Predicting misconduct before the hotline call

Ethics programmes are built around the hotline, so they learn about harm after someone was harmed enough to report it. The earlier signals, reporting decay, retaliation markers, third-party gaps, sit in data the function already owns.

2 min read

An ethics programme built around the hotline learns about harm after someone was harmed enough to report it. No amount of benchmarking fixes that.

The best benchmarks come from NAVEX, whose annual analysis draws on millions of reports across thousands of organisations. Its 2026 edition describes case volumes, report rates and closure times, with closure times notably lengthening, in authoritative detail. Every number describes something that already happened. A hotline report is filed after the harassment, after the fraud began, after conditions in a unit passed someone's tolerance.

The signals that arrive earlier

The predictive information exists, and most of it sits in data the ethics function already owns:

  • Speak-up decay. Healthy cultures produce a steady baseline of questions and minor reports; a team going quiet after a management change or a missed target is a timed signal, sitting in the hotline data itself.
  • Retaliation markers. What happened to the last three people who reported in that unit? Their ratings, transfers and exits, relative to peers, show up in HR data well before a retaliation claim is filed.
  • Case-pattern drift. More anonymous reports in one location, confirmation rates drifting apart between units, the same names accumulating low-severity cases. Individually routine, jointly a forecast.
  • The third-party blind spot. Ethics teams increasingly own third-party conduct risk, yet sector surveys find most have assessed well under half of the third parties they answer for. The intermediary in a high-risk jurisdiction, with ownership two layers deep and no completed diligence, is a predictable incident.

None of this requires new surveillance. It requires reading the data the programme already generates, jointly and statistically.

The regulator is already asking

Since its 2024 revision, the US Department of Justice's Evaluation of Corporate Compliance Programs has asked prosecutors to probe whether compliance functions have access to company data and use analytics on it. It also asks how the company governs its own use of AI. A programme that cannot show it looks at data proactively will argue its adequacy after an incident, from a weak position.

For once, the defensive move and the ambitious one are the same. Model speak-up decay, monitor retaliation markers, triage the third-party portfolio by predicted risk, and route each signal to a named owner. The hotline still runs and cases still get investigated. What changes is the tense the programme operates in.

Predictions about people need guard rails

Predictions about people demand more care than predictions about shipments. Signals should target units and portfolios, not individuals. Thresholds should trigger review, not accusation. And every model needs the published calibration and bias scrutiny you would demand of any consequential score. This is a way to allocate attention and support earlier, not a verdict engine.

A test for your own programme. Could you name, today, the three units where speak-up volume has decayed fastest this year? The data to answer that is already in your case system, and the Prophesee Compliance Suite reads it. See what your case data is signalling.

New essays land on LinkedIn first. Follow 3RDi to catch them, or get a demo to see Prophesee on your own data.