ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / UNCATEGORIZED
2 AUG 2026 · 17 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: UNCATEGORIZED
DOCKET NO. 754 · THE DEFENSE DESK

How Companies Can Protect Against Whistleblower Claims.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

According to the SEC’s whistleblower page, most SEC whistleblowers reportedly raise their concerns internally before approaching the SEC. Thus, one of the most effective ways companies can prevent whistleblower claims is by implementing a whistleblower program that makes it possible for employees to raise their concerns internally, and that ensures the concerns they raise are addressed before regulators get involved. Key elements of an effective whistleblower program include:

  • Accountable governance. As with all corporate compliance programs, whistleblower programs must be overseen by the company’s senior management or a group of independent directors.
  • Accessibility. Reporting channels must be readily accessible to all employees. Importantly, these channels must remain accessible even when the employees do not believe they can go to their immediate manager with their concerns.
  • Independent investigations. Companies must conduct prompt and thorough investigations in response to whistleblower reports. This includes preserving all relevant evidence, utilizing an independent internal (and/or external) investigation team, and promptly remediating any employee’s concerns that are validated during the investigation.
  • Rigorous retaliation safeguards. Because whistleblower retaliation claims are a common secondary effect of reporting whistleblower concerns to the SEC, companies must implement rigorous safeguards designed to prevent retaliation. For example, after an employee raises concerns internally, any employment decisions affecting that employee should receive independent review and approval before implementation.

Q: What is the SEC Whistleblower Program?

The SEC Whistleblower Program was created by Section 922 of the Dodd-Frank Wall Street Reform and Consumer Protection Act. Unlike several other federal whistleblower statutes, Section 922 does not allow whistleblowers to file private enforcement lawsuits in federal court. Instead, it requires potential whistleblowers to submit a Tip, Complaint or Referral (TCR) form. Whistleblowers are eligible for monetary awards only if they (i) voluntarily provide the SEC with information about a violation of federal securities laws, and (ii) such information is provided as a result of the individual’s independent knowledge or analysis.

Q: Who should oversee a company whistleblower reporting program?

With regard to oversight, the employees or consultants hired to oversee a company’s whistleblower reporting program should be named. This should include (i) personnel responsible for complaint intake; (ii) personnel responsible for conducting investigations; (iii) personnel responsible for implementing remediation; and, (iv) personnel responsible for maintaining compliance records. This is a key element of the U.S. Department of Justice (DOJ) Evaluation of Corporate Compliance Programs. Additionally, as discussed below, Section 10A(m)(4) of the Securities Exchange Act requires issuers’ audit committees to establish procedures for handling employee complaints relating to accounting and auditing matters.

Q: Does Section 10A(m)(4) of the Securities Exchange Act impose any whistleblower-related obligations on audit committees?

Yes, Section 10A(m)(4) requires audit committees to establish procedures for accepting and handling employee complaints regarding “questionable accounting or auditing matters.” Section 10A(m)(4) specifies that companies’ procedures must ensure that “employees are able to submit concerns to the issuer’s audit committee confidentially and anonymously.” This provision imposes a compliance obligation on the audit committee for the SEC’s enforcement purposes.

In addition to this obligation imposed by Section 10A(m)(4), audit committees (and issuers’ other governing bodies) will need to have procedures in place to ensure that whistleblowers can reach the right people in all cases. This includes, but is not limited to, ensuring that:

  • Allegations against senior executives are routed directly to independent directors without bypassing the chain of command;
  • Allegations that indicate a systemic compliance failure that warrants higher-level attention are routed to the company’s board or an appropriate board committee (as the case may warrant); and,
  • Potential whistleblowers are able to report their concerns outside their chain of management if they believe that going to their managers with their concerns would interfere with a company’s ability to act upon or address the concerns.

This includes not only ensuring that whistleblowers can submit complaints through multiple channels. While this is important, it is not sufficient. Companies must also ensure that these channels are:

  • Fully accessible to all employees, contractors, and third parties;
  • Readily accessible, in that these channels are open 24/7 and provide employees with a means for reporting their concerns in all languages that may be spoken by relevant employees (i.e., English speaking employees must be able to speak English with anyone, and Spanish speaking employees must be able to speak Spanish with anyone);
  • Functioning (i.e., hotline abandonment rates should be low); and,
  • Known to all employees who need to be aware of the channels’ existence.

Q: Can external auditors become SEC whistleblowers?

Under Sarbanes-Oxley (SOX) Section 301, audit professionals who are (i) in consultation with their firm’s appropriate authority (typically the firm’s board or an audit committee, as appropriate) are able to become SEC whistleblowers if they independently determine that, (ii) they have substantial evidence that the issuer has failed to take appropriate remedial action following the employee’s internal report. In this situation, if they have evidence that the company failed to take appropriate remedial action, auditors can report their concerns to the SEC, and they will be eligible for whistleblower awards as well.

  • Audit professionals must generally give issuers 120 days to take appropriate remedial action before they can become SEC whistleblowers;
  • Audit professionals are eligible to become SEC whistleblowers more quickly if there is reasonable basis to believe that, (i) an issuer’s auditors’ failure to take appropriate remedial action would lead to substantial investor injury in the event that the auditors did not report their concerns to the SEC; or, (ii) an issuer’s auditors’ failure to take appropriate remedial action would lead to substantial investor injury in the event that the auditors failed to report the suspected violation to the SEC.
  • To become a SEC whistleblower, audit professionals must have independently determined that (i) they have substantial evidence that an issuer has failed to take appropriate remedial action; or, (ii) an issuer’s audit professional or appropriate authority has committed an appropriate action that is substantially improper.

How should companies investigate complaints and preserve evidence?

Q: What should be included in a company’s complaint intake records?

A company’s complaint intake records should include information that allows a subsequent auditor to determine if the complaint allegations were adequately addressed by the company’s internal investigation. This information includes: (i) the allegations; (ii) the implicated personnel; (iii) potential conflicts, if any, that warrant an independent internal or external investigation team; (iv) any decisions to escalate the complaint to the appropriate level of management or the board of directors; (v) evidence indicating the company’s receipt of the complaint; (vi) the date of receipt of the complaint; (vii) any internal routing of the complaint; and, (viii) any decisions to delegate handling of the complaint to any person (i.e. the general counsel, internal investigators, and/or external investigators).

Q: How does management compromise the independence of a company’s internal investigation?

A company’s internal investigation can be compromised if the accused manager:

  • Selects the internal investigator (or investigators) that will be responsible for the investigation;
  • Supervises the investigator (or investigators) that will be responsible for the investigation;
  • Vetoes investigators; or,
  • Determines who the final investigative findings will be reported to.

This is true in all cases. For example, if an employee believes his or her manager has retaliated against them for reporting certain concerns internally, the manager should not oversee the company’s investigation into the employee’s retaliation claim.

Q: Who will determine the findings of a company’s internal investigation?

If a company’s internal investigators are independent in that they are not selected, supervised, or reviewed by the manager (or managers) whose actions are the subject of an employee’s whistleblower report (or reports), then the investigators’ findings should be reported outside the accused manager’s (or managers’) chain of command to ensure they are not reviewable by, or subject to veto by, those managers.

Ultimately, the investigator’s (or investigators’) findings may have implications for the company’s reputation and its ability to maintain an effective internal compliance program. As a result, the investigator’s findings should go to:

  • The legal department (such as the in-house counsel) if appropriate;
  • The appropriate internal or external compliance team if appropriate;
  • Appropriate members of senior management;
  • The general counsel;
  • The appropriate member(s) of the company’s board or a board committee; or,
  • Other personnel whose role in the company make it appropriate to be provided with investigative findings.

The appropriate recipients of an investigation’s findings will vary based on the context of the investigation.

Q: When must companies preserve evidence?

When litigation becomes reasonably foreseeable, companies must take steps to preserve evidence. With respect to whistleblower complaints, companies must take steps to preserve evidence when there is reason to believe that a whistleblower complaint will result in the investigation of a whistleblower complaint by the SEC or in a lawsuit that may be filed by the whistleblower or potentially by the government. This includes:

  • Preserving all relevant email, text messages, and other messages;
  • Preserving all hotline files, if any;
  • Preserving personnel files if they contain, or should contain, relevant information;
  • Preserving hard copies of documents (if any);
  • Preserving digital documents and metadata;
  • Halting automated deletion of electronic records; and,
  • Establishing an appropriate litigation hold.

When implementing an appropriate litigation hold, companies should ensure that they stop the routine destruction of all electronic information that should have been subject to the litigation hold. This includes hard drives and cloud servers, as well as other information sources.

Q: What is an investigation’s effectiveness metric for a company’s internal investigation?

Similar to employee accessibility for its internal reporting mechanisms, the effectiveness of a company’s internal investigation process can be measured by these metrics:

  • Average case age, in days;
  • Average time to close a whistleblower case, in days;
  • Average percentage of whistleblower cases that are substantiation;
  • Percentage of whistleblower cases closed with remediation in the case of substantiation;
  • Percentage of whistleblower cases closed with or without further action when not substantiated; and,
  • Timely closure of whistleblower cases with and without remediation.

Q: What should be included in a company’s investigation file?

A company’s investigation file should include information that allows a subsequent auditor to determine if the complaint allegations were adequately addressed by the company’s internal investigators. Information that should be included in the company’s investigation file:

  • The scope of the investigation, if defined;
  • A listing of all evidence reviewed during the investigation;
  • Notes taken during the investigation;
  • The investigator’s (or investigators’) findings and conclusions regarding the complainant’s credibility, findings of fact, and legal analysis;
  • Information about the steps the company took to remediate if any information was substantiated;
  • Evidence of closure of the investigation, if applicable; and,
  • Information regarding the identity of the investigator (or investigators) and any conclusions drawn by the investigator (or investigators) that was determined by an external auditor who was involved in the investigation.

Todd Spodek is the managing partner of Spodek Law Group, a second generation criminal defense firm that has been practicing since 1976.

What should companies do after substantiating a complaint?

Q: What should a company do if a whistleblower makes internal reports to its compliance personnel before making a report to the SEC?

If a whistleblower makes internal reports to its compliance personnel before making a report to the SEC, the company’s compliance personnel can take the time to investigate the allegations, determine whether they are substantiated, and assess what it would take to resolve the issue. If the whistleblower is an audit professional who reports internally, the company will have 120 days to address the issue before the audit professional can become an SEC whistleblower and be eligible for an award. If the whistleblower is an internal audit professional, the relation-back period is 120 days unless there is a reasonable basis to believe that shorter time is warranted. This includes taking time to investigate, implement appropriate remediation, and evaluate whether self-reporting to the SEC is necessary. During this period, if the internal audit professional decides to communicate with the SEC’s staff, the internal audit professional’s disclosure will be deemed voluntary, and the internal audit professional will be eligible for an award from the SEC.

Q: To what extent can companies restrict what employees say to the SEC?

Companies cannot restrict what employees say to the SEC, and they cannot interfere with employees’ ability to speak to the SEC. SEC Rule 21F-17 prohibits anyone from taking action to impede an individual from communicating directly to the SEC staff about possible violations of federal securities laws. This rule explicitly includes “through employment agreements, confidentiality agreements, non-disclosure agreements, or other means.”

Q: Can companies enforce confidentiality agreements that include terms that restrict employees’ ability to make protected disclosures?

Yes, companies can enforce confidentiality agreements and similar non-disclosure agreements that include terms that restrict employees’ ability to make protected disclosures to the SEC, as long as the companies’ agreements do not impede employees from making protected whistleblower reports to the SEC. Companies can and should enforce their confidentiality agreements that protect the companies’ proprietary information, trade secrets, and other information that is protected under applicable law.

Q: What factors does the SEC consider when making enforcement decisions?

The SEC’s Seaboard Report provides the framework for making enforcement decisions. To avoid an enforcement action, companies should consider the following:

  • Self-policing;
  • Self-reporting;
  • Remediation;
  • Cooperation;
  • Prior issues;
  • Presence of independent directors on the company’s board; and,
  • Presence of external consultants.

Q: What steps should companies take to remediate internal control failures?

If a company has confirmed internal control failure, it should take all steps necessary to remediate the control failure. Remediation includes, but is not limited to:

  • Assigning a responsible person to oversee the remediation process;
  • Developing a comprehensive remediation plan;
  • Assigning a specific completion date for implementing the required controls;
  • Implementing controls that adequately address the issue;
  • Testing the newly implemented controls to ensure that they function as intended; and,
  • Testing and documenting compliance with the newly implemented controls.

Q: What are the requirements for SEC whistleblower awards?

Whistleblowers are eligible for an award from the SEC if the following are both true:

  • The SEC’s enforcement action results in monetary sanctions exceeding $1 million.
  • The information that the whistleblower provides to the SEC is qualifying information.

If the whistleblower is eligible for an award, the award amount will be between 10% and 30% of the amount of sanctions that the SEC collects.

Q: How can employers prevent retaliation against internal corporate whistleblowers?

Similar to preventing internal whistleblowers from reporting to the SEC, employers can prevent retaliation against internal corporate whistleblowers by:

  • Educating managers about internal corporate whistleblowers’ rights and protections;
  • Training managers to recognize internal corporate whistleblowers’ protected activity;
  • Encouraging managers to promptly escalate internal corporate whistleblower complaints;
  • Training managers to handle internal corporate whistleblower complaints properly;
  • Educating employees about the companies’ available remedies for retaliation;
  • Maintaining accurate personnel records that reflect each employee’s performance and any history of misconduct;
  • Maintaining contemporaneous performance records;
  • Ensuring the company takes a comprehensive approach to monitoring employees’ ability to make internal corporate whistleblower reports, protecting their rights, and responding to retaliation claims; and,
  • Ensuring that any steps the company takes are consistent with its policies, practices, and employee handbook.

These strategies apply both when a company has received an internal corporate whistleblower report and when a company is anticipating litigation based on a report that was already made to the SEC.

Q: Do internal corporate whistleblowers have retaliation protection under the Dodd-Frank Act?

No, Dodd-Frank’s retaliation protection only applies if the employee has reported a potential securities law violation to the SEC. Internal corporate whistleblowers who report to the company’s legal department do not get retaliation protection from Dodd-Frank until they report their concerns to the SEC.

Q: Do internal corporate whistleblowers have retaliation protection under the Sarbanes-Oxley Act?

Yes, internal corporate whistleblowers may have retaliation protection under the Sarbanes-Oxley Act, or “SOX”. SOX prohibits retaliation against employees for, “among other things,” qualifying internal whistleblowing reports. The most important qualification is that the reporting employee must reasonably believe that the company’s suspected violations of federal securities law are substantial.

Q: What types of activities are protected under SOX?

SOX protects all activities that are reasonably taken in:

  • “The employee’s capacity as an internal auditor or other auditor;”
  • “The employee’s capacity as an officer or employee of an issuer, as a potential officer or employee of an issuer, or as a contract employee of an issuer;”
  • “The employee’s capacity as an agent or consultant of an issuer, or as an agent or consultant of a client or customer of an auditor of an issuer who provided services related to any internal control over financial reporting;” and,
  • “The employee’s capacity as a client or customer of an issuer who provided services related to any internal control over financial reporting.”

If an internal corporate whistleblower is not protected under SOX, they may still have other forms of protection, including protection under state laws or tort law.

Q: What forms of employee adverse treatment count as retaliation under SOX?

Forms of adverse treatment that constitute retaliation under SOX include:

  • Termination, demotion, reassignment to a less desirable position, or any other change in employment status that reduces an employee’s income or benefits;
  • Harassment and discrimination; and,
  • Denial of overtime and other denial of pay.

This is true in all cases involving internal corporate whistleblowers, regardless of where their internal report ends up (or whether it ends up being forwarded to the SEC).

Q: How can companies avoid liability in SOX whistleblower retaliation claims?

To avoid liability in a SOX whistleblower retaliation claim, an employer must clearly and convincingly prove that it would have taken the same adverse action against the employee regardless of the employee’s internal whistleblower report. This includes maintaining documentation and records that substantiate the employer’s decision to terminate, demote, or reassign the employee regardless of the employee’s report.

Q: What happens if a whistleblower files a retaliation claim?

A whistleblower retaliation claim will have different implications depending on what statute the whistleblower is claiming retaliation under. For example, if an employee is claiming retaliation under the Sarbanes-Oxley Act (“SOX”), he or she will need to file a retaliation complaint with the U.S. Department of Labor (DOL) Office of Occupational Safety and Health Administration (OSHA) within 180 days of the time the employee became aware of the alleged retaliation. If the whistleblower is claiming retaliation under the Dodd-Frank Act (“Dodd-Frank”), he or she will need to file a retaliation complaint in federal district court.

If a whistleblower is able to establish that the company has retaliated against them, the company may be subject to the remedies provided under the whistleblower’s retaliation statute. For example, if a whistleblower files a retaliation complaint under Dodd-Frank, the remedies that the whistleblower may seek will include:

  • Reinstatement,
  • Double back pay,
  • Compensation for other similar financial losses,
  • Special damages (including litigation costs), and,
  • Attorney’s fees.

If a whistleblower files a retaliation complaint under SOX, the remedies will include:

  • Reinstatement,
  • Back pay with interest,
  • Special damages,
  • Litigation costs, and,
  • Attorney’s fees.

Whistleblowers can also file retaliation complaints under state law. In this scenario, the length of the statute of limitations, the standard for establishing causation, and the types of available remedies will all depend on the relevant state’s laws.

Q: What are the statute of limitation for whistleblower complaints under the Dodd-Frank Act?

The statute of limitations for whistleblower complaints filed under the Dodd-Frank Act will depend on which type of whistleblower complaint the whistleblower is filing. The statute of limitations for an anti-retaliation complaint under the Dodd-Frank Act is six years from the time of the alleged retaliation. If the employee did not know that they were experiencing retaliation, the statute of limitations will be three years from the date that they discovered they were retaliated against. If the retaliation occurred more than 10 years before the employee’s complaint was filed, the complaint is barred by the 10-year repose period.

Q: What are the statute of limitations for whistleblower complaints under the Sarbanes-Oxley Act?

The statute of limitation for whistleblower complaints filed under the Sarbanes-Oxley Act is generally one year from the time of the alleged violation, except that the retaliation statute of limitations for SOX is 180 days.

Q: Will a company’s employment practices liability insurance policy cover its defense costs for whistleblower retaliation claims?

Employment practices liability insurance policies are available for whistleblower retaliation claims. These policies cover the costs for defending these claims subject to certain terms and conditions. For example, an insurance policy may limit an insured’s ability to access its benefits to claims that arose from specified forms of retaliation. Insurance policies may also limit an insured’s ability to access its benefits to claims that arose from whistleblower complaints filed under specified whistleblower laws.

Q: How will defense costs be allocated among the insureds if more than one party is named in a lawsuit?

If more than one party is named in a lawsuit, the insurance policy will allocate defense costs between the covered and uncovered parties. If an insured is covered for an insurance claim, their attorneys’ fees will be covered under the policy. However, if an insured is not covered for an insurance claim, then their attorneys’ fees will not be covered.

Q: When can a company indemnify its officers and directors?

Companies can indemnify their officers and directors for civil liabilities that arise out of the officers’ and directors’ role with the company. The laws that govern indemnity vary depending on the company’s state of incorporation, and the company’s organizational documents (such as its bylaws). This includes indemnification for whistleblower retaliation claims if applicable.

Get Advice on Your Situation

If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.