As per Occupational Fraud 2024 report published by ACFE, tips were the most
common way frauds came to light, with 43% of cases being uncovered due to a tip
from a whistleblower. This is more than three times as many cases as any other
detection mechanism.
Before delving into the concept of whistleblowing and their protection, it is
essential to define who a whistleblower is. A whistleblower, whether an
individual or a group, is typically an insider with direct knowledge of fraud,
corruption, misconduct, or other unlawful activities occurring within an
organization.
These individuals, who are often current or former employees, vendors, or
affiliates, play a critical role in safeguarding the integrity of the
organization and the interests of its stakeholders. Their decision to report
such activities is often dependent on assurances that the information will be
handled appropriately, resulting in a comprehensive investigation and corrective
actions.
The protection of whistleblowers is crucial in fostering an environment where
individuals can report unethical behavior without fear of retaliation.
Employers, however, often view whistleblowers unfavorably, especially when their
actions may expose illegal or unethical practices. Retaliation against
whistleblowers can manifest in various forms, such as creating a hostile work
environment, demotion, or termination, which can have severe consequences for
the whistleblower's current and future employment opportunities.
Whistleblowing can have significant repercussions, including financial
difficulties and damage to one's professional reputation as well. Even if the
employer refrains from retaliating, the ongoing psychological strain may become
unbearable for the employee, ultimately compelling them to leave the company on
their own accord.
Interestingly, in a recent example, a whistleblower who played a crucial role in
exposing a major financial scandal, revealed a widespread fraud that shook the
corporate world. Despite facing personal risks and retaliation, his efforts
highlighted the importance of whistleblowers in uncovering corporate misconduct.
Inspired by his experience, he co-founded Confide with his former colleague. It
aims to help businesses detect and address misconduct early while protecting
reporting employees. Their software allows employees to file anonymous reports,
creating a secure paper trail accessible to both the whistleblower and the
accused company. These records are stored on third-party infrastructure to
prevent tampering. Confide significantly advances tools and protections for
whistleblowers, promoting a more transparent and accountable corporate culture.
Legal Framework and Challenges for Whistleblowers in India
In India, no specific laws protect whistleblowers in private, unlisted
companies, or unincorporated entities, allowing employers to create their own
policies. The Whistleblower Protection Act of 2014 primarily covers public
servants and public sector undertakings, with concerns about its enforcement and
effectiveness. Despite this, other following acts aim to protect and encourage
whistleblowers.
The Companies Act of 2013 requires a "vigil mechanism" for listed companies,
enabling reporting of wrongdoing. SEBI mandates whistleblower policies in listed
companies and has increased monetary incentives to ₹10 crores to combat insider
trading. Securities Exchange Board of India also proposes enhanced surveillance
at asset management companies (AMCs) due to numerous whistleblower complaints,
holding senior management accountable.
The Companies (Auditor's Report) Order of 2020 emphasizes financial transparency
and cooperation with auditors. Moreover, in 2024, the Competition Commission of
India introduced the "lesser penalty plus" regime, incentivizing whistleblowers
to report unknown cartels. Most recently, the Law Commission of India's 289th
report recommends legislation for trade secrets with strong whistleblower
protection, including a safe harbor clause for immunity from retaliation.
Whistleblowing policies in private entities are driven by internal policies.
Some ESG-compliant companies, particularly subsidiaries of multinational
corporations, have adopted global whistleblower policies.
The Role of Social Media and AI in Transforming Whistleblowing
Social media and digital platforms, along with artificial intelligence (AI),
have revolutionized whistleblowing by enhancing transparency, accessibility, and
impact. These advancements enable individuals to gather and share critical
evidence, such as digital documents, emails, and chat logs, more efficiently.
AI-powered tools further streamline the process by aiding in the collection,
analysis, and preservation of relevant information.
Moreover, social media amplifies the reach of whistleblowers, allowing them to
expose corporate misconduct to a global audience. Platforms like Twitter,
Facebook, and LinkedIn provide forums for sharing stories and evidence,
garnering public support and media attention.
For example, social media was effectively used to blow the whistle on insider
ethical breaches and financial misconduct within a prominent tax firm known for
discovering the 'Mauritius route.' The whistleblower leveraged various platforms
to reveal the firm's involvement in significant tax evasion and other unethical
practices, bringing these issues to public attention.
In recent years, AI and machine learning (ML) have further transformed the
whistleblowing landscape, making it more secure and efficient. These
technologies manage large datasets, ensuring confidentiality and focusing on
essential data, which is crucial for handling the vast amounts of information
involved in whistleblower cases.
The enforcement of artificial intelligence (AI) and the protection of
whistleblowers have become priority areas for both the Securities and Exchange
Commission (SEC) and the Department of Justice (DOJ). The SEC's long-standing
whistleblower program has led to numerous significant enforcement actions,
including the agency's first-ever AI fraud cases. The SEC has consistently
warned market participants about "AI washing" and its potential dangers.
Similarly, the DOJ launched its AI enforcement program in February 2024,
targeting crimes perpetrated through AI.
Furthermore, in March 2024, the DOJ introduced a new pilot whistleblower rewards
program, highlighting its commitment to integrating AI assessments into
corporate compliance evaluations and advocating for stiffer penalties for AI
misuse.
A primary benefit of AI is its ability to anonymize whistleblower reports.
AI-powered systems can intelligently remove or replace identifiers such as
names, locations, and dates with generic terms. This preserves the core
information of the report while protecting the whistleblower's privacy.
Natural Language Processing (NLP), a key component of AI, plays a significant
role in this anonymization process. NLP algorithms can understand and interpret
human language, distinguishing between essential information and details that
could reveal a whistleblower's identity.
AI also enhances the security of data transmission between whistleblowers and
authorities. Advanced technologies like encryption and blockchain, optimized by
AI, ensure data security. Encryption scrambles data, making it unreadable
without the decryption key, while blockchain provides a decentralized and
immutable ledger.
AI manages these systems, verifying data integrity and adding transparency.
Additionally, AI can autonomously adjust security parameters in real-time,
continuously analyzing the environment for new risks and updating security
measures accordingly.
Risks of AI in Whistleblower Protection
AI presents substantial risks, particularly for whistleblowers. Advanced
surveillance technologies enable organizations to monitor employees
comprehensively, complicating safe reporting of misconduct and increasing
retaliation risks. AI's ability to track activities, such as emails, keystrokes,
and video conferencing, can identify and silence whistleblowers, while the lack
of transparency in data practices exacerbates the issue. Sophisticated tracking
mechanisms make it difficult for whistleblowers to report through offline means,
like using personal devices.
Recent news from California highlighted these dangers through an open letter
from employees of Google DeepMind, Anthropic and OpenAI. They called for legal
protections and transparent practices within the industry, emphasizing the need
for AI-specific laws to protect those exposing potential AI risks.
These
employees underscored both the benefits and dangers of AI, advocating for
industry practices that facilitate more open discussion. Hence, this call for
action underscores the critical need to balance the benefits of AI with the
protection of individual rights and ethical standards in the industry.
Moreover, to ensure AI enhances whistleblower protection without compromising
safety, organizations can implement several measures. Firstly, transparency in
AI use is essential. Organizations should inform employees about the type of
data collected, how it is monitored, and its storage duration. This transparency
builds trust and makes employees aware of potential risks.
For example, a company using AI to monitor internal communications must clearly
communicate this to their staff, which can foster a more trusting environment
while ensuring employees understand the system's capabilities and limitations.
Furthermore, human oversight is crucial. Compliance personnel should work
alongside AI systems to ensure fair decisions and protect whistleblowers'
rights, as human judgment is necessary to interpret AI findings and take
appropriate actions. Regular audits and updates of AI systems are vital. These
audits help detect and correct biases, while continuous updates ensure that the
AI stays aligned with evolving ethical standards and improves its accuracy and
fairness over time.
While whistleblowers have proven essential in detecting corporate fraud and
misconduct, the effectiveness of their protection remains inconsistent,
particularly within the private sector in India. The advent of AI and social
media has significantly enhanced the capacity for whistleblowing by providing
tools for anonymous reporting and broad dissemination of information.
However, these technological advancements also introduce risks, such as
potential biases in AI systems and threats to whistleblower privacy. Thus, it is
critical to establish comprehensive legal protections, enforce transparent AI
practices, and maintain stringent human oversight to ensure that whistleblowers
can report unethical activities without fear of retaliation, thereby fostering a
culture of transparency and accountability in organizations.
Written By:
- Era Dahiya and
- Shrugal Borkar
Please Drop Your Comments