Overview
ISO 37002:2021 - Whistleblowing management systems - Guidelines provides practical guidance for establishing, implementing and maintaining an effective whistleblowing management system. Built on the core principles of trust, impartiality and protection, the standard describes a lifecycle approach in four steps: receiving, assessing, addressing, and concluding reports of wrongdoing. It is generic and adaptable for organizations of any type, size or sector and may be implemented as a stand‑alone system or integrated with other management systems.
Keywords: ISO 37002, whistleblowing management systems, whistleblower protection, whistleblowing policy, governance, compliance
Key topics and technical requirements
ISO 37002 outlines structure and content consistent with ISO’s harmonized management‑system format. Major topics include:
- Context of the organization (Clause 4): understanding internal/external drivers, interested parties and determining system scope.
- Leadership (Clause 5): governance roles, top management commitment, whistleblowing policy, responsibilities and authorities.
- Planning (Clause 6): actions to address risks and opportunities, objectives and change management.
- Support (Clause 7): resourcing, competence, awareness, communication, documented information, data protection and confidentiality.
- Operation (Clause 8): operational controls for receiving, assessing, addressing and concluding reports; protecting whistleblowers, subjects and other interested parties; preventing detrimental conduct.
- Performance evaluation (Clause 9): monitoring, indicators, internal audit and management review.
- Improvement (Clause 10): continual improvement, nonconformity handling and corrective action.
The standard emphasizes practical safeguards such as impartial case handling, confidentiality controls and mechanisms to protect whistleblowers and those implicated.
Practical applications
Organizations use ISO 37002 to:
- Design or improve internal whistleblowing policies and reporting channels.
- Ensure consistent, timely handling of misconduct, fraud, corruption or safety risks.
- Demonstrate governance, ethical behavior and regulatory compliance to regulators, investors and stakeholders.
- Protect whistleblowers and reduce retaliation through documented procedures and protections.
- Integrate whistleblowing processes into broader compliance, risk management or ethics programs.
Who should use this standard
- Compliance, legal and governance teams wanting a structured whistleblowing program.
- HR and ethics officers responsible for culture, reporting channels and staff protection.
- Small, medium and large enterprises, public sector bodies and non‑profits seeking to align with best practices.
- Auditors and consultants advising on whistleblower frameworks or regulatory readiness.
Related standards
ISO 37002 is complementary to other ISO management standards (same harmonized structure), and can be implemented alongside governance, risk and compliance standards for a unified management approach.