Skip to main content
Rules Mate

Comply with corporate whistleblower protections (Part 9.4AAA Corporations Act)

Public companies and large proprietary companies must have a whistleblower policy and protect disclosers.

highcurrentongoingCriminal liability

Who must comply

Public companies, large proprietary companies and proprietary company trustees of RSEs must have a policy — except not-for-profit public companies limited by guarantee with consolidated revenue under $1 million (ASIC Instrument 2019/1146). The protections apply to all corporations.

What triggers it

Being a covered entity.

When due

Whistleblower policy in place; ongoing protection.

Evidence required

Whistleblower policy, training records, intake mechanism, investigation protocol.

Max penalty

No policy: strict liability offence up to 60 penalty units ($21,840). Breaching confidentiality or victimising a discloser: civil penalties up to $1.82M for individuals (5,000 penalty units), plus criminal liability

Who must comply with this? The applicability test by industry, business structure and size.

Summary

Part 9.4AAA of the Corporations Act (and Pt IVD of the Taxation Administration Act 1953) provides legal protections for whistleblowers reporting misconduct in corporations. Public companies, large proprietary companies and proprietary companies that are trustees of registrable superannuation entities must have a written whistleblower policy (s 1317AI). Exemption: ASIC Corporations (Whistleblower Policies) Instrument 2019/1146 relieves a public company limited by guarantee that is operated on a not-for-profit basis (and is not an RSE trustee) from the policy requirement for so long as its consolidated revenue is under $1 million in each financial year; once revenue reaches $1 million it has 6 months after the end of that financial year to adopt a policy. The whistleblower protections themselves still apply to exempt companies. Not having a required policy is a strict liability offence of up to 60 penalty units ($21,840). Confidentiality and victimisation breaches carry separate, much larger civil and criminal penalties.

Enforced by

Source legislation

Entity types

company

Topics

whistleblowergovernancedirectors

Related

Frequently asked questions

Who must comply with corporate whistleblower protections (Part 9.4AAA Corporations Act)?
Public companies, large proprietary companies and proprietary company trustees of RSEs must have a policy — except not-for-profit public companies limited by guarantee with consolidated revenue under $1 million (ASIC Instrument 2019/1146). The protections apply to all corporations.
What triggers corporate whistleblower protections (Part 9.4AAA Corporations Act)?
Being a covered entity.
When is corporate whistleblower protections (Part 9.4AAA Corporations Act) due?
Whistleblower policy in place; ongoing protection.
What is the maximum penalty for corporate whistleblower protections (Part 9.4AAA Corporations Act)?
No policy: strict liability offence up to 60 penalty units ($21,840). Breaching confidentiality or victimising a discloser: civil penalties up to $1.82M for individuals (5,000 penalty units), plus criminal liability
What evidence is required for corporate whistleblower protections (Part 9.4AAA Corporations Act)?
Whistleblower policy, training records, intake mechanism, investigation protocol.

Source: https://www.asic.gov.au/for-business-and-companies/. Rules Mate is not a law firm. Always verify against the live regulator source before acting.