Buyer guide

What should a reporting program actually do?

A form can collect a concern. The program also needs a trusted way to receive it, a person responsible for follow-up, access appropriate to the case, and a record of what happened.

01 / The workflow

Follow the report past the submit button.

Ask who can receive the report, how a conflict is handled, who may open the case and its attachments, when the reporter hears back, and how the organization records its decisions. Test those paths with a sensitive example involving someone in the reporting chain.

Ask the vendor to show a complete sample: intake, acknowledgement, two-way follow-up, assignment, investigation steps, and closure. Confirm which capabilities are available in the plan you are buying.

02 / Questions to take into a demo

01

Who can see the case?

Test access to the queue, detail, search results, messages, and attachments. Include a case involving an investigator or senior leader.

02

Can the reporter return?

Check how a reporter receives questions and updates without having to disclose a name.

03

What happens on time?

Identify the people responsible for acknowledgement, follow-up, escalation, and overdue work.

04

What can you prove later?

Look for a reviewable record of access, actions, evidence, decisions, and closure.

03 / United States

Start with the issue and the organization.

There is no single U.S. rule for every reporting program. Requirements vary by sector, state, and type of concern. For workplace harassment, the EEOC recommends a route outside the employee’s chain of command, confidentiality to the greatest possible extent, protection against retaliation, prompt impartial investigation, and corrective action when needed.

The U.S. Department of Justice’s compliance-program guidance asks how companies receive concerns, protect whistleblowers, route complaints, investigate them, and track results. Use these as review questions alongside the laws and policies that apply to your organization.

04 / European Union

Check the Directive and the local law.

For reports within its scope, Directive (EU) 2019/1937 calls for confidential internal channels, an impartial person or department to follow up, acknowledgement within seven days, and feedback within three months. It generally applies to private entities with 50 or more workers, with exceptions; Member States implement the Directive through national law.

Before selecting a system, identify the countries and entities involved, the local rules that apply, the required languages and channels, who will receive and investigate reports, and how records will be retained. Confirm those choices with local counsel.

See the current offer

Test the path with a real question.

NOW IMS currently offers anonymous web reporting, private-code follow-up, and a staff inbox for U.S. schools and workplaces. Bring your access, timing, and deployment requirements to a walkthrough; we will distinguish available controls from planned capabilities.

Request a walkthrough

This is a buyer checklist, not a statement that software alone establishes legal compliance. Requirements depend on the organization, jurisdiction, and report type.