Skip to main content

Investigative Reporter Pack

Ten tools and guides plus three copy-and-paste templates for investigative journalists: the full FOI appeal chain, source protection, story risk assessment, social media verification, whistleblower outreach, legal-read requests, legal-threat response, and key law guides on production orders and SLAPPs.

Last reviewed: Next review due:

Who this pack is for

This pack is for journalists working on longer-term investigations — whether data-driven FOI investigations, source-based investigations into public bodies or powerful individuals, or cross-border investigations that involve sensitive information and legal risk. It brings together the practical tools and legal knowledge you need to run an investigation from first FOI request to publication without leaving dangerous gaps in your process.

The pack is structured around the three core risk areas of investigative journalism: obtaining information (FOI tools, including the full appeal chain), protecting sources and managing legal risk (source protection, story risk register, SLAPP and production order guides, whistleblower outreach), and verifying and defending what you publish (social media verification, legal-read requests, and legal-threat response). Use it as a pre-publication and post-publication checklist for every investigation.

What’s included

Six tools and four guides — click any card to open it directly.

Copy-and-paste templates

Three ready-to-use templates for the moments an investigation most often goes wrong: first contact with a source, the pre-publication legal read, and a legal threat after publication.

Template: SecureDrop Initial Approach Message

Use this as your first substantive reply to a potential whistleblower who has contacted you through SecureDrop or a similarly secure, source-controlled channel. It sets expectations honestly without pressuring the source to identify themselves.

SECUREDROP INITIAL APPROACH MESSAGE (TO A POTENTIAL WHISTLEBLOWER)

[Send only via SecureDrop or another anonymous, source-controlled channel.
Never ask the source to reply from a work email, work phone, or work device.]

Thank you for getting in touch through SecureDrop.

Before we go any further, here is what you need to know:
1. You do not have to tell me who you are. SecureDrop is designed so that I
   cannot identify you unless you choose to share identifying details.
2. If you want to talk further, please use only this SecureDrop channel or
   another secure method we agree — not your work email, phone, or device.
3. I cannot guarantee an outcome — only that I will treat what you share
   carefully, verify it independently, and will not publish anything that
   identifies you without your explicit, informed agreement.
4. If the material is sensitive to your employment or safety, please read
   our source protection guidance first: [LINK TO SOURCE PROTECTION GUIDE]

If you can tell me more about what you have and why it is in the public
interest, that helps me judge whether I can pursue it. No obligation —
you can stop this conversation at any time.

[YOUR FIRST NAME], [PUBLICATION]
Reachable only via this SecureDrop channel: [SECUREDROP ONION ADDRESS]

Template: Legal-Read Request Note

Send this alongside your near-final draft to your in-house or retained lawyer. Flagging the specific risk areas up front — rather than sending the draft cold — gets you a faster and more useful legal read.

LEGAL-READ REQUEST NOTE (TO IN-HOUSE / RETAINED LAWYER)

To: [LAWYER NAME]
From: [YOUR NAME], [PUBLICATION]
Re: Legal read — "[WORKING HEADLINE]"
Target publication date: [DATE]
Attached: near-final draft ([WORD COUNT] words), editorial file ref: [FILE REF]

SUMMARY OF THE STORY
[2-3 sentence summary of the central allegation/finding.]

SPECIFIC RISK AREAS I NEED YOU TO LOOK AT
1. Defamation: paragraphs [X, Y, Z] allege facts against [NAMED INDIVIDUAL/
   ORGANISATION]. Public interest defence basis: [SUMMARY].
2. Contempt: [NAME] is subject to [ONGOING PROCEEDINGS/TRIAL DATE]. Please
   confirm whether any paragraph risks serious prejudice under the Contempt
   of Court Act 1981.
3. Privacy: story includes [TYPE OF PERSONAL/SENSITIVE INFORMATION]. Public
   interest justification attached (Public Interest Test Builder output).
4. Source material: relies on [LEAKED DOCUMENTS/CONFIDENTIAL SOURCE].
   Provenance and corroboration logged in the Story Risk Register (attached).
5. Right of reply: sent to [NAMES] on [DATE], deadline [DATE/TIME], status:
   [RECEIVED / NOT YET DUE / NO RESPONSE].

QUESTIONS FOR YOU
- Any paragraphs you'd want removed, softened, or sourced more strongly?
- Any additional right-of-reply steps needed before we can safely publish?
- Any injunction risk (has anyone threatened to seek one)?

Please turn this around by [DATE/TIME] given our publication schedule.
Happy to talk it through by phone if that's faster.

[YOUR NAME]

Template: Post-Publication Legal Threat Response

A holding reply for when a legal threat arrives after publication. It acknowledges receipt and buys time for proper legal advice without conceding any point in the complaint.

POST-PUBLICATION LEGAL THREAT RESPONSE (HOLDING REPLY)

To: [SENDER — SOLICITOR / CLAIMANT]
From: [YOUR NAME / PUBLICATION LEGAL CONTACT]
Re: Your letter dated [DATE] regarding "[ARTICLE HEADLINE]", published [DATE]

Dear [SENDER NAME],

Thank you for your letter dated [DATE], received [DATE RECEIVED].

I acknowledge receipt of your correspondence concerning the above article.
This matter is being referred to [PUBLICATION]'s legal advisers, and we will
respond substantively in due course.

In the meantime, please note:
1. We have not altered or removed the article and do not intend to do so
   pending proper legal consideration of your complaint.
2. If your letter raises specific factual inaccuracies, please set them out
   clearly with the basis for the claim, and we will consider them through
   our normal corrections process.
3. All source material, notes, and editorial records have been preserved.

We aim to respond substantively within [10/14] working days. If you require
a response sooner due to a specific legal deadline, please identify it.

Yours sincerely,
[NAME / TITLE], [PUBLICATION]

--- INTERNAL NOTE (DO NOT SEND) ---
On receipt of any legal threat: (1) log date/time/channel, (2) forward
immediately to editor + legal adviser, (3) do not amend or unpublish without
legal sign-off, (4) freeze the editorial file as it stood at publication,
(5) do not communicate with the sender beyond this holding reply.

How to use this pack

  1. 1

    Open a Story Risk Register at the start of every investigation

    Before filing FOI requests or contacting sources, open a Story Risk Register entry. Log the allegations, evidence, legal risks (defamation, contempt, privacy), and required steps before publication. Update it throughout the investigation. This is your editorial file — keep it current and accurate.

  2. 2

    Use the FOI tools systematically

    For data-driven investigations, use the FOI Request Builder to file with multiple authorities and the FOI for Investigations guide for advanced tactics. Track each request with its reference number and deadline. If a request is refused, escalate immediately through the internal review and ICO complaint templates rather than waiting.

  3. 3

    Apply source protection from the first contact

    Run through the Source Protection Checklist before any contact with a confidential source. If a source approaches you anonymously, reply using the SecureDrop Initial Approach Message template rather than improvising — it avoids common mistakes like asking for identifying details too early. Use Signal for ongoing communications, meet in person where possible, and do not keep records that link sources to their information.

  4. 4

    Verify every piece of digital evidence

    For any digital evidence — documents, screenshots, social media posts, images — run through the Social Media Verification Checklist. Document your verification steps in your editorial file. Do not publish material you cannot independently corroborate.

  5. 5

    Send the legal-read request with time to act on it

    Before publishing any investigation, send your near-final draft to your lawyer using the Legal-Read Request Note, flagging the specific defamation, contempt, and privacy risk areas. Build in enough time before your deadline to actually resolve the queries that come back, not just to receive them.

  6. 6

    Have the legal-threat response ready before you publish

    Know in advance who receives legal threats at your publication and how quickly they escalate. If a threat arrives, use the Post-Publication Legal Threat Response template as your immediate holding reply, preserve your editorial file exactly as it stood at publication, and do not amend or unpublish the story without legal sign-off.

Red-flags checklist

Run every investigation against this list before you file for publication.

INVESTIGATION RED-FLAGS CHECKLIST

Review every investigation in development against these warning signs:

SINGLE-SOURCE ALLEGATION
[ ] Central allegation supported by only one source, no documentary
    corroboration? → Do not publish. Seek a second source or corroboration.

UNVERIFIED LEAKED DOCUMENT
[ ] Leaked document's authenticity not verified (metadata, provenance,
    corroborating source)? → Treat as unverified; do not state as fact.

NO RIGHT OF REPLY SENT
[ ] Named individual/organisation not given fair opportunity to respond?
    → IPSO Clause 1 risk. Send it before publication.

SOURCE IDENTITY EXPOSURE RISK
[ ] Could the story, even unnamed, let the subject identify the leaker
    (e.g. "one of three people with access")? → Generalise further or delay.

ONGOING COURT PROCEEDINGS
[ ] Anyone named currently facing criminal charges or trial? → Check
    contempt risk under the Contempt of Court Act 1981 before publication.

NO LEGAL READ BEFORE DEADLINE
[ ] Lawyer hasn't reviewed the final draft with time to resolve queries?
    → Do not let deadline pressure skip this step.

EDITORIAL FILE INCOMPLETE
[ ] Story Risk Register not current on sourcing, corroboration, right of
    reply? → Complete it; it's your primary evidence if challenged later.

Sources: IPSO Editors' Code of Practice, Contempt of Court Act 1981,
Defamation Act 2013, NUJ Code of Conduct.

Common mistakes

  • Publishing on the strength of a single anonymous source with no independent corroboration, because the story "feels right."
  • Contacting a whistleblower on their work email or work phone before establishing a secure channel — this can expose them to their employer's IT monitoring immediately.
  • Sending the legal read too late to act on the lawyer's feedback, so genuine concerns get overridden by a publication deadline.
  • Responding substantively to a post-publication legal threat before getting legal advice, which can inadvertently concede points or create new liability.
  • Failing to keep the Story Risk Register updated in real time, leaving no contemporaneous record of sourcing and corroboration decisions if the story is challenged months later.

Primary sources

Frequently asked questions

How do I protect a confidential source?
Source protection requires operational security at every stage. Use end-to-end encrypted communications (Signal is preferred by most security professionals). Do not keep records that link a source to their information. Anonymise your notes — refer to sources by code names in your files. Be aware that your communications metadata (who you called, when, for how long) may be accessible even if message content is encrypted. The Source Protection Checklist in this pack walks you through each operational step. The Source Protection Law guide explains your legal rights under the Police and Criminal Evidence Act 1984 and the Terrorism Act 2000.
What is a production order and how do journalists resist one?
A production order under the Police and Criminal Evidence Act 1984 (Sch.1) compels a journalist or news organisation to hand over journalistic material (notes, recordings, sources). The police must satisfy a circuit judge that the material is likely to be relevant to a serious arrestable offence and cannot reasonably be obtained elsewhere. Journalists can — and should — contest these applications. The Production Orders guide in this pack explains the procedure, the grounds for resistance, and how to get emergency legal help.
What is a SLAPP and what protection do journalists have?
A SLAPP (Strategic Lawsuit Against Public Participation) is a legal claim — typically defamation or privacy — brought primarily to suppress or punish journalism rather than to vindicate a genuine legal right. The Economic Crime and Corporate Transparency Act 2023 introduced early dismissal provisions for SLAPPs related to economic crime. The SLAPP Response Playbook in this pack guides you through identifying whether a claim is a SLAPP, the early dismissal procedure, and how to access legal support.
How should I use FOI for investigations?
FOI is most powerful in investigations when used systematically: file requests to multiple authorities on the same topic to enable comparison, use the Dataset Request template to get machine-readable data rather than PDFs, and file follow-up requests based on what disclosures reveal. The FOI for Investigations guide explains advanced tactics: using WhatDoTheyKnow searches to find prior disclosures, using the EIR route for environmental data, and coordinating FOI requests with source-based reporting.
How do I verify information from an anonymous source?
Anonymous source material should never be published on the basis of a single source alone. Seek documentary corroboration — records, receipts, emails, data — that independently supports what the source is telling you. Cross-check specific facts with other sources who can confirm independently. Use the Social Media Verification Checklist to verify any digital material the source provides. Document your corroboration in your editorial file. If you cannot corroborate, consider whether to approach the subject for comment, which may itself confirm or deny the allegation.
How should I make first contact with a potential whistleblower?
Make first contact on a channel the source controls and that does not require them to reveal their identity before they are ready. SecureDrop (used by the Bureau of Investigative Journalism, the Guardian, and others) lets a source submit documents anonymously without you knowing who they are unless they choose to tell you. Never ask a potential whistleblower to use their work email, work phone, or work computer to contact you. The SecureDrop Initial Approach Message in this pack gives you wording that explains the risks honestly and does not pressure the source to identify themselves.
When should I send my draft to the in-house lawyer before publication?
Send a legal-read request as soon as you have a near-final draft of any investigation involving allegations against a named individual or organisation, use of leaked or confidential material, contested facts, or potential contempt issues (an ongoing court case, an imminent trial). Do not wait until the day of publication — a proper legal read needs time to raise queries and for you to address them. The Legal-Read Request Note in this pack is a structured way to flag the specific risk areas to your lawyer rather than just sending the draft cold.
What should I do if I receive a legal threat after publication?
Do not ignore it, do not engage substantively without legal advice, and do not take the story down or amend it unilaterally. Acknowledge receipt, log the date and channel, forward it immediately to your editor and legal adviser, and preserve your entire editorial file (notes, sources, drafts, legal-read sign-off) exactly as it stood at publication. The Post-Publication Legal Threat Response template in this pack is a holding reply that buys time for proper legal advice without conceding anything.

Related packs

Related guides