How to Structure a Whistleblowing Annual Report to the Board Under SYSC 18
This guide sets out how to build a board-level whistleblowing report that meets FCA SYSC 18.6 expectations while protecting reporter identity and case confidentiality. After reading, you will know what to include, what to leave out, and how to frame themes so the board can discharge oversight without becoming a de facto investigations committee.
The SYSC 18.6.1R requirement is short: at least annually, the governing body must receive a report on the operation and effectiveness of the firm's whistleblowing systems and controls. The difficulty is not the rule. It is producing a document that gives the board enough to challenge the framework without turning individual cases into board-level exhibits, and without creating a discoverable record that could identify reporters or prejudice live investigations.
Key Executive Takeaways
- SYSC 18 requires assurance on the framework, not case-by-case reporting; structure the paper around themes, trends and control effectiveness rather than individual matters.
- Anonymisation is not just redacting names; small case volumes, distinctive facts and business unit tags can re-identify reporters and must be actively managed.
- The Whistleblowers' Champion owns the report's credibility; the board's job is to test the framework, not to adjudicate outcomes.
Start with what the board actually needs to conclude
The board is being asked to form a view on whether the firm's whistleblowing arrangements are operating effectively. That is the only question the paper needs to answer. Everything else is supporting evidence. Draft the conclusion first, then work backwards to the sections that support it. If you cannot state a clear view on effectiveness, the report is not ready.
The seven sections that belong in the report
- Champion's opinion. A short, signed statement from the Whistleblowers' Champion on effectiveness, gaps and planned changes. This is the anchor.
- Framework changes in the period. Policy updates, channel changes, vendor changes, training refresh, jurisdictional updates (EU Directive interaction where relevant).
- Volumes and channels, at aggregate level. Total reports received, split by channel (hotline, line manager, email, external), with prior-year comparatives. Avoid business unit splits where volumes are low enough to identify individuals.
- Thematic analysis. Categories of concern (conduct, financial crime, market abuse, HR-adjacent, other), triage outcomes at category level, and any emerging patterns. Themes, not stories.
- Timeliness and process metrics. Time to acknowledge, time to triage, time to close, proportion investigated versus signposted elsewhere. These demonstrate the framework works.
- Detriment monitoring. What the firm has done to detect and prevent detriment against reporters, including exit analysis, performance rating checks and manager awareness. This is often the weakest section and the one the FCA cares most about.
- Effectiveness assessment and forward plan. Independent assurance findings, benchmarking where available, and the actions committed for the next cycle.
Where anonymisation actually breaks
Most reports fail the re-identification test in three places. First, low-volume business unit breakdowns: two reports from a 40-person desk names the reporter. Second, timing plus subject matter: "a concern raised in Q2 regarding a senior trader" is not anonymous. Third, outcome narratives: describing remediation actions specifically enough to be useful often describes the case specifically enough to be identifying.
Good practice is to suppress any cell with fewer than five cases, aggregate across periods where necessary, and never link category, business area and outcome in the same table. If the board asks for more granularity, the answer is a private session with the Champion, not a richer paper.
What most firms get wrong
They treat the report as a case log with a cover note. The result is a document that the General Counsel will not want disclosed, that the board cannot usefully challenge, and that invites the FCA to ask why individual matters are being escalated to the governing body rather than investigated properly below it. The board should not be approving outcomes on named cases. It should be testing whether the system that produced those outcomes is credible.
The second common failure is a silent report: low numbers presented as good news. Low volumes are a warning sign, not a comfort. Address them directly, with reference to speak-up culture indicators, engagement survey data and independent assurance.
The decision to make now
Before the next reporting cycle, agree with the Champion and the Company Secretary what will and will not appear in the board paper, what sits in a confidential annex for the Champion only, and what remains solely in the case management system. If that boundary is not written down, someone will get it wrong under time pressure.
Frequently Asked Questions
Should individual cases ever be named to the board?
Only where a case itself presents a governance risk the board must manage, for example a concern implicating a Senior Manager. Even then, brief the Chair and Champion privately first and document why board-level visibility is necessary.
How do we handle cases still under investigation at year-end?
Report them in aggregate as open matters with expected closure timing. Do not describe facts. If a live matter is material, the Champion should brief the Chair separately outside the annual paper.
Does the report need to go to the full board or a committee?
SYSC 18.6.1R refers to the governing body. Most firms present to the full board with the Audit or Risk Committee reviewing first. Committee-only reporting is defensible if the terms of reference are explicit and the board minutes record the delegation.
How should we treat reports made to the FCA or PRA directly?
Disclose that the firm is aware of such reports where it is, at aggregate level, and describe the firm's cooperation posture. Do not speculate on matters the regulator has not shared with you.
What role does internal audit play?
Internal audit should provide periodic independent assurance on the framework, typically on a two to three year cycle, and its most recent findings should be referenced in the effectiveness section. Audit does not own the report; the Champion does.
Frequently asked questions
Should individual cases ever be named to the board?
Only where a case itself presents a governance risk the board must manage, for example a concern implicating a Senior Manager. Even then, brief the Chair and Champion privately first and document why board-level visibility is necessary.
How do we handle cases still under investigation at year-end?
Report them in aggregate as open matters with expected closure timing. Do not describe facts. If a live matter is material, the Champion should brief the Chair separately outside the annual paper.
Does the report need to go to the full board or a committee?
SYSC 18.6.1R refers to the governing body. Most firms present to the full board with the Audit or Risk Committee reviewing first. Committee-only reporting is defensible if the terms of reference are explicit and the board minutes record the delegation.
How should we treat reports made to the FCA or PRA directly?
Disclose that the firm is aware of such reports where it is, at aggregate level, and describe the firm's cooperation posture. Do not speculate on matters the regulator has not shared with you.
What role does internal audit play?
Internal audit should provide periodic independent assurance on the framework, typically on a two to three year cycle, and its most recent findings should be referenced in the effectiveness section. Audit does not own the report; the Champion does.
Related guides
Regulated Industry Governance Best Practice: A Practical Guide
This guide sets out what governance best practice actually looks like in regulated financial services, from board composition to evidencing challenge. After reading it, senior leaders will know where their governance is likely to fail regulatory scrutiny and what to fix first.
What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test a major decision after the fact, and how to build defensibility into the decision itself rather than reconstruct it later. You will finish with a clear view of what to document, who to involve, and where most firms leave themselves exposed.
How to Make a Defensible Board Decision
A practical guide to constructing board decisions that hold up under regulatory, legal, and shareholder scrutiny long after the vote. Readers will finish knowing what to document, how to structure the discussion, and where most boards leave themselves exposed.
How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure
This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.
How to Structure a Section 166 Response That Preserves Board Credibility
A practical guide to responding to a Skilled Person review in a way that protects the board's standing with the regulator. Covers how to sequence the engagement, where boards typically damage their own credibility, and how to convert findings into a credible remediation posture.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity