Whistleblower Reports
Somebody in your organization has noticed something wrong. Whether they say anything depends almost entirely on whether they believe it will be handled by a person who will take it seriously and protect them afterward. That belief is fragile, it is built slowly, and it can be destroyed in a single interaction. This is the process where a well-meant efficiency improvement does the most damage, and it deserves a deliberate decision by the board about what stays human.

Almost every nonprofit above the Form 990 filing threshold answers yes to the question about having a whistleblower policy. Far fewer could describe what happens when someone uses it. The policy usually exists as a page in the employee handbook, adopted at a board meeting several years ago, naming a recipient who may no longer work there, with a process nobody has ever run.
That dormancy is not automatically a failure. Most organizations genuinely do not receive many reports. But dormancy makes it very easy to modernize the wrong parts. As organizations digitize their operations, the whistleblower channel is an obvious candidate for a form, a workflow, an automated acknowledgment, and a tracking system. Some of that is a real improvement. Some of it will convince the one person who was thinking about coming forward that nobody is listening.
The distinction that matters is between the logistics of receiving a report and the substance of responding to one. Logistics benefit from structure and from tools. Substance depends on a person exercising judgment, taking responsibility, and being accountable for the outcome. The IRS framing of what a whistleblower policy should do points at the same split: encourage people to come forward, protect them from retaliation, and identify who they can report to. Two of those three are entirely about human trust.
What follows covers what your policy is required to accomplish, why the channel matters more than the document, exactly where AI has a legitimate role, the parts that should never be automated and why, the confidentiality problem that most organizations have not thought about, and what the board specifically owns in all of this.
What the Policy Is Supposed to Accomplish
Federal tax law does not require a nonprofit to have a whistleblower policy. The Form 990 asks whether you have one because the IRS treats it as a marker of good governance, and the instructions describe what a policy should do: encourage staff and volunteers to come forward with credible information about illegal practices or violations of organizational policy, state explicitly that the organization will protect them from retaliation, and identify the people to whom such information can be reported.
Separately, the retaliation protections in the Sarbanes-Oxley Act apply to nonprofits. Section 1107 makes it a federal crime to knowingly take harmful action against a person for providing truthful information to a law enforcement officer about the commission of a federal offense. Sections 802 and 1102 make destroying or altering records to obstruct a federal investigation a crime, which is why a whistleblower matter and your records retention practices intersect immediately: the moment a credible report arrives, routine deletion of anything relevant needs to stop.
State law adds its own protections, and many states have whistleblower statutes covering employees of nonprofit corporations. Employment counsel in your state should confirm what applies to you, because the specifics differ and they affect what your policy should promise.
Beyond the legal frame, the policy has a practical purpose that boards frequently miss. It is the mechanism by which the board learns about problems that management would prefer it did not learn about. If every path for raising a concern runs through the executive director, the board has no independent source of information about the executive director. That is the single most important design question in the whole policy, and it is answered by naming a board-level recipient with a contact route that does not pass through staff.
What a working policy contains
Beyond the paragraph that satisfies the 990
- Who it covers: employees, volunteers, board members, contractors, and often clients
- What it covers, in examples rather than abstractions
- At least two named recipients, one of them outside management
- A route to the board that does not pass through the executive director
- An explicit no-retaliation commitment, with consequences stated
- What the reporter can expect: acknowledgment, timeline, and follow-up
- How confidentiality is handled, including its honest limits
- Whether anonymous reports are accepted, and how they are handled
The Channel Matters More Than the Document
No one has ever decided to report a concern because the policy was well drafted. They decide based on whether they can imagine the conversation going acceptably, and that imagination is built from everything they have observed about how the organization treats people who raise difficult things.
This is why small nonprofits face a genuinely hard version of the problem. In a twelve-person organization, confidentiality is largely fictional. The details of most concerns identify the person raising them, because only two people were in the room. Promising anonymity you cannot deliver is worse than being honest that you cannot, and the honest version, which is that you will protect their identity as far as you are able and will tell them where you cannot, earns more trust than a promise nobody believes.
It is also why the choice of channel is a substantive decision rather than a technical one. A shared email address monitored by the finance manager sends one message. A named board member's personal phone number sends another. An external third-party service sends a third, signaling both seriousness and distance. Organizations with a history of concerns being buried need the strongest available signal of independence. Organizations with high trust may do better with a person's name and door.
The one universal requirement is that the channel be reachable by people without organizational credentials. Volunteers, contractors, former employees, and clients frequently see things staff do not, and a reporting route that requires an internal login excludes exactly the people whose observations are hardest to obtain by other means.
Finally, the channel has to be visible. A policy in a handbook that new hires acknowledge and never reopen is invisible. The contact route should appear where people actually look, be repeated at least annually, and be mentioned in a way that treats reporting as a normal part of organizational health rather than an extreme step. Boards that ask each year how many reports were received, and treat zero as a question rather than as good news, tend to have channels that work.
The Narrow Band Where AI Helps
There is a legitimate role here, and it sits almost entirely before a report arrives and after a decision is made, rather than anywhere in the middle.
Writing and translating the policy. Most whistleblower policies are written in language that discourages use. Rewriting one into plain, direct sentences that a part-time program assistant can act on is a genuine improvement, and translating it accurately into the languages your staff and volunteers actually speak removes a real barrier. Have a native speaker review any translation, because the stakes of a mistranslated protection clause are high.
Building the training that makes the channel visible. Scenario-based training that helps staff recognize what is worth reporting, and helps supervisors understand what they must do when someone raises something with them informally, is more useful than an annual policy acknowledgment. Drafting those materials is ordinary content work where AI assistance is fine.
Tracking the process, not the substance. A register of reports with dates received, acknowledgment sent, investigator assigned, status, and resolution date lets the board see whether the process is functioning without reading the contents. Automated reminders when an acknowledgment is overdue or a matter has gone quiet for weeks are exactly the kind of administrative discipline that prevents the most common failure, which is a report that simply stops moving.
Preserving evidence properly. When a matter opens, someone has to identify what needs preserving and stop routine deletion across email, files, and now assistant histories and meeting transcripts. Tooling that helps enumerate where relevant material might live is useful, and this is precisely where the AI-era gap in most hold procedures bites hardest.
Aggregate reporting to the board. Counts, categories, timeliness, and trends across years, presented without identifying details, give the board oversight without turning them into investigators. This connects to the broader oversight discipline described in our guide to board oversight in an AI-enabled organization.
Preparing an investigation plan template. Not conducting one. A structured checklist covering scope, who should be interviewed, what documents to gather, conflict of interest screening for the investigator, and documentation standards helps a first-time investigator avoid procedural mistakes. The investigator still does every part of the work.
What Should Never Be Automated
The list below is short and the reasoning behind each item is the same: these are moments where a person is taking a risk, and the organization's response tells them whether the risk was worth taking.
Intake as a conversation with a bot. A structured form is fine and often helpful, because it prompts for details people forget to include. A conversational agent that questions someone about a serious concern is different in kind. It signals that the organization has delegated the first moment of listening to software, and it produces exactly the impression the policy exists to prevent. If a person is prepared to talk, a person should be there.
Triage and credibility assessment. Scoring reports by apparent seriousness or plausibility is the most dangerous idea in this area. Real reports are frequently incoherent, emotional, partial, and delivered by people who are frightened, and those characteristics correlate with nothing useful about whether the underlying concern is real. A system that deprioritizes a badly written report has made a substantive judgment about a person's credibility using signals that should never carry that weight.
The investigation. Interviewing people, weighing accounts that conflict, evaluating documents in context, and reaching a conclusion about what happened is human work with due process implications for everyone involved, including the person accused. A summary of documents produced by a tool can support an investigator. It cannot substitute for their judgment, and a finding that rests on an automated analysis is a finding that cannot be properly defended.
Any determination about retaliation. Whether a schedule change, a reassignment, or a performance conversation was retaliatory depends on intent, timing, and context, and it is a legally significant determination. This one is not close. It belongs to counsel and the board.
Communicating with the reporter. The acknowledgment can be templated, and there is nothing wrong with a prompt automated confirmation that a report was received, provided a person follows within a stated period. Everything after that should come from the named human handling the matter. An automated status update about a serious personal risk someone took is a small insult that people remember.
Closing a matter. Deciding that a concern has been resolved is a judgment with consequences, including for whether the reporter believes the process worked. It should be made by a named person, recorded with reasons, and communicated by that person. This is the same principle we applied to conflict of interest review: tools assemble and track, people decide and answer for it.
Reasonable to systematize
Logistics, visibility, and discipline
- A structured intake form alongside a human contact
- Immediate acknowledgment of receipt, followed by a person
- Status tracking and overdue reminders on the process
- Evidence preservation checklists when a matter opens
- Plain-language policy drafting and accurate translation
- Anonymized aggregate reporting to the board
Never automate
Listening, judging, and answering for it
- Conversational intake that replaces a human listener
- Scoring reports for credibility, seriousness, or priority
- Conducting or concluding an investigation
- Determining whether an action was retaliatory
- Substantive communication with the person who reported
- Deciding that a matter is closed
The Confidentiality Problem Nobody Mentions
Even where the human judgment stays human, there is a technical exposure that most organizations have not considered, and it can undo the protection the policy promises.
Consider what happens when a whistleblower matter is handled using the same tools as everything else. The board chair pastes the report into an assistant to help organize the issues. An investigator uses a notetaker during interviews. Someone asks a tool to summarize the documents. Each of those actions puts the most sensitive material your organization holds into a system with its own retention, its own access model, and possibly its own vendor employees. The person who reported believed the circle was three people. It may now include a service they have never heard of.
Access inside your own systems deserves the same scrutiny. If the investigation file lives in shared cloud storage, the question is who has administrative visibility. In many small nonprofits the answer is the operations manager, who may be the subject of the report. A matter involving anyone with systems access needs to be handled outside the systems they can reach, and that decision has to be made at the start rather than discovered later.
There is also an identification risk specific to text. A short report written in someone's distinctive voice, referencing details only a few people know, can identify its author to a colleague reading it even when the name is removed. Organizations that circulate a report verbatim to a committee in the name of transparency have frequently unmasked the reporter without intending to. Summarize, restrict circulation, and think about who can infer what.
The practical answer is to decide in advance, in writing, which tools may touch whistleblower material and which may not, and to make that decision part of both your acceptable use policy and your investigation procedure. An organization that has already done the work described in our guide to privacy risk assessment for AI projects will find this a short extension of it. One that has not will be making the decision under pressure with a live matter open.
Decide these before a matter arrives
Written into the procedure, not improvised
- Which tools may never be used on whistleblower material
- Where investigation files are stored, and who can administer that location
- What happens when the subject of a report controls the systems
- Whether meeting transcription is permitted during interviews
- How reports are summarized before any wider circulation
- How long investigation records are retained, and by whom
What the Board Specifically Owns
Whistleblower policy is one of the few governance areas where the board has an operational role rather than only an oversight one, because the whole design depends on a path that management does not control.
The board should name a specific director as a reporting recipient, publish a way to reach that person directly, and ensure the role transfers when the person rotates off. A policy naming a board chair who left in 2023 is a dead channel that looks alive, which is worse than having no channel, because the report goes into a mailbox nobody reads.
The board should also decide in advance how a report concerning the executive director is handled. Who investigates, whether outside counsel is retained, who communicates with staff, and how the board manages a situation where it is simultaneously the employer of the subject and the body evaluating the report. Deciding this in the abstract takes twenty minutes. Deciding it in the middle of a live allegation, with directors who have personal relationships with the executive, goes badly with reliable consistency.
An annual review belongs on the calendar. How many reports came in, how quickly they were acknowledged, how long they took to resolve, and whether the channel is still functional. Test the channel by sending something through it and confirming it arrives. A board that has never verified that the reporting email address works is taking a fairly large fact on faith.
Finally, the board sets the tone that determines whether any of this matters. Organizations where difficult information reaches the board have usually built that over years through visible responses to smaller concerns. Where the culture treats a report as disloyalty, no policy, channel, or system will produce the information the board needs. That cultural work is slow and it is not delegable to a tool, which is ultimately the theme of this entire subject.
A board agenda item worth twenty minutes a year
Most of this is decisions, not work
- Confirm the named board recipient is current and reachable
- Test the reporting channel end to end and record the result
- Review counts, categories, and timeliness without identifying details
- Agree in advance how a report about the executive is handled
- Confirm which tools are excluded from handling these matters
- Ask whether staff would actually use the channel, and why or why not
Conclusion
We have argued in a great many articles that nonprofits should put AI to work on the tedious, repetitive, comparison-heavy tasks that consume staff time. This is the counterexample that clarifies the rule. Whistleblower reporting is not a throughput problem. Your organization probably receives a handful of reports a year, and the value of the process is entirely in how each one is received and handled.
So the useful automation here is unglamorous. Track the process so nothing stalls. Make the policy readable and available in the right languages. Preserve evidence properly when a matter opens. Give the board an anonymized view of whether the system functions. All of that is real and worth doing, and none of it touches the report itself.
Everything else stays with people. Someone listens, someone decides what to do, someone investigates, someone tells the reporter what happened, and someone is accountable for the outcome. When a staff member takes a real personal risk to tell the organization something it needs to hear, the response has to come from a person who is prepared to own it. That is not an efficiency to be found. It is the entire point.
Know Where the Line Sits Before You Cross It
We help nonprofit boards decide which processes benefit from automation and which depend on human judgment, then build the governance that holds that line.
