Analysis of competing hypotheses (ACH): a working method for security teams
Analysis of competing hypotheses is a structured technique in which an analyst lists all plausible explanations, builds a matrix of evidence against every hypothesis, marks each item consistent, inconsistent or not applicable, and rejects the hypotheses with the most inconsistent evidence. The surviving hypothesis is the judgement, and diagnostic evidence drives it.
ACH was designed to counter the single most common analytic failure: adopting the first plausible explanation and then collecting evidence that supports it. It replaces advocacy with elimination.
- Generate the full hypothesis set before looking at the evidence.
- Score every item against every hypothesis, not only the favoured one.
- Diagnostic evidence discriminates between hypotheses; everything else is noise.
- Eliminate on inconsistency — do not crown the hypothesis with the most supporting items.
- Record what would overturn the surviving hypothesis.
Step 1 — Build the hypothesis set
List every plausible explanation, including the ones you consider unlikely and the deliberately uncomfortable one. For an unexplained reconnaissance report near a venue, the set might include hostile pre-attack surveillance, journalistic activity, activist scouting, commercial filming and coincidence.
Step 2 — List the evidence and the arguments
Include hard evidence, absence of expected evidence, and assumptions. Absence matters: if hostile surveillance were under way, you would normally expect repeat sightings, and the absence of them is itself evidence.
Step 3 — Score the matrix for diagnosticity
For each item, mark consistent, inconsistent or not applicable against each hypothesis. An item consistent with every hypothesis has zero diagnostic value, however dramatic it looks. The analytic work concentrates on the small number of genuinely discriminating items.
Step 4 — Refute, then rank
Rank hypotheses by weight of inconsistent evidence and reject from the bottom. The hypothesis with the fewest inconsistencies survives — not the one with the warmest narrative. Where two survive, say so and task collection against the item that would separate them.
Step 5 — Report sensitivity and triggers
State which one or two items the judgement rests on and what happens if they are wrong. This turns the assessment into something operations can monitor: name the observable that would flip the conclusion, and who is watching for it.
Frequently asked questions
- When should ACH be used?
- Use ACH when several explanations are plausible, when the decision carries significant cost, when an early hypothesis has become entrenched, or when evidence is fragmentary and partly from unreliable sources.
- What is diagnostic evidence?
- Diagnostic evidence is information that is consistent with some hypotheses and inconsistent with others, so it changes the ranking. Evidence consistent with every hypothesis has no diagnostic value and should not drive a judgement.
Apply this to your next event
Preventio turns event details into a structured intelligence brief with OSINT review, threat matrix, crowd analysis and operational recommendations.
Related guides
The correct intelligence analysis methodology, step by step: requirements, collection, source evaluation, structured analytic techniques, estimative language, confidence levels and BLUF reporting.
Probability yardsticks, confidence levels and analytic standards: how to phrase intelligence judgements so decision-makers read them the way the analyst intended.
A structured methodology for event threat assessment: scenario framing, likelihood and impact scoring, vulnerability analysis and a defensible overall risk rating.
