August 7, 2026

Criminal Intelligence (CRIMINT): Intelligence Discipline Guide

0

Criminal intelligence is not case notes with better formatting. It is the discipline that turns scattered incidents into an articulable picture of who is offending, with whom, and what they will likely do next.

criminal-intelligence-intelligence-discipline-guide

Criminal intelligence is not case notes with better formatting. It is the discipline that turns scattered incidents into an articulable picture of who is offending, with whom, and what they will likely do next.

What Criminal Intelligence is as a discipline

Criminal intelligence is the systematic collection, evaluation and analysis of information about offenders, criminal groups and criminal series in support of investigation, disruption and prosecution. It works at three levels: tactical intelligence that directs an active operation, operational intelligence that maps a network or a crime series, and strategic intelligence that describes how a criminal market behaves over time. The practice is defined less by exotic sources than by rigorous handling: every item is graded for source reliability and content credibility, provenance is recorded, and inference is kept visibly separate from fact so a product survives disclosure and cross-examination.

Sub-methods include entity resolution across aliases and identifiers, association and network charting, crime pattern and series linkage, comparative case analysis, telephone and financial sequence-of-events reconstruction, and target profiling. In the intelligence cycle, criminal intelligence sits closest to the direction and dissemination ends: analysts negotiate requirements with an investigative lead, then produce products that trigger a decision, not products that merely inform.

Why it matters

Only criminal intelligence answers whether apparently separate offences are one enterprise, which individual is structurally load-bearing rather than merely visible, and where a network is brittle. It answers whether an arrest degrades capability or simply promotes a deputy. It distinguishes a crime spike caused by one prolific offender from one caused by market entry. It also answers the disclosure question investigators must eventually face: what do we actually know, how do we know it, and what can be evidenced in court.

What analysts actually look for

These are the concrete, observable signals that carry weight in this area of work:

  • Alias, date-of-birth and identifier clusters that resolve multiple record fragments to a single offender across jurisdictions and agencies
  • Co-arrest, co-defendant and co-location patterns that expose association strength far more reliably than self-declared social media links
  • Modus operandi features: entry method, tooling, timing windows, victim selection, language used, and post-offence disposal behaviour
  • Charging, plea and sentencing histories that reveal role, escalation trajectory and prior cooperation with authorities
  • Corporate and property records tying an individual to premises, vehicles and shell entities used for storage or laundering
  • Geographic and temporal clustering of incidents indicating territory, supply routes or a single travelling offender
  • Custodial and supervision status changes that correlate with the start or cessation of an offence series
  • Communication and transaction sequencing that establishes tasking direction and hierarchy within a group

Where the data comes from

Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:

  • CourtListener and RECAP — Free US federal and selected state dockets, opinions and filed exhibits, with alerts on new case activity
  • PACER — Authoritative US federal docket and filing text; paid per page but definitive for charging and case posture
  • FBI Crime Data Explorer and NIBRS — Incident-level US offence data for baselines, series context and strategic crime market analysis
  • State and county court and inmate roster portals — Charge histories, custody status, bond conditions and release dates that time-anchor offender activity
  • INTERPOL public notices — Wanted and missing person notices with identifiers, useful for cross-border alias and travel resolution
  • OFAC SDN and consolidated sanctions lists — Designated individuals and entities with aliases, addresses and identifier fragments for entity resolution
  • Europol and UNODC threat assessments — Strategic baselines on organised crime markets, routes and methods for framing local findings

A working method

A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:

  1. Fix the requirement — Agree with the investigative lead what decision the product must support, the deadline, and what would change the decision. Write it down before collecting anything.
  2. Build the entity spine — Resolve subjects to canonical entities using identifiers rather than names, recording every alias, date of birth variant and identifier with its source.
  3. Grade every item — Apply a source evaluation scheme to each piece of information, separating what is corroborated from what is single-sourced or reported hearsay.
  4. Chart associations and sequence — Build the network and a timeline in parallel. Structure without chronology hides tasking direction; chronology without structure hides who is peripheral.
  5. Test alternatives — State at least two competing explanations for the pattern and identify which observable would discriminate between them, then collect against that gap.
  6. Produce to the decision — Write the judgement first with a confidence level, then the supporting evidence, then explicit intelligence gaps and recommended collection.
  7. Handle and review — Apply handling and dissemination conditions, log the audit trail, and schedule review so stale intelligence is revalidated or purged.

How this connects across the intelligence taxonomy

Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.

Applied in these mission domains

Operates on these data points

  • Person / Name — A named individual — the subject of identity resolution and profiling.
  • Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
  • Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
  • Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
  • Company / Organization — A legal entity — corporation, LLC, NGO, or business.
  • Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
  • Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
  • Messaging Handle — An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
  • Phone Number — Telephone number for voice, SMS, or messaging identification.
  • Onion / Hidden Service — A Tor hidden service address on the dark web.

Related disciplines

Inside the platform: where Criminal Intelligence lives

The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.

The modules that matter most here:

Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.

Automation, playbooks and AI skills

Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.

AI skills that apply

The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:

  • Threat Hunt
  • Auto-Collect Feeds
  • Enrichment → Local
  • Summarise (Copilot)
  • Generate Report

Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.

Feeds, data sources and the API

The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.

Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:

STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.

That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.

Use cases

Three ways this entry earns its keep in day-to-day work:

  1. Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Fix the requirement is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
  2. Building the picture. A single indicator is rarely the story. Grade every item turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
  3. Producing something actionable. Analysis that ends in a document nobody can use is wasted. Handle and review feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.

Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.

How each sector uses Criminal Intelligence

The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.

🎖 Military and defence

In a military context criminal intelligence supports force protection, base security and counter-threat network work where crime and armed group financing overlap. The analyst maps local criminal actors, protection rackets, contract fraud around basing and logistics, and the overlap between criminal facilitators and insurgent supply. Products feed J2 threat assessments, IPB overlays of the human terrain, and vetting of local nationals and contractors. Constraints are significant: military analysts rarely hold police powers, host nation law governs any enforcement action, and criminal information about civilians must be handled under status of forces arrangements and national data rules. The correct output is usually a referral and a risk picture, not a target.

🕵 National intelligence

National intelligence uses criminal intelligence where organised crime intersects state interests: sanctions evasion, procurement networks, corruption of officials, and criminal groups used as proxies. Collection is requirements-driven and fused with financial, communications and diplomatic reporting, so the criminal picture becomes one strand of an all-source assessment rather than a standalone case file. Handling is the hard part. Material sourced from police holdings carries originator control and downstream disclosure risk in any future prosecution, so classification and caveating must be decided at the point of receipt. Dissemination back to law enforcement requires a route that preserves both source protection and the prospect of a viable case.

👮 Law enforcement

This is the discipline's home ground. Criminal intelligence directs proactive investigation, prioritises subjects, and supports charging decisions by showing the enterprise behind individual offences. Every item must be graded for source reliability and information credibility, retained only where a documented suspicion basis exists, and reviewed on schedule. Intelligence products are not evidence: material intended to reach court needs continuity, exhibit numbering and a lawful acquisition route such as a production order, warrant or mutual legal assistance request. Analysts must keep the sanitised intelligence stream and the evidential stream visibly separate, and anticipate disclosure obligations, because an undisclosed intelligence trail can collapse a prosecution years later.

🔍 Private investigation and corporate security

Corporate investigators use criminal intelligence method for pre-employment and counterparty due diligence, insider threat triage, fraud and asset recovery, and litigation support. The method transfers cleanly: entity resolution, association mapping and chronology building work the same way on public records. The limits do not transfer. A private actor has no access to police intelligence systems, cannot lawfully obtain criminal record data outside statutory disclosure schemes, must not pretext for information, and cannot conduct surveillance that would amount to harassment. Findings that indicate serious criminality should be referred to police or a regulator rather than acted on unilaterally, and clients must be told when a matter has crossed that line.

📰 Journalism and OSINT media

Journalists apply criminal intelligence method when reconstructing a network from court records, sanctions listings and corporate filings. The verification standard is higher than an investigator's, because publication is irreversible: every assertion needs a document a reader could in principle inspect, and single-source police briefings should be treated as claims about what police believe rather than facts. Named individuals who have not been convicted require careful framing, a genuine right of reply with adequate time to respond, and awareness of contempt and reporting restrictions where proceedings are active. Source protection matters especially with police and prosecution sources, who face disciplinary and criminal exposure for unauthorised disclosure.

🌍 NGO, humanitarian and human rights

NGOs use criminal intelligence method to document trafficking, forced labour, illicit extraction and predatory networks for advocacy and accountability. Practice must be victim-centred: identifying information about victims and witnesses should be minimised, stored encrypted and separated from analytical products, and consent should be informed and revocable. Do no harm governs publication timing, because naming a network before survivors are safe can trigger retaliation. Documentation should be built to a standard a prosecutor or a UN mechanism could use later, with provenance and chain of custody, even where no prosecution is envisaged. Staff exposed to offender material need vetting, supervision and structured psychological support.

🎓 University and research

Researchers use criminal intelligence method to study offending networks, crime markets and the effectiveness of disruption. Methodological discipline centres on the sampling bias built into official records: arrest and conviction data measure enforcement attention as much as offending. Ethics approval is required for any work involving identifiable offenders, victims or police holdings, and data-sharing agreements with agencies typically constrain publication, so negotiate release terms before collection. Reproducibility demands published coding schemes for network ties and offence classification, since association coding decisions drive most results. Cite the record version and extraction date, and archive derived, de-identified datasets rather than raw personal data.

Playbook: working Criminal Intelligence end to end

A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.

Phase 1 — Requirement and decision framing

Sit with the investigative or executive lead and write down the decision the product must support, the deadline, and what evidence would change the decision either way. Record any legal constraint on how the answer may be used. A good output is a one-page terms of reference naming the customer, the question, the decision point and the prohibited uses. Stop when the customer agrees the question as written; if they cannot state a decision, the request is a browse and should be declined or reframed.

Phase 2 — Legal and handling baseline

Before collection, establish which regime governs the data you will touch: police data protection rules, criminal intelligence file standards, contractual limits on commercial databases, and any originator caveats on material already held. Decide the handling code, retention period and review date at the outset rather than retrofitting them. A good output is a documented lawful basis per source category and a named reviewing officer. Stop when you can say, for every intended source, who may see the resulting product and for how long you may keep it.

Phase 3 — Entity spine construction

Build a canonical entity list before any analysis. Resolve people on identifiers and identifier fragments rather than name strings, recording each alias, date of birth variant, address, phone, account and vehicle with its source and date. Do the same for companies and premises. A good output is an entity table where every attribute traces to a record and every merge decision is logged with the evidence that justified it. Stop merging when the next candidate link rests only on name similarity, and record it as an unresolved possible identity instead.

Phase 4 — Source grading and provenance

Grade every item for source reliability and information credibility using a documented scheme, and record how the item reached you. Separate what you observed, what a named record states, what a human source reported and what an analyst inferred. A good output is a source register in which no analytical claim traces to an ungraded item. Stop treating an item as corroborated when the supposed second source turns out to derive from the first, which is the most common failure in this step.

Phase 5 — Association and network charting

Chart relationships with typed, dated and weighted edges: co-arrest, co-defendant, co-location, familial, financial, communication. Avoid undifferentiated link charts where a family tie and a single co-sighting look identical. A good output is a network in which centrality claims survive removal of the weakest evidence tier, and in which every edge carries a source reference. Stop expanding when new nodes stop changing structural conclusions, not when you run out of records or the product becomes an unreadable hairball.

Phase 6 — Chronology and sequence reconstruction

Build a timeline in parallel with the network, placing offences, communications, movements, financial events and custody status changes on one axis. Sequence is what exposes tasking direction and hierarchy: who moves before whom, and whose absence stops activity. A good output is a chronology with explicit time zones, a source per event, and gaps marked as gaps rather than silently closed. Stop when the timeline can answer whether a candidate principal was actually available and active during the key periods.

Phase 7 — Series linkage and comparative case analysis

Test whether apparently separate offences form a series using behavioural features that are discretionary rather than dictated by the situation: approach, language used, tool choice, victim selection, post-offence behaviour. Weight rare features heavily and common features hardly at all. A good output is a linkage judgement with a stated confidence and the specific features supporting it. Stop and reconsider if linkage rests on features most offenders in that offence type would display, which is how base rate error enters.

Phase 8 — Alternative hypotheses and discriminating collection

State at least two competing explanations for the pattern, including the mundane one, and identify for each the observable that would discriminate between them. Then task collection against that observable specifically rather than gathering more of what you already have. A good output is a short hypothesis matrix with a named diagnostic indicator per hypothesis. Stop collecting when the diagnostic indicator is either obtained or shown to be unobtainable, and record the latter as a standing intelligence gap.

Phase 9 — Vulnerability and disruption assessment

Assess where the network is brittle rather than where it is visible. Identify functions that cannot be quickly replaced: a specific corrupt insider, a single laundering channel, a technical specialist, an access holder at a port or a licence. Model the likely consequence of removing each, including displacement and succession. A good output is a ranked set of disruption options with predicted effect and predicted adaptation. Stop short of recommending tactics you cannot legally support; the analyst names the pressure point, the operational lead chooses the method.

Phase 10 — Product build and dissemination

Write the judgement first with an explicit confidence level and the reason for that confidence, then the supporting evidence, then the gaps and recommended collection. Apply handling conditions and dissemination limits inside the document, not just in the covering email. A good output is readable by the decision maker in five minutes and defensible in a disclosure hearing in five years. Stop before adding material that is interesting but does not bear on the decision, because volume erodes the credibility of the judgement.

Phase 11 — Evidential handover and disclosure preparation

Where intelligence is to become evidence, identify the lawful route to acquire the same fact evidentially: production order, warrant, witness statement, mutual legal assistance. Never launder intelligence into an exhibit. Maintain a disclosure schedule listing intelligence material, its sensitivity and any application to withhold. A good output is a package a disclosure officer can review without needing the analyst present. Stop and take legal advice whenever protecting a source appears to conflict with the defendant's right to a fair trial.

Phase 12 — Review, revalidation and purge

Schedule review of every retained record against the original suspicion basis. Revalidate what remains necessary, downgrade what has decayed, and purge what no longer meets the threshold, recording the decision and its author. Feed back to collection whether the product changed a decision. A good output is an audit trail showing that retention is a decision someone made rather than a default. Stop retaining any person record where you can no longer articulate why the individual is of intelligence interest today.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

Source register: what to collect from, and how

Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.

Source Access What it gives you How it is used here
CourtListener and the RECAP Archive Open Free US federal and selected state dockets, opinions and user-contributed PACER filings with full text search and docket alerts Establishes charging history, co-defendant sets and case posture, and surfaces exhibits naming associates and premises
PACER Registration Authoritative US federal docket sheets and filed documents across district, bankruptcy and appellate courts, billed per page Definitive confirmation of charges, superseding indictments, plea agreements and cooperation indicators that anchor role assessment
FBI Crime Data Explorer and NIBRS Open Incident-level US offence, arrest and clearance data with offender, victim and property segments where agencies report Builds offence baselines so a spike can be attributed to a prolific offender, a new entrant or changed recording practice
Bureau of Justice Statistics Open US national statistics on offending, victimisation, corrections and case processing including the National Crime Victimization Survey Supplies base rates that keep series linkage and offender projections honest against police-recorded crime alone
INTERPOL notices and databases Open Public red, yellow and other notices carrying names, aliases, identifiers and offence summaries, plus member country channels Cross-border alias and identity resolution, and a lawful route to request checks through the national central bureau
Europol threat assessments and analysis products Open SOCTA, IOCTA and thematic reports describing EU criminal market structure, methods and network typologies Provides typologies to test a local network against, and strategic context for market entry and displacement judgements
UNODC data and threat assessments Open Global crime, drug and trafficking statistics and regional assessments including transnational organised crime studies Frames a domestic series against global market conditions, supply route shifts and pricing changes
OFAC SDN and consolidated sanctions lists Open Designated individuals and entities with aliases, dates of birth, passport fragments, addresses and vessel identifiers Entity resolution fuel and an immediate flag when a subject or associate is already designated
OpenSanctions Open Consolidated global sanctions, politically exposed person and watchlist data with entity reconciliation and bulk exports Single query across dozens of national lists during entity resolution, with source attribution retained per record
OpenCorporates Registration Aggregated company registry data across jurisdictions covering officers, addresses, status and filing history Links offenders to premises, shell entities and co-directors, exposing shared addresses and repeated nominee use
OCCRP Aleph Registration Searchable archive of leaks, registries, court records and procurement data indexed for cross-document entity search Finds an entity across document sets an analyst would not otherwise know to query individually
National Center for State Courts court record guidance Open Directory and guidance on US state and county court record systems, access rules and online availability Identifies which local court and custody records exist for a jurisdiction before a manual sweep
College of Policing authorised professional practice Open UK national guidance on intelligence management, source evaluation, tasking and coordination and product standards Standard template for structuring products and tasking cycles that partner agencies will recognise
Bureau of Justice Assistance criminal intelligence guidance Open US criminal intelligence systems operating policy material covering submission criteria, review, purge and dissemination Authoritative test for whether a person record may lawfully be retained in a criminal intelligence file
ACLED political and criminal violence event data Registration Geocoded, dated violence event data with actor coding and source citations covering many fragile jurisdictions Geographic and temporal clustering of violent events attributable to specific criminal actors abroad

Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.

Tooling

Tools commonly used against Criminal Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.

  • IBM i2 Analyst's Notebook — Long-standing link and timeline charting used across police agencies; powerful for evidential charts, but licence cost and file-based working hinder collaboration.
  • Maltego — Graph exploration with transforms across open and commercial data; fast for lead generation, but transform provenance must be recorded manually for evidential use.
  • Neo4j and Cypher — Graph database for large typed association networks queried at scale; requires schema discipline and offers no built-in source grading.
  • Gephi — Open-source network visualisation with betweenness and community detection; excellent for exploration, weak for producing court-ready exhibits.
  • OpenRefine — Reconciliation and clustering of messy identity data before entity resolution; effective on name variants but single-user and not audit-logged by default.
  • Aeon Timeline or equivalent chronology tools — Builds dated event sequences linked to entities; useful for chronology products, though time zone and precision handling must be enforced by the analyst.
  • QGIS — Open-source mapping for hot spot, journey-to-crime and territory analysis; strong analytically but demands care with population and exposure normalisation.
  • Hunchly — Captures web pages with hashes and timestamps during online research; preserves provenance for later disclosure, limited to browser-visible material.
  • Structured analytic technique templates — Analysis of competing hypotheses and key assumptions check matrices; cheap and effective, but only if completed before the judgement is drafted.

AI skills and automation in detail

These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.

  • Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
  • Auto-Collect Feeds — Pulls the registered feed set server-side on a schedule, recording per-feed status so a silently dead feed is visible.
  • Enrichment → Local — Materialises enrichment into the local store so dashboards render from your own database instead of a live third-party call.
  • Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
  • Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.

A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • Corroboration means an independent origin, not a second appearance. Two databases fed by the same original report are one source. Trace each item to its origin before calling anything confirmed, because circular reporting is the commonest cause of confident error.
  • Visibility is not centrality. The person appearing in most reports is often the one taking the most operational risk, not the one directing. Test candidate principals by whether activity pauses while they are in custody, not by how many edges they hold.
  • Grade the information, not the person. A generally unreliable source can provide a specifically verifiable fact, and a normally reliable one can pass on hearsay. Splitting source reliability from information credibility is what makes a grading scheme worth using.
  • Absence in a record set is rarely absence in reality. Before treating a gap as meaningful, establish whether the agency records that category at all, whether the record is delayed, and whether the subject simply operates outside that reporting system.
  • Write the disclosure position while you write the product. Deciding years later what was intelligence and what became evidence is how cases collapse. Mark sensitivity, source protection needs and evidential routes at the moment of creation.
  • Beware the promoted deputy. Removing a leader frequently produces a short violence spike and a more capable successor. A disruption recommendation should predict succession and displacement explicitly, or it is a tactical suggestion dressed as analysis.
  • Behavioural linkage should rest on discretionary features. Anything the situation forces the offender to do carries little discriminating power. Rare, chosen behaviours such as specific language, sequencing or post-offence conduct actually distinguish a series.

Measuring whether it is working

Capability claims should be falsifiable. These are the measures that show whether work on Criminal Intelligence is producing anything, and they are worth baselining before you change process or tooling.

  • Proportion of intelligence products cited in a documented operational decision, tasking or charging decision, rather than filed and never referenced again.
  • Time from requirement agreed to product delivered, tracked against the decision deadline, with the percentage delivered after the decision point reported separately.
  • Entity resolution accuracy measured by later-discovered false merges and missed merges per hundred subjects, sampled through independent review.
  • Share of retained person records that pass scheduled review with an articulable current suspicion basis, and the volume purged as a result.
  • Post-disruption assessment completed within an agreed window for each major operation, recording whether predicted succession and displacement effects occurred.
  • Number of disclosure challenges or adverse judicial comments arising from intelligence handling, tracked as a defect measure rather than an activity measure.
  • Analyst-identified intelligence gaps that were subsequently tasked and answered, expressed as a proportion of all gaps recorded in delivered products.

Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.

Common pitfalls

  • Treating an intelligence product as evidence. Graded intelligence supports direction and decisions; it must be independently evidenced before it reaches a courtroom
  • Name-based matching that merges two people with common names, contaminating an entire network chart and every downstream judgement
  • Confusing visibility with importance: the loudest or most-arrested subject is frequently expendable rather than structurally central
  • Circular reporting, where the same original claim re-enters the file through three agencies and is mistaken for corroboration
  • Letting an investigative hypothesis drive collection so tightly that disconfirming information is never sought or recorded
  • Retaining personal data beyond its lawful review period, which risks both legal exposure and decisions based on stale relationships

Legal and ethical considerations

Criminal intelligence handling is tightly regulated. Retention, sharing and review of personal data are governed by law enforcement data protection regimes, and in many jurisdictions by specific criminal intelligence file standards requiring a documented reasonable suspicion basis for retention. Products carry handling conditions that bind onward disclosure. Anything that may become evidence must have unbroken provenance and be disclosable to the defence. Private-sector analysts must not represent themselves as law enforcement or access restricted systems, and should route referrals through lawful channels.

Data integrity: no fabrication, no drift, no hallucination

Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.

Provenance on every record

Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.

Nothing is invented to fill a gap

If the platform has no data for Criminal Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.

Scoring is deterministic and reproducible

Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.

Where AI is used, and where it is not

Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.

Guarding against drift

Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.

What this means for you

You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.

By the numbers

The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.

This particular entry connects directly to 10 data points, 10 mission domains, 1 closely related entries — every one of them a tag you can follow, and a dashboard you can open.

Questions analysts actually ask

When does intelligence become evidence?

It does not convert. Intelligence and evidence are separate streams with separate rules. If an intelligence item matters to the case, you must obtain the same fact through an evidential route: a witness who can speak to it, a production order or warrant for the underlying record, or a formal request through mutual legal assistance. The intelligence record still exists and is usually disclosable material even if it never becomes an exhibit. Attempting to present intelligence directly as evidence, or to reverse-engineer an evidential trail to conceal the original source, is how prosecutions collapse and officers face misconduct findings.

How do I handle a single-source report that is operationally critical?

Grade it honestly, act on it if the risk justifies acting, and say clearly in the product that it is single-sourced and uncorroborated. The failure mode is not acting on single-source material, which is sometimes necessary, but presenting it with borrowed confidence. State what the source is positioned to know and what they would not be positioned to know. Identify the specific observable that would corroborate or refute it, and task against that. If the decision cannot be reversed once taken, escalate the confidence question to the decision maker explicitly.

Can a private analyst do criminal intelligence work?

The method transfers; the access does not. A private investigator or corporate analyst can build entity spines, association charts and chronologies from court records, registries, sanctions lists and open sources, and this is legitimate due diligence and litigation support work. What they cannot do is access police intelligence systems, obtain criminal records outside statutory disclosure schemes, pretext for personal data, or run surveillance amounting to harassment. Where findings indicate serious criminality, the correct step is referral to police or a regulator with a documented package, not unilateral action or publication.

How much of a network should I chart?

Chart until additional nodes stop changing your structural conclusions. That is usually two steps out from the core for association, and one further step for financial and corporate links. Sprawl beyond that produces charts nobody reads and retention of person records for whom you cannot articulate a suspicion basis, which is a legal problem as well as an analytical one. If you cannot say what decision a node's inclusion supports, remove it. Keep the raw material, but let the product contain only what bears on the question.

What is the fastest reliable way to include or exclude a suspect?

Custody and supervision status. Inmate rosters, bail conditions, probation records and immigration detention records give hard availability windows that cut through speculation quickly and are usually retrievable within a day. Pair that with the offence chronology before doing anything more elaborate. The second fastest is identifier-based record resolution: a validated identifier match to a distinctive record beats any amount of name-similarity reasoning. Do both before network charting, because they frequently make the charting unnecessary.

How should I present confidence to a non-analyst decision maker?

Use a small fixed vocabulary with defined probability ranges, state the confidence with the judgement rather than in a footnote, and give the reason for the confidence level in one clause: number of independent sources, quality of the weakest link in the chain, and how much of the judgement rests on inference. Avoid mixing a probability statement with a hedging adverb. If the decision maker asks what would change your mind, you should be able to name the specific observable immediately; if you cannot, the judgement is not yet analysis.

What retention basis do I need to keep a person on file?

An articulable, recorded reason connecting that person to criminal activity or to a legitimate policing purpose, reviewed on a schedule and removed when it no longer holds. In the United States, criminal intelligence systems receiving federal funding operate under 28 CFR Part 23, which requires reasonable suspicion for submission and mandates review and purge. In the UK and EU, law enforcement data protection regimes impose necessity, proportionality and review duties. Association alone is not a basis: being a family member, neighbour or contact of a subject does not justify a retained record.

Standards, frameworks and further reading

Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:

  • 28 CFR Part 23, the US operating policy for criminal intelligence systems, setting the reasonable suspicion submission threshold and mandatory review, purge and dissemination controls.
  • UK National Intelligence Model and College of Policing authorised professional practice, defining tactical, operational and strategic products and the tasking and coordination process that commissions them.
  • The 5x5x5 and equivalent source evaluation schemes, which grade source reliability, information credibility and handling conditions as three separate axes on every item.
  • Law Enforcement Directive (EU) 2016/680 and UK Data Protection Act 2018 Part 3, governing necessity, proportionality, retention review and data subject rights in police processing.
  • Criminal Procedure and Investigations Act disclosure regime in England and Wales, and Brady and Giglio obligations in the United States, determining what intelligence material must be revealed to the defence.
  • Europol SOCTA methodology, providing a repeatable indicator framework for assessing organised crime group threat and prioritising groups for tasking.
  • Intelligence Community Directive 203 analytic standards, widely borrowed by police analysts for sourcing transparency, separation of fact from judgement and consistent confidence language.
  • INTERPOL notices and national central bureau framework, which defines the lawful route for cross-border requests and prohibits informal agency-to-agency use of member country data.

References

Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Criminal intelligence systems operating policies guidance — US Bureau of Justice Assistance. The governing federal standard for submission, review, purge and dissemination in criminal intelligence systems
  2. Authorised Professional Practice: Intelligence Management — College of Policing (UK). National guidance on intelligence products, source evaluation and the National Intelligence Model tasking cycle
  3. Serious and Organised Crime Threat Assessment — Europol. Periodic EU-wide assessment of organised crime structures, markets and methods with an explicit indicator methodology
  4. World Drug Report and Global Report on Trafficking in Persons — UN Office on Drugs and Crime. Authoritative global baselines for drug and trafficking markets used as strategic context for local analysis
  5. Uniform Crime Reporting and NIBRS documentation — US Federal Bureau of Investigation. Incident-level national crime data with published coding rules and agency participation caveats
  6. National Crime Victimization Survey — US Bureau of Justice Statistics. Household survey measuring unreported offending, the essential counterweight to police-recorded crime data
  7. Analytic Standards, Intelligence Community Directive 203 — US Office of the Director of National Intelligence. Standards for sourcing transparency, confidence expression and separation of fact from judgement
  8. INTERPOL notices system — INTERPOL. Describes notice types, identifier content and the national central bureau route for lawful cross-border requests
  9. Directive (EU) 2016/680 on data processing by law enforcement authorities — European Union, EUR-Lex. The legal instrument governing necessity, retention review and subject rights in police data processing

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this entry: unifies entity resolution, association charting and case-linked collection into an auditable intelligence file. Explore the platform, or browse the rest of the library by following any tag above.

Leave a Reply

Your email address will not be published. Required fields are marked *