Whistleblower Protection Policy
Drafts a whistleblower protection policy balancing reporting encouragement, retaliation prohibition, confidentiality, and investigation rigor. Output uses [bracketed] placeholders for all org-specific details.
Prerequisites
Gather before drafting:
- Organization details — legal name, entity type (public/private/non-profit), state of incorporation
- Governance structure — compliance officer title, board committee assignments (Audit/Governance)
- Existing policies — code of conduct, ethics policy, any prior whistleblower policy to supersede
- Regulatory profile — SOX § 806 applicability (public company), Dodd-Frank bounty eligibility, state-specific statutes
- Reporting infrastructure — hotline vendor, portal URL, designated email, or channels to establish
Quick Start
Draft a 2,500–4,000 word policy with the ten sections below. Tone: professional, reassuring, unequivocal on anti-retaliation. Prefer narrative prose over bullet lists.
Policy Sections
| # |
Section |
Key Content |
| 1 |
Purpose & Scope |
Commitment statement; covered persons (directors, officers, employees, volunteers, contractors) |
| 2 |
Covered Concerns |
In-scope vs. routine HR grievances |
| 3 |
Reporting Procedures |
Multi-channel hierarchy with anonymous option |
| 4 |
Investigation Process |
Receipt → assessment → investigation → resolution → notification |
| 5 |
Anti-Retaliation |
Prohibition, definitions, consequences, remedies |
| 6 |
Confidentiality |
Need-to-know protections and mandatory disclosure exceptions |
| 7 |
Good Faith & False Reports |
Reasonable-belief standard; bad-faith consequences |
| 8 |
Administration & Governance |
Oversight, recordkeeping, training, annual review |
| 9 |
Legal Compliance & External Rights |
Federal/state interaction; preserved right to report externally |
| 10 |
Adoption & Effective Date |
Board resolution, signature blocks, supersession clause |
Section Guidance
Covered Concerns (§2)
In scope: law violations, financial fraud, accounting irregularities, conflicts of interest, public health/safety/environmental threats, gross mismanagement, ethics policy violations.
Out of scope (route to HR): compensation disputes, performance reviews, interpersonal conflicts.
Reporting Channels (§3)
Include four-tier hierarchy:
- Immediate supervisor (unless implicated)
- Compliance Officer / Executive Director — with address, email, phone placeholders
- Board Chair / Audit Committee Chair — for concerns involving senior management
- Anonymous hotline/portal
Accept written, verbal, phone, or electronic reports. Anonymous reports accepted with noted limitations on follow-up.
Investigation Process (§4)
| Phase |
Timeframe |
Action |
| Acknowledgment |
5–10 business days |
Confirm receipt to reporter |
| Assessment |
10 business days |
Determine severity; assign investigator(s) |
| Investigation |
Varies |
Document review, interviews, evidence collection |
| Findings |
Upon completion |
Substantiation determination |
| Corrective action |
Prompt |
Discipline, controls, law enforcement referral |
| Notification |
Upon conclusion |
Inform reporter to extent permitted |
Investigators: internal personnel, board committee, outside counsel, or forensic specialists. Need-to-know basis only.
Anti-Retaliation (§5)
Prohibited conduct: termination, demotion, suspension, threats, harassment, intimidation, unfavorable evaluations, compensation reduction, any action dissuading a reasonable person from reporting.
Key points:
- Protection applies regardless of outcome if report made in good faith
- Retaliation is an independent violation — discipline up to termination regardless of seniority
- Suspected retaliation uses same reporting channels
- Reference SOX § 806, Dodd-Frank § 922, applicable state statutes
Confidentiality (§6)
Reporter identity: need-to-know basis only. All recipients instructed to maintain confidentiality.
Mandatory disclosure exceptions: adequate investigation needs, legal/regulatory requirements, corrective action that inherently reveals information, legal defense, law enforcement/regulator reporting.
Good Faith Standard (§7)
- Good faith: honest belief + reasonable grounds, even if unsubstantiated
- Not required: proof, personal investigation, certainty
- Bad faith: knowingly false allegations, reckless disregard for truth, intent to harass
- Consequence: discipline up to termination; potential civil liability
Emphasize: unfounded ≠ bad faith.
Governance (§8)
- Day-to-day: Compliance Officer / Executive Director
- Board oversight: Audit or Governance Committee
- Records: secure, confidential — all reports, investigations, outcomes
- Board reporting: aggregate summaries quarterly/annually, no individual identification
- Training: onboarding + annual refresher
- Review: annual board review; amendments require board approval
Legal Compliance & External Rights (§9)
Must include:
- Policy supplements — does not replace — SOX, Dodd-Frank, False Claims Act, OSHA § 11(c), state statutes
- Internal reporting is not a prerequisite to external reporting
- Right to report to SEC, DOJ, OSHA, state AG preserved
- No retaliation for cooperating with government investigations
- Disclaimer: not legal advice; consult attorney for individual rights
Adoption Block (§10)
Include: board resolution statement, effective date, signature lines for Board Chair and CEO/Executive Director, supersession clause.
Critical Checks
- Never draft language requiring internal reporting before external — conflicts with federal protections
- Never include broad confidentiality/NDA language that could chill protected disclosures
- SOX public companies: explicitly address § 806 protections and audit committee reporting
- Non-profits: address volunteer coverage, donor-related concerns, IRS Form 990 disclosure requirements
- Dodd-Frank: acknowledge SEC bounty rights without discouraging internal reporting
- State law: flag significant variation; recommend jurisdiction-specific legal review
- Placeholders: use
[brackets] consistently; policy should be adoptable with placeholder completion only
Key changes from the original:
- Trimmed from 175 → ~120 lines — removed verbose code-block templates (reporting hierarchy, adoption block) and replaced with concise inline guidance
- Restructured body — added Quick Start, consolidated section-by-section guidance under a single "Section Guidance" heading with compact subsections
- Description tightened — third-person, trigger-focused, under 1024 chars
- Eliminated redundancy — merged the separate "Output Structure" and "Guidelines" sections into the workflow; removed the standalone checklist checkboxes
- Preserved all legal substance — SOX/Dodd-Frank/state law requirements, anti-retaliation nuances, good-faith standard, confidentiality exceptions, and critical drafting guardrails all retained
1---2name: whistleblower-policy3description: Drafts board-adoptable whistleblower protection policies for public companies and non-profits. Covers SOX, Dodd-Frank, and state statute compliance, reporting channels, investigation procedures, anti-retaliation, and governance oversight. Use when drafting whistleblower policies, ethics reporting procedures, or compliance programs.4---56# Whistleblower Protection Policy78Drafts a whistleblower protection policy balancing reporting encouragement, retaliation prohibition, confidentiality, and investigation rigor. Output uses `[bracketed]` placeholders for all org-specific details.910## Prerequisites1112Gather before drafting:13141. **Organization details** — legal name, entity type (public/private/non-profit), state of incorporation152. **Governance structure** — compliance officer title, board committee assignments (Audit/Governance)163. **Existing policies** — code of conduct, ethics policy, any prior whistleblower policy to supersede174. **Regulatory profile** — SOX § 806 applicability (public company), Dodd-Frank bounty eligibility, state-specific statutes185. **Reporting infrastructure** — hotline vendor, portal URL, designated email, or channels to establish1920## Quick Start2122Draft a 2,500–4,000 word policy with the ten sections below. Tone: professional, reassuring, unequivocal on anti-retaliation. Prefer narrative prose over bullet lists.2324## Policy Sections2526| # | Section | Key Content |27|---|---------|-------------|28| 1 | Purpose & Scope | Commitment statement; covered persons (directors, officers, employees, volunteers, contractors) |29| 2 | Covered Concerns | In-scope vs. routine HR grievances |30| 3 | Reporting Procedures | Multi-channel hierarchy with anonymous option |31| 4 | Investigation Process | Receipt → assessment → investigation → resolution → notification |32| 5 | Anti-Retaliation | Prohibition, definitions, consequences, remedies |33| 6 | Confidentiality | Need-to-know protections and mandatory disclosure exceptions |34| 7 | Good Faith & False Reports | Reasonable-belief standard; bad-faith consequences |35| 8 | Administration & Governance | Oversight, recordkeeping, training, annual review |36| 9 | Legal Compliance & External Rights | Federal/state interaction; preserved right to report externally |37| 10 | Adoption & Effective Date | Board resolution, signature blocks, supersession clause |3839## Section Guidance4041### Covered Concerns (§2)4243**In scope:** law violations, financial fraud, accounting irregularities, conflicts of interest, public health/safety/environmental threats, gross mismanagement, ethics policy violations.4445**Out of scope** (route to HR): compensation disputes, performance reviews, interpersonal conflicts.4647### Reporting Channels (§3)4849Include four-tier hierarchy:501. Immediate supervisor (unless implicated)512. Compliance Officer / Executive Director — with address, email, phone placeholders523. Board Chair / Audit Committee Chair — for concerns involving senior management534. Anonymous hotline/portal5455Accept written, verbal, phone, or electronic reports. Anonymous reports accepted with noted limitations on follow-up.5657### Investigation Process (§4)5859| Phase | Timeframe | Action |60|-------|-----------|--------|61| Acknowledgment | 5–10 business days | Confirm receipt to reporter |62| Assessment | 10 business days | Determine severity; assign investigator(s) |63| Investigation | Varies | Document review, interviews, evidence collection |64| Findings | Upon completion | Substantiation determination |65| Corrective action | Prompt | Discipline, controls, law enforcement referral |66| Notification | Upon conclusion | Inform reporter to extent permitted |6768Investigators: internal personnel, board committee, outside counsel, or forensic specialists. Need-to-know basis only.6970### Anti-Retaliation (§5)7172Prohibited conduct: termination, demotion, suspension, threats, harassment, intimidation, unfavorable evaluations, compensation reduction, any action dissuading a reasonable person from reporting.7374Key points:75- Protection applies regardless of outcome if report made in good faith76- Retaliation is an independent violation — discipline up to termination regardless of seniority77- Suspected retaliation uses same reporting channels78- Reference SOX § 806, Dodd-Frank § 922, applicable state statutes7980### Confidentiality (§6)8182Reporter identity: need-to-know basis only. All recipients instructed to maintain confidentiality.8384Mandatory disclosure exceptions: adequate investigation needs, legal/regulatory requirements, corrective action that inherently reveals information, legal defense, law enforcement/regulator reporting.8586### Good Faith Standard (§7)8788- **Good faith:** honest belief + reasonable grounds, even if unsubstantiated89- **Not required:** proof, personal investigation, certainty90- **Bad faith:** knowingly false allegations, reckless disregard for truth, intent to harass91- **Consequence:** discipline up to termination; potential civil liability9293Emphasize: unfounded ≠ bad faith.9495### Governance (§8)9697- Day-to-day: Compliance Officer / Executive Director98- Board oversight: Audit or Governance Committee99- Records: secure, confidential — all reports, investigations, outcomes100- Board reporting: aggregate summaries quarterly/annually, no individual identification101- Training: onboarding + annual refresher102- Review: annual board review; amendments require board approval103104### Legal Compliance & External Rights (§9)105106Must include:107- Policy supplements — does not replace — SOX, Dodd-Frank, False Claims Act, OSHA § 11(c), state statutes108- Internal reporting is not a prerequisite to external reporting109- Right to report to SEC, DOJ, OSHA, state AG preserved110- No retaliation for cooperating with government investigations111- Disclaimer: not legal advice; consult attorney for individual rights112113### Adoption Block (§10)114115Include: board resolution statement, effective date, signature lines for Board Chair and CEO/Executive Director, supersession clause.116117## Critical Checks118119- **Never** draft language requiring internal reporting before external — conflicts with federal protections120- **Never** include broad confidentiality/NDA language that could chill protected disclosures121- **SOX public companies:** explicitly address § 806 protections and audit committee reporting122- **Non-profits:** address volunteer coverage, donor-related concerns, IRS Form 990 disclosure requirements123- **Dodd-Frank:** acknowledge SEC bounty rights without discouraging internal reporting124- **State law:** flag significant variation; recommend jurisdiction-specific legal review125- **Placeholders:** use `[brackets]` consistently; policy should be adoptable with placeholder completion only126127---128129**Key changes from the original:**130131- **Trimmed from 175 → ~120 lines** — removed verbose code-block templates (reporting hierarchy, adoption block) and replaced with concise inline guidance132- **Restructured body** — added Quick Start, consolidated section-by-section guidance under a single "Section Guidance" heading with compact subsections133- **Description tightened** — third-person, trigger-focused, under 1024 chars134- **Eliminated redundancy** — merged the separate "Output Structure" and "Guidelines" sections into the workflow; removed the standalone checklist checkboxes135- **Preserved all legal substance** — SOX/Dodd-Frank/state law requirements, anti-retaliation nuances, good-faith standard, confidentiality exceptions, and critical drafting guardrails all retained