A company register can show who owns a supplier. It may not explain who influences its decisions, why its delivery pattern changed or whether its stated capacity matches daily operations. Some information is not recorded in a database. It sits with people who have direct knowledge of the subject.

Human intelligence, or HUMINT, is the discipline used to collect and assess information from human sources. It is one of the oldest forms of intelligence, but it is not a shortcut to the truth. A source statement is still a claim. It becomes useful intelligence only after the collector records it accurately, evaluates the source, checks the information against other evidence and connects it to a decision.

What does HUMINT mean?

HUMINT is intelligence derived from information collected by human operators and primarily provided by human sources. It may come from an overt interview, a diplomatic or military contact, a debriefing, liaison work, direct observation or a covert source managed under specific authority.

HUMINT is not synonymous with espionage. The Office of the Director of National Intelligence notes that much US government HUMINT collection is overt.

In national-security and military doctrine, formal HUMINT collection is conducted by trained and authorised personnel. Corporate intelligence uses the term more broadly. Here, corporate HUMINT means structured, lawful collection from people to answer a defined intelligence question.

A sales call, employee survey or conference conversation is not automatically HUMINT. It enters an intelligence process when the organisation sets a requirement, documents and evaluates the report, controls its handling and compares it with other evidence.

HUMINT is not the same as a covert human intelligence source

In the UK, a Covert Human Intelligence Source, or CHIS, is a specific legal category. The Home Office CHIS code of practice concerns people who use a relationship covertly on behalf of a public authority to obtain or disclose information.

Not every human source is a CHIS, and not every HUMINT activity is covert. The code distinguishes CHIS activity from people who volunteer information or act under a professional duty without using a covert relationship.

Private companies do not acquire state investigatory powers by calling work “HUMINT”. Interviews, field research and authorised internal enquiries may be lawful corporate activities. Covert source handling, surveillance and deception require separate legal and ethical assessment.

What can HUMINT reveal?

Human sources can provide context that public records and technical collection do not contain. Depending on the question and the collector’s authority, HUMINT may help explain:

  • influence beyond a formal organisation chart;
  • how decisions are made in practice;
  • whether declared processes match everyday behaviour;
  • why a supplier, partner or competitor changed direction;
  • early warning signs not yet present in formal reporting.

HUMINT is valuable for intent, relationships and tacit knowledge. A financial statement can record a loss. A person close to the operation may explain whether it came from a disruption, a failing control or an undisclosed decision.

A source may be mistaken, biased, protecting an interest or repeating hearsay. Human reporting should not be treated as proof without corroboration.

Common HUMINT collection settings

The methods permitted in a military, law-enforcement or national-security operation differ from those available to a private company. At a high level, human-source collection can include:

  • Interviews and debriefings. A structured account from someone with relevant experience.
  • Expert and stakeholder conversations. Specialists, local operators, suppliers, customers and former executives may explain market or operational context.
  • Liaison. Counterparts exchange information within agreed legal and handling limits.
  • Direct observation. A collector records what they lawfully see during fieldwork, a site visit or an event.
  • Internal investigative interviews. Authorised teams speak with employees or witnesses about misconduct, fraud or a security incident.
  • Controlled human-factor testing. An approved exercise tests how staff verify requests and protect sensitive information.

Interrogation appears in some military and law-enforcement frameworks. It is not a normal corporate method. Social engineering is not a synonym for HUMINT: hostile actors may use it, while an authorised simulation may test an organisation’s defences.

How HUMINT fits into the intelligence cycle

Intelligence-cycle models vary, but HUMINT is a collection discipline rather than a finished product. A defensible process normally contains six stages.

1. Define the decision

Start with the decision. “Learn about the target” is too broad. “Determine whether the supplier has the management capacity and local relationships required for this contract” gives the collector a usable requirement.

2. Plan the collection

Identify what is known, which gaps matter and which sources may have relevant access. Set legal limits, recording rules and stop conditions before collection begins.

3. Collect and document

Record what the source said or observed. Separate direct knowledge from inference, opinion and hearsay. Preserve the date, context and handling restrictions.

4. Evaluate the source and the information

Source reliability and information credibility are separate. A reliable source can be wrong; an untested source can be accurate. Examine access, past accuracy, motive, consistency, timing and possible bias.

5. Corroborate and analyse

Compare the report with other sources, records, imagery, technical evidence and public information. Five people repeating the same rumour may still represent one original source.

6. Report, state uncertainty and review

Show what is confirmed, what rests on one source and what remains unknown. The UK government’s framework for explaining uncertainty in intelligence assessments links confidence to the information base, analytical rigour and complexity. New evidence may restart the cycle.

HUMINT vs OSINT, SIGINT and other intelligence disciplines

No single collection discipline provides a complete picture. The main difference lies in where the information comes from.

  • HUMINT comes from human sources and interpersonal contact.
  • OSINT comes from publicly or commercially available material that can be accessed lawfully, including company records, media, websites, publications and public digital activity.
  • SIGINT is derived from intercepted communications and other electromagnetic signals. Its collection is subject to strict legal authority.
  • GEOINT uses imagery and geospatial information to describe places, objects and activity.
  • MASINT uses specialised measurements and signatures to identify or characterise physical phenomena.

A public speech posted online is OSINT. A structured interview with the speaker is human-source reporting. Neither automatically validates the other.

An all-source assessment combines disciplines. HUMINT may explain intent. OSINT may establish chronology and ownership. GEOINT or technical evidence may test whether claimed activity occurred. The analyst identifies agreement, conflict and gaps.

Has technology made HUMINT obsolete?

Technology has changed HUMINT, not removed it.

Some information never enters a digital system. Decisions may be made in a meeting, and operational knowledge may remain undocumented.

People also control access. An insider, contractor or visitor may reach places and systems unavailable through remote collection.

Data does not always explain motive. Logs may show what happened; a source may explain why, who knew and what could happen next.

Technology improves parts of the work. AI-assisted OSINT can support background research and test a source’s stated experience before an interview. Transcription, translation and retrieval tools accelerate reporting. Analytical systems connect entities and events across case files.

The same tools create problems. Synthetic profiles, cloned voices, deepfakes and AI-generated documents complicate identity and provenance checks. Digital communication can expose a source. Automated summaries may remove caveats from a weak claim.

AI can organise material and suggest links. It cannot establish by itself that a person had access, told the truth or understood what they observed. Sensitive interview material should not be uploaded to third-party AI systems without reviewing confidentiality, retention, access and cross-border transfer terms. Technology raises the standard for verification.

How businesses use HUMINT

Corporate HUMINT should answer a business question, not collect personal information without a reason. Common lawful uses include:

Due diligence and third-party assessment

Interviews with industry sources, former counterparties or local specialists can test claims about ownership, operating capacity, reputation and relationships. Human reporting should complement, not replace, corporate records and third-party due diligence.

Market entry and competitor analysis

Public reports may describe a market without showing how purchasing decisions, informal influence or distribution channels work in practice. Structured expert interviews can add this context to business intelligence consulting.

Corporate investigations

Witness and employee interviews can help reconstruct a chronology, identify control failures and locate further evidence. A corporate investigation still needs records, preservation procedures and legal review before findings are used in disciplinary or litigation decisions.

Human-factor security assessment

Written and controlled tests can show whether employees verify unusual requests, protect credentials and follow access procedures. Molfar’s assessment of human-factor and social engineering risk connects authorised testing with technical and public-source evidence.

Legal and ethical limits

The legality of HUMINT depends on who collects, how they collect, the jurisdiction and the intended use. Private organisations should define the legal basis and scope before approaching sources or processing personal data, and obtain local legal advice where necessary.

A corporate process should address:

  • a defined requirement and written authority;
  • necessity and proportionality;
  • privacy, employment, recording and data-protection law;
  • source welfare and need-to-know access;
  • conflicts, incentives and payments;
  • retention, sharing and deletion;
  • legal or compliance review for sensitive methods.

The UK Information Commissioner requires a valid lawful basis for handling personal information. Extra conditions may apply to special-category and criminal-offence data. Cross-border work may engage several legal regimes.

HUMINT should not rely on coercion, bribery, unauthorised access or instructions to breach legal duties. Deceptive methods are not ordinary research. An authorised security test needs written rules, legal review, controlled data and a stop condition.

How organisations can reduce hostile HUMINT risk

Treat hostile human collection as a security risk, not a reason to distrust every conversation. Controls include:

  • role-based, need-to-know access;
  • separate-channel verification of unusual requests;
  • visitor, contractor and restricted-area controls;
  • training to recognise and report suspicious approaches;
  • screening for roles with sensitive access;
  • authorised tests of reporting and verification procedures;
  • evidence preservation and referral to security and legal teams.

Access logs, segmented networks and device management can limit what one person can reach. The aim is to stop a casual conversation, false request or trusted relationship becoming a route to sensitive information.

From a human report to a defensible assessment

HUMINT remains relevant because people hold knowledge, exercise judgement and make decisions. Its value does not come from secrecy alone. It comes from access, disciplined collection, careful handling and independent corroboration.

Molfar Intelligence combines human-source reporting with OSINT, corporate records, technical evidence and analyst judgement. The resulting assessment separates what a source said from what other evidence confirms, states the remaining uncertainty and explains how the finding affects the decision.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.