The Madlanga Commission

Verify Leaks Fast Using MVS, AP and Madlanga Records for Journalists

A concise checklist for journalists to secure, verify and document leaks using the MVS matrix, AP standards and Madlanga records.

Published 2026-09-10

Verify Leaks Fast Using MVS, AP and Madlanga Records for Journalists

Verify Leaks Fast Using MVS, AP and Madlanga Records for Journalists

Journalist comparing archival case files

Publish leaked material only when it clears three gates: the documents check out, publication serves a genuine public interest, and releasing them won’t get someone hurt. If any gate fails, hold the story. If a leak lands on your desk right now, isolate the files, preserve the original in its native format, and loop in an editor before you read past page one.


TL;DR:

  • Leaks should only be published after thoroughly authenticating the material through metadata checks, independent verification, and corroboration from public records or expert sources.
  • Assess the source’s motive carefully, considering the leak’s timing and whether it benefits personal, political, or organizational interests, which influences how skeptically the material is treated.
  • Editorial and legal approval must be obtained in writing before publication, ensuring the organization understands confidentiality risks and jurisdictional legal protections.
  • Redact all unnecessary identifying details and transparently report which claims are verified to maintain credibility and minimize harm.
  • Keep detailed, timestamped records of verification steps to defend against potential challenges and promote responsible, ethical reporting.

Madlanga Commission
Follow The Evidence Behind The Headlines
Explore testimony, case files, and evolving evidence from the Madlanga Commission in one accessible public record.
Explore the Commission records

Table of Contents

Ethical reporting on leaks: the step-by-step checklist

Every leak deserves the same disciplined sequence, whether it arrives as a manila envelope or an encrypted drive. Skipping steps under deadline pressure is how newsrooms end up retracting stories.

  1. Triage the source and the material. Note who sent it, how they contacted you, and what they seem to want. Preserve the original files untouched before you do anything else.
  2. Move to a secure environment. Review sensitive documents on an air-gapped machine, not a networked laptop, and store copies in encrypted storage with access limited to people who need it.
  3. Authenticate before you report. Check metadata, look for signs of tampering, and corroborate claims against public records, named experts, or a second independent source.
  4. Run the public-interest test. Ask what harm publication prevents versus what harm it might cause, and weigh that against the source’s own motive.
  5. Seek comment from the subjects. Give them a real window to respond, not a token email sent an hour before deadline.
  6. Redact and minimize harm. Strip identifying details that don’t serve the story, following the same checklist Media Helping Media uses for verifying sources and protecting them.
  7. Get editorial and legal sign-off. Document who approved what and why, before publication, not after a complaint arrives.
  8. Tell readers what you verified. State plainly which claims are confirmed and which remain unverified.

Pro Tip: Keep a private, timestamped log of every verification step as you go. If the story is ever challenged, that log is your best defense, and rebuilding it from memory after the fact never holds up as well.

How to verify leaked material before you report it

Authentication is not optional, and it is not a single step. It’s a layered process that starts with the file itself and ends with independent human confirmation.

AP’s standard requires managerial vetting and outside corroboration before anonymous-source material runs, and that same bar applies to leaked documents, according to AP’s guidelines on anonymous sources. Being transparent about which parts you’ve confirmed, ethics reviewers note, tends to be the strongest defense against accusations of inaccuracy later.

Why did the leak happen, and does the public need it?

Motive doesn’t decide whether you publish. It shapes how skeptically you read the material and how you frame it for readers. A whistleblower exposing safety failures and a rival leaking a competitor’s emails both hand you documents, but they deserve very different scrutiny.

Tell readers what you know about the source’s likely motive, even in broad terms, so they can weigh the story the same way you did.

Before anything runs, someone above the reporter needs to have actually reviewed the decision, not just been told about it.

  1. Confirm sign-off exists in writing. A verbal “go ahead” from a busy editor is not documentation.
  2. Assess confidentiality promises against reality. Can your organization actually resist a subpoena for source identity, or is that promise weaker than it sounds?
  3. Prepare a legal defense before you need one. Know your jurisdiction’s protections and your outlet’s appetite for a fight if challenged.
  4. Decide what to tell readers about uncertainty. State plainly which claims rest on one source versus several, and where verification stopped.

AP’s model requires this kind of managerial vetting specifically because anonymous or leaked material carries more risk than on-record reporting, and that vetting standard exists precisely to catch problems before publication, not after.

What a public inquiry teaches reporters about sourcing

Public inquiries offer a working model for documenting how evidence gets handled, and reporters can learn from watching one operate in real time.

A working journalist’s take on leaks and trust

The instinct to protect a source and the instinct to inform the public rarely conflict as often as newsroom debates suggest. Most leaks fail on veracity long before they raise a genuine ethical dilemma about harm. My heuristic under deadline pressure: if you can’t explain your verification steps to a skeptical reader in three sentences, you’re not ready to publish, whatever the motive behind the leak.

— Meriol Lainchyon

Quick reference: standards worth bookmarking

Keep the MVS matrix, the Perugia Principles, and the Madlanga Commission’s case files close at hand for your next leak decision.

Sources

Source protection is a technical problem as much as an ethical one. Good intentions don’t stop a subpoena or a compromised inbox.

The Perugia Principles treat confidentiality as the default for whistleblowers, not a courtesy extended case by case, and call for stronger legal protections around the world, though those protections vary sharply from one country to the next.

Pro Tip: When redacting PDFs before publication, use a tool built for permanent redaction rather than a black box drawn over text in a PDF viewer. A tool like FlowPDF’s redaction feature strips the underlying data instead of just hiding it visually, which matters because plenty of “redacted” leaks have been unmasked by simply copying the covered text.

FAQ

What does ethical reporting mean?

It means verifying material independently, weighing public interest against potential harm, and being transparent with readers about what you confirmed and what remains unverified.

What is a leak in journalism?

A leak is confidential or restricted information passed to a journalist without official authorization, often by someone inside an organization with direct access to it.

What does the MVS matrix mean in journalism?

MVS stands for motive, veracity, and security. It’s a framework for evaluating why a source is leaking material, whether that material is genuine, and what risks publishing it could create, as described in Media Helping Media’s MVS matrix.

What are the main ethical considerations for reporters handling leaks?

Reporters need to verify authenticity, assess source motive, protect confidential sources, seek comment from subjects, redact unnecessary personal details, and get editorial and legal sign-off before publishing.