1. Map the context
Identify covered entities, audiences, languages, categories, responsible people and potential conflicts of interest.
2. Define the procedure
Define how triage, assignment, communication, investigation, decision-making, retention and reporting will be handled.
3. Configure the channel
Prepare identity, instructions, content, forms, users, permissions and follow-up mechanisms.
4. Test and communicate
Test the entire journey, train the responsible people and publicise the channel through the appropriate channels.
5. Review regularly
Review access, content, categories, response times and process effectiveness.
Governance and conflicts of interest
Implementation should state who administers the platform, who receives each reporting category and what happens when there is a conflict of interest. In corporate groups, central oversight can coexist with local responsible people provided that information separation and permissions are clearly documented.
Testing before production
Testing should cover anonymous and identified submissions, notification delivery, code-based access, message exchange, attachments, statuses, deadlines and unavailability scenarios. Privacy texts, contact details and the mobile experience should also be checked.
Review after launch
After launch, the organisation should review access, response times, categories, communication quality and channel usage. Periodic review makes it possible to remove unnecessary access, adjust instructions and identify difficulties before they become process failures.
Implementation and go-live checklist
Implementation should produce concrete decisions about people, process, technology and communication. A visually complete portal is not enough if there are no absence cover arrangements, escalation rules or criteria for protecting information.
Before going live, confirm and document:
- Covered entities, authorised audiences, languages and available reporting methods.
- Primary owners, substitutes and the handling of conflicts of interest.
- Categories, triage criteria, priorities and routing rules for each case.
- Privacy information, data minimisation and retention rules.
- Profiles, permissions, notifications and separation between companies or units.
- Tests for anonymous and identified reports, attachments, messages and access recovery.
- Training for responsible people and clear communication to potential reporters.
- Periodic review of access, response times, content and process effectiveness.
Legal notice
This content is for information purposes, does not constitute legal advice and should be reviewed in light of the legislation and guidance applicable at the time of use.
See how the platform organises the process.
See the reporter portal and the back office in a personalised demo.
Book a demo