Escalation Processes: How Concerns Flow Up and Decisions Get Made
Camille is the director of talent acquisition at a regional health system with about 4,200 employees and a recruiting team of 18, and she learned the hard way that knowing who to call is not the same as having a process. Two years ago, a sourcer flagged that an AI resume-ranking tool seemed to be down-ranking candidates with employment gaps. Camille knew exactly who should hear about it: legal, the vendor, her VP. She sent three emails. Then the concern simply evaporated. Legal assumed the vendor was handling it. The vendor asked for "a formal ticket" that no one knew how to file. The VP was traveling. Six weeks later the sourcer asked Camille what had happened, and Camille had no honest answer. Nothing had happened, because routing a concern to the right people is not a process. A process is what tells those people what to do, by when, who decides, and how the answer gets back to the person who raised it.
Why Routing Is Not a Process
A sibling lesson covers the routing question of when to involve legal, compliance, DEI, or leadership. That is the "who to call" map, and it matters. But Camille's failure was not a routing failure; she routed correctly. What she lacked was a governed pipeline with defined stages, owners, time limits, and a closing step. A concern that lands in three inboxes with no single accountable owner and no clock on it does not get resolved, it gets diffused. The EEOC's guidance on employer use of algorithmic decision tools makes clear that the employer remains responsible for outcomes even when a vendor built the tool, and that accountability cannot be discharged by forwarding an email. It is discharged by a process that produces a documented, owned decision.
The litmus test of governance is not what sits on paper. It is what happens when something goes wrong. If someone spots a potential fairness problem, can they raise it safely? Is the concern investigated thoroughly and quickly? Is remediation swift and visible? Is the person who raised it protected from retaliation? Many organizations have escalation processes on paper and very few have ones that work, and the difference is almost never the policy document.
The rest of this lesson treats escalation as a system with six working parts: a foundation of psychological safety, a single intake behind many doors, a triage rule, a decision-authority map, an investigation protocol ending in a documented resolution, and a feedback loop, all wrapped in a review cadence.
Psychological Safety Comes Before Any Pipeline
People will only escalate concerns if they feel safe doing so. If they fear retaliation, punishment, or dismissal they stay silent, and silent organizations are where problems fester underground until they surface as a lawsuit or a regulatory inquiry. Psychological safety is therefore not a soft preamble to the process design; it is the input without which the machinery has nothing to process. Camille rebuilt from this end deliberately, on the reasoning that a pipeline with no concerns entering it looks identical to a workplace with no problems in it.
Creating that safety requires more than announcing that concerns are welcome. It is demonstrated through four observable behaviors, and people read the behaviors rather than the announcement. First, the immediate response to a raised concern is curiosity rather than defensiveness: "tell me more about what you observed" rather than "that can't be right." Second, the investigation that follows is thorough and fair; the person is not automatically assumed to be right, and is also not dismissed, because the investigation looks at evidence and is documented. Third, the outcome is communicated back. Fourth, and least intuitive, when a concern turns out not to be a problem, the person is thanked rather than blamed: "we investigated and found X, no action needed, but we appreciate your diligence." That fourth behavior decides whether you hear about the next thing, because it removes the private cost of being wrong. If the price of a false alarm is looking foolish, people report only what they are certain about, and certainty arrives long after intervention is cheap.
The mechanism is easiest to see in a case Camille uses when she trains managers. A recruiter noticed that an AI screening tool seemed to be screening out candidates with health-related employment gaps. She was not sure whether the pattern was real or her own perception, and she worried about raising it, because what if she was wrong? Her manager had built enough safety that she raised it anyway. The team investigated and found the tool was penalizing candidates with medical leaves, a flaw the company had fixed. She was thanked for catching it early, and other recruiters now surface problems because they have seen that concerns are valued. Without that safety she stays silent, the flaw runs for months, more candidates are unfairly screened out, and the eventual liability is larger.
One Intake, Many Doors
People need several comfortable ways to raise a concern, but everything they raise must land in one place. These are different design goals, and conflating them is where most escalation systems break. A sourcer worried about her own manager's behavior will never walk through the manager door, and someone who just noticed an odd tool pattern does not want to file an anonymous report. Offering only one channel silently filters out an entire class of problem: precisely the class involving the person who owns that channel.
Camille's system offers five doors. A direct conversation with a manager is fast and relationship-based. A direct line to the governance committee lead handles concerns about the recruiting function itself, or from someone uncomfortable going to their manager. An anonymous web form or hotline covers concerns where confidentiality is critical, such as "I think there is bias in our interviews but I am worried about retaliation." Some larger organizations add a third-party ombudsman who receives concerns and investigates, buying independence no internal channel can match. And a periodic pulse survey asking whether anyone has observed anything concerning in hiring captures issues people would never proactively report but will answer honestly when asked. Anonymity deserves its own defense, because leaders often read an anonymous channel as an insult to their own fairness. People are more willing to raise concerns when they can do so anonymously, and that holds even under fair leaders. The case Camille cites is blunt: a company whose only channel was talk to your manager had a recruiter who observed gender bias in how a hiring manager interviewed candidates, and that manager was her own, so she never raised it and the bias continued for months. When an anonymous hotline was added, similar concerns arrived immediately, were investigated, and the bias was addressed.
The critical design choice is that all doors feed a single intake log, owned by one person. Camille made the governance committee's program coordinator the intake owner. Every concern, regardless of door, becomes a numbered, timestamped record with a status field. This single log prevents the three-inbox diffusion that killed her first attempt. When a concern exists as exactly one tracked record with one owner and one status, "nothing happened" stops being possible, because the status field is visible and someone is accountable for moving it. The record captures the minimum: what was observed, when, which tool or process, who raised it or that it was anonymous, and a first read on severity. Nothing more is required at the door, because demanding a polished report discourages people from raising anything.
Triage: Deciding the Clock and the Path
Not every concern deserves the same response, and pretending otherwise either burns out the committee or buries serious issues in a queue of minor ones. Triage assigns each intake record a severity tier, and each tier carries a different clock and a different path. The tiers map to service-level agreements the committee publishes, so anyone raising a concern knows what to expect. That published expectation is itself part of the safety design: an unanswered concern feels like dismissal, while an acknowledged one with a stated date feels like a process.
| Tier | What it looks like | Clock and path |
|---|---|---|
| Tier 1 | Possible active harm: a tool that may be producing disparate outcomes in live hiring right now | Acknowledged within 24 hours, initial investigation decision within 72 hours, including authority to pause the tool immediately while the investigation runs |
| Tier 2 | A credible concern with no evidence of immediate harm: a pattern someone noticed that needs investigation but is not actively excluding candidates this week | Acknowledged within 3 business days, resolution target of 15 business days |
| Tier 3 | A process or quality improvement: a rejection email that reads coldly, a step that should be documented better | Acknowledged within a week, resolved or scheduled at the next monthly review |
The triage decision is made by the intake owner plus one committee member using a short written rubric, so tiering is not one person's mood on a Monday. The rubric also performs the initial credibility and scope assessment. Is the concern within the remit of the governance process? Concerns about recruiting tools and process are; concerns about a colleague's personality generally are not, and routing those elsewhere promptly is kinder than letting them sit in a fairness queue. Triage also sets the path. A tool-bias concern routes to the data lead, a behavior concern routes to HR and the recruiting lead, and a concern touching legal exposure pulls in counsel. That routing is the sibling lesson's territory; here the point is that triage is where the clock starts and the path is set, both on the record.
Who Actually Decides: A RACI for Escalations
The most common reason escalations stall is that no one is sure who has the authority to decide, so everyone waits for everyone else. Camille fixed this by writing a one-page RACI for every concern type, assigning four roles: Responsible (does the investigation work), Accountable (owns the decision and signs it), Consulted (provides input before the decision), and Informed (told after). The rule that makes it work is that exactly one person is Accountable for any given decision. If two names sit in that column, you have the three-inbox problem with a fancier chart, and the delay is indistinguishable from indifference to the person waiting.
In Camille's map, a Tier 1 tool-bias concern makes the data lead Responsible for the analysis, Camille Accountable for the pause-or-continue decision, legal and DEI Consulted, and the hiring managers using the tool Informed. A Tier 2 interviewer-behavior concern makes the recruiting lead Responsible, the HR business partner Accountable, and legal Consulted. Decisions above a defined threshold, such as permanently retiring a vendor tool or anything touching NYC Local Law 144 bias-audit obligations for automated employment decision tools, escalate the Accountable role up to the VP of talent and require legal as a Consulted party on the record. Writing this down before a concern arrives means that when one does, the question "who decides?" is already answered, and the investigation starts on day one instead of after a week of polite deferral.
The Investigation Protocol
Once a concern is tiered and owned, the investigation follows a documented protocol rather than improvisation, because an investigation designed in the moment tends to look for whatever is easiest to check. Camille's protocol runs in five steps. Intake and documentation records what was observed, when, by whom, and how serious it appears, timestamped. Initial assessment tests credibility, scope, and urgency: does this need action now because a tool is causing harm, or can it wait for the next committee meeting? Investigation assigns the work, usually to the data lead for a tool or metrics concern and the recruiting lead for a process or people concern, with explicit time and resources, and it names what data is needed, who must be interviewed, and what tests will run.
The fourth step is findings, and the standard here is specificity. A finding that says "we looked into it and did not see a major issue" is not a finding, it is a mood. A usable finding names the population, the measured rates, and the strength of the evidence, in the shape of: we analyzed tool output for 500 candidates and found that candidates with a given background advanced at 25 percent while candidates without it advanced at 35 percent, a difference statistically significant at p=0.02, which suggests potential bias in the tool. Writing findings that way forces honesty about how much the evidence supports, and gives the Accountable owner something to act on rather than something to interpret. The fifth step is communication, and it is not optional even when the answer is that nothing was found.
A Concern Flows Through the Pipeline
Walk one concern through Camille's rebuilt system end to end. On a Tuesday, a recruiter reported through the anonymous web form that a new scheduling-and-screening assistant appeared to advance candidates from two large local employers at a much higher rate than everyone else. The intake owner logged it as record ESC-2026-014 at 9:15 a.m., severity flagged for triage. By Wednesday the intake owner and one committee member triaged it Tier 1, because the tool was live and the pattern suggested possible disparate impact, which started the 72-hour decision clock and routed it to the data lead as Responsible with Camille as Accountable.
The data lead pulled tool output for the last 500 candidates and found applicants from those two employers advanced at 38 percent while everyone else advanced at 26 percent, a gap significant enough to investigate as built-in favoritism rather than noise. The tool had been trained on historical hiring data in which those two employers were heavily overrepresented, so it had learned to prefer them: a textbook proxy-bias pattern, not intentional discrimination but a real adverse-impact risk the employer owns under EEOC accountability. The investigation answered a question about the mechanism rather than the symptom, which is what made the remedy obvious rather than debatable.
On Friday morning, 71 hours after intake, Camille made the decision she was Accountable for: pause the tool's auto-advance feature, fall back to human screening for the affected roles, and commission a retrain on balanced data. Legal and DEI, as Consulted parties, had reviewed the analysis on Thursday and agreed the pause was defensible given Local Law 144's bias-audit framing. The decision, the reasoning, the data, the sign-off, and the names in each RACI role went into ESC-2026-014. Two weeks later the retrained tool was re-audited, the gap had closed to within normal variance, and auto-advance was restored under a 90-day monitoring window. That is the difference between Camille's first attempt and her second: the same correct instinct, wrapped in a process that produced an owned, dated, signed decision instead of three forwarded emails.
Decision and Remediation
After the investigation, the decision follows pre-agreed criteria rather than a fresh argument. If no bias is found and the process is working as intended, communicate the findings and thank the person who raised the concern. That outcome is a success, not an embarrassment, and treating it as a false alarm to be quietly buried teaches people that only confirmed problems are worth reporting. If bias is found, stop the tool or the practice immediately rather than waiting for more data. Confirmation is the threshold; once bias is confirmed you already have enough. Pause, tell the team why, and start remediation.
The remediation menu is wider than people assume, and the right item depends on the mechanism the investigation identified. Retrain the tool on better data. Change the process. Add human review at the decision point. Modify the decision criteria the tool or the panel applies. And audit past decisions made under the flawed condition to see whether any need reconsidering, the step most teams skip because it reaches backward into decisions already communicated to candidates. Skipping it leaves the affected people exactly where the flaw put them, which is both the fairness problem and, in a dispute, the hardest fact to explain.
Transparency about the outcome shows that concerns lead to action and models the honesty you want the team to practice. Camille points to a company that found disparate impact in a technical assessment tool and, instead of hiding it, publicly acknowledged the problem, explained why it happened, described what they changed, and set out how they now monitor it. The external read is straightforward: they found a problem and fixed it, which is trustworthy. A company that hides problems or denies bias earns the opposite read, usually later and more expensively.
Documentation and the Decision Record
The decision record is not bureaucratic overhead; it is the artifact that proves the employer met its accountability obligation, and it is the only thing that survives staff turnover. Camille's standard for closing any escalation is that the record answers six questions: what was raised, how it was triaged and why, who investigated and what they found, who decided and what they decided, who was consulted and informed, and what the follow-up commitment is. A concern is not "closed" in the log until those six fields are complete and the Accountable owner has signed.
This matters for two reasons beyond hygiene. First, regulators and plaintiffs credit documented processes that were actually followed, not good intentions. If a fairness question reaches the EEOC or surfaces in litigation, a clean trail of dated, owned decisions is the employer's strongest evidence of reasonable diligence. Under NYC Local Law 144, the bias-audit and notice obligations for automated employment decision tools assume the employer can show its governance, and an escalation log demonstrating that the organization catches and corrects problems is exactly that kind of evidence. Second, the record is institutional memory: when the data lead leaves, the reasoning behind a paused tool does not leave with them. Camille treats the escalation log the way a hospital treats incident reports, dull to maintain and decisive when it matters.
Closing the Loop and the Review Cadence
An escalation process that does not return an answer to the person who raised the concern quietly trains everyone to stop raising concerns, which is the most dangerous failure mode of all because it looks like calm. Closing the loop is a required step, not a courtesy. For named reporters, the Accountable owner sends the outcome directly: here is what you raised, here is what we found, here is what we decided, and thank you. Even a finding of no evidence gets the full reasoning, because that is what makes the answer credible. For anonymous reports, Camille publishes a short outcome summary to the team so the person who raised it sees their concern moved something without being identified. In the worked example, the team saw a two-line note that a tool had been paused and retrained after a fairness concern. The next quarter, anonymous-form submissions went up, not down, because people learned the door actually led somewhere.
Finally, the process reviews itself on a cadence. Camille's committee spends 30 minutes monthly on open and recently closed escalations, and quarterly looks at the meta-level: how many concerns came in, through which doors, how long each tier took against its SLA, and whether any stalled. If Tier 2 concerns consistently blow past the 15-day target, that is a process defect to fix, not a reason to blame individuals. This cadence keeps the system from becoming the thing Camille started with, a paper process that looks alive and does nothing.
Anti-Patterns
Escalation theater. This is having an escalation process on paper that nobody actually runs. Concerns are raised, nothing happens, and over time people learn that escalation does not matter. The mechanics are mundane: a hotline exists, a recruiter submits a concern about an AI tool, weeks pass with no investigation and no communication, the recruiter tells colleagues the hotline is useless, and problems go undetected because nobody uses it. The failure compounds because low report volume gets read as a healthy culture rather than a dead channel. The counter is to commit to using the process you advertise. If you cannot resource investigations, do not pretend to have one, because a pretend process is worse than admitting you have none.
Investigation without action. Some organizations investigate thoroughly and then do nothing with the findings. They confirm bias, document it, present it, and the process stays exactly as it was. That is arguably the worst outcome, because it demonstrates the organization recognizes its problems and has decided they are not worth fixing, which destroys trust more thoroughly than never having looked. The pattern is recognizable: a team analyzes interview feedback, finds gender bias, documents and presents it, and nothing changes, so the next cycle reproduces the same bias and the data team is demoralized. The counter is a standing rule that investigation obligates action, whether that is training the people producing the bias, adding human review, or changing the process, with the action communicated to the team.
Retaliation. Some organizations claim to welcome concerns and then punish the people who raise them, sometimes explicitly and more often through a hundred small exclusions. Retaliation destroys psychological safety completely, because people can see that raising concerns carries a personal cost and they respond rationally by staying quiet. The typical shape is not a dramatic firing: a recruiter raises a concern about a hiring manager's biased interviewing, the manager finds out, and the recruiter is treated coldly and left off important meetings. She regrets speaking up, tells others not to escalate, and the organization loses its ability to self-correct. The counter is explicit protection: make retaliation grounds for discipline, follow up with people who raise concerns to check they are not facing consequences, and state plainly that raising concerns is protected.
Practice
- Map your current process stage by stage. For intake, assessment, investigation, decision, and communication, write one paragraph describing what actually happens today rather than what the policy says. The gap is usually between investigation and decision.
- Build an escalation decision tree. Define what type of concern triggers what level of response, in the form "concern about an individual hiring manager decision goes to the recruiting lead with the data lead investigating, response within two weeks." Publish it.
- Audit your channels. List the escalation channels that exist right now. Can people escalate anonymously? Which door is missing, and which category of concern is that missing door currently suppressing?
- Write an investigation protocol. Specify, for a potential bias concern, what data you collect, who you interview, what tests you run, what timeline applies, and how findings get documented. Write it while no concern is live, because a protocol invented under pressure investigates whatever is easiest to check.
- Write your RACI for the three concern types you see most. One name in the Accountable column each, plus a threshold above which that role moves up. Then confirm every named person knows they are named.
Reflection
- If you observed a potential fairness problem in your own recruiting tomorrow, would you feel safe raising it, and what specifically makes you answer the way you do?
- What would need to be true for you to escalate a concern about your own manager? Does that route exist today?
- Have you seen someone treated badly after raising a concern? What did the rest of the team learn from watching it?
- Which element matters most in your situation: psychological safety, rigorous investigation, clear decision authority, or communication back? What does your answer say about where your process is weakest?
- How would you know whether your process is actually working? Name the two measures you would trust, and be honest about whether low report volume would look like health or like silence.
Glossary
- Psychological safety. The belief that you can take an interpersonal risk, such as raising a concern, without fear of negative consequences. It determines whether anything ever enters the pipeline.
- Escalation. The process of raising a concern to a level of authority able to investigate it and decide on it.
- Intake log. The single numbered, timestamped register every concern enters regardless of door, with one owner and a visible status field.
- Triage. The step that assigns a concern a severity tier, and with it a published acknowledgment and resolution clock and an investigation path.
- RACI. A role map assigning, for each decision, who is Responsible for the work, Accountable for the decision, Consulted before it, and Informed after. Exactly one name belongs in the Accountable column.
- Investigation protocol. The documented process for investigating a concern: what data is collected, how analysis is run, what timeline applies, and how findings are recorded.
- Decision record. The closing artifact for an escalation, covering what was raised, how it was triaged, who investigated and found what, who decided, who was consulted and informed, and the follow-up commitment.
- Retaliation. Negative treatment of someone in response to their raising a concern. Unlawful in many contexts, and the fastest way to shut a reporting channel permanently.
Related Lessons
- Escalation Paths: When to Involve Legal, Compliance, DEI, or Leadership is the routing map this lesson deliberately does not duplicate. It covers which function owns which kind of decision and what evidence to bring each one, which is the input your triage step depends on.
- Decision Rules: Explicit Criteria for Escalation sits upstream of everything here, defining the written thresholds that determine what counts as an escalation in the first place, so a concern reaches your intake log by rule rather than by someone's discomfort.
- Remediation and Escalation: When and How to Act on Findings goes deeper on what happens once an investigation confirms a problem, including how to verify a fix actually held.
- Governance Structures: Committees, Roles, and Decision Authority describes the standing bodies whose members appear in your RACI.
- Feedback Loops: How to Report AI Errors and Improve System Performance covers the lower-stakes channel that catches tool problems before they become a Tier 1 escalation.
- Root Cause Analysis: Understanding Why Bias or Errors Occurred is the analytical discipline behind the investigation step, and what separates fixing a symptom from fixing a mechanism.
Closing
The uncomfortable lesson in Camille's first attempt is that she did everything right except build a machine. She spotted the concern, believed the person who raised it, and routed it to the correct three functions within a day. Six weeks later there was still no answer, because correct instincts do not survive contact with organizational ambiguity. What made her second attempt different was unglamorous: one log, one owner per record, published clocks, a single name in the Accountable column, a protocol for the investigation, a record that closes only when six questions are answered, and an answer that goes back to the person who spoke up.
Escalation processes are how an organization self-corrects, and the best of them are both rigorous and fair: rigorous enough that legitimate concerns are genuinely investigated, fair enough that the process does not become a vehicle for grievance or politics. Most organizations underinvest here, focusing on policy documents and skipping the part that makes the system real, which is the ability of any person to surface a concern and have it taken seriously. When you design yours, use the simplest test available: imagine raising a concern about your own manager tomorrow. You would want more than one door, confidentiality if you needed it, a thorough investigation rather than a dismissal, an answer at the end, and a guarantee against retaliation. Build that.
Key Takeaways
- Routing is not a process. Knowing who to call is the sibling skill; an escalation process is the machinery that tells those people what to do, by when, who decides, and how the answer returns. Three inboxes with no owner and no clock diffuse a concern rather than resolve it.
- Psychological safety is the input, not the preamble. A flawless pipeline processes nothing if people are afraid to use it. Safety is demonstrated by responding with curiosity, investigating fairly, reporting the outcome back, and thanking people whose concerns turn out to be nothing.
- Many doors, one intake log. Offer several ways to raise a concern, including an anonymous channel and periodic pulse questions, but route all of them into a single numbered, timestamped record with one owner and a visible status. A single-channel organization cannot hear about the person who owns the channel.
- Triage assigns a clock and a path. Published severity tiers mean a possible active harm gets a 72-hour decision while a quality improvement waits for the monthly review, and triage is also where credibility and scope get assessed on a written rubric.
- Exactly one person is Accountable for each decision. Write a RACI before concerns arrive so "who decides?" is already answered. Two names in that column recreate the diffusion problem; one name plus a defined threshold for high-stakes calls makes decisions move.
- Investigate on a protocol and write findings with numbers. State the population, the rates, and the strength of the evidence explicitly. Once bias is confirmed, stop rather than waiting for more data, then match the remedy to the mechanism: retrain, change the process, add human review, modify criteria, and audit past decisions made under the flawed condition.
- The decision record is the accountability artifact. Close every escalation with a signed record covering what was raised, how it was triaged, who investigated and found what, who decided, who was consulted and informed, and the follow-up. Regulators credit documented processes that were followed, not good intentions.
- Close the loop or the channel dies. Return the outcome to named reporters directly and to anonymous reporters through a de-identified team summary. When people see their concern moved something, reporting goes up; when answers never come back, it silently stops.
- The process must review itself on a cadence. Monthly review of open cases and quarterly review of volume, doors, and SLA performance turn escalation into something that improves. A governance process is only as real as the last concern it actually resolved and returned.
Frequently Asked Questions
Do we really need an anonymous channel if our managers are approachable? Yes, and the approachability of your managers is not the variable that decides it. The concerns an anonymous door unlocks are disproportionately the ones about the people who own the other doors, and no amount of individual fairness solves that structurally. People are consistently more willing to raise concerns when they can do it anonymously, even under leaders they trust. The cost of the extra door is small and the category of report it surfaces is one you would otherwise never receive, as the recruiter who could not report her own manager's interviewing demonstrates.
We confirmed a problem, but the fix will take a quarter. What do we do meanwhile? Stop relying on the flawed component now and remediate on its own timeline. Once bias is confirmed you have enough evidence to act, and waiting for more data while the tool keeps running means every candidate processed in the interim is evaluated by the thing you already know is broken. Pause the affected function, fall back to human review, tell the team why, and run the deeper remedy in parallel. Then do the step most teams skip: audit the decisions already made under the flawed condition and determine whether any need reconsidering.
How do we know the process itself is working rather than just existing? Measure the pipeline, not the paperwork. Look at how many concerns arrive and through which doors, how long each tier takes against its published SLA, how many records stalled, and whether any closed without an answer going back to the reporter. Read the volume carefully: rising anonymous submissions after a visible outcome is a healthy signal, while a quiet channel is more often a dead one than a clean organization.
Skill.re