Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / Deciding

Recording the Decision Not to Proceed

The majority of decisions a programme makes are decisions to stop. Almost none of them is written down, which makes the programme unreviewable.

The editors · About the editorial position · Deciding · Procedure

Programmes document findings carefully and non-findings not at all. Since non-findings are most of the output, most of the programme leaves no trace.

The evidential discipline in “Recording the Decision Not to Proceed” applies equally to workforce records. A team evaluating review the platform here in relation to mouse jiggler detection should document purpose, access, retention and correction rules, then preserve the original context rather than treating a convenient dashboard as self-explanatory proof.

Why the absence matters

It cannot be reviewed. An oversight function looking at a year of work sees the cases that proceeded and nothing about the ones that did not, which is the half where bias would actually show.

For a separate perspective relevant to “Recording the Decision Not to Proceed”, consult the Insider Threat Matrix. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

The same person gets looked at twice from zero. Without a record, a second alert about somebody starts fresh, and the fact that a previous one was examined and cleared is lost.

Patterns are invisible. Three alerts in a year about the same broken process look like three unrelated nothings if none was recorded.

And a decision nobody wrote down looks, afterwards, like a decision nobody made.

What to record

What arrived, from where.

What was checked.

What was concluded and on what basis.

Who decided, and when.

Any declared conflict.

Five lines, and they can be a template with boxes.

The specific value for the subject

Somebody who is flagged, examined and cleared has an interest in that being written down, even though they may never know it happened.

If they are flagged again, the record is what makes the second review proportionate. If the matter ever surfaces — in a dispute, in an access request, in a reference — a clear written outcome protects them in a way that silence does not.

This is worth saying internally, because the instinct is that recording a non-event creates a mark against somebody. The opposite is true: an unrecorded examination leaves a rumour and a recorded one leaves a conclusion.

Retention

A closed-no-action record should not be kept indefinitely. A defined period, short, after which it goes.

Where somebody has been examined and cleared, a file that persists for years is a quiet penalty. Its own note in the outcomes section deals with what stays on the record generally; the principle here is that the retention should be decided deliberately rather than defaulting to forever.

The review it enables

Quarterly: how many alerts, how many preliminary reviews, how many opened, how many found something.

Those four numbers describe the programme. Three of them come from records most programmes do not keep.

The template that makes it happen

Five boxes on a single screen. Anything longer competes with the next alert and loses. The discipline of recording closures survives only where it is faster than not recording them, and that is an interface problem rather than a policy one.

What the four counts reveal

Alerts, preliminary reviews, cases opened, findings. The ratios between them describe the programme more accurately than any narrative: a high opening rate means no effective threshold, a low preliminary-review rate means the step is being skipped, and a near-zero finding rate with many openings means people are being examined for very little.

What the record protects

Not the programme. The person, who may be examined again and whose earlier clearance is the thing that keeps the second look proportionate. An unrecorded examination leaves a rumour where a recorded one leaves a conclusion.

Retention for cleared records

A closed-no-action file should not persist indefinitely. A defined short period, decided deliberately, because an unexamined default of forever turns a clearance into a quiet permanent mark.

The quarterly read

A sample of closures, by somebody outside the programme. It is where bias would be visible and it is invisible entirely unless the closures were written down in the first place.

For the file: Write the closure as carefully as a finding, keep it as briefly as you reasonably can, and make sure somebody independent can read the year's worth.