Whistleblower Policy
1. Purpose
The purpose of this Whistleblower Policy is to provide a safe, confidential, and accessible process for individuals to report suspected wrongdoing, misconduct, unethical behaviour, fraud, corruption, abuse, or other serious concerns relating to the organisation.
The policy is intended to encourage individuals to raise genuine concerns without fear of retaliation and to ensure that reported concerns are handled appropriately, fairly, and confidentially.
2. Scope
This policy applies to individuals who have information relating to the organisation or its activities, including:
-
Board members and directors.
-
Committee members.
-
Officers and office bearers.
-
Employees.
-
Members.
-
Volunteers.
-
Contractors and consultants.
-
Former employees or members, where appropriate.
-
Other individuals who have a legitimate relationship with the organisation.
3. What Is Whistleblowing?
Whistleblowing is the reporting of information concerning suspected wrongdoing, misconduct, illegal activity, unethical behaviour, or serious organisational concerns.
A whistleblower may report a concern where they reasonably believe that something has occurred, is occurring, or may occur that is inconsistent with the organisation’s responsibilities, policies, values, or applicable requirements.
4. Matters That May Be Reported
Concerns that may be reported under this policy include:
-
Fraud or suspected fraud.
-
Theft or misuse of organisational funds or property.
-
Corruption or bribery.
-
Financial misconduct or serious financial irregularities.
-
Conflicts of interest that have not been properly disclosed.
-
Serious breaches of organisational policies.
-
Abuse of authority or position.
-
Harassment, discrimination, bullying, or other serious misconduct.
-
Unlawful or unethical conduct.
-
Manipulation or falsification of records.
-
Serious breaches of confidentiality or information security.
-
Conduct that may cause significant harm to individuals or the organisation.
-
Attempts to conceal wrongdoing.
-
Other serious concerns that should reasonably be brought to the attention of the organisation.
5. What Is Not Normally Covered
Routine complaints, interpersonal disagreements, or ordinary workplace or membership concerns should normally be addressed through the organisation’s applicable Grievance Policy, Complaints Policy, or other appropriate procedure.
However, a matter initially raised as a grievance or complaint may be handled under this policy if it involves serious wrongdoing or falls within the scope of whistleblowing.
6. Who Can Make a Report?
A report may be made by any individual who has reasonable grounds to believe that wrongdoing or serious misconduct has occurred or may occur.
A person does not need to have complete evidence before making a report. However, reports should be made honestly and in good faith and should provide as much relevant information as reasonably possible.
7. How to Make a Report
A whistleblower may report a concern through the reporting channels designated by the organisation.
Where possible, a report should include:
-
A description of the concern.
-
The individuals or organisations involved.
-
The date, location, or timeframe of the suspected conduct.
-
Relevant documents, records, or other evidence.
-
Names of potential witnesses, where appropriate.
-
Any other information that may assist with assessing the concern.
Reports may be made in writing or through another approved reporting channel where available.
8. Anonymous Reports
The organisation may accept anonymous reports where its reporting systems allow for them.
Individuals making anonymous reports should provide sufficient information to allow the concern to be assessed and investigated.
Where a report is anonymous, the organisation may have limited ability to obtain additional information, provide updates, or communicate the outcome.
9. Confidentiality
Reports made under this policy will be treated as confidential to the extent reasonably possible.
Information concerning the whistleblower, the allegations, evidence, witnesses, and investigation will only be shared with individuals who require access for the purpose of assessing, investigating, managing, or resolving the matter.
Confidentiality may be limited where disclosure is required by law, necessary to conduct a fair investigation, or necessary to protect individuals or the organisation.
10. Protection from Retaliation
The organisation does not tolerate retaliation against an individual who raises a genuine concern in good faith.
Retaliation may include:
-
Threats or intimidation.
-
Harassment or bullying.
-
Unfair treatment.
-
Victimisation.
-
Unjustified disciplinary action.
-
Unlawful termination or adverse treatment.
-
Attempts to damage an individual’s reputation or position because they made a report.
Any individual who believes they have experienced retaliation should report the matter through the appropriate organisational process.
11. Good-Faith Reporting
Individuals are encouraged to report concerns where they have reasonable grounds to believe that wrongdoing may have occurred.
A report does not need to be proven correct for the whistleblower to receive protection, provided the report was made honestly and in good faith.
Individuals should avoid knowingly making false, misleading, or malicious allegations.
12. False or Malicious Reports
Knowingly making a false, deliberately misleading, or malicious report may constitute misconduct and may be addressed under the organisation’s applicable policies and procedures.
A report will not be considered false or malicious simply because an investigation does not substantiate the allegation.
13. Assessment of Reports
All reports will be assessed to determine:
-
Whether the matter falls within the scope of this policy.
-
Whether immediate action is required.
-
Whether an investigation is appropriate.
-
Whether the matter should be referred to another organisational process.
-
Whether external reporting or notification may be required.
The organisation may appoint an appropriate person, committee, or independent investigator to assess the matter.
14. Investigation
Where an investigation is required, it should be conducted as fairly, objectively, and confidentially as reasonably possible.
An investigation may involve:
-
Reviewing documents and records.
-
Interviewing relevant individuals.
-
Reviewing financial or operational information.
-
Examining electronic records where authorised.
-
Obtaining specialist or independent advice.
-
Taking other reasonable steps necessary to establish the relevant facts.
Individuals involved in an investigation are expected to cooperate and provide truthful information.
15. Conflicts of Interest
Any person responsible for receiving, assessing, investigating, or deciding a whistleblower matter must disclose any actual, potential, or perceived conflict of interest.
Where a conflict exists, the organisation may appoint another suitably independent person or body to manage the matter.
16. Interim Measures
Where appropriate, the organisation may take temporary measures while a matter is being assessed or investigated.
These measures may include:
-
Restricting access to certain information or systems.
-
Separating individuals involved in the matter.
-
Protecting records or evidence.
-
Temporarily changing reporting arrangements.
-
Taking steps to protect the whistleblower or other individuals.
-
Other reasonable measures necessary to prevent further harm or interference with the investigation.
17. Reporting to External Authorities
Nothing in this policy prevents an individual from making a disclosure to an appropriate external authority where permitted or required by applicable law.
Where the organisation becomes aware of conduct that may require reporting to a regulator, law-enforcement authority, or other external body, it may make the appropriate referral or notification.
18. Outcome of a Report
Once an investigation or assessment has been completed, the organisation will determine an appropriate outcome based on the available information.
Where appropriate and legally permissible, the whistleblower may be informed that the matter has been addressed.
The organisation may be unable to provide detailed information about the outcome where doing so would breach confidentiality, privacy, employment, disciplinary, or legal requirements.
19. Recordkeeping
The organisation will maintain appropriate records relating to whistleblower reports, assessments, investigations, and outcomes.
Records will be stored securely and access will be restricted to authorised individuals.
Records should be retained in accordance with the organisation’s applicable recordkeeping and privacy requirements.
20. Responsibilities of the Organisation
The organisation is responsible for:
-
Providing appropriate channels for reporting concerns.
-
Taking genuine reports seriously.
-
Protecting confidentiality where reasonably possible.
-
Assessing reports appropriately.
-
Taking reasonable steps to investigate serious concerns.
-
Protecting whistleblowers from retaliation.
-
Managing conflicts of interest.
-
Maintaining appropriate records.
-
Taking corrective action where necessary.
21. Responsibilities of Individuals
Individuals making or participating in a report are expected to:
-
Provide truthful and accurate information.
-
Report concerns in good faith.
-
Preserve relevant evidence where possible.
-
Maintain appropriate confidentiality.
-
Cooperate with reasonable investigation requests.
-
Avoid retaliation or interference with the investigation.
-
Avoid knowingly making false or malicious allegations.
22. Relationship With Other Policies
This policy should be read together with the organisation’s:
-
Constitution and/or Bylaws
-
Member in Good Standing Policy
-
Grievance Policy
-
Confidentiality Policy
-
Conflict of Interest & Disclosure Policy
-
Code of Conduct
-
Ethics Policy
-
Disciplinary Policy
-
Fraud and Anti-Corruption Policy
-
Complaints Policy
-
Privacy and Data Protection Policy
23. Policy Review
This policy will be reviewed periodically to ensure that it remains effective, relevant, and consistent with the organisation’s governing documents, internal procedures, and applicable requirements.
Policy Owner: [Organisation/Department Name]
Effective Date: [Date]
Last Reviewed: [Date]
Next Review Date: [Date]
Version: [Version Number]