Skip to main content
Trust but Verify? Why Fake Reports Are RealEthics and Conduct
5 min readFor Risk Managers

Trust but Verify? Why Fake Reports Are Real

The Conventional Wisdom

Your organization's reporting system's greatest threat is often perceived as coming from employees who file frivolous complaints to settle scores or shield themselves from discipline. This is where compliance teams typically focus their skepticism and build defenses. Managers are trained to spot retaliatory claims, patterns of serial complainants are documented, and triage protocols are established to separate credible allegations from noise.

This focus seems logical. Internal bad actors know your systems, understand vulnerabilities, and have personal stakes in outcomes. They're the obvious risk.

A Broader Threat

However, your reporting system faces another threat that compliance officers rarely anticipate: external actors exploiting your intake channels for purposes unrelated to your organization.

By summer 2021, compliance teams were managing pandemic-era risks when serious allegations of collusion, accounting fraud, and kickbacks began appearing in executive inboxes and online reporting portals. The reports seemed credible enough to trigger investigations. Some organizations engaged outside counsel, and external auditors demanded explanations. Companies diverted resources from genuine cases to chase these leads.

WilmerHale then discovered a pattern. Multiple clients received identical reports. The allegations were part of academic research by a PhD student at the National University of Singapore, approved by the university's Institutional Review Board.

The student's admission email claimed the reports "deliberately did not bare enough details to necessitate the launch of an investigation." This reveals a misunderstanding of how compliance programs function. When you receive an allegation of accounting fraud with limited specifics, you don't dismiss it. You spend more resources trying to substantiate it because the claim is serious and the details are sparse.

This wasn't an isolated incident. A Harvard professor used the same methodology in 2020, sending multiple fake scenarios to 250 companies covering financial misconduct, bribery, harassment, and discrimination. His IRB approval rested on a technicality: reporting to firms isn't reporting about people, therefore it doesn't constitute human subject research under Department of Health and Human Services regulations.

The Evidence

The costs were substantial and measurable. Organizations that engaged outside counsel incurred thousands of dollars per case in legal fees. Multiply that across hundreds of reports, and you're looking at millions in aggregate expenses triggered by fictitious allegations.

But the financial impact is only part of the damage:

Diverted Investigative Capacity. High-priority fake reports consumed attention that should have gone to authentic cases. Your case management queue doesn't expand to accommodate hoaxes.

Compromised Metrics. Before discovery, compliance reporting data reflected cases that never happened. If you're tracking investigation timelines, case outcomes, or allegation categories for board reporting or regulatory filings, those metrics were wrong.

Reduced System Access. Some organizations restricted public web access to reporting portals to guard against potential malware, limiting one intake channel until the threat was resolved.

Regulatory Complications. Companies under enforcement actions or consent decrees may have been required to report these serious allegations to government agencies before completing internal investigations. You can't easily un-report a hoax to the SEC.

Eroded Executive Support. When senior leaders discover they've spent significant resources investigating fabricated claims, their confidence in the reporting mechanism suffers. That skepticism carries forward to the next serious allegation.

The NUS student's IRB approval and the Harvard professor's rationale both relied on the assumption that minimal detail would prevent costly investigations. That assumption fails on two grounds. First, compliance teams treat vague but serious allegations with heightened urgency, not dismissal. Second, even confirming that an allegation is baseless requires investigation work, documentation, and often legal consultation.

What to Do Instead

You can't prevent external actors from accessing your reporting systems without also preventing legitimate reporters. But you can adjust your intake and triage protocols to account for this threat category.

Pattern Recognition at Intake. Train your case managers to flag reports that share unusual similarities in language, structure, or allegation type across a compressed timeframe. The WilmerHale discovery happened because attorneys compared notes across clients. Your intake team should do the same across cases.

Verification Thresholds for High-Impact Claims. When a report alleges serious regulatory violations but provides minimal substantiating detail, establish a preliminary verification step before engaging outside counsel. Can you confirm basic facts? Do the named parties exist? Does the alleged conduct align with any known business activity? This doesn't mean dismissing vague reports. It means adding a verification gate before incurring major investigation costs.

Information Sharing with Peer Organizations. When hoax patterns emerge, compliance networks and law firms can alert other potential targets quickly. Subscribe to relevant legal alerts and maintain relationships with outside counsel who represent multiple organizations in your sector.

IRB Awareness. If you receive an admission that a report was part of academic research, verify it directly with the institution. The NUS student's admission email initially seemed like another layer of hoax. Direct university confirmation matters.

Cost Tracking by Case. Document investigation expenses tied to each case, including internal hours, outside counsel fees, and audit costs. When a hoax is discovered, you'll have concrete data on the impact. That documentation supports future conversations with academic institutions, IRBs, or regulatory bodies about research methodology standards.

Balancing Internal and External Threats

Internal bad actors remain your primary reporting risk. Employees with personal agendas, those facing discipline, or individuals attempting to manipulate investigations still generate the majority of problematic reports. Your existing protocols for identifying retaliatory claims, documenting serial filers, and assessing reporter credibility remain essential.

The focus on internal threats shouldn't shift entirely to external ones, but it should expand to acknowledge that your reporting system's accessibility, which enables legitimate whistleblowing, also creates exposure to exploitation by actors who have no connection to your organization and no stake in its compliance outcomes.

The academic community needs to reconsider whether IRB frameworks designed for human subject research adequately address the corporate impact of field experiments that treat firms as laboratories. Until those reforms happen, your intake protocols need to account for threats that conventional wisdom hasn't anticipated.

You Might Also Like