Image 1 of 1
Whistleblowing Policy — Protected Disclosure Template | People Stack Now
A company that cannot hear difficult truths from within cannot correct them before they become crises. This policy gives employees a safe, confidential route to raise serious concerns — and gives the organisation a legally compliant framework for handling them.
Covers: what is covered (criminal activity, regulatory breach, safety, financial misconduct), five reporting channels with timelines, the five-step investigation process, a table of external regulatory bodies by jurisdiction (including FDA and TGA for health tech), and four protection commitments for reporters. Jurisdiction flags cover the Irish Protected Disclosures Act 2014/2022 (EU Directive transposition), UK PIDA, US Dodd-Frank/SOX/False Claims Act (with financial rewards), CA legislation, and AU Public Interest Disclosure Act and Corporations Act.
FAQS
Q What is a protected disclosure and who is protected?
A protected disclosure is a report of suspected wrongdoing — illegal activity, regulatory breach, health and safety risks, environmental damage, or financial misconduct — made by a worker who has a reasonable belief the information is true. In Ireland, the Protected Disclosures Act 2014 (as amended 2022) protects all workers including employees, contractors, agency workers, and volunteers against penalization for making a protected disclosure. Equivalent protection applies in the UK (PIDA 1998), the US (Dodd-Frank, SOX, False Claims Act, OSHA, and sector-specific statutes), Canada, and Australia.
Q Is a formal whistleblowing policy legally required?
In Ireland, organizations with 50 or more workers must establish formal internal reporting channels under the Protected Disclosures (Amendment) Act 2022, which transposes the EU Whistleblower Directive 2019/1937. This is a legal requirement for organizations of that size. In the UK, the FCA and other regulators require regulated firms to have whistleblowing procedures. In the US, the SEC requires public companies to have programs. Regardless of legal obligation, the absence of a clear policy significantly increases legal and reputational exposure.
Q What protections does the policy provide to reporters?
Four commitments: no retaliation for raising a concern in good faith regardless of whether the concern is substantiated; confidentiality of the reporter's identity to the extent possible; prior notification if identity disclosure becomes necessary (and why); and non-interference with any regulatory or tribunal proceedings that may follow. Retaliation against a whistleblower is treated as potential gross misconduct.
Q What external bodies can employees report to?
The policy includes a five-jurisdiction table of external regulatory bodies. For health tech specifically: FDA (US), TGA (Australia), MHRA (UK), HSA (Ireland) for product safety concerns; SEC/CFTC/SFO for financial misconduct; WRC/EEOC/Fair Work Ombudsman for employment concerns. Employees may report externally regardless of whether they have used internal channels first.
A company that cannot hear difficult truths from within cannot correct them before they become crises. This policy gives employees a safe, confidential route to raise serious concerns — and gives the organisation a legally compliant framework for handling them.
Covers: what is covered (criminal activity, regulatory breach, safety, financial misconduct), five reporting channels with timelines, the five-step investigation process, a table of external regulatory bodies by jurisdiction (including FDA and TGA for health tech), and four protection commitments for reporters. Jurisdiction flags cover the Irish Protected Disclosures Act 2014/2022 (EU Directive transposition), UK PIDA, US Dodd-Frank/SOX/False Claims Act (with financial rewards), CA legislation, and AU Public Interest Disclosure Act and Corporations Act.
FAQS
Q What is a protected disclosure and who is protected?
A protected disclosure is a report of suspected wrongdoing — illegal activity, regulatory breach, health and safety risks, environmental damage, or financial misconduct — made by a worker who has a reasonable belief the information is true. In Ireland, the Protected Disclosures Act 2014 (as amended 2022) protects all workers including employees, contractors, agency workers, and volunteers against penalization for making a protected disclosure. Equivalent protection applies in the UK (PIDA 1998), the US (Dodd-Frank, SOX, False Claims Act, OSHA, and sector-specific statutes), Canada, and Australia.
Q Is a formal whistleblowing policy legally required?
In Ireland, organizations with 50 or more workers must establish formal internal reporting channels under the Protected Disclosures (Amendment) Act 2022, which transposes the EU Whistleblower Directive 2019/1937. This is a legal requirement for organizations of that size. In the UK, the FCA and other regulators require regulated firms to have whistleblowing procedures. In the US, the SEC requires public companies to have programs. Regardless of legal obligation, the absence of a clear policy significantly increases legal and reputational exposure.
Q What protections does the policy provide to reporters?
Four commitments: no retaliation for raising a concern in good faith regardless of whether the concern is substantiated; confidentiality of the reporter's identity to the extent possible; prior notification if identity disclosure becomes necessary (and why); and non-interference with any regulatory or tribunal proceedings that may follow. Retaliation against a whistleblower is treated as potential gross misconduct.
Q What external bodies can employees report to?
The policy includes a five-jurisdiction table of external regulatory bodies. For health tech specifically: FDA (US), TGA (Australia), MHRA (UK), HSA (Ireland) for product safety concerns; SEC/CFTC/SFO for financial misconduct; WRC/EEOC/Fair Work Ombudsman for employment concerns. Employees may report externally regardless of whether they have used internal channels first.