ISO certificate
ISO 37002 Certification (Whistleblowing Management System)
A practical guide to speak‑up channels, impartial investigations, confidentiality, and evidence that builds trust with employees and stakeholders.
What ISO 37002 is (in operational terms)
ISO 37002 provides requirements and guidance for building a whistleblowing management system: how concerns are reported, assessed, investigated, and closed fairly. Audits focus on confidentiality, impartiality, non‑retaliation controls, and whether case handling is consistent and evidenced.
Common audit focus areas
- Reporting channels (anonymous where applicable) and access control to reports.
- Case intake, triage, and conflict-of-interest handling for investigators.
- Confidentiality and evidence control (who can see what, and why).
- Non‑retaliation measures and follow-up monitoring.
- Corrective actions, trends, and management review inputs.
- Training and communication: awareness of how to report and what to expect.
Typical evidence pack (examples)
- Whistleblowing policy + case handling procedure.
- Role/authority matrix + COI declarations for investigators.
- Case logs (sanitized), closure criteria, and corrective action records.
- Evidence retention and access control records.
- Training records and communication rollouts.
Related certificates
ISO 37002 is commonly implemented together with governance and integrity standards such as ISO 37001 and ISO 37301.
Next step
Want a clear path to certification?
Send your scope and target date and we’ll reply with an implementation path and quotation.