> Whistleblower reporting requirements for banks, investment firms, and insurers under EU Directive 2019/1937, MiFID II, MAR, and AML directives, and what DORA means for procuring a reporting channel.

Source: https://ethicsportal.eu/industries/financial-services/
Updated: 2026-08-24

---

# Whistleblower compliance for financial services

Financial institutions operate under the EU Whistleblower Directive *and* sector-specific regulations that independently require internal reporting channels. Non-compliance exposes firms to penalties from both national transposition laws and financial regulators.

## Regulations that require reporting channels

- **EU Directive 2019/1937** — requires confidential reporting channels, 7-day acknowledgment, and 3-month feedback deadlines. The 50-employee threshold that applies to most private-sector firms **does not apply to regulated financial entities**: under Article 8(4), entities within the scope of the Union financial-services and anti-money-laundering acts listed in Parts I.B and II of the Annex must operate an internal reporting channel irrespective of headcount. A supervised firm with 20 employees carries the same obligation as one with 2,000.
- **MiFID II (2014/65/EU)** — Article 73 requires investment firms to have procedures for employees to report potential breaches internally. National regulators enforce this independently of the Whistleblower Directive.
- **Market Abuse Regulation (EU 596/2014)** — Article 32 requires member states to establish mechanisms for reporting actual or potential market abuse. Firms must ensure internal channels exist so employees can report before going to regulators.
- **Anti-Money Laundering Directives (AMLD 4/5/6)** — require internal reporting procedures for suspicious transactions. The upcoming AMLD package (2024) strengthens whistleblower protections for AML reporting.
- **Solvency II (2009/138/EC)** — Article 71 requires insurers to maintain whistleblowing procedures.

## Sector regulators with enforcement powers

| Country | Regulator | Scope |
|---------|-----------|-------|
| [Germany](/whistleblower-laws/germany/) | BaFin | Banking, insurance, securities |
| [France](/whistleblower-laws/france/) | AMF / ACPR | Markets / banking and insurance |
| [Netherlands](/whistleblower-laws/netherlands/) | AFM / DNB | Markets / prudential supervision |
| [Italy](/whistleblower-laws/italy/) | Consob / Banca d'Italia | Markets / banking |
| [Spain](/whistleblower-laws/spain/) | CNMV | Securities markets |
| [Poland](/whistleblower-laws/poland/) | KNF | All financial sectors |
| [Romania](/whistleblower-laws/romania/) | ASF / BNR | Markets and insurance / banking |
| [Ireland](/whistleblower-laws/ireland/) | Central Bank of Ireland | All financial sectors |

These regulators can impose fines independently of national whistleblower authorities.

## Procurement under DORA

Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. It does not require a reporting channel — but for financial entities within its scope, it governs how one is *procured*. Whistleblowing software is an ICT service, so the engagement runs through your ICT third-party risk process rather than as an ordinary software purchase.

In practice:

- The engagement is recorded in your **Register of Information** and reported to your competent authority.
- **Article 30** contractual provisions apply. Which set — the baseline in Article 30(2), or the extended requirements in Article 30(3) — depends on whether the service is classified as supporting a *critical or important function*. That classification is the financial entity's determination, not the vendor's.
- Audit, access, and inspection rights must extend to your competent authority, not only to you.
- Subcontracting, incident reporting, service levels, and a documented **exit strategy** must be addressed contractually.

Most of what a DORA third-party assessment asks for is published rather than released on request: the [subprocessor list](/subprocessors/), [security architecture](/security/), [business continuity plan](/policies/business-continuity/), [incident register](/incidents/), and the data export and deletion terms in the [DPA](/dpa/).

## What gets reported

- Market manipulation and insider trading
- AML/KYC procedure failures
- Mis-selling of financial products
- Sanctions evasion
- Unauthorized trading or risk limit breaches
- Conflicts of interest in advisory roles

## Why a dedicated channel matters

Financial sector employees who report through general HR channels risk having their disclosure misrouted to the person responsible for the breach. Article 9 of the Directive requires channels that protect confidentiality and prevent conflicts of interest — critical in organizations where compliance, trading, and management overlap.

---

[Deploy your reporting channel →](/pricing/)
