Ask your compliance data anything. Sienna Insights, now available.
Schrijf je in op de wachtlijst

Compliance and whistleblowing glossary

Compliance work runs on shared language. A policy that says "confidential" when it means "anonymous" creates a promise nobody can keep, and a supplier questionnaire that asks about a grievance mechanism means something different from one that asks about a whistleblowing channel.

This glossary defines the terms that show up in regulations, internal policies, and software evaluations, with a link to a deeper resource where one exists. Use the letter navigation to jump, or search the page.

Table of contents

    A

    Actual, potential, and perceived conflict
    An actual conflict of interest is already influencing a decision, a potential conflict could influence a future one, and a perceived conflict is one a reasonable observer could suspect even where no decision has been affected. The perceived category is the one organizations most often dismiss, and the one that does the most reputational damage when it surfaces publicly. See common examples of conflict of interest in the workplace.

    AFA (Agence Française Anticorruption)
    The AFA is the French Anti-Corruption Agency, created by Sapin II to supervise anti-corruption compliance across the public and private sectors. It runs audits on its own initiative as well as after judicial referral, and its independent sanctions committee can impose fines of up to €1 million on a company. See Sapin II, France's anti-corruption law.

    AI voice intake
    AI voice intake is a reporting method where someone describes a concern by speaking into a phone or app, and AI transcribes, translates, and structures the account for the case handler. It removes the interpreter wait that causes reporters to hang up on traditional hotlines. See Sienna AI.

    Anonymous reporting
    Anonymous reporting is a reporting method where the person raising a concern provides no identifying information at any point, including to the case handler. It differs from confidential reporting, where the organization knows who reported and protects that identity from wider disclosure. See whistleblowing software.

    Automated triage
    Automated triage is the use of software to categorize, prioritize, and route incoming reports against predefined rules. Cases reach the right handler without someone reading and sorting every submission first. See SpeakUp Report.

    B

    Beschwerdeverfahren
    Beschwerdeverfahren is the complaint procedure German companies must operate under the LkSG. It has to be publicly accessible, let people raise concerns confidentially, and protect complainants from retaliation. See supply chain grievance software.

    Bribery
    Bribery is offering, giving, requesting, or accepting something of value to influence a decision dishonestly. See how to catch bribery issues before the regulator does.

    Bullying
    Bullying is repeated behavior intended to intimidate, humiliate, or harm a colleague. Where a group targets one person rather than an individual, it is usually called mobbing. See understanding workplace harassment.

    Burden of proof (retaliation)
    The burden of proof in a retaliation claim determines which party has to establish whether adverse treatment was connected to a protected disclosure. Under the EU Whistleblowing Directive it sits with the employer, who must show the treatment had another cause; under the UK's PIDA it sits with the worker. See the EU Whistleblowing Directive.

    C

    Case escalation
    Case escalation is the process of raising a report to a higher level of authority, either because the severity warrants it or because the initial response was inadequate. Escalation paths should be defined in the policy before they are needed. See 7 tips for compliance officers to effectively handle misconduct.

    Case handler
    A case handler is the person responsible for assessing, investigating, and closing a report. Under the EU Whistleblowing Directive, the handler must be impartial and trained for the role.

    Case management
    Case management is the structured handling of a report from intake through to closure, covering acknowledgment, triage and assessment, investigation, decision, remediation, and monitoring. Predictability at each stage is one of the UN Guiding Principles' effectiveness criteria for a grievance mechanism. See 9 essential features for whistleblower and case management software.

    Chain of activities
    Chain of activities is the CSDDD's term for the scope of a company's due diligence duty: its own operations, its subsidiaries, and its upstream and downstream business partners.

    CJIP
    The CJIP (Convention Judiciaire d'Intérêt Public) is France's deferred prosecution agreement, introduced by Sapin II. It lets prosecutors resolve a corporate corruption case without a conviction, in exchange for a financial penalty, publication of the agreement, and a compliance improvement program under AFA oversight. See how Sapin II is enforced.

    Code of conduct
    A code of conduct is the document setting out the standards of behavior an organization expects from its people, and the process for raising concerns when those standards are breached. See what is the corporate governance code in UK.

    Compliance
    Compliance is adherence to the laws, regulations, and internal standards that apply to how an organization operates.

    Compliance framework
    A compliance framework is the structure an organization uses to identify its obligations, assign responsibility for them, and evidence that they are being met. See what is governance, risk and compliance.

    Confidential reporting
    Confidential reporting is a reporting method where the organization knows the reporter's identity and protects it from disclosure beyond the people handling the case. Reporters often assume confidential means anonymous, which is why the distinction belongs in the policy and in the intake form itself. See 8 things to look for in secure and anonymous misconduct reporting channels.

    Conflict of interest
    A conflict of interest is a situation where someone's personal interests could influence, or appear to influence, a professional decision they are responsible for. See conflict of interest software.

    Conflict of interest disclosure
    A conflict of interest disclosure is the formal process by which an employee, board member, or contractor reports a situation where their personal interests could affect their professional decisions. Disclosing a conflict is not an admission of wrongdoing, and treating it as one is the fastest way to stop people disclosing at all. See conflict of interest policy examples and templates.

    Corporate Whistleblower Awards Pilot Program
    The Corporate Whistleblower Awards Pilot Program is a US Department of Justice initiative launched in August 2024 that offers financial awards to people who report corporate misconduct directly to the government. It sits alongside the SEC program created by Dodd-Frank, and it changes the calculation on internal channels: where employees do not trust yours, the government is now competing for the report. See DOJ guidelines on corporate compliance programs.

    Corruption
    Corruption is the abuse of entrusted power for private gain, most often through bribery, kickbacks, influence peddling, or the misuse of position to direct decisions. See the EU Anti-Corruption Directive.

    Corruption risk mapping
    Corruption risk mapping is a documented assessment of where an organization is exposed to corruption and influence peddling, broken down by geography, business sector, and counterparty type. It is the third of Sapin II's eight compliance pillars, and the AFA expects it to be refreshed at least annually. See the eight pillars of Sapin II.

    CSDDD
    The CSDDD is the EU Corporate Sustainability Due Diligence Directive, which requires large companies to identify, prevent, and address adverse human rights and environmental impacts across their chain of activities, including through a notification mechanism and complaints procedure. Omnibus I narrowed and delayed it: it now applies to companies above 5,000 employees and €1.5 billion net worldwide turnover, from 26 July 2029.

    D

    Data localization
    Data localization is a legal requirement to store data inside the country where it was collected.

    Data residency
    Data residency is the geographic location where data is physically stored. Buyers in regulated sectors often ask about it during security review, separately from any legal localization requirement. See assurance and security.

    Data sovereignty
    Data sovereignty is the principle that data is subject to the laws of the country where it is stored, regardless of where the organization holding it is based.

    Discrimination
    Discrimination is treating someone less favorably because of a protected characteristic such as race, sex, age, religion, disability, or sexual orientation.

    Divestment
    Divestment is a conflict of interest mitigation where the employee gives up the outside financial interest creating the conflict. It is generally reserved for senior leadership and board members, where the scale of decision-making authority makes lighter controls insufficient.

    Dodd-Frank Act
    The Dodd-Frank Act is US legislation that created the SEC's whistleblower award program, which pays 10 to 30% of sanctions collected in cases resulting in more than $1 million in penalties. Reporters can remain anonymous if they are represented by an attorney. See also Sarbanes-Oxley Act.

    E

    ECCP
    The ECCP is the US Department of Justice's Evaluation of Corporate Compliance Programs, the guidance prosecutors use to judge whether a company's compliance program was effective. It turns on three questions: is the program well designed, is it adequately resourced and empowered, and does it work in practice. The third is where documentation-heavy programs come apart. See the DOJ compliance program guidelines.

    Ethics
    Ethics is the set of principles governing what an organization or individual treats as right conduct, including where the law is silent.

    Ethics hotline
    An ethics hotline is a dedicated channel, often operated by a third party, that lets employees report concerns confidentially. Phone-only hotlines struggle on anonymity, documentation, and language coverage, which is why most programs now run phone alongside web and app intake. See top ethics hotline providers.

    EU AI Act
    The EU AI Act is the EU regulation on artificial intelligence, which sorts AI systems into risk tiers and attaches obligations to each tier. It matters twice over for a compliance team: once for the AI the business deploys commercially, and once for the AI running inside the compliance function itself. See what is the EU AI Act.

    EU Anti-Corruption Directive
    The EU Anti-Corruption Directive harmonizes how member states criminalize corruption, covering bribery in both the public and private sectors, misappropriation, trading in influence, obstruction of justice, and concealment of proceeds. It introduces corporate liability for failure of supervision, with turnover-based fines, and treats an effective compliance program as a mitigating factor. See the EU Anti-Corruption Directive.

    EU Whistleblowing Directive
    The EU Whistleblowing Directive, Directive (EU) 2019/1937, requires organizations with 50 or more employees to operate an internal reporting channel, keep the reporter's identity confidential, acknowledge a report within seven days, and give feedback within three months. All 27 member states have transposed it into national law, and the national versions differ on anonymity, penalties, and retention. See the EU Whistleblowing Directive.

    F

    Failure of supervision or control
    Failure of supervision or control is the basis on which the EU Anti-Corruption Directive makes a company liable for corruption committed by someone acting on its behalf, where the company did not exercise adequate oversight. A documented, functioning compliance program is the evidence that oversight existed. See corporate liability under the EU Anti-Corruption Directive.

    FCPA
    The FCPA is the US Foreign Corrupt Practices Act, which prohibits bribery of foreign public officials and requires issuers to maintain accurate books and records. Complying with the FCPA does not automatically satisfy Sapin II or the UK Bribery Act, both of which are more prescriptive about what a program has to contain. See how the DOJ evaluates compliance programs.

    Fraud
    Fraud is deception carried out for financial or personal gain, such as falsifying records, misrepresenting performance, or submitting fabricated invoices. See AI document fraud and compliance.

    Free-format intake
    Free-format intake is a reporting method that lets someone describe a concern in their own words rather than answering fixed questions. It captures detail a structured form would miss, at the cost of more work at triage.

    G

    Gifts and entertainment register
    A gifts and entertainment register is a structured log of gifts, hospitality, and other benefits given to or received from parties an organization does business with. It usually runs through the same disclosure workflow as conflicts of interest, since both ask employees to declare their own situation rather than report someone else's conduct. See gifts and entertainment software.

    Governance
    Governance is the system of rules, roles, and accountabilities by which an organization is directed and controlled. In a compliance program, it defines who owns each obligation and who decides on a case.

    Grievance mechanism
    A grievance mechanism is a formal process that lets employees or external stakeholders raise concerns about misconduct, unfair treatment, or policy breaches and have them addressed. See also supply chain grievance mechanism, which covers the external-stakeholder variant. See HR grievance management.

    H

    High-risk AI system
    A high-risk AI system is a category under the EU AI Act covering uses where AI could materially affect health, safety, or fundamental rights, including several employment and worker-management applications. Systems in this tier carry the heaviest obligations, including risk management, logging, human oversight, and technical documentation. See the EU AI Act risk tiers.

    Hinweisgeberschutzgesetz (HinSchG)
    The Hinweisgeberschutzgesetz is Germany's whistleblower protection law, in force since 2 July 2023. It requires companies with 50 or more employees to operate internal reporting channels, with protections closely mirroring the EU Whistleblowing Directive.

    Human rights due diligence
    Human rights due diligence is the ongoing process of identifying, preventing, and addressing a company's actual and potential human rights impacts across its own operations and value chain. It is the foundation of the UN Guiding Principles and the basis for laws including the CSDDD and the LkSG.

    I

    Incident management system
    An incident management system is software for logging, tracking, and resolving reported incidents. The term is broader than case management and often covers operational and safety incidents alongside conduct reports.

    Influence peddling
    Influence peddling, called trading in influence in EU legislation, is using a position or set of connections to sway a public decision in exchange for a benefit, without the direct offer of value that defines bribery. Sapin II and the EU Anti-Corruption Directive both treat it as an offense distinct from bribery. See offenses under the EU Anti-Corruption Directive.

    Internal reporting channel
    An internal reporting channel is a route established inside an organization for people to raise concerns directly, rather than going to a regulator or the press. The EU Whistleblowing Directive makes one mandatory at 50 or more employees. See whistleblowing software.

    ISO 37002
    ISO 37002 is the international standard for whistleblowing management systems, published in 2021. It is written as guidance rather than a requirements standard, so an organization can align its program with ISO 37002 but cannot be certified against it.

    L

    Legal hold
    A legal hold is the process of preserving all potentially relevant information once litigation or an investigation is reasonably anticipated.

    Loi Waserman
    The Loi Waserman is French law No. 2022-401 of 21 March 2022, which transposed the EU Whistleblowing Directive into French law and widened Sapin II's whistleblower protections. It broadened who counts as a whistleblower, extended protection to facilitators and to relatives who face retaliation by association, and reversed the burden of proof in retaliation claims. See whistleblowing obligations under Sapin II.

    LkSG
    The LkSG is Germany's Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz), which requires companies with 1,000 or more employees in Germany to operate a complaint procedure, the Beschwerdeverfahren, for supply chain concerns. The due diligence and complaint procedure obligations remain in force; the annual reporting obligation has been withdrawn in practice, with BAFA no longer reviewing reports since October 2025. See supply chain grievance software.

    M

    Materiality (conflict of interest)
    Materiality is how significant the interest behind a conflict actually is, used to calibrate the response. A small shareholding in a supplier sits at a different risk level from a controlling stake, and the mitigation should scale with it.

    Misconduct
    Misconduct is behavior by an employee or representative that breaches law, policy, or the organization's stated standards. See how to manage global misconduct and whistleblower reporting.

    Mitigation (conflict of interest)
    Mitigation is the control applied once a conflict has been assessed, ranging from documentation and monitoring at the low end to recusal, independent sign-off, reporting-line changes, divestment, or prohibition at the high end. Applying the same control to every disclosure regardless of risk is a common failure in manual programs. See the hidden risk in manual disclosure programs.

    Mobbing at work
    Mobbing is a form of bullying where a group of colleagues repeatedly targets one person, creating a hostile working environment. It is the more common framing in Dutch and German workplace law than the English "bullying".

    Multilingual access
    Multilingual access is the availability of a reporting channel in the languages the workforce and supply chain actually speak. Intake in 100+ languages removes the interpreter delay that stops reports being completed. See solving multilingual whistleblowing.

    N

    Non-retaliation policy
    A non-retaliation policy is an organization's formal commitment that nobody who raises a concern in good faith will face adverse treatment for it. See what is a non-retaliation policy.

    Notification mechanism and complaints procedure
    Notification mechanism and complaints procedure is the CSDDD's term for the grievance channel in-scope companies must establish or participate in, so affected people and their representatives can raise concerns about adverse human rights and environmental impacts.

    O

    Omnibus I
    Omnibus I is the EU's 2026 simplification package, Directive (EU) 2026/470, in force from 18 March 2026. It raised the thresholds for the CSDDD and the CSRD and pushed back their application dates, changing who has to comply and when rather than whether a grievance mechanism is required at all.

    P

    PIDA
    PIDA is the UK's Public Interest Disclosure Act 1998, which protects a worker who makes a qualifying disclosure they reasonably believe shows wrongdoing and is in the public interest. Unlike the EU Whistleblowing Directive, PIDA does not require an employer to operate a reporting channel, and the burden of proof in a retaliation claim sits with the worker. See whistleblowing policy: a step-by-step guide.

    Prescribed person
    A prescribed person is an external body, typically a regulator, that a worker can report to and still keep legal protection without having reported internally first. Which bodies qualify varies by country.

    Protected disclosure
    A protected disclosure is a report that meets the legal test for whistleblower protection under a given law, such as a qualifying disclosure under the UK's PIDA or a report covered by the EU Whistleblowing Directive. See the 5 conditions of whistleblowing.

    Proxy reporting
    Proxy reporting is the submission of a report by one person on behalf of another, for example a manager or works council representative raising a concern for a colleague.

    Q

    Qualifying disclosure
    A qualifying disclosure is the UK PIDA's term for information a worker reasonably believes shows a criminal offense, a breach of legal obligation, a miscarriage of justice, a danger to health, safety, or the environment, or a cover-up of any of these.

    R

    Recusal
    Recusal is the conflict of interest mitigation where an employee steps back from the specific decisions the conflict touches while continuing the rest of their role. It is the control applied most often, because it is proportionate and reversible.

    Regulatory change management
    Regulatory change management is the process of tracking legal and regulatory changes, assessing what they mean for the organization, and implementing the response. See how to comply with global whistleblowing regulations.

    Related-party transaction
    A related-party transaction is a transaction between an organization and a party connected to one of its employees, board members, or executives, such as a supplier owned by a relative. It generally runs through the same disclosure and approval workflow as a conflict of interest.

    Remediation
    Remediation is the action taken to address harm once a grievance or violation has been substantiated, such as corrective measures at a supplier, compensation, improved conditions, or a systemic change. Remediation is assigned to a named owner and tracked to completion, which is what separates it from a decision recorded and closed.

    Renewal cycle
    A renewal cycle is the periodic process, usually annual, where employees confirm that their previously disclosed conflicts of interest are still accurate and declare any new ones. Event-based triggers such as a role change or a new vendor relationship should prompt a fresh disclosure outside the cycle. See SpeakUp Paths.

    Reporter check-back rate
    Reporter check-back rate is the share of anonymous reporters who return to their case to check its status or answer a follow-up question. It works as a proxy for trust in a channel, because reporters only come back if they believe something is happening at the other end. SpeakUp measures a 49% check-back rate across its platform. See SpeakUp Report.

    RetaliationRetaliation is adverse treatment of someone because they raised a concern, including dismissal, demotion, exclusion, poor performance reviews, or informal blacklisting.Risk assessmentRisk assessment is the process of identifying what could go wrong, how likely it is, and what the impact would be, so controls can be prioritized against the largest exposures. The DOJ expects it to be ongoing and informed by incidents elsewhere in the sector, not completed once at program launch. See how the DOJ assesses risk management.

    S

    Sapin II
    Sapin II is France's anti-corruption law (Law No. 2016-1691), in force since 1 June 2017, which requires companies above 500 employees and €100 million turnover to run an eight-pillar anti-corruption program. A separate and lower threshold applies to whistleblowing: any organization with 50 or more employees in France must operate a confidential reporting channel, regardless of turnover. See Sapin II explained.

    Sarbanes-Oxley Act (SOX)
    The Sarbanes-Oxley Act is US legislation that protects employees of public companies who report securities fraud, whether to a supervisor or a federal agency. A SOX retaliation claim has to be filed with OSHA within 180 days of the retaliation before it can reach court. See SOX compliance.

    Speak-up culture
    A speak-up culture is a working environment where people raise concerns early because they expect to be listened to rather than punished. Channels and policies support it; manager behavior is what actually creates it. See what is a speak-up culture and how to build it.

    Speak-up officer
    A speak-up officer is the person designated to oversee an organization's reporting program, including intake, case allocation, and reporting to leadership. See the role of a Chief Compliance Officer.

    Supply chain grievance mechanism
    A supply chain grievance mechanism is a formal, accessible process that lets workers, communities, and other stakeholders across a company's value chain raise concerns about human rights, labor, environmental, or ethical harm and have them investigated and addressed. What distinguishes it from internal whistleblowing is who it serves: people without corporate accounts, across many languages, often on low-bandwidth channels. See supply chain grievance software.

    T

    Third-party due diligence
    Third-party due diligence is the assessment of corruption and conduct risk presented by customers, suppliers, and intermediaries before a relationship starts, plus the monitoring of that risk afterward. Under Sapin II it is the fourth compliance pillar, and it has to follow from the risk map rather than run as a blanket exercise across every counterparty. See third-party due diligence requirements in France.

    Third-party reporting
    Third-party reporting is the use of an external provider to receive and manage reports, which gives reporters distance from internal management and gives the organization documented, consistent intake.

    Third-party risk management
    Third-party risk management is the practice of assessing and controlling the risks that vendors, suppliers, agents, and other external partners create for the organization.

    Tier 1, tier 2, and tier 3 supplier
    Supplier tiers describe how far a supplier sits from direct contract with the company: tier 1 contracts directly, while tier 2 and tier 3 sit further up the chain. The further down the chain a grievance mechanism has to reach, the more its accessibility and language coverage decide whether it gets used at all.

    Transparency
    Transparency is openness about how decisions are made and how concerns are handled, including telling reporters what will happen to their report and when.

    Two-way anonymous communication
    Two-way anonymous communication is the capability for a case handler and a reporter to keep exchanging messages while the reporter's identity stays hidden. Without it, an anonymous report is a single message with no way to ask the follow-up question that makes it actionable. See whistleblowing software.

    U

    UK Bribery Act
    The UK Bribery Act 2010 criminalizes offering and receiving bribes, bribing a foreign public official, and the corporate offense of failing to prevent bribery. The defense to the corporate offense is having adequate procedures in place, which puts the compliance program itself on trial. See how to catch bribery issues before the regulator does.

    UNGP effectiveness criteria
    The UNGP effectiveness criteria are the eight tests Principle 31 of the UN Guiding Principles sets for a non-judicial grievance mechanism: legitimate, accessible, predictable, equitable, transparent, rights-compatible, a source of continuous learning, and based on engagement and dialogue. Auditors and buyers increasingly ask companies to evidence each one.

    W

    Whistleblower
    A whistleblower is someone who reports wrongdoing they have encountered through their work, whether inside the organization or to an external authority. See famous whistleblower examples in the workplace.

    Whistleblowing
    Whistleblowing is the act of reporting or disclosing wrongdoing such as fraud, misconduct, or a breach of law, by someone who encountered that information in a work-related context. See what is whistleblowing.

    Whistleblowing channel
    A whistleblowing channel is the route through which a report reaches the organization, such as web form, mobile app, phone, voice intake, or in person. Most programs run several, because reporters differ in what they will actually use. See top whistleblowing software tools.

    Whistleblowing policy
    A whistleblowing policy is the document setting out what people can report, how to report it, who handles reports, what timelines apply, and what protection reporters receive. See whistleblowing policy: a step-by-step guide.

    Workflow automation
    Workflow automation is the use of software to carry out repeatable steps in a compliance process, such as acknowledging a report within the seven-day deadline or routing a disclosure to the right approver.

    Z

    Zero tolerance policy
    A zero tolerance policy is a stated position that specific breaches carry fixed consequences with no discretion. It signals seriousness, and it can also suppress reporting when people fear the consequences for a colleague are disproportionate.