Following on from Part I, where we analysed the Australian legal framework and the common pitfalls for employers and employees, we will now consider the traits of a good, effective and safe compliance framework.
What a robust whistleblowing compliance program actually looks like
As a useful diagnostic for any organisation, the key question is: if someone reported tomorrow that a senior leader was doing something seriously wrong, what would actually happen? If the honest answer is that the report would reach people motivated to protect those complained of, that the investigation would be run by people with a stake in the outcome, that the reporter’s identity couldn’t reliably be protected, and that nothing would happen unless the matter became public or escalated out of control, then the program exists on paper only.
ASIC’s December 2025 benchmarking report, read alongside the KPMG and TerraCom matters, shows that this is far from a rare lapse.
The following is a list of nine traits of a good, effective and safe compliance structure.
1. A policy that is fit for purpose, not a document exercise
ASIC’s Regulatory Guide 270 sets out mandatory content for whistleblower policies at public companies and large proprietary companies: who is protected, what conduct is disclosable, who the eligible recipients are, how investigations will be conducted, and how the whistleblower will be protected from detriment.
ASIC’s own review of several companies in different sectors across Australia, as referred to in its December 2025 benchmarking report, found significant variation in practice, with many companies not adopting even basic best practices.
2. Reporting channels that are visible, accessible and independent
ASIC found that dedicated channels accounted for 69% of all disclosures received, yet 36% of companies had no dedicated web page and 20% had no hotline.
Good practice means offering multiple accessible channels that cater for anonymity, with at least one genuinely independent of the chain of command most likely to be implicated — the exact structural flaw the TerraCom and KPMG matters exposed. Companies that regularly communicate about their programs and provide recurring training achieve higher disclosure rates. Posters and periodic emails were among the most effective measures identified.
3. Treating complaints as risk intelligence, not as risk
This is arguably the most important cultural reframe. A rise in disclosures can indicate a stronger speak-up culture and greater trust in internal processes, and it surfaces issues an organisation might not otherwise identify.
A low disclosure rate is not automatically a healthy sign: it may simply mean people don’t trust the process. The instinct to treat internal complaints as reputational threats to be contained, rather than as valuable intelligence, is precisely the instinct that backfired at KPMG.
4. Independent, rigorous and properly resourced investigation
ASIC found that businesses closing cases in under three weeks had the lowest substantiation rates: speed is not quality.
Where a complaint implicates senior management, the investigation must sit above them in the governance structure (board or audit committee level), or be handled by external specialists.
Employment issues involving a whistleblower should be handled entirely separately from the disclosure itself, with separate documentation and different staff. The failure to maintain that separation is how whistleblowers end up managed out under cover of a performance process while the substantive complaint is quietly parked.
Aside from the reputational risk, this is also likely to lead to a costly general protections claim (adverse action) under the Fair Work Act.
5. Active identity protection
Where dedicated legislation applies, such as the Corporations Act, it is illegal to reveal a whistleblower’s identity, or information likely to lead to their identification, without consent.
As demonstrated by the KPMG case, where the identity of the whistleblower was inadvertently disclosed at a parliamentary hearing, the obligation to protect the whistleblower’s identity can be breached inadvertently even by people who believe they are acting responsibly.
A confidentiality obligation on paper is not enough: the number of people who know the reporter’s identity must be actively and operationally controlled from the outset, kept to a minimum and limited to those who need to know.
6. No adverse action
Victimisation extends well beyond dismissal: removal of responsibilities, social exclusion, reassignment, unfavourable performance reviews and denial of promotions all count as adverse action under the Fair Work Act, and the law presumes retaliation following a protected disclosure.
Good compliance means actively tracking the treatment of anyone who has disclosed and investigating promptly if their conditions appear to deteriorate.
7. Active support for the discloser
Beyond process, organisations should actively support the person who has come forward: offering counselling or Employee Assistance Program access, maintaining regular contact to check on their wellbeing, and demonstrating through action, not just policy, that the disclosure was valued.
8. Board and leadership ownership
Responsibility for preventing workplace misconduct sits with leadership, not HR alone. HR can implement measures, but ownership must be driven from the top.
Boards need regular, meaningful reporting: not just whether a policy exists, but how many disclosures were received, how they were categorised, how investigations were conducted, and the outcomes and timeframes. ASIC has been clear that strong whistleblower practices go to the core of good corporate governance.
9. Periodic review and staff feedback
Organisations should periodically seek feedback from employees about the whistleblower program itself: their knowledge of it, their trust in it, and their willingness to use it. A program that staff don’t know about, don’t trust, or don’t believe will protect them is a program that will fail exactly when it matters most.
The bottom line
Australian law offers real, if fragmented, protection for whistleblowers — but that protection is narrower than most people assume, procedurally demanding, and, as Boyle shows, unforgiving of the wrong method of disclosure.
For employers, TerraCom and KPMG demonstrate that a legally compliant policy is necessary but nowhere near sufficient.
The organisations that get this right treat disclosures as intelligence rather than threat, protect identity operationally rather than just on paper, and keep leadership genuinely accountable for what happens after a report is made — not just for whether a policy document exists.
More information: whistleblowing webinar
Praetorium Law’s Fito Pando Molina was kindly invited by Diligent to speak at the webinar “7 Vital Traits of a Trusted, Defensible Whistleblowing Program” on 22 July 2026.
To hear more insights on this topic visit: https://learn.diligent.com/Trusted_Whistleblowing_Program.html
Need legal advice on this topic?
Praetorium Law advises employers and employees on this and all other aspects of Employment Law. Contact us at info@praetoriumlaw.com to discuss how we can help.
© Praetorium Law 2026. This article is intended as general information only and does not constitute legal advice. Contact us for specific legal advice for your circumstances.
