1. Which companies must have a whistleblower policy
    1. The large proprietary company test
  2. What your policy must contain
  3. Who can report, and what they can report
  4. The protections your people get, and their limits
    1. Confidentiality
    2. Protection from detriment
    3. Immunity from liability
    4. Compensation for detriment
  5. What happens if your company does not comply
  6. A practical compliance checklist
  7. When you should get legal help
  8. The threshold that catches private companies by surprise

Australian companies in three categories must have a written whistleblower policy: public companies, large proprietary companies and corporate trustees of APRA-regulated superannuation entities. The requirement sits in s 1317AI of the Corporations Act 2001 (Cth) (the Act), and it has applied since 1 January 2020. The policy must also be made available to your officers and employees, and failing to have one is an offence.

The obligation is easy to overlook because whistleblowing is often treated as a listed-company issue. In practice the test for a large proprietary company is modest: a private company with 50 or more employees can be in scope. And even if your company is not required to have a policy, the whistleblower protections in Part 9.4AAA of the Act still apply to anyone who reports concerns about your business. This guide sets out who must have a policy, what it must contain, the protections your people get when they speak up, and the consequences of not complying.

Which companies must have a whistleblower policy

Section 1317AI of the Act applies to three categories of entity:

  • Public companies: every public company, listed or unlisted, must have a policy and make it available to its officers and employees.
  • Large proprietary companies: a proprietary company that has been a large proprietary company for a financial year must have a policy in place from a date at least six months after the end of that financial year.
  • Corporate trustees of superannuation entities: a proprietary company that is the trustee of a registrable superannuation entity regulated by APRA must have a policy, regardless of its size.

ASIC has exempted public companies limited by guarantee that are not-for-profits or charities with annual consolidated revenue of less than $1 million from the policy requirement, under the ASIC Corporations (Whistleblower Policies) Instrument 2019/1146.

The large proprietary company test

Whether a proprietary company is large is decided under s 45A(3) of the Act against the financial year just ended. A company is large if it satisfies at least two of the following three tests:

Test Threshold
Consolidated revenue for the financial year $25 million or more
Consolidated gross assets at year end $12.5 million or more
Employees at year end 50 or more

Employees are counted on a full-time equivalent basis, and the revenue and asset figures are consolidated with entities the company controls and calculated under accounting standards. Some older guides quote higher figures, such as $50 million revenue, $25 million assets or 100 employees; those figures are out of date. The thresholds above are the ones currently in the Act, so check the current text of s 45A before assuming your company is exempt.

Two timing points are worth noting. First, the policy obligation for a large proprietary company does not bite the moment the company crosses a threshold; it applies from the later financial year, at least six months after the end of the first financial year in which the company was large. Second, the obligation is ongoing: the policy must exist on each day the company remains in scope, and it must be made available to officers and employees, not simply drafted and filed away.

Companies that fall outside the three categories are not required to have a policy. But the protections in the Act apply to disclosures about any company, and ASIC encourages every entity to put arrangements in place for handling disclosures. A policy is also increasingly expected by investors, customers and larger suppliers doing due diligence, so most growing businesses are better off having one.

What your policy must contain

Section 1317AI(5) lists the matters the policy must deal with. ASIC's Regulatory Guide 270 (Whistleblower policies) explains each requirement and sets out ASIC's good practice guidance on implementing and maintaining a policy. At a minimum, your policy must set out:

  • The protections available to whistleblowers: including under Part 9.4AAA of the Act.
  • Who can receive a protected disclosure and how it can be made: including anonymous reporting channels.
  • How the company will support whistleblowers and protect them from detriment: the support available to reporters and the steps the company will take to prevent detriment.
  • How the company will investigate protected disclosures: including who assesses them and how.
  • How the company will ensure fair treatment of employees: including those who are mentioned in, or the subject of, a disclosure.
  • How the policy will be made available: to officers and employees.
  • Any matters prescribed by the regulations: any matters prescribed under the Act from time to time.

RG 270's good practice guidance covers how to promote the policy, train officers and employees on it, and review it over time. ASIC's Information Sheet 247 sets out what company officers must do when they receive a report.

Who can report, and what they can report

An eligible whistleblower is defined in s 1317AAA of the Act and the definition is broader than many directors expect. It covers current or former officers and employees, anyone who supplies goods or services to the company (paid or unpaid) and their employees, associates of the company, and relatives and dependants of any of those people. A person does not need to identify themselves for the disclosure to qualify for protection.

For the protections to apply, the whistleblower must have reasonable grounds to suspect that the information concerns misconduct or an improper state of affairs in the company, or that the company, its officers or employees have contravened the Corporations Act, the Australian Securities and Investments Commission Act 2001 (Cth) (the ASIC Act) or other listed financial services legislation, under s 1317AA. The test also covers offences against any other Commonwealth law punishable by imprisonment for 12 months or more, and conduct that represents a danger to the public or the financial system.

Disclosures qualify for protection when they are made to an eligible recipient, defined in s 1317AAC: an officer or senior manager, an auditor or audit team member, an actuary, or a person the company has authorised to receive disclosures. A disclosure made directly to ASIC, APRA or another prescribed regulator qualifies in its own right, as does a disclosure to a legal practitioner for the purpose of obtaining legal advice about the operation of the protections.

The protections your people get, and their limits

Three protections sit at the centre of the regime, and your policy should explain each of them accurately.

Confidentiality

It is an offence, and a civil penalty, to disclose information that identifies a whistleblower or is likely to lead to their identification, under s 1317AAE. The prohibition has limited exceptions: disclosure to ASIC, APRA or the Australian Federal Police, to a legal practitioner for legal advice, with the whistleblower's consent, or where disclosure is reasonably necessary for an investigation and reasonable steps are taken to reduce the risk of identification.

Protection from detriment

Under s 1317AC, it is an offence, and a civil penalty, to cause detriment to a person, or to threaten to do so, where a belief or suspicion that the person made a protected disclosure is the reason or part of the reason for the conduct. Section 1317ADA defines detriment widely: dismissal, injury in employment, altering duties to a person's disadvantage, discrimination, harassment or intimidation, psychological harm, and damage to reputation, property, business or financial position.

Immunity from liability

Under s 1317AB, a person who makes a qualifying disclosure is not subject to civil, criminal or administrative liability, including disciplinary action, for making the disclosure. They also have qualified privilege, and a contract cannot be terminated on the basis that the disclosure breached it. The immunity has clear limits: it does not cover liability for the person's own conduct that the disclosure reveals, and it does not protect knowingly false reports. Your policy and training should reflect those limits rather than promising blanket protection.

Compensation for detriment

If a whistleblower suffers detriment, a court can order the person who caused it to compensate them for loss, damage or injury, under ss 1317AD and 1317AE. A threat counts even if it is implied or conditional, and it does not matter whether the person threatened actually feared it would be carried out. Employers can be ordered to compensate jointly with the employee who caused the detriment, and where the whistleblower brings a claim, the onus can shift so that the company has to prove the claim is not made out.

What happens if your company does not comply

Non-compliance is not a paper risk. The consequences include:

  • No policy, or policy not made available: a strict liability offence under s 1311(1) of the Act, so no proof of intent is required.
  • Breach of confidentiality or victimisation: each is a criminal offence and a civil penalty provision, so both the individual responsible and the company can be pursued.
  • Detriment: court orders for compensation and other remedies, which can be made against the company as well as the individual responsible.
  • Regulator attention: ASIC investigates whistleblower-related misconduct and can take enforcement action against companies and officers.

A practical compliance checklist

Whatever your size, the following steps put you in a defensible position:

  • Confirm your status: check your latest financial year figures against the tests in s 45A(3) and confirm whether you are a public company, a large proprietary company or a corporate trustee of a registrable superannuation entity.
  • Draft a tailored policy: cover every matter in s 1317AI(5), and make the document fit your structure, reporting lines and risk profile rather than copying a template.
  • Have it approved at the top: a policy approved by the board or directors carries more weight and is consistent with ASIC's good practice guidance.
  • Set up reporting channels: at least one confidential channel that supports anonymous reporting, monitored by a small group of trained recipients.
  • Designate eligible recipients: name the officers, senior managers or authorised people who can receive disclosures, and publish who they are.
  • Make the policy available: distribute it to every officer and employee, include it in onboarding, and keep it somewhere easy to find.
  • Train recipients and managers: make sure they can recognise a protected disclosure, protect confidentiality and escalate promptly.
  • Investigate fairly and confidentially: triage each disclosure, appoint an investigator, keep records, and protect the identity of the reporter.
  • Review annually and after incidents: update the policy, the channels and the training as the business changes.
  • Check your confidentiality documents: NDAs, employment contracts and settlement agreements should carve out protected disclosures to eligible recipients and regulators.

Whistleblower obligations are a place where advice early is cheaper than advice after an incident. A lawyer can help you:

  • Assess whether you are in scope: including how the large proprietary company test applies to your group structure and consolidated figures.
  • Draft or redraft your policy: against s 1317AI(5) and RG 270, aligned with your employment contracts, staff handbook, privacy policy and confidentiality agreements.
  • Handle a live disclosure: assess whether it qualifies for protection, manage confidentiality, and run the investigation properly so the company does not inadvertently breach the Act.
  • Respond to a detriment complaint or regulator inquiry: if a whistleblower claims they were treated badly, or ASIC comes knocking, the response needs to be handled carefully because the evidential onus can shift to the company.
  • Train your people: officers and eligible recipients can be walked through the legal definitions and their personal obligations under the Act.

The threshold that catches private companies by surprise

Of the three categories, the large proprietary company test is the one most often missed, because directors of private companies assume whistleblower obligations are a listed-company problem. A private company with 50 employees and $25 million in revenue meets two of the three tests on the current figures in s 45A(3), and with that status comes a legal duty to have a written policy and make it available to everyone who works for the company. The second most common gap is the availability limb: companies draft a policy, file it and never distribute it, even though making it available to officers and employees is part of the duty itself. The practical first step is to pull your last financial year's figures and run them against the three tests. If you are in scope, get the policy drafted, approved and distributed before the six-month grace period runs out. If you are not, a simple policy is still the cheapest way to make sure a genuine concern reaches the right person quickly, with the legal protections intact.