Skip to main content
All guides
11 min read·

Mandatory internal reporting channel for GmbH and AG: legal obligations, implementation costs, and compliance in Switzerland

Federal regulatory framework, indirect obligations for EU subsidiaries and regulated sectors, data protection, and a realistic budget for Swiss SMEs.

Why GmbH and AG companies must take whistleblowing seriously

Managing internal reports of irregularities — from cash theft to accounting manipulation, from workplace harassment to data protection breaches — has become a compliance priority for Swiss corporations. GmbH and AG companies with cross-border activities, EU subsidiaries (50-employee threshold per Member State), exposure in regulated sectors, or clients imposing governance standards increasingly find they must equip the organisation with a structured internal channel, even in the absence of a generalised federal law modelled on EU Directive 2019/1937.

Swiss employment law does not currently require all SMEs to have a formalised whistleblowing system: the Federal Council's 2018 proposal was definitively rejected by the National Council on 5 March 2020 (after an initial refusal in June 2019); a further parliamentary attempt failed in February 2024. However, Federal Supreme Court case law, supervisory obligations in regulated sectors, the revised Federal Act on Data Protection (FADP), and expectations from clients, banks, and international partners make an internal channel, in practice, a compliance requirement for many GmbH and AG companies — not an optional internal communication tool.

This guide explains when the obligation truly arises, what minimum requirements must be met, how much implementation costs, and how to integrate the process into the company's administrative and accounting management, with references updated to 2026.

The cascade system: why the internal channel is the legal prerequisite

According to established Federal Supreme Court case law, an employee who discloses irregularities externally without first attempting internal reporting may breach the duty of loyalty (Art. 321a para. 1 CO) and the obligation of confidentiality (para. 4). The lawful path follows three stages:

Stage Recipient Condition Risk if absent
1st — Internal Employer / dedicated channel Good-faith report of a material irregularity Employee has no documented lawful path
2nd — Authority Competent authority (FINMA, cantonal, criminal) Failed or manifestly ineffective internal attempt; public interest Premature external report = possible offence
3rd — Public Media, public opinion Inert authority; last resort; overriding public interest Civil and criminal liability of the reporter

For GmbH and AG companies this means that, even without dedicated whistleblowing legislation, the absence of an accessible and credible internal channel weakens the company's position in the event of leaks to the outside and makes it harder to challenge the legitimacy of public disclosure by an employee.

Minimum compliance requirements for the internal channel

A generic email address is not enough. A system compliant with Swiss and European best practice must ensure:

Accessibility and reporting methods

Written channel (encrypted online form, dedicated mailbox) and, as best practice, the option of oral reporting (hotline, appointment). For EU subsidiaries, applicable national law generally requires both methods and, in many countries, acceptance of anonymous reports.

Confidentiality and need-to-know

Identity of the reporter, content of the report, and data of persons involved processed only by authorised individuals. Separation between those receiving the report and the management line concerned, to avoid conflicts of interest.

Documented procedure

Internal regulations approved by the Board of Directors (AG) or management (GmbH) defining: material scope (fraud, corruption, discrimination, safety, accounting violations), acknowledgement times, investigation methods, communication to the reporter, and archiving. For EU standards: receipt confirmation within 7 days and feedback within 3 months.

Protection from retaliation

Explicit prohibition of mobbing, demotion, or dismissal motivated by lawful reporting. In Switzerland, protection relies primarily on Art. 336 CO (abusive dismissal, compensation of up to 6 months' salary) and internal documentation demonstrating fair treatment.

FADP compliance

Privacy notice, legal basis for processing (generally overriding legitimate interest under Art. 31 FADP), technical and organisational measures, retention limitation (generally 5–10 years unless proceedings pending), management of access rights of the reported person. Violations may result in criminal fines of up to CHF 250,000 for responsible natural persons (Art. 60 et seq. FADP).

GmbH vs AG: governance differences in managing reports

Legal form does not exempt from the de facto obligation to establish a channel, but affects who decides, approves, and oversees the process:

Aspect GmbH AG
Responsible body Management (Art. 812 CO); relevant shareholders in family SMEs Board of Directors (Art. 716a CO); delegation to operational management
Regulations approval Management; shareholders' meeting approval only if provided for in the articles of association Board of Directors; general meeting for material statutory amendments
Channel manager Internal compliance officer, external consultant, or fiduciary General secretary, compliance officer, or external ombudsman
Conflict of interest Critical if management is involved; frequent recourse to external fiduciary Audit committee or independent Board member often designated
Reporting to senior management Periodic report to management and, if applicable, shareholders Aggregated report (without unnecessary personal data) to the Board of Directors
Audit Auditor may assess adequacy of the internal control system Audit committee (if present) monitors channel effectiveness

Implementation costs: realistic budget for SMEs

Costs vary depending on organisational complexity, number of languages, and EU compliance obligations. Order of magnitude for companies with 50–250 employees in Switzerland:

Basic solution

CHF 1,000–5,000

First year, SME < 50 FTE, Switzerland only

  • • Internal regulations (template + legal review)
  • • Dedicated email mailbox or simple web form
  • • Brief management training
  • • Recurring costs: CHF 500–2,000/year

Standard solution

CHF 5,000–15,000

50–250 FTE, possible EU exposure

  • • SaaS platform (Navex, EQS, Integrity Line, etc.)
  • • Multilingual 24/7 hotline
  • • Privacy consulting and FADP alignment
  • • Recurring costs: CHF 3,000–8,000/year

Advanced solution

CHF 15,000–40,000

Groups, financial sector, multi-site

  • • Independent external ombudsman
  • • HR, audit, and ticketing integration
  • • Due diligence and group-wide policies
  • • Recurring costs: CHF 10,000–30,000/year

By way of comparison, according to international whistleblowing studies, the average financial damage from undetected irregularities can regularly exceed CHF 100,000 per incident in affected companies. The internal channel is therefore not purely defensive administrative cost, but an internal control investment with measurable return.

Accounting and tracking in Accountex

Implementing the channel generates costs and, potentially, provisions that should be recorded correctly from project launch:

1

Setup costs (CAPEX vs OPEX)

Legal consulting, platform configuration, and initial training: generally operating expenses (accounts 6200–6600, depending on the chart of accounts). Annual SaaS licences: recurring cost allocated over 12 months or recorded on invoice.

2

Dedicated cost centre

Create a "Compliance / Governance" cost centre to monitor whistleblowing expenses, follow-up audits, and internal hours of the compliance officer. Useful for Board reporting and justifying renewal budget.

3

Provisions for damages and proceedings

If an internal report reveals probable asset damage (theft, corruption, missed VAT), assess a provision under Swiss GAAP FER or applicable IFRS standards. Document the decision with Board or management minutes and attach the investigation file.

4

Documentation for auditor and audit

Retain invoices, provider contracts, internal regulations, aggregated statistical reports (number of reports by category, closure times), and proof of staff training. The auditor — even under opting-out — may request evidence on the internal control system.

Six-phase implementation plan

Phase 1 — Applicability analysis (1–2 weeks)

Map employees by country, contracts with whistleblowing clauses, regulated sectors, and EU subsidiaries. Determine whether to apply minimum Swiss standards or full EU requirements.

Phase 2 — Process design (2–4 weeks)

Draft regulations, define roles (receiver, investigator, decision-maker), rules on conflicts of interest, and escalation flow to governing bodies and auditor.

Phase 3 — Platform selection (1–2 weeks)

Compare providers on hosting (Switzerland/EU), encryption, anonymity, languages, IT integration, and costs. Verify the data processing agreement (DPA) under the FADP.

Phase 4 — Approval and communication (1 week)

Formal approval by the Board of Directors or management. Communication to all employees (intranet, onboarding, posters), with explicit reference to the regulations and non-retaliation.

Phase 5 — Training and testing (1 week)

Train those handling reports on FADP confidentiality, employment law, and investigation techniques. Run an end-to-end channel test.

Phase 6 — Ongoing monitoring (annual)

Annual report to senior management, review of regulations, training updates, and FADP compliance verification. Adapt the system to any new federal or cantonal rules.

Quick compliance checklist

  • Accessible internal channel (at least in writing; also oral if required by applicable law or as best practice) communicated to all employees
  • Regulations approved by the Board of Directors or management, with clear scope and procedure
  • Designated responsible person independent from the management line involved
  • FADP privacy notice and DPA contract with any external provider
  • Documented anti-retaliation policy aligned with personnel regulations
  • Defined acknowledgement and feedback times (ideally aligned with EU standards where applicable)
  • Secure archiving with retention periods and limited access
  • Costs recorded in accounting and renewal budget planned
  • Annual effectiveness review and update in case of organisational changes

Legislative outlook and operational recommendation

The Federal Parliament has so far rejected a unified legislative initiative on whistleblowing — the latest motion on the subject was defeated by the National Council in February 2024 — but international pressure (OECD, EU trading partners) and the evolution of corporate practice are pushing towards clearer regulation. Meanwhile, GmbH and AG companies operating across borders or in regulated sectors cannot wait: the compliance obligation is already operational for many of them.

The recommendation for Swiss SMEs is to implement an internal channel proportionate to size and risk profile, document it formally, and integrate it into the internal control system. Those participating in public tenders, working with listed groups, or exceeding the 50-employee threshold in European subsidiaries benefit immediately: reduced legal risk, early fraud detection, and a credible signal of good governance to banks, investors, and auditors.

Note: this article is for informational purposes only and does not replace personalised legal or tax advice. Cantonal provisions and national transpositions of the EU directive in individual Member States may vary; always verify the specific situation with a qualified adviser.

Simplify your Swiss accounting

AccountEX handles VAT, QR-invoices and bookings with AI. Start for free.