The anonymous reporting policy, and how to make it work
What the policy has to cover, the response commitment most of them skip, and how to turn the document into categories and questions people actually follow. Part of our guide to anonymous reporting software.
What is an anonymous reporting policy for?
An anonymous reporting policy has one job: to answer, before anyone needs it, the four questions a person asks at the moment they are deciding whether to speak up. What can I report? How? Who will see it? What will happen to me?
Most policies answer the first two and leave the last two vague, which is the wrong way round. Someone weighing up a report is not confused about the subject matter. They are worried about exposure and doubtful that anything will change.
A policy is not the programme. It is the promise the programme has to keep, which is why the response times in it should be ones you can meet on your worst week, not your best.
What goes in an anonymous reporting policy?
Six sections cover it. The printable below is the same list as a one-page outline you can mark up with whoever owns the policy.
1. Scope
What can be reported, in words people use, with examples. Say what belongs somewhere else too: a pay query or a broken laptop in the reporting channel is a sign the scope was never explained.
2. Who can use it
Employees, but also contractors, agency staff, suppliers, applicants and former employees. Anyone who can see a problem in your organisation should be able to report it, and in the EU most of these groups are protected by law whether your policy names them or not.
3. How to report
The channels by name, whether anonymous reporting is accepted, and how to reach a regulator instead. That last point is not a risk to manage. People go external when internal feels pointless, and a policy that pretends the external route does not exist reads as exactly that.
4. What happens next
Who reads reports, described by role. How long until an acknowledgement, and how long until the outcome. In the EU those two are set: seven days to acknowledge, three months to give feedback. Elsewhere, pick numbers and keep them.
5. Protection from retaliation
A plain statement that retaliation is a disciplinary matter, examples so people recognise it, and what to do if it happens. Protection should cover reports made in good faith, including ones that turn out to be mistaken. NAVEX's benchmark of 2025 data puts substantiation at 44%, so a policy that only protects reporters who turn out to be right protects roughly half of them.
6. Records and review
What is recorded, who can see it, how long it is kept, who owns the policy and when it is reviewed.
The policy outline, section by section
A one-page outline of the decisions each section forces. Print it for a policy review. No email, no form.
One thing this page deliberately does not give you is clause text. A reporting policy sits inside employment and data protection law that differs by country, and a template copied from a software vendor is how a policy ends up promising something local law does not allow.
The part most policies skip: the response commitment
Nearly every policy says reports will be handled promptly and confidentially. Neither word means anything to the person deciding whether to file one.
A response commitment is two dates and a name. You will hear from us within X days. You will know the outcome within Y. The people who read reports are Z, by role. Put those in and the policy stops being reassurance and becomes something a reporter can hold you to, which is the only version that builds any trust.
It also changes how the programme runs. A date in a policy has to be met by someone, which forces the questions most programmes avoid until their first serious report: who is on call in August, who covers a report about the person who normally handles them, and what happens when a case is genuinely complex and three months is not enough. Better to answer those on paper than at the time.
Turning the policy into intake people actually follow
A policy is read once, if at all. The intake form is read by everyone who reports. So the practical test of a policy is whether its scope survived the journey into the channel.
- Categories are your scope, made clickable. If the policy covers harassment, safety, fraud, discrimination and policy breaches, those are the categories. A reporter should never have to decide which paragraph of a policy their problem falls under.
- Guided questions are your investigation, asked upfront. Each category should ask the three or four things a handler would otherwise have to go back for: when it happened, whether it is ongoing, who else saw it, whether it was raised before. This is the single biggest lever on whether a report can be acted on.
- Risk levels are your priority rules, written down. Attaching a severity to the category means the queue sorts itself, rather than being sorted by whoever shouted most recently.
- The anonymity statement belongs on the form, not only in the policy. It is read at the moment it matters.
In CultureMonkey's Speak Up, those are the same four settings: categories, their questions, their risk level and the portal's anonymity wording. The page on anonymous harassment reporting shows how one category's questions and routing work in practice.
Your policy, as the form people fill in
Set your own categories, the questions each one asks, and who handles them, so the channel matches the document rather than drifting from it.
How often should a reporting policy be reviewed?
Once a year, and again after the first report that does not fit the process. A policy stops being true quietly: the named handler leaves, the channel changes, the law moves, and the document on the intranet describes a process nobody runs. Three habits are enough.
- Review it on a schedule and after an incident. Of the two, the incident is the more useful trigger.
- Check the handler list every time someone joins or leaves. This is the most common silent failure, and the easiest to prevent.
- Publish it where people are, in the languages they read, and repeat it. Our guide to training people to use it covers what to say and when.
If you are starting from nothing, our guide to anonymous reporting in the workplace covers the programme around the policy, and our explainer on the EU Whistleblower Directive covers what European law requires of the channel itself.
Reporting policies, answered
What should an anonymous reporting policy include?
Six sections: what can be reported, who can use the channel, how to report including whether anonymous reports are accepted, what happens next with named response times, protection from retaliation, and how records are kept and the policy reviewed. The section most often missing is the response commitment: a date for acknowledgement and a date for the outcome.
Is a whistleblowing policy a legal requirement?
It depends where you operate. EU employers with 50 or more workers must run an internal reporting channel and give information about how reports are handled, and in Australia public companies and large proprietary companies must have a whistleblower policy under ASIC's RG 270. Other countries have no general duty. Check the national law everywhere you employ people.
How quickly should we respond to a report?
Fast enough that the reporter knows they were heard. In the EU the deadlines are set: acknowledge within 7 days and give feedback within 3 months. Elsewhere, choose numbers you can meet in a bad month and publish them, because an undated promise to respond promptly is not one anyone can rely on.
Should the policy promise complete anonymity?
No. Promise what is true: that nothing identifying is collected, that only named handlers can read reports, and that retaliation is a disciplinary matter. Then say where anonymity ends, such as details in the report that could identify the writer. A policy that promises the impossible is not believed even when the rest of it is solid.
Do we need separate policies for harassment and whistleblowing?
Usually not two channels, whatever the documents look like. Employers commonly keep a harassment or grievance policy alongside a whistleblowing policy, but people should not have to work out which one applies before they can report. One channel with clear categories, and policies that point at the same channel, is easier to use and easier to run.
Who should own the policy?
Whoever can be held to the response times in it. In most mid-sized organisations that is HR or People, with legal or compliance reviewing the text and a named executive accountable. The one arrangement that fails is a policy owned by nobody in particular and reviewed when someone remembers.
How do we turn the policy into the reporting form?
Make the categories match the policy's scope, give each category the three or four questions a handler would otherwise chase, attach a risk level so the queue sorts by severity, and put the anonymity statement on the form itself. If the categories and the policy disagree, people follow the form.