Skip to main content Required by EU law for organizations with 50+ employees

Whistleblower compliance for financial services #

Financial institutions operate under the EU Whistleblower Directive and sector-specific regulations that independently require internal reporting channels. Non-compliance exposes firms to penalties from both national transposition laws and financial regulators.

Regulations that require reporting channels #

Sector regulators with enforcement powers #

CountryRegulatorScope
GermanyBaFinBanking, insurance, securities
FranceAMF / ACPRMarkets / banking and insurance
NetherlandsAFM / DNBMarkets / prudential supervision
ItalyConsob / Banca d’ItaliaMarkets / banking
SpainCNMVSecurities markets
PolandKNFAll financial sectors
RomaniaASF / BNRMarkets and insurance / banking
IrelandCentral Bank of IrelandAll financial sectors

These regulators can impose fines independently of national whistleblower authorities.

Procurement under DORA #

Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. It does not require a reporting channel — but for financial entities within its scope, it governs how one is procured. Whistleblowing software is an ICT service, so the engagement runs through your ICT third-party risk process rather than as an ordinary software purchase.

In practice:

Most of what a DORA third-party assessment asks for is published rather than released on request: the subprocessor list , security architecture , business continuity plan , incident register , and the data export and deletion terms in the DPA .

What gets reported #

Why a dedicated channel matters #

Financial sector employees who report through general HR channels risk having their disclosure misrouted to the person responsible for the breach. Article 9 of the Directive requires channels that protect confidentiality and prevent conflicts of interest — critical in organizations where compliance, trading, and management overlap.


Deploy your reporting channel →

Last updated: