Engage Logo

Whistleblower Policy

HR policy templateLast reviewed Engage HR editorial team

A whistleblower policy sets out how someone inside an organisation can report suspected wrongdoing, who receives the report, how it is investigated, and what protection the reporter has against retaliation. For several classes of company in India it is a statutory obligation known as the vigil mechanism.

Download in Word

At a glance

Summary of this policy template
Document typeHR policy template
Issued byEmployer
Templates included3 ready to use versions
Download formatWord (.docx)
Statutory referenceCompanies Act, 2013
Last reviewed26 August 2026
Maintained byEngage HR editorial team

Whistleblower policy, grievance procedure and POSH complaint

Organisations often route everything through one channel. These three address different things, involve different people, and one of them is constituted separately by law.

Whistleblower policyGrievance procedurePOSH complaint
What it is forSuspected wrongdoing: fraud, corruption, falsified records, safety or legal breaches.The employee's own terms or treatment: pay, workload, a manager, a decision affecting them.Sexual harassment at the workplace.
Who the reporter isOften a bystander with no personal stake in the matter.Always the affected person.The aggrieved person, or another person on their behalf where permitted.
Who receives itA designated officer, with direct access to the audit committee chair for serious matters.The reporting line, escalating to HR and the grievance committee.The committee constituted for that purpose.
Can it be anonymousUsually yes, though anonymity limits what can be investigated.Rarely, because the complaint concerns the complainant.No. The process requires an identified aggrieved person.
Where organisations go wrongOne channel used for everything, so real concerns sit behind parking disputes.Treated as a complaints box with no timeline.Routed through the general channel instead of the constituted committee.

What a whistleblower policy contains

A workable policy has ten sections. The ordering below moves from scope to protection, which is the order a worried reader looks for.

  1. Purpose and scope. What the policy covers, and who may use it. Scope should extend beyond employees to directors, contractors and vendors where the organisation wants their reports.
  2. What may be reported. A list of categories with examples, and an explicit statement of what belongs elsewhere.
  3. What does not belong here. Personal grievances, and sexual harassment complaints, each routed to the correct process by name.
  4. How to report. Every available channel, with the actual address, number or link, and whether each can be used anonymously.
  5. The designated officer. Who receives reports, and the direct route to the audit committee chair where the report concerns senior management.
  6. Acknowledgement and timelines. When the reporter hears back, and by when the matter is concluded.
  7. Investigation. Who investigates, how confidentiality is handled, and what the subject of the report is told and when.
  8. Protection from retaliation. What counts as retaliation, what the reporter should do if it happens, and what follows for whoever retaliates.
  9. Deliberately false reports. What happens to a report made in bad faith, stated so it does not deter a good faith report that turns out to be mistaken.
  10. Records and reporting. What is recorded, who reviews the numbers, and how often.

The channels section is the one worth over-engineering. A policy naming a single internal email address controlled by the finance team will not receive reports about the finance team.

3 policy templates

Whistleblower Policy for standard company policy

The general version, suitable for a private company establishing a vigil mechanism or adopting one voluntarily.

WHISTLEBLOWER POLICY

[Company Name]
Effective from: [Effective Date]
Approved by: [Approving Body]
Policy owner: [Policy Owner Designation]
Next review: [Review Date]

1. PURPOSE
[Company Name] expects every director, employee and business partner to act honestly. This policy gives anyone who suspects wrongdoing a way to raise it without fear, and commits [Company Name] to acting on what is raised.

2. SCOPE
This policy applies to directors, employees, trainees, contract and temporary staff, consultants, vendors and any other person engaged with [Company Name].

3. WHAT MAY BE REPORTED
a) Fraud, theft, misappropriation or misuse of assets
b) Bribery, kickbacks or improper payments
c) Falsification of records, accounts or reports
d) Breach of law, regulation or [Company Name] policy
e) Concealment of any of the above
f) Danger to health, safety or the environment
g) Abuse of authority for personal gain

4. WHAT DOES NOT COME HERE
a) Personal grievances about your own employment, pay, appraisal or manager. These go through the grievance procedure at [Grievance Policy Reference].
b) Complaints of sexual harassment. These go to the committee constituted for that purpose, contactable at [Committee Contact]. Do not use this policy for such complaints.

5. HOW TO REPORT
You may report through any of the following:
Email: [Whistleblower Email Address]
Post: [Designated Officer Name and Postal Address], marked confidential
Telephone: [Whistleblower Helpline Number]
Online: [Reporting Portal Address]

Where the concern involves senior management or the designated officer, write directly to the Chairperson of the Audit Committee at [Audit Committee Chair Contact].

6. ANONYMOUS REPORTING
You may report anonymously. Please note that an anonymous report limits our ability to seek further information, and may limit what can be established. If you give your name it will be kept confidential and shared only with those who need it to investigate.

7. WHAT HAPPENS NEXT
Acknowledgement within [Acknowledgement Period] of receipt, where contact details are provided.
Initial assessment within [Assessment Period] to decide whether to investigate.
Investigation concluded within [Investigation Period], or the reporter told why more time is needed.
Outcome communicated to the reporter to the extent [Company Name] is able.

8. PROTECTION FROM RETALIATION
[Company Name] will not tolerate retaliation against anyone who reports in good faith. Retaliation includes dismissal, demotion, transfer, changes to duties or pay, exclusion, or any other detriment connected to the report.

If you believe you have suffered retaliation, contact [Retaliation Contact] directly. Retaliation is itself a disciplinary matter and will be dealt with as such.

Protection applies where the report was made in good faith, whether or not the concern turns out to be well founded.

9. DELIBERATELY FALSE REPORTS
A report made in bad faith, knowing it to be untrue, is a disciplinary matter. A report made in good faith that proves unfounded is not.

10. RECORDS
The designated officer maintains a confidential register of reports, action taken and outcomes. A summary is placed before [Reviewing Body] every [Reporting Frequency].

11. REVIEW
This policy is reviewed every [Review Frequency] by [Policy Owner Designation].

Approved: [Approving Authority]
Date: [Date]

Whistleblower Policy for listed entity vigil mechanism

For a listed company, where the mechanism is a regulatory requirement and disclosure obligations attach to it.

VIGIL MECHANISM AND WHISTLEBLOWER POLICY

[Company Name]
Approved by the Board on: [Board Approval Date]
Effective from: [Effective Date]
Next review: [Review Date]

1. REGULATORY BASIS
This policy establishes the vigil mechanism required of [Company Name] and is administered under the oversight of the Audit Committee.

2. SCOPE
This policy is available to directors and employees of [Company Name] and to [Extended Categories, for example vendors and contract staff].

3. REPORTABLE MATTERS
a) Fraud, misappropriation or misuse of company assets
b) Manipulation or falsification of company records, accounts or financial statements
c) Bribery, corruption or improper payments
d) Insider dealing or misuse of unpublished price sensitive information
e) Breach of the code of conduct
f) Breach of applicable law or regulation
g) Deliberate concealment of any of the above

4. MATTERS EXCLUDED
Personal grievances go to the grievance procedure at [Grievance Policy Reference]. Complaints of sexual harassment go to the committee constituted for that purpose at [Committee Contact].

5. CHANNELS
Designated officer: [Designated Officer Name and Designation]
Email: [Whistleblower Email Address]
Helpline: [Helpline Number]
Portal: [Reporting Portal Address]
Post: [Postal Address], marked confidential

6. DIRECT ACCESS TO THE AUDIT COMMITTEE
In appropriate cases, and in every case where the concern involves senior management, the designated officer or the integrity of the mechanism itself, the reporter may approach the Chairperson of the Audit Committee directly at [Audit Committee Chair Contact]. Access is not conditional on first using any other channel.

7. PROCESS AND TIMELINES
Acknowledgement: within [Acknowledgement Period]
Preliminary assessment: within [Assessment Period]
Investigation: concluded within [Investigation Period], extendable with reasons recorded
Report to the Audit Committee: every [Reporting Frequency], and immediately for any matter above [Escalation Threshold Description]

8. INVESTIGATION
Investigations are conducted by [Investigating Function], or by an external party where independence requires it. The identity of the reporter is disclosed only to those who need it. The subject of a report is given an opportunity to respond before any adverse finding.

9. PROTECTION AGAINST VICTIMISATION
[Company Name] provides safeguards against victimisation of any person using this mechanism. Victimisation includes dismissal, demotion, transfer, adverse appraisal, withdrawal of duties, exclusion, or any other detriment connected to a report. Any such act is itself a disciplinary matter.

10. DISCLOSURE
The existence of this mechanism is disclosed as required, and this policy is published at [Website Location].

11. RECORDS AND REVIEW
The designated officer maintains a confidential register. The Audit Committee reviews the mechanism and this policy every [Review Frequency].

Approved by the Board of Directors
Date: [Date]

Whistleblower Policy for small company short form

For an organisation adopting a policy voluntarily, where a long document would go unread and there is no separate audit committee.

SPEAK UP POLICY

[Company Name]
Effective from: [Effective Date]
Owner: [Policy Owner Designation]

1. WHY THIS EXISTS
If you think something dishonest or unsafe is happening at [Company Name], we want to hear about it. This policy tells you how to raise it and what we will do.

2. WHO CAN USE IT
Anyone working with [Company Name]: employees, interns, contractors, consultants and vendors.

3. WHAT TO RAISE
Fraud, theft or misuse of company money or assets. Bribes or kickbacks. Falsified records or reports. Anything unsafe. Any breach of law or of our own policies. Any attempt to hide these things.

4. WHAT NOT TO RAISE HERE
Problems with your own job, pay, appraisal or manager go to [Grievance Contact] under the grievance procedure.

Sexual harassment complaints go to the committee constituted for that purpose, at [Committee Contact]. Please do not use this policy for those.

5. HOW TO RAISE IT
Email [Whistleblower Email Address], or speak to [Designated Officer Name] directly.

If your concern is about [Designated Officer Name], or about anyone they report to, write instead to [Escalation Contact].

You can report without giving your name. We will still look into it, though it is harder for us to follow up if we cannot ask you questions.

6. WHAT WE WILL DO
We will acknowledge your report within [Acknowledgement Period] if we have your contact details.
We will tell you within [Assessment Period] whether we are investigating.
We will finish the investigation within [Investigation Period], or explain why we need longer.
We will tell you the outcome, as far as we are able to.

7. YOU WILL NOT BE PUNISHED FOR SPEAKING UP
Nobody at [Company Name] may treat you badly for raising a concern honestly. That includes dismissal, demotion, a transfer you did not ask for, changes to your work or pay, a worse appraisal, or being left out.

This protection applies even if it turns out you were mistaken, as long as you raised it honestly. If you think you are being treated badly for reporting, contact [Escalation Contact] straight away.

8. RAISING SOMETHING YOU KNOW IS UNTRUE
Making up an allegation deliberately is a disciplinary matter. Being wrong in good faith is not.

9. RECORDS
[Policy Owner Designation] keeps a confidential record of reports and what was done, and reviews it with [Reviewing Body] every [Reporting Frequency].

Approved: [Approving Authority]
Date: [Date]

What it has to contain

ElementWhy it matters
A channel that bypasses the ordinary reporting lineThe reports that matter most are usually about someone senior. A mechanism routing everything through management, or through an inbox that management controls, cannot receive those reports, and its silence will be mistaken for cleanliness.
Named recipients with real contact detailsA policy saying reports go to "the designated officer" without naming anyone or giving an address is not a channel. Whoever is worried enough to report will not go looking.
A definition of retaliationRetaliation is rarely dismissal. It is a transfer, a changed appraisal, work withdrawn, exclusion from meetings. Naming these forms is what makes the protection mean something, and lets someone recognise what is happening to them.
Timelines for acknowledgement, assessment and conclusionSilence after a report is what stops the next one. Stated periods give the reporter something to hold the organisation to and give the investigator a deadline.
An explicit carve-out for sexual harassmentThose complaints go to the committee constituted for that purpose under the applicable law. A whistleblower policy silent on this will receive them, and handling one outside the statutory process is a serious failure.
The good faith standard, stated plainlyPeople do not report because they fear being wrong. Saying that protection depends on honesty rather than on being correct removes the main reason for staying quiet.
A record and a periodic review of the numbersReports received, investigated and substantiated are the only evidence that the mechanism functions. An organisation that has never counted cannot say whether its policy works.

How to write one

  1. Establish whether the mechanism is mandatory for you. Certain classes of company are required to establish a vigil mechanism, and listed entities have their own obligation. Check your class against the current statutory position with your company secretary or counsel rather than assuming, because the thresholds turn on borrowings, deposits and listing status.
  2. Decide who receives reports, and who receives the ones about them. Name a designated officer, then name the escalation route for concerns involving that officer or senior management. Where an audit committee exists, its chairperson is the natural second route and direct access should not be conditional on using the first.
  3. Build more than one channel. An email address, a postal address and a phone line at minimum, with an external portal if the budget allows. Different reporters trust different channels, and a single channel is a single point of failure.
  4. Write the retaliation clause specifically. List the forms retaliation takes, say who to contact if it happens, and state that retaliating is itself a disciplinary offence. A general promise not to victimise anyone does not help someone whose appraisal has quietly dropped.
  5. Route the exclusions by name. Send personal grievances to the grievance procedure and sexual harassment complaints to the committee constituted for that purpose, naming both. Otherwise this becomes the channel for everything and the serious reports get lost.
  6. Tell people it exists, more than once. Cover it at induction, repeat it annually, and put the contact details somewhere findable without asking HR. A policy that exists only in a handbook no one reopens has no users.
  7. Review the numbers, not the document. Count reports received, investigated and substantiated each period, and put the count in front of whoever oversees the mechanism. Zero reports over a long period is a finding about the channel, not about the organisation.

Why most policies receive nothing

Organisations with a whistleblower policy and no reports usually conclude that there is nothing to report. That is rarely the explanation.

The common causes are structural. The channel runs through the people a serious report would be about. Nobody knows the channel exists, because it was covered once at induction and never again. An earlier report produced no visible response, and the reporter told colleagues. Or the policy promises protection in terms so general that nobody believes it applies to them.

Each of these is fixable, and none is fixed by rewriting the document. The channel needs a route that bypasses management. Awareness needs repeating on a schedule. Response needs timelines the organisation meets. Protection needs to name the specific forms retaliation takes.

The diagnostic worth running: ask a few people at different levels who they would contact if they saw something wrong, and see whether anyone names the mechanism. That answer tells you more than any policy review.

The order in which a whistleblower policy gets builtThe seven steps this page sets out, in order. Deciding who receives the reports about the recipients is what makes the mechanism usable at senior level. Reviewing the numbers rather than the document is what surfaces a policy that is receiving nothing.1Establish whether the mechanism is mandatory for you2Decide who receives reports, and who receives the ones about them3Build more than one channel4Write the retaliation clause specifically5Route the exclusions by name6Tell people it exists, more than once7Review the numbers, not the document
The seven steps this page sets out, in order. Deciding who receives the reports about the recipients is what makes the mechanism usable at senior level. Reviewing the numbers rather than the document is what surfaces a policy that is receiving nothing.

The statutory position in outline

India frames the obligation as a vigil mechanism under section 177(9) of the Companies Act, 2013. It binds every listed company and any prescribed class, so a private company is covered only if it falls within one. Section 177(10) requires safeguards against victimisation and direct access to the Audit Committee chairperson.

In India the obligation to maintain a whistleblower channel is framed as a vigil mechanism, and it sits in section 177 of the Companies Act, 2013.

Section 177(9) provides that every listed company, or such class or classes of companies as may be prescribed, shall establish a vigil mechanism for directors and employees to report genuine concerns in such manner as may be prescribed. Two things follow from the wording. The obligation is not universal, so a private company is covered only if it falls within a prescribed class. And the mechanism is for directors and employees, which is a floor rather than a ceiling: nothing prevents an organisation opening it to contractors and vendors, and most that take it seriously do.

Section 177(10) is the part that decides whether the mechanism works. It requires the mechanism to provide adequate safeguards against victimisation of persons who use it, and to make provision for direct access to the chairperson of the Audit Committee in appropriate or exceptional cases. A channel that routes everything through management does not satisfy the second limb. The proviso to the same sub-section requires the details of the establishment of the mechanism to be disclosed on the company's website, if any, and in the Board's report.

One drafting point is worth noting for anyone reading the section itself. Section 177(1), which deals with the Audit Committee, was amended to read every listed public company, while section 177(9) still reads every listed company. The two are not the same formulation and should not be carried across.

The classes of company beyond listed companies are set by rules made under the Act, and turn on financial tests such as the acceptance of public deposits and the level of borrowing from banks and public financial institutions. Because those tests move as a company grows, coverage is a question for the company secretary or counsel against the current rule rather than something to infer. This page does not state the thresholds.

Two points hold regardless. Adopting the mechanism voluntarily is open to anyone and is common well below the statutory line. And separate legislation dealing with disclosures by public servants does not create obligations for private employers, which is a frequent source of confusion when searching for the applicable law.

Anonymity and what it costs

Most policies permit anonymous reporting, and most reporters who use it would not have reported otherwise. It is worth having. It is also worth being honest about its limits.

An anonymous report cannot be clarified. The investigator cannot ask which quarter, which vendor, or who else saw it. Where the allegation is specific enough to stand on its own the investigation proceeds normally, and where it is not, it may not be possible to establish anything.

The honest drafting is to permit anonymity, say plainly what it limits, and offer a middle option: confidential reporting, where the reporter identifies themselves to the designated officer alone and their identity goes no further than the investigation requires. A good number of reporters will take that option when it is explained, and those reports are far more likely to lead somewhere.

What should not be promised is anonymous investigation. Once an allegation is specific, the subject may be able to work out who reported it, whatever the organisation does. Saying so in the policy is better than a reporter discovering it afterwards.

Protecting the reporter after the investigation closes

Retaliation is mostly a slow phenomenon. The reporter is not dismissed the following week. Their appraisal is a little worse the following cycle, a project moves to someone else, an invitation stops arriving.

This is why a policy that treats the outcome as the end of the matter misses most of what it exists to prevent. Nobody is watching by the time anything happens, and the individual acts are each small enough to be explained.

Two practices help. Set a scheduled check with the reporter some months after closure, ask specifically about the forms retaliation takes, and record that the check happened. And where the report concerned the reporter's own management chain, have someone outside that chain review their next appraisal before it is finalised.

Neither is expensive. Both convert a promise in a document into something the organisation actually does, and both produce a record that the promise was honoured.

Common mistakes

MistakeWhy it causes troubleWhat to do instead
One channel, controlled by the function most likely to be reported onConcerns about finance cannot be sent to a finance inbox. The mechanism then receives nothing serious and its silence is read as an absence of problems.Provide a route that bypasses management entirely, and where an audit committee exists, give direct access to its chairperson.
Promising confidentiality that cannot be keptSome investigations cannot proceed without revealing who reported. A promise of absolute confidentiality is broken at exactly the moment the reporter is most exposed.Promise that identity is shared only with those who need it to investigate, and say plainly what anonymity will cost in terms of what can be established.
Treating a report as closed once the investigation endsRetaliation usually starts after the investigation, not during it. An organisation that stops paying attention at the outcome never sees it.Check in with the reporter at a set interval after closure, and record that the check happened.
Receiving sexual harassment complaints through this channelThose complaints have a statutory process and a constituted committee. Handling one outside it is a failure of the process, whatever the intention.Exclude them by name in the policy, give the committee's contact details, and train whoever receives reports to redirect immediately.
A policy that exists only for the auditorIt is adopted, filed, disclosed, and never mentioned again. When something goes wrong, nobody knew there was a channel.Cover it at induction and annually, and measure awareness rather than assuming it.
No timelinesThe reporter hears nothing, concludes the report went nowhere, and tells colleagues so. One unanswered report can close the channel for years.Commit to an acknowledgement period, an assessment period and a conclusion period, and tell the reporter when a deadline needs to move.

Statutory reference

Act
Companies Act, 2013
Key limits
The classes of company beyond listed companies are prescribed by rules made under the Act and turn on financial tests, so coverage changes as a company grows. No threshold from those rules is stated on this page. Listed entities also carry an obligation under the securities regulations applicable to them, which is not stated here. Note that section 177(1) reads 'every listed public company' while section 177(9) reads 'every listed company'; the two formulations differ.
Provisions of the Companies Act, 2013 referred to on this page
ProvisionWhat it says
Section 177(9)Provides that every listed company, or such class or classes of companies as may be prescribed, shall establish a vigil mechanism for directors and employees to report genuine concerns in such manner as may be prescribed.
Section 177(10)Requires that the vigil mechanism provide for adequate safeguards against victimisation of persons who use it, and make provision for direct access to the chairperson of the Audit Committee in appropriate or exceptional cases, with a proviso that the details of the establishment of the mechanism be disclosed by the company on its website, if any, and in the Board's report.

Read the Companies Act, 2013 in full

Frequently asked questions

Is a whistleblower policy mandatory in India?

Not for every company. Section 177(9) of the Companies Act, 2013 requires every listed company, and such class or classes of companies as may be prescribed, to establish a vigil mechanism. The classes beyond listed companies are set by rules made under the Act, and turn on financial tests such as public deposits and borrowing from banks and public financial institutions. So whether a particular company is covered changes as it grows, and should be checked against the current rule.

What is the difference between a vigil mechanism and a whistleblower policy?

Vigil mechanism is the term the company law uses for the required channel; whistleblower policy is what most organisations call the document that implements it. Where the obligation applies, the policy is how the company discharges it. Organisations not covered often adopt the same document voluntarily.

Can whistleblower complaints be made anonymously?

Most policies allow it, and it is worth allowing because some reporters would not come forward otherwise. The limitation is practical: an anonymous report cannot be clarified, so unless the allegation is specific enough to investigate on its own terms, it may not be possible to establish anything. Offering confidential reporting as a middle option tends to produce more actionable reports.

Who should receive whistleblower reports?

A named designated officer, plus a route that bypasses management. Section 177(10) requires the mechanism to make provision for direct access to the chairperson of the Audit Committee in appropriate or exceptional cases, so that access should not be conditional on using the ordinary channel first. It also requires adequate safeguards against victimisation of anyone who uses the mechanism.

Can a whistleblower be dismissed or transferred after reporting?

Any detriment connected to a good faith report is retaliation and should itself be a disciplinary matter under the policy. The policy should name the forms this takes, including dismissal, demotion, transfer, adverse appraisal, withdrawal of duties and exclusion, so that a reporter can recognise it and raise it.

Should sexual harassment complaints go through the whistleblower policy?

No. Those complaints have their own statutory process and a committee constituted for the purpose. A whistleblower policy should exclude them by name, give the committee's contact details, and whoever receives reports should be trained to redirect immediately rather than begin an investigation.

What if someone makes a false whistleblower complaint?

A report made in bad faith, knowing it to be untrue, is properly a disciplinary matter. A report made honestly that turns out to be unfounded is not, and the policy should say so in terms. If the distinction is not stated clearly, people who are unsure whether they are right will stay silent.

How long should a whistleblower investigation take?

There is no single answer, but the policy should commit to stated periods for acknowledgement, for the decision whether to investigate, and for conclusion. Where a deadline needs to move, the reporter should be told why. Silence is what stops the next report from being made.

Whistleblower reports in Engage

Engage keeps the register of reports, the assessment, the investigation record and the outcome against a single case, with access limited to the people handling it. Timelines raise reminders, so an acknowledgement or a conclusion date does not pass unnoticed, and the periodic count that goes to the reviewing body comes out of the record rather than being reconstructed.

Book a demo
WhatsApp