Strip an ethics and compliance programme to its operating core and you find the hotline: the channel where employees report what they have seen, feeding the case management process that investigates it. The field's best benchmarks are built on this machinery. NAVEX's annual analysis draws on millions of reports across thousands of organisations, and its 2026 edition describes case volumes, report rates and closure times, with closure times notably lengthening, in authoritative detail.
Notice, though, what every one of those numbers has in common: each describes something that already happened. A hotline report is filed after the harassment, after the fraud began, after conditions in a business unit deteriorated past someone's willingness to stay silent. The function's primary instrument is a lagging indicator, and benchmarking lagging indicators, however well, is measurement of harm, not prevention of it.
The signals that arrive earlier
The predictive information exists, and most of it sits in data the ethics function already owns or can lawfully reach:
- Speak-up decay. A team whose reporting volume drops to zero is not a healthy team; healthy cultures produce a steady baseline of questions and minor reports. Silence following a management change, a restructuring or a missed target is a signal with timing attached, visible in the hotline data itself, if anyone models the baseline instead of celebrating the quiet.
- Retaliation risk markers. What happened to the last three people who reported in that unit: their ratings, their transfers, their exits, relative to peers? Retaliation is both a harm and a silencer of future signal, and its statistical shadow shows up in HR data well before a retaliation claim is filed.
- Case-pattern drift. Rising anonymity rates in one location, substantiation rates diverging between units, repeat subjects accumulating low-severity cases: individually routine, jointly a forecast, when read across the portfolio rather than case by case.
- The third-party blind spot. Ethics teams increasingly own third-party conduct risk while having audited only a fraction of the portfolio; sector surveys find most programmes have assessed well under half of the third parties they are accountable for. The intermediary operating in a high-risk jurisdiction, with ownership two layers deep and no completed diligence, is a predictable incident with a name and an account number.
None of these signals requires new surveillance. They require reading, jointly and statistically, the data the programme already generates.
The regulator is already asking
The US Department of Justice's Evaluation of Corporate Compliance Programs has, since its 2024 revision, asked prosecutors to probe whether compliance functions have access to company data, whether they use analytics on it, and how the company governs its own use of AI, including safeguards against misuse. The direction is unambiguous: a programme that cannot demonstrate it looks at data proactively is a programme whose adequacy will be argued about after an incident, from a weak position.
For once, the defensive and the ambitious move are the same move. A programme that models speak-up decay, monitors retaliation markers, triages its third-party portfolio by predicted risk and routes each signal to a named owner is simultaneously doing the thing regulators now ask about and the thing the function was always for. The cases still get investigated; the hotline still runs. What changes is the tense the programme operates in.
The honest constraint deserves stating: predictions about people demand more care than predictions about shipments. Signals should target units and portfolios, not individuals; thresholds should trigger review, not accusation; and every model needs the same published calibration and bias scrutiny you would demand before trusting any consequential score. Prediction here is a way to allocate attention and support earlier, not a verdict engine.
A test for your own programme: could you name, today, the three units where speak-up volume has decayed fastest this year? The data to answer that is already in your case system; the Prophesee Ethics module reads it. See what your case data is signalling.