Skip to main content

The SEC Whistleblower Program, Explained: What a 10–30% Bounty Means for Your Company's Internal Controls

Published 9 min readMike ThriftMike Thrift
The SEC Whistleblower Program, Explained: What a 10–30% Bounty Means for Your Company's Internal Controls

Any current or former employee, vendor, or investor can report your company to the SEC — anonymously, through a lawyer — and collect between 10 and 30 percent of every dollar the agency collects above $1 million. In fiscal year 2025, the SEC received a record 53,753 tips, complaints, and referrals, up nearly 19 percent from the prior year, and paid about $60 million to 48 whistleblowers. The program has now paid well over $1 billion since the first award in 2012, with the largest individual awards running into nine figures.

If you run a small or closely held company, this is not someone else's problem. The whistleblower program covers violations of the federal securities laws, and those laws reach far beyond public companies: private offerings, investment advisers, broker-dealers, and fraud in connection with the purchase or sale of securities all count. This guide explains how the program works, what protections whistleblowers get, and the concrete internal-control steps that keep a concern from becoming an enforcement action.

How the Program Works

Congress created the SEC whistleblower program in Section 21F of the Securities Exchange Act as part of the Dodd-Frank Act of 2010. The mechanics are straightforward, and every element of them should shape how you run your company.

The three eligibility requirements

To earn an award, a whistleblower must:

  1. Voluntarily provide information to the SEC. Information counts as voluntary when it is given before the SEC (or certain other authorities) requests it from the person. Someone responding to a subpoena is not a volunteer.
  2. Provide "original information." The information must come from the whistleblower's independent knowledge or independent analysis — not from publicly available sources or someone else's tip — and must not already be known to the SEC.
  3. Have the information lead to a successful enforcement action. The SEC action (plus any related actions by other authorities arising from the same facts) must result in monetary sanctions exceeding $1 million.

Anyone can qualify: insiders and outsiders, employees and former employees, vendors, investors, even competitors. There is no requirement to report internally first, and a whistleblower can file anonymously as long as they are represented by counsel.

The 10–30% award range

When the conditions are met, the SEC pays awards totaling 10 to 30 percent of the monetary sanctions actually collected — in aggregate, split among claimants if there is more than one. The percentage is discretionary, not formulaic: the significance of the information, the assistance provided, and the programmatic interest in deterring the violation all push the number up or down. Critically, awards are paid only to the extent sanctions are collected, and they come from the Investor Protection Fund, a separate Treasury fund financed entirely through sanctions paid by violators. As the SEC puts it in every award announcement, no money is taken or withheld from harmed investors to pay whistleblowers.

The SEC guards whistleblower identities

By statute, the SEC protects whistleblower confidentiality and does not disclose information that could reveal a tipster's identity. Combined with the anonymous-through-counsel option, this means you may never learn who reported you — which is one more reason the rational response to the program is fixing problems early rather than hunting for the source.

Why Small and Closely Held Companies Are in Scope

A common misconception is that the SEC only polices public companies. In reality, several of the most enforcement-active corners of the securities laws sit squarely in small-business territory:

  • Private offerings. Fraud, material misstatements, or a botched exemption in a Regulation D raise, a Regulation Crowdfunding campaign, or a friends-and-family round can all draw enforcement interest — and anyone who saw the pitch deck can be the tipster.
  • Registered and exempt investment advisers. Small RIAs, fund managers, and financial planners live under SEC or state jurisdiction, and fee, custody, and disclosure violations are perennial tip subjects.
  • Broker-dealers and funding portals. Small firms handling other people's money face the same whistleblower exposure as large ones.
  • Fraud in connection with securities transactions. Classic fraud — lying to investors to get their money — does not require a ticker symbol.

FY2025's enforcement results underline the point: while the total number of new actions fell, the Commission emphasized fraud cases, returned approximately $262 million to harmed investors, and rewarded whistleblowers in significant numbers. A record tip volume means more eyes on more conduct, including yours.

The Anti-Retaliation Shield (and What It Means for Employers)

The bounty gets the headlines, but the anti-retaliation rules are what most directly constrain how you manage people.

Dodd-Frank Section 21F(h)

Employers may not discharge, demote, suspend, threaten, harass, or otherwise discriminate against a whistleblower because of a lawful report to the SEC. The SEC can bring its own enforcement action against a company that retaliates, and the affected individual can sue as well. One important boundary, settled by the Supreme Court in 2018: Dodd-Frank's anti-retaliation protection applies to people who report to the SEC, not to those who only ever report internally.

Sarbanes-Oxley Section 806

Internal reporting is not unprotected, though. SOX Section 806 shields employees of public companies — plus employees of their contractors, subcontractors, and agents — who report suspected securities violations to a supervisor or other appropriate internal channel, and complaints go through the Department of Labor with federal-court review available. If your small business does work for a public company, your employees may carry SOX protection into your workplace.

Rule 21F-17: don't impede, even on paper

Separate from retaliation, SEC Rule 21F-17(a) provides that no person may take any action to impede an individual from communicating directly with SEC staff about a possible securities law violation — including enforcing, or threatening to enforce, a confidentiality agreement covering such communications. The SEC has brought enforcement actions over confidentiality, severance, and employment-agreement language with a chilling effect on whistleblowing even where it found no evidence that anyone was actually deterred from reporting.

Practical consequence: pull out your standard NDA, severance and separation agreements, employee handbook, and the confidentiality notices used in internal investigations. Any blanket "you may not disclose anything about the company to anyone" clause needs a carve-out expressly permitting reports to government agencies including the SEC. Have counsel review the language; this is one of the cheapest enforcement risks to eliminate.

The Internal-Controls Playbook: Five Steps

You cannot prevent anyone from calling the SEC, and you should not try. What you can do is make internal reporting the path of least resistance and make violations less likely to occur in the first place. The payoff is real: under the SEC's cooperation framework — the Seaboard factors of self-policing, self-reporting, remediation, and cooperation — companies that police themselves, report, fix problems, and cooperate can receive reduced charges, lighter sanctions, mitigating language, or even no enforcement action at all. In FY2025, several parties received reduced penalties or avoided actions entirely on exactly these grounds.

1. Give concerns somewhere to go

A three-person company does not need a vendor hotline, but it does need a defined channel: a named contact (ideally not the person whose conduct might be reported), a dedicated email inbox, and a written promise — kept — that reports will be taken seriously and that retaliation is prohibited. Tell employees the channel exists, more than once. Most whistleblowers the SEC rewards first tried to raise the issue inside the company; a credible internal path means you hear about the problem while it is still fixable.

2. Investigate promptly and document everything

When a report lands, move quickly: preserve relevant records, scope the facts, interview the right people, and write down what you did and found. A contemporaneous paper trail showing a good-faith investigation is both how you actually fix things and, if the matter ever reaches regulators, evidence of self-policing. Slow-walking an investigation while the conduct continues is the worst of both worlds.

3. Remediate for real

Stop the violation, discipline proportionally, fix the control that failed, and make harmed parties whole where possible. Remediation is one of the four Seaboard pillars precisely because the SEC weighs what you did after discovery. Cosmetic fixes — a memo and a training slide deck while the same revenue-recognition games continue — earn no credit.

4. Preserve documents from the first hint of trouble

Implement a litigation hold as soon as a serious report or inquiry surfaces, and suspend routine deletion for the affected records. Destroying documents after a duty to preserve attaches invites obstruction exposure on top of the underlying issue. Routine, written retention policies adopted in calm times make holds far easier to execute in stressful ones.

5. Get counsel involved early on self-reporting

Whether to self-report to the SEC is a judgment call with real tradeoffs, and it should be made with experienced securities counsel — not in a vacuum. But understand the incentive structure: prompt self-reporting paired with genuine cooperation and remediation is the fact pattern that produces declinations and zero-penalty resolutions. Finding out from a subpoena what an employee told the SEC months ago is the fact pattern that does not.

Common Mistakes That Turn Reports Into Cases

  • Overbroad confidentiality language in NDAs, severance agreements, and handbooks that chills reporting (see Rule 21F-17 above).
  • Retaliation by a thousand cuts — the poor performance review, the reassignment, the sudden exclusion from meetings — after someone raises a concern. Retaliation claims often outlive the underlying issue.
  • Assuming "we're private" means "we're exempt" from securities-law exposure, especially around fundraising and investor communications.
  • Treating the books as an afterthought. A disproportionate share of tips trace back to accounting: premature revenue recognition, buried related-party transactions, round-tripped expenses, unsupported valuations. Sloppy books both enable misconduct and make innocent errors look intentional.
  • No segregation of duties. When one person can initiate, approve, and record a transaction, every dispute about that transaction becomes a credibility contest instead of a paper-trail review.

Keep Your Books Investigation-Ready

Clean, reconcilable books are both a deterrent and a defense: they make misconduct harder to hide, innocent mistakes easier to explain, and cooperation faster and cheaper if regulators ever come calling. Segregate duties even in a tiny team, reconcile accounts on a schedule, and keep an audit trail that shows who recorded what and when.

Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — every transaction version-controlled and reviewable, with no black boxes. Get started for free and see why developers and finance professionals are switching to plain-text accounting. If you want to explore dashboards and reports on top of your ledger, take a look at /fava/ as well.

Share this article

Source: https://beancount.io/blog/2026/09/14/sec-whistleblower-program-bounty-internal-controls-small-business-guide

Published: September 14, 2026