Skip to Content

ISO 37002 Whistleblowing, Step by Step

The four steps and three principles of the standard, turned into a channel that leaves evidence of each one.

Talk to us on WhatsApp See the whistleblower channel See every service

ISO 37002:2021 gives guidelines for a whistleblowing management system built on trust, impartiality and protection, in four steps: receiving, assessing, addressing and concluding reports of wrongdoing. The COX whistleblower channel turns each step into a stage of the case, and records its date, who handled it and why each decision was made.

What ISO 37002 Is

  • An international standard published by ISO in 2021, titled "Whistleblowing management systems: Guidelines".
  • Written as guidelines: it recommends what a whistleblowing system should do rather than setting requirements to certify against.
  • Meant for any organization, whatever its type, size or activity, public, private or not-for-profit.
  • Built on the common structure of the ISO management system standards, so it can stand alone or sit inside a wider management system.

Three Principles, Three Sets of Controls

The standard asks that trust, impartiality and protection run through the whole system. This is where each one shows up in the channel.

The principle of trust

  • Anonymous or confidential reporting, at the reporter's choice
  • No IP address or browser kept with any report
  • Automatic acknowledgment and a follow-up page with code and key
  • Deadlines to acknowledge and to answer, with reminders

The principle of impartiality

  • Users named in a report cannot read it, whatever their role
  • Reports about compliance or management go to alternate reviewers
  • A dated declaration of no conflict before investigating
  • Every decision with its reason, dismissals included

The principle of protection

  • Retaliation risk and protective measures in every evaluation
  • A retaliation check scheduled months after closing
  • Retaliation reported by the reporter as a new, linked case
  • Access limited to the channel role of each company

The Four Steps in the Channel

What the standard covers at each step, and what COX records.

1

Receiving reports

The standard distinguishes open, confidential and anonymous reporting. This step is about how a report reaches the organization.

In COX: a public link per company, a form with evidence files, a reference and an automatic acknowledgment, and a case code and secret key shown once. The case starts as Received.

2

Assessing reports

The standard calls the first assessment triage: categorize, take preliminary measures, prioritize and assign. It also asks to assess the risk of detrimental conduct against the reporter.

In COX: the Under Evaluation stage, with admissibility and its reason, category, severity, urgency, retaliation risk and measures, investigator and conflict declaration. Or dismissal with a justification.

3

Addressing reports

Addressing the reported wrongdoing, protecting and supporting the reporter, dealing with detrimental conduct and protecting the people a report names.

In COX: the In Investigation stage, with notes, findings and messages to the reporter. People named in the report are kept out of it, and retaliation can be reported from the follow-up page.

4

Concluding cases

Bringing each case to a close.

In COX: Closed with a result and an explanation, or Dismissed with a justification. The reporter reads the outcome on the follow-up page, and a retaliation check is scheduled.

What COX Covers, and What Stays With You

The channel handles

  • Operating the four steps, from the report to the conclusion
  • Confidentiality and access control of every case
  • Deadlines and reminders
  • The record: stages, decisions, messages and evidence, none of it deletable

Your organization decides

  • The whistleblowing policy and the commitment of top management
  • Who handles reports and who reviews them when the team is involved
  • Awareness and training of your people
  • Evaluating how the system performs and improving it, with the times the stage history gives you

COX does not certify your organization against ISO 37002, and using the channel does not by itself make a management system.

Frequently Asked Questions

ISO 37002 is written as guidelines, as its title says: it recommends what a whistleblowing system should do instead of setting requirements to certify against. Ask your certification body what, if anything, it can assess. COX gives you the tool and the evidence, not a certificate.

No. The standard says its guidelines apply to any organization, whatever its type or size, and that how far they are applied depends on its context. A small firm can follow the same four steps with fewer people.

No. An ISO standard is voluntary, and the law of your country and the rules of your regulator come first. The same channel serves both: it records what a regulator asks about each report.

The ones your company sets: days to acknowledge a report and months to give the reporter a first answer, 7 days and 3 months by default. Each report keeps the deadlines in force the day it arrived, and the team gets reminders before they expire.

Through the follow-up page. The reporter enters with the case code and secret key they received when reporting, reads the team's messages and answers them, and can add files. Their identity never enters the conversation.

ISO 37002 is a standard of the International Organization for Standardization. COX is not affiliated with ISO, and this page summarizes the standard without replacing it. It is not legal advice.

Put the Four Steps to Work

Open your company's channel and handle the first report with every step on record.

Talk to us on WhatsApp See every service Estimate your costs

Escríbenos por WhatsApp