Intelligence analysis methodology: how to produce a defensible assessment

12 min readUpdated Aug 2026
In short

Correct intelligence analysis follows six steps: define the requirement, plan and run collection, evaluate each source for reliability and credibility, apply structured analytic techniques to test competing explanations, express findings in calibrated estimative language with an explicit confidence level, and deliver a BLUF-first product that lists assumptions, intelligence gaps and recommended actions.

Most security assessments fail not because the analyst lacked information, but because the reasoning was never made explicit. A defensible assessment separates what is known from what is inferred, states how likely each outcome is, declares how confident the analyst is and why, and remains readable by a decision-maker in under two minutes.

Key takeaways
  • Analysis starts with a decision to support, not with data collection.
  • Rate the source and the information separately — a reliable outlet can still carry a doubtful claim.
  • Use structured techniques (ACH, key assumptions check, red teaming) to attack your own leading hypothesis.
  • Never mix likelihood with confidence: one describes the world, the other describes your evidence.
  • Every product states its assumptions, its gaps and what would change the judgement.

1. Requirements: define the decision before the question

An intelligence requirement is anchored to a decision someone must take: whether to move a set-down point, whether to add a search lane, whether to change a principal's arrival window. Write the requirement as a question with a decision attached, a deadline, and the threshold at which the answer changes behaviour.

Break the requirement into essential elements of information (EEI) — the specific facts needed to answer it. EEIs make collection tasking testable and make gaps visible when they are not filled.

  • Decision supported: what will change based on the answer.
  • Question: single, falsifiable, time-bounded.
  • EEIs: the discrete facts required.
  • Deadline: when the answer stops being useful.

2. Collection: plan it, log it, bound it

Collection is tasked against EEIs, not against curiosity. Maintain a collection plan that maps each EEI to sources, owners and a check time, and log every item with its URL, publication date and retrieval time. An item with no retrievable origin cannot enter the assessment as evidence.

Bound the collection window. For event work, information older than the last comparable edition of the event is context; information from the final 72 hours is signal.

3. Source evaluation: reliability and credibility, rated separately

The NATO Admiralty scale remains the clearest convention: a letter for source reliability (A completely reliable to F cannot be judged) and a number for information credibility (1 confirmed to 6 cannot be judged). A B2 rating tells a reader far more than the phrase "a good source said".

Rate corroboration honestly. Three outlets republishing one agency wire is one source, not three. Independent corroboration means independent origin.

  • A-F: reliability of the source, based on its history and access.
  • 1-6: credibility of this specific item, based on corroboration and plausibility.
  • Circular reporting check: trace each item to its original publisher.

4. Structured analytic techniques: test, do not confirm

The default failure mode of analysis is confirmation bias: building a case for the first plausible story. Structured analytic techniques force the opposite behaviour.

Use analysis of competing hypotheses (ACH) to score evidence against every candidate explanation and eliminate the hypotheses with the most inconsistent evidence, rather than promoting the one with the most supporting evidence. Run a key assumptions check to surface load-bearing beliefs nobody has tested, and a devil's advocacy or red-team pass on any judgement that drives significant expenditure or restriction.

  • Analysis of competing hypotheses — disconfirm rather than confirm.
  • Key assumptions check — list assumptions, ask what happens if each is wrong.
  • Indicators and warnings — pre-define observable signs that a scenario is materialising.
  • Red team / devil's advocacy — argue the rejected hypothesis deliberately.
  • What-if analysis — assume the low-probability, high-impact case happened and work backwards.

5. Estimative language: calibrated probability words

Words like "possible" and "likely" mean different things to different readers, so intelligence practice pins them to numeric ranges and uses them consistently. A common yardstick: almost no chance (1-5%), very unlikely (5-20%), unlikely (20-40%), roughly even chance (40-60%), likely (60-80%), very likely (80-95%), almost certain (95-99%).

Never hedge twice. "It is possible that there may perhaps be disruption" carries no information. Choose one probability term, state the timeframe, and name the outcome.

6. Confidence levels: about the evidence, not the event

Confidence describes the quality of the evidentiary base and the reasoning behind a judgement — source depth, corroboration, gaps, assumption load. Likelihood describes the world. A judgement can be "very likely" with low confidence when it rests on a single uncorroborated source.

State confidence as high, moderate or low, and justify it in one sentence naming the driver: corroboration, source access, recency or assumption dependence.

7. Reporting: BLUF, gaps and triggers

Lead with the bottom line up front: the judgement, its probability term, its confidence level and the single action it implies. Everything after the BLUF exists to let a reader audit the judgement.

Close with intelligence gaps and change triggers — the specific observations that would raise or lower the assessment. A product that cannot be falsified by future events was never an assessment.

  • BLUF: judgement + probability + confidence + implied action.
  • Assumptions: explicit and dated.
  • Gaps: what you could not answer, and who could.
  • Triggers: observations that would change the judgement.

8. Analytic standards and integrity

Public analytic standards (notably the US ODNI's ICD 203) codify what practitioners expect: objectivity, independence from policy preference, timeliness, clear source description, distinction between underlying intelligence and assumptions, expression of uncertainty, consistency over time with an explicit note when a judgement changes, and accurate attribution of others' work.

Applied to commercial event security, the practical test is simple: could a reader who disagrees with you reconstruct exactly how you reached the judgement, and identify the evidence that would overturn it?

Frequently asked questions

What is the intelligence analysis process?
The intelligence analysis process runs through requirements definition, collection planning, source evaluation, structured analysis, estimative judgement with confidence assessment, and dissemination in a BLUF-first product, followed by feedback that refines the next collection cycle.
What is the difference between likelihood and confidence?
Likelihood is the estimated probability that an outcome occurs, expressed with calibrated terms such as unlikely or very likely. Confidence describes how strong the evidence and reasoning behind that estimate are, expressed as high, moderate or low. A judgement can be very likely but held with low confidence.
What are structured analytic techniques?
Structured analytic techniques are explicit procedures that make reasoning visible and reduce cognitive bias — analysis of competing hypotheses, key assumptions checks, indicators and warnings, red teaming, what-if analysis and premortem. They are designed to disconfirm hypotheses rather than accumulate supporting evidence.
How do analysts rate sources?
Analysts rate the source and the information separately, commonly with the NATO Admiralty scale: a letter A to F for source reliability and a number 1 to 6 for the credibility of the specific item. Corroboration only counts when the corroborating reports have independent origins.

Apply this to your next event

Preventio turns event details into a structured intelligence brief with OSINT review, threat matrix, crowd analysis and operational recommendations.