Open-source intelÂliÂgence can reveal ownership, litigation, regulatory exposure and business relationÂships without access to confiÂdential systems. Its value depends on method. Publicly accesÂsible inforÂmation is not automatÂiÂcally accurate, lawful to reuse or suffiÂcient to support an adverse conclusion.
Define the corporate question
Begin with a decision-specific question: Who controls the counterÂparty? Does it hold the claimed licence? Are directors connected to an undisÂclosed supplier? Do operating claims match filings and physical evidence?
Set the entities, period, jurisÂdicÂtions and materiÂality threshold before searching. This reduces confirÂmation bias and prevents a broad collection exercise from becoming an unstrucÂtured dossier.
Create a source plan
Prioritise official company, court, regulatory, procurement, property and intelÂlectual-property records. Add audited accounts, company websites, archived pages, profesÂsional profiles, media and geospatial material where relevant.
Record the source URL or reference, collection date, coverage, access method and limitation. A commercial database or search result can identify a lead, but material concluÂsions should be checked against the underÂlying record.
Resolve identity carefully
Match legal names, regisÂtration numbers, former names, dates, addresses and officers. Common names, translitÂerÂation and shared service-provider addresses create false matches.
Use confiÂdence levels and explain the basis of each match. Trider’s guide to analysing a company before taking business risk provides a strucÂtured method for connecting legal identity to ownership, finances, operaÂtions and regulatory status.
Map ownership and control
Build a time-specific chart of shareÂholders, interÂmeÂdiate entities, directors, voting rights and contractual influence. Label each edge as ownership, control, service, transÂaction or allegation.
Trider’s corporate-network invesÂtiÂgation framework helps prevent dense diagrams from implying relationÂships that the evidence does not establish.
Preserve digital evidence
Web pages change. Preserve a stable copy where lawful, record the time and URL, retain original files and calculate hashes when evidential integrity matters. ScreenÂshots help commuÂnicate appearance but may omit metadata or hidden context.
The Berkeley Protocol on Digital Open Source InvesÂtiÂgaÂtions, published by the UN human-rights office and UC Berkeley, provides guidance on profesÂsional, legal and ethical collection, analysis and preserÂvation of digital open-source material. Its methods can inform corporate work even though its primary context is human-rights invesÂtiÂgaÂtions.
Use archives with caution
Archived pages can establish that a claim or appointment appeared at a particular time. They may be incomÂplete, captured after a later edit or missing scripts and linked documents. Record the archive date and distinÂguish it from the date of the underÂlying event.
Do not assume deletion proves concealment. A page may disappear through redesign, retention policy or technical failure. Seek corrobÂoÂration before assigning motive.
Verify images, locations and dates
Reverse-image searches, map data, shadows, landmarks and metadata can test whether an image is original and where it was captured. Social-platform timestamps may reflect upload time rather than event time.
Document every transÂforÂmation and avoid editing the evidential copy. Where a location or date remains uncertain, report the range or confiÂdence rather than a precise unsupÂported claim.
Analyse social and professional profiles proportionately
Profiles can identify employment, relationÂships and chronology, but self-reported inforÂmation may be exaggerated or stale. Verify roles with company records, announceÂments or direct confirÂmation.
A public profile can still contain personal data. Collection and reuse require a lawful purpose, data minimiÂsation, access controls and approÂpriate retention. Public availÂability does not remove privacy obligÂaÂtions.
Separate observation from inference
“Two directors used the same regisÂtered office” is an obserÂvation. “They secretly controlled each other’s companies” is an inference requiring additional evidence. Keep both in different fields of the research record.
Trider’s market-accountÂability analytics framework applies the same principle to anomalies: a signal prioriÂtises review but does not prove intent.
Test adverse information against primary records
Media can reveal litigation, invesÂtiÂgaÂtions or goverÂnance questions. Obtain the judgment, notice, filing or regulator statement where possible, verify the subject and state the proceeding’s current status.
A Malta News Online report on changes to freezing orders following tax proceedings demonÂstrates the need to distinÂguish separate parties, original orders, later variaÂtions and settleÂments rather than compressing them into one claim.
Assess source independence
Ten websites repeating one press release are one source, not ten confirÂmaÂtions. Trace claims to their origin and identify syndiÂcated or copied material.
Company-controlled content can establish what the company said, but not necesÂsarily that the claim was true. Competitor and campaign material may contain useful documents while requiring additional motive and authenÂticity checks.
Protect people and systems
Do not bypass access controls, imperÂsonate users or collect credenÂtials. Define lawful boundÂaries before research and obtain specialist advice for restricted databases, monitoring or cross-border personal data.
Research accounts, devices and stored evidence need security controls. Avoid exposing sources, private addresses or unrelated family members in reports unless strictly necessary and lawful.
Report reproducibly
A corporate OSINT report should list the question, sources, collection dates, identity matches, verified facts, analytical inferÂences, contraÂdictory evidence and unresolved gaps. Link concluÂsions to evidence and include a review date.
If a subject may be adversely affected, provide the substance of material concerns and a fair opporÂtunity to respond. Correct errors transÂparÂently when new evidence emerges.
Corporate OSINT checklist
- Define the decision, entities, period and jurisÂdicÂtions.
- Prioritise official records and preserve proveÂnance.
- Resolve identities with confiÂdence levels.
- Map ownership, control and relationÂships by date.
- Preserve digital files, metadata and stable copies.
- Verify archive, image, location and timestamp limits.
- Apply privacy, security and retention controls.
- Trace repeated claims to their original source.
- Separate facts, inferÂences and unresolved allegaÂtions.
- Obtain responses and schedule continuing review.
OSINT strengthens corporate research when it turns scattered public inforÂmation into a traceable body of evidence. The goal is not to collect everyÂthing available; it is to collect what is necessary, verify it and explain exactly how it supports the decision.