Skip to content
All articlesCompliance PracticeField guide

How to Set Up a Speak-Up Channel for Compliance

A speak-up channel needs more than an inbox. Build intake, triage, case records, outcomes, and follow-up checks that hold up later.

TT
Truvara Team
October 7, 2026
10 min read

A speak-up channel is judged by what it leaves behind: a record per concern showing how it was received, how it was routed, how it was decided, and what happened to the person who raised it. The channel itself is the easy part.

A channel is a record, not a mailbox

A speak-up channel earns the name when it produces a file per concern: who raised it, what happened next, and who decided.

A form or a shared inbox is intake. Intake matters, but it is the smallest piece of the work. The channel is the record that survives the conversation, and that record is what a reviewer, a board member, or a nervous employee asks about months later.

The compliance lead owns that record. Not the person who raised the concern, not the manager whose team was named, and not the tool that captured the form. Ownership is what makes a channel answerable when someone asks why a case ended the way it did.

Concerns arrive in every shape. Some name a person. Some describe a pattern that has built up over months. Some are one sentence with no detail at all. The record holds all of them to the same standard, while keeping the detail away from people who have no reason to see it.

Intake has to capture what triage will need

Intake captures the concern, when it arrived, how it came in, and whether the reporter can be contacted again. Missing fields cost a second conversation later.

Intake is where a channel gains or loses its ability to investigate. A form that stores free text and little else gives triage nothing to sort on: no category, no indication of whether the concern touches a manager, a customer, or a process where failure carries a heavier consequence.

Intake fieldWhat it holdsWhy triage needs it
Reporter pathNamed, confidential, or anonymousSets what can be asked later
Concern summaryThe concern in the reporter's own wordsAnchors every note that follows
Issue typeThe kind of problem describedRoutes it to the right owner
Named people and teamsWho or what the concern touchesStarts the conflict screen
Contact preferenceWhether follow-up is possibleDecides which questions can be asked

A field left empty is not neutral. It is a question someone will need answered once the case is moving, and by then the reporter may have gone quiet.

Triage decides who sees the concern

Triage screens the people named in the concern, routes it to an owner who is clear of that conflict, and records the routing decision with a name attached.

Sequence matters more than speed. A concern about a manager cannot be handled by that manager's own team, and a concern about a process needs someone who understands the process. The conflict screen runs before routing, because a conflict discovered after the investigation starts costs the whole piece of work.

Triage stepOwnerWhat the record shows
Intake reviewCompliance leadThe concern arrived and was read
Conflict screenCompliance leadWho is excluded, and the reason
RoutingCompliance leadWhich owner takes the case
HandoverCase ownerThe case has a name against it

Triage also sets the clock in the reporter's mind. Someone who raised a concern and heard nothing for a month will not raise the next one, whatever the policy says. The record cannot fix silence, but it can show whether the handover happened and when.

The case log is the evidence

The case log holds one entry per concern: the intake record, the triage decision, the actions taken, the outcome, and the name behind the outcome.

This is the file that carries the case forward. The shape of a case log is the program's own choice, but the record cannot be thin. A list of dates with no outcome tells a reader that something happened and nothing was concluded.

Log fieldWhat it carriesWhy it matters later
Case referenceThe link between the log and the underlying filePoints a reader at the source
OutcomeSubstantiated, unsubstantiated, or not pursued, with the reasonAnswers what the case concluded
Decision ownerThe person accountable for the outcomeAnswers who decided
Actions takenWhat the team did, in orderShows the case moved
Closure noteWhy the case stoppedAnswers why it ended there

An outcome without a reason is an opinion. The standard for the closing note, and for the log entry around it, is the standard a working paper meets: a document a stranger can read without being walked through it. Audit working papers apply that test to a whole file, and the same test fits a single case.

Non-retaliation record is its own record

Proving that raising a concern carried no penalty takes a deliberate check: what changed for the reporter after the case, recorded beside the outcome.

This is the part channels skip. The case closes, the reporter returns to work, and nobody looks at what happened to them next. When the answer turns out to be a reassignment, a project quietly taken away, or a review comment that traces back to the case, the channel loses the trust it runs on.

A non-retaliation check is a look at the reporter's treatment after closure: their role, their access, their assignments, and their standing with the manager who decides those things. The person who runs the check is not the person named in the concern. The result goes into the record whether or not anything changed.

The record needs the empty result as much as the event. An entry that says the reporter's role and access were unchanged is the record. A blank space is an assumption, and an assumption leaves the next reader without a clear answer.

Anonymity limits what the record can hold

An anonymous report changes the follow-up path, not the case. The concern still gets triaged and decided; the log notes that no clarification is possible.

Anonymity is a promise about the reporter, not about the case. The concern still needs an owner and an outcome. What disappears is the follow-up conversation, the confirmation that someone read it, and any later check on how the reporter was treated. That gap belongs in the log, stated plainly, so a reader knows why certain steps are missing instead of assuming they were skipped.

Confidentiality sits between a named report and an anonymous one. The compliance lead knows who raised it and the case owner does not, so the record has to split what the case owner needs from what identifies the reporter. That split is a decision made at intake. Trying to separate the two afterwards is where a channel leaks an identity.

Escalation needs a second name, not a committee

An escalation path names who takes a concern when the first owner cannot handle it, and that name sits in the record before the case ever needs it.

Escalation failures can be quiet. A case sits with an owner on leave. An owner turns out to be named in a later concern about the same area. The file stops moving and nobody notices for a fortnight. A second name, agreed in advance and recorded with the case, is what keeps a stalled case visible.

The escalation owner needs what the first owner has: enough of the file to decide, and a record of the decision. An escalation that happens in a corridor and leaves no note puts the case back where it started.

Read the channel as a program signal

The case log, read as a whole, shows where concerns cluster: which parts of the business raise issues, and which parts stay silent.

A channel that produces nothing is not a healthy one. It is an unmeasured one, or a channel nobody trusts. The pattern matters more than the count. Concerns clustering in a single team point at something local. Concerns that arrive only from one function, with silence everywhere else, suggest the channel is not reaching the rest of the business. Neither reading shows anything on its own. Together they tell leadership where to look next.

Close the note as carefully as the case

Every case closes with a short note that states the outcome, the decision owner, and the reason, so the next reader does not have to reconstruct the file.

A closing note turns a case into a record someone else can use. It is also where a program shows its own consistency: the note for a substantiated concern and the note for one that was not pursued belong to the same standard, or the log starts to look like it only documents the wins.

The closing note is where culture shows up as well. A program that documents the cases it took seriously and waves through the rest teaches the business which concerns are worth raising. Compliance culture versus checkbox compliance makes the same point at the program level: what the record rewards is what people repeat.

Evidence that the channel worked

The case log and the non-retaliation checks are the two records that show a channel functioned, and neither is worth much if the other is missing.

Audit trail requirements rest on the same principle in a different register: a system that records what happened is easier to review than one that only preserves its final state. A case log with every action in it, plus a check on the reporter afterwards, gives a reviewer a chain instead of a conclusion.

The same discipline keeps an assurance program repeatable. A program that can produce both records on request has something some policies only promise: record that raising a concern was safe. That record is what leadership, customers, and employees are asking for when they ask whether a speak-up channel works.

FAQ

Who owns the case log?

The compliance lead. The owner of the log can be different from the owner of any single case, and that separation is intentional: the lead sees the whole record, while each case owner sees only what they need to decide. When someone asks how the channel performed, the answer comes from the log owner.

Can a channel work without anonymity?

Yes, and confidential reporting covers some of the ground. Confidential means the compliance lead knows who raised the concern and the case owner does not. Anonymous reporting is the fallback for cases where a name would stop the concern being raised at all, and it carries a cost: no follow-up and no way to check on the reporter afterwards.

What does a non-retaliation check actually look at?

What changed for the reporter after the case closed: their role, their access, their assignments, and how the manager who decides those things treats them. The check runs after closure and its result goes into the record whether or not anything moved. The person who runs it is not someone named in the concern.

What if the person named in the concern would normally own the investigation?

The escalation path handles it. A second owner is named in advance for exactly this situation, takes the file, and records the decision. The record then shows the original routing and the escalation without relying on memory.

How long should a case stay open?

Until the outcome and the reason are both in the log. Time is a poor measure on its own: a case can sit for months with nothing happening, and it can close quickly with the reason missing. The better question is whether the file explains why it stopped where it did.

Where CASK fits

Speak-up work is a case file that has to hold up months later, when the details are gone and only the record remains. CASK by Truvara keeps intake, triage, outcome, and the non-retaliation check beside each case in a local-first workspace, so the log reads as one continuous file instead of fragments scattered across a mailbox. Teams draft the case note, attach the evidence behind it, and route the decision for a named approval. CASK does not investigate concerns, does not decide outcomes, and does not replace the judgment of the people who own the case. That stays with your team, and the workspace shows who decided what. Try CASK now and see how a case log reads when every entry carries its own reason.

TT

Truvara Team

Truvara.ai