Overview
When a scam is detected, the investigation doesn’t end with identifying the threat. Every decision, piece of evidence and action taken throughout the investigation should be documented to create a clear record of what happened and why.
For many organisations, that information is often scattered across emails, spreadsheets, screenshots and chat messages, making it difficult to reconstruct an investigation, collaborate across teams or demonstrate how decisions were made.
As organisations prepare for Australia’s Scams Prevention Framework (SPF), maintaining a structured audit trail is becoming increasingly important. The draft Codes require regulated entities to record key information about scam investigations, supporting greater accountability, consistency and transparency throughout the response process.
Why Documentation Matters
Scam investigations rarely involve a single piece of evidence or a single decision. Analysts often review multiple indicators, corroborate intelligence from different sources and assess whether an activity is likely to be a scam before determining the appropriate response.
Without clear documentation, it can be difficult to understand how an investigation reached its outcome. Important evidence may be overlooked, decisions can become inconsistent, and valuable context may be lost when investigations are handed between team members or revisited weeks or months later.
This is reflected in Australia’s draft SPF Codes. Rather than simply requiring organisations to investigate scam activity, the draft also requires key investigation information to be recorded. This includes whether an activity was identified as a scam, the evidence supporting that assessment, how consumers were contacted, and the identifiers used by the scam, such as URLs, email addresses, phone numbers and social media profiles.
Maintaining this level of documentation creates a reliable audit trail that supports consistent decision-making, improves collaboration and provides organisations with a clear record of every stage of an investigation. As scam threats continue to evolve, having evidence of what was investigated, how decisions were made and what actions were taken is becoming just as important as detecting the threat itself.
Why Emails and Spreadsheets Don't Create Audit Trails
Many organisations still manage scam investigations using a combination of email threads, spreadsheets, shared folders and messaging platforms. While these tools can help teams communicate and track individual tasks, they don’t create a structured audit trail.
Evidence is often spread across multiple systems. Screenshots may be stored in shared drives, analyst notes captured in Word documents, domain lookups copied into emails, and case updates discussed in Teams or Slack. As investigations progress, it becomes increasingly difficult to piece together the full history of a case.
This fragmented approach also makes it challenging to answer simple questions. Who reviewed the threat? What evidence supported the decision? When was the takedown request submitted? Has the case already been investigated? Without a central record, finding those answers often relies on searching through inboxes, spreadsheets or chat history.
A structured audit trail brings this information together in a single, chronological record. Every piece of evidence, investigation step, analyst decision and enforcement action is captured in one place, making investigations easier to manage, review and revisit over time.
What Should an Audit Trail Include?
An effective audit trail should capture every stage of an investigation, from the initial detection through to the final outcome. Rather than relying on disconnected notes or emails, organisations should be able to reconstruct the entire investigation from a single record.
Depending on the nature of the investigation, an audit trail may include:
- Detection details: When the threat was identified, how it was detected and the initial intelligence received.
- Supporting evidence: Screenshots, URLs, domain information, WHOIS records, DNS data, email addresses, phone numbers, social media profiles and other evidence gathered during the investigation.
- Investigation notes: Analyst observations, supporting information, risk assessments and the rationale behind decisions made throughout the investigation.
- Actions taken: Notifications, takedown requests, escalations, communications with third parties and any other disruption or enforcement activities.
- Case history: Status updates, timestamps, ownership changes and the final outcome of the investigation.
Maintaining this information in a single, chronological record creates a clear audit trail that supports collaboration, improves consistency and makes it easier to demonstrate how decisions were reached if an investigation is reviewed at a later date.
How unphish Creates a Complete Audit Trail
unphish is designed to capture the complete lifecycle of every investigation within a single case file, bringing together the evidence, decisions and actions taken throughout the investigation. Rather than relying on emails, spreadsheets and disconnected systems, analysts can review the full history of a case from initial detection through to enforcement.
(Centralise every investigation with a complete case file containing evidence, screenshots, analyst notes, metadata and enforcement activity.)
Each case file can include supporting evidence such as screenshots, URLs, domain information, WHOIS and DNS data, AI-assisted analysis, analyst notes, attachments, timestamps and enforcement activity, creating a structured record of how the investigation progressed and why particular actions were taken.
(Track every investigation with a complete activity log, recording analyst actions, system updates, evidence and case progression.)
By centralising investigation activity in a single platform, unphish helps organisations maintain consistent documentation, improve collaboration between teams and retain the evidence needed to support future reviews, reporting and compliance obligations.
As the Scams Prevention Framework continues to evolve, organisations should consider not only how they detect and disrupt scams, but also how they document every stage of the investigation. A clear audit trail helps demonstrate that investigations were conducted consistently, decisions were supported by evidence and appropriate actions were taken.