Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / The programme

Audit and Oversight of the Investigators

A function with access to everybody's records needs somebody checking it. The arrangement is simple and is almost never in place.

The editors · About the editorial position · The programme · Procedure

An insider programme can look at anybody. That capability requires oversight for the same reason every such capability does, and insider programmes are frequently the least overseen function in an organisation.

The evidential discipline in “Audit and Oversight of the Investigators” applies equally to workforce records. A team evaluating time tracking software for proportionate review in relation to time tracking software should document purpose, access, retention and correction rules, then preserve the original context rather than treating a convenient dashboard as self-explanatory proof.

What oversight should examine

Access logs for the investigators themselves: who looked at what, when, and under which case reference.

For a separate perspective relevant to “Audit and Oversight of the Investigators”, consult the WIRED security coverage. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

Queries run without a case reference, which should be close to zero and rarely are.

Scope compliance: what was authorised against what was collected, which the scope note identifies as the measure of whether the control worked.

Cases closed with no record, which should also be zero.

And the closed-no-action set, which the recording note argues is where bias would show and which is invisible if closures are not written down.

Who should do it

Internal audit, where it exists and is independent of security.

Otherwise a named person outside the programme with the standing to ask uncomfortable questions: a general counsel, a non-executive, a data protection lead.

Not the programme's own management, which is the common arrangement and is not oversight.

The query without a case

The single most useful check. An analyst looking at somebody's records with no case reference is doing something unauthorised, and the capability to detect it exists in most platforms.

Running that report quarterly, and acting on what it shows, does more for the programme's integrity than any policy.

It also protects the analysts: a function whose access is demonstrably logged and reviewed is one whose staff cannot be casually accused.

Reviewing a sample properly

Not the headline cases. A random sample of closures, read against the questions this collection raises: was there a threshold decision, a scope, a declared conflict, a proportionate response, a recorded outcome, a communication to the subject.

Six checks against ten files, once a quarter. Half a day.

What oversight should be able to require

A case to be reopened.

A capability to be withdrawn.

A rule to be retired.

An outcome to be reviewed.

Oversight that can only observe is a reporting arrangement rather than a control, and everybody involved knows the difference.

The report

To whoever governs the programme, with the findings and the response.

And in summary to the workforce, which the transparency note argues for and which is what makes the oversight credible rather than internal.

The query with no case reference

Close to zero is the only acceptable number and almost nobody has ever run the report. It is the single most useful integrity check available, it exists in most platforms, and it protects the analysts as much as it constrains them.

Oversight that can require change

The ability to reopen a case, withdraw a capability, retire a rule or review an outcome. Oversight that can only observe is a reporting arrangement, and everybody involved knows the difference from the first meeting.

Six checks, ten files

A random sample of closures read against the threshold, scope, conflicts, proportionality, outcome and communication. Half a day a quarter, and it is the only evidence that the controls described in a policy are operating.

Protecting the analysts

A function whose access is demonstrably logged and reviewed is one whose staff cannot be casually accused of looking at things they should not. The oversight constrains them and it is also the only thing that can clear them.

Reporting the oversight itself

Findings and the response, to whoever governs the programme, and in summary to the workforce. Oversight whose results are never seen outside the function is indistinguishable from no oversight at all.

For the file: Run the no-case-reference query this quarter. If nobody has ever run it, the number will be larger than expected and that is the finding.