How to implement a whistleblowing channel in your company: a practical step-by-step guide

Professionals reviewing internal policy, PGR and a checklist to implement a whistleblowing channel

Updated on July 8, 2026

Quick answer: implementing a whistleblowing channel involves six steps: defining the internal policy, choosing the channel format, structuring the investigation flow, protecting the reporting person and the data (LGPD), communicating and training the team, and monitoring results. For companies required to establish CIPA, Law No. 14,457/2022 requires procedures for receiving, monitoring and investigating reports, with guaranteed anonymity.

The main legal basis includes Law No. 14,457/2022, which addresses the prevention of harassment and other forms of workplace violence for companies with CIPA; NR-01, which includes psychosocial risk factors in Occupational Risk Management; and the LGPD, Brazil’s General Personal Data Protection Law, which requires care in the processing of personal data received through reports.

In previous articles, we explained when a whistleblowing channel is mandatory and what NR-01 requires from companies in managing psychosocial risks. The next question is natural: how can a company implement a whistleblowing channel in practice, especially in a small or medium-sized business, without turning it into an expensive and bureaucratic project?

The good news is that implementation is simpler than it may seem, provided the company follows a logical sequence. In this article, we present a six-step guide, the most common mistakes, data protection precautions and a practical checklist to get started.

Step What to do Why it matters
1 Define the internal policy Sets rules, scope and the commitment against retaliation
2 Choose the channel format Ensures anonymity, confidentiality and follow-up
3 Structure the investigation Avoids improvisation and conflicts of interest
4 Protect data and whistleblowers Reduces legal risk and builds trust
5 Communicate and train Makes the channel known and used correctly
6 Monitor results Generates indicators and supports the PGR

What is a whistleblowing channel?

A whistleblowing channel is a structured means through which employees, service providers, outsourced workers, suppliers, clients or other people connected to the company can report inappropriate conduct, irregularities or violations of internal rules. In practice, the channel may receive reports involving issues such as:

  • moral harassment;
  • sexual harassment;
  • discrimination;
  • workplace violence;
  • abuse of power;
  • breach of internal rules;
  • fraud;
  • conflicts of interest;
  • retaliation;
  • unethical conduct;
  • situations that may affect people’s health, safety or integrity.

The purpose of the channel is not to create a punitive environment. It is to allow the company to become aware of internal problems, investigate the facts responsibly and adopt corrective measures before the situation escalates. A well-structured channel works as an early warning system.

Is a whistleblowing channel mandatory?

For companies required to establish CIPA (Internal Commission for the Prevention of Accidents and Harassment), yes: the obligation arises from Law No. 14,457/2022. The law does not necessarily require hiring a specific platform, but it requires procedures for receiving and monitoring reports, investigating the facts, applying administrative sanctions when applicable and guaranteeing anonymity to the reporting person.

In practice, this requires a minimally structured, secure and publicized channel capable of preserving the confidentiality of information. Even for companies not required to establish CIPA, the channel can be a strategic measure for prevention, governance, reputational protection and labor risk management.

In addition, the update to NR-01 reinforced the importance of listening mechanisms, because psychosocial risk factors related to work became part of GRO (Occupational Risk Management) and the PGR (Risk Management Program).

Step 1: define the internal policy and the scope of the channel

Before the tool comes the rule. The company needs to clearly define the purpose of the channel, who can use it, what topics can be reported and how reports will be handled. This rule may be included in a Code of Conduct, a Whistleblowing Channel Policy or a specific internal policy for preventing harassment.

The document should explain, in simple language:

  • which conducts may be reported;
  • who can file a report;
  • whether the channel will accept reports from employees, third parties, interns, suppliers, clients or the external public;
  • how the report is received;
  • who will have access to the reports;
  • what the basic investigation steps are;
  • what measures may be adopted;
  • how confidentiality will be guaranteed;
  • how anonymity will be preserved when the person chooses not to identify themselves;
  • what the company’s commitment against retaliation is.

A common mistake is to restrict the channel only to harassment cases. Although moral and sexual harassment are central topics, the channel can and should be broader, especially when the company wants to strengthen its culture of integrity. The clearer the scope, the lower the chance of doubts, misuse or loss of credibility.

Step 2: choose the channel format

The law does not impose a specific technology. What it requires is that the company have secure procedures for receiving, monitoring and investigating reports, with guaranteed anonymity. In practice, however, not every format meets these requirements well.

A regular HR email account tends not to guarantee, by itself, adequate access segregation, a follow-up protocol and real preservation of anonymity. A physical suggestion box can also create problems: lack of traceability, risk of improper access, difficulty in providing feedback and absence of organized records of the measures adopted.

An adequate channel should offer, at a minimum:

  • real possibility of anonymity, without mandatory collection of identifying data;
  • a follow-up protocol, so the reporting person can check progress without identifying themselves;
  • access segregation, with visibility restricted to authorized people;
  • a record of the steps taken in handling the report;
  • a trail of the measures adopted;
  • permanent availability, not only during business hours;
  • a secure environment for storing information.

For this reason, many companies have chosen specialized digital platforms, which already provide these requirements in a more organized way and at an accessible cost even for small companies. The main point is not the technology itself, but ensuring trust, confidentiality, traceability and security.

Step 3: structure the report handling flow

Receiving the report is only the beginning. What differentiates an effective channel from a merely decorative one is what happens after the report is submitted. The company needs a clear flow to receive, classify, investigate, conclude and record the measures adopted. A recommended minimum flow involves five steps.

1. Receipt and triage

The report should be received and classified by topic, severity and urgency. A report involving sexual harassment, threats, physical violence or retaliation requires more sensitive and priority handling than a question about an internal rule. Triage helps the company understand what the subject is, who is involved, whether there is immediate risk, whether evidence needs to be preserved, whether there is a conflict of interest and who should conduct the investigation.

2. Appointment of the responsible person

The company must define who will be responsible for the investigation, respecting a basic rule: anyone mentioned in the report, anyone with a close relationship with the person mentioned or anyone who may have an interest in the outcome should not participate. This is the impediment (conflict-of-interest) rule. Without it, the channel loses credibility. Imagine a report against a manager being analyzed exclusively by that same manager: even if the investigation is honest, the perception of impartiality is compromised.

3. Confidential investigation

The investigation must be conducted with confidentiality, impartiality and care. Depending on the case, it may involve document analysis, conversations with people involved, interviews with witnesses, verification of messages and records, analysis of previous reports and assessment of immediate preventive measures. Both the reporting person and the reported person have rights: confidentiality protects the integrity of the investigation and reduces the risk of injustice, retaliation or unnecessary harm.

4. Conclusion and measures

At the end of the investigation, the company must record the conclusion and the measures adopted, which may include closing the case for lack of evidence, internal guidance, warning, training, process changes, preventive removal in serious cases, disciplinary sanction, communication to competent authorities when applicable, improvement of internal controls and inclusion of the topic in a preventive action plan. The important point is that the decision be reasoned, proportional and documented.

5. Feedback through the protocol

Whenever possible, the company should provide feedback to the reporting person through the protocol. This feedback does not need to expose sensitive details, third-party data or specific disciplinary measures, but it is important that the person knows the report was received, analyzed and handled. A complete absence of feedback creates distrust and reduces the likelihood of future reports.

Step 4: protect the reporting person and handle data carefully

Protecting the reporting person is one of the pillars of a reliable channel. Law No. 14,457/2022 requires the guarantee of anonymity, and the internal policy should make it clear that the company does not tolerate retaliation against anyone who reports in good faith.

Non-retaliation

Retaliation is any form of punishment, persecution or harmful treatment against someone who filed a report or cooperated with an investigation. It can appear as dismissal without justification shortly after the report, isolation, unjustified change of role, removal of duties, threats, persecution, humiliation, loss of opportunities or negative evaluations without basis. The company must treat signs of retaliation with the same seriousness as a new report. Without protection against retaliation, the channel does not work: people simply stop reporting.

Confidentiality of those involved

Confidentiality does not protect only the reporting person. The reported person, witnesses and third parties mentioned should also have their exposure limited. Until the investigation is concluded, information should circulate only among those who truly need it. This care avoids premature judgments, preserves the investigation and reduces legal risks.

LGPD and data protection

Whistleblowing reports often contain personal data and, in many cases, sensitive data. The LGPD (General Personal Data Protection Law, Law No. 13,709/2018) requires the company to process these data for a legitimate purpose, with restricted access, adequate security and transparency compatible with the investigation context. In practice, the company should:

  • define the applicable legal basis for data processing;
  • record the purpose of the processing;
  • limit access to reports;
  • adopt security measures;
  • define a data retention period;
  • establish rules for internal or external sharing;
  • avoid unnecessary exposure of people involved;
  • include the channel in the company’s data mapping;
  • guide the people authorized to access reports.

The whistleblowing channel is not only a compliance or HR tool: it is also a personal data processing operation and, therefore, must be connected to the company’s privacy governance.

Step 5: communicate the channel and train the team

A channel that no one knows about does not fulfill its role. Communication should be broad, simple and permanent. The company may communicate the channel through onboarding, internal notice boards, intranet, email signatures, posters with QR codes, internal communications, training sessions, team meetings, internal manuals and contracts with third parties, when applicable.

In addition, Law No. 14,457/2022 requires training, guidance and awareness actions for employees at all hierarchical levels, at least every 12 months, for companies required to establish CIPA. Leadership deserves special attention, because many reports involve managers’ conduct, abuse of power or excessive pressure. It is also important to keep evidence (attendance lists, materials, communications and training records), useful in an inspection, expert examination or labor lawsuit.

Step 6: monitor, measure and feed the PGR

The whistleblowing channel generates strategic information. It should not be seen only as a place to receive problems: it also helps the company identify patterns, correct processes and prevent risks. Periodic reports with aggregated data may show the volume of reports, the most recurring topics, the most frequently mentioned departments, average investigation time, types of measures adopted, recurrence of topics and areas with greater vulnerability.

In addition, aggregated channel data may support the update of the PGR, especially regarding psychosocial risk factors provided for in NR-01. Example: if the company receives recurring reports about abusive targets, public humiliation or excessive working hours in a certain department, these data may indicate a psychosocial risk that needs to be assessed and addressed in the action plan. Important: management reports should use aggregated and, whenever possible, anonymized data. The individual content of reports must remain restricted to the investigation flow.

Quick checklist to implement a whistleblowing channel

Before launching the channel, check whether the main points have been defined:

  • Has the company defined an internal policy or updated the Code of Conduct?
  • Is the scope of the channel clear?
  • Does the policy explain which topics can be reported?
  • Has the company defined who can use the channel?
  • Does the channel allow anonymous reports?
  • Is there a follow-up protocol?
  • Is access to reports restricted?
  • Is there an impediment rule to avoid conflicts of interest?
  • Is the investigation flow documented?
  • Is there protection against retaliation?
  • Has the company defined how to process personal data under the LGPD?
  • Has the channel been communicated to employees?
  • Have leaders been trained?
  • Are there records of communications and training?
  • Has the company defined indicators to monitor the channel?
  • Will aggregated data be used to support psychosocial risk management in the PGR?

The most common implementation mistakes

In practical experience, some mistakes undermine the credibility of the channel from the beginning:

  • creating the channel and not communicating it;
  • treating implementation as a mere checklist item;
  • failing to define an impediment rule;
  • allowing people mentioned in a report to participate in the investigation;
  • promising anonymity without real technical assurance;
  • using a regular email account as if it were a structured channel;
  • not giving feedback to the reporting person;
  • ignoring the LGPD when processing reports;
  • unduly exposing people involved;
  • failing to record the measures adopted;
  • not training leaders;
  • not using channel data to improve internal processes.

A poorly implemented channel can produce the opposite effect: instead of increasing trust, it reinforces the perception that the company does not take reports seriously.

How much does it cost to implement a whistleblowing channel?

The cost varies according to the company’s size, number of employees, complexity of the investigation flow, contracted features and level of support. In recent years, the popularization of digital platforms has significantly reduced implementation costs, making the channel accessible even for companies with only a few dozen employees. To put it in perspective: the monthly investment in a digital channel is often a fraction of the cost of a single labor claim, not to mention the reputational damage of a poorly handled crisis. From a risk management perspective, the channel can be one of the simplest and most accessible protections for the company.

Need to implement a whistleblowing channel with anonymity, a follow-up protocol and investigation management? Denuncie Aqui helps your company leave improvisation behind and structure the channel in a simple and secure way.

Discover Denuncie Aqui

Frequently asked questions about implementing a whistleblowing channel

Can a whistleblowing channel be just an email address?

As a rule, a regular email address is not the best solution. It may receive reports, but it tends to fail on important points such as anonymity, follow-up protocol, access segregation, evidence control and traceability. To properly fulfill the channel’s purpose, it is recommended to use a structure that allows confidentiality, records, access control and secure follow-up.

Does the whistleblowing channel need to be anonymous?

Yes. For companies required to establish CIPA, Law No. 14,457/2022 requires the guarantee of anonymity. In practice, the channel must allow the person to report without identifying themselves. It is also recommended to allow identified reports if the person prefers, as long as identification is not mandatory.

Who should investigate the reports?

It depends on the company’s structure and the type of report. In smaller companies, it may be a designated person or committee, provided there is confidentiality, impartiality and an impediment rule. In larger companies, it may involve compliance, legal, HR, internal audit or an ethics committee. The central point is to avoid conflicts of interest: anyone mentioned in the report or directly related to those involved should not conduct the investigation.

Is a whistleblowing channel mandatory for small companies?

It depends. The obligation under Law No. 14,457/2022 is linked to companies required to establish CIPA, which depends on the number of employees, the risk level and the classification under NR-05. Even when there is no direct obligation, the channel may be recommended as a measure of prevention, labor protection, risk management and strengthening of internal culture.

Does the whistleblowing channel help with the PGR?

Yes. Aggregated channel data can help identify patterns related to psychosocial risks, such as harassment, abusive targets, excessive working hours, internal conflicts and leadership failures. This information can support the update of the PGR and the definition of preventive measures in the action plan.

Conclusion: start simple, but start correctly

Implementing a whistleblowing channel does not require a complex project. It requires method. The company needs a clear policy, an adequate tool, a defined investigation flow, protection for the reporting person, care with personal data, constant communication, training and monitoring.

Law No. 14,457/2022 already requires procedures for receiving and monitoring reports for companies with CIPA. NR-01 now includes psychosocial risk factors in Occupational Risk Management. And the LGPD requires care in processing personal data. In addition, although the Federal Supreme Court temporarily suspended the application of administrative fines and sanctions related to NR-01’s psychosocial risk provisions, the standard remains in force and the topic remains relevant for occupational health and safety management, for the action of the Labor Prosecutor’s Office and for the analysis of liability in labor lawsuits.

In this scenario, the whistleblowing channel is the meeting point between prevention, listening, documentation and business protection. Companies that start correctly not only reduce legal risks: they also build a safer work environment, improve internal trust and demonstrate a real commitment to integrity.

Want to implement a complete whistleblowing channel, with real anonymity, a follow-up protocol and investigation management, without complication and at an accessible cost? Get to know the Denuncie Aqui platform.

Discover Denuncie Aqui

Important note

This article is for informational purposes only and does not replace legal analysis of a specific case. The structuring of the channel and the investigation flow should consider the company’s size, sector, risk level, internal structure and reality. When a report involves facts that may also constitute a crime, the company’s internal channel does not replace the possibility of reporting the matter to the competent authorities.

Legal references and official sources

  • Law No. 14,457/2022 — Emprega + Mulheres Program.
  • Law No. 13,709/2018 — General Personal Data Protection Law (LGPD).
  • NR-01 — General Provisions and Occupational Risk Management.
  • Ordinance MTE No. 1,419/2024 — new wording of chapter 1.5 of NR-01, including psychosocial risk factors.
  • Ordinance MTE No. 765/2025 — effective date of the new wording of chapter 1.5 of NR-01 on May 26, 2026.
  • Decision of the Federal Supreme Court in ADPF 1316 — temporary suspension of administrative sanctions related to NR-01’s psychosocial risk provisions.
  • NR-05 — Internal Commission for the Prevention of Accidents and Harassment (CIPA).


Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top