Select Page

Author: Mr Adrian Ramdat (Director of Training & Consultancy)

August 2026

Every organisation that authorises and manages Covert Human Intelligence Sources (CHIS) has a legal and moral responsibility to protect those who assist them. A fundamental part of that responsibility is completing and maintaining an effective CHIS risk assessment before and throughout the lifetime of an authorisation.

When discussing the legal framework governing CHIS, most practitioners immediately think of the Regulation of Investigatory Powers Act 2000 (RIPA), the Scottish equivalent, RIPSA, and the Covert Human Intelligence Sources Code of Practice. They establish the statutory framework for authorising and managing CHIS and require organisations to identify, assess and manage risk before an authorisation is granted. However, effective CHIS risk management is not shaped by legislation alone. One of the most influential legal principles affecting the management of covert human intelligence sources comes from Article 2 of the European Convention on Human Rights and the case of Osman v United Kingdom.

Although the case had nothing to do with covert policing, the principles established by the European Court of Human Rights continue to influence how organisations should identify, assess and manage the risks associated with using a CHIS.

For any organisation using CHIS, and particularly for handlers, controllers and authorising officers, understanding the Osman ruling is not simply about legal compliance. It is about protecting those who assist public authorities while ensuring operational decisions remain lawful, proportionate and defensible.

In summary, Osman v United Kingdom established that where a public authority knows, or ought reasonably to know, of a real and immediate risk to life, it has a positive obligation under Article 2 to take reasonable steps within its powers to reduce that risk. For organisations managing CHIS, this reinforces the need for dynamic risk assessments that are continually reviewed throughout the lifetime of an authorisation rather than treated as a one-off exercise.

Who Needs to Understand CHIS Risk Management?

When people hear the term CHIS, they often think of police informants. In reality, a range of public authorities have statutory powers to authorise and manage Covert Human Intelligence Sources where the legal requirements are met.

These include law enforcement agencies, regulators, government departments, staff working within prisons and, in prescribed circumstances, local authorities.

While the operational environments may differ, the responsibilities are remarkably similar. Every organisation that authorises a CHIS must identify foreseeable risks, assess those risks carefully and continually review whether the safeguards in place remain appropriate.

Whether the objective is national security, preventing or detecting crime, protecting the public or supporting a lawful investigation, effective CHIS risk management remains fundamental.

What is Osman v United Kingdom?

The case arose after a teacher developed an unhealthy obsession with one of his pupils, Ahmed Osman. Despite a number of warning signs, no effective intervention prevented the situation from escalating. The teacher eventually shot Ahmed, seriously injuring him, and murdered his father.

The family argued that the authorities had failed to protect them despite having information suggesting there was a foreseeable risk.

Although the European Court of Human Rights did not find a breach of Article 2 on the specific facts of the case, it established an important legal principle that continues to influence public authorities today.

The Court held that where a public authority knows, or ought reasonably to know, that an identified individual faces a real and immediate risk to life from the criminal acts of a third party, it has a positive obligation under Article 2 to take reasonable measures within its powers to reduce that risk.
Importantly, the Court also recognised that public authorities cannot eliminate every risk.

The obligation is not to guarantee safety in every circumstance but to act reasonably, proportionately and on the basis of the information available at the time decisions are made.

Why Does Osman Matter to CHIS Management?

Managing a CHIS has always involved balancing operational benefit against personal risk.

Whether a CHIS is supporting a police investigation, assisting a regulator investigating serious criminal offending, working with a government department or being managed within a prison environment, intelligence gathering should never be separated from safeguarding the individual providing that information.

The CHIS Code of Practice reflects this by requiring a CHIS risk assessment to be completed before an authorisation is granted. That assessment should identify foreseeable risks, consider the vulnerability of the CHIS and record the measures that will be taken to reduce those risks.

However, completing the initial risk assessment is not the end of the process. It is the beginning.

The principles established in Osman remind us that risk is dynamic. Operational circumstances change, criminal behaviour evolves and the personal circumstances of a CHIS may alter during the course of an operation. Effective CHIS management requires organisations to recognise those changes and respond accordingly.

A CHIS Risk Assessment Should Never Stand Still

From my own experience as both a CHIS handler and controller, one lesson became clear very quickly.

The greatest risks rarely appeared overnight. More often, they developed gradually through a series of small changes that, when viewed individually, appeared insignificant but, when considered collectively, fundamentally altered the overall assessment of risk.

A routine meeting might reveal that a criminal associate had started asking unexpected questions. The source's domestic circumstances may have changed. Fresh intelligence might indicate increasing levels of violence within the criminal group, or the CHIS may simply express concerns that deserve further examination.

None of these developments should be dismissed simply because they appear minor in isolation.

That is why every meaningful contact with a CHIS should include consideration of whether the existing risk assessment remains accurate.

Sometimes there will be nothing to change. On other occasions, one apparently minor development may justify revising the entire assessment.

Reviewing a CHIS risk assessment after every meaningful contact is not simply good administration. In my experience, it is one of the most effective ways of identifying emerging risks before they become significant operational problems.

Understanding "Real and Immediate Risk"

The phrase "real and immediate risk" is often misunderstood. It does not mean that harm is inevitable, nor does it require certainty that a CHIS will suffer serious injury.

Instead, handlers, controllers and authorising officers should continually consider whether the information available demonstrates a genuine and present risk requiring further action.

Questions that should be considered include whether new intelligence has altered the threat to the CHIS, whether the source's personal circumstances have changed, whether the operational environment has become more hostile, whether there are signs that the CHIS may have been compromised and whether the existing safeguarding measures remain appropriate.

These questions should not only be asked before authorisation. They should be revisited throughout the lifetime of the CHIS relationship.

Osman Is Not the Only Case Influencing CHIS Management

While Osman v United Kingdom establishes the Article 2 obligation to take reasonable steps where a real and immediate risk to life is known, it is not the only case relevant to the management of Covert Human Intelligence Sources.

In An Informer v A Chief Constable (2012), the Court of Appeal recognised the unique relationship that exists between a public authority and a CHIS. The Court accepted that, depending upon the circumstances, a duty of care may arise because of the very nature of that relationship and the risks associated with acting as a covert human intelligence source.

Taken together, these cases reinforce an important principle. Managing a CHIS is not simply about obtaining intelligence or complying with statutory procedures. It is about exercising sound professional judgement, continually assessing foreseeable risks and taking reasonable steps to protect those who assist public authorities in often challenging and potentially dangerous circumstances.

For handlers, controllers and authorising officers, that means the initial CHIS risk assessment completed before authorisation should never be regarded as the end of the process. Every meaningful contact presents an opportunity to identify new information, review existing safeguards and determine whether the current assessment continues to reflect the reality of the operational environment.

Good Records Demonstrate Good Decision Making

Risk management is only effective if it can be demonstrated.

If an operation is later scrutinised, organisations should be able to show what information was known at the time, what risks had been identified, what options were considered, why particular decisions were made, what measures were introduced to reduce those risks and when the CHIS risk assessment was reviewed and updated.

Good records demonstrate that risks were actively managed throughout the CHIS relationship rather than simply acknowledged before authorisation. They also provide evidence that operational decisions were made thoughtfully, proportionately and on the basis of the information available at the time.

Frequently Asked Questions

Does Osman v United Kingdom apply specifically to CHIS?

No. The case was unrelated to covert policing. However, the legal principles established by the judgment influence how all public authorities approach foreseeable risks to life, making it highly relevant to organisations managing CHIS.

How often should a CHIS risk assessment be reviewed?

A CHIS risk assessment should never be regarded as a one-off document. There are set points when a CHIS risk assessment should be formally reviewed and updated but it should also be reviewed whenever new information becomes available and, as good operational practice, after every meaningful contact with a CHIS.

Why is Article 2 important in CHIS management?

Article 2 places a positive obligation on public authorities to take reasonable steps to protect life where they know, or ought reasonably to know, that an identified individual faces a real and immediate risk. For organisations managing CHIS, this reinforces the importance of continual risk assessment, effective safeguarding and well-reasoned operational decision making.

Final Thoughts

Osman v United Kingdom was not a covert policing case, but its principles continue to influence every organisation that authorises and manages Covert Human Intelligence Sources.

The judgment reminds us that where foreseeable risks to life exist, public authorities have a positive obligation under Article 2 to identify those risks, keep them under continual review and take reasonable and proportionate steps to reduce them.

Having managed CHIS as both a handler and a controller, I have always viewed the initial CHIS risk assessment as the foundation of effective source management rather than the finish line. The most important decisions were often made after subsequent meetings with a CHIS, when new information required risks to be reassessed and safeguarding measures to be reviewed.

Whether you work in law enforcement, a regulatory body, government, a prison or another public authority with CHIS powers, the principle remains the same. Effective CHIS management depends upon recognising that risk is constantly evolving and ensuring that every meaningful contact with a CHIS is used to review existing assessments, identify emerging risks and make informed, defensible operational decisions.

At The Signature Brand Training & Consultancy, our CHIS training is delivered by practitioners with extensive operational experience as handlers, controllers and authorising officers. We combine the legal framework with the practical realities of managing Covert Human Intelligence Sources, helping organisations develop the knowledge, judgement and confidence needed to manage CHIS lawfully, safely and effectively.

Find out more about the CHIS training that we offer here:

https://thesignaturebrand.co.uk/training/covert-skills-training/covert-human-intelligence-source-chis-humint-training/ and our RIPA/RIPSA training here:
https://thesignaturebrand.co.uk/training/ripa-ripsa-training/

or to discuss your organisation's specific requirements, please get in touch at info@thesignaturebrand.co.uk. We'd be pleased to help.

About the Author

Adrian Ramdat is Director of The Signature Brand Training & Consultancy and has more than 40 years of investigative experience. A former senior detective and former Head of Covert Training for the National Policing Improvement Agency (NPIA) now the College of Policing, he has managed Covert Human Intelligence Sources as both a handler and controller and has extensive experience of managing complex investigations.

He holds a degree in Education and a Postgraduate Certificate in Education (PGCE), combining extensive operational expertise with recognised teaching qualifications. Adrian delivers specialist training and consultancy across CHIS management, RIPA, investigative interviewing, intelligence, covert investigations, whistleblowing and workplace investigations for organisations throughout the UK and internationally.