InvesÂtigative journalism can materially improve risk assessment, but a published allegation should not be converted directly into a risk score or adverse finding. Reporting is most valuable when it identifies previÂously unknown entities, events, documents or affected people that can be tested against primary records. The risk team’s job is to preserve that lead, verify it and decide whether it changes exposure.
Define the decision and risk taxonomy
Start by stating the decision the assessment must support: onboarding a customer, retaining a supplier, entering a market, financing a project or escalating an existing relationship. Map the reporting to defined risk categories such as fraud, corruption, sanctions, human rights, litigation, goverÂnance or operaÂtional resilience. A dramatic article that does not affect the decision’s scope should not dominate the assessment.
Preserve the report and its claims
Save the article, publiÂcation date, author, cited documents and relevant updates or correcÂtions. Break the story into individual claims and distinÂguish direct evidence, witness testimony, documentary interÂpreÂtation and editorial inference. Trider’s guide to deep-dive research into financial cover-ups shows why a claim ledger is more reliable than treating a long narrative as one indivisible fact.
Assess source quality without relying on reputation alone
Consider whether the reporter identifies sources, publishes underÂlying records, seeks responses and explains uncerÂtainty. Anonymous sources may be necessary, but the assessor should underÂstand what corrobÂoÂration is described. A reputable publiÂcation can make an error, while a small outlet can publish decisive primary evidence. Check for litigation, correcÂtions and later regulator or court findings without assuming that a challenge disproves the reporting.
Corroborate every material point
Test corporate identities, dates, ownership, licences, financial figures and legal status against registries, filings, regulator notices and court records. Interview affected stakeÂholders where approÂpriate and preserve contrary evidence. The OECD’s guidance on risk-based due diligence for responÂsible business conduct supports an ongoing process of identiÂfying and addressing impacts rather than a one-off media search.
Translate evidence into exposure
Separate inherent risk, control effecÂtiveness and residual risk. Ask how the reported conduct could affect the organÂiÂsation, which relationship creates exposure, how severe the impact could be and whether existing controls would detect or prevent it. The UN Guiding Principles explain that human-rights due diligence should identify and assess actual or potential impacts across operaÂtions and business relationÂships; the official UN framework also stresses consulÂtation with potenÂtially affected groups.
Network reporting can expose connecÂtions that a convenÂtional checklist misses. Malta Media’s examiÂnation of companies, licences and sponsorship links associated with the Badalyan family is a secondary-source example. Its questions should be tested against company, licensing and financial records, and no network connection alone estabÂlishes misconduct.
Apply governance and escalation controls
Record the source, corrobÂoÂration, confiÂdence, potential impact, owner and next action for each risk. High-severity claims may justify enhanced due diligence, legal review or temporary controls, but decisions should be proporÂtionate and reviewable. Trider’s guide to using goverÂnance reports to invesÂtigate boardroom misconduct helps connect allegaÂtions to documented oversight failures.
Keep the assessment current
Journalism often begins a timeline rather than ends it. Monitor responses, filings, enforcement actions, judgments and correcÂtions, and change the rating when evidence changes. For matters spanning jurisÂdicÂtions, use the evidence-handling principles in Trider’s guide to cross-border fraud invesÂtiÂgaÂtions. The final record should make clear what is verified, disputed, inferred and still unknown.