Investigative Reporter Pack
Ten tools and guides plus three copy-and-paste templates for investigative journalists: the full FOI appeal chain, source protection, story risk assessment, social media verification, whistleblower outreach, legal-read requests, legal-threat response, and key law guides on production orders and SLAPPs.
Last reviewed: Next review due:
Who this pack is for
This pack is for journalists working on longer-term investigations — whether data-driven FOI investigations, source-based investigations into public bodies or powerful individuals, or cross-border investigations that involve sensitive information and legal risk. It brings together the practical tools and legal knowledge you need to run an investigation from first FOI request to publication without leaving dangerous gaps in your process.
The pack is structured around the three core risk areas of investigative journalism: obtaining information (FOI tools, including the full appeal chain), protecting sources and managing legal risk (source protection, story risk register, SLAPP and production order guides, whistleblower outreach), and verifying and defending what you publish (social media verification, legal-read requests, and legal-threat response). Use it as a pre-publication and post-publication checklist for every investigation.
What’s included
Six tools and four guides — click any card to open it directly.
FOI Request Builder
Generate a compliant, personalised FOI request for any UK public authority type in under two minutes.
FOI Internal Review Template
Challenge a refusal with a structured internal review request citing the correct exemption by section number.
ICO Complaint Template
Escalate to the Information Commissioner's Office after a failed internal review using this step-by-step complaint draft.
Source Protection Checklist
A step-by-step operational checklist for protecting confidential sources from identification — communications, records, and meetings.
Story Risk Register
Log and assess the legal and editorial risks of an investigation in development with a structured pre-publication risk matrix.
Social Media Verification Checklist
Verify social media posts, images, and accounts before publication following the First Draft verification protocol.
Guide: Source Protection Law
Your legal rights as a journalist when protecting confidential sources under PACE 1984 and the Terrorism Act 2000.
Guide: Production Orders
How production orders work, the grounds for resistance, and how to get emergency legal help when police seek your material.
Guide: SLAPP Response Playbook
Identify SLAPPs, use the early dismissal procedure under the ECCTA 2023, and access anti-SLAPP legal support.
Guide: FOI for Investigations
Advanced FOI tactics for investigative journalists: bulk requests, dataset routes, EIR, and coordinating FOI with source reporting.
Copy-and-paste templates
Three ready-to-use templates for the moments an investigation most often goes wrong: first contact with a source, the pre-publication legal read, and a legal threat after publication.
Template: SecureDrop Initial Approach Message
Use this as your first substantive reply to a potential whistleblower who has contacted you through SecureDrop or a similarly secure, source-controlled channel. It sets expectations honestly without pressuring the source to identify themselves.
SECUREDROP INITIAL APPROACH MESSAGE (TO A POTENTIAL WHISTLEBLOWER) [Send only via SecureDrop or another anonymous, source-controlled channel. Never ask the source to reply from a work email, work phone, or work device.] Thank you for getting in touch through SecureDrop. Before we go any further, here is what you need to know: 1. You do not have to tell me who you are. SecureDrop is designed so that I cannot identify you unless you choose to share identifying details. 2. If you want to talk further, please use only this SecureDrop channel or another secure method we agree — not your work email, phone, or device. 3. I cannot guarantee an outcome — only that I will treat what you share carefully, verify it independently, and will not publish anything that identifies you without your explicit, informed agreement. 4. If the material is sensitive to your employment or safety, please read our source protection guidance first: [LINK TO SOURCE PROTECTION GUIDE] If you can tell me more about what you have and why it is in the public interest, that helps me judge whether I can pursue it. No obligation — you can stop this conversation at any time. [YOUR FIRST NAME], [PUBLICATION] Reachable only via this SecureDrop channel: [SECUREDROP ONION ADDRESS]
Template: Legal-Read Request Note
Send this alongside your near-final draft to your in-house or retained lawyer. Flagging the specific risk areas up front — rather than sending the draft cold — gets you a faster and more useful legal read.
LEGAL-READ REQUEST NOTE (TO IN-HOUSE / RETAINED LAWYER) To: [LAWYER NAME] From: [YOUR NAME], [PUBLICATION] Re: Legal read — "[WORKING HEADLINE]" Target publication date: [DATE] Attached: near-final draft ([WORD COUNT] words), editorial file ref: [FILE REF] SUMMARY OF THE STORY [2-3 sentence summary of the central allegation/finding.] SPECIFIC RISK AREAS I NEED YOU TO LOOK AT 1. Defamation: paragraphs [X, Y, Z] allege facts against [NAMED INDIVIDUAL/ ORGANISATION]. Public interest defence basis: [SUMMARY]. 2. Contempt: [NAME] is subject to [ONGOING PROCEEDINGS/TRIAL DATE]. Please confirm whether any paragraph risks serious prejudice under the Contempt of Court Act 1981. 3. Privacy: story includes [TYPE OF PERSONAL/SENSITIVE INFORMATION]. Public interest justification attached (Public Interest Test Builder output). 4. Source material: relies on [LEAKED DOCUMENTS/CONFIDENTIAL SOURCE]. Provenance and corroboration logged in the Story Risk Register (attached). 5. Right of reply: sent to [NAMES] on [DATE], deadline [DATE/TIME], status: [RECEIVED / NOT YET DUE / NO RESPONSE]. QUESTIONS FOR YOU - Any paragraphs you'd want removed, softened, or sourced more strongly? - Any additional right-of-reply steps needed before we can safely publish? - Any injunction risk (has anyone threatened to seek one)? Please turn this around by [DATE/TIME] given our publication schedule. Happy to talk it through by phone if that's faster. [YOUR NAME]
Template: Post-Publication Legal Threat Response
A holding reply for when a legal threat arrives after publication. It acknowledges receipt and buys time for proper legal advice without conceding any point in the complaint.
POST-PUBLICATION LEGAL THREAT RESPONSE (HOLDING REPLY) To: [SENDER — SOLICITOR / CLAIMANT] From: [YOUR NAME / PUBLICATION LEGAL CONTACT] Re: Your letter dated [DATE] regarding "[ARTICLE HEADLINE]", published [DATE] Dear [SENDER NAME], Thank you for your letter dated [DATE], received [DATE RECEIVED]. I acknowledge receipt of your correspondence concerning the above article. This matter is being referred to [PUBLICATION]'s legal advisers, and we will respond substantively in due course. In the meantime, please note: 1. We have not altered or removed the article and do not intend to do so pending proper legal consideration of your complaint. 2. If your letter raises specific factual inaccuracies, please set them out clearly with the basis for the claim, and we will consider them through our normal corrections process. 3. All source material, notes, and editorial records have been preserved. We aim to respond substantively within [10/14] working days. If you require a response sooner due to a specific legal deadline, please identify it. Yours sincerely, [NAME / TITLE], [PUBLICATION] --- INTERNAL NOTE (DO NOT SEND) --- On receipt of any legal threat: (1) log date/time/channel, (2) forward immediately to editor + legal adviser, (3) do not amend or unpublish without legal sign-off, (4) freeze the editorial file as it stood at publication, (5) do not communicate with the sender beyond this holding reply.
How to use this pack
- 1
Open a Story Risk Register at the start of every investigation
Before filing FOI requests or contacting sources, open a Story Risk Register entry. Log the allegations, evidence, legal risks (defamation, contempt, privacy), and required steps before publication. Update it throughout the investigation. This is your editorial file — keep it current and accurate.
- 2
Use the FOI tools systematically
For data-driven investigations, use the FOI Request Builder to file with multiple authorities and the FOI for Investigations guide for advanced tactics. Track each request with its reference number and deadline. If a request is refused, escalate immediately through the internal review and ICO complaint templates rather than waiting.
- 3
Apply source protection from the first contact
Run through the Source Protection Checklist before any contact with a confidential source. If a source approaches you anonymously, reply using the SecureDrop Initial Approach Message template rather than improvising — it avoids common mistakes like asking for identifying details too early. Use Signal for ongoing communications, meet in person where possible, and do not keep records that link sources to their information.
- 4
Verify every piece of digital evidence
For any digital evidence — documents, screenshots, social media posts, images — run through the Social Media Verification Checklist. Document your verification steps in your editorial file. Do not publish material you cannot independently corroborate.
- 5
Send the legal-read request with time to act on it
Before publishing any investigation, send your near-final draft to your lawyer using the Legal-Read Request Note, flagging the specific defamation, contempt, and privacy risk areas. Build in enough time before your deadline to actually resolve the queries that come back, not just to receive them.
- 6
Have the legal-threat response ready before you publish
Know in advance who receives legal threats at your publication and how quickly they escalate. If a threat arrives, use the Post-Publication Legal Threat Response template as your immediate holding reply, preserve your editorial file exactly as it stood at publication, and do not amend or unpublish the story without legal sign-off.
Red-flags checklist
Run every investigation against this list before you file for publication.
INVESTIGATION RED-FLAGS CHECKLIST
Review every investigation in development against these warning signs:
SINGLE-SOURCE ALLEGATION
[ ] Central allegation supported by only one source, no documentary
corroboration? → Do not publish. Seek a second source or corroboration.
UNVERIFIED LEAKED DOCUMENT
[ ] Leaked document's authenticity not verified (metadata, provenance,
corroborating source)? → Treat as unverified; do not state as fact.
NO RIGHT OF REPLY SENT
[ ] Named individual/organisation not given fair opportunity to respond?
→ IPSO Clause 1 risk. Send it before publication.
SOURCE IDENTITY EXPOSURE RISK
[ ] Could the story, even unnamed, let the subject identify the leaker
(e.g. "one of three people with access")? → Generalise further or delay.
ONGOING COURT PROCEEDINGS
[ ] Anyone named currently facing criminal charges or trial? → Check
contempt risk under the Contempt of Court Act 1981 before publication.
NO LEGAL READ BEFORE DEADLINE
[ ] Lawyer hasn't reviewed the final draft with time to resolve queries?
→ Do not let deadline pressure skip this step.
EDITORIAL FILE INCOMPLETE
[ ] Story Risk Register not current on sourcing, corroboration, right of
reply? → Complete it; it's your primary evidence if challenged later.
Sources: IPSO Editors' Code of Practice, Contempt of Court Act 1981,
Defamation Act 2013, NUJ Code of Conduct.Common mistakes
- Publishing on the strength of a single anonymous source with no independent corroboration, because the story "feels right."
- Contacting a whistleblower on their work email or work phone before establishing a secure channel — this can expose them to their employer's IT monitoring immediately.
- Sending the legal read too late to act on the lawyer's feedback, so genuine concerns get overridden by a publication deadline.
- Responding substantively to a post-publication legal threat before getting legal advice, which can inadvertently concede points or create new liability.
- Failing to keep the Story Risk Register updated in real time, leaving no contemporaneous record of sourcing and corroboration decisions if the story is challenged months later.
Primary sources
- Police and Criminal Evidence Act 1984 — production order procedure for journalistic material
- Contempt of Court Act 1981 — reporting restrictions on active proceedings
- Economic Crime and Corporate Transparency Act 2023 — SLAPP early-dismissal provisions
- NUJ Code of Conduct — source protection and public interest principles
- IPSO Editors’ Code of Practice — accuracy, right of reply, and confidential sources (Clause 14)
- The Bureau of Investigative Journalism — investigative methodology and SecureDrop practice
- SecureDrop — open-source whistleblower submission platform used by major UK and international newsrooms
- Information Commissioner’s Office (ICO) — FOI complaints and data protection guidance