Corruption & Governance: Mission Domain Intelligence Guide
Grand corruption almost never appears in a budget line. It appears as a contract awarded in nineteen days to a company incorporated twenty-three days earlier, owned by someone who shares a surname with the awarding official.
Grand corruption almost never appears in a budget line. It appears as a contract awarded in nineteen days to a company incorporated twenty-three days earlier, owned by someone who shares a surname with the awarding official.
What Corruption & Governance covers as a mission domain
Corruption and governance intelligence covers the abuse of entrusted power for private gain and the institutional conditions that permit it. It spans bribery of officials, procurement rigging and collusive bidding, state capture through licensing and regulatory decisions, embezzlement of public funds, illicit enrichment, conflict of interest and revolving-door appointments, judicial and law enforcement corruption, and political finance abuse. Analysts combine procurement data, corporate ownership, asset declarations, court records and financial tracing to move from a suspicious award to documented evidence of the benefit received and by whom.
The field distinguishes petty corruption at the service-delivery level from grand corruption, where the scale is fiscally significant and the perpetrators control the institutions meant to investigate them. A separate strand is transnational bribery, where companies pay officials abroad, governed by the FCPA, the UK Bribery Act and the OECD Convention. Enablers include local agents and intermediaries, law firms, banks and the offshore structures used to hold and disguise the proceeds.
Why it matters
Corruption diverts money from health, education and infrastructure into private hands, and it kills through unbuilt clinics, uninspected buildings and unqualified contractors. It entrenches inequality, distorts elections and drives emigration by people who see no prospect of fairness. For companies, bribery exposure brings criminal liability, debarment from public contracting and multi-year monitorships. For investigators, corruption is also the mechanism that protects every other criminal economy from enforcement.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Tenders with unusually short bidding windows, hyper-specific technical requirements, or repeated single-bid awards to the same supplier.
- Winning bidders incorporated shortly before the tender, with no prior contract history and minimal declared staff or assets.
- Losing bidders sharing directors, addresses, bank details or sequential document metadata with the winner, indicating cover bidding.
- Contract values amended upwards by large margins after award, or work split into lots that fall just below competitive thresholds.
- Officials' declared assets diverging from observable lifestyle, property records or family members' sudden acquisition of businesses.
- Local agents appointed with vague scopes of work and success fees wholly disproportionate to any identifiable deliverable.
- Regulatory or licensing decisions that reverse published technical advice in favour of a single connected beneficiary.
- Rapid post-office employment of a former official by the company or sector they previously regulated or awarded contracts to.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- Transparency International CPI and national chapters — Comparative perception scoring and country-level research used to frame baseline risk and prioritise.
- World Bank Listing of Ineligible Firms — Debarred companies and individuals with the sanctionable practice and debarment period identified.
- OECD Anti-Bribery Convention monitoring reports — Country enforcement assessments and case summaries covering transnational bribery.
- Open Contracting Data Standard portals and national e-procurement systems — Tender, award and contract data structured for systematic red-flag analytics.
- OpenCorporates, OpenOwnership and asset declaration registries — Company ownership and official wealth disclosures supporting conflict-of-interest analysis.
- ICIJ investigations and leak databases — Documented offshore holdings connected to politically exposed persons and their associates.
- Stanford FCPA Clearinghouse and DOJ or SEC enforcement records — Case-level detail on bribery schemes, intermediaries and settlement terms.
- UNCAC implementation reviews — Country legal frameworks and identified gaps in criminalisation, asset recovery and mutual legal assistance.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Frame the decision under scrutiny — Identify the specific discretionary act, whether an award, licence, permit, appointment or waiver, and who legally controlled it.
- Reconstruct the process — Obtain tender documents, evaluation records, timelines and amendments, then compare them against the applicable procurement rules.
- Red-flag the whole bidder field — Test all participants, not only the winner, for shared control, sequential registration and classic cover-bidding patterns.
- Resolve beneficial ownership — Identify the natural persons behind the winner and any intermediaries, and establish their relationships to the decision-makers.
- Trace the benefit — Follow both money and non-cash benefits: property, tuition, employment for relatives, shareholdings and settlement of personal debts.
- Test the institutional response — Establish whether oversight bodies acted, and document interference, dismissals or unexplained case closures as evidence in themselves.
- Publish or refer safely — Prepare a package for prosecutors, audit institutions, donors or publication, with right of reply and source protection built in.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Government Intelligence — Government Structures, Policy, and Officials
- Financial Intelligence — Following Value Through the Financial System
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- News Intelligence — Media Reporting as an Intelligence Source
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Open Source Intelligence — Publicly Available Information, Systematically Collected
Worked in these data points
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Corporate Filing — A regulatory or corporate filing (SEC, Companies House, court).
- Real Property / Parcel — A land or building record — deeds, title, valuation, and ownership history.
- Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
- Bank Account / IBAN — A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
- Sanction / Watchlist Entry — An entry on a sanctions list, watchlist, or PEP database.
Adjacent mission domains
- Anti-Money Laundering
- Financial Crime
- Organized Crime
- Election Security & PSYOP
- Mining & Resource Crime
- Forced Labour & Modern Slavery
Inside the platform: where Corruption & Governance lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=corruption— Corruption & Governance dashboardtheater.php?d=corruption— Threat theater viewsearch.php— Person / Name profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Corruption & Governance:
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Score Country Risk
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Frame the decision under scrutiny is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Red-flag the whole bidder field turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Publish or refer safely feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Corruption & Governance
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Corruption analysis supports contracting integrity, host-nation partner assessment and mission effectiveness. Assistance delivered through a captured procurement system converts into leakage, ghost soldiers and unserviceable equipment, so assessment of a partner force's financial management is directly relevant to operational planning. Products feed contract award decisions, security force assistance design and reporting on partner reliability. On deployment, procurement and local contracting are themselves major corruption vectors requiring internal controls. Constraints include the diplomatic sensitivity of assessments about a host government, the need to route allegations through the appropriate investigative body, and the reality that anti-corruption findings may conflict with short-term operational relationships.
🕵 National intelligence
National services analyse grand corruption as a governance, influence and vulnerability question: which officials are capturable, which networks control state resources, and how illicit wealth creates leverage. Requirements ask who benefits, through which structures, and where the proceeds are held. Fusion combines procurement records, corporate registries, asset declarations, financial intelligence and human reporting. Handling must accommodate that the subjects are often serving officials in partner states, so dissemination carries diplomatic consequences and requires policy clearance. Outputs support sanctions designation under human rights and anti-corruption authorities, visa restrictions and assessment of a state's susceptibility to external influence.
👮 Law enforcement
Investigations require proof of the improper benefit and the connection to an official act. Evidence comes from procurement files, bank records, corporate documents, asset registers, travel records and communications, most of it requiring production orders and cross-border assistance. Foreign bribery cases add jurisdictional complexity and depend heavily on corporate cooperation and self-reporting. Immunities, statutes of limitation and the political position of the subject shape what is achievable. Charging often proceeds on money laundering or tax offences, which are documented, rather than on the bribery itself, which usually is not. Asset recovery runs in parallel and requires early restraint.
🔍 Private investigation and corporate security
Private work covers anti-bribery due diligence on agents and joint venture partners, transaction diligence, internal investigations and support to self-reporting decisions. The deliverable identifies specific red flags, meaning politically exposed connections, unexplained intermediaries, disproportionate commissions and irregular payments, with the evidence behind each. A private actor may not pay for information from officials, obtain bank data by pretext, or conduct surveillance on public figures unlawfully. Where an investigation identifies a probable offence, the decision on self-reporting is legal and must be taken with counsel, and the investigation should be structured to preserve privilege where that is intended.
📰 Journalism and OSINT media
Corruption reporting is document-driven: procurement notices, contracts, company filings, asset declarations, land registries, court records and, where lawfully obtained, leaks. Corroborate ownership links with at least two independent sources, since name coincidence is common and defamation exposure is severe. Distinguish clearly between a documented conflict of interest and proven corruption. Protect sources absolutely, since whistleblowers in this field face prosecution, dismissal and violence. Provide detailed right of reply with adequate time. Expect legal intimidation and coordinated smear campaigns, and secure pre-publication legal review and personal security planning for the reporting team.
🌍 NGO, humanitarian and human rights
Anti-corruption organisations document cases, support victims of state capture, campaign for transparency reform and drive asset recovery for affected populations. Documentation should be built to standards usable by prosecutors, sanctions authorities and courts, with provenance for every document. Do-no-harm requires assessing retaliation risk to local partners and sources before publication, and recognising that naming officials in some jurisdictions invites violence rather than due process. Duty of care includes legal support, digital security and physical security planning for staff, since organisations in this field are systematically targeted with surveillance, litigation and criminal charges.
🎓 University and research
Research spans political economy, public procurement analysis, network analysis of elite structures and evaluation of anti-corruption interventions. Methodology has improved substantially with open procurement data, allowing quantitative detection of single-bidder patterns, award timing anomalies and supplier concentration, all reproducible. Perception indices remain useful for cross-country comparison but should not be used as outcome measures for interventions. Ethics approval is essential for fieldwork where respondents face retaliation, with strong anonymisation. Reproducibility is served by publishing procurement data cleaning and entity resolution code, which is where most methodological disagreement in this field actually lies.
Playbook: working Corruption & Governance end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Frame the specific allegation
Reduce a general suspicion to a testable proposition: this contract was awarded improperly, this official received a benefit, this licence decision favoured a connected party. Identify the decision, the decision maker, the beneficiary and the claimed impropriety. Output is a hypothesis with the evidence that would confirm or refute it. Stop when the question is narrow enough that specific documents would answer it.
Phase 2 — Assemble the procurement or decision record
Obtain the tender notice, specification, bid list, evaluation record, award notice, contract, variations and payment record, using freedom of information routes where necessary. The anomalies are usually in the procedural detail: compressed timelines, restrictive specifications, single bidder outcomes, repeated variations and awards just below thresholds requiring scrutiny. Stop when you can reconstruct the decision timeline day by day.
Phase 3 — Resolve the beneficiary
Take the winning entity through registries: incorporation date relative to award, officers, shareholders, beneficial owners, addresses and other contracts held. Newly incorporated entities, shared addresses with other bidders and directors connected to the awarding body are the recurring findings. Output is an ownership picture with sources. Stop when you reach natural persons or document precisely where the chain breaks.
Phase 4 — Map the relationship to the official
Establish the connection between decision maker and beneficiary: family relationships, prior business associations, shared addresses, co-directorships, social connections evidenced publicly, and post-employment moves. Asset and interest declarations, where they exist, are the highest-value source and are frequently unchecked by anyone. Stop when the relationship is documented rather than inferred from a shared surname.
Phase 5 — Test for the benefit
Identify what the official received: payments, property, education fees for family, employment for relatives, shares, loans on non-commercial terms, or post-office employment. Compare declared income and assets against observable lifestyle and property holdings. Illicit enrichment analysis, where the offence exists, can proceed on the disproportion alone. Output is a benefit assessment with the documentary basis for each element.
Phase 6 — Trace the proceeds
Follow the money outward: intermediary companies, consultancy agreements, offshore vehicles, real estate, and the professional enablers who constructed the route. Property registries in destination countries are often the most productive source, since assets are held in the family name or through a structure that leaves a registry trace. Stop when you can name the holding structure and the jurisdiction of each significant asset.
Phase 7 — Establish the pattern
Test whether this is an isolated award or a system: examine the awarding body's full contract history for concentration, repeated winners, consistent single-bidder outcomes and timing patterns around political events. Systemic findings are more robust, harder to explain away and more likely to drive institutional response than a single contract, however egregious.
Phase 8 — Quantify the harm
Establish what was lost: price inflation against market benchmarks, undelivered goods or services, and the consequence for the affected population, such as a hospital not built or medicines not delivered. Corruption findings without harm quantification rarely move political decisions. Stop when the loss estimate has a stated method and would survive challenge.
Phase 9 — Assess the transnational dimension
Determine whether foreign bribery statutes are engaged, whether proceeds moved through jurisdictions with enforcement capacity, and which foreign professionals and institutions facilitated the structure. This frequently opens enforcement routes unavailable domestically, particularly where the domestic institutions are themselves captured. Output is a jurisdictional analysis naming the available authorities.
Phase 10 — Verify before exposure
Re-examine every link for alternative explanations, confirm identity matches with more than one identifier, and put the specific allegations to every named party with adequate time to respond. Responses frequently change the analysis. This step is both an accuracy control and the legal protection for what follows, and skipping it is how well-founded investigations become defamation cases.
Phase 11 — Route to the right authority
Match findings to the instrument: domestic prosecution, foreign bribery referral, sanctions designation under anti-corruption or human rights authorities, visa restriction, asset freezing and recovery proceedings, multilateral development bank debarment, or publication. Where domestic institutions are captured, foreign and multilateral routes are the realistic options. Output is a tailored package per route.
Phase 12 — Support recovery and reform
Follow through on asset recovery, which is slow, and on the institutional changes that would prevent recurrence: procurement transparency, beneficial ownership disclosure, asset declaration verification and audit independence. Individual cases without systemic change simply rotate the beneficiaries. Stop when the reform recommendations are held by an institution with the power to implement them.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Transparency International research and indices | Open | Corruption Perceptions Index, bribe payers research, national chapter investigations and policy analysis. | Provides comparative country context and locates national partners with jurisdiction-specific expertise. |
| OECD anti-bribery framework and monitoring | Open | Anti-Bribery Convention, country monitoring reports and typology work on foreign bribery enforcement. | Establishes the transnational bribery legal framework and each state's actual enforcement record. |
| UNODC and UNCAC resources | Open | UN Convention against Corruption, implementation review reports and technical guidance for states parties. | Supplies the international legal basis and the implementation gaps in a specific country's framework. |
| StAR Initiative | Open | Stolen Asset Recovery Initiative guidance and case data on tracing and recovering proceeds of corruption. | Provides practical asset recovery methodology and precedent for cross-border restraint and confiscation. |
| TED European public procurement notices | Open | EU tender and award notices with contracting authority, value, procedure type and winning supplier detail. | Enables systematic detection of single-bidder awards, compressed timelines and supplier concentration in the EU. |
| Open Contracting Partnership and OCDS data | Open | Data standard and country implementations publishing structured procurement data across the contracting cycle. | Supports quantitative red flag analysis on award patterns where national data is published to the standard. |
| OCCRP and Aleph | Registration | Investigative reporting network with a cross-searchable archive of registries, leaks and court documents. | Finds prior documented links between officials, companies and intermediaries across multiple jurisdictions. |
| ICIJ investigations and Offshore Leaks | Open | Cross-border investigative projects and a searchable database of offshore entities and their officers. | Identifies offshore structures holding assets for politically exposed persons and the agents who formed them. |
| OpenCorporates | Registration | Company registry aggregation with officers, addresses and filings across many jurisdictions. | Resolves contract winners, tests incorporation dates against award dates and detects shared officers between bidders. |
| OpenOwnership | Open | Standardised beneficial ownership data aggregated from participating national registers. | Establishes declared beneficial owners of contracting entities and inconsistencies between national declarations. |
| World Bank sanctions and debarment records | Open | List of firms and individuals debarred or otherwise sanctioned for fraud and corruption in bank-financed projects. | Checks whether a contractor has been debarred by a multilateral development bank and for what conduct. |
| US Department of Justice FCPA enforcement records | Open | Charging documents, deferred prosecution agreements and declinations in foreign bribery matters. | Supplies documented bribery mechanics, intermediary structures and the evidential standard applied in practice. |
| UK Serious Fraud Office case records | Open | Published investigations and outcomes in bribery and corruption cases including deferred prosecution agreements. | Provides UK precedent on corporate liability, self-reporting and the evidence relied on in bribery prosecutions. |
| EITI disclosures | Open | Standardised reporting on extractive licences, contracts, revenues and beneficial ownership in implementing countries. | Exposes licence awards and revenue flows in resource sectors where grand corruption concentrates. |
| U4 Anti-Corruption Resource Centre | Open | Applied research and practitioner guidance on corruption risks by sector and on intervention effectiveness. | Supplies sector-specific typologies and evidence on which anti-corruption measures actually work. |
| Land and property registries | Registration | Title, ownership and transaction records for real property in most destination jurisdictions. | Locates assets held by officials and their families abroad, frequently the most productive proceeds evidence. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Corruption & Governance. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Procurement red flag analysis scripts — Detect single-bidder awards, short deadlines, threshold avoidance and repeat winners across large datasets. Limitation: red flags indicate risk, not corruption, and require case-level verification.
- Aleph by OCCRP — Cross-searches registries, leaks and court records for entity and person mentions. Limitation: coverage and document dating are uneven, so every hit needs verification at source.
- Linkurious or Maltego — Graphs relationships between officials, companies, addresses and contracts. Limitation: encourages visual over-attribution when link confidence is not recorded separately.
- OpenRefine — Cleans and reconciles messy registry and procurement data, which is where most of the analytical work sits. Limitation: entity resolution decisions drive results and must be documented.
- OpenCorporates and registry APIs — Automates ownership and officer lookups across jurisdictions. Limitation: no beneficial ownership data in many of the jurisdictions that matter most.
- Freedom of information request management — Systematises document requests and tracks appeals across multiple bodies. Limitation: response times and exemptions frequently defeat time-sensitive investigations.
- Web archive services — Preserves tender notices, official biographies and company sites before they are altered or removed. Limitation: dynamic content and login-gated portals are poorly captured.
- Secure collaboration and document handling platforms — Protect sources and documents in teams working across hostile jurisdictions. Limitation: security depends on operational discipline, not the tool.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Score Country Risk — Recomputes country risk from the weighted inputs and snapshots the result so movement over time is measurable.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Incorporation date against award date is the highest-yield single check in the domain. A company formed weeks before winning a substantial contract, with no trading history and no relevant capacity, is a documented fact rather than an inference and it survives every rebuttal.
- Systemic patterns beat single cases. One suspicious award invites an explanation about exceptional urgency; a contracting authority with a consistent single-bidder rate and a concentrated supplier set produces a finding that no individual explanation can absorb.
- Asset declarations are under-exploited. Where they exist they are frequently published, rarely verified by anyone, and directly comparable against registries, property records and observable lifestyle, which makes them one of the few places where an official's own statement can be tested against documents.
- Distinguish conflict of interest from corruption in your language, always. Conflicts are documentable and frequently lawful if declared, and conflating the two is how credible investigations become defamation cases and how genuine findings get dismissed as overreach.
- Follow the professional enablers. Lawyers, formation agents, bankers and estate agents in destination jurisdictions build the same structures repeatedly, and they are subject to regulation, licensing and enforcement in ways that the official never is.
- Where domestic institutions are captured, the enforcement leverage sits abroad. Foreign bribery statutes, sanctions authorities, development bank debarment, visa restrictions and destination-country property law frequently offer routes that no domestic prosecutor can pursue.
- Quantify the human harm alongside the financial loss. A number for the stolen sum moves specialists; the undelivered hospital, the unpaid teachers or the collapsed bridge move political decisions, and both belong in the same product.
- Assume surveillance and litigation from the outset. Organisations working on grand corruption are systematically targeted with spyware, criminal complaints and coordinated smear campaigns, so digital security, legal preparation and source protection are operational requirements rather than good practice.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Corruption & Governance is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of investigated awards where the beneficiary is resolved to natural persons with documentary support, rather than left at corporate level.
- Number of findings routed to an authority with jurisdiction and capability, and the proportion that result in formal action.
- Value of assets restrained or recovered attributable to the analysis, tracked over multi-year horizons because recovery is slow.
- Change in single-bidder rate or supplier concentration at a targeted contracting authority following intervention.
- Proportion of published findings that survive legal challenge without correction, as a direct measure of verification discipline.
- Number of officials whose asset declarations have been substantively checked against independent records.
- Zero incidents of source exposure or unmanaged retaliation attributable to the organisation's handling of documents or publication.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Reading a single red flag as corruption, when procurement irregularity is common and the benefit itself must still be evidenced.
- Assuming perception indices measure actual corruption levels rather than expert and business sentiment about it.
- Ignoring that anti-corruption prosecutions are themselves sometimes instruments of political score-settling.
- Confusing legal conflict of interest with criminal bribery, when the standards, evidence and consequences differ substantially.
- Relying on asset declarations without checking whether relatives, nominees and trusts fall within the disclosure obligation at all.
Legal and ethical considerations
Corruption reporting exposes analysts and sources to litigation, prosecution and physical risk, particularly where the subject controls the courts. Apply a documented evidentiary standard, offer right of reply, and separate proven fact from reasonable inference in the text itself. Whistleblower protections vary widely and are often weak in practice, so assume a source can be identified from the material they supply and redact accordingly. Data from leaks may raise admissibility and data-protection issues, so corroborate from official records wherever possible.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Corruption & Governance, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
What is the single most productive dataset?
Public procurement records, where they are published in structured form. They contain the decision, the timeline, the value, the procedure used and the winner, which is almost everything needed to identify anomalies, and they can be analysed at scale rather than case by case. Combined with company registry data, they allow the incorporation-date-against-award-date test, supplier concentration analysis and detection of threshold avoidance. Where procurement data is not published, obtaining it through freedom of information becomes the investigation's first phase, and the refusal pattern itself is frequently informative.
Are red flags evidence?
No. Single-bidder awards, short deadlines, contract variations and newly formed suppliers all occur legitimately, particularly in emergencies and specialist markets. They identify where to look, not what happened. Treating them as findings produces false accusations and discredits the method for everyone. The correct sequence is to use red flags to prioritise, then obtain the underlying documents, resolve the beneficiary, establish the relationship to the decision maker and evidence the benefit. A report that publishes red flag scores as if they were conclusions will be dismantled by the first competent response.
How do you handle a case where the subject controls the police?
Shift the enforcement question abroad. Grand corruption almost always has a transnational footprint: proceeds held in foreign property, structures formed by foreign professionals, payments through foreign banks, and children educated abroad. That creates jurisdiction for foreign bribery statutes, anti-corruption sanctions and visa authorities, money laundering prosecutions in destination states, development bank debarment and civil recovery proceedings. Publication also functions as an accountability route where legal process cannot. Structure the evidence package from the outset for these external routes rather than for a domestic prosecutor who will not act.
Do perception indices measure corruption?
They measure perceptions, which is a legitimate and useful thing to measure, but they are frequently misused. They cannot show whether an intervention worked, because perceptions move with media coverage, political change and the salience of scandals rather than with underlying incidence, and an effective anti-corruption drive often makes perceptions worse by surfacing cases. For evaluation, use outcome measures grounded in data: single-bidder rates, price benchmarks against comparable contracts, procurement competitiveness, asset declaration compliance and prosecution outcomes. Use perception indices for cross-country context and long-run comparison, not as a programme metric.
How should conflicts of interest be reported?
Precisely and separately from allegations of corruption. State the relationship, the decision, whether declaration was required, whether it was made, and what the applicable rule says. A documented, undeclared conflict is a serious finding in its own right and is far easier to prove than bribery. Conflating it with an accusation of corruption weakens both, invites litigation and lets the subject dispute the strongest available claim by attacking the weakest. Journalists and analysts who maintain this distinction consistently find that their conflict findings drive institutional consequences even when the corruption case cannot be proved.
What protects an investigator working on grand corruption?
Preparation across three fronts. Legally, pre-publication review, documented verification, right of reply with adequate time, and access to counsel who will defend rather than dilute. Digitally, hardened devices, compartmented storage, secure source communication and awareness that commercial spyware is used against people doing this work. Physically, risk assessment, travel planning and an agreed protocol if contact is lost. Institutionally, an organisation prepared to absorb litigation and pressure rather than settle. Individual investigators without this structure are the ones who get hurt, and arranging it after publication is far too late.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- UN Convention against Corruption, the global framework covering prevention, criminalisation, international cooperation and asset recovery.
- OECD Anti-Bribery Convention, obliging parties to criminalise bribery of foreign public officials and subjecting them to peer monitoring.
- US Foreign Corrupt Practices Act, covering anti-bribery and books-and-records provisions with extraterritorial reach.
- UK Bribery Act, including the corporate offence of failing to prevent bribery and the adequate procedures defence.
- ISO 37001 anti-bribery management systems, the certifiable framework for organisational anti-bribery controls.
- Open Contracting Data Standard, defining structured publication of procurement information across the contracting cycle.
- FATF Recommendations on politically exposed persons and beneficial ownership, governing financial sector handling of corruption proceeds.
- Global Magnitsky-style sanctions authorities in the US, UK, EU and Canada, enabling designation for corruption and human rights abuse.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- UN Convention against Corruption and implementation reviews — UN Office on Drugs and Crime. The global anti-corruption treaty framework and country implementation assessments.
- Anti-Bribery Convention monitoring reports — OECD. Peer review of foreign bribery enforcement by each state party.
- Corruption Perceptions Index and research — Transparency International. Comparative country perception data and national chapter investigations.
- Asset recovery guidance and case studies — StAR Initiative, World Bank and UNODC. Practical methodology for tracing and recovering proceeds of corruption.
- FCPA enforcement actions — US Department of Justice. Charging documents detailing bribery mechanics and intermediary structures.
- Open Contracting Data Standard — Open Contracting Partnership. Structured procurement publication standard enabling systematic analysis.
- Cross-border corruption investigations — OCCRP. Documented investigative case work on elite networks and offshore structures.
- Debarment and sanctions decisions — World Bank Group. Records of firms sanctioned for fraud and corruption in financed projects.
- Applied anti-corruption research — U4 Anti-Corruption Resource Centre. Sector typologies and evidence on intervention effectiveness.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: joins procurement records, ownership data and official disclosures to surface the beneficiary behind a decision. Explore the platform, or browse the rest of the library by following any tag above.