The channel and the investigation: screening reports with absolute confidentiality
How to use AI to screen ethics-channel reports by severity and urgency without ever compromising the confidentiality of who reported. Connecting well accelerates screening; connecting wrong exposes the whistleblower's identity and destroys trust in the entire channel.
The ethics channel receives one hundred eighty reports a month, from harassment to embezzlement, and the compliance team handling it has three people. Without screening, everything piles into the same queue, and a serious harassment report can wait weeks behind minor administrative complaints. You ask AI to read each report (the text, never the name of whoever wrote it) and classify severity and area, without concluding whether it's valid. It flags that twelve reports look urgent, among them one describing retaliation against someone who already reported before, the worst signal an ethics channel can get. Except the report text is pasted straight into a public AI, along with details that, together, allow identifying the whistleblower within a small area, and now the confidentiality that would protect that person from retaliation has already leaked outside the company's controlled environment.
You ask public AI to analyze a suspicious expense pattern reported by an anonymous whistleblower, pasting the full complaint email into the prompt, which mentions the department and the specific shift of the suspect, information that already narrows down who could have written it. The email just went outside the company's controlled environment, and even without a name, the combination of details could be enough for someone in the area to identify the whistleblower. Running the analysis in a controlled environment, stripping unnecessary detail before processing, protects the whistleblower without losing the expense-pattern analysis.
You ask public AI to help draft the notice opening an internal investigation, pasting the whistleblower's full account into the prompt, with name and title, to give it more context. It hands back a well-written notice, but the whistleblower's name and case details just traveled through an outside server the firm doesn't control, breaking the confidentiality that the very law protecting whistleblowers requires. Running this task in a controlled environment, with the whistleblower's data anonymized from the start, solves the problem without giving up AI's help drafting.
You ask public AI to help draft the internal communication about a substantiated report involving an ad piece, pasting details into the prompt that, combined, point to a specific member of the creative team. This informally exposes who might have reported, even without a name, within a small team. Handling this communication with wording generic enough, reviewed inside the company's controlled environment, protects the whistleblower without compromising transparency about the outcome for the rest of the team.
You ask public AI to help draft the termination communication for a manager after a harassment investigation, pasting the victim's account into the prompt with specific dates and locations. This, combined with the termination communication, could let colleagues identify who reported. Handling this drafting inside the controlled environment, with the victim's account never leaving the HR system, protects confidentiality without compromising the necessary communication about the termination.
You ask public AI to help investigate a report about misuse of user data by a member of the product team, pasting the full account into the prompt with the whistleblower's name and a technical detail only they would have access to describe. The account just traveled outside the controlled environment, and the specific technical detail could expose who reported within the team. Running the initial screening in a controlled environment, removing the name and generalizing the technical detail, protects the whistleblower without losing the substance of the report.
You ask public AI to help analyze a report about an irregular commission paid to a salesperson, pasting the whistleblower's full email into the prompt, which cites amounts and a specific conversation only one person on the team would have witnessed. The email just went outside the controlled environment, and the conversation detail could identify the whistleblower within the sales team. Running this analysis in a controlled environment, with the account generalized before processing, protects the whistleblower without losing the signal of the irregularity.
You ask public AI to help investigate a report of improper waste disposal filed by a night-shift operator, pasting the full account into the prompt, which cites the specific shift and area, information that already narrows down who could have reported. The account just traveled outside the controlled environment, exposing the whistleblower to an identification risk within a small shift. Running the analysis in a controlled environment, generalizing shift and area before processing, protects the whistleblower without losing the signal of the environmental problem.
You connect AI to the history of already investigated and closed ethics-channel cases, with no data identifying who reported, only the pattern of the report and the outcome. It starts screening new reports by comparing them to similar cases and flags that a recurring complaint against the same manager has already appeared three times in six months, under different accounts. This changes the priority: it's no longer an isolated report, it's a pattern. At the same time, the screening runs entirely inside the company's controlled environment, never in a public tool, because the text of a harassment report, even anonymized, still carries enough detail to identify someone on a small team.
You ask public AI to help investigate a report of improper access to sensitive data, pasting the whistleblower's full account into the prompt, which describes a specific log only someone with access to the restricted system could have seen. This, combined with the account, greatly narrows down who could have reported. The account just went outside the controlled environment, exposing the whistleblower. Running the screening in a controlled environment, with the technical detail generalized before processing, protects the identity without losing the signal of the improper access.
You ask public AI to help investigate a report about a design pattern that tricks the user into accepting a recurring charge, pasting the whistleblower's full account into the prompt, which describes a specific design meeting only one person on the team witnessed. The account just traveled outside the controlled environment, exposing who reported within a small team. Running the screening in a controlled environment, generalizing the meeting detail before processing, protects the whistleblower without losing the signal of the deceptive pattern.
You ask public AI to help prepare the executive summary of a conflict-of-interest investigation involving a senior executive, pasting the whistleblower's full account into the prompt with detail about specific meetings only one person on the team would have witnessed. The summary just went outside the controlled environment, and the specific meeting detail could identify who reported within a small group of people. Preparing this summary inside the controlled environment, with details generalized enough to protect identity, solves the problem without losing the substance of the account for the board.
Whoa, notice something: the risk in the ethics channel has two faces, and they pull in opposite directions. On one side, with no screening at all, a serious report gets lost in the queue behind a minor complaint, and weeks pass before anyone investigates a retaliation account. On the other, when you speed up screening with AI, comes the temptation to paste the whistleblower's entire account into a public tool to "understand the case better," and then the problem stops being slowness and becomes exposure of someone who trusted the channel to report. This lesson is about doing both things at once: truly accelerating screening AND keeping the whistleblower's confidentiality absolute, always.
The core idea of this lesson. AI can screen reports by severity, area, and urgency, flagging what needs immediate attention (retaliation, physical risk, ongoing financial harm) without concluding whether the report is valid. That truly accelerates the ethics channel. But in compliance, screening has one non-negotiable lock: the whistleblower's confidentiality is absolute. It's not "preferably," it's not "when possible." It's the condition for the channel to keep receiving real reports, because whoever fears retaliation simply stops reporting the moment they suspect their identity could leak. Connecting wrong exposes the whistleblower; connecting right accelerates screening without ever touching who they are.
01Why screening without context gets severity wrong
AI without context on your channel answers off the top of its head. It has never read your company's case history, never seen the retaliation pattern that already happened before, never knows which area has the most recurrence. So it classifies severity generically, which can underestimate exactly the type of case your company already knows is most dangerous.
Think about the difference between two screening analysts. The first reads the isolated report and classifies it by appearance, with no memory of what already happened. The second cross-references the new report with the history of closed cases (no names, just patterns), and because of that sees when a new account is actually the fourth report about the same manager.
Connecting AI to the history of patterns, not identities, is turning it into the second analyst. It flags priority and recurrence; the conclusion about whether it's valid stays with the compliance team. Fair?
02What "connecting" means: AI screens the pattern, never the identity
Connecting here doesn't mean giving AI access to the name of whoever reported. It means giving it the history of already closed cases, stripped of any identifier, so it can recognize patterns (the same manager cited several times, the same area with recurrence, the type of account that historically needed urgent action) and cross-reference that with the new report.
With every incoming report, AI classifies severity, urgency, and area, and flags whether the pattern matches something already seen before. It never sees, and never needs to see, who wrote it. The account text goes in, the classification comes out, and the whistleblower's name stays exactly where it always should: only with whoever has legal authorization to access it, usually a single person within compliance.
03The absolute lock: the whistleblower's confidentiality
In the ethics channel, the whistleblower's confidentiality isn't a good practice, it's the channel's condition of existence. If word gets around that whoever reports can be identified, even indirectly, people stop reporting, and the channel becomes decorative. That's why this lock is called absolute, not "recommended": it admits no exception for convenience, not even "just this once, to understand the case better."
The blind spot lives in a detail the General Data Protection Law (LGPD) already addresses in article 46, on security in personal data processing: the text of a report carries detail that identifies someone even without naming them. Shift, area, the date of a specific meeting, exact title: put three of those together on a small team and the whistleblower's identity becomes obvious to whoever reads it. Pasting that entire text into a public AI tool to "help understand the case" is the digital equivalent of discussing the report out loud in the hallway.
Think of the physical rule: a confidential report doesn't leave the ethics committee without necessity and without control. The digital world doesn't change the rule, it just changes the door it can leak through. Before processing any account with AI, the question is always the same: does this text, as it stands, allow identifying who wrote it? Fair?
04How to screen without leaking: anonymize, run locally, and the gateway that blocks
Screening safely isn't "don't use AI in the ethics channel." It's deciding, before processing any account, what goes out and what stays. Three levers solve most cases, the same ones that apply to any sensitive compliance data.
The first is anonymization before processing, never after. Before AI sees the text, you remove name, exact title, specific date, and any detail that, combined, points to a single person. AI keeps classifying severity and pattern without seeing who anyone is.
The second is running in a controlled environment. The ethics channel, by nature, handles the most sensitive material that exists in compliance: an accusation against a colleague, against a manager, sometimes against leadership itself. That should never travel through some public tool; it runs on infrastructure the company controls, always.
The third is the gateway. Every AI call related to the ethics channel goes through a layer that blocks the exit of anything that looks like an identifier (name, email, employee ID) before the call goes out to the model, and that logs who accessed what, so access to the screening itself is auditable.
Do it now
Think of a real type of report that passes (or would pass) through your company's ethics channel: your real task.
- List 3 to 5 details that, even without naming names, could identify who reported within your structure (shift, area, specific date, exact title).
- Write how you would generalize each of those details before processing the account with AI, without losing the signal of what's being reported.
- Define your gateway's rule: what does it need to automatically block before any AI call goes out toward the model (name, employee ID, email, combination of shift and area)?
- Write who, at your company, is the only person or role authorized to see the whistleblower's identity, and confirm that access never passes through AI.
You've just designed a screening process that accelerates the ethics channel without opening a single crack in the absolute confidentiality of whoever reported.
Practice
1. Why is the whistleblower's confidentiality called 'absolute' in the ethics channel, and not just 'recommended'?
2. What is the right approach to using AI in report screening without breaching the whistleblower's absolute confidentiality?
3. What can AI conclude on its own when screening a report, and what stays with the compliance team?
For the board
On confidentialityit is not an optional good practice, it is the condition for the channel to exist. Without trust, the real report stops coming.
On the howanonymise first, run in a controlled environment, and keep a gateway that blocks. All three together, never just one.
On the limitthe AI speeds up the triage of the queue. The investigation and the finding stay human.
Thanks for the feedback. It helps sharpen the next lesson.