Skip to main content

How to Structure a Whistleblowing Annual Report to the Board Under SYSC 18

This guide sets out how to build a board-level whistleblowing report that meets FCA SYSC 18.6 expectations while protecting reporter identity and case confidentiality. After reading, you will know what to include, what to leave out, and how to frame themes so the board can discharge oversight without becoming a de facto investigations committee.

The SYSC 18.6.1R requirement is short: at least annually, the governing body must receive a report on the operation and effectiveness of the firm's whistleblowing systems and controls. The difficulty is not the rule. It is producing a document that gives the board enough to challenge the framework without turning individual cases into board-level exhibits, and without creating a discoverable record that could identify reporters or prejudice live investigations.

Key Executive Takeaways

  • SYSC 18 requires assurance on the framework, not case-by-case reporting; structure the paper around themes, trends and control effectiveness rather than individual matters.
  • Anonymisation is not just redacting names; small case volumes, distinctive facts and business unit tags can re-identify reporters and must be actively managed.
  • The Whistleblowers' Champion owns the report's credibility; the board's job is to test the framework, not to adjudicate outcomes.

Start with what the board actually needs to conclude

The board is being asked to form a view on whether the firm's whistleblowing arrangements are operating effectively. That is the only question the paper needs to answer. Everything else is supporting evidence. Draft the conclusion first, then work backwards to the sections that support it. If you cannot state a clear view on effectiveness, the report is not ready.

The seven sections that belong in the report

  1. Champion's opinion. A short, signed statement from the Whistleblowers' Champion on effectiveness, gaps and planned changes. This is the anchor.
  2. Framework changes in the period. Policy updates, channel changes, vendor changes, training refresh, jurisdictional updates (EU Directive interaction where relevant).
  3. Volumes and channels, at aggregate level. Total reports received, split by channel (hotline, line manager, email, external), with prior-year comparatives. Avoid business unit splits where volumes are low enough to identify individuals.
  4. Thematic analysis. Categories of concern (conduct, financial crime, market abuse, HR-adjacent, other), triage outcomes at category level, and any emerging patterns. Themes, not stories.
  5. Timeliness and process metrics. Time to acknowledge, time to triage, time to close, proportion investigated versus signposted elsewhere. These demonstrate the framework works.
  6. Detriment monitoring. What the firm has done to detect and prevent detriment against reporters, including exit analysis, performance rating checks and manager awareness. This is often the weakest section and the one the FCA cares most about.
  7. Effectiveness assessment and forward plan. Independent assurance findings, benchmarking where available, and the actions committed for the next cycle.

Where anonymisation actually breaks

Most reports fail the re-identification test in three places. First, low-volume business unit breakdowns: two reports from a 40-person desk names the reporter. Second, timing plus subject matter: "a concern raised in Q2 regarding a senior trader" is not anonymous. Third, outcome narratives: describing remediation actions specifically enough to be useful often describes the case specifically enough to be identifying.

Good practice is to suppress any cell with fewer than five cases, aggregate across periods where necessary, and never link category, business area and outcome in the same table. If the board asks for more granularity, the answer is a private session with the Champion, not a richer paper.

What most firms get wrong

They treat the report as a case log with a cover note. The result is a document that the General Counsel will not want disclosed, that the board cannot usefully challenge, and that invites the FCA to ask why individual matters are being escalated to the governing body rather than investigated properly below it. The board should not be approving outcomes on named cases. It should be testing whether the system that produced those outcomes is credible.

The second common failure is a silent report: low numbers presented as good news. Low volumes are a warning sign, not a comfort. Address them directly, with reference to speak-up culture indicators, engagement survey data and independent assurance.

The decision to make now

Before the next reporting cycle, agree with the Champion and the Company Secretary what will and will not appear in the board paper, what sits in a confidential annex for the Champion only, and what remains solely in the case management system. If that boundary is not written down, someone will get it wrong under time pressure.

Frequently Asked Questions

Should individual cases ever be named to the board?

Only where a case itself presents a governance risk the board must manage, for example a concern implicating a Senior Manager. Even then, brief the Chair and Champion privately first and document why board-level visibility is necessary.

How do we handle cases still under investigation at year-end?

Report them in aggregate as open matters with expected closure timing. Do not describe facts. If a live matter is material, the Champion should brief the Chair separately outside the annual paper.

Does the report need to go to the full board or a committee?

SYSC 18.6.1R refers to the governing body. Most firms present to the full board with the Audit or Risk Committee reviewing first. Committee-only reporting is defensible if the terms of reference are explicit and the board minutes record the delegation.

How should we treat reports made to the FCA or PRA directly?

Disclose that the firm is aware of such reports where it is, at aggregate level, and describe the firm's cooperation posture. Do not speculate on matters the regulator has not shared with you.

What role does internal audit play?

Internal audit should provide periodic independent assurance on the framework, typically on a two to three year cycle, and its most recent findings should be referenced in the effectiveness section. Audit does not own the report; the Champion does.

Frequently asked questions

Should individual cases ever be named to the board?

Only where a case itself presents a governance risk the board must manage, for example a concern implicating a Senior Manager. Even then, brief the Chair and Champion privately first and document why board-level visibility is necessary.

How do we handle cases still under investigation at year-end?

Report them in aggregate as open matters with expected closure timing. Do not describe facts. If a live matter is material, the Champion should brief the Chair separately outside the annual paper.

Does the report need to go to the full board or a committee?

SYSC 18.6.1R refers to the governing body. Most firms present to the full board with the Audit or Risk Committee reviewing first. Committee-only reporting is defensible if the terms of reference are explicit and the board minutes record the delegation.

How should we treat reports made to the FCA or PRA directly?

Disclose that the firm is aware of such reports where it is, at aggregate level, and describe the firm's cooperation posture. Do not speculate on matters the regulator has not shared with you.

What role does internal audit play?

Internal audit should provide periodic independent assurance on the framework, typically on a two to three year cycle, and its most recent findings should be referenced in the effectiveness section. Audit does not own the report; the Champion does.

Related guides

Boards, Governance & Defensibility

How to Structure a Basel 3.1 Board Paper That Secures Approval

This guide sets out how to write a Basel 3.1 implementation board paper that wins approval without softening the capital impact numbers. Read it to sharpen your framing, sequencing, and stakeholder handling before the paper goes to committee.

Regulatory changeBoardsRegulators
4 min readRead guide →
Boards, Governance & Defensibility

Structuring a Consumer Duty Board Champion Report That Evidences Good Outcomes

This guide sets out how to write a Consumer Duty board champion report that demonstrably evidences good outcomes without triggering FCA product intervention or supervisory escalation. It shows senior leaders what to include, what to leave out, and how to frame difficult findings so the board can act without handing the regulator a case file.

Regulatory changeRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

How to Build Real Board Accountability in Regulated Industries

This guide sets out what board accountability actually requires in regulated financial services firms, from information rights to individual responsibility. After reading, you will be able to test whether your board is genuinely accountable or only appears to be.

Regulatory changeBoardsRegulators
4 min readRead guide →
Boards, Governance & Defensibility

Structuring an MLRO Annual Report That Satisfies SYSC 6 Without Triggering FCA Intervention

This guide sets out how to structure and write the MLRO annual report so it meets SYSC 6.3.9G expectations and gives the board a defensible record of financial crime oversight. After reading it, senior decision-makers will know what to include, what to leave out, and how to frame weaknesses without inviting supervisory follow-up.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

Regulated Industry Governance Best Practice: A Practical Guide

This guide sets out what governance best practice actually looks like in regulated financial services, from board composition to evidencing challenge. After reading it, senior leaders will know where their governance is likely to fail regulatory scrutiny and what to fix first.

Regulatory changeBoardsRegulators
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity