Guides & Tools

The FOI backlog recovery playbook

How access-to-information teams dig out of a request backlog — triage, intake discipline, a burn-down that holds, and the habits that stop it coming back.

Last reviewed: August 2026

Every FOI backlog looks the same from the outside: a number that keeps growing. From the inside, it is a queue of individually reasonable decisions — a vacancy left unfilled, a records custodian who stopped answering, a surge quarter nobody staffed for — that compounded. Backlogs compound because late files generate their own work: chaser emails, complaints to the oversight body, internal escalations, and eventually regulator investigations that consume the very analyst hours you needed for the queue. The Information Commissioner of Canada found the RCMP holding 4,532 active access requests in February 2019, 92 percent of them past their statutory due date — and traced the failure not to one cause but to six: tasking, procedures, training, electronic systems, insufficient resources, and the absence of any comprehensive recovery strategy.

This playbook is the field-tested sequence: triage what you have, stop the bleeding on new intake, run a disciplined burn-down, communicate before you are asked, measure recovery honestly, and change the conditions that created the backlog. It draws on what regulators in the UK, Canada, and the US have actually required of authorities in this position.

Step one: triage the backlog you already have

Build the inventory and age-band it

You cannot recover from a backlog you cannot describe. The first deliverable is a single list of every open request with its received date, statutory due date (including any extensions properly taken), current stage, assigned analyst, and estimated remaining effort. Then band it by age: 0–30 days, 31–90, 91–180, 181–365, and over a year. The bands matter because each one implies a different action. Files in the youngest band can still be saved on time; files over a year old will almost never be closed by normal processing and need a dedicated intervention.

Separate deemed-refusal exposure from merely-late

Not all late files carry the same risk. In deemed-refusal jurisdictions — Canada federally under subsection 10(3) of the Access to Information Act, Ontario under FIPPA, and many others — a request past its due date is legally treated as a refusal, which means the requester can complain or appeal immediately and the burden shifts to you. Under US federal FOIA, a blown deadline means constructive exhaustion: the requester can sue without waiting for your response. Mark every file that has crossed that legal threshold separately from files that are merely at risk of crossing it. The first group is your liability; the second is your opportunity, because every file you save from crossing shrinks the future problem.

Flag the special files

Pull out anything with a complaint or appeal already attached, anything in or near litigation, and anything from journalists, elected officials, or frequent requesters whose escalation is predictable. These files need named owners and weekly review regardless of where they sit in the age bands.

Identify the probably-abandoned

Every mature backlog contains requests that are effectively dead: a deposit invoiced and never paid, a clarification question never answered, a requester whose email now bounces. Do not close them yet — that comes in the burn-down, with proper notice — but count them now. It is common for 10–20 percent of a multi-year backlog to fall in this category, and knowing that changes the shape of the recovery plan you commit to.

Step two: stop the bleeding on new intake

A burn-down that runs while new requests quietly join the backlog is a treadmill. Before adding recovery capacity, fix the intake so that new requests stop becoming old ones.

Acknowledgment discipline

Acknowledge every new request within one or two business days, from a template, with the statutory due date computed and stated. This costs minutes and buys three things: it starts the file clean, it reduces the “did you even get my request” chasers that eat analyst time, and it forces the due-date calculation to happen on day one instead of being discovered in a panic on day twenty-nine.

Clarify early, once, and well

The most expensive clarification is the one sent in week three. If a request is ambiguous, ask on first reading — and ask everything in one message, not a drip of follow-ups. In several jurisdictions a well-founded clarification request pauses or restarts the statutory clock; in all of them it prevents the far worse outcome of searching for the wrong records and starting over.

Have the scoping conversation

A ten-minute phone call with a requester about what they actually want is the highest-leverage act in FOI processing. Broad requests are usually broad because the requester does not know how your records are organized, not because they want everything. Offer the narrower interpretation explicitly, confirm it in writing, and note the agreement on the file. Regulators consistently endorse this; requesters usually prefer a fast, focused release to a slow, padded one.

Run two queues

Keep new intake and backlog recovery as separate queues with separately protected capacity. If one team works a blended pile, urgent-and-new always crowds out old-and-hard, and the backlog core never shrinks. The split can live inside one team — two named analysts on recovery, everyone else on intake — but it must be explicit, or it will not survive the first busy week.

Step three: the burn-down

Dedicated capacity versus blend

Dedicate if you can. A recovery cell of even two people who touch nothing but backlog files will outperform a whole team doing backlog work “when things are quiet,” because things are never quiet. If headcount is impossible, dedicate time instead: recurring blocked days that leadership visibly protects. What matters is that backlog hours are scheduled and accounted for, not residual.

Oldest-first versus quickest-first

Quickest-first collapses the count: close the near-complete files, the duplicates, the single-document requests, and morale and statistics both improve within weeks. But it leaves the oldest files aging, and those are the ones generating complaints and regulator attention. Oldest-first attacks the legal risk but produces weeks of invisible effort on the hardest files. The answer is a fixed ratio, not a philosophy — for example, 60 percent of recovery hours on the oldest band, 40 percent on quick closures — reviewed monthly. Choose quickest-first weighting when the backlog is young and morale is the constraint; choose oldest-first weighting when deemed-refusal files or an active regulator investigation dominate the risk.

Batch the look-alikes

Sort the inventory by subject as well as age. Ten requests touching the same program, incident, or dataset can share one records search, one set of consultations, and one exemption analysis. Batching routinely turns ten file-efforts into three.

Close the abandoned — with documented notice

Now act on the abandoned files identified in triage. The defensible pattern: a written notice to the requester's address of record stating exactly what is outstanding, a stated deadline of two to four weeks to respond, a plain statement that the file will be closed as abandoned otherwise, and a copy retained on the file. Then actually close them on the stated date. Done this way, bulk closure is legitimate housekeeping that regulators accept; done silently, it is the seed of the next investigation.

Release in parts

Where the statute permits, interim releases convert a stuck 2,000-page file into a flowing one. Releasing the reviewed 400 pages now, with the rest to follow, reduces complaint risk, shows the regulator movement, and often satisfies the requester enough that the remaining scope narrows.

Communicate before you are asked

To requesters: when a file is late, say so, give a revised date you can actually meet, and meet it. A requester with an honest date complains far less than one in silence — and every complaint you prevent is analyst hours returned to the queue.

To the regulator: the evidence strongly favours going first. In December 2024 the UK Information Commissioner's Office publicized action against four authorities, and the contrast is instructive. Goldsmiths, University of London had itself notified the ICO that it could not meet its timeliness obligations; Dorset Police had already cut its backlog from 205 overdue requests in July 2023 to 52 — both received supportive practice recommendations. The City of London Police, with compliance at 68 percent, received a binding enforcement notice: an action plan within 30 days and the backlog cleared within six months. The pattern repeated in December 2025, when the Foreign, Commonwealth & Development Office — which had let performance slide after an earlier practice recommendation — was put under an enforcement notice with quarterly-measured targets running to 2027 and the High Court as the stated consequence of failure. Arriving with your own inventory, plan, and weekly numbers is not an admission; it is the difference between the two outcomes.

Measure the recovery

Five numbers, reviewed weekly, on one page:

  • On-time percentage of requests closed that week — the intake-discipline signal. If this is not rising toward the 90 percent range regulators now set as targets, the bleeding has not stopped.
  • Median age of open requests — the honest centre of the queue. Falling median with a stable count means the burn-down is reaching the old files.
  • Oldest open request — a single date that keeps the worst file visible to leadership every week.
  • Net closure rate — closures minus new intake. This is the only number that predicts the finish date: backlog divided by weekly net closures equals weeks remaining.
  • Files past statutory due date — the deemed-refusal count, which is what your regulator will measure you by.

Resist the temptation to report only the total open count. A total can fall for months while the oldest files rot — the exact pattern systemic investigations later call out.

Prevent the relapse

Relapse is the norm, not the exception. The FCDO improved from 37 percent on-time responses to 77 percent within a year of its 2024 practice recommendation — then slid to 47 percent while its overdue backlog grew from 32 to 174 during 2025, ending in enforcement. Recovery that depends on a heroic push relapses when the push ends. What holds:

  • Capacity planning from your own statistics. You now have real numbers: requests per month, hours per request by complexity, seasonal peaks. Turn them into a staffing case — the US GAO found in March 2024 that of fourteen federal agencies required to produce backlog-reduction plans, only two set goals and none set timelines. A plan with your own arithmetic in it is rarer, and more fundable, than it should be.
  • Templates for everything repeatable. Acknowledgments, clarifications, fee estimates, extension notices, abandonment notices, release letters. Every templated minute is a minute returned to review work, and templated notices are also more legally consistent.
  • Delegation that matches the work. If every release needs a signature from someone with a three-week inbox, the signature is your bottleneck. Formal delegation instruments that push routine decisions to trained analysts are among the most common systemic-investigation recommendations for a reason.
  • Early-warning triggers. Decide now what number triggers intervention — median age above 25 days, on-time percentage below 85, any file entering the 91-day band — and who is obliged to act on it. A backlog caught at 30 files is a bad month; caught at 300, it is a two-year program.

Sources

If your team is planning a recovery, the numbers behind the staffing case are worth modelling — the FOI ROI calculator works through hours per phase and volume. AccessPoint handles the mechanics this playbook depends on — computed statutory deadlines, age and on-time reporting, templated notices, and an audit trail of every closure — inside your own Microsoft 365 tenant; see FOI request management, or import your existing backlog, statuses and due dates intact, and book a demo to see the burn-down reporting live.

Backlog Recovery Questions

Should we work the oldest requests first or the quickest ones?

Both, deliberately. Quickest-first closures shrink the count fast and free up capacity, but they leave your oldest and riskiest files untouched. Oldest-first reduces deemed-refusal and complaint exposure but shows slow progress on the headline number. Most successful recoveries split capacity: a fixed share of hours on the oldest files every week, with the rest clearing quick wins. What fails is drifting between the two without a rule.

Can we close old requests where the requester has gone silent?

Usually yes, if you do it properly. Write to the requester at their address of record, state what is outstanding (an unpaid deposit, an unanswered clarification), give a clear response deadline of two to four weeks, explain that the file will be closed as abandoned if you hear nothing, and keep a copy of the notice on the file. A documented abandonment process closes files defensibly; quietly deleting them creates complaints and destroys trust with your oversight body.

Should we tell the regulator we have a backlog before they come asking?

In most cases, yes. Regulators in the UK and Canada have repeatedly shown they treat authorities that self-report and arrive with a credible plan more leniently than authorities they have to chase. Dorset Police cut an FOI backlog from 205 overdue requests to 52 and received a supportive practice recommendation; authorities that ignored earlier recommendations, like the UK Foreign, Commonwealth and Development Office, ended up under legally binding enforcement notices.

How long does a backlog recovery realistically take?

Plan in months, not weeks. Regulator-imposed timelines are a useful benchmark: the ICO gave the City of London Police six months to clear its backlog, and gave the FCDO roughly two years to reach and sustain 90 percent on-time compliance. A working rule of thumb: divide the backlog by your demonstrated net closure rate (closures minus new intake per week) and add contingency for the oldest, hardest files.

What metrics prove the backlog is actually recovering?

Track five numbers weekly: on-time percentage for newly closed requests, median age of open requests, age of the oldest open request, net closure rate (closures minus intake), and the count of files past their statutory due date. A shrinking total count alone can hide a rotting core of very old files; median age and oldest-open expose it.

See AccessPoint in action. 30 minutes, on your jurisdiction's rules, with the person who built it.

© 2026 Realizer Services Inc. About Privacy Terms