A whistleblowing policy is a formal document that sets out how workers in an organisation can raise concerns about wrongdoing, unsafe practice, or malpractice. It explains:
- what types of concerns can be raised
- who workers can report to
- how reports will be handled
- what protections are available
The policy sits alongside the practical process for receiving, managing, and investigating concerns. It gives workers confidence that they can speak up without fear, and it gives organisations a structured way to respond when concerns are raised.
This guide is for anyone creating or updating a whistleblowing policy in the UK. It covers what a policy should contain, how it relates to UK whistleblowing law, and practical steps for implementation.
Free UK whistleblowing policy template
Save time creating or reviewing your policy with our adaptable template. It covers the essential elements of a UK whistleblowing policy and can be tailored to your organisation.
There is no general legal requirement for all UK employers to have a whistleblowing policy. However, some sectors are required to have one, and having a policy is widely considered good practice for any organisation that wants to foster a speak-up culture.
For most UK employers, having a whistleblowing policy is not a statutory requirement. The Public Interest Disclosure Act 1998 (PIDA) does not compel organisations to create a policy. Instead, the law protects workers who make protected disclosures regardless of whether the organisation has a policy.
Some regulated sectors are required to have whistleblowing policies or procedures:
- Early years settings: Since September 2025, the Early Years Foundation Stage (EYFS) statutory framework has required providers to have appropriate whistleblowing procedures in place for all staff.
- Schools: While not universally mandated, schools are strongly encouraged to have whistleblowing policies, and multi-academy trusts are increasingly expected to standardise them across their schools.
- Financial services: The FCA expects regulated firms to have robust whistleblowing arrangements in place.
- NHS organisations: NHS England has issued a national Freedom to Speak Up policy that all NHS organisations in England must implement.
Even when not legally required, having a whistleblowing policy is good practice for several reasons:
- It demonstrates a commitment to ethical standards and accountability.
- It gives workers clear guidance on how to raise concerns.
- It helps organisations respond consistently when concerns are raised.
- It can protect against claims of retaliation by showing the organisation took the matter seriously.
- It supports compliance with sector-specific guidance and regulatory expectations.
The Law Society, which provides a model whistleblowing policy template, notes that having a clear policy is "only one step in implementing effective whistleblowing arrangements" and recommends organisations "conduct an audit of their current arrangements".
A well-drafted whistleblowing policy typically covers the following areas.
The policy should explain why the organisation is implementing it, confirm the organisation's commitment to openness and accountability, and state that workers who raise concerns in good faith will be supported.
The policy should identify who it applies to (all workers, including employees, agency workers, contractors, trainees, and volunteers) and make clear that it does not replace the grievance procedure for personal employment concerns.
The policy should explain what types of wrongdoing may qualify as whistleblowing. The law protects disclosures relating to:
- criminal offences (such as fraud)
- breaches of legal obligations
- miscarriages of justice
- dangers to health and safety
- environmental damage
- sexual harassment
- deliberate concealment of any of the above
The policy should also make clear that the worker must reasonably believe the disclosure is in the public interest, meaning it affects others rather than just their own employment situation.
The policy should state that personal employment concerns—such as grievances about pay, working conditions, or treatment of the individual—should usually be dealt with through the grievance procedure unless they also involve wider public interest wrongdoing.
The policy should set out:
- who workers should normally report to (a line manager, HR, or a nominated whistleblowing officer)
- an alternative contact if the normal recipient is implicated
- how to make a report (verbally or in writing)
ACAS recommends: "You should make it as clear as possible to your employer that you're making a disclosure" and that while disclosures "do not need to be in writing... it's better to put it in writing so you have evidence".
The policy should explain how the organisation will protect the reporter's identity, including that reports will only be shared with those who need to know. It should also acknowledge that there may be circumstances where identity must be disclosed—for example, to protect someone from harm or to comply with a court order.
If the organisation allows anonymous reporting, the policy should explain:
- what anonymous reporting means (the organisation does not know the reporter's identity)
- that follow-up and updates depend on the reporting channel — a suitable anonymous system can support secure two-way communication without revealing identity, while email-only, paper or basic anonymous forms may provide no practical way to follow up
- the practical reality that context may still reveal identity
If anonymous reporting is not available, the policy should explain what confidential reporting means instead.
The policy should set out the organisation's approach to handling concerns, including:
- acknowledgment of receipt
- initial assessment and triage
- investigation or referral
- timescales
- keeping the reporter updated (where contactable)
- confidentiality throughout the process
The Law Society's model policy includes a section explaining that "the staff member who made the disclosure should be given certain (but not always all) information about the matter's progression".
The policy should acknowledge that workers may need to escalate their concern externally if they are not satisfied with the internal response. It should signpost:
- prescribed persons or bodies (regulators, government authorities)
- the circumstances in which external reporting is appropriate
- that disclosures to prescribed persons may also be protected
The policy should confirm that workers who make protected disclosures will be protected from detriment (unfair treatment) and, if they are employees, from unfair dismissal. It should also state that the organisation will not tolerate retaliation against whistleblowers.
The policy should state that knowingly making a false or malicious allegation may result in disciplinary action. This protects both the organisation and individuals who may be falsely accused.
The policy should explain how records of concerns will be kept, who will have access, how long records will be retained, and how data protection requirements will be met.
The policy should identify who is responsible for it and state when it will be reviewed. Annual review is recommended.
In practice, most organisations combine the policy and procedure into one document. However, they are conceptually different.
Policy: The statement of principles, commitment, and rules.
Procedure: The step-by-step process for raising and handling concerns.
A combined document typically starts with the policy statement and then sets out the practical procedure for making a report and how the organisation will respond. The "procedure" component addresses search intent for those looking for a whistleblowing procedure, often by outlining the reporting and investigation process.
For a broader introduction to the concept and UK legal framework, see What Is Whistleblowing?.
To qualify as whistleblowing under UK law, a worker must:
-
Reasonably believe that their disclosure shows one or more of the specified types of wrongdoing (criminal offence, breach of legal obligation, miscarriage of justice, danger to health and safety, environmental damage, sexual harassment, or concealment).
-
Reasonably believe that reporting the wrongdoing is in the public interest—meaning it affects others, not just the worker.
-
Make the report through appropriate channels—such as to their employer, a prescribed person, or a legal adviser.
| Concern type | Example |
|---|
| Criminal offence | An employer commits fraud or theft |
| Breach of legal obligation | An employer does not have the right insurance |
| Health and safety danger | Customers are served contaminated food |
| Environmental damage | Business activities pollute local rivers |
| Sexual harassment | A worker sexually harasses other workers |
| Concealment | Evidence of wrongdoing is deliberately hidden |
Important: Whether a specific situation qualifies as a protected disclosure depends on the facts. The examples above are illustrative only.
A grievance is usually a personal complaint about an employee's own employment situation—their pay, working conditions, or treatment by a manager. A whistleblowing concern is about wrongdoing that affects others (the public interest).
| Whistleblowing | Grievance |
|---|
| Primary concern | Wrongdoing affecting others (public interest) | Personal employment situation |
| Legal framework | PIDA 1998 | Employment law, ACAS code |
| Protection | Protection from detriment and dismissal | Employment rights apply |
| Confidentiality | May be anonymous or confidential | Usually not anonymous |
But they can overlap: As ACAS guidance notes, "grievances can also amount to whistleblowing if the grievance contains an appropriate disclosure of information and so should be dealt with as such".
For a detailed comparison, see our separate guide: Whistleblowing vs Grievance: What's the Difference?.
Safeguarding protects people from abuse, neglect, and harm. Whistleblowing is the act of raising a concern about wrongdoing.
A safeguarding concern could also form the subject of a whistleblowing disclosure. If a worker witnesses abuse and reports it, this is both a safeguarding concern and potentially a whistleblowing concern. However, not every safeguarding concern is whistleblowing (a family member raising a concern about a relative's care would not be), and not every whistleblowing concern is a safeguarding concern (reporting financial fraud may not involve safeguarding).
Urgent safeguarding concerns should be handled through safeguarding procedures without delay, regardless of the whistleblowing label.
Allowing anonymous reporting can help overcome fear of retaliation. Whether follow-up and updates remain possible depends on the reporting channel, not only on whether the reporter's identity is known.
| Anonymous | Confidential |
|---|
| Identity | The organisation does not know the reporter's identity | Known to authorised recipients but handled confidentially |
| Follow-up | Depends on the reporting channel. A suitable anonymous reporting system can support secure two-way follow-up without revealing identity | Direct follow-up is normally possible |
| Updates | Can be provided anonymously where the reporting channel supports return access or anonymous messaging | Direct updates are normally possible |
| Limitation | Email-only, paper or basic anonymous forms may provide no practical way to follow up | Confidentiality cannot always be guaranteed absolutely |
| Protection | Legal protection depends on the circumstances; anonymity can make some protections harder to evidence or enforce | Direct contact can make protections easier to evidence or enforce |
Even if a report is made anonymously, the substance may reveal the reporter's identity. If the report describes a specific incident that only a limited number of people could have witnessed, others may guess who raised the concern.
Organisations should be transparent about whether anonymous reporting is available and the limitations of using it. Workers should not be promised absolute anonymity that cannot be guaranteed.
A dedicated anonymous reporting channel can support organisations that want to offer confidential and anonymous routes, including secure two-way follow-up where the system supports it.
The following is a typical whistleblowing procedure.
A worker raises a concern through a reporting channel (in writing, in person, or via a secure reporting system).
The worker receives confirmation that the concern has been received. This should happen as soon as possible.
The recipient assesses whether the concern falls within the whistleblowing policy and whether the normal handler has a conflict of interest.
The concern is assigned to an appropriate person or team to handle. If the normal recipient is implicated, an alternative handler should be used.
Where possible and appropriate, the organisation contacts the reporter for clarification or additional evidence. Where the reporting channel supports anonymous two-way communication, the organisation can request clarification without requiring the reporter to reveal their identity. Basic anonymous forms or email-only routes may still make clarification impossible.
The concern is investigated internally or referred to an external body (a regulator, the police, or a prescribed person) if appropriate.
Where contactable, the reporter is informed of the outcome or told why no action was taken. Detailed findings may not always be shared due to confidentiality or employment matters.
Records of the concern and the investigation are retained in line with data protection requirements.
Organisations should review trends in whistleblowing concerns and report to senior leadership or governance bodies where appropriate.
Appropriate recipients include:
- line managers
- HR or Employee Relations teams
- compliance or governance teams
- a nominated whistleblowing officer
- senior leadership
- the board or audit committee
Crucially, the procedure should provide an alternative recipient if the normal contact is implicated in the wrongdoing. Whistleblowing concerns should not be funnelled exclusively through the person at the centre of the concern.
ACAS advises that if a worker has made a disclosure to their employer, "the problem is not resolved," they may then make the same disclosure to a prescribed body.
Good record keeping is essential for accountability and, in some sectors, regulatory compliance.
- Case records: Each concern should have a unique record with the date received, summary of the concern, and actions taken.
- Evidence: Attachments, documents, and notes should be stored securely.
- Access controls: Only those who need to know should have access.
- Audit history: Records should show who accessed the case, when, and why.
- Communications: Notes or records of any communications with the reporter should be maintained.
- Retention: Records should be retained for an appropriate period and then securely destroyed.
- Organisational continuity: If the handler leaves, the case record should be accessible to their successor.
A secure case management approach can support recording and audit trails for whistleblowing concerns.