The Sword and the Shield: Open Source Intelligence

August 29, 2024

Good human beings are indistinguishable from the terrible ones. So how can we tell them apart in the context of business relationships? Open Source Intelligence is both the sword and the shield in attempting to separate the good from the bad.

This investigative tool can be a game changer when it comes to counterparty risk. And yet, this discipline is underappreciated and not well understood. It is a critical process underlying effective anti-money laundering, investor due diligence, anti-bribery and corruption compliance and fraud risk management.

What most organizations hope to receive from open source intelligence – or investigative due diligence – is the negative assurance that there are no deal breakers that would prevent a prospective relationship from moving forward. Where the value is really delivered though is in unearthing problems.  Prior knowledge of what the problems are enables an organization to make much more informed decisions about whether to move forward with a new customer, vendor, intermediary or venture partner.

You provide this service long enough and you will uncover some truly wild findings.  For me, these include the theft of two naval warships, the sale of salvaged military equipment to Saddam Hussein’s regime, a hedge fund manager who brandished a loaded shotgun at a coworker, an investment banking target who was indicted for money laundering while we were investigating him and a litigious landlord who had a prior conviction for murder for hire. Given the potential for this type of adverse finding – is not performing investigative due diligence even an option?

I discussed this and a number of other related topics with two experts in the performance of open source intelligence, Tanya Shelburne and Integrity Risk International CEO Jim McWeeney.

Tanya said that there are still very sophisticated companies and individuals who don’t quite understand open source intelligence, what it is and how best to utilize it. She elaborated that most everyone in business is performing some form of research. What she finds difficult is encouraging them to do the research to the level that they need to given the risks they are trying to mitigate. Internet research alone is not sufficient. Not by a long shot. If the stakes are high as they often are, you need seasoned professionals. And with the number of information sources growing every day, performing thorough and meaningful open source intelligence research is only getting more difficult. The challenge is convincing somebody that they need to do it to a different degree and explaining what they may be missing in the way they are doing their research.

Jim added that the combination of analytical subject matter expertise, artificial intelligence and internet research is what is necessary. The difference between raw research and open source intelligence is the critical thinking of the analyst who can present the findings in the context of the risks that the end user is trying to mitigate. And raw research alone doesn’t tell you whether you missed something.

Indeed, the Internet is a vast and incredibly valuable resource, but it’s not organized in the way that some of the other resources professional investigators utilize are organized. Another important consideration is there’s some critically important information that is sitting behind a paywall and not readily accessible.

Something else that bedevils consumers of open source intelligence is when there are an enormous number of counterparties. Very large organizations might have millions of customers, hundreds of thousands of vendors or tens of thousands or intermediaries, and that volume can be paralyzing. Jim provided some strategies that he’s seen organizations employ to stratify risk across large populations of counterparties and perform open source due diligence on a risk basis.

Jim said that rigorous FCPA enforcement and prevalence of bribe-paying intermediaries has forced organizations to step up their efforts at isolating high risk third parties and hold them to a heightened standard of care. They may have 30,000 or more counterparties with which they have to contend. It is a difficult but not impossible task.

It starts with asking the question, do you know how many counterparties you have and what have you done to assess them? If it’s a regulator posing the question and you don’t have a good answer, things do not go well from that point.

Don’t treat every third party the same. Instead, look across your third party population and risk rank them. Categorize each one, gauge your financial exposure to each, the revenue attached to that counterparty, what industry sector are they operating in and what role they will play. The most overused and yet still very important risk characteristic is geography. There are certain countries and regions around the world that are higher risk than others. Looking at these various risk criteria holistically will allow you to frame your risk-based approach and make what seemed unmanageable – manageable.

Once you have applied these risk criteria to your third party population, you can then bucket them as high, medium and low risk.  A best practice would then be perform a sanctions and watch list screen for all third parties. This is not expensive and there are tools that will enable you to run all of them at once. Where it can get difficult is when you have numerous hits and adverse findings, and you must adjudicate each one of them. This enables you to make the affirmative statement that you screened all of your third parties, even those designated as low risk.

For medium to high risk third parties – which typically make up between 10 and 15% of a population – a leading practice is to perform enhanced due diligence consisting of Open Source Intelligence, Human Intelligence or both. Having a documented, repeatable and consistently applied process in place will lower your susceptibility to third party risk and demonstrate to regulators that you have a robust and effective process in place.

We’re very fortunate here in the U.S. where we have access to vast amounts of open source data about individuals and entities spanning federal, state, and municipal public record repositories, media archives, and the internet. When you start venturing outside of the US however, open source resources tend to be an inch deep and a mile wide in some instances. And this dearth of reliable electronic data sources sometimes requires that we supplement those limited data sources by using human intelligence, HUMINT.

Tanya and Jim explained what is meant by the term human intelligence, how it’s performed and the steps practitioners take to feel comfortable that the human intelligence we’re receiving can be relied on.

Tanya said more and more information is becoming available outside of the U.S. This expansion of electronically available resources outside of the U.S. makes open source intelligence more of an option in parts of the world where it wasn’t that useful in the recent past. Tanya recently left the Department of Defense where she spent the past 14 years. While there, she had boots on the ground in every corner of the world. It helped drive home the point for her that HUMINT is incredibly important. She emphasized that HUMINT is just as important when working in the U.S. as it is overseas.

Tanya explained that HUMINT is speaking to well-placed human beings in a position to know information and provide it discretely. She highlighted how important it is to speak with a cross section of individuals. It is also important to understand why these individuals are willing to share information and whether they have an “axe to grind”.  There is no substitute for that dialogue with somebody. It’s very different than the lawsuit that you’re going to read. That’s much more sterile.

Jim added that he thinks of two things when it comes to human intelligence: candor and context. Jim added that some clients are skeptical about the value of human intelligence. There is certainly a great deal of value but it has to be carried out the right way and the sources need to be of known reliability. Human intelligence assets also have to be closely managed. There needs to be an upfront understanding about who they’re going to talk to, how they are going to do it, who is going to oversee the operation, and how it will be monitored. Human intelligence assets need to understand whether there are any restrictions such as prohibitions against speaking to current employees of a subject company or speaking directly to a subject.

Human intelligence is very valuable but use of it as an investigative resource comes with a word of caution. Human beings are always the wild card and you have to operate on the assumption that one or more of them might tell your subject about the existence of the investigation and the client has to be prepared for that possibility. Sometimes that’s a good thing, but it’s always an important conversation and understanding to have before you pull the trigger on human intelligence.

In recent years, the DOJ has published guidance on what comprises an effective compliance program. One often cited component of that guidance is the 10 hallmarks of what underlies an effective compliance program. Two of those hallmarks are very relevant to this discussion: mergers and acquisitions and third party due diligence and payments. I asked Jim and Tanya to explain where and how OSINT and HUMINT come into play in these two critically important areas.

Jim said that most investors know they need to do some sort of intelligence gathering but some may leave it to the last minute. The difference between OSINT and HUMINT is that if the target entity is not known to have any scandal or issues reported on in the media, they are probably a candidate for regular diligence. Other factors that support that decision are the business is located in low risk jurisdiction or industry sector. Under this scenario, “level 1 due diligence” is more than adequate. When that review is completed, if any red flags or issues are identified, the investigation can always be expanded to include human intelligence.

Other scenarios suggest the need to include HUMINT at the outset. For example, if you’ve got a subject company or an executive known to have some prior issues reported in the media, allegations, or other problems that were revealed during initial research or they’re in a high risk jurisdiction or sector, the gold standard is to include HUMINT as part of the initial scope. Some countries automatically trigger the need for HUMINT including China, Russia (before the Ukraine invasion) and other opaque jurisdictions like Mexico, Nigeria, Saudi Arabia and most of the Commonwealth of Independent States comprising the former Soviet Union.

The conversation moved to whether prospective business partners should be told upfront that they plan on investigating them. There are two schools of thought. Telling them gives them an opportunity to disclose things preemptively.  That’s actually a very good sign when a prospective business partner “owns” a problem or issue by disclosing it.

Jim agreed telling the client of the existence of the investigation is critically important if the scope includes HUMINT since there’s a chance one or more of the sources may tell the subjects about the investigation. Jim explained that OSINT is a little bit different where he sees a mix. The higher level the executive, the less they want to fill out a one page form.

In recent years, social media and deep web research has been added to the scope of open source research. Jim and Tanya discussed the benefits and shared some words of caution.

They are both big believers in including that research upfront. Social media research goes hand in hand with public records and media research. You find things in social media and in the business media that then prompts you go back into public filings and perform additional research based on that information. It can be very voluminous and there’s a lot of noise out there. And there are many social media platforms to look at. And all of that increases the amount of time it takes to complete an investigation. Overlaying social media on top of the somewhat dry litigation or business filings research brings the product to life.

Some consumers of investigative due diligence struggle with “what do I do with this stuff?”  Some of the investigative findings are self-explanatory, and others cause people wonder what to do next. For recurring users of open source and human intelligence, its advisable for them to have a review protocol. This would include guidance as to how to respond to certain findings and list out those that require input from the general counsel or chief compliance officer and the steps one should consider to gather additional information and ultimately, use the information to make the decision whether to onboard the third party, exit the relationship or onboard them if certain conditions or restrictions are met.

Open Source and Human Intelligence are both the sword and the shield when it comes to safeguarding your organization from a wide range of potential risks posed by customers, third parties and acquisition targets. Have a thoughtful approach to evaluating these counterparties, make strategic use of open source and human intelligence, use professional investigators and apply the approach consistently. And be prepared to walk away from a relationship whenever the findings suggest that they are not the right partner.

To listen to the entire conversation with Tanya Shelburne and Jim McWeeney, click here.

Read Also

Read More
Read More
Read More

Leave a Reply

Discover more from White Collar Forensic

Subscribe now to keep reading and get access to the full archive.

Continue reading