Hidden gaps in misconduct reporting that could become a compliance crisis

Hidden gaps in misconduct reporting that could become a compliance crisis

23 August 2026 Consultancy.com.au
Hidden gaps in misconduct reporting that could become a compliance crisis

Rising misconduct reporting volumes are creating new challenges for Australian organisations. Andrew Amos, Vice President at Diligent, outlines why stronger governance and better case management are becoming essential to protecting people, preserving evidence and turning individual disclosures into meaningful insight.

One misconduct report may look like a one-off. Three from the same business unit in under a year is a pattern, and potentially a much bigger problem.

That challenge is becoming more significant as reporting volumes rise. Since Australia’s whistleblower reforms were introduced in 2019, disclosures to Australian Securities and Investments Commission (ASIC) have more than tripled – from an average 207 a year between 2015 and 2019 to 736 a year since.

Yet only around one in ten is assessed as actionable. That gap matters: it means most organisations aren’t yet equipped to tell an isolated complaint from a symptom of something bigger.

Misconduct reporting is often judged by what happens at the point of disclosure: whether a hotline exists, employees know how to use it, and anonymous reporting is available. But many of the greatest compliance and reputational risks emerge after a report has been submitted.

A concern can end up with the wrong person. It can get handled over email instead of through a proper process. It can land with an investigator who has a conflict or get closed with no record of how the decision was made. The real test for legal, risk and governance teams isn’t whether a report was received, it’s whether the organisation can show it was handled confidentially, consistently and fairly from disclosure through to resolution.

Unclear ownership and handoffs

Misconduct cases aren’t uniform. Fraud, regulatory breaches, harassment, safety issues, conflicts of interest, executive misconduct – each needs a different response, but responsibility isn’t always clearly defined.

Cases get passed between human resources, legal, compliance and operational teams without a documented decision about who’s accountable. Context gets lost, response times lengthen, and employees receive inconsistent treatment.

A defensible process needs clear triage rules: where a report goes, who owns the next step, and when it must be escalated. Without defined ownership, an organisation can struggle to explain who made critical decisions and why.

Fragmented investigation trails

Many organisations still manage investigations through spreadsheets, shared drives, inboxes and informal messages. This makes it difficult to maintain a complete case record. Evidence ends up stored in different locations, access isn’t controlled, and important decisions aren’t documented consistently.

The problem becomes more serious when a regulator, board or external adviser asks how a matter was handled. The organisation needs to show when the concern was received, who accessed it, what evidence was considered, and why a particular outcome was reached.

Centralised case management provides a clear investigation trail from intake to closure, backed by controlled access, structured workflows and audit-ready records. These systems don’t determine investigation outcomes, but they make the process more consistent and defensible.

Hidden gaps in misconduct reporting that could become a compliance crisis

Since Australia’s whistleblower reforms were introduced in 2019, misconduct disclosures have more than tripled

Anonymity without meaningful protection

Anonymous reporting is now common, but anonymity alone doesn’t necessarily make a process safe. Employees worry their identity will be inferred from the details they’ve given, that information will be shared too widely, or that they’ll face retaliation. Investigations can also stall if follow-up questions can’t be asked without compromising the reporter.

Secure, two-way anonymous communication lets investigators continue the conversation while protecting the reporter’s identity. Access controls and confidentiality safeguards ensure sensitive information is only available to those responsible for the case.

Organisations need to look beyond anonymity at the point of disclosure, with clear processes for identifying and managing retaliation risks throughout the investigation and after its resolution.

Conflict-of-interest blind spots

A process can appear independent while still allowing biased individuals to influence how a case is handled. This risk is particularly significant when an allegation involves a senior executive, an investigator, an important client or a commercially sensitive relationship. A case might even be automatically routed to someone who works closely with the person named in the report.

Conflicts aren’t always deliberate or obvious, which is why organisations need defined checks rather than relying on individuals to recognise and declare them. Potential conflicts should be identified during triage, with alternative investigation and escalation pathways available. Serious cases may call for independent internal oversight, external advisers, or escalation to a board committee.

Independence must be demonstrated, not assumed. If employees believe hierarchy or personal relationships can sway an outcome, confidence in the reporting program erodes quickly.

Limited visibility of systemic issues

A case can be resolved appropriately in isolation while still contributing to a wider organisational problem.

Aggregated reporting and trend analysis help legal, risk and governance teams identify patterns while protecting sensitive information. Artificial intelligence can also support consistent classification, routing and the identification of related concerns, provided appropriate controls and human oversight remain in place.

The goal isn’t to automate judgement. It’s to give decision-makers a clearer view of where risk may be accumulating.

The real measure of trust

A strong misconduct reporting program is more than a channel for raising concerns – it is a governance system that protects people, preserves evidence and helps leaders see where risk is building. Organisations that leverage technology to support clear accountability, independent oversight and connected case data are better placed to respond early, demonstrate fairness and withstand regulatory scrutiny.

The real measure for boards and executives is not simply whether people feel safe to report concerns, but whether the organisation has the systems, processes and oversight to act on what they say.