Skip to content
AI-014 Accounts & Identity

Accounts & IdentityAI-014

Who was responsible for the activity?

Responsibility is an evidential conclusion drawn from conduct, knowledge and control. Account ownership, access or use may contribute to that conclusion, but none of them automatically proves who was responsible for the activity.

Start with the conduct

Identify precisely what happened and which decision, instruction or action caused the relevant outcome.

A person may have:

  • carried out the activity personally;
  • instructed somebody else to carry it out;
  • configured software or an automated process;
  • knowingly provided access;
  • approved or directed the activity; or
  • controlled the operation without performing the final technical action.

Responsibility may therefore extend beyond the person who pressed a button or used the final device.

Equally, the registered account holder may have had no involvement. The account may have been shared, misused or compromised.

Separate the different roles

Do not collapse every role into the label “account holder”.

Establish, where relevant:

  • who registered or paid for the account;
  • who controlled its credentials and recovery methods;
  • who had access at the relevant time;
  • who used the device, browser or session;
  • who gave instructions or approved the activity;
  • who benefited from the outcome; and
  • who attempted to conceal, continue or explain the activity afterwards.

These roles may belong to one person or to several people with different levels of involvement.

What may support responsibility

Technical records should be considered alongside the wider evidence.

Relevant material may include:

  • messages and communications;
  • device and session evidence;
  • financial records;
  • location and access records;
  • witness accounts;
  • admissions or explanations;
  • evidence of planning or benefit; and
  • behaviour before and after the event.

The strength of the conclusion normally comes from the way these sources combine, rather than from one account, IP address, device or login record in isolation.

What account evidence does not establish

A name attached to an account does not by itself prove who performed an action.

Likewise, evidence that a device or session accessed an account may establish a technical link without proving who controlled it, what they knew or whether they authorised the activity.

Technical uncertainty should not obscure strong wider evidence, but technical association should not be overstated as personal responsibility.

Where responsibility may have a particular legal or disciplinary meaning, apply the relevant legal test, policy or specialist advice separately.

State the conclusion accurately

Match the wording to the strength of the evidence.

There is an important difference between saying:

  • a person was linked to the account;
  • the evidence is consistent with them using it;
  • the evidence supports them directing or controlling the activity; and
  • the evidence establishes that they were responsible for the conduct.

Each conclusion requires a different level of evidential support.

The investigative question is not merely who owned the account. It is who did what, when, with what knowledge, authority and control.

Key takeaway

Determine responsibility from the complete evidential picture. Separate account ownership, access, use, direction and control, then state only the conclusion that the combined evidence supports.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.