Twelve questions, three stages, and an honest answer about how much of your speak-up program still runs on people doing things by hand.
Compliance lags the rest of the business by 45.5 points on AI adoption, according to a recent Ethisphere and Ethena study. That gap is the thing regulators will look at. The current ECCP guidance already asks whether there's an imbalance between the technology a company uses to capture market opportunities and the technology it uses to detect and mitigate risk.
Which means the risk has flipped. Compliance teams have spent three years worrying about the risks AI poses. The bigger risk now is running a traditional compliance program in an agentic era.
Nobody crosses that gap in a quarter. The teams pulling ahead move through three stages, in order, because each one builds on the last. Hotline and case management is the program element where all three show up fastest, and it's usually where the distance is widest between where a team is and where it thinks it is.
So here's a way to find out. Twelve capabilities across the three stages. Score one point for each one your system does today. Be strict: a roadmap slide isn't a yes, and neither is a feature your vendor will quote you for.
Stage 1: Agentic tools for your compliance team
Low risk • Fast to implement • Goal: get out of survival mode
These agents work for your investigators, not your employees, which is why they're the fastest points on the list to score. They buy back hours. They don't yet change what your program can see.
1. AI summarizes each case and keeps the summary current as the case evolves.
A compliance lead at a transportation company told us she could do the math on the hours it saves her. Worth having, and the lowest bar on this list.
2. Intake and reports translate in both directions, instantly.
Most teams treat translation as a reporter-side problem. A semiconductor company that evaluated us named the other half: deciphering complex reports from non-native English speakers was slowing their investigators down. Adding a language should also take a click, rather than a services quote and a 72-hour wait.
3. AI suggests the category from the narrative, not the dropdown.
Your reporters pick the wrong category constantly, and every wrong pick costs you days. A compliance leader at an edtech company asked for this directly: have AI read the description of the incident and suggest what the case type actually is.
4. AI triages severity on arrival.
High, medium, low, flagged at intake so the serious report doesn't sit behind an expense-policy question. Compliance stays in the loop on every judgment call. Substantiation carries legal consequences, and it stays with your investigator permanently.
Score so far: __ / 4
Stage 2: Employee-facing compliance agents
Medium risk • Moderate to implement • Goal: a culture where people actually speak up
Your employees already expect a conversational interface for everything else in their working life. Compliance has been the exception, and being the exception costs you reports you never hear about. Employee-facing doesn't mean unsupervised: compliance in the loop beats compliance as a bottleneck.
5. Something answers your phone immediately, in the caller's language.
Secret-shopping traditional hotlines regularly returns hold times north of 15 minutes, and the person on hold just worked up the nerve to call. An AI call taker picks up on the first ring, switches language with no wait for a translator, and writes the report straight into case management. No queue, no third-party call center typing "harrassment" into your permanent record.
6. Reporters describe what happened in their own words.
Your webform probably opens with ten dropdowns before anyone types a sentence. Compliance leaders keep telling us the same thing: people don't report because they don't know how, or because the process looks intimidating. A conversational intake asks follow-up questions where the account is thin, which raises your volume and drops your anonymity rate.
7. Anonymous reporters can still have a conversation.
One prospect asked us whether her hotline could mediate follow-up questions while keeping the reporter anonymous. Most can't, so investigators lose the thread on exactly the cases where they need it most.
8. Employees can ask whether something is even reportable.
Most people who consider raising something never file. They ask a question, get no quick or definitive answer, then guess. An agent that answers in plain language and pulls compliance in on anything sensitive turns a percentage of those guesses into reports you can act on.
Score so far: __ / 8
Stage 3: A team of agents
High risk • Slower to implement • Goal: risk intelligence, and a program that moves in days
Hardly anyone scores here. This is where your tech stack stops being a set of tools and starts behaving like a team, and where your case data starts changing what your program does next.
9. Related cases link themselves.
Three reports about the same manager across three quarters look like three isolated cases in a traditional system. They aren't. At this stage the pattern surfaces on its own, including the geographic version most teams can't get today.
10. You ask a question in a sentence and get a board-ready answer.
"There's no automation to say, hey, I want this report sent to these people on the first of every month." That's a healthcare compliance leader describing the tool he's using right now. At Stage 3 the board conversation moves from how much you did to what changed, and building the deck stops being a weekend.
11. You know how your numbers compare.
Volume, substantiation rate, anonymity rate. An ethics advisor told us his clients get comfortable with hotline volume fast, then immediately want to know how their substantiation rate stacks up against peers. That answer should come from a live cohort, rather than a benchmark report published once a year.
12. A closed case sets the next thing in motion.
A substantiated case in one business unit tells the Training Agent to build the remediation training for that business unit, and tells the Policy Agent where your policy left room for the behavior. You approve or you don't. The agents hand off to each other, and your job becomes deciding which recommendations are worth acting on.
Final score: __ / 12
What your score means
Traditional isn't a stage. It's the starting line.
0 to 3: Traditional
Your team is the automation. Every report gets read, sorted, and forwarded by a person, and the board deck gets built by hand every quarter. Stage 1 is a fast climb from here, and it's the one that gives you the time to do the rest.
4 to 8: Stage 1
The most common score, and the easiest one to mistake for being finished. Agents are reading for your investigators. They aren't talking to your employees, and they aren't telling you anything about your risk picture you didn't already know.
8 to 11: Stage 2
Rare, and it shows up in your numbers. Volume goes up because reporting got easy, anonymity rate goes down because the experience feels safe, and your investigators open every case with the work already started.
12: Stage 3
We haven't met you yet. Please get in touch.
How to tell it's working
AI usage is a bad metric. Nobody's board wants to hear how many prompts you ran. Track two things instead.
Efficiency. How many hours your team got back. Count the time you no longer spend summarizing cases by hand, chasing follow-ups, or rebuilding the same quarterly report. Those hours go into judgment calls only a person can make.
Sophistication. How fast your program can move when something changes. A new market, a new regulation, a new scam in your industry. Traditional programs measure that cycle in months. Agentic programs measure it in days, and your hotline is usually the first place the difference shows.
Bring us your score
Thirty minutes, and we'll do the work before you show up.
Tell us your number when you book. We'll have your branded reporting page built before the call, so you're looking at your own program instead of a demo account. Then we'll walk the points you're missing, in the order you'd get them.
Book 30 minutes. If you scored 12, book anyway. We'd like to know how you did it.