Ongoing operations
Whistleblower reporting channel
The EU Whistleblower Directive requires organisations to provide safe, anonymous channels for reporting misconduct. EuroCompliant provides a built-in whistleblower reporting channel that meets these requirements.
Transcript
The EU Whistleblower Directive requires organisations with more than 50 employees to establish internal channels for reporting breaches of EU law. Non-compliance can result in fines and reputational damage. EuroCompliant provides a built-in channel that meets these requirements.
Reports can be submitted without an account. The reporter selects a category, describes the concern, and receives a claim code. This code lets them track the status and receive responses without revealing their identity.
Reports are categorised into fraud, safety, AI violation, discrimination, or other. This helps compliance administrators prioritise and route the report to the right person for investigation.
After submission, the reporter gets a unique claim code. They can check the status of their report at any time by entering this code on the public status page, without logging in or creating an account.
Compliance administrators see every report in the Whistleblower dashboard, each with its category, status, and description, without anything identifying the reporter.
Reports carry a status of open, under investigation, or resolved, and the claim code is all a reporter needs to check it, any time, without ever creating an account or revealing who they are.
The submission itself, timestamped and categorised, is the record regulators expect during an inspection: proof the channel exists and was actually used, not just documented as a policy.
Why this is required
The EU Whistleblower Directive (2019/1937) requires organisations with more than 50 employees to establish internal reporting channels. Non-compliance can result in fines and reputational damage.
A structured reporting channel protects both the reporter and the organisation, ensuring reports are handled consistently and documented for regulatory review.
What EuroCompliant does
Reports can be submitted without an account. The reporter receives a claim code and can check their report's status with it at any time, without revealing their identity.
Compliance administrators see every report in the Whistleblower dashboard: its category, status, and description, without anything identifying the reporter.
The submission itself is timestamped and categorised: the record regulators expect during an inspection, proof the channel exists and was actually used.
Walking through it
Set up the reporting channel
Configure the whistleblower channel in your organisation settings. Share the public reporting URL with your team.
Open /settings →Review incoming reports
Compliance administrators can view every report, its category and status, in the Whistleblower dashboard.
Open /operations →Reporters track their own report
A reporter checks their report's status anytime with their claim code. No account, no login, no way to identify them.
Open /operations →The law
Internal reporting channels
Organisations with more than 50 employees must establish internal channels for reporting breaches of EU law, including the AI Act.
Risk management system
Effective incident reporting and whistleblowing channels support the continuous risk management process required by the AI Act.
Frequently asked
Can reporters remain anonymous?
Yes. Reports can be submitted without creating an account. The reporter receives a claim code to track their submission.
Who can see the reports?
Only designated compliance administrators with the appropriate role can view whistleblower reports, and the report never contains anything identifying the reporter.
Related guides
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Serious incident reporting
The Article 73 duty when a high-risk AI system causes serious harm, with deadlines that tighten to two days in the worst cases.
Team, roles and access control
Inviting your team, assigning roles, organising departments, and locking down accounts with 2FA and SSO.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial