Get useful tips, learn best practices and read the latest newsThe Whistlelink Blog

ISO 37002:2021 Whistleblowing Management Systems

ISO 37002 Whistleblowing

Download our free whitepaper:

How to get compliant with the Whistleblowing Law

by Livia Schiavi, Compliance Specialist Bureau Veritas Italia S.p.A.

ISO – International Organization for Standardization – has developed the first standard entirely dedicated to whistleblowing management: the ISO 37002:2021 Whistleblowing management systems — Guidelines standard.

The standard provides guidelines for the implementation, management, evaluation, maintenance, and improvement of a whistleblowing management system within an organisation. Like any ISO standard, it represents the international best practice that companies and organisations around the world can take as a model to structure their internal processes.

International standard for whistleblowing management systems

The decision to develop an international standard for whistleblowing management systems comes at an opportune time: the European Union has also intervened on the subject, adopting the Whistleblowing Directive 2019/1937 concerning the protection of persons who report wrongdoing. Many organisations across Europe will have to implement or improve their whistleblowing programme for the first time.

Whistleblowing is defined in ISO 37002 as the act of reporting alleged violations or risks of non-compliance. Based on the principles of trust, impartiality, and protection, it aims to guide organizations in the management of the entire whistleblowing cycle, divided into four phases:

  1. Identification and reporting of alleged unlawful acts: Employees of an organisation must receive training on the complaints channel in order to properly carry out the report;
  2. Assessment of reports: The management system will have to specify the procedure for classifying communications, also taking into account the risk that the reported event may entail;
  3. Means of dealing with reporting: The management system must establish channels for whistleblowing, how to submit and receive complaints;
  4. Closure of reporting cases: The management system must also provide for specific investigative rules, as well as adequate protection and follow-up measures for the whistleblower and those who may be the subject of the report related to the complaint.

ISO 37002 Whistleblowing management systems is applicable to any type of organisation

whether private, public or non-profit, regardless of size, nature of the business, size or geographical location.

It is a standard that contains recommendations and best practices for organisations, so it is not certifiable. Following the high-level structure (HLS) it can be implemented independently and integrated with the management systems already present in organizations (e.g., ISO 9001, ISO 37001:2016 Management system for the prevention of corruption, ISO 37301:2021 Compliance Management System). As such, the added value will be to consider whistleblowing as part of corporate compliance. It will be integrated into the processes and commitments undertaken by the organisation, not only linked to Legislative Decree 231/01 or to the laws on the prevention of corruption.

Organisations that want to be aware of the ability of their whistleblowing system to identify and deal with offenses according to international guidelines, will be able to submit the ISO 37002 management system to a third-party evaluation. This will be an independent entity whose sole focus is to evaluate the degree of alignment with best practice.

In addition to being a valuable element of comparison with the internal functions of the organisation, the third-party assessment also translates into a certification that guarantees stakeholders the maturity of whistleblowing processes in line with the best practice ISO 37002. Thus, increasing the reputation and credibility of the subject who applies it. The ISO 37002 assessment is a valid tool to demonstrate to society, markets, regulatory authorities, and stakeholders the practices that are capable of intercepting possible issues. The course includes an initial assessment, followed by two additional evaluations after 12 and 24 months.

To read more about ISO 37002 Whistleblowing management systems, please visit Bureau Veritas. You can read more about the assessment process here.

Are you interested in learning more about a whistleblowing service and safe internal reporting channels? Read more about the EU Whistleblowing Directive here and at EUR-Lex.

Are you looking for a safe and secure whistleblowing solution? Read more here.

Would you like to discuss a whistleblowing system for your organisation?
Please contact us or book a free demo!

If you have any thoughts about this article or would like to know more about Whistlelink, we’d love to hear from you.

Are you looking for a safe and secure whistleblowing solution for your organisation?Please book a free demo of our system in the calendar below!

Talk with Territory Manager
Annelie Demred

0046 (0)706 83 82 88

WEBINARThe Whistleblowing Law

Annelie DemredVP, Strategy and Growth

Are you up to date?

Wednesday   |   11:00 – 11:30

WHISTLELINK BLOGWhat to read next...​

A new Polish draft law has officially introduced "the whistleblower"
Enhancing the Vatican’s whistleblowing strategy: Transparency, anonymity and beyond
Whistleblowing in the Hospitality Industry: Protecting customers, employees, businesses, and reputation
Whistlelink resources

Download the Whitepaper

Nice to meet you!

Get in touch

Our team would like to offer you a free demo of Whistlelink.
Please select a suitable time in our calendar.

Talk with Territory Manager
Annelie Demred

0046 (0)706 83 82 88

HAPPY TO MEET YOU!

Get in touch

Our team is ready to answer your questions. Find the answer by visiting our support centre, or fill out the form below and we'll be in touch as soon as possible. Or simply give us a call!

Talk with Territory Manager
Annelie Demred

0046 (0)706 83 82 88

HAPPY TO MEET YOU!

Get in touch

Our team is ready to answer your questions. Find the answer by visiting our support centre, or fill out the form below and we'll be in touch as soon as possible. Or simply give us a call!

Talk with Territory Manager
Annelie Demred

0046 (0)706 83 82 88