The Right Time, the Right Team, the Right Objective
What the tactical side of asset tracing actually looks like in practice
When the intelligence picture is built, and it is time to act, the decisions made in the next few hours often determine whether a case holds or falls apart. Surveillance deployed too early. Digital forensics commissioned before the right questions have been asked. Insider risk left unmapped until it becomes a problem. These are not failures of resource or intent. They are failures of sequence.
The tactical side of asset tracing is where everything that came before it either pays off or doesn’t.
Surveillance: the most expensive last step
Surveillance is often the first thing a client imagines when they hear asset tracing. In practice, it should almost always be the last.
The reason is not just financial, although the costs are real. A surveillance team in the field across multiple days, across potentially multiple jurisdictions, with the logistics that requires, represents a significant commitment of time and resources. But the deeper reason is strategic. Surveillance conducted without a solid intelligence foundation is not just expensive. It is directionally wrong. You are putting people in the field without knowing precisely what you are looking for, which means you may be watching the wrong subject, at the wrong location, at the wrong time.
“People come to me all the time and say they need surveillance done. And I get it. But surveillance is the most costly option in any investigation, and it should always be the last thing we do, never the first. Before anyone goes near a subject, I need the full picture. The background research. The intelligence picture. A proper subject profile. The right time, the right team and the right objective, in that order, always. Get any one of those wrong, and you’ve spent a lot of money on very little.” – James Ellender, Co-Founder and CEO, Futurum Risk
The intelligence picture that precedes surveillance is what makes it productive. Who is the subject. Where do they go. What does their pattern of life look like. Who do they meet. What are they protecting. Without answers to those questions, surveillance is observation without purpose. With them, it becomes a precision tool capable of producing the best evidence available in a case.
There is also the question of exposure. Surveillance conducted badly, or conducted before the subject has any reason to expect it, can expose the investigation itself. A subject who realises they are being watched gains information they did not have before. They know the investigation is active. They know roughly what the focus is. They can change their behaviour, move assets, warn associates, or simply become significantly harder to follow. The intelligence advantage that weeks of careful preparation created can be lost in an afternoon.
This is why the sequence is not a matter of preference. It is a matter of outcome. Background research first. An intelligence picture built from open source, corporate records, digital footprint analysis and human sources second. A clear, specific subject profile third. Surveillance, if it is needed at all, comes after all of that, when the objective is precise enough that the team knows exactly what evidence it is trying to secure and why every hour in the field is justified.
The cases that get surveillance right are the ones that have done everything else first. The cases that get it wrong are the ones that reached for it before they were ready.
Digital forensics: finding what was meant to stay hidden
Digital forensics is one of the most misunderstood disciplines in asset tracing, partly because the term covers a wide range of capabilities, and partly because its role in an investigation is often unclear until it is actually needed.
At its core, digital forensics in an asset tracing context is about recovering, preserving and analysing electronic evidence in a way that is legally defensible and capable of withstanding scrutiny in court. That distinction matters. It is not simply a matter of finding information on a device. It is finding it in a way that documents how it was found, where it was found, and that nothing was altered or contaminated in the process. Chain of custody is not a technicality. It is what makes the evidence usable.
What digital forensics can reveal is significant and frequently decisive. Financial flows that have been deliberately obscured through layered transactions and offshore structures often leave traces in the digital record that are impossible to eliminate entirely. Communications that establish prior knowledge of a fraud, or that demonstrate a subject was aware of impending litigation before they moved assets, can be recovered from devices long after the subject believed them deleted. Metadata embedded in documents and files places them in specific locations at specific times, and that context can fundamentally change what a document means. Deleted records, supposedly permanent removals, frequently remain recoverable through forensic techniques that operate below the level of standard file management.
None of this is accessible without the investigative foundation that makes it possible to identify the right devices, accounts and systems in the first place. Digital forensics applied blindly, without a clear hypothesis about what is being sought and why, produces enormous volumes of data and very little actionable intelligence. Applied precisely, after the intelligence picture has identified where to look and what the objective is, it can surface the single piece of evidence that changes a case.
“Ask someone what happened and you get their version, filtered through memory and self-interest. Ask their device, and you get something closer to the truth: deleted files that aren’t really gone, metadata that contradicts a witness statement, geolocation pings that place a phone somewhere its owner swears it wasn’t. A bank statement shows money moved. A forensic image can show who logged in beforehand, what they searched for, and whether a document was quietly backdated. That gap, between what people say and what their devices recorded, is usually where a case is actually won.”– Auhom Ahrar Al Quazi, Research Associate, APAC
The discipline this requires mirrors everything else in a well-run investigation. Knowing what you are looking for before you start looking. Being willing to question what you find before you act on it. Understanding that volume of data is not a substitute for clarity of purpose.
A sample asset tracing report from the BVI, one of the most opaque jurisdictions in the world for this kind of work, is available to download here, showing what a properly resourced investigation can surface even in that environment. [Link to BVI sample report]
Insider threat: the risk that comes from inside
Insider threat is one of the most consistently underestimated risks in a corporate investigation context. The focus tends to fall on external actors. The assumption is that the people inside the organisation are on the right side of the matter.
That assumption is frequently wrong. Insider threat, whether deliberate or inadvertent, through compromised employees, undisclosed relationships or conflicts of interest that were never surfaced, can undermine an investigation before it has properly started. Background checks and third party due diligence, done properly, don’t just verify what someone has told you. They reveal what they haven’t.
What makes this genuinely complex is that the risk profile looks different depending on the market. Ghina Abdul, Futurum’s senior associate based in Singapore, works across Southeast Asia where the regulatory environment, the nature of corporate relationships and the cultural assumptions around disclosure create a specific set of considerations.
“In Asia, especially Southeast Asia, there is a greater emphasis on trust and collectivism, which makes it hard for some companies to see insider risk as an actual possibility. This is amplified by informal loyalty obligations and, in some cases, patronage networks and family-linked ownership. Having security measures in place can appear excessive, even distrustful. However, this doesn’t negate or lessen the damage that insider threats bring. An effective insider threat framework requires the ability to navigate these intricate social networks rather than override them. Cultural understanding is not just preferable. It’s imperative.” – Ghina Abdul, Senior Associate, APAC
Katelin van Zyl, Futurum’s research associate in the Africa team, brings a different regional lens to the same challenge.
“Insider threats are a significant operational and reputational risk across Africa. From petty theft to large-scale fraud and embezzlement, workplace violence and harassment to incompetence, these risks are prevalent and consistently underestimated. One of the most common issues is the use of false qualification claims, including forged degree certificates. Many employees are dismissed once these are discovered, but others go undetected entirely. This has contributed to growing calls for more robust background checks, and it is exactly the kind of risk that a thorough pre-employment screening process is designed to surface before it becomes a problem.”– Katelin van Zyl, Research Associate, Africa
Two markets, one lesson. The underlying risk is the same wherever you are. An undisclosed relationship looks different in Singapore than it does in Lagos. A conflict of interest that surfaces immediately in one regulatory environment can remain invisible in another. What changes is knowing where to look for it, and having people who already understand the ground before the question is even asked.
What it all comes back to
The answers lie in getting the sequence right. The pre-litigation intelligence picture built before a counterparty knows they are being looked at. The investigative discipline that questions what it finds before acting on it. The on the ground knowledge of markets that behave differently from how they appear from the outside. And the tactical decisions about when to deploy which tools and in what order.
Get the sequence right, and you have something that holds. Get it wrong, and the window closes before you realise it was open.
If you would like to talk through how any of this applies to a matter you are currently working on, get in touch with the team.