Author: Mr Adrian Ramdat (Director of Training & Consultancy)
June 2026
When discussing covert powers, much of the focus naturally falls on authorisations. Investigators and Authorising Officers spend considerable time ensuring that applications are lawful, necessary and proportionate. Policies are developed, training is delivered and oversight mechanisms are established to ensure compliance with the Regulation of Investigatory Powers Act 2000 (RIPA), the Regulation of Investigatory Powers (Scotland) Act 2000 (RIPSA) and the Investigatory Powers Act 2016 (IPA).
Yet obtaining a lawful authority is only the beginning.
The true test of compliance often comes months or even years later when an organisation is required to account for what happened to the material it obtained. How was it stored? Who had access to it? Was it reviewed? Was it retained for longer than necessary? Was it destroyed when it no longer served a lawful purpose?
These questions sit at the heart of product management.
In the covert environment, "product" refers to the intelligence, evidence and information generated through the use of covert powers. While considerable emphasis is often placed on obtaining that material, less attention is sometimes paid to its management throughout its lifecycle. Yet this is precisely where organisations can find themselves exposed to criticism from regulators, inspectors, courts and tribunals.
The Hidden Risk in Covert Activity
Most practitioners understand the importance of securing an authority before conducting surveillance using a Covert Human Intelligence Source or acquiring communications data. What is less visible is the ongoing responsibility that follows.
Every piece of material obtained through covert means carries legal, ethical and operational obligations. Organisations must be able to demonstrate why information is being retained, how often it is reviewed and when it should be destroyed. Failure to do so risks breaching not only legislation but also the fundamental principles of necessity and proportionality upon which covert powers are based.
In many organisations, product management is viewed as an administrative function. In reality, it is a critical safeguard that protects investigations, individuals and the organisation itself.
A perfectly lawful authorisation can still become problematic if the resulting material is mishandled.
Lessons from Real Cases
MI5 and Data Handling Failures
One of the most significant examples emerged from concerns regarding MI5's handling of data obtained under RIPA and the IPA.
Issues first identified internally in 2016 later became the subject of legal challenges and scrutiny by the Investigatory Powers Tribunal. The concerns centred on the retention of material, including legally privileged information and datasets that no longer held operational value.
The Tribunal identified serious shortcomings in data handling arrangements. Importantly, these were not failures in obtaining the material; they were failures in managing it once acquired.
The case highlighted weaknesses in oversight, governance and organisational understanding of retention and review obligations. It demonstrated that compliance cannot be achieved simply through obtaining lawful authorities. Organisations must maintain effective control over the product generated throughout its lifecycle.
The Blackpool Murder Investigation
The investigation into the murder of a 14-year-old girl in Blackpool provides a further example of how product management failures can affect operational outcomes.
Subsequent scrutiny identified concerns around the handling of covert surveillance material, including recording, transcription and disclosure processes. These shortcomings contributed to significant evidential difficulties and attracted criticism from oversight bodies.
Again, the issue was not simply the collection of information. The difficulties arose because the product generated by the investigation was not managed to the standard required.
The consequences were significant. Valuable material became vulnerable to challenge, confidence in the investigation was affected and additional scrutiny followed.
Why IPCO Focuses on Retention, Review and Disposal
These and other cases have shaped the approach taken by the Investigatory Powers Commissioner's Office (IPCO).
In recent years, IPCO inspections have placed increasing emphasis on Retention, Review and Disposal (RRD), supported through its Data Assurance Programme. Inspectors are no longer interested solely in whether powers were lawfully authorised.
They are equally concerned with what happens afterwards.
- Can the organisation demonstrate why information is still being held?
- Are reviews taking place at appropriate intervals?
- Is there evidence of decision-making?
- Can an audit trail be followed?
- Has material that no longer serves a lawful purpose been destroyed?
These questions reflect a growing recognition that the greatest risks often emerge after collection rather than during it.
Common Themes Identified During Inspections
Across a range of public authorities, similar issues continue to arise:
- Material retained without a clear and documented justification.
- Review processes that are inconsistent or poorly evidenced.
- Uncertainty regarding ownership and responsibility for retained material.
- Weak audit trails that make decisions difficult to justify retrospectively.
- A tendency to retain information indefinitely on the basis that it may prove useful in the future.
None of these issues are usually the result of deliberate misconduct. More often they arise because staff are unclear about their responsibilities or because retention processes have evolved informally over time.
However, when inspectors arrive, good intentions are rarely enough. Organisations must be able to demonstrate compliance through records, policies and documented decision-making.
Increasingly a Courtroom Issue
The importance of product management is not confined to inspections and audits. It is increasingly becoming an area of scrutiny within criminal proceedings.
A recent court case involving a covert authority highlighted this issue directly. The Authorising Officer was called to give evidence and, unsurprisingly, the initial questions focused on the authority itself. What was more revealing was that one of the next lines of questioning concerned the product generated from the activity and the officer's responsibilities for it.
The defence clearly recognised that while obtaining an authority may be lawful, weaknesses in the subsequent handling, retention, review or disclosure of the material can present opportunities to challenge the reliability of the investigation or the credibility of those involved.
Whether that challenge ultimately succeeds is almost beside the point. The fact that these questions are now being asked demonstrates a growing awareness amongst defence practitioners that product management can be an avenue for scrutiny. Organisations should therefore view retention, review and disposal not merely as compliance requirements, but as matters capable of being tested in court.
The reality is that investigators, Authorising Officers and organisations may increasingly find themselves being asked not only why material was obtained, but what happened to it afterwards.
A Question Worth Asking
Every organisation that uses covert powers should consider a simple question:
If an IPCO inspection took place tomorrow, could you confidently justify every item of covert material currently being retained?
For many organisations, that question is more challenging than it first appears.
The issue is not whether material was obtained lawfully in the first place. Rather, it is whether the organisation can demonstrate that it has continued to manage that material lawfully throughout its lifecycle.
- Can decision-makers explain why information is still being held?
- Is there a clear audit trail showing when reviews took place and who conducted them?
- Can the organisation evidence that retention remains necessary and proportionate?
- Has material that no longer serves an operational purpose been identified and disposed of appropriately?
These questions sit at the heart of modern oversight. Increasingly, inspectors are looking beyond authorisations and examining the systems, governance and decision-making that support the ongoing management of covert product.
The answer to those questions often determines whether an organisation is viewed as merely compliant on paper or genuinely accountable in practice.
Conclusion
Product management is not an administrative afterthought. It is a fundamental component of lawful and professional covert activity and should be thought about at the very start of the process.
The collection of information may be what advances an investigation, but it is the management of that information that protects the organisation. Strong retention, review and disposal practices safeguard privacy, support evidential integrity, demonstrate compliance and build public confidence.
The lesson from oversight bodies, tribunals and court proceedings is clear: obtaining information lawfully is only part of the responsibility. Managing it properly is what ultimately determines whether an organisation can withstand scrutiny.
As oversight continues to evolve, organisations that treat product management as a core operational discipline rather than an administrative function will be best placed to demonstrate compliance, protect investigations and maintain public confidence.
For organisations seeking to strengthen their approach to retention, review and disposal, or to better understand the expectations of regulators, inspectors and the courts, we are always happy to discuss the practical challenges involved. Contact us at info@thesignaturebrand.co.uk or join us on our webinar covering product management on the 2nd July 2026. Find out more about our webinar here: https://thesignaturebrand.co.uk/book-now-our-open-bitesized-training-schedule-for-2026/