Whistleblower compliance for financial services #
Financial institutions operate under the EU Whistleblower Directive and sector-specific regulations that independently require whistleblowing channels. Non-compliance exposes firms to penalties from both national transposition laws and financial regulators.
Regulations that require whistleblowing channels #
- EU Directive 2019/1937 — requires confidential whistleblowing channels, 7-day acknowledgment, and 3-month feedback deadlines. The 50-employee threshold that applies to most private-sector firms does not apply to regulated financial entities: under Article 8(4), entities within the scope of the Union acts listed in Parts I.B and II of the Annex must operate an internal reporting channel irrespective of headcount. Part I.B is the financial services, products, markets and anti-money-laundering list; Part II covers sector-specific acts that carry their own reporting rules. A supervised firm with 20 employees carries the same obligation as one with 2,000.
- MiFID II (2014/65/EU) — Article 73 requires investment firms to have procedures for employees to report potential breaches internally. National regulators enforce this independently of the Whistleblower Directive.
- Market Abuse Regulation (EU 596/2014) — Article 32 requires member states to establish mechanisms for reporting actual or potential market abuse. Firms must ensure internal channels exist so employees can report before going to regulators.
- Anti-Money Laundering Directives (AMLD 4/5/6) — require internal reporting procedures for suspicious transactions. The upcoming AMLD package (2024) strengthens whistleblower protections for AML reporting.
- Solvency II (2009/138/EC) — Article 71 requires insurers to maintain whistleblowing procedures.
Sector regulators with enforcement powers #
| Country | Regulator | Scope |
|---|---|---|
| Germany | BaFin | Banking, insurance, securities |
| France | AMF / ACPR | Markets / banking and insurance |
| Netherlands | AFM / DNB | Markets / prudential supervision |
| Italy | Consob / Banca d’Italia | Markets / banking |
| Spain | CNMV | Securities markets |
| Poland | KNF | All financial sectors |
| Romania | ASF / BNR | Markets and insurance / banking |
| Ireland | Central Bank of Ireland | All financial sectors |
These regulators can impose fines independently of national whistleblower authorities.
Procurement under DORA #
Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. It does not require a whistleblowing channel — but for financial entities within its scope, it governs how one is procured. Whistleblowing software is an ICT service, so the engagement runs through your ICT third-party risk process rather than as an ordinary software purchase.
In practice:
- The engagement is recorded in your Register of Information and reported to your competent authority.
- Article 30 contractual provisions apply. Which set — the baseline in Article 30(2), or the extended requirements in Article 30(3) — depends on whether the service is classified as supporting a critical or important function. That classification is the financial entity’s determination, not the vendor’s.
- Audit, access, and inspection rights must extend to your competent authority, not only to you.
- Subcontracting, incident reporting, service levels, and a documented exit strategy must be addressed contractually.
The DORA ICT third-party map provides provider-side register fields, an Article 30 crosswalk, stated limitations, and legacy UKNF mapping. It is procurement evidence, not a compliance certification or contract. The DORA contracting template is a non-binding starting point; DORA commitments arise only through a customer-specific order signed by both parties.
Electronic money institutions and payment institutions have a narrower scope question — which parts of DORA apply at their size, and what a whistleblowing channel has to satisfy. That is set out separately for e-money and payment institutions .
What gets reported #
- Market manipulation and insider trading
- AML/KYC procedure failures
- Mis-selling of financial products
- Sanctions evasion
- Unauthorized trading or risk limit breaches
- Conflicts of interest in advisory roles
Why a dedicated channel matters #
Financial sector employees who report through general HR channels risk having their disclosure misrouted to the person responsible for the breach. Article 9 of the Directive requires channels that protect confidentiality and prevent conflicts of interest — critical in organizations where compliance, trading, and management overlap.
Deploy your whistleblowing channel →
Last updated: