home  /  insights  /  what-a-whistleblower-report-obligates
Detection & Investigation

What does a whistleblower report obligate a company to do?

Less than most boards assume and more than most hotline policies describe. For a listed company the duty is architectural — procedures the audit committee must have in place — while the sharpest obligations attach to how the reporter is treated afterward and to what stops being deleted the day the report arrives.

September 15, 2026 · 11 min read

The short answer

For a listed company the core obligation is structural rather than case-by-case: Section 301 of the Sarbanes-Oxley Act, codified at 15 U.S.C. § 78j-1(m)(4), and Exchange Act Rule 10A-3, 17 CFR 240.10A-3(b)(3), require the audit committee to establish procedures for the receipt, retention and treatment of complaints regarding accounting, internal accounting controls or auditing matters, and for confidential, anonymous employee submission of concerns about questionable accounting or auditing matters. Neither the statute nor the rule prescribes what the treatment of any particular complaint must be. The obligations that bite hardest attach elsewhere — to retaliation, under Section 806 of Sarbanes-Oxley, 18 U.S.C. § 1514A, and under Section 21F of the Securities Exchange Act, 15 U.S.C. § 78u-6, and to preservation, once litigation becomes reasonably foreseeable. Everything beyond that is practice, and the distinction is worth keeping straight, because practice is where most internal policies actually live.

What this article establishes

  • Section 301 of the Sarbanes-Oxley Act, 15 U.S.C. § 78j-1(m)(4), and Exchange Act Rule 10A-3(b)(3), 17 CFR 240.10A-3(b)(3), require audit committee procedures for “the receipt, retention, and treatment of complaints” and for “the confidential, anonymous submission by employees” of concerns about questionable accounting or auditing matters — enforced as a listing condition, since Rule 10A-3(a) directs exchanges to bar listing of non-compliant issuers.
  • Section 806 of Sarbanes-Oxley, 18 U.S.C. § 1514A, protects a report made to a Federal regulatory or law enforcement agency, to a member or committee of Congress, or to a person with supervisory authority over the employee; a complaint goes first to the Secretary of Labor within 180 days, and may move to federal court if there is no final decision within 180 days.
  • In Murray v. UBS Securities, LLC, 601 U.S. 23 (2024), decided 8 February 2024, a unanimous Court held that a whistleblower who invokes Section 1514A “bears the burden to prove that his protected activity ‘was a contributing factor in the unfavorable personnel action alleged in the complaint,’ 49 U. S. C. §42121(b)(2)(B)(i), but he is not required to make some further showing that his employer acted with ‘retaliatory intent.’”
  • Digital Realty Trust, Inc. v. Somers, 583 U.S. 149 (2018), decided 21 February 2018, answered “No” to whether Dodd-Frank’s anti-retaliation provision reaches someone who has not reported to the Securities and Exchange Commission: “To sue under Dodd-Frank’s anti-retaliation provision, a person must first ‘provid[e] . . . information relating to a violation of the securities laws to the Commission.’” So an internal-only report leaves Section 806, not Section 21F, as the protection.
  • Federal Rule of Civil Procedure 37(e) applies to electronically stored information “that should have been preserved in the anticipation or conduct of litigation”; the 2015 committee note states that the rule rests on the common-law duty recognized by many decisions holding that potential litigants must preserve relevant information when litigation is reasonably foreseeable.

What does a whistleblower report legally obligate a listed company to do?

It obligates the audit committee to run the complaint through procedures it was already required to have. Section 301 of the Sarbanes-Oxley Act of 2002 added Section 10A(m) to the Securities Exchange Act, codified at 15 U.S.C. § 78j-1(m), and paragraph (m)(4) requires each audit committee to establish procedures for “the receipt, retention, and treatment of complaints received by the issuer regarding accounting, internal accounting controls, or auditing matters” and for “the confidential, anonymous submission by employees of the issuer of concerns regarding questionable accounting or auditing matters.” Exchange Act Rule 10A-3, 17 CFR 240.10A-3(b)(3), carries the same two requirements in the Commission’s own words.

The enforcement mechanism is unusual and shapes how the duty behaves. Rule 10A-3(a) directs national securities exchanges and associations to prohibit the initial or continued listing of a security of an issuer that does not comply, with a reasonable opportunity to cure first. The obligation therefore runs to the issuer’s listing rather than to any individual complainant, and Rule 10A-3(c) exempts several categories, including certain foreign private issuers with a home-country board of auditors, asset-backed issuers, and some subsidiaries of compliant parents. A privately held company is outside all of it; whatever its hotline policy promises, the source of that promise is the policy.

Does the company have to investigate the allegation?

Section 301 and Rule 10A-3 do not say so, and reading them as if they did is the most common error in this area. Both require procedures for the receipt, retention and treatment of complaints. Neither defines treatment, sets a timetable, requires an outside investigator, or specifies what the audit committee must conclude. The requirement is that the machinery exist and that anonymous submission be possible.

What converts that into an investigation is usually something else in the file: a company policy the board adopted and can be measured against, a fiduciary duty question under state law, an auditor’s own obligations, or the simple fact that an unexamined allegation tends to be the first exhibit later. For audits of Securities and Exchange Commission issuers, Section 10A(b) of the Exchange Act, 15 U.S.C. § 78j-1(b), sets a separate statutory escalation chain when the auditor detects information indicating a possible illegal act, which is why a complaint routed to the auditor rather than to the hotline behaves differently. The Institute’s Why didn’t our auditors catch the fraud? sets out that chain, and Detection & the Auditor’s Duty maps the standards around it.

What protects the employee who made the report?

Section 806 of the Sarbanes-Oxley Act, codified at 18 U.S.C. § 1514A, which is the provision that reaches purely internal reporting. It prohibits a covered employer — a company with a class of securities registered under Section 12 of the Securities Exchange Act of 1934 or required to file reports under Section 15(d), any subsidiary or affiliate whose financial information is included in its consolidated financial statements, and nationally recognized statistical rating organizations, along with their officers, employees, contractors, subcontractors and agents — from discharging, demoting, suspending, threatening, harassing or in any other manner discriminating against an employee in the terms and conditions of employment because of protected activity. Protected activity includes providing information about conduct the employee reasonably believes violates 18 U.S.C. § 1341, § 1343, § 1344 or § 1348, any rule or regulation of the Securities and Exchange Commission, or any provision of Federal law relating to fraud against shareholders, where that information goes to a Federal regulatory or law enforcement agency, to any Member of Congress or any committee of Congress, or to a person with supervisory authority over the employee.

The procedure is administrative first. Under § 1514A(b)(1) the employee files with the Secretary of Labor and may bring an action in federal district court for de novo review if there is no final decision within 180 days; § 1514A(b)(2)(D) requires the complaint to be filed not later than 180 days after the violation occurs or after the employee became aware of it. Remedies under § 1514A(c) include reinstatement with the same seniority status, back pay with interest, and compensation for special damages including attorney fees and expert witness costs. The short administrative clock is the detail most often missed on both sides of a matter.

What did Murray v. UBS Securities change about proving retaliation?

It removed a requirement the Second Circuit had added. In Murray v. UBS Securities, LLC, 601 U.S. 23 (2024), decided 8 February 2024, Justice Sotomayor wrote for a unanimous Court that a whistleblower who invokes § 1514A “bears the burden to prove that his protected activity ‘was a contributing factor in the unfavorable personnel action alleged in the complaint’ . . . but he is not required to make some further showing that his employer acted with ‘retaliatory intent.’” Trevor Murray was a UBS research strategist required by Securities and Exchange Commission regulation to certify that his reports were produced independently; he reported to his supervisor that trading desk leaders were pressuring him to skew them, and was fired. The Second Circuit had vacated his jury verdict on the ground that retaliatory intent is an element of the claim.

The Court’s reasoning turned on the burden-shifting framework Sarbanes-Oxley borrowed. Section 1514A(b)(2)(C) imports the burdens of proof in 49 U.S.C. § 42121(b), under which the employee must show the protected activity was “a contributing factor in the unfavorable personnel action alleged in the complaint” and the burden then shifts to the employer to show “by clear and convincing evidence” that it “would have taken the same unfavorable personnel action in the absence of” that activity. Animus is one way to prove contribution, the Court said, but not the only way, and the employer’s clear-and-convincing defense is what protects legitimate decisions. The standard was Congress’s choice, and the Court said it “cannot override that policy choice by giving employers more protection than the statute itself provides.”

Does Dodd-Frank protect someone who reported only inside the company?

No. In Digital Realty Trust, Inc. v. Somers, 583 U.S. 149 (2018), decided 21 February 2018, Justice Ginsburg, writing for a Court unanimous in the judgment, framed the question as whether the provision reaches an individual who has not reported a violation of the securities laws to the Securities and Exchange Commission, and answered it directly: “We answer that question ‘No’: To sue under Dodd-Frank’s anti-retaliation provision, a person must first ‘provid[e] . . . information relating to a violation of the securities laws to the Commission.’” The definition controls: 15 U.S.C. § 78u-6(a)(6) defines a whistleblower as an individual who provides “information relating to a violation of the securities laws to the Commission, in a manner established, by rule or regulation, by the Commission.” The Commission conformed its rule afterward — 17 CFR 240.21F-2(a)(1), as amended at 85 FR 75942 (5 November 2020), makes a person a whistleblower as of the time he provides the Commission with information in writing, and 21F-2(d)(1) requires that status to exist before the retaliation for which redress is sought.

The practical consequence is that the two regimes differ in what they offer and demand. Section 806 requires administrative exhaustion and a 180-day filing; Section 21F lets a whistleblower sue an employer directly in federal district court, 15 U.S.C. § 78u-6(h)(1)(B)(i), not more than six years after the violation or three years after the date when facts material to the right of action were known or reasonably should have been known, and in no circumstance more than ten years after the violation, § 78u-6(h)(1)(B)(iii), with relief that “shall include” “2 times the amount of back pay otherwise owed to the individual, with interest,” § 78u-6(h)(1)(C)(ii). Two further points sit alongside them. Rule 21F-2(d)(3) states that retaliation protection does not depend on satisfying the award procedures. And 17 CFR 240.21F-17(a) provides that “[n]o person may take any action to impede an individual from communicating directly with the Commission staff about a possible securities law violation, including enforcing, or threatening to enforce, a confidentiality agreement” — which is why severance and internal investigation paperwork drafted after a report is itself a recurring enforcement subject.

What has to be preserved once a report has been made?

Whatever the company should have preserved in the anticipation or conduct of litigation, measured from the point litigation became reasonably foreseeable rather than from the point a case was filed. Federal Rule of Civil Procedure 37(e) applies where electronically stored information “that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it,” and it cannot be restored or replaced through additional discovery. On a finding of prejudice a court may order measures no greater than necessary to cure it; only on a finding that the party “acted with the intent to deprive another party of the information’s use in the litigation” may it presume the lost information was unfavorable, so instruct the jury, dismiss the action or enter default. The 2015 committee note is explicit that the rule rests on the common-law duty and “does not attempt to create a new duty to preserve,” and that courts should consider the extent to which a party was on notice that litigation was likely.

Two criminal statutes sit behind that. 18 U.S.C. § 1519, enacted by Section 802 of Sarbanes-Oxley, reaches whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies or makes a false entry in any record, document or tangible object with intent to impede, obstruct or influence the investigation or proper administration of any matter within the jurisdiction of a federal department or agency, or any case under title 11, “or in relation to or contemplation of any such matter or case,” and carries up to 20 years. 18 U.S.C. § 1520(a)(1) separately requires an accountant who audits an issuer to maintain all audit or review workpapers for five years from the end of the fiscal period in which the audit or review was concluded.

The records that decide these matters are rarely the ones anybody thinks to hold. Hotline intake logs, the human resources file, the mailbox of the person who received the complaint and the record of what was done with it usually sit on the shortest retention settings in the organization, and an ordinary offboarding or device-reissue cycle removes them without anyone deciding anything. Preserving before interviewing is the sequence that survives later scrutiny; Should our company hire the forensic accountant, or should our lawyers? covers who should be directing that work. Nothing here is legal advice, an opinion on whether any report is well founded, or a statement that fraud occurred in any matter. What a loss is worth, if one is established, belongs to our Economic Damages Institute rather than here.

For informational purposes only. Not legal advice, and not an opinion on whether fraud occurred or on the conduct of any person or organization.

Related

The practice area

forensic conciergeorientation · not a finding of fraud
Happy to. Tell me what surfaced, how it surfaced, and roughly when. If it is recent, the traceable claim is already shrinking, so that is worth establishing first.