Pav Gill on Wirecard, Confide, and why whistleblowing hotlines are not enough
From whistleblower to technology founder: Pav Gill on building the reporting platform he wished had existed when he helped expose the fraud at Wirecard
Key Takeaways
Many whistleblowing systems break down after the report is received, not at the point of intake.
Regulation can force companies to open a channel. It cannot create trust or competent follow-through.
Serious speak-up systems need structured processes, clear escalation routes, and unbroken records — not just another hotline.
When I approached Pav Gill for this interview, I did not want simply to ask him to retell the Wirecard story. He has spoken about that experience on many occasions, and the broad outline is now well known. What interested me was what happened before the scandal became public: the warnings raised inside the company, the investigation that was started and then curtailed, and the pressure placed on those who tried to pursue the evidence.
Over the last four months there have been endless headlines relating to the KPMG debacle in Australia, with shocking revelations about whistleblower retaliation, botched investigations and a pattern of fabrications and equivocations that went all the way to the very top of the firm.
The problem was not just the local firm. The whistleblower escalated his concerns to KPMG International through its International Whistleblower Hotline and by contacting Global General Counsel Anne Collins and Global Chairman and CEO Bill Thomas directly. But instead of following up his claims, they declined to investigate and relied on the legal separation between the global organisation and its Australian member firm.
This raises an obvious question. What is the point of a whistleblower hotline if reports are not investigated properly. This is what Pav and I focused on in this interview.
Who is Pav Gill?
Pav Gill is a former Magic Circle lawyer and fintech general counsel, entrepreneur and keynote speaker, best known as the whistleblower who helped expose the fraud at Wirecard, one of Europe’s largest corporate scandals.
After experiencing first-hand the risks faced by people who raise concerns inside powerful organisations, Gill founded Confide, an AI-native governance, risk and compliance case-management platform. It is designed to help organisations manage whistleblowing reports and other high-stakes matters, including conflicts of interest, vendor risk and AI governance.
In this Expert Voices interview, Pav discusses how his experience shaped Confide, why traditional whistleblowing hotlines often fail, what the EU Whistleblowing Directive does and does not solve, and what companies, boards, auditors and professional advisers still misunderstand about speak-up systems, investigations, AI governance and corporate accountability.
1. From Wirecard to Confide
Your personal experience as the Wirecard whistleblower is central to the founding of Confide. When did the idea for Confide first begin to take shape? Was it something you were already thinking about during the Wirecard experience itself, or did it emerge later, when you had time to reflect on what had gone wrong?
After coming out publicly about a year after Wirecard crashed, with the release of the Sky documentary “Wirecard: A Billion Euro Lie”, I hit the speaking circuit. The EU was rolling out the Whistleblowing Directive at the time, and many of my talks centred not only on my role as Wirecard’s Head of Legal for Asia-Pacific but on how different jurisdictions were approaching whistleblowing.
Somewhere in that period it hit me: was the bigger purpose in exposing Wirecard to do something more than speak about it? I had seen first-hand, during my years as general counsel, how fragmented the compliance industry was, with solutions built to handle one or two matters at a go. Why not use my experience to build the thing I could never buy: one platform that brings everything together, designed by someone who has lived through what happens when these systems fail and built so that employees would trust it enough to use?
2. Why Formal Channels Are Not Enough
Many organisations have formal reporting channels, policies and hotlines. Yet serious concerns can still be mishandled, delayed, under-escalated or treated as a compliance problem rather than a governance problem.
What do you see as the biggest recurring weaknesses in how organisations handle internal reports of misconduct or concern? How did those weaknesses shape the way you thought about Confide?
There’s a tendency to treat compliance, and even governance, as a tick-box exercise designed to keep regulators at bay, and another to shoot the messenger, particularly when the news threatens the company’s reputation, its stock price or one of its sacred cows.
On top of that, the audit trail from receipt of a whistleblowing report to its resolution is usually broken. Plenty of companies can receive a report. The difficulties usually begin afterwards. Very few organisations can show, in a structured way, when a concern was first raised, how it was handled and how it was eventually resolved. That was one of the problems I wanted Confide to address.
3. When Reports Involve Senior Leadership
When allegations concern senior leaders, reporters may fear that people connected to the matter can see or influence the report. How can technology create independent escalation routes, ring-fenced investigations and direct board-level visibility?
The first thing to accept is that the org chart is the threat model. When an allegation touches senior people, the question stops being the quality of your policy and becomes whether the people implicated can see the report, influence it or quietly starve it of resources.
At Wirecard the reporting lines looked normal on paper and routed, in practice, toward people close to the matters being reported. Technology helps because routing can be made structural rather than discretionary: conflict rules that automatically exclude named individuals from a case, ring-fenced case files that stay sealed even from system administrators, escalation paths that reach the audit committee without passing through the executives concerned and an immutable log of who accessed what and when.
I have come to call the broader approach a firewalled investigation. One trusted party handles the source and liaises with the investigation team on the source’s behalf, so the reporter is never bounced across multiple channels and unfamiliar people, which is the fastest way to lose them. Technology can enforce that separation, but it will only work if the organisation’s governance arrangements genuinely support it.
4. The EU Whistleblowing Directive
The EU Whistleblowing Directive has made internal reporting channels and follow-up procedures a formal obligation for many organisations. Do you see Confide primarily as a compliance solution for regulations such as the Directive, or as something broader — a tool for changing how organisations handle risk, misconduct and internal accountability?
Both, though if a company buys Confide purely to tick the Directive box, the Directive will not save them. I have been open about the implementation gap.
Germany adopted a relatively restrained sanctions regime: certain offences carry fines of up to €50,000, potentially rising to €500,000 for legal persons under the corporate-fine rules. Spain, by contrast, permits fines of up to €1 million for legal persons. That tells you how seriously different capitals take the same obligation.
A directive can require an organisation to provide a reporting channel, but it cannot make employees trust that channel. That depends on whether people believe their concerns will be handled competently and that raising them will not end their careers.
So I treat the Directive as a floor and I am glad it exists. Wirecard helped underline why the Directive mattered and increased pressure for proper implementation. But the companies getting real value from us are asking a bigger question than what the regulation requires. They are asking how leadership hears bad news early enough to act on it.
5. When a Hotline Becomes a Dead End
Recent reporting on KPMG Australia has raised an important question about whistleblowing systems in large professional services networks. In some cases, a whistleblower may use a formal reporting route, but the matter can still become complicated by questions about who has authority to investigate: local management, global leadership, outside lawyers, the board or an independent function.
What does that kind of situation reveal about the limits of traditional hotlines? Where can technology help, and where does the answer still depend on governance, independence and culture?
I will leave the specifics of any individual firm to the reporting, but the structural problem is real and bigger than one network.
Professional services firms are partnerships, and partnerships concentrate exactly the conflicts a whistleblowing system is supposed to manage. The people with authority to investigate are often the people with the closest commercial ties to the subject matter, and local management, global leadership, outside lawyers and the board can spend months debating who owns the problem while the evidence goes stale and the reporter loses faith.
A hotline answers none of that, because intake was never the hard part. Where technology genuinely helps is the part machines are good at: a permanent record of who received the report, who held authority at each stage, what was done and when, so the jurisdictional hot potato is at least visible and timestamped rather than buried in partner emails. Whether anyone independent actually gets to run the investigation is a governance choice, and no software can make that choice for a firm that does not want to make it.
6. Anonymity, Protection and Effective Investigation
One of the hardest balances in this area is protecting the reporter while still enabling thorough and defensible investigations. How should organisations approach that balance? What does genuine protection actually require in practice, and how did that thinking shape Confide?
Protection starts at capture. At Wirecard, a colleague from the finance team came to me with what she knew, and the first thing I did was give her the code name “Bobby,” chosen so nothing about her could be inferred, including her gender, and I used that name in every internal conversation.
The second thing was to have her give a detailed written statement to external counsel early, so her account was crystallised while it was fresh. People underestimate how much a reporter’s circumstances and willingness to remain involved can change over the life of a process. Fear builds, doubt builds, colleagues start watching, and reporters who began with conviction start looking for the exit.
If the first account is captured properly, the investigation survives that. If the process depends on the reporter staying available and willing indefinitely, it will not.
All of that shaped Confide’s design: two-way anonymous communication so investigators can ask follow-up questions without unmasking anyone, structured early capture so the first account is complete and preserved, and retaliation tracking that watches what actually happens to the reporter in the months afterwards. Anonymity that ends the moment someone forwards an email is theatre.
7. Who Should Own Whistleblowing?
Where should responsibility for whistleblowing and speak-up systems sit within an organisation — legal, compliance, HR, internal audit, the board, or an external provider? How should companies manage potential conflicts of interest, especially when allegations involve senior people or important commercial areas?
Ownership matters less than routing. Wherever the function sits day to day, the design has to answer one question honestly: who handles the case when the allegation concerns the person the system normally reports to? Routine matters can sit comfortably with compliance or legal. Serious matters involving senior people need a pre-agreed independent route to the audit committee or the board that does not pass through management on the way.
In my view, intake or triage should not automatically be entrusted to the company’s regular external law firm, whose day-to-day working relationship may be managed by executives whom the report could implicate. Nor, in my view, should it be the firm auditing the accounts, given its continuing professional and commercial relationship with the organisation.
Independence at intake is cheap to establish before a crisis and almost impossible to retrofit during one. Some of our clients go further and outsource first-line triage entirely to a team with no connection to the business, precisely so that nobody inside the building decides what the building gets to know.
8. Conducting Investigations in a Controlled System
A whistleblowing channel is only the beginning. The real test is what happens after a report is made.
From a governance and risk perspective, what are the advantages of keeping the report, investigation, evidence trail, escalation decisions and outcome in a controlled system? What tends to go wrong when investigations are handled through fragmented emails, spreadsheets or external parties with unclear accountability?
Because 18 months later somebody will ask you to reconstruct exactly what happened, and by then the people involved will have quietly revised their recollections. A controlled system means the report, the triage decision, the conflict check, every piece of evidence, every escalation and the closure rationale sit in one place with a log of who touched what and when.
Fragmented handling fails in predictable ways. Evidence lives in inboxes that leave with departing employees. Privilege gets blurred because half the analysis happened in email chains with forty people copied. Spreadsheets may be duplicated, overwritten or maintained without reliable version control, external advisers hold documents the company cannot produce and nobody can say with confidence who decided to close the matter or why.
An investigation is ultimately judged by someone who was not in the room, whether that is a regulator, a court or a journalist, and their question is always the same one: show me. If you cannot, it does not much matter what actually happened.
9. Should Auditors Have Visibility Over Whistleblowing Systems?
External auditors are expected to consider fraud risks and relevant allegations. In practice, however, they may see only what management or legal advisers disclose to them. What would be the benefits — and the risks — of giving auditors controlled, read-only visibility into financially relevant whistleblowing matters? How could technology support this responsibly?
At Wirecard, the external auditors’ picture of the company was, to put it charitably, curated by the people they were auditing. So I am sympathetic to the idea.
Auditors ask for bank confirmations as a matter of routine, and there is a serious argument they should also be able to see, in controlled form, whether financially relevant allegations exist and how they were resolved. Technology makes the controlled part workable: read-only access, filtered to defined categories such as revenue recognition or management override, reporter identities redacted, every access logged and employees told up front that this visibility exists.
The risks are real. There is a chilling effect if employees fear their report becomes an audit workpaper, there is scope creep, and there is the danger of auditors treating visibility as liability cover rather than as a reason for scepticism. Tight scope answers most of that. What settles it for me is the history: Wirecard collapsed over a hole that confirmations eventually exposed, but allegations existed inside the company years earlier. The people with a professional duty to be sceptical never saw them.
10. AI Governance and Professional Services
Recent cases involving AI-assisted reports by major professional services firms have raised questions about hallucinated citations, source verification, approval processes and quality control.
What would proper AI governance require before such reports are published? Are these primarily AI failures, or governance failures involving review, evidence, sign-off and accountability?
They are governance failures wearing an AI costume. A hallucinated citation in a published report is not a new species of error. It is an unverified source, and unverified sources have always been a review failure. What has changed is the volume and confidence with which a model can produce them, which makes the checking step more important at precisely the point when some firms appear not to have performed that checking adequately.
Proper governance before publication is boring and well understood: verify every citation against the underlying source, require named human sign-off where the signatory personally owns the content, disclose where and how AI was used and keep a record of the workflow so that when something goes wrong you can locate where.
The uncomfortable question for professional services is commercial. If a firm charges premium fees for a report produced substantially through AI but does not subject it to proper human review, clients are entitled to question what professional value the firm has added. We are AI-native at Confide and the rule we hold internally is that AI accelerates the work while a named human owns every conclusion. The important point is that a named individual must remain accountable for the work and for any errors that survive the review process.
11. The Future of Speak-Up Systems
Confide has expanded beyond whistleblowing into broader governance, risk and compliance workflows, including areas such as grievances, conflicts of interest, vendor risk, fraud and AI governance.
What does that say about where the market is going? Are companies beginning to understand whistleblowing as part of a wider accountability system, or are many still treating it as a narrow compliance requirement?
The expansion was pulled by customers more than pushed by us. What they kept telling us is that the machinery a serious whistleblowing case needs—structured intake, conflict handling, evidence management, escalation and an unbroken audit trail—is also needed for a conflict-of-interest disclosure, a grievance, a vendor red flag or an AI incident.
As a general counsel, I lived the alternative: a fragmented stack of point solutions stitched together with email, where every category of bad news travelled a different route and none of the routes talked to each other.
The market splits into two kinds of buyers now. One group is buying a channel to satisfy a regulator, and they will get what they pay for. The other group is building the layer through which bad news travels to people with the authority to act on it, and they treat a report as free intelligence rather than a threat. Both groups may pass their audits. The difference between them shows up later, in which of them ends up in the headlines.
About Pav Gill
Pav Gill is a Singaporean lawyer, former fintech general counsel and the founder and chief executive of Confide Platform. He is best known for helping to expose the fraud at Wirecard, the German payments company that collapsed in 2020.
Gill graduated from the National University of Singapore Faculty of Law. He began his legal career as a pupil of Senior Counsel Jimmy Yim before working at Allen & Overy, Clifford Chance and King & Spalding. His private-practice work included banking, finance and capital-markets matters. He later moved in-house, joining the financial-comparison business GoBear before taking a senior legal role at Wirecard.
Gill joined Wirecard in Singapore in September 2017 and became responsible for legal matters across the Asia-Pacific region. A few months later, a member of the regional finance team approached him with concerns about accounting practices inside the company. Gill helped arrange an investigation by an external law firm. The investigation was initially known as Project Phoenix and was later renamed Project Tiger. It examined allegations involving fabricated documents, round-tripping and accounting entries used to make parts of Wirecard’s Asian business appear more profitable than they were.
The investigation did not end as Gill had expected. He has said that control of it was taken away from the Singapore legal team and that he was subjected to sustained pressure before leaving Wirecard in 2018. He left with a substantial archive of internal emails and other material connected to the investigation. Gill was initially reluctant to approach the press. His mother, Sokhbir Kaur, began contacting journalists herself and eventually put him in touch with the Financial Times. Information supplied by Gill became an important part of the newspaper’s reporting on Wirecard from January 2019 onwards.
Wirecard’s auditors were unable to verify €1.9 billion that the company claimed was held in trustee accounts. Wirecard subsequently acknowledged that the money probably did not exist and filed for insolvency in June 2020. Gill did not identify himself publicly as one of the principal internal sources until the following year, when he and his mother appeared in the Sky documentary Wirecard: A Billion Euro Lie.
Speaking out came at a considerable cost. Gill has described the damage to his career, the difficulty he faced finding work after leaving Wirecard and his fears that he and his mother were being watched. His experience also showed him how little practical protection may be available to an employee once an internal report implicates powerful people. In 2022, the Association of Certified Fraud Examiners presented him with its Cliff Robertson Sentinel Award, which recognises people who disclose wrongdoing despite the possible personal or professional consequences.
Gill later founded Confide with Ryan Dougherty, a former colleague from his work in legal and compliance roles. The company began with whistleblowing and case-management software intended to preserve the record of a report from its initial submission through investigation and resolution. It has since expanded into a broader governance, risk and compliance platform covering areas including conflicts of interest, grievances, fraud, vendor risk and AI governance. Gill remains its founder and chief executive.
Alongside his work at Confide, Gill speaks and writes about whistleblowing, corporate misconduct, the responsibilities of in-house lawyers and the way organisations respond when allegations concern senior management. His interest in those subjects is practical rather than academic. He has experienced the reporting process from several positions: as the lawyer receiving concerns from employees, as the person attempting to investigate them, and eventually as the whistleblower himself.
Sources and further reading
EU Whistleblowing Directive — The official text of Directive (EU) 2019/1937.
https://eur-lex.europa.eu/eli/dir/2019/1937/oj/eng
European Parliament briefing — Background to the adoption of the EU’s whistleblower-protection rules.
https://www.europarl.europa.eu/news/en/agenda/plenary-news/2019-04-15/1/protecting-whistle-blowers-new-eu-wide-rules
Pav Gill and the Wirecard investigation — The ACFE’s detailed account of Gill’s role in exposing the fraud.
https://www.acfe.com/fraud-magazine/all-issues/issue/article?s=2022-march-april-pav-gill-wirecard-whistleblower
More than the Wirecard whistleblower — The Singapore Academy of Law profile of Gill’s legal career and experience.
https://sal.org.sg/articles/pav-gill-more-than-just-the-wirecard-whistleblower/
From Wirecard to Confide — Wired on Gill’s experience and the creation of his whistleblowing platform.
https://www.wired.com/story/pav-gill-wirecard-confide-shield-whistleblowers/
Confide’s origins — The company’s account of why Gill founded the platform and how it developed.
https://www.confideplatform.com/our-story
KPMG’s global hotline problem — Big4News reporting on the handling of the KPMG Australia whistleblower’s escalation.
https://www.big4news.com/p/whistleblower-hotline-to-nowhere
Wirecard’s missing €1.9 billion — The company’s June 2020 announcement that the purported cash probably did not exist.
https://wirecard.com/2020/06/22/wirecard-ag-statement-of-the-management-board-about-the-current-situation-of-the-company/
This article is part of the Big4News Expert Voices Series
Expert Voices
This section features candid interviews with whistleblowers, legal experts, and financial professionals who have direct experience with the inner workings of Deloitte, PwC, EY, and KPMG.
About Claudine Cassar
I’m a corporate anthropologist and former Deloitte equity partner. I sold my technology business to Deloitte in 2016 and led the Malta Consulting team for five years. I am the founder and editor of Big4News, which provides independent, clear analysis of PwC, Deloitte, EY, and KPMG — free from corporate spin.
Find me on LinkedIn, X, Instagram, or my author website.
Feel free to reply to this newsletter — I read every reply.













