In collaboration towards better boards with Herbert Smith Freehills Kramer

A Preamble

I doubt that you are reading this out of curiosity or self-development. There wouldn’t be time in your week. So, it’s most likely that you are reading this because there is a chance of a potential whistleblowing situation in one of your boards or it has just happened. You know you are not experienced. It’s one of those situations when the most important thing you must do is acknowledge your ignorance and incompetence on the matter and simply STOP. THINK.

One of the most proven legal sources of Counsel on these matters is the international law firm Herbert Smith Freehills Kramer. Of note, Chair and Senior Partner, Rebecca Maslen-Stannage and Partner, Michael Gonski with whom we are grateful and reassured to be co-writing this paper.

Listening to their experience reveals the harrowing but inevitable revelation that a Whistleblowing event can turn quickly into a Whistleblowing crisis simply because of the well-meaning, even intuitive, immediate actions that a Chair takes following being informed of the event, only to later face an allegation that those actions breached the whistleblowing regime.

Our paper here is not meant to be an emergency instruction kit nor a horror story. What are the conditions that need to be in place by a Board ahead of any future Whistleblowing event that optimise success in handling? What must Chairs do in the event of a situation being triggered?

We draw on the extraordinary proven advice and insights of our contributors at HSFK as well as our own experience with Chairs internationally over many years. In addition, we research the contemporary insights into how case studies can inform a process towards best practice.

In good news, we think that those of you that usually start with what should we do not what could we do will likely fall on the right side of how to deal with these matters.

Executive Summary

Whistleblowing is no longer a peripheral compliance matter. It has become one of the most reliable early-warning systems available to a Board, and one of the sharpest tests of whether an organisation’s stated values are real. Almost every major corporate scandal of the past quarter-century, from Enron to the misconduct exposed by Australia’s banking Royal Commission, reached the public domain, and ultimately the courts, because someone inside the organisation spoke up. How the Board responds to that voice determines whether the organisation contains a problem early or is engulfed by it later.

For the Chair, whistleblowing carries a particular weight. The Chair sets the tone of the Board, controls its agenda and is frequently the person to whom a disclosure of high consequence is ultimately escalated, whether through a formal channel or by a direct, informal approach.

The additional context within which Boards operate is that there are currently unprecedented levels of whistleblowing, and it can be difficult to distinguish between a workplace grievance or a response to performance management and the raising of genuine concerns of misconduct within the company.

This guide does three things. First, it traces how whistleblowing policy and protection evolved, and where it has been famously tested. Second, it sets out the Australian legal framework, definitions, rights, obligations and penalties, in plain terms a director can act on. Third, and most practically, it gives the Chair a structured playbook and a detailed checklist for the three phases that matter: Before a whistle is blown, During the handling of a disclosure, and After resolution.

The central message: a Chair demonstrates good governance not by reacting well in the moment, but by having built the conditions, culture, policy, escalation paths and Board literacy, that make a good response possible before the disclosure ever arrives.

3 Golden Rules

As you will likely all be aware, especially in Australia, the laws in relation to whistleblowing might be counter-intuitive. For example, why shouldn’t a Chair who receives a complaint be able to get their CEO involved to help investigate if the CEO is not implicated? Well, they can’t under the laws. However, the aim of this paper is not to scaremonger or complain but rather to consider how to practically deal with a complaint when it comes in.

As a general principle, if the following 3 Golden Rules are followed, a Chair will not breach the laws:

  1. Don’t do nothing. This seems odd but our experience is that some Board directors on receiving a complaint think that if they ignore it, they can’t get into any trouble. While they won’t breach the whistleblowing laws, they could bring a company into disrepute as there are many other laws like Stop Sexual Harassment or WHS laws which would require some action being taken when on notice of an issue.
  2. Get consent from the discloser before sharing. The laws require consent to share the discloser’s name with anyone. This should not be hard, you can always send them an email with something like:

 

‘ Thanks for your disclosure. We take these very seriously. In order for me to investigate it properly, can I ask that you please respond to my email and confirm that I can share it as required? I would propose to do so on a need-to-know basis and would of course ensure that you are not victimised for having made such a disclosure. ’

 

You can also send the disclosure to a lawyer (your General Counsel or external law firm) without breaching the law. This can often help to get a second person to give you an opinion on what to do in the circumstances rather than having to make that decision on your own.

  1. Don’t victimise the discloser. Again self-explanatory, however, in the main recent cases, some directors have gotten into trouble where they perhaps thought that a discloser might be making things up and have treated them poorly after they made their disclosure. It may be that they are making things up but it is still important to protect them from any victimisation.

What Whistleblowing Is, and the Two Ways It Reaches a Board

A whistleblower is a person who reports wrongdoing, misconduct or an improper state of affairs within an organisation, usually from a position that gives them insight an outsider could not have. The defining feature is the asymmetry of risk: the discloser typically risks their job, relationships and reputation, while the organisation gains information it could not easily obtain elsewhere. Sound governance recognises and rebalances that.

Formal Channels

Most disclosures are designed to flow through a formal whistleblowing channel: an internal reporting line, an independent external hotline, a dedicated email or portal, or a named set of eligible recipients authorised to receive reports. Formal channels create an auditable record, allow triage and investigation under a defined protocol, and let the organisation manage confidentiality and protection deliberately. A well-run formal channel is the Board’s preferred route because it is structured, defensible and repeatable.

Informal Escalation, the Word That Reaches the Board Directly

Not every serious matter arrives neatly through the formal channel. A Chair or director may be approached directly, at a site visit, after a meeting, by letter, or through a quiet phone call, by someone who has lost faith in management, fears retaliation, or believes the matter is too grave or too close to senior leadership to report internally. These direct, informal disclosures are often the highest-consequence of all, precisely because the person has bypassed the ordinary machinery.

A critical point of Australian law: protection does not depend on the discloser using the official channel. A report made directly to a director or company secretary, both of whom are officers and therefore eligible recipients, can attract the full statutory protections.1 A Chair who receives an informal approach is not a bystander; they may be the trigger point for the organisation’s legal obligations. Treating an informal disclosure casually is one of the most dangerous mistakes a Chair can make.

How Whistleblowing Policies and Protections Evolved

Whistleblowing protection developed reactively, each major framework tends to follow a scandal that exposed the cost of silence. Understanding that history helps a Chair see why the current obligations exist and what they are designed to prevent.

From Individual Courage to Institutional Obligation

For most of the twentieth century, speaking up against an employer was an act of individual courage with little legal cover. The discloser bore the entire risk. The modern shift, from relying on individual bravery to requiring institutional systems, is the single most important development in the field. Today the question regulators ask is not merely did someone do the right thing? but did the organisation make it safe and systematic to do so?

The United States and Sarbanes-Oxley

The collapse of Enron in 2001 and WorldCom in 2002 was the turning point for corporate whistleblowing globally. Sherron Watkins, an Enron vice-president, warned Chairman Kenneth Lay of what she described as accounting problems that could bring the company down; Cynthia Cooper led the internal audit team that uncovered billions in fraudulent entries at WorldCom. Both were later named, with FBI whistleblower Coleen Rowley, as TIME’s Persons of the Year for 2002.2

The legislative response was the Sarbanes-Oxley Act of 2002, which codified Board-level expectations, director independence and expertise, CEO certification of financial statements, and statutory protection for employees of public companies who report fraud.3 Sarbanes-Oxley reframed whistleblowing as a matter of Board governance, not just employee relations, a framing that has shaped every regime since.

The United Kingdom and Europe

The United Kingdom was an early mover with the Public Interest Disclosure Act 1998, which inserted protections into the Employment Rights Act 1996 and was widely treated as a global model. Later reforms removed the good faith precondition and added a public-interest test and co-worker liability.4 The European Union then harmonised protection across member states through the EU Whistleblowing Directive (2019/1937), which, unlike the older UK regime, mandates internal reporting channels for organisations above a size threshold, protects a broad class of persons including Board members and facilitators, and shifts the burden of proof to the employer to show that any detriment was justified.5

Australia’s Trajectory

Australia protected public-sector disclosers first, culminating in the Public Interest Disclosure Act 2013 (Cth).6 Private-sector protection lagged until the 2019 reforms. The Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 consolidated and substantially strengthened Part 9.4AAA of the Corporations Act 2001 (Cth), with the expanded protections operating from 1 July 2019 and the mandatory-policy obligation from 1 January 2020.7 A parallel regime for tax matters sits in Part IVD of the Taxation Administration Act 1953 (Cth).8 There has been some commentary about the need for things like bounties to pay people for making successful disclosures (which is on offer in the USA) but we do not think it is likely this will occur.

Where Whistleblowing Has Been Famously Tested

The following cases are widely cited because each changed how organisations and lawmakers think about disclosure. They are summarised here for governance lessons, not legal analysis.

Enron and WorldCom (United States)

These twin collapses demonstrated two enduring lessons. First, internal warnings often arrive before external collapse, Watkins warned Lay months ahead of Enron’s bankruptcy. Second, a warning ignored is worse than no warning, because it later evidences that leadership knew. For a Chair, the Enron story is a cautionary tale about what happens when a disclosure reaches the top and is not acted upon.

The Commonwealth Bank and Australia’s Banking Royal Commission

Jeff Morris, a financial adviser, repeatedly reported misconduct in the Commonwealth Bank’s financial-planning arm from 2008. His persistence, through internal channels, the regulator and ultimately a Senate inquiry, was a significant catalyst in the chain of events that led to the Royal Commission into Misconduct in the Banking, Superannuation and Financial Services Industry.9 The episode exposed how poorly even large, sophisticated institutions handled internal disclosures, and how reputational damage compounds when a whistleblower is left to escalate externally. It is a central reason Australia’s 2019 reforms were given real teeth.

Emerging Australian Case Law

Because the strengthened regime is recent, judicial guidance is still developing. Two 2025 Federal Court decisions, Mount v Dover Castle Metals and Reiche v Neometals, gave early guidance on key phrases such as improper state of affairs, reasonable grounds for suspicion and detriment, and on questions of burden of proof and confidentiality where a disclosure is made to both eligible and non-eligible recipients.10 Although both claims failed on their facts, the decisions confirm that courts will scrutinise causation closely, a reminder that contemporaneous, well-documented decision-making by the Board is the organisation’s best protection.

The Neometals case is useful as it does require the person who is alleged to have victimised a discloser to subjectively believe that the discloser was a whistleblower. This is helpful as plaintiff law firms will often try and re-create history and say that a disclosure was a whistleblowing complaint after the fact when it might have otherwise been thought of as a normal HR issue.

The Australian Legal Framework

This section sets out the core of the corporate regime in Part 9.4AAA. It is deliberately practical; section references are footnoted so advisers can be directed to the source.

Who Is Protected, the Eligible Whistleblower

The class of protected persons is deliberately broad. It includes current and former officers, employees and contractors of the entity, and extends to suppliers and their employees, and to relatives, dependants and spouses of any of those people. Importantly, a disclosure can be made anonymously and still be protected, and the discloser need not identify themselves to qualify.

To Whom, the Eligible Recipient

A protected disclosure can be made to a range of recipients. Inside the entity these include an officer (which covers a director and the company secretary) and a senior manager, as well as the entity’s auditor or actuary and any person authorised by the company to receive disclosures. Disclosures can also be made externally to ASIC, APRA, or a legal practitioner for the purpose of obtaining advice. This is why a Chair can become an eligible recipient simply by being approached directly.

What Qualifies, Disclosable Matters

The discloser must have reasonable grounds to suspect that the information concerns misconduct, or an improper state of affairs or circumstances, in relation to the entity or a related body corporate; or that the entity or an officer or employee has engaged in conduct that breaches specified laws or represents a danger to the public or financial system.11 Notably, the regime does not require the disclosure to be made in good faith, the test is the objective reasonableness of the suspicion, not the discloser’s motive. Purely personal work grievances are generally excluded. However, in practice, these can raise risk when an employee or plaintiff law firm later seeks to re-characterise a work grievance as a whistleblowing complaint.

The Protections

Where a disclosure qualifies, the law provides three principal protections:

  • Confidentiality of identity. It is an offence to disclose the identity of a whistleblower, or information likely to reveal it, outside permitted exceptions.
  • Protection from detriment. It is unlawful to cause or threaten detriment to a person because of a belief or suspicion that they have made, may make, or could make a protected disclosure. Detriment is defined very broadly and includes dismissal, demotion, alteration of duties to a disadvantage, harassment, discrimination, reputational damage and psychological harm.
  • Immunity and compensation. The discloser has immunity from civil, criminal and administrative liability for making the disclosure, and may seek compensation and other remedies through the courts if they suffer loss as a result of detriment. These protections can apply even where no disclosure was actually made, for example, where a person is victimised because of a mere suspicion that they might report.12

The Mandatory Policy Obligation

Public companies, large proprietary companies and corporate trustees of registrable superannuation entities must have a compliant whistleblower policy and make it available to officers and employees.13 Section 1317AI requires the policy to address, among other things, the protections available, how and to whom disclosures can be made, how the entity will support and protect disclosers from detriment, how it will investigate disclosures, and how it will ensure fair treatment of employees mentioned in a disclosure. ASIC’s Regulatory Guide 270 sets out detailed mandatory content and good-practice expectations and should be treated as the working benchmark.14

ASIC has provided narrow relief, for example, for small not-for-profit and charitable companies limited by guarantee below a revenue threshold, but the substantive protections continue to apply even where the policy obligation does not.

A Global Point of View

Chairs of organisations with international operations need a sense of how regimes differ, because a disclosure may engage more than one. The table below is a high-level orientation only.

JurisdictionCore FrameworkDistinctive Features
AustraliaCorporations Act Pt 9.4AAA (corporate); Taxation Administration Act Pt IVD (tax); PID Act 2013 (public sector)No good faith requirement; mandatory policies for larger entities; broad detriment definition; criminal and civil penalties; ASIC oversight.
United StatesSarbanes-Oxley Act 2002; Dodd-Frank Act 2010 (SEC bounty programme)Board-level certification duties; financial incentives for disclosers reporting securities violations to the SEC.
United KingdomPublic Interest Disclosure Act 1998 in the Employment Rights Act 1996Public-interest test; no statutory duty to maintain an internal policy; employment-tribunal route; longstanding model now seen as needing modernisation.
European UnionEU Whistleblowing Directive 2019/1937Mandatory internal channels above a size threshold; protects Board members and facilitators; reverse burden of proof on detriment; tiered reporting.

The common direction of travel is clear: away from reliance on individual courage and towards mandatory systems, broader protected classes, and real penalties for retaliation.

The Chair’s Role in Governing Whistleblowing

The Chair’s responsibilities are distinct from those of management and even from those of other directors. The Chair owns the Board’s culture and process and is often the ultimate human escalation point. Five responsibilities deserve particular attention.

Setting the Tone

Whether people speak up is determined less by the policy document than by whether they believe the organisation means it. The Chair’s visible, repeated endorsement of speaking up, and visible consequences when retaliation occurs, is the single most powerful lever on disclosure culture.

Ensuring the Architecture Exists

The Chair must satisfy themselves that a compliant policy and functioning channels exist, that eligible recipients are trained, and that there is a clear, pre-agreed path for escalating high consequence matters to the Board or a committee. This is not a one-off; it requires periodic review and testing.

Preserving Independence and Managing Conflicts

A disclosure may implicate the CEO, senior management, or even a director. The Chair must be able to ring-fence the investigation from anyone implicated, including by commissioning independent investigators and seeking external legal advice. Pre-deciding how conflicts will be handled prevents paralysis in the moment.

Protecting the Discloser

The Chair carries personal credibility into the commitment that the discloser will not suffer detriment. Confidentiality must be protected rigorously, information shared strictly on a need-to-know basis, and any sign of retaliation treated as a serious matter in its own right.

Leading the Board Through It

The Chair decides what the Board needs to know and when (within the parameters of the legal advice on what can legally be disclosed), frames the decision the Board must make, documents the Board’s reasoning, and ensures the Board acts on the substance rather than shooting the messenger. The quality of the Board minute is often the organisation’s best evidence of good governance.

Before, During and After: The Chair’s Playbook

Effective governance of a disclosure is overwhelmingly determined before any whistle is blown. The three phases below structure the Chair’s thinking; the detailed checklist that follows operationalises them.

Before, Preparation and Prevention

The objective in this phase is readiness: a culture that surfaces problems, infrastructure that handles them, and a Board that knows its role. The Chair should ensure the policy is current and ASIC RG 270-compliant, that channels work and have been tested, that eligible recipients and the Board itself have been briefed, and that a confidential, conflict-aware escalation path to the Board exists. The Chair should also pre-agree how the Board will obtain independent advice and investigators at speed, because the moment a serious disclosure lands is the worst time to be negotiating those arrangements.

Crucially, the Chair should rehearse the scenario of receiving a direct, informal disclosure. Knowing in advance how to listen, what to commit to (confidentiality and protection) and what not to commit to (no promises about outcomes), and how to record the approach, prevents the most common early missteps.

During, Handling a Live Disclosure

Once a disclosure is received, the priorities are: protect the person, preserve the information, and run a fair, independent process. The Chair ensures the matter is triaged for seriousness and conflict, that confidentiality is locked down, that the discloser is acknowledged and supported, and that the investigation is properly scoped, independent of anyone implicated, and documented. Throughout, the Board must guard against the instinct to defend the organisation reflexively or to identify and isolate the discloser. Decisions and their reasons should be minuted contemporaneously.

The Chair also manages the Board dynamic: deciding the appropriate forum within the permitted disclosure parameters having obtained internal or external legal advice (full Board, a sub-committee, or directors excluding any conflicted member), controlling the flow of sensitive information, and keeping the Board focused on its governance role rather than drifting into operational investigation.

After, Resolution, Remediation and Learning

After the investigation concludes, good governance is demonstrated by acting on findings, remediating root causes rather than symptoms, checking on the discloser’s wellbeing and confirming they have suffered no detriment, meeting any reporting or disclosure obligations, and feeding lessons back into policy, controls and culture. The Chair should ensure the Board formally closes the loop and records what was changed as a result, both because it is right and because it evidences a functioning system if the matter is ever scrutinised externally.

The Chair’s Whistleblowing Checklist

This checklist consolidates the playbook into actionable items across the three phases. It is designed to be lifted out, tailored to the entity, and used as a Board working document.

Before, Readiness and Prevention

Policy, Infrastructure and Board Readiness
Confirm the entity has a current whistleblower policy that complies with s 1317AI and ASIC RG 270, and that it is reviewed on a defined cycle.
Verify the policy is genuinely accessible to employees and, where relevant, to external disclosers such as suppliers and contractors.
Confirm reporting channels (internal and any external or anonymous hotline) actually work, and have been tested end-to-end within the last 12 months.
Confirm eligible recipients are clearly identified, trained on the 3 Golden Rules above and know how to preserve confidentiality from the first contact.
Ensure a clear, confidential escalation path exists for high-consequence matters to reach the Board, a committee, or the Chair directly.
Pre-agree how conflicts will be handled if a disclosure implicates the CEO, senior management or a director, including ring-fencing arrangements.
Establish, in advance, fast access to independent investigators and external legal advice the Board can call on.
Ensure the Board itself has been briefed on its role and the legal framework, and that whistleblowing is a periodic Board or committee agenda item.
Personally rehearse how to respond to a direct, informal disclosure: how to listen, what to commit to, and how to record it.
Confirm directors’ and officers’ insurance and indemnity arrangements are understood in the context of whistleblowing exposure.

During, Handling a Live Disclosure

Protect the Person, Preserve the Information, Run a Fair Process
Treat the disclosure seriously from the first moment, regardless of the channel or the discloser’s manner or motive.
Lock down confidentiality immediately; share identity and details only with a lawyer or once consent has been obtained.
Acknowledge the discloser, explain (at a high level) what will happen next, and offer appropriate support, without promising a particular outcome.
Triage the matter for seriousness, urgency, legal exposure and conflicts of interest before deciding the forum and process.
Determine the right decision-making body, full Board, sub-committee, or directors excluding any conflicted member, and record why.
Commission an investigation that is properly scoped and independent of anyone implicated; use external investigators where independence requires it.
Preserve relevant documents and data early; guard against any destruction, alteration or file sanitisation.
Actively monitor for and prevent any detriment or retaliation against the discloser or anyone suspected of disclosing.
Take legal advice early on obligations, privilege, and any mandatory reporting to regulators (for example, ASIC or APRA).
Minute the Board’s decisions and reasons contemporaneously; the quality of the record is the organisation’s best evidence of good governance.
Resist the two reflexes that destroy trust: defending the organisation prematurely, and seeking to identify or isolate the discloser.

After, Resolution, Remediation and Learning

Act on Findings, Remediate Causes, Close the Loop
Ensure the Board acts on the investigation’s findings, addressing root causes, not just the immediate symptom.
Confirm the discloser has suffered no detriment, and continue to monitor for delayed or subtle retaliation.
Check on the discloser’s wellbeing and, where appropriate, communicate the outcome to them to the extent permissible.
Meet any external reporting, disclosure or continuous-disclosure obligations, taking advice on timing and content.
Hold individuals accountable where wrongdoing is substantiated, applying consistent and proportionate consequences.
Feed lessons back into the policy, internal controls, training and culture; update the policy if gaps were exposed.
Record formally what changed as a result of the disclosure, evidence of a functioning, responsive system.
Review how the process itself performed: what worked, what did not, and what to improve before the next disclosure.
Report appropriately to the Board (and to shareholders or regulators where required) on themes and systemic issues, in de-identified form.
Reaffirm, visibly, that speaking up was the right thing to do, reinforcing the culture for the next person who must decide whether to come forward.

Ten Governing Principles for the Chair

  1. Readiness beats reaction, the response is decided before the disclosure arrives.
  2. Tone is set at the top, and disbelieved unless it is acted on.
  3. An informal word to a director can carry the full weight of the law, treat it accordingly.
  4. Protect the person first; the information and the process depend on it.
  5. Confidentiality is a legal obligation, not a courtesy.
  6. Retaliation turns a contained problem into the organisation’s own breach.
  7. Independence of investigation is non-negotiable where leadership is implicated.
  8. Contemporaneous documentation is the Board’s best defence and its discipline.
  9. Remediate the cause, not just the case.
  10. Close the loop visibly, the next whistleblower is watching.

A Board is rarely judged by whether misconduct occurred, misconduct occurs in the best-run organisations. It is judged by what it did when someone found the courage to say so.

Bibliography and Source References

The following main sources informed this guide. Legislative and case references should be confirmed against the current consolidated versions, and specialist legal advice obtained for any specific matter.

No.Author or IssuerTitle or ReferenceSource
1ASICProtections for corporate sector whistleblowersASIC website (asic.gov.au)
2Parliament of AustraliaTreasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 (Cth)Royal Assent 12 March 2019
3Parliament of AustraliaCorporations Act 2001 (Cth), Part 9.4AAAFederal Register of Legislation / AustLII
4ASICRegulatory Guide 270: Whistleblower policies (RG 270)13 November 2019
5Parliament of AustraliaCorporations Act 2001 (Cth), ss 1317AAA, 1317AAC (eligible whistleblowers and recipients)AustLII
6Parliament of AustraliaCorporations Act 2001 (Cth), s 1317AA (disclosable matters)AustLII
7Parliament of AustraliaCorporations Act 2001 (Cth), s 1317AI (whistleblower policies); ASIC INFO 247AustLII / ASIC
8Parliament of AustraliaCorporations Act 2001 (Cth), ss 1317AC, 1317AD, 1317AE (detriment, victimisation, compensation)AustLII
9Government Accountability Project / TIMETIME Persons of the Year 2002, Watkins, Cooper, Rowley; commentary on Enron and WorldComwhistleblower.org; TIME
10US CongressSarbanes-Oxley Act of 2002, Pub. L. 107-204US Government
11Commonwealth of AustraliaHayne Royal Commission Final Report (2019); Senate inquiry into CBA / ASIC (2014)Royal Commission / Parliament
12Federal Court of AustraliaMount v Dover Castle Metals Pty Ltd [2025] FCA 101; Reiche v Neometals Ltd (No 2) [2025] FCA 125Federal Court of Australia
13European UnionDirective (EU) 2019/1937 (EU Whistleblowing Directive)Official Journal of the EU

Endnotes

  1. Corporations Act 2001 (Cth) s 1317AAA (eligible whistleblower); s 1317AAC (eligible recipient).
  2. Government Accountability Project; TIME Persons of the Year 2002 (Watkins, Cooper, Rowley).
  3. Sarbanes-Oxley Act of 2002 (US), Pub. L. 107-204.
  4. Public Interest Disclosure Act 1998 (UK), inserting Part IVA into the Employment Rights Act 1996; Enterprise and Regulatory Reform Act 2013 (UK).
  5. Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law (EU Whistleblowing Directive).
  6. Public Interest Disclosure Act 2013 (Cth) (Australian public sector).
  7. Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 (Cth); Royal Assent 12 March 2019.
  8. Taxation Administration Act 1953 (Cth) Part IVD (tax whistleblower regime).
  9. Senate Economics References Committee inquiry into CBA / ASIC (2014); Royal Commission into Misconduct in the Banking, Superannuation and Financial Services Industry (Hayne Royal Commission), Final Report, 2019.
  10. Mount v Dover Castle Metals Pty Ltd [2025] FCA 101; Reiche v Neometals Ltd (No 2) [2025] FCA 125.
  11. Corporations Act 2001 (Cth) s 1317AA (disclosable matters); reasonable grounds to suspect standard.
  12. Corporations Act 2001 (Cth) ss 1317AC, 1317AD (detriment / victimisation); s 1317AE (compensation and remedies).
  13. Corporations Act 2001 (Cth) s 1317AI (whistleblower policy requirement); ASIC INFO 247.
  14. ASIC, Regulatory Guide 270: Whistleblower policies (RG 270), 13 November 2019.

The Chair’s Guide to Whistleblower Events
©CHAIRS Global Pty Ltd all rights reserved

This publication is the intellectual property of CHAIRS Global and is provided exclusively for the use of authorised recipients. It may not be reproduced, distributed, shared, quoted, or transmitted in whole or in part without the prior written permission of CHAIRS Global. For further information or permissions requests, please contact CHAIRS Global.

This was a complimentary article

Become a member to access our full suite of intelligence.

Become a Member