Business: Compliance · Lesson N.comp.6

The channel and the investigation: screening reports with absolute confidentiality

How to use AI to screen ethics-channel reports by severity and urgency without ever compromising the confidentiality of who reported. Connecting well accelerates screening; connecting wrong exposes the whistleblower's identity and destroys trust in the entire channel.

Examples for

The ethics channel receives one hundred eighty reports a month, from harassment to embezzlement, and the compliance team handling it has three people. Without screening, everything piles into the same queue, and a serious harassment report can wait weeks behind minor administrative complaints. You ask AI to read each report (the text, never the name of whoever wrote it) and classify severity and area, without concluding whether it's valid. It flags that twelve reports look urgent, among them one describing retaliation against someone who already reported before, the worst signal an ethics channel can get. Except the report text is pasted straight into a public AI, along with details that, together, allow identifying the whistleblower within a small area, and now the confidentiality that would protect that person from retaliation has already leaked outside the company's controlled environment.

Whoa, notice something: the risk in the ethics channel has two faces, and they pull in opposite directions. On one side, with no screening at all, a serious report gets lost in the queue behind a minor complaint, and weeks pass before anyone investigates a retaliation account. On the other, when you speed up screening with AI, comes the temptation to paste the whistleblower's entire account into a public tool to "understand the case better," and then the problem stops being slowness and becomes exposure of someone who trusted the channel to report. This lesson is about doing both things at once: truly accelerating screening AND keeping the whistleblower's confidentiality absolute, always.

The core idea of this lesson. AI can screen reports by severity, area, and urgency, flagging what needs immediate attention (retaliation, physical risk, ongoing financial harm) without concluding whether the report is valid. That truly accelerates the ethics channel. But in compliance, screening has one non-negotiable lock: the whistleblower's confidentiality is absolute. It's not "preferably," it's not "when possible." It's the condition for the channel to keep receiving real reports, because whoever fears retaliation simply stops reporting the moment they suspect their identity could leak. Connecting wrong exposes the whistleblower; connecting right accelerates screening without ever touching who they are.

01Why screening without context gets severity wrong

AI without context on your channel answers off the top of its head. It has never read your company's case history, never seen the retaliation pattern that already happened before, never knows which area has the most recurrence. So it classifies severity generically, which can underestimate exactly the type of case your company already knows is most dangerous.

Think about the difference between two screening analysts. The first reads the isolated report and classifies it by appearance, with no memory of what already happened. The second cross-references the new report with the history of closed cases (no names, just patterns), and because of that sees when a new account is actually the fourth report about the same manager.

Connecting AI to the history of patterns, not identities, is turning it into the second analyst. It flags priority and recurrence; the conclusion about whether it's valid stays with the compliance team. Fair?

02What "connecting" means: AI screens the pattern, never the identity

Connecting here doesn't mean giving AI access to the name of whoever reported. It means giving it the history of already closed cases, stripped of any identifier, so it can recognize patterns (the same manager cited several times, the same area with recurrence, the type of account that historically needed urgent action) and cross-reference that with the new report.

With every incoming report, AI classifies severity, urgency, and area, and flags whether the pattern matches something already seen before. It never sees, and never needs to see, who wrote it. The account text goes in, the classification comes out, and the whistleblower's name stays exactly where it always should: only with whoever has legal authorization to access it, usually a single person within compliance.

Screening separated from identity Report text (no identifier) AI classifies severity, area, pattern Prioritized list for the team to investigate Whistleblower's identity never enters the AI flow, stays only with authorized compliance staff

03The absolute lock: the whistleblower's confidentiality

In the ethics channel, the whistleblower's confidentiality isn't a good practice, it's the channel's condition of existence. If word gets around that whoever reports can be identified, even indirectly, people stop reporting, and the channel becomes decorative. That's why this lock is called absolute, not "recommended": it admits no exception for convenience, not even "just this once, to understand the case better."

The blind spot lives in a detail the General Data Protection Law (LGPD) already addresses in article 46, on security in personal data processing: the text of a report carries detail that identifies someone even without naming them. Shift, area, the date of a specific meeting, exact title: put three of those together on a small team and the whistleblower's identity becomes obvious to whoever reads it. Pasting that entire text into a public AI tool to "help understand the case" is the digital equivalent of discussing the report out loud in the hallway.

Think of the physical rule: a confidential report doesn't leave the ethics committee without necessity and without control. The digital world doesn't change the rule, it just changes the door it can leak through. Before processing any account with AI, the question is always the same: does this text, as it stands, allow identifying who wrote it? Fair?

04How to screen without leaking: anonymize, run locally, and the gateway that blocks

Screening safely isn't "don't use AI in the ethics channel." It's deciding, before processing any account, what goes out and what stays. Three levers solve most cases, the same ones that apply to any sensitive compliance data.

The first is anonymization before processing, never after. Before AI sees the text, you remove name, exact title, specific date, and any detail that, combined, points to a single person. AI keeps classifying severity and pattern without seeing who anyone is.

The second is running in a controlled environment. The ethics channel, by nature, handles the most sensitive material that exists in compliance: an accusation against a colleague, against a manager, sometimes against leadership itself. That should never travel through some public tool; it runs on infrastructure the company controls, always.

The third is the gateway. Every AI call related to the ethics channel goes through a layer that blocks the exit of anything that looks like an identifier (name, email, employee ID) before the call goes out to the model, and that logs who accessed what, so access to the screening itself is auditable.

Raw account with detail Gateway removes identifier, logs the access AI classifies severity and pattern, never identity No identifier crosses the gate toward the model.

Do it now

Do it yourself

Think of a real type of report that passes (or would pass) through your company's ethics channel: your real task.

  1. List 3 to 5 details that, even without naming names, could identify who reported within your structure (shift, area, specific date, exact title).
  2. Write how you would generalize each of those details before processing the account with AI, without losing the signal of what's being reported.
  3. Define your gateway's rule: what does it need to automatically block before any AI call goes out toward the model (name, employee ID, email, combination of shift and area)?
  4. Write who, at your company, is the only person or role authorized to see the whistleblower's identity, and confirm that access never passes through AI.

You've just designed a screening process that accelerates the ethics channel without opening a single crack in the absolute confidentiality of whoever reported.

Practice

1. Why is the whistleblower's confidentiality called 'absolute' in the ethics channel, and not just 'recommended'?

2. What is the right approach to using AI in report screening without breaching the whistleblower's absolute confidentiality?

3. What can AI conclude on its own when screening a report, and what stays with the compliance team?

For the board

On confidentialityit is not an optional good practice, it is the condition for the channel to exist. Without trust, the real report stops coming.
On the howanonymise first, run in a controlled environment, and keep a gateway that blocks. All three together, never just one.
On the limitthe AI speeds up the triage of the queue. The investigation and the finding stay human.
What did you think of this page?
Would you recommend this page to someone on your team?