A Case Study: Improving FOI Performance

Recently the Information Commissioner’s Office (ICO) has taken a more robust approach to Freedom of Information (FOI) compliance in parts of the NHS, including serving enforcement notices on trusts where performance has fallen well short of the statutory deadline. (Information Commissioner’s Office) Many of these organisations (and they won’t be alone) have had longstanding difficulty meeting the 20 working day requirement under the Freedom of Information Act 2000 (FOIA).

Over the years I’ve been brought in to address poor FOI performance and bring it back up to standard. Given the ICO’s firmer stance, I thought I’d share a practical, “what worked” case study of how I tackled a significant backlog and stabilised delivery.

 

________________________________________________________________________________________________

About the Author
Michael is an expert in governance and information governance, with many years’ experience developing and improving freedom of information systems and processes. He has worked in this field across the public sector including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five star rated Freedom of Information course.

What is Freedom of Information?

FOIA gives anyone the right to request recorded information held by public authorities, including NHS trusts. In broad terms, you have two core duties when you receive a request:

  1. Confirm whether you hold the information, and
  2. Provide it, unless a valid exemption applies. (Information Commissioner’s Office)

Your obligation is to respond promptly, and in any event no later than the 20th working day after receipt (with day 1 being the first working day after the request is received).

You also have a duty to provide advice and assistance to requesters, which often means helping them clarify what they actually want and guiding them towards what you can provide in the quickest, most helpful way.

Finally, FOIA requires authorities to maintain a publication scheme—proactively publishing certain classes of information. (Done well, proactive publication is one of the most effective ways to reduce FOI volume and repeat requests.)


Consequences of non-compliance

Unlike GDPR, FOIA doesn’t generally involve large monetary penalties for late responses. But that doesn’t make FOI “low risk”.

The ICO’s key enforcement tool is the enforcement notice. These carry real weight: if you fail to comply with an enforcement notice, you can end up in serious legal territory, and the reputational and operational impact can be significant.


The case study: what I walked into

I was brought in as interim Director of Governance for an NHS Trust, with FOI under my remit. The Trust had a sizeable backlog (several hundred), with many requests more than a year overdue.

How did it happen?

The root cause wasn’t one dramatic failure—it was a set of predictable process gaps:

  • No single, reliable log/tracker of requests
  • Weak or inconsistent handoffs to departments holding the information
  • No structured follow-up (requests simply went “cold”)
  • Duplicate/repeat requests not spotted
  • Limited cross-referencing to information already published
  • Inconsistent exemption decisions and wording across similar requests
  • Little or no management reporting, so poor performance wasn’t visible early enough

Most concerning of all was a tendency to focus on who was asking and why. That is directly contrary to the spirit of FOIA, wastes time, and creates avoidable delay.


Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won’t use your data for anything else.

Sign Up Here:

 

________________________________________________________________________________________________

What I did: the remediation approach

1) Backlog triage (without pretending it “fixes” historic lateness)

First, we stabilised the situation by triaging the oldest requests.

  • Where requests were unclear or ambiguous, we wrote to the requester to clarify scope. Under ICO guidance, where clarification is needed to identify and locate the information, the effective “date of receipt” becomes the date the clarification is received. (Information Commissioner’s Office)
  • If clarification didn’t arrive, we used a clear cut-off. The ICO notes that two months is usually an appropriate time to wait for clarification before closing (with an invitation to resubmit at any time).

For valid, clear requests that were already late, we didn’t pretend the statutory breach vanished. But we did contact requesters to check whether they still wanted a response, and if so we agreed a firm delivery date and treated that as a restart point for operational planning. (In practice, many old requests were no longer needed, and confirming that freed capacity for the ones that mattered.)

2) A single tracker and “pre-deadline” chasing

Next, we rebuilt the basic engine:

  • One authoritative FOI tracker with owners, dates, status, and dependencies
  • A standard workflow that built in at least two chases within the 20 working day window (before you’re in trouble, not after)
  • Escalation rules: if a department hasn’t responded by a set day, it triggers escalation automatically

3) Better use of what’s already published (and what’s about to be)

We reduced unnecessary work by improving how we handled “already public” information:

  • Stronger signposting to information already published (including where it sits)
  • Better internal awareness of what was scheduled for publication, so teams could respond consistently and quickly

4) Exemptions applied consistently and faster

We invested time in exemption capability (this is where many organisations lose days or weeks):

  • Standardised exemption templates and reasoning
  • Training/support for departments on how to apply relevant exemptions consistently
  • Ensuring teams understood when they needed to justify decisions and when a public interest test was relevant (and documenting that clearly)

5) Proactive publication that reduces repeat demand

We also improved the publication scheme approach in a very practical way:

  • Publishing FOI requests and responses (appropriately redacted) where feasible, to reduce repeats
  • Keeping an accessible library of frequently requested information
  • Publishing a “we don’t hold this information” explainer for the most recurring misconceptions—with governance (reviewed regularly) so it remained accurate

6) Handling repeat/simple requests in-team (with a quick sense-check)

Finally, we reduced turnaround time on “FOI churn”:

  • The FOI team handled straightforward and repeat requests in-house using previous precedents with a short sense-check to confirm circumstances hadn’t materially changed.
  • Where a request was genuinely repetitive, we considered whether it should be treated as a repeat request under FOIA section 14(2), in line with ICO guidance.

7) “Applicant blind” built into the process

We embedded “applicant blind” handling:

  • Requests were redacted to remove identifiers and irrelevant background before being passed to departments
  • Teams were coached to focus on the information held and the statutory tests—never the requester’s identity or motives

Reporting and metrics that drive the right behaviour

We reported:

  • % completed within 20 working days
  • Average response time, aiming for <10 working days overall

That second metric matters because the ICO makes clear the legal requirement is promptly, with 20 working days acting as the outer limit—not a target. (Information Commissioner’s Office)

We also reported performance by department, which:

  • highlighted bottlenecks,
  • enabled targeted support,
  • and reduced the “mystery” around why FOI was slipping.

A key learning: clear the “easy wins” fast. Rapidly closing requests where information isn’t held (with a helpful explanation) improves averages dramatically and frees time for complex cases.


Want help improving FOI performance?

If you’d like help with FOI remediation—process redesign, triage, training, publication strategy, or performance reporting—please get in touch.

________________________________________________________________________________________________

Learn About the Freedom of Information

Gain the practical skills you need work with Freedom of Information and GDPR with these five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

 

Five star training testimonial