[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-predicting-misconduct-before-the-hotline-call":3},"\nAn ethics programme built around the hotline learns about harm\nafter someone was harmed enough to report it. No amount of\nbenchmarking fixes that.\n\nThe best benchmarks come from NAVEX, whose annual analysis draws\non millions of reports across thousands of organisations. Its 2026\nedition describes case volumes, report rates and closure times,\nwith closure times notably lengthening, in authoritative detail.\nEvery number describes something that already happened. A hotline\nreport is filed after the harassment, after the fraud began, after\nconditions in a unit passed someone's tolerance.\n\n## The signals that arrive earlier\n\nThe predictive information exists, and most of it sits in data the\nethics function already owns:\n\n- Speak-up decay. Healthy cultures produce a steady baseline of\n  questions and minor reports; a team going quiet after a\n  management change or a missed target is a timed signal, sitting\n  in the hotline data itself.\n- Retaliation markers. What happened to the last three people who\n  reported in that unit? Their ratings, transfers and exits,\n  relative to peers, show up in HR data well before a retaliation\n  claim is filed.\n- Case-pattern drift. More anonymous reports in one location,\n  confirmation rates drifting apart between units, the same names\n  accumulating low-severity cases. Individually routine, jointly a\n  forecast.\n- The third-party blind spot. Ethics teams increasingly own\n  third-party conduct risk, yet sector surveys find most have\n  assessed well under half of the third parties they answer for.\n  The intermediary in a high-risk jurisdiction, with ownership two\n  layers deep and no completed diligence, is a predictable\n  incident.\n\nNone of this requires new surveillance. It requires reading the\ndata the programme already generates, jointly and statistically.\n\n## The regulator is already asking\n\nSince its 2024 revision, the US Department of Justice's Evaluation\nof Corporate Compliance Programs has asked prosecutors to probe\nwhether compliance functions have access to company data and use\nanalytics on it. It also asks how the company governs its own use\nof AI. A programme that cannot show it looks at data proactively\nwill argue its adequacy after an incident, from a weak position.\n\nFor once, the defensive move and the ambitious one are the same.\nModel speak-up decay, monitor retaliation markers, triage the\nthird-party portfolio by predicted risk, and route each signal to\na named owner. The hotline still runs and cases still get\ninvestigated. What changes is the tense the programme operates in.\n\n## Predictions about people need guard rails\n\nPredictions about people demand more care than predictions about\nshipments. Signals should target units and portfolios, not\nindividuals. Thresholds should trigger review, not accusation. And\nevery model needs the published calibration and bias scrutiny you\nwould demand of any consequential score. This is a way to allocate\nattention and support earlier, not a verdict engine.\n\nA test for your own programme. Could you name, today, the three\nunits where speak-up volume has decayed fastest this year? The\ndata to answer that is already in your case system, and\n[the Prophesee Compliance Suite](/solutions/compliance/ethics)\nreads it. [See what your case data is signalling](/contact).\n",1786984937086]