SlideShare ist ein Scribd-Unternehmen logo
1 von 45
2021 Global Whistleblowers Day
ISO 37002 Roadmap
Prof. Hernan Huwyler
The compliance think
tank in the Nordics
and beyond
Certifications Compliance Privacy InfoSec Risk
ISO 37301
First global
certifiable
standard
Improves
corporate
defense and
board buy-in
ISO 37000 > Governance of
organizations (Q3 2021, high level
structure)
ISO 37301:2021 > Compliance
management systems
37002 > Whistleblowing
management systems (Q4 2021)
The missing relatives
ISO 10002:2018 > Quality
management, customer
satisfaction, guidelines for
complaints handling in
organizations
The missing relatives
Disclosure 102-17 of the
Global Reporting Initiative>
Mechanisms for advice and
concerns about ethics
ISO 37000 Draft
Governance of organizations
Whistleblowing as a channel of information
The governing body should ensure
• its controls and internal and external assurance
• Its process to receive, assess, monitor and react
ISO 37301:2021
Management system
• Organization to meet compliance objectives
• Interration with internal and external parties
• Policies, procedures, people, platform
• Governance of tasks and controls to document
ISO 37301:2021
Compliance management systems
Whistleblowing as a requirement to raise concerns
The governing body should
• consider anonymity or confidentiality
• cover the reporting and guidance
• communicate to employees and agents
• prevent fear for retaliation
ISO 37301:2021
Requirements for investigations
• for allegations and misconduct suspicions
• by employees and third-parties
• policies for investigation protocol, disciplinary
actions and addressing remediation measures
• independent and complete
• escalation of the reporting of findings
ISO 37301:2021
Requires to identify root causes on non-
compliances
• extent and impact
• pervasiveness of internal controls
• number and level of the personnel involved
• duration
• frequency
ISO 37301:2021
Requires to incorporate data and trends of
whistleblowing channels in assessing the
effectiveness of the compliance systems
• internal and externa reporting (e.g. police)
• by source > employee, third parties
• emerging issues
ISO 37301:2021
Excludes
incentives for
reporting
ISO 37301:2021
Requires to ensure anti retaliation controls
• Implement a leniency program
• Have an independent investigative team
• Prevent risks in the complaint ramifications
• Monitor peer pressure, bullying and exclusion
ISO 37301:2021
• Approve changes in work conditions
• Include the impact on family members
• Provide financial and emotional support
• Protect whistleblowers from 3 to 5 years
ISO 37301:2021
Excludes
incentives for
reporting
ISO 37002 process
Assess
Address
Close
Report
Concerns
ISO 37002 wrongdoing
Current of past action
or omission causing
harm
ISO 37002 wrongdoing
Harm to
• human rights
• environment
• public health and safety
• safe work-practices
• public interests
ISO 37002 wrongdoing
Action or omission
• unethical behavior
• fraud, and corruption
• breach of law
• breach of code of conduct or
policy
ISO 37002 wrongdoing
• gross negligence
• discrimination, bullying and
harassment
• unauthorized use of public funds
• abuse of authority
• conflict of interest
• gross waste or mismanagement
ISO 37002 whistleblowing
Reporting of wrongdoing by
a whistleblower who has
reasonable grounds to
believe that the information
reported is true at the time of
reporting
ISO 37002 whistleblowing
Channels
• verbal
• in person
• in writing
• in electronic format
• in digital format
ISO 37002 whistleblowing
• open > whistleblower identity
and report disclosed
• confidential > whistleblower
identity and report not disclosed
until consent or legally required
• anonymous > whistleblower
identity unknown
ISO 37002 whistleblowing
• confidential >
• incentive to increase the
reporting (reference 3/5
reports a year per 10k
employees)
• better protocols and practices
• strong data security controls
ISO 37002 Step 1
Understand the context
• Public complaints from external stakeholders
• Past complaints from staff
• Non compliances and integrity breaches
• Past threats to whistleblowers
• Relationship with compliance systems
ISO 37002 Step 1
Scope
• Size
• Structure
• Locations
• Culture
• Staff needs
• Business model
• Associates
• Regulations
• Exposure to
public interests
• Stakeholders´
expectations
ISO 37002 Step 1
Who can report?
Past, current or future:
• Employees
• External parties
• Associated people
• Union representatives
ISO 37002 Step 2
Plan objectives for whistleblowing
• Assess compliance risks > ISO 31000/37301
• Implement and communicate the policy with
given principles, responsibilities
• Monitor by top management
• Ask and receive information about the
efficiency of the whistleblowing system
ISO 37002 Step 2
Data protection
• Identify who can manage and approve
accesses > need-to-known and consent
• Implement security controls > enhanced
controls on personal data
• Ensure data retention and rules for deletion
• Log activities
ISO 37002 Step 2
Policy
• Implement timely and comprehensive non
retaliation measures
• Enable and simplify the reporting
• Ensure the integrity and confidentiality
• Assess capabilities and resources
• Train employees and third parties
ISO 37002 Step 3
Acknowledge the report
• Provide a receipt to the whistleblower
• Cover all channels > emails, web, phone, app
• If decided, secure anonymity > no capture Ips
• Ensure two-way anonymous exchanges
• Include the case of referrals
ISO 37002 Step 3
Acknowledge the report
• What > facts, impact, already reported
• Where > jurisdiction of wrongdoing
• When > past, ongoing, future
• Who > accused, may know, seniority levels
• How > evidence, submit documentation, risks for
whistleblower or others
ISO 37002 Step 4
Decide what to do > triage
• Assess the impact of the potential wrongdoing
on the whistleblower, staff, organization and
stakeholders
• Categorize/prioritize to allocate resources
• Start preliminary measures such as protecting
the whistleblower and the evidence
ISO 37002 Step 4
Assess if the case is
• reportable under the policy
• involving a criminal offence
• posing health, safety, operational continuity and
reputational risks
• able to be corroborated > firsthand or hearsay
• reported previously
ISO 37002 Step 5
Address the report
• Execute the investigation protocol
• Coordinate with HR, legal, audit, finance, etc
• Contain the potential impact > suspend staff
• Involve external parties > forensic consultants
• Monitor the investigation
ISO 37002 Step 6
Conclude the report
• Facilitate the decision with recommendations
• Report to internal and external parties >
whistleblower, law enforcement, regulators
• Identify lessons learned
ISO 37002 Step 6
Remediate vulnerabilities
• Take corrective actions to address causes of
non-conformities
• Follow up the remediation plans
ISO 37002 Step 7
Audit the whistleblowing system
• Conduct regular internal audits to evaluate
the system
• Verify the effective implementation
• Review the documentation against policies,
objectives and controls
ISO 37002 Step 7
Audit the whistleblowing system
• Conduct regular internal audits to evaluate
the system
• Verify the effective implementation
• Review the documentation against policies,
objectives and controls
ISO 37002 Step 7
Improve the system
• Assess the suitability and adequacy
• Evaluate the impact of changes
• Ask for regular and consistent feedback
• Compare results against objectives
• Change the system with improvement
opportunities
There are four types of employees
• those who would expose the truth,
• those who would suffer serious
consequences for exposing the truth,
• those who would know the truth but kept it
for their safety, and
• those who wouldn´t stand for what is the
truth
Two and Two Short
by Babak Anvari
@hewyler
/hernanwyler
mydailyexecutive.blogspot.com
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap

Weitere ähnliche Inhalte

Was ist angesagt?

Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementationPrivacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementationPECB
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance BOC Group
 
ISMS Part I
ISMS Part IISMS Part I
ISMS Part Ikhushboo
 
Basic introduction to iso27001
Basic introduction to iso27001Basic introduction to iso27001
Basic introduction to iso27001Imran Ahmed
 
Presentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCMPresentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCMShantanu Rai
 
How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...Hernan Huwyler, MBA CPA
 
Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001technakama
 
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...Instansi
 
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...iFour Consultancy
 
ISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdfISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdfSerkanRafetHalil1
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementationRalf Braga
 
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and DifferencesCMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and DifferencesPECB
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewNaresh Rao
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?PECB
 
Demo of ISO 37001:2016 documentation kit
Demo of ISO 37001:2016 documentation kitDemo of ISO 37001:2016 documentation kit
Demo of ISO 37001:2016 documentation kitGlobal Manager Group
 
ISO 9001:2015 Reshaping the role of the auditor - updated version
ISO 9001:2015 Reshaping the role of the auditor - updated versionISO 9001:2015 Reshaping the role of the auditor - updated version
ISO 9001:2015 Reshaping the role of the auditor - updated versionBywater Training
 

Was ist angesagt? (20)

Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementationPrivacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance
 
ISMS Part I
ISMS Part IISMS Part I
ISMS Part I
 
Basic introduction to iso27001
Basic introduction to iso27001Basic introduction to iso27001
Basic introduction to iso27001
 
Presentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCMPresentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCM
 
Iso 37000
Iso 37000Iso 37000
Iso 37000
 
How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...
 
Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
 
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
ISO 37001 : Anti Bribery Management System Fraud & Bribery Concepts, Laws & R...
 
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
ISO 27001 2013 Clause 4 - context of an organization - by Software developmen...
 
27001 awareness Training
27001 awareness Training27001 awareness Training
27001 awareness Training
 
ISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdfISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdf
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementation
 
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and DifferencesCMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
Coso framework
Coso frameworkCoso framework
Coso framework
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Demo of ISO 37001:2016 documentation kit
Demo of ISO 37001:2016 documentation kitDemo of ISO 37001:2016 documentation kit
Demo of ISO 37001:2016 documentation kit
 
ISO 9001:2015 Reshaping the role of the auditor - updated version
ISO 9001:2015 Reshaping the role of the auditor - updated versionISO 9001:2015 Reshaping the role of the auditor - updated version
ISO 9001:2015 Reshaping the role of the auditor - updated version
 

Ähnlich wie Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap

Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Nimonik
 
Thorough Compliance Lac Megantic
Thorough Compliance Lac MeganticThorough Compliance Lac Megantic
Thorough Compliance Lac Meganticssuser1246df
 
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...Egyptian Engineers Association
 
Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Chandan Singh Ghodela
 
The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...
The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...
The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...ExternalEvents
 
ISO 27701 Essentials: Building a Robust Privacy Management System
ISO 27701 Essentials: Building a Robust Privacy Management SystemISO 27701 Essentials: Building a Robust Privacy Management System
ISO 27701 Essentials: Building a Robust Privacy Management SystemShyamMishra72
 
Get your Ducks in a Row - The OCR Audit Season is About to Begin
Get your Ducks in a Row - The OCR Audit Season is About to BeginGet your Ducks in a Row - The OCR Audit Season is About to Begin
Get your Ducks in a Row - The OCR Audit Season is About to BeginID Experts
 
Quality and Safety in Primary Care by VLE
Quality and Safety in Primary Care by VLEQuality and Safety in Primary Care by VLE
Quality and Safety in Primary Care by VLEAtlantic Training, LLC.
 
FRSecure Sales Deck
FRSecure Sales DeckFRSecure Sales Deck
FRSecure Sales DeckEvan Francen
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksIT Governance Ltd
 
ISO 45001 Key Implementation Steps
ISO 45001 Key Implementation StepsISO 45001 Key Implementation Steps
ISO 45001 Key Implementation StepsPECB
 
Dancyrityshy 1foundatioieh
Dancyrityshy 1foundatioiehDancyrityshy 1foundatioieh
Dancyrityshy 1foundatioiehAnne Starr
 
ISMS Requirements
ISMS RequirementsISMS Requirements
ISMS Requirementshumanus2
 
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due DiligenceResilient Systems
 
Integrated ohsas 18001
Integrated ohsas 18001Integrated ohsas 18001
Integrated ohsas 18001soebagja
 
Tips for Implementing a Whistleblower Hotline
Tips for Implementing a Whistleblower HotlineTips for Implementing a Whistleblower Hotline
Tips for Implementing a Whistleblower HotlineCase IQ
 
ISO 45001 and Organisations as Complex Adaptive Systems
ISO 45001 and Organisations as Complex Adaptive SystemsISO 45001 and Organisations as Complex Adaptive Systems
ISO 45001 and Organisations as Complex Adaptive SystemsSAMTRAC International
 

Ähnlich wie Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap (20)

Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
 
Thorough Compliance Lac Megantic
Thorough Compliance Lac MeganticThorough Compliance Lac Megantic
Thorough Compliance Lac Megantic
 
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
 
Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001
 
Intro to ISO
Intro to ISOIntro to ISO
Intro to ISO
 
The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...
The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...
The problematic of certification and control for GIs, by Rainer Bächi (IMO Sw...
 
ISO 27701 Essentials: Building a Robust Privacy Management System
ISO 27701 Essentials: Building a Robust Privacy Management SystemISO 27701 Essentials: Building a Robust Privacy Management System
ISO 27701 Essentials: Building a Robust Privacy Management System
 
Get your Ducks in a Row - The OCR Audit Season is About to Begin
Get your Ducks in a Row - The OCR Audit Season is About to BeginGet your Ducks in a Row - The OCR Audit Season is About to Begin
Get your Ducks in a Row - The OCR Audit Season is About to Begin
 
Quality and Safety in Primary Care by VLE
Quality and Safety in Primary Care by VLEQuality and Safety in Primary Care by VLE
Quality and Safety in Primary Care by VLE
 
FRSecure Sales Deck
FRSecure Sales DeckFRSecure Sales Deck
FRSecure Sales Deck
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risks
 
ISO 45001 Key Implementation Steps
ISO 45001 Key Implementation StepsISO 45001 Key Implementation Steps
ISO 45001 Key Implementation Steps
 
Dancyrityshy 1foundatioieh
Dancyrityshy 1foundatioiehDancyrityshy 1foundatioieh
Dancyrityshy 1foundatioieh
 
Iso 27001 2013
Iso 27001 2013Iso 27001 2013
Iso 27001 2013
 
Risk - IT Services
Risk - IT ServicesRisk - IT Services
Risk - IT Services
 
ISMS Requirements
ISMS RequirementsISMS Requirements
ISMS Requirements
 
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
 
Integrated ohsas 18001
Integrated ohsas 18001Integrated ohsas 18001
Integrated ohsas 18001
 
Tips for Implementing a Whistleblower Hotline
Tips for Implementing a Whistleblower HotlineTips for Implementing a Whistleblower Hotline
Tips for Implementing a Whistleblower Hotline
 
ISO 45001 and Organisations as Complex Adaptive Systems
ISO 45001 and Organisations as Complex Adaptive SystemsISO 45001 and Organisations as Complex Adaptive Systems
ISO 45001 and Organisations as Complex Adaptive Systems
 

Mehr von Hernan Huwyler, MBA CPA

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfHernan Huwyler, MBA CPA
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Hernan Huwyler, MBA CPA
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsHernan Huwyler, MBA CPA
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceHernan Huwyler, MBA CPA
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler, MBA CPA
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfHernan Huwyler, MBA CPA
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerHernan Huwyler, MBA CPA
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksHernan Huwyler, MBA CPA
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerHernan Huwyler, MBA CPA
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler, MBA CPA
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?Hernan Huwyler, MBA CPA
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software DevelopmentHernan Huwyler, MBA CPA
 
Information Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksInformation Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksHernan Huwyler, MBA CPA
 
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwylerStronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwylerHernan Huwyler, MBA CPA
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento Hernan Huwyler, MBA CPA
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Hernan Huwyler, MBA CPA
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler, MBA CPA
 

Mehr von Hernan Huwyler, MBA CPA (20)

Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdfProf. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
Prof. Hernan Huwyler IE Law School - AI Risks and Controls.pdf
 
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
Asociacion Profesionistas de Compliance - Initiatives to Reduce the Cost of C...
 
Model to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdfModel to Quantify Compliance Risks.pdf
Model to Quantify Compliance Risks.pdf
 
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat MapsProf Hernan Huwyler MBA CPA - Ditch your Heat Maps
Prof Hernan Huwyler MBA CPA - Ditch your Heat Maps
 
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional ComplianceProfesor Hernan Huwyler MBA CPA - Operacional Compliance
Profesor Hernan Huwyler MBA CPA - Operacional Compliance
 
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023 Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
Hernan Huwyler - IE Compliance Corporate Risk Management Full 2023
 
The Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdfThe Behavioral Science of Compliance CUMPLEN.pdf
The Behavioral Science of Compliance CUMPLEN.pdf
 
R is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using RR is for Risk 2 Risk Management using R
R is for Risk 2 Risk Management using R
 
Compliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan HuwylerCompliance and the russian invasion - Prof Hernan Huwyler
Compliance and the russian invasion - Prof Hernan Huwyler
 
DPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy RisksDPO Day Conference - Minimizing Privacy Risks
DPO Day Conference - Minimizing Privacy Risks
 
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan HuwylerMaster in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
Master in Sustainability Leadership Sustainability Risks Prof Hernan Huwyler
 
Cyber Laundering and the AML Directives
Cyber Laundering and the AML DirectivesCyber Laundering and the AML Directives
Cyber Laundering and the AML Directives
 
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
Hernan Huwyler - Iberoamerican Compliance Conference UCM Congreso Iberoameric...
 
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
ARENA - Prof Hernan Huwyler - Debate Is Machine Learning Mature Enough?
 
Qa Financials - 10 Smart Controls for Software Development
Qa Financials  - 10 Smart Controls for Software DevelopmentQa Financials  - 10 Smart Controls for Software Development
Qa Financials - 10 Smart Controls for Software Development
 
Information Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT RisksInformation Risk Management - Cyber Risk Management - IT Risks
Information Risk Management - Cyber Risk Management - IT Risks
 
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwylerStronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
Stronger 2021 Building the Blocks to Quantify Cyber Risks - Prof hernan huwyler
 
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento IE Curso  ISO 37301 Aseguramiento de Controles de Cumplimiento
IE Curso ISO 37301 Aseguramiento de Controles de Cumplimiento
 
Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks Strategy Insights - How to Quantify IT Risks
Strategy Insights - How to Quantify IT Risks
 
Hernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized WorldHernan Huwyler - Boards in a Digitalized World
Hernan Huwyler - Boards in a Digitalized World
 

Kürzlich hochgeladen

GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfGUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfDanny Diep To
 
Introducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsIntroducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsKnowledgeSeed
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFChandresh Chudasama
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryEffective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryWhittensFineJewelry1
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationAnamaria Contreras
 
Supercharge Your eCommerce Stores-acowebs
Supercharge Your eCommerce Stores-acowebsSupercharge Your eCommerce Stores-acowebs
Supercharge Your eCommerce Stores-acowebsGOKUL JS
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
WSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfWSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfJamesConcepcion7
 
BAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxBAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxran17april2001
 
Planetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in LifePlanetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in LifeBhavana Pujan Kendra
 
business environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxbusiness environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxShruti Mittal
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsIndiaMART InterMESH Limited
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Americas Got Grants
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdfChris Skinner
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024Adnet Communications
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...SOFTTECHHUB
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...ssuserf63bd7
 

Kürzlich hochgeladen (20)

GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdfGUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
GUIDELINES ON USEFUL FORMS IN FREIGHT FORWARDING (F) Danny Diep Toh MBA.pdf
 
Introducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applicationsIntroducing the Analogic framework for business planning applications
Introducing the Analogic framework for business planning applications
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDF
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold JewelryEffective Strategies for Maximizing Your Profit When Selling Gold Jewelry
Effective Strategies for Maximizing Your Profit When Selling Gold Jewelry
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement Presentation
 
Supercharge Your eCommerce Stores-acowebs
Supercharge Your eCommerce Stores-acowebsSupercharge Your eCommerce Stores-acowebs
Supercharge Your eCommerce Stores-acowebs
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors Data
 
WSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdfWSMM Media and Entertainment Feb_March_Final.pdf
WSMM Media and Entertainment Feb_March_Final.pdf
 
BAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxBAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptx
 
Planetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in LifePlanetary and Vedic Yagyas Bring Positive Impacts in Life
Planetary and Vedic Yagyas Bring Positive Impacts in Life
 
business environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxbusiness environment micro environment macro environment.pptx
business environment micro environment macro environment.pptx
 
Welding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan DynamicsWelding Electrode Making Machine By Deccan Dynamics
Welding Electrode Making Machine By Deccan Dynamics
 
WAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdfWAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdf
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf20200128 Ethical by Design - Whitepaper.pdf
20200128 Ethical by Design - Whitepaper.pdf
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
 

Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap

  • 1. 2021 Global Whistleblowers Day ISO 37002 Roadmap Prof. Hernan Huwyler
  • 2. The compliance think tank in the Nordics and beyond Certifications Compliance Privacy InfoSec Risk
  • 5. ISO 37000 > Governance of organizations (Q3 2021, high level structure) ISO 37301:2021 > Compliance management systems 37002 > Whistleblowing management systems (Q4 2021)
  • 6. The missing relatives ISO 10002:2018 > Quality management, customer satisfaction, guidelines for complaints handling in organizations
  • 7. The missing relatives Disclosure 102-17 of the Global Reporting Initiative> Mechanisms for advice and concerns about ethics
  • 8. ISO 37000 Draft Governance of organizations Whistleblowing as a channel of information The governing body should ensure • its controls and internal and external assurance • Its process to receive, assess, monitor and react
  • 9. ISO 37301:2021 Management system • Organization to meet compliance objectives • Interration with internal and external parties • Policies, procedures, people, platform • Governance of tasks and controls to document
  • 10. ISO 37301:2021 Compliance management systems Whistleblowing as a requirement to raise concerns The governing body should • consider anonymity or confidentiality • cover the reporting and guidance • communicate to employees and agents • prevent fear for retaliation
  • 11. ISO 37301:2021 Requirements for investigations • for allegations and misconduct suspicions • by employees and third-parties • policies for investigation protocol, disciplinary actions and addressing remediation measures • independent and complete • escalation of the reporting of findings
  • 12. ISO 37301:2021 Requires to identify root causes on non- compliances • extent and impact • pervasiveness of internal controls • number and level of the personnel involved • duration • frequency
  • 13. ISO 37301:2021 Requires to incorporate data and trends of whistleblowing channels in assessing the effectiveness of the compliance systems • internal and externa reporting (e.g. police) • by source > employee, third parties • emerging issues
  • 15. ISO 37301:2021 Requires to ensure anti retaliation controls • Implement a leniency program • Have an independent investigative team • Prevent risks in the complaint ramifications • Monitor peer pressure, bullying and exclusion
  • 16. ISO 37301:2021 • Approve changes in work conditions • Include the impact on family members • Provide financial and emotional support • Protect whistleblowers from 3 to 5 years
  • 19. ISO 37002 wrongdoing Current of past action or omission causing harm
  • 20. ISO 37002 wrongdoing Harm to • human rights • environment • public health and safety • safe work-practices • public interests
  • 21. ISO 37002 wrongdoing Action or omission • unethical behavior • fraud, and corruption • breach of law • breach of code of conduct or policy
  • 22. ISO 37002 wrongdoing • gross negligence • discrimination, bullying and harassment • unauthorized use of public funds • abuse of authority • conflict of interest • gross waste or mismanagement
  • 23. ISO 37002 whistleblowing Reporting of wrongdoing by a whistleblower who has reasonable grounds to believe that the information reported is true at the time of reporting
  • 24. ISO 37002 whistleblowing Channels • verbal • in person • in writing • in electronic format • in digital format
  • 25. ISO 37002 whistleblowing • open > whistleblower identity and report disclosed • confidential > whistleblower identity and report not disclosed until consent or legally required • anonymous > whistleblower identity unknown
  • 26. ISO 37002 whistleblowing • confidential > • incentive to increase the reporting (reference 3/5 reports a year per 10k employees) • better protocols and practices • strong data security controls
  • 27. ISO 37002 Step 1 Understand the context • Public complaints from external stakeholders • Past complaints from staff • Non compliances and integrity breaches • Past threats to whistleblowers • Relationship with compliance systems
  • 28. ISO 37002 Step 1 Scope • Size • Structure • Locations • Culture • Staff needs • Business model • Associates • Regulations • Exposure to public interests • Stakeholders´ expectations
  • 29. ISO 37002 Step 1 Who can report? Past, current or future: • Employees • External parties • Associated people • Union representatives
  • 30. ISO 37002 Step 2 Plan objectives for whistleblowing • Assess compliance risks > ISO 31000/37301 • Implement and communicate the policy with given principles, responsibilities • Monitor by top management • Ask and receive information about the efficiency of the whistleblowing system
  • 31. ISO 37002 Step 2 Data protection • Identify who can manage and approve accesses > need-to-known and consent • Implement security controls > enhanced controls on personal data • Ensure data retention and rules for deletion • Log activities
  • 32. ISO 37002 Step 2 Policy • Implement timely and comprehensive non retaliation measures • Enable and simplify the reporting • Ensure the integrity and confidentiality • Assess capabilities and resources • Train employees and third parties
  • 33. ISO 37002 Step 3 Acknowledge the report • Provide a receipt to the whistleblower • Cover all channels > emails, web, phone, app • If decided, secure anonymity > no capture Ips • Ensure two-way anonymous exchanges • Include the case of referrals
  • 34. ISO 37002 Step 3 Acknowledge the report • What > facts, impact, already reported • Where > jurisdiction of wrongdoing • When > past, ongoing, future • Who > accused, may know, seniority levels • How > evidence, submit documentation, risks for whistleblower or others
  • 35. ISO 37002 Step 4 Decide what to do > triage • Assess the impact of the potential wrongdoing on the whistleblower, staff, organization and stakeholders • Categorize/prioritize to allocate resources • Start preliminary measures such as protecting the whistleblower and the evidence
  • 36. ISO 37002 Step 4 Assess if the case is • reportable under the policy • involving a criminal offence • posing health, safety, operational continuity and reputational risks • able to be corroborated > firsthand or hearsay • reported previously
  • 37. ISO 37002 Step 5 Address the report • Execute the investigation protocol • Coordinate with HR, legal, audit, finance, etc • Contain the potential impact > suspend staff • Involve external parties > forensic consultants • Monitor the investigation
  • 38. ISO 37002 Step 6 Conclude the report • Facilitate the decision with recommendations • Report to internal and external parties > whistleblower, law enforcement, regulators • Identify lessons learned
  • 39. ISO 37002 Step 6 Remediate vulnerabilities • Take corrective actions to address causes of non-conformities • Follow up the remediation plans
  • 40. ISO 37002 Step 7 Audit the whistleblowing system • Conduct regular internal audits to evaluate the system • Verify the effective implementation • Review the documentation against policies, objectives and controls
  • 41. ISO 37002 Step 7 Audit the whistleblowing system • Conduct regular internal audits to evaluate the system • Verify the effective implementation • Review the documentation against policies, objectives and controls
  • 42. ISO 37002 Step 7 Improve the system • Assess the suitability and adequacy • Evaluate the impact of changes • Ask for regular and consistent feedback • Compare results against objectives • Change the system with improvement opportunities
  • 43. There are four types of employees • those who would expose the truth, • those who would suffer serious consequences for exposing the truth, • those who would know the truth but kept it for their safety, and • those who wouldn´t stand for what is the truth Two and Two Short by Babak Anvari