Regulation and standard

What training do Australian whistleblower laws expect?

Short answer

The Corporations Act 2001 (Part 9.4AAA) requires public companies, large proprietary companies and corporate trustees of registrable superannuation entities to have and make available a whistleblower policy. The Act does not mandate training, but Regulatory Guide 270 from the Australian Securities and Investments Commission (ASIC) says entities should give every employee upfront and ongoing training, train managers to handle disclosures, and give specializt training to eligible recipients on confidentiality and detriment.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
6 min
Jurisdiction
Australia (Commonwealth)
Regulator
Australian Securities and Investments Commission (ASIC)

Key takeaways

  • Strengthened protections have applied since July 1, 2019, and the policy requirement in section 1317AI since January 1, 2020.
  • Failing to have and make available a compliant policy is a strict liability offense with a penalty of 60 penalty units (s1317AI(4)).
  • RG 270.131 to RG 270.137 set ASIC's training expectations: all employees, all levels of management, specializt training for eligible recipients, and overseas operations.
  • Breaching a whistleblower's confidentiality or causing detriment are civil penalty provisions as well as offenses, so managers and recipients need practical, tested knowledge.
  • Treasury's statutory review of the corporate and tax whistleblower regimes is under way; consultation closed on July 29, 2026.

What does the law require?

The Corporations Act requires certain companies to have a whistleblower policy covering specified content and to make it available to officers and employees. According to ASIC's RG 270, section 1317AI(5) requires the policy to cover:

  1. the protections available to whistleblowers, including under the Corporations Act
  2. to whom protected disclosures may be made, and how
  3. how the entity will support whistleblowers and protect them from detriment
  4. how the entity will investigate protected disclosures
  5. how the entity will ensure fair treatment of employees mentioned in or the subject of disclosures
  6. how the policy will be made available to officers and employees
  7. any matters prescribed by regulations

The Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 received Royal Assent on March 12, 2019 and the strengthened regime applied from July 1, 2019. ASIC reminded companies that policies were required by January 1, 2020. The legal text is in the Corporations Act 2001. This page reflects the law as at September 2026.

Which organizations must have a whistleblower policy?

Public companies, large proprietary companies and proprietary companies that are trustees of registrable superannuation entities must have a policy. RG 270.7 explains that a proprietary company is large for a financial year if it meets at least two of three tests: consolidated revenue of $50 million or more, consolidated gross assets of $25 million or more, or 100 or more employees at year end.

The protections apply more widely than the policy requirement. ASIC notes that the protections in Part 9.4AAA are available to any discloser who makes a qualifying disclosure, whether or not the entity must have a policy (RG 270.4), and that eligible whistleblowers include current and former employees, officers and contractors, and their relatives and dependants, whether identified or anonymous (ASIC). ASIC has given relief from the policy requirement to not-for-profit public companies limited by guarantee with annual consolidated revenue under $1 million.

What training does RG 270 expect?

RG 270 expects upfront and ongoing training for every employee, management training on handling disclosures, and specializt training for people with roles under the policy. RG 270.131 states that an entity "should conduct upfront and ongoing education and training regarding its whistleblower policy, processes and procedures. The training should be provided to every employee."

RG 270 training expectations by audience
AudienceRG 270 expectationParagraph
All employeesUpfront and ongoing training on the policy, processes and procedures; regular training keeps them freshRG 270.131 to 270.132
All levels of management, especially line managersAppropriate training in how to deal effectively with disclosuresRG 270.133
Eligible recipients and others with roles under the policySpecializt training on receiving and handling disclosures, including confidentiality and the prohibitions against detrimental conductRG 270.134
External eligible recipients such as auditors and actuariesBe informed of their obligations under the Corporations Act and tax whistleblower regimeRG 270.135
Overseas-based operationsAppropriate training, because disclosures to or about overseas entities may qualify for protectionRG 270.136
Everyone, after a policy changeTargeted communications and training, plus specializt training for role holdersRG 270.137

RG 270's Good practice tip 16 suggests employee training cover practical examples of disclosable matters, how to make a disclosure, how disclosers are protected and supported, examples of conduct that may cause detriment and its consequences, what the policy does not cover (such as personal work-related grievances), and where to raise other concerns. It suggests management training may be incorporated into management competency training.

What has ASIC observed in stronger programs?

ASIC's review of whistleblower programs found that firms with stronger programs trained all employees on when and how to make disclosures and trained the people who receive and handle them. REP 758, released March 2, 2023, reports good practices including annual training for all categories of eligible recipients that set legal requirements in a practical context, quick reference guides for recipients, and whistleblowing content delivered either as standalone e-learning or integrated into other mandatory training modules.

ASIC's media release on the report also noted that its 2020 review of 102 whistleblower policies found many fell short. A policy that staff have never been trained on is unlikely to protect the entity or the discloser.

How can training evidence whistleblower compliance?

Evidence should show that each audience can do what the policy asks of them, not only that they saw it. The mapping below is original and illustrative.

Illustrative mapping of whistleblower duties to learning outcomes and evidence
DutyAudienceLearning outcomeEvidence
Make the policy available (s1317AI(5)(f))All staffKnows where the policy is and the channels for disclosureInduction record, intranet access, knowledge check
Protect confidentialityEligible recipients, investigators, managersHandles a disclosure without revealing identity or identifying information except as permittedScenario assessment with a pass mark
Prevent detrimentLine managersRecognizes actions that could be detrimental and escalates risk of detrimentCase based assessment, manager attestation
Distinguish disclosures from grievancesManagers, HRCorrectly routes a personal work-related grievance versus a qualifying disclosureTriage exercise results
Investigate fairlyInvestigatorsFollows the investigation procedure, including fair treatment of people namedFile review against procedure

These records form part of an audit trail for the board. The guide on how to evidence training effectiveness to a regulator covers assessment design, and policy attestation explains why sign off alone is weak evidence.

Are the whistleblower laws changing?

A statutory review is under way but, as at September 2026, the obligations described here have not changed. Section 1317AK of the Corporations Act requires a review to start after July 1, 2024. Treasury's review page shows it as open, with consultation responses due by July 29, 2026 and a written report to government to follow. Training content should be versioned so it can be updated quickly if the review leads to amendments; see updating training when regulations change.

How does Knowledge Foundry approach this?

Knowledge Foundry structures the policy's required content, the protections and each audience's responsibilities as a framework, then links each audience to the scenarios they must handle correctly. If the statutory review changes the law, the affected concepts, modules and assessments can be identified from that structure.

Frequently asked questions

Is whistleblower training legally mandatory?

The Corporations Act requires a compliant policy that is made available to officers and employees, not a specific training program. ASIC's RG 270 says entities should train every employee, managers and eligible recipients. Training is also the most direct evidence that the policy has been made available and is understood.

How often should whistleblower training run?

RG 270 says upfront and ongoing, and that regular training keeps the policy fresh. It does not set an interval. ASIC's REP 758 observed annual training for eligible recipients as a good practice, and RG 270.137 expects extra training when the policy or procedures change.

Who are eligible recipients?

Eligible recipients are the people and bodies a whistleblower can disclose to and still be protected, including officers, senior managers, auditors, actuaries and people the entity authorizes to receive disclosures. RG 270.134 says they should receive specializt training on handling disclosures, confidentiality and detriment.

What is the penalty for not having a policy?

RG 270.24 says failing to have and make available a whistleblower policy is a strict liability offense with a penalty of 60 penalty units for individuals and companies, citing sections 1317AI(4) and 1311(1). The dollar value depends on the Commonwealth penalty unit amount in force.

Sources

  1. RG 270 Whistleblower policies, ASIC
  2. Regulatory Guide 270 Whistleblower policies (PDF), ASIC
  3. Protections for corporate sector whistleblowers, ASIC
  4. 19-372MR Whistleblower policies required from 1 January 2020 for certain large and public companies, ASIC
  5. REP 758 Good practices for handling whistleblower disclosures, ASIC
  6. 23-046MR ASIC publishes report on good practices for handling whistleblower disclosures, ASIC
  7. Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019, Federal Register of Legislation
  8. Corporations Act 2001, Federal Register of Legislation
  9. Statutory review of tax and corporate whistleblowing, The Treasury

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.