Reporters can now speak their report. Voice reporting is live on all plans.Learn more
Ashio whistleblowing software

Glossary

Whistleblowing and compliance terms, in plain language.

The vocabulary you meet in the EU Whistleblowing Directive, in procurement questionnaires and in your own DPA conversations. Short definitions, no jargon.

Why this list

One word, one meaning.

Whistleblowing vocabulary drifts between the directive, national law, auditors and vendors. These are the definitions we use, and the ones we hold ourselves to in our own product and documentation.

Terms

Definitions.

Whistleblower
A person who reports a breach of law or serious wrongdoing they learned about in a work-related context. Under Directive (EU) 2019/1937 that covers employees, contractors, suppliers, shareholders and volunteers.
Whistleblowing
Reporting that breach through an internal channel, an external channel, or both.
Internal reporting channel
The confidential route inside an organisation for receiving reports. Mandatory in the EU for organisations with 50 or more employees.
External reporting channel
A route outside the organisation, such as a supervisory authority or an ombudsman. Reporters may use it instead of, or after, the internal channel.
Directive (EU) 2019/1937
The EU Whistleblowing Directive. It requires member states to protect reporters and to oblige organisations to run internal channels. Transposition deadline: 17 December 2021.
Acknowledgment
Written confirmation to the reporter that their report was received. Due within 7 days under the Directive.
Feedback
The information given to the reporter about the follow-up to their report. Due within 3 months of the acknowledgment.
Follow-up
Every step taken after a report arrives: assessment, investigation, decision and the response to the reporter.
Retaliation
Any detriment suffered because someone reported, such as dismissal, demotion or harassment. Prohibited by the Directive.
Anonymous reporting
A report submitted without identifying details. Ashio's reporting pages set no cookies and record no IP addresses.
Confidential reporting
A report where the organisation knows who reported, but their identity is protected from wider disclosure.
End-to-end encryption
Encryption performed in the reporter's browser, so the server only ever stores ciphertext and cannot read the report.
Zero-access architecture
A design in which the operator cannot decrypt customer content at all, even with direct database access.
Audit trail
The immutable, timestamped record of every event on a case: created, assigned, acknowledged, answered, closed.
Pseudonymisation
Replacing identifying data with a reference, so it can no longer be attributed to a person without additional information.
Retention period
How long personal data is kept before it is deleted. Set by your organisation, within the limits of the law.
ISO 37002
The international standard for whistleblowing management systems. It describes how a channel should be governed, operated and reviewed.
ISO 27001
The information security standard. The servers Ashio runs on are ISO 27001 certified, in Switzerland.

See the definitions in a running channel.

The 7-day and 3-month deadlines, the audit trail and end-to-end encryption are all in the product. 14-day free trial, no card.