How to implement a formal internal whistleblowing policy
Creating a safe way for your team to speak up protects your business from legal risks and fosters a culture of integrity.
To implement an effective whistleblowing policy, you must provide a confidential reporting channel that is independent of the person being reported and guarantee that employees will not face "detriment" (retaliation) for raising genuine concerns about malpractice. This is not just a HR best practice; for Fintech firms, it is a key requirement under the FCA’s Senior Management Arrangements, Systems and Controls (SYSC) sourcebook.
Understanding whistleblowing vs. grievances
Before writing your policy, it is vital to distinguish between a personal grievance and whistleblowing. A grievance is usually a personal complaint regarding an individual's employment situation (e.g., a pay dispute). Whistleblowing, or making a "protected disclosure," involves reporting wrongdoing that affects the public interest, such as:
- Criminal offences (including fraud or money laundering)
- Failure to comply with legal or regulatory obligations
- Miscarriages of justice
- Health and safety risks
- Environmental damage
- Deliberate concealment of any of the above
Steps to establish your policy
Your policy should be a clear, accessible document that guides an employee through the process of raising a concern without fear of losing their job or being mistreated.
- Define the scope: State clearly who the policy applies to. In the UK, whistleblowing protections extend beyond permanent employees to include contractors, trainees, and agency workers.
- Appoint a Whistleblowers' Champion: If your firm is within the scope of the FCA’s SYSC 18 rules, you may need to appoint a non-executive director as a "Whistleblowers’ Champion." This person ensures the firm maintains high standards of integrity and that the whistleblowing process is independent.
- Establish reporting channels: Provide multiple ways to report. This could be a dedicated secure email address, an external hotline, or a physical "drop box." The key is that the person receiving the report must be impartial.
- Outline the investigation process: Detail how you will investigate a report. This should include timelines for acknowledging the report, how you will maintain confidentiality, and how the whistleblower will be kept informed of the progress.
- Guarantee protection: Explicitly state that the firm has a zero-tolerance policy for retaliation against whistleblowers. This aligns with the Public Interest Disclosure Act 1998 (PIDA).
Implementation and training
A policy sitting in a folder is not enough; your team needs to know it exists and trust that it works. Conduct a brief training session for all staff to explain the policy and show them where to find the reporting details. Ensure managers are specifically trained on how to react if an employee approaches them with a concern—the first reaction should always be supportive and professional.
Tip: Consider offering an anonymous reporting option. While it can make investigations harder, it significantly increases the likelihood that staff will come forward with high-risk information they might otherwise be too afraid to share.
Regulatory reporting
Remember that as an FCA-regulated firm, your policy must also inform employees that they have the right to report concerns directly to the FCA or the Prudential Regulation Authority (PRA) at any time. You cannot force them to use your internal channels first, and you must never ask them to sign a "gagging clause" (non-disclosure agreement) that prevents them from whistleblowing.
| Element | Requirement |
| Confidentiality | Mandatory protection of the whistleblower's identity. |
| Accessibility | Policy must be available to all staff, including contractors. |
| Reporting | Provide both internal and external (FCA) contact routes. |
Created by hatch. • Updated on April 28, 2026