Back to Resources
From Guidance to Proof: What an Evidence-Grade, Globally Credible OSINT Standard Must Deliver
OSINT

From Guidance to Proof: What an Evidence-Grade, Globally Credible OSINT Standard Must Deliver

Building on their work discussing The OSINT Standards Gap, The Coalition of Cyber Investigators explore what a globally agreed OSINT standard must deliver: evidential integrity, graded intelligence, AI and translation accountability, role-based competence and transparent governance. OSINT has already proved it can find information. The task now is to prove its most consequential findings deserve to be relied upon.

Paul Wright & Neal Ysart28 September 202615 min read
Share

The first article in this series argued that open-source intelligence (OSINT) must be further professionalised. The harder question is what professionalisation should produce: what would make an OSINT standard credible, practicable and worthy of trust across investigations, courts, businesses, newsrooms, civil-society organisations and national borders?

This article builds on The OSINT Standards Gap: Why Open-Source Intelligence Must Professionalise Further. It draws on the Berkeley Protocol, ISO digital-evidence and forensic-science standards, guidance from the Scientific Working Group on Digital Evidence (SWGDE) on online acquisition, recognised AI-risk frameworks and the ISO conformity-assessment family. Its purpose is not to replace those sources, but to show how their strongest controls can be combined with other leading practices and methodologies to help form a cross-sector framework for competence, evidential integrity, AI accountability, translation assurance and independent review.

The article also considers intelligence-grading principles, international translation-services standards and practical certification models, such as those used by GAI Translate. These controls matter because uncertainty, linguistic ambiguity and the transformation of multilingual evidence must remain visible, documented and open to scrutiny.

THE STANDARDS GAP IS NOW AN IMPLEMENTATION GAP

The case for professionalisation is no longer difficult to make. OSINT increasingly shapes investigative direction before formal evidence is obtained. It helps identify accounts, infrastructure, providers, assets, relationships and risks. What remains incomplete is a broadly adopted way to demonstrate that findings were collected lawfully, preserved reliably, analysed fairly and reported with an appropriate level of confidence by competent and certified practitioners.

Existing frameworks make substantial contributions. Some are strong on intelligence policy, collection management, analytical discipline, privacy, training or organisational governance. Others address digital evidence, journalism, human rights investigations or cyber incident response. The weakness is fragmentation across professions, legal mandates and institutional cultures. A framework designed for one field cannot automatically serve as a universal investigative standard applicable across all sectors.

The Berkeley Protocol is the clearest reason to make that distinction. Published by the UN Office of the High Commissioner for Human Rights and the Human Rights Centre at UC Berkeley, it provides a detailed methodology for identifying, collecting, preserving, verifying, analysing, and reporting on digital open-source information in international criminal, human rights, and humanitarian investigations. It is an evidence-oriented operational protocol, not merely a statement of principles.

Its influence is considerable, but it was not designed as a universal, cross-sector OSINT standard. It does not provide a complete system for certifying practitioners, auditing organisations or accrediting independent assessors. Nor can it remove differences in national law, evidential rules, institutional resources and sector-specific duties.

The United States does not currently publish a single, cross-sector and independently assessable OSINT standard. It does, however, maintain the Intelligence Community's strategies, policies, and tradecraft guidance. The Department of State’s inaugural INR OSINT Strategy, issued in May 2024, prioritises governance, capability investment, training and collaboration. The establishment of a dedicated House Intelligence Committee OSINT Subcommittee in 2025 further demonstrates the growing institutional importance of OSINT governance and accountability. Neither initiative, however, constitutes a conformity-assessable professional standard.

The appropriate task is therefore not to replace or relabel the Berkeley Protocol, but to build on its strongest investigative controls within a broader framework that covers competence, governance, intelligence grading, digital forensic validation, AI accountability, translation assurance, and independent conformity assessment.

The Central Test

Can another competent person understand what was done, examine the preserved material, test the reasoning and identify the limits of the conclusion?

FOUR LAYERS THAT SHOULD NOT BE CONFUSED

Professional debates often blur four different things. Keeping them separate would immediately improve clarity.

Principles set the values: legality, necessity, proportionality, integrity, fairness and accountability.

Operational requirements specify what a practitioner or organisation must do: authorise, record, preserve, verify, review, retain and disclose.

Practice guidance shows how requirements may be met in different contexts without freezing the discipline around today's tools.

Conformity assessment tests whether people, processes, tools or organisations meet the requirements.

A document can be thoughtful without being a formal standard. A formal standard can exist without adoption. Training can exist without independent competence assessment. A certification badge can exist without rigorous assessment behind it. Credibility depends on stating exactly which function is being performed.

Conformity assessment must also match the object being assessed. Individual investigators, investigative organisations, collection processes, analytical methods, technical tools and certification providers raise different assurance questions. Personnel certification, management system assessment, process conformity, laboratory testing, and accreditation should not be treated as interchangeable badges of quality.

Nine Critical Requirements for an OSINT Standard

1. Start With Evidence, Not Merely Information

Intelligence may guide a decision or generate a lead. Evidence must be capable of supporting a proposition under scrutiny. An evidence-grade OSINT standard must explicitly address that transition.

At minimum, it should require a contemporaneous record of the source, date and time, access conditions, acquisition method, relevant metadata, contextual material, transformations and storage location. Where appropriate, it should require cryptographic hashing, controlled repositories, retention rules and an auditable history of access and handling.

The standard should also recognise the limits of capture. A screenshot may show what appeared on screen while omitting source code, metadata, linked content, platform state or the sequence in which material was accessed. Preservation protects what was obtained; it does not automatically authenticate it.

"Preservation protects what was obtained; it does not automatically authenticate it."

The Berkeley Protocol, paras. 167-169 and annexes I-V helps address these concerns by distinguishing evidentiary copies from working copies, requiring chronological chain-of-custody records, and providing templates for planning, threat assessment, digital landscape assessment, and online data collection.

Online collection also creates risks. Dynamic content may change based on browser identity, authentication, location, or time; live access may leave a footprint; and collection tools may alter or incompletely reproduce what was available. Acquisition procedures should therefore record the environment, tools, settings, and limitations, preserve contextual material, and produce auditable working and archival copies.

Purpose-built web-capture tools can help operationalise these requirements if they are treated as part of the evidential process rather than a substitute for it. For example, tools such as Forensic OSINT may support structured capture, preservation, and review of web-based material, while the practitioner has to ensure that the resulting record can be independently understood, tested, and challenged.

Defensibility continues after acquisition. Methods must be fit for purpose, and the analysis must preserve continuity and validity while producing results that others can reproduce, repeat and independently review. These practices should run throughout the investigation, providing a sound foundation for a wider OSINT framework.

2. Make Verification and Attribution Separate Disciplines

Verification asks whether an artefact, event or observation is authentic and accurately described. Attribution asks who created, controlled or caused it. The second is usually harder and should never be conflated with the first.

A robust standard should require investigators to identify alternative explanations, evaluate source independence, record contradictory indicators and use language proportionate to the evidence. Shared usernames, profile images, contact details, infrastructure or wallet interactions may support an association. They do not automatically establish identity, ownership, control, intent or culpability.

Professional wording becomes investigative control. 'Observed', 'associated with', 'consistent with', 'assessed' and 'confirmed' should have defined meanings. Confidence should be explained by evidence and limitations, not generated by a tool or converted into a decorative percentage.

The broader forensic science framework reinforces this discipline. ISO 21043 separates analysis, interpretation, and reporting and requires suitable methods, qualified personnel, consideration of alternative propositions, and clear, impartial reporting. Those requirements are directly relevant when OSINT observations are converted into attribution or another decision-relevant opinion.

3. Grade Intelligence Without Disguising Uncertainty

A professional OSINT intelligence framework should distinguish source reliability, information credibility, analytical confidence and handling restrictions. These are related but separate judgements. A source's history does not determine whether a particular claim is true, and corroboration does not automatically establish identity, intent or legal responsibility.

Grading should make the basis of an assessment visible, record information gaps and contradictory reporting, and prevent confidence terminology from being mistaken for evidential proof. Systems such as the UK 3x5x2 model and the analytic principles in ICD 203 offer useful examples, but a global framework should define interoperable concepts rather than impose one jurisdiction's coding system.

Intelligence grading is not legal admissibility, evidential weight, attribution confidence, probability or security classification. A reliable source can provide inaccurate information; an unknown source can provide independently verified information; and a high-confidence assessment may still be inadmissible in formal proceedings.

This is important as clearly graded intelligence shows stakeholders what you know, how you know it, and what remains uncertain. Separating source evaluation from evidential proof helps ensure that OSINT is used appropriately and no one is misled as to the weight it should carry.

4. Require Tool and AI Accountability

Modern investigations depend on commercial platforms, scripts, enrichment services, archives, translation tools and generative or analytical AI. Some are transparent; others are black boxes. A standard that ignores tools will be obsolete, but a standard that names approved tools will age just as quickly.

The better approach is capability-neutral accountability. Practitioners should record when an automated system materially shaped collection, ranking, translation, clustering, matching or summarisation. They should preserve enough information to understand the input, relevant settings, the output, and the human review. Critical findings should be checked against primary material wherever possible.

AI output should be treated as a processing product, not a new source. It may help an investigator see a pattern, but it cannot repair weak provenance, replace linguistic or cultural expertise, or convert an inference into evidence. Human oversight must mean active challenge, not a final click on an approval button.

This is especially important for AI-enabled intelligence platforms that generate summaries, associations or leads from mixed-source material. A platform such as Tesari AI may support investigative efficiency, but its outputs should remain traceable to underlying sources and subject to human challenge. The evidential value lies in preserved primary material and documented reasoning, not in the platform's conclusion alone.

OSINT-specific AI controls should sit within established organisational risk frameworks. ISO/IEC 42001 provides a management-system model for responsible AI governance and continual improvement, while the NIST Generative AI Profile addresses risks across the generative-AI lifecycle. An investigative standard should translate those broader controls into requirements for source traceability, data and prompt handling, validation, privacy, output retention, limitations and human challenge.

5. Treat Translation as an Evidential Transformation

In multilingual investigations, translation is not an administrative convenience. It is a transformation capable of changing meaning, tone, intent and evidential significance. Machine translation may support discovery and triage, but material findings should be verified by a suitably qualified human.

Where a translation will be used in court, regulatory proceedings, or another formal process, the translator and certification method must satisfy the requirements of the relevant jurisdiction. There is no single global status that makes a translation accurate or admissible everywhere; the appropriate control is risk-based translation assurance.

The investigation record should preserve the original-language material, identify the translator and automated tools, record the translated version and date, document revision and terminology decisions, retain material alternative translations and disclose unresolved ambiguity. ISO 17100, ISO 20771, ISO 18587 and ISO 5060 provide useful process and evaluation models.

6. Build Competence Around Judgement

Tool familiarity is not professional competence. Search techniques matter, but investigators also need legal awareness, source evaluation, preservation skills, analytical reasoning, report writing, operational security, trauma-aware handling of harmful material and the judgement to stop when the available evidence does not justify a conclusion.

"Tool familiarity is not professional competence."

A credible competence framework should define roles and levels. A collector, analyst, reviewer, team leader and expert witness do not need identical capabilities. Assessment should use realistic scenarios and work products, not attendance alone. Reassessment and continuing professional development are essential because platforms, laws and adversary methods change.

The Berkeley Protocol requires appropriate training, technical skills, ethical conduct and ongoing security awareness. A wider framework should retain those expectations while adding role definitions, assessment criteria, reassessment and independent assurance. Training providers may contribute to curriculum design, but teaching, examining and certifying the same candidates without meaningful separation creates an avoidable credibility problem.

7. Design For Jurisdictions, Not Around One Jurisdiction

Global legitimacy cannot be achieved by exporting the assumptions of one national security system, legal tradition, commercial market or political bloc. OSINT is used by law enforcement, defence, private investigators, corporations, journalists, lawyers, human rights groups and safeguarding teams. Their mandates, powers, disclosure duties and risk tolerances differ.

"Global legitimacy cannot be achieved by exporting the assumptions of one national security system, legal tradition, commercial market or political bloc."

A global framework should establish a politically neutral core: lawful mandate, necessity, proportionality, source protection, data minimisation, evidential integrity, transparency, accountability and respect for human rights. Jurisdiction-specific annexes can then explain local legal bases, admissibility rules, disclosure obligations, privacy constraints and professional licensing requirements.

This model would create interoperability without pretending that law is uniform. It would also widen participation beyond the best-funded institutions and ensure that practitioners from Africa, Latin America, the Middle East and Asia-Pacific help shape the core rather than merely comment on a finished product.

8. Give Governance the Same Scrutiny as Tradecraft

The credibility of a standard depends partly on the credibility of the process that produced it. Distinguished experts and large professional networks can offer genuine insight, but reputation is not a substitute for transparent governance.

The Berkeley Protocol offers a credible development model: a joint institutional partnership, multidisciplinary working groups, more than 150 expert consultations, and documented review, revision and validation. A future cross-sector initiative should match that transparency and extend it through continuing public consultation, declared conflicts and version governance.

The 2024 INR OSINT Strategy and the establishment of a dedicated House Intelligence Committee OSINT Subcommittee demonstrate increasing institutional attention to OSINT governance, competence and accountability, but neither constitutes a cross-sector, conformity-assessable professional standard.

A standards initiative should publish its legal structure, decision-making process, participation criteria, funding model, conflicts policy, editorial controls, complaints route, correction process and review method. Working groups should include investigators, digital forensics specialists, lawyers, prosecutors and defence perspectives, data protection professionals, journalists, academics, civil society and affected communities.

Sponsors and technology vendors can provide expertise and resources, but their involvement must be declared and controlled. No participant should be able to shape requirements in a way that privileges its own product or institutional interest. Drafts should be exposed to consultation, with material responses recorded and resolved transparently.

9. Validate Before Claiming Authority

Self-publication is a legitimate way to start a professional conversation. It is not the end of a standards journey. Authority grows through testing, adoption, independent review and evidence that the framework improves outcomes.

Pilot programmes should test requirements against different case types: online fraud, cyber incidents, asset tracing, safeguarding, corporate investigations, public-interest reporting and cross-border matters. Exercises should measure whether another practitioner can reconstruct the work, whether reviewers detect unsupported conclusions, whether preservation survives challenge and whether reporting helps non-specialists make proportionate decisions.

The results, including failures, should inform revisions. A versioned standard, a published change log, and a scheduled review cycle would show that the framework learns from practice. The Berkeley Protocol was validated as a methodology through expert development and review; conformity assessment asks a different question: whether a particular practitioner, organisation or process demonstrably meets defined requirements.

A PRACTICAL MINIMUM VIABLE STANDARD

The first usable edition need not solve every issue. It should produce a small set of concrete artefacts that improve real investigations from day one:

Minimum Viable Standard: Core Artefacts
  • ✓A common vocabulary separating source, observation, inference, assessment, attribution and evidence;
  • ✓A lawful-purpose and proportionality record;
  • ✓A minimum collection and preservation log;
  • ✓A verification, corroboration, alternative-hypothesis and method-validation record;
  • ✓An analytical record exposing reasoning, confidence and limitations;
  • ✓A tool and AI-use register covering material automated contributions, validation and risk controls;
  • ✓An intelligence-grading record separating source reliability, information credibility, analytical confidence and handling;
  • ✓A translation-assurance record covering original material, human review, automated assistance, alternative meanings and limitations;
  • ✓A plain-language reporting model for non-specialist decision-makers;
  • ✓A role-based competence and independent assessment model; and
  • ✓A governance, consultation, complaints and revision process for the standard itself.

This minimum set should not start from a blank page. The Berkeley Protocol's investigation plan, risk assessment, landscape assessment, collection and tool-validation materials offer tested starting points. Cross-sector development should map, reuse and extend such artefacts before creating new ones.

BUILD ON WHAT ALREADY WORKS

Professionalisation should begin with a structured comparison of existing frameworks. The Berkeley Protocol provides a strong evidentiary baseline; digital-evidence standards, forensic-science standards, journalism protocols, intelligence doctrine, and sector-specific investigative rules add further strength.

The task is not to collapse those materials into a lowest-common-denominator checklist. It is to identify a common professional core, preserve domain-specific safeguards and define interfaces that allow findings to move between investigators, lawyers, courts, companies and public bodies without losing provenance or meaning.

This changes the claim being made. The standards gap is not that a professional OSINT methodology has never been written. It is that strong methodologies remain unevenly adopted, differently scoped and largely disconnected from a shared system of competence assessment, institutional accountability and independent assurance.

WHAT CREDIBLE LEADERSHIP LOOKS LIKE

No single organisation needs to claim ownership of the entire field. The more credible role for practitioner networks, professional associations, academic groups, civil society organisations and public bodies is to contribute what they know, expose their assumptions and support an independent, inclusive process.

Practitioner-led groups are important because they understand where elegant policy fails in live casework: disappearing content, incomplete platform records, ambiguous identities, disclosure pressures, translation errors, harmful material, client urgency and courtroom challenge. Their experience should shape operational requirements and testing.

But practitioner experience must itself be reviewable. Methodologies should be documented at a level that protects sensitive techniques while allowing others to assess quality. Editorial review, declarations of interest, anonymised case studies, correction mechanisms and external challenge strengthen rather than diminish professional authority.

CONCLUSION: STANDARDS MUST EARN TRUST

The next stage of OSINT professionalisation is not another declaration that good practice matters, nor a reinvention of methods that already work. It is the extension of strong domain-specific methodologies into a coherent system that can show what good practice looks like across sectors, test whether it occurred and correct it when it did not.

A globally credible OSINT standard must be evidence-focused, operational, politically neutral and independently reviewable. It should incorporate the Berkeley Protocol's strengths in legality, ethics, security, preparation, preservation, verification and reporting; digital-evidence and forensic-science controls for collection, method assurance, analysis, interpretation and reporting; and modern requirements for AI governance, translation assurance, intelligence grading, cross-sector interoperability, role-based competence and conformity assessment.

Most importantly, it must resist the temptation to confuse visibility with authority. Credible people, useful guidance, a large audience and strong institutional connections can all advance the field. A standard becomes authoritative only when its development is transparent, its requirements are testable, its governance is trusted, and its value is demonstrated in practice.

The most credible path is to use the Berkeley Protocol as a foundational reference, rather than rebranding it as a complete global OSINT standard. Its controls could form part of a wider framework alongside ISO digital-evidence and forensic-science standards, SWGDE guidance, intelligence-grading doctrine, AI governance, translation assurance and independent conformity assessment.

OSINT has already proved that it can find information. The task now is to prove that its most consequential findings deserve to be relied upon.

Authored by: The Coalition of Cyber Investigators,

Paul Wright (United Kingdom) & Neal Ysart (Philippines).

©2026 The Coalition of Cyber Investigators. All rights reserved.

The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator; Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime.

The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.

Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open-source intelligence, risk management, and strategic risk advisory roles across multiple continents.

They have been instrumental in establishing foundational legal precedents and case law in cybercrime investigations and in contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition's commitment to excellence and ethical practice.

Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team's capabilities and reach.

The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.

Our team's expertise is not just theoretical - it's built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.