Seven days to acknowledgement Three months to response Reporting without giving your name

Custom app for an internal whistleblowing procedure

A whistleblowing policy that exists only on paper is worse than none: it creates the expectation that something will happen with a report. The law sets deadlines for this. An acknowledgement within seven days and a substantive response within three months at most are not aspirations but obligations, and the clock starts from the moment the report is made.

What the law requires of the channel

Employers with at least fifty employees must have an internal reporting procedure that meets the requirements of the Dutch Whistleblower Protection Act. Some employers with fewer staff are also covered, for example in the financial sector. The procedure describes how a report is handled and who a person can turn to, and there must be contact points with an independent officer.

Two deadlines apply to handling. An acknowledgement of receipt within seven days, and a substantive response within a reasonable period of three months at most. The first is short enough to be missed when a report lands in a shared mailbox and the handler is on holiday. This is not a theoretical risk: it is exactly how most deadlines get overrun.

In addition, you must record all reports in a dedicated register. That register is also the most sensitive file you hold, because it contains suspicions about colleagues and the identity of whoever reported. It must therefore exist, be complete, and at the same time be tightly protected. Meeting all three requirements at once with a mailbox and a folder doesn't work.

How we build this

Confidentiality and deadline monitoring pull against each other. If you want to protect the reporter, you cannot let the handling run through a mailbox; if you want to meet the deadline, you cannot either.

1
Separating the channel from everyday systems

A report does not belong in a shared mailbox, a ticketing system, or a personnel file. Anyone with access to one should not automatically have access to the other.

2
Making anonymous reporting possible while still being able to respond

A reporter who does not want to give their name must still be able to receive an answer. That requires a conversation channel without identity attached, and that is a design decision, not a setting.

3
Running deadlines from the moment of reporting

The seven days and the three months start when the report is made, not when someone reads it. That clock belongs in the system.

4
Populating the register properly from the outset

Every report goes in, including reports that turn out to show no wrongdoing. Adding them afterwards isn't possible, because you would then miss precisely the reports that were dismissed without being registered.

What the app does in practice

The reporting channel with deadline monitoring underpins the whole arrangement. What else you include depends on your size and on who handles the reports.

Reporting with or without a name

The reporter chooses. For anonymous reports, a conversation channel stays open without the identity becoming known, because otherwise anonymous reporting is a dead end.

Seven days and three months monitored

Both deadlines run from the moment of reporting and are tracked visibly, with a signal before they expire rather than after.

Handling with a visible status

The reporter can see which stage their report is at, without substantive details. Silence is the main reason people report externally.

The mandatory register populated automatically

Every report is recorded, with its date, nature and how it was handled. A register compiled afterwards will, by definition, miss reports that were resolved informally.

Points of contact and external confidential adviser

The law requires points of contact with an independent officer. That officer can be an external party, who then has access only to their own reports.

Everything recorded, including who looked

When a report concerns a line manager, who has viewed the file is just as relevant as the report itself.

Who we build for

The setup depends on your size and on who handles the reports. Four situations.

Organisations with 50 or more employees

This is where the obligation begins. The pitfall is a scheme that has been adopted but whose channel is a mailbox nobody monitors. The training around it is covered under integrity training.

Healthcare and education

Large organisations with multiple locations and a sensitive relationship between reporter and line manager. Access separation matters most here.

Organisations with a public duty

Alongside the law, there are often their own integrity frameworks and sometimes an external supervisory body. That calls for a register that can serve several frameworks at once, through integrations with your existing systems.

External confidential advisers and lawyers

You act for several employers. Strict separation per client is then not a luxury but the core of your position. For the surrounding quality documentation, there is a quality management system.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and integrations

Deadlines, categories and points of contact differ between organisations and change over time. All of this should be configurable and not hard-coded into the app.

React Native or native iOS and Android, with a web channel Reporting with or without identity Conversation channel for anonymous reports Deadline monitoring from the moment of reporting Status information for the reporter Reports register with categories Access strictly separated from HR systems External confidential adviser with own access Full access logging Retention periods with deletion Configurable points of contact and routes Export for accountability without identity Audit logging Hosting in the EU

Why Appfront

Anonymous reporting must also allow for a reply

We build a reporting channel without identity. Reporting anonymously with no feedback is a suggestion box, not a procedure.

Seven days pass quickly

We start the clock from the moment of reporting and flag deadlines in advance. In a shared mailbox, meeting that deadline is a matter of luck.

The channel should be kept separate

We keep this apart from your HR and ticketing systems. Anyone with access to personnel files should not automatically be able to access reports.

Silence drives people outside

We show the reporter the status of their case without disclosing its content. That is the cheapest way to prevent an external report.

Security and privacy

This is probably the most sensitive file in your organisation: it contains suspicions about individuals and the identity of those who reported. We grant access exclusively to designated handlers, keep it strictly separate from HR and ticketing systems, and log every access, including refused attempts. For a report about a line manager, that person must demonstrably have had no access.

For anonymity, technology and policy need to work together. When an anonymous report comes in, we do not store any identifying data, and we build the communication channel so that feedback remains possible without tracing the reporter. Retention periods are set and destruction moments are carried out, because a register that keeps everything forever is itself a risk. How we handle security ourselves is described in our information security policy; reports from outside come through our vulnerability disclosure policy.

Frequently asked questions about the internal reporting scheme

Employers with at least fifty employees must have an internal reporting procedure that meets the requirements of the Dutch Whistleblowers Protection Act (Wet bescherming klokkenluiders). Some employers with fewer employees are also bound by this obligation, for example in the financial sector. Have a lawyer check your own position, as the way employees are counted follows its own rules.

An acknowledgement of receipt within seven days of the report, and a substantive response within a reasonable period of no more than three months. Both run from the moment the report is made, not from the moment someone picks it up. That distinction is where most overruns occur.

The law does not require anonymous reporting in every case, but in practice it is the only way some wrongdoing comes to light. Whoever offers it must do it properly: an anonymous report without a feedback channel is a black hole. Have your scheme legally reviewed on this point.

All reports of suspected wrongdoing, held in a dedicated register. That includes reports that turn out, after investigation, to show no wrongdoing. In practice, these are often dismissed informally and never recorded, and that gap is what stands out in an inspection.

We advise against it. A ticketing system is designed to distribute and make work visible, which is precisely the opposite of what is needed here. Access to reports should be strictly limited and fully logged, and that is difficult to enforce reliably in a shared system.

An incident reporting portal deals with reports to a regulator within a short timeframe, such as in the case of a calamity or a data breach. This page is about reports by employees of suspected wrongdoing within their own organisation, with protection of the reporter at its core.

Yes, and this is often sensible. The law requires contact points with an independent officer; this could be an integrity officer, a lawyer or an independent third party. We give that person their own access to their own reports only, separate from your internal handlers.

That depends on your size, whether there are multiple sites or entities, and whether an external confidential adviser is involved. The reporting channel with deadline tracking and the register is usually quick to put into use and covers the core of the obligation; investigation files and reporting follow afterwards. We will give you a reasoned estimate after the discovery phase.

Want to know whether your channel actually works?

Send a test report yourself to your own reporting channel and see how many days it takes before you receive an acknowledgement. If it takes longer than seven days, your scheme does not currently comply. We build this as a standalone app and as part of a wider custom app development project.

If you manage the scheme across multiple entities yourself, look at software for managing your internal reporting scheme.

Edit content