Frankfurt am Main, 5 August 2026
The ECB has issued its first-ever public report on whistleblowing across the Single Supervisory Mechanism, revealing a growing number of reports, with internal governance failures accounting for nearly two-thirds of substantiated cases. The findings offer a rare insight into how confidential tips increasingly shape European banking supervision.
The European Central Bank (ECB) and the national competent authorities (NCAs) of the Member States participating in the Single Supervisory Mechanism (SSM) have set up protected channels[1] to enable the reporting of suspected breaches of European law under the prudential rules applicable to credit institutions.
Persons who work for or are in direct contact with a credit institution are often the first to know about any deficiencies or breaches of regulatory requirements that put credit institutions’ prudent management at risk. By reporting such deficiencies and breaches, either internally within the credit institution or to the supervisory authorities, whistleblowers can play a key role in exposing and preventing compliance risks and in ensuring, in the interest of the concerned credit institution and also of the general public, that the credit institution returns to compliance.
In addition, suspected breaches committed by the relevant authorities themselves, i.e. the ECB and the NCAs, in their prudential supervision of credit institutions can also be reported via those channels.
As such, whistleblowing activities contribute to the safety and soundness of credit institutions, to the stability of the financial system as a whole, and also to the effectiveness of prudential supervision.
Recent years have seen a rapid increase in the amount of available data and the development of tools enabling the collection and analysis of data. Exploring this trend, a group of experts from the ECB and NCAs decided to collect data on the whistleblowing reports that the ECB and NCAs receive in the context of the exercise of their supervisory tasks.
This report is the first ECB public report on SSM whistleblowing activities. The objective of this publication is to provide the public with an overview of the SSM- wide whistleblowing activities conducted in the context of prudential supervision. It summarises, in an aggregated manner, information on whistleblowing reports received by the relevant authorities in 2025, including the follow-ups. Data were collected and compiled along standardised categories to improve comparability of the information related to whistleblowing reports received by the ECB and the NCAs.
Whistleblowing reports received in 2025
Anyone with reasonable grounds to believe that a breach of relevant European law has occurred is encouraged to submit a whistleblowing report to the relevant authorities via protected channels. Any report of a breach of European law relating to prudential matters submitted in good faith will be treated as a protected report. The relevant authorities ensure the confidentiality of the reports and the protection of personal data included in the reports in compliance with the EU data protection framework. Personal data of informants, if disclosed in the report, is protected and not shared further within the relevant authority unless the informants give their explicit consent to their personal data being shared.
Reports relating to prudential matters of credit institutions under the SSM are referred to as “SSM-related reports” in this publication. Other reports received by the ECB or the NCAs, such as reports relating to the area of consumer protection or anti-money laundering, but not relevant to prudential supervision, are categorised as “non-SSM-related reports”. A significant number of non-SSM-related reports was received by the ECB and the NCAs, but only SSM-related reports were subject to further analysis for the purpose of this publication. Senders of non-SSM-related reports, such as consumer complaints or fraud allegations, were invited to resubmit their reports via the appropriate channels provided by the respective competent authorities. In some jurisdictions, the NCA itself redirected the report to the competent authority (often within the same institution, but in a different directorate).
In some cases, the SSM-related reports were shared among different authorities, if considered relevant for different jurisdictions (obeying to the required data protection requirements). To minimise double counting in the production of the data presented in this publication, reports are attributed to the relevant authority (ECB or NCA) that has performed the final assessment, regardless of which authority initially received or submitted the report. For example, if an SSM-related report received by an NCA is related to a significant credit institution, the report is sent by the NCA for further assessment to the ECB. In this context, the report is attributed to the ECB. In 2025, 12 SSM-related reports received by the ECB were shared with NCAs for further assessment and 100 SSM-related reports received by NCAs were shared with the ECB.
Overall figures
In 2025, 592 of the reports received by the ECB and the NCAs were assessed as being SSM-related reports[2], with 153 received by the ECB (26%) and 439 by the NCAs (74%).[3] Since the number of SSM-related reports only constitutes a small proportion of the total number of reports received by the ECB and the NCAs, several relevant authorities provide additional information on their websites redirecting senders of non-SSM related reports to the appropriate reporting channels.
Chart 1: Proportion of SSM-related reports received in 2025

Given the continuously increasing number of reports submitted in the recent years, it appears that persons willing to report suspected breaches are generally aware of the possibility to do so and are also able to identify the relevant channels for submitting these reports. There were only two NCAs that did not receive any SSM-related reports during the review period.
The majority of SSM-related reports pertained to less significant credit institutions (approximately 59%) and the remaining (approximately 40%) pertained to significant credit institutions under the direct supervision of the ECB. The number of reports received seem to tally with the ratio of less significant institutions to significant institutions within the SSM (LSIs account for 72% of all supervised entities).[4] Less than 1% of SSM-related reports pertained to alleged breaches by the supervisory authorities themselves. It is worth noting that a single whistleblowing report can concern multiple types of institutions at the same time, meaning that a single report can be related to both a significant and a less significant credit institution, or to a credit institution and a supervisory authority simultaneously.
Chart 2: SSM-related reports received in 2025 (by target group)

Area of reported infringements
For those reports where infringements could be established,[5] the majority (63%) of the SSM-related reports pertained to alleged breaches in the area of internal governance. These reported breaches included infringements of risk management and internal controls, the suitability of management body functions and remuneration. Within internal governance, reports pertaining to risk management and internal controls and management body functions, including fit and proper concerns, were the most common areas of reported infringements.
Considerably fewer reports pertained to alleged breaches in the areas of reporting (2%), remuneration (2%) and capital requirements (2%).
Reporting channels and sources
A whistleblowing report can be submitted to the supervisory authorities via different reporting channels, namely by email, online, letter, telephone or in person.[6] Over 80% of the reports were submitted to the supervisory authorities by electronic means, either via a specific reporting tool on the supervisory authority’s website or by email.[7] The choice of the preferred reporting channel seems to be driven by convenience. Given that around 50% of the reports were submitted using an anonymous reporting tool provided by the supervisory authorities and available on their websites, this choice of anonymity would appear to play a significant role.
Chart 3: SSM-related reports received in 2025 (by channel)

With regard to the authors of the whistleblowing reports, it is important to note that it is not only employees of credit institutions that can report a suspected breach of prudential requirements to the relevant supervisory authorities. It is not even necessary for the reported information to have been acquired in the context of work-related activities. Indeed, the majority of SSM-related reports were considered as coming from informants who did not have access to bank-internal information (55%), whereas the remaining reports were considered as being reported by insiders, as it could be reasonably assumed that in those cases the informant had access to internal information not publicly available.[8]
Chart 4: SSM-related reports assessed in 2025 (by source)

Follow-up to whistleblowing reports
Whistleblowing reports are forwarded within the SSM to the respective supervisory authority and duly followed up. However, not all whistleblowing reports are of sufficient quality or contain enough evidence to justify taking supervisory actions. In 2025, 82% of the follow-up measures consisted of a supervisory investigation, including on-site inspections and requests for information from the concerned credit institution. 16% consisted of supervisory measures and 2% of enforcement or sanctioning proceedings.
For example, if an informant reports, with appropriate evidence, that a supervised entity grants loans to clients connected to its board members at a discount, such information may lead to a request for information addressed to the supervised entity, followed by an in-depth review of its lending policies, the role and responsibilities of the credit committee and the appropriateness of the internal controls applied. Any findings could translate into specific qualitative requirements addressed to the supervised entity in the Supervisory Review and Evaluation Process (SREP). They might also trigger a reassessment of the suitability of board members or even result in the initiation of sanctioning procedures against the supervised entity, in case a breach of prudential requirements has been determined.
Chart 5: Types of measures taken as follow-up in 2025

Conclusion
Whistleblowing has become an important and integral part of European banking supervision. While many whistleblowing reports received by the relevant authorities pertain to tasks that are not related to banking supervision, SSM-related reports do have the potential to uncover breaches that the supervisor might otherwise not know about or only detect at a later stage.
In light of the figures shown in this report, in particular those concerning the follow-up measures taken upon receipt of an SSM-related report, it can be concluded that the relevant authorities within the SSM do contribute to the safety and soundness of credit institutions by providing confidential, anonymous reporting channels and ensuring a proper follow-up to whistleblowing information.
Read the report
Source – ECB Banking Supervision
