LODLINE
EN / SV

compliance-sanctions-cyber

Whistleblowing channels and internal investigations: step by step

Whistleblowing channels and internal investigations: step by step follow five stages that recur regardless of company size: set up a channel that meets confidentiality and access requirements, acknowledge and triage the report, run the fact-finding stage without alerting the person concerned prematurely, decide on remedial or disciplinary measures, and close the file with documented feedback to the person who reported. Skipping a stage, or leaving it undocumented, is usually what converts a routine internal matter into exposure for the company itself.

Who this concerns

This sits within the wider compliance, sanctions and cyber practice area and speaks to three groups in particular. The first is a company setting up a whistleblowing channel, sometimes called a visselblåsarkanal in Swedish, for the first time and wanting the structure right before the first report ever arrives. The second is a compliance or HR function that already has a report sitting on the desk and needs the next step, not a general explanation of the topic. The third is a group structure where the Swedish entity is required to run its own channel even though the group's whistleblowing policy, and often the platform it runs on, was set somewhere else.

None of these three readers need a description of why whistleblowing rules exist. They need the sequence, the decision points inside that sequence, and the point at which an internal file stops being something the company can safely handle on its own.

What the law says

Under Swedish law as it currently stands, an employer above a certain size is required to maintain an internal channel through which workers can report suspected wrongdoing, and confidentiality of the reporting person's identity has to be preserved against anyone who does not need it to process the case. The rules require the report to be acknowledged and require feedback to the reporting person within a timeframe set by the applicable legislation, and they protect the reporting person against retaliation connected to having reported in good faith. Alongside the internal route, the framework provides for an external channel through the competent supervisory authority and, in narrower circumstances, for public disclosure.

None of this displaces ordinary employment law or the company's own disciplinary procedures. The whistleblowing rules govern how the report is received, kept confidential and fed back to the reporting person. What happens to the underlying conduct once it has been investigated, whether that is a warning, a dismissal, a policy change or a referral to an authority, is decided under the rules that would apply to that conduct anyway.

How it works in practice

Setting up the channel

A compliant channel needs a way to report in writing and, if requested, orally, and it needs a person or function handling it who is independent enough from the likely subject of a future report to be credible. Access to the case has to be limited to those who need it, and the channel needs its own record of who reported, when, and who has touched the file since.

Receiving and acknowledging a report

The first working decision is not investigative, it is classificatory: does the report describe conduct the whistleblowing channel is meant to protect, or is it an ordinary grievance that should go through normal HR channels instead. Getting this wrong in either direction causes problems later, either by extending protection where it was not meant to apply or by denying it where it should have applied. Once classified, the report is logged and receipt is confirmed to the person who reported.

Scoping the investigation

Before any evidence is gathered, the scope needs to be written down: what conduct is being looked at, over what period, and who is covered by the protection that comes with having reported. This is also where a decision is made, and recorded, on whether and when the person accused is told that an investigation exists.

Interviews and evidence gathering

Evidence is preserved before it is reviewed, particularly IT systems and correspondence, and any review of personal data has to sit within the company's ordinary data protection obligations rather than override them because the matter is sensitive. The usual order is to speak to witnesses and gather documentary evidence before interviewing the person accused, so that the interview tests an already assembled account rather than shapes it.

Provisional measures

Suspension, restricted system access or a temporary change of duties can be justified while a file is open, but only where the measure is proportionate to the risk of continued conduct or evidence tampering, not as a punishment applied before any finding has been made. A provisional measure that reads as punitive is itself a source of retaliation exposure, separate from whatever the underlying report concerns.

Deciding the outcome

The file closes on one of a limited set of outcomes: unfounded, founded with disciplinary or remedial action, founded with a wider process or policy change, or referral to an external authority or the police. The reasoning behind the chosen outcome needs to be written down in enough detail that it would survive being read by someone who was not in the room.

Feedback and closing the file

The reporting person is entitled to feedback on the outcome, within limits set by confidentiality toward third parties and, where relevant, by an ongoing criminal process. Records are retained for a bounded period rather than indefinitely, and the retention period itself should be fixed before the file is closed, not decided afterwards.

What to check before you open a file

  • Who is handling the case, and whether that person reports to, or is close to, the likely subject of the complaint
  • Whether the channel used to receive the report actually meets the confidentiality standard, or whether it leaked before the file was even opened
  • Whether the scope of the investigation is written down before any evidence is gathered
  • Whether a decision on informing the accused, and when, has been made and recorded
  • Whether a parallel notification obligation exists outside the whistleblowing process itself, for instance a security incident that also falls within NIS2 scoping and registration, which runs on its own clock and does not pause because the internal file is still open
  • Whether the retention period for the case file has been set

Does a whistleblowing report change how a police search at company premises is handled?

If law enforcement executes a search connected to the same conduct, the internal investigation should pause the parts of its evidence-gathering that overlap with the authorities' own work and let the criminal timeline take precedence. See a search at company premises: timeline and cost for how that process runs and what it actually costs the business in time and disruption.

Can a report about payments to a related party trigger capital maintenance exposure separately from the investigation?

Yes. A report describing a transfer of value to a related counterparty can raise capital maintenance questions that exist independently of what the internal investigation concludes about any individual's conduct. See capital maintenance and unlawful value transfers for how that exposure is assessed when the counterparty sits close to the company.

Do whistleblowing channels overlap with NIS2 incident reporting obligations?

They can. A report that describes a security incident rather than misconduct may trigger a notification clock under the NIS2 framework that runs separately from, and typically faster than, the internal whistleblowing process. See NIS2 scoping and registration: the regulator's view to check whether the company falls within scope before assuming the internal channel is the only obligation triggered.

The numbers

The legislation ties specific obligations to specific company sizes and specific windows for acknowledgment and feedback. Those figures should be read from the current text of the applicable act rather than assumed, because size thresholds and grace periods for smaller employers have moved before and are the kind of detail that changes without much notice. What can be said generically is that the acknowledgment step is short by design, the feedback step is measured in months rather than weeks, and the retention period for case records is bounded rather than open-ended.

What drives the actual cost and duration of a case is not the size of the company but the shape of the file: how many witnesses need to be interviewed, whether external counsel is brought in to preserve independence, whether a parallel regulatory notification is triggered by the same facts, and whether the records will later need to be produced to an authority or in litigation. A single-witness report closed within weeks and a multi-jurisdiction report that runs for months are both routine outcomes of the same procedure; the procedure does not predict which one a given report will be.

Where it usually goes wrong

The channel exists on paper but is not genuinely independent, most commonly because the person handling reports also manages the people most likely to be reported. Confidentiality is broken informally rather than through the channel itself, which is enough to expose the company even if the formal process was followed to the letter. The person accused is told too early, before evidence has been secured, which changes what the subsequent investigation is actually able to establish.

Provisional measures are applied as a punishment before any finding has been made, which turns a protective step into a retaliation claim against the company. Group companies headquartered outside Sweden sometimes route every report to a shared service centre abroad without maintaining a Swedish channel at all, which is where the local obligation is missed even though group policy technically covers the topic. Where the reporting person, the accused, or the underlying conduct sits partly outside Sweden, for instance because the parent company is based in another EU state, the question of where a resulting order or judgment can actually be enforced becomes relevant later rather than sooner. See recognition of a Swedish judgment in Portugal for how that plays out once the counterparty's assets sit abroad.

Finally, a company sometimes assumes the internal channel is the only obligation in play and never checks whether the same facts also trigger an external notification duty, closing the internal file while a separate clock is still running elsewhere.

What to do next

The steps above cover how to run the channel and the file competently once a report exists. What they cannot answer from a template is whether a specific report changes the company's regulatory exposure, or whether it exposes a gap in existing supplier arrangements: where the conduct involves a subcontractor, that question sits closer to supplier and subcontractor security requirements than to the whistleblowing process itself.

That judgement needs the actual file in front of someone qualified to read it, not a general description of the procedure. Book an assessment call once the internal steps above are underway; the call is for scoping what the report means for the company's exposure, not for running the investigation in place of it.

Request a preliminary assessment