCTV system overwrites footage on a short cycle. A plan with a decision point at 'potential electronic evidence identified' forces a preservation step immediately. An investigator without that checkpoint might keep planning for days while the footage is overwritten, then build the case around a gap. The plan is not paperwork; it is the mechanism that turns 'we should preserve that' into a dated, assigned task.
Evidence handling: showing an artifact is what you say it is
Chain of custody is the documented record of who collected, transferred, and stored each item. Its purpose is to let a later reviewer verify the item was not altered between collection and presentation of findings.
Work with the named practices: documenting items in place before collection, contemporaneous notes written during the activity rather than reconstructed afterward, custody entries for every transfer of hands, and hashing for digital items, where a calculated value acts as a fingerprint so any later change to the file is detectable. In your mock case, write the custody entry for one physical item and one digital item and compare what each requires.
Worked scenario: while processing the mock shrinkage case, an investigator finds a company laptop possibly used to alter inventory records. He copies the drive onto a USB stick at a colleague's desk and writes one line in his notes: 'laptop imaged.' Plausible mistake: no record of who collected it, when, from where, who handled the copy, or any hash values. Better decision: photograph the laptop where found, record collection date, time, location and collector, calculate and note hash values before and after copying, and log every subsequent transfer. Why it matters: months later, a hearing panel cannot distinguish 'the investigator copied the original records' from 'the records could have been changed along the way,' and every conclusion resting on that drive weakens together.
Interview versus interrogation: choosing the posture before you sit down
An interview is a non-accusatory conversation to gather information. An interrogation is an accusatory exchange aimed at obtaining an admission from a person you already believe responsible. Choose the posture deliberately before the meeting.
The distinction is about purpose, tone, and your state of belief, not the room or the paperwork. In an interview you ask open questions, invite a free narrative, and treat the person primarily as a source of information. In an interrogation you present a conclusion, challenge accounts, and seek acknowledgement. Because the posture carries different obligations and risks, the decision must rest on evidence you can already point to, not on a hunch formed in the hallway beforehand.
Worked scenario: in the mock case, the person who maintains fuel-card and inventory records becomes a person of interest. An investigator books a room, opens with 'You know why you're here, so tell me what you did,' and offers to 'go easy' if she cooperates. Plausible mistake: switching to an accusatory posture while she is still largely a witness, plus making inducements the investigator may not be able to keep. Better decision: conduct a non-accusatory interview first, gather her account and the system details she controls, and reserve an interrogative posture for when documented facts support believing she is responsible. Why it matters: the posture chosen shapes how the person is treated, how her statements are later evaluated, and whether the transcript supports or undercuts the final report.
| Dimension | Interview | Interrogation |
|---|---|---|
| Purpose | Gather information and an account | Obtain an admission from a suspected person |
| Opening approach | Open questions inviting a free narrative | Accusatory statement of belief or conclusion |
| Belief required beforehand | None; person may be witness or subject | Documented facts supporting responsibility |
| Treatment of the person | Source of information | Person whose account is being tested |
| Documentation focus | What the person says, verbatim where possible | Questions, answers, and any admissions claimed |
Legal and ethical boundaries in private-sector investigations
A private-sector investigator works within the authority granted by their role, the organization's policies, and applicable law. Consent, privacy expectations, and data-handling rules determine which collection methods are defensible.
Learn these as distinct concepts you can apply to any fact pattern: scope of authority (what your role and mandate actually permit), consent (whose permission a method requires), privacy expectations (what a person could reasonably consider private in that setting), need-to-know handling of personal information, and proportionality (whether the method fits the seriousness of the alleged conduct). These are general professional principles; the specific thresholds differ by jurisdiction, so identify the governing framework with counsel or policy rather than importing a memorized rule from elsewhere.
Apply the concepts to your mock case with a question set instead of an answer key. A supervisor asks the investigator to search an employee's personal locker. Ask: Who owns or controls the locker, and under what policy? Has the workforce received notice of searches? Is the request within the investigator's written mandate? What less intrusive method could answer the same question? Working the same fact pattern through each question teaches you where a defensible method ends, which is the judgment the domain is actually testing.
Case reporting: separating observed facts from investigator opinion
A defensible report records what was done, what was observed, and what sources said, then states findings as conclusions tied to specific evidence, keeping the investigator's speculation clearly labeled or excluded.
Structure practice around report anatomy: an activity log (what the investigator did and when), an evidence inventory with custody entries, interview summaries attributed to their sources, and a findings section. Train the fact-versus-inference distinction with sentence pairs from your mock case: 'The badge log shows badge 4021 entered the storeroom at 22:14' is a fact; 'Badge 4021's holder stole the stock' is an inference that belongs only in findings, and only if linked to supporting evidence.
Practical exercise — the single-case rewrite drill: take your mock case file and draft a two-page report containing only the four components above. Then audit it against this rubric and note your observations: (1) Objective — does the opening state what the investigation sought to establish? (2) Traceability — can every finding be matched to a specific log entry, exhibit, or interview summary? (3) Custody — does each evidence item have an unbroken documented trail? (4) Labels — is every opinion or inference visibly separated from reported facts? A useful milestone is a draft where you can point to the supporting source for every sentence in the findings; if any sentence fails that check, either source it or cut it.
An adaptable preparation sequence and readiness checks
Sequence your preparation around the mock case: build it, plan it, handle its evidence, run its interviews on paper, pressure-test its legal posture, then write and defend its report before revisiting your weakest domain.
Adjust the depth of each phase to your background: an experienced interviewer may spend one session on interviewing but several on evidence handling; a records specialist may invert that. Keep the order intact regardless, because each phase consumes the outputs of the one before it, and the report phase is the natural place to discover which earlier phase needs rework.
Use these readiness checks as milestones for the whole method, not as predictions of any score outcome: you can state your case objective in one sentence a stranger understands; you can write a complete custody trail for a digital item without consulting notes; you can explain, for a given fact pattern, which conversation posture applies and why; you can hand a stranger your draft report and have them trace each finding to its source. Any check you fail identifies the domain to revisit, and rebuilding that phase of the mock case is itself the remediation.
- Session 1-2: build the mock case and write the investigative plan with decision points
- Session 3: create the evidence inventory, custody entries, and one hashing example
- Session 4: script an interview and, separately, the conditions that would justify a different posture
- Session 5: run a fact pattern through the authority, consent, privacy, and proportionality questions
- Session 6: draft and rubric-audit the case report, then rebuild the weakest phase
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
