Ashio whistleblowing software
ISO 37002:2021

ISO 37002-aligned whistleblowing, anonymous by default.

ISO 37002 demands confidentiality, retaliation protection, and continuous improvement. Ashio delivers โ€” anonymous by design (no IP, no cookies, no fingerprinting), end-to-end encrypted, ISO 27001 hosted. Live in 10 minutes.

Overview

What is ISO 37002:2021?

ISO 37002:2021 is the international standard published by the International Organization for Standardization (ISO) that provides guidelines for whistleblowing management systems. Published in July 2021, it offers a framework for organizations to receive, assess, and act on reports of wrongdoing โ€” protecting whistleblowers from retaliation and ensuring due process. ISO 37002 complements the EU Whistleblowing Directive by providing a voluntary management system standard organizations can be audited against.

Key principles

The six core principles of ISO 37002

ISO 37002 defines six foundational principles that underpin an effective whistleblowing management system:

Trust and impartiality

The system must be designed to earn and maintain the trust of all stakeholders. Reports are handled impartially, without prejudice or bias.

Protection from retaliation

Whistleblowers must be protected from any form of retaliation โ€” whether direct (dismissal, demotion) or indirect (harassment, exclusion).

Confidentiality and anonymity

The identity of the whistleblower must be protected. Anonymous reporting must be accepted and processed with the same diligence as named reports.

Visibility and accessibility

The reporting channel must be clearly communicated and accessible to all relevant parties โ€” including employees, contractors, suppliers, and other stakeholders.

Timely and transparent process

Reports must be acknowledged promptly and processed within defined timeframes. Whistleblowers should be kept informed of progress throughout.

Continuous improvement

The system should be regularly reviewed, monitored, and improved. Feedback loops ensure the process evolves with organizational needs and emerging risks.

Standards compared

ISO 37002 vs EU Directive vs BSI PAS 1999 vs NIST

Three frameworks, one goal. ISO 37002 is the voluntary international standard, the EU Whistleblowing Directive is binding law in EU member states, BSI PAS 1999 is a UK pre-standard, and NIST SP 800-53 covers US federal reporting. Most multinational organizations align with ISO 37002 first, then layer on jurisdiction-specific requirements.

FrameworkScopeMandatory?Overlaps with ISO 37002
ISO 37002:2021Whistleblowing management โ€” globalVoluntaryโ€” (baseline)
EU Directive 2019/1937EU member states, 50+ employeesYes (EU)High โ€” ISO 37002 = compliant w/ directive
BSI PAS 1999:2020UK, voluntaryVoluntaryVery high โ€” predecessor, fully compatible
NIST SP 800-53 ยง3.6US federal information systemsYes (US federal)Partial โ€” covers reporting, narrower scope

Structure

The structure of ISO 37002:2021

ISO 37002 has 9 main clauses plus annexes. Clauses 1-3 are scope/normative references. Clauses 4-10 are the actionable content โ€” context, leadership, planning, support, operation, performance evaluation, improvement. Most implementations focus effort on clauses 6 (planning), 8 (operation), and 10 (improvement).

Clause 1: Scope

Defines the boundary of the standard โ€” applies to organizations of all sizes that want to establish, implement, maintain, and improve a whistleblowing management system.

Clause 2: Normative references

References to ISO 37000 series, ISO 26000 (social responsibility), and other standards referenced in the body. No mandatory version pinning.

Clause 3: Terms and definitions

Defines core terms: whistleblowing, whistleblower, report, investigation, retaliation, welfare check, etc. Aligns with ISO 704 terminology where possible.

Clause 4: Context of the organization

Identifies internal and external issues that affect the system's intended outcomes. Includes stakeholder analysis โ€” employees, contractors, suppliers, customers, regulators, public.

Clause 5: Leadership

Top management must demonstrate commitment, establish policy, assign roles and responsibilities. Includes protection against retaliation as a leadership commitment, not just an operational one.

Clause 6: Planning

Address risks and opportunities, set objectives, plan changes. Risk assessment focuses on both operational risks (when an issue is raised) and integrity risks (when an issue is suppressed).

Clause 7: Support

Resources, competence, awareness, communication, documented information. Includes training needs analysis for both investigators and management.

Clause 8: Operation

The largest clause. Covers receiving reports, assessing and acknowledging, investigating, communicating outcomes, closing. Includes both formal reports and informal concerns.

Clause 9: Performance evaluation

Monitoring, measurement, analysis, evaluation, internal audit, management review. Includes both system-level metrics and individual case metrics.

Clause 10: Improvement

Nonconformity, corrective action, continual improvement. Includes lessons learned from each case, pattern analysis across cases.

Implementation

How to implement ISO 37002:2021

Most organizations complete a working ISO 37002-aligned system in 60-90 days when using a focused framework. The roadmap below is what mature compliance teams follow.

1

Week 1-2: Scoping and leadership buy-in

Identify scope (whole organization vs business unit), secure top management commitment per clause 5, document the policy. Map internal and external stakeholders per clause 4.

2

Week 3-4: Risk assessment and policy

Identify integrity risks per clause 6: where could issues arise, who could be affected, what channels currently exist, where are the gaps. Draft or update the whistleblowing policy.

3

Week 5-6: Channel and process design

Implement or upgrade the reporting channel per clause 8 โ€” intake, acknowledgement, investigation, communication, closure. Document the procedure.

4

Week 7-8: Competence and awareness

Per clause 7: train investigators, brief managers, communicate to all employees. Make the policy visible, in local languages, at the point where reports are most likely to be considered.

5

Week 9-10: Go live and monitoring

Launch. Per clause 9: set KPIs, run an internal audit within 60 days, hold a management review within 90 days. Report early metrics to leadership.

6

Quarter 1 onwards: Continual improvement

Per clause 10: pattern analysis across cases, root cause analysis for nonconformities, year-end management review. Update policy and procedures as needed.

How Ashio helps

How Ashio maps to ISO 37002 requirements

You don't need to start from scratch. Ashio implements the operational parts of ISO 37002 out of the box. Here's the clause-by-clause mapping.

Clause 5 (Leadership): policy + governance

Configurable policy text in 11 languages, published alongside the report form. Single sign-on for investigators with role-based permissions and full audit trail.

Clause 6 (Planning): risk-aware design

Configurable categories mirror the risk taxonomy. Channel reaches internal employees, contractors, suppliers, customers โ€” all stakeholder groups ISO requires you to consider.

Clause 7 (Support): training + documentation

Ashio handles the technical platform; we provide ready-to-use training materials for investigators and employees. All documentation is in ISO 27001-certified data centers.

Clause 8 (Operation): the core

End-to-end case management: receive, acknowledge, investigate, communicate, close. The two mandatory timelines (7 days acknowledgement, 3 months feedback) are automatic. Anonymity built in.

Clause 9 (Performance evaluation): metrics

Automatic KPIs: time-to-acknowledge, time-to-close, case volume, category distribution. Exportable for management review per ISO requirement.

Clause 10 (Improvement): learning loop

Pattern analysis across cases, root cause workflows, year-end management review templates. Continuous improvement built in.

Certification

Can you get certified to ISO 37002?

Short answer: no, not directly. ISO 37002 is a guidance document, not a certifiable management system standard. The certifiable system standard for compliance is ISO 37301 (compliance management systems). However, ISO 37002 alignment is often a proxy requirement, and certification bodies offer ISO 37002 alignment attestations.

ISO 37002 itself is not certifiable

It is a Type B guidance standard, not a Type A certifiable management system standard. Look for ISO 37301 if you need a certifiable compliance framework.

Many certification bodies offer attestations

BSI, TรœV, DNV, Bureau Veritas, SGS and others offer independent assessments of ISO 37002 alignment. Useful for vendor due diligence and customer trust.

Internal audit is required for ISO 37002

Per clause 9, you must run internal audits at planned intervals. A first-year organization typically audits twice; mature organizations once a year.

Ashio provides the data you need for both

Reports on time-to-acknowledge, time-to-close, pattern analysis โ€” all the inputs an external auditor or your own internal audit will need.

Key metrics

The metrics that prove your ISO 37002 system works

Clause 9 of ISO 37002 requires monitoring, measurement, and evaluation. Here are the metrics mature compliance teams track.

Time-to-acknowledge

Target: <7 days per EU Directive and clause 8.2. Below 3 days is excellent. Measures responsiveness to reporters and signals system health.

Time-to-close

Target: <3 months per EU Directive. Below 1 month is excellent. Tracks investigation efficiency and feedback cycles. Distinguish closure (information given) from full resolution (action taken).

Report volume per 100 employees

Industry benchmark: 1-3 reports per 100 employees per year. Significantly below: possible under-reporting. Significantly above: possibly a serious problem OR a strong speak-up culture.

Channel mix diversity

ISO 37002 clause 8.1 requires multiple channels. Track what % comes via each. If 95% comes from one source, diversity is poor and you may be missing entire categories of reports.

Official sources

Official sources

For verifying your own obligations and reading original texts. The international standards body, the EU Directive, and complementary management system standards are listed below.

ISO 37002:2021 (ISO.org)

The official abstract, scope, and committee information from the International Organization for Standardization.

iso.org/standard/80095

ISO 37301:2021 (Compliance management systems)

The certifiable management system standard that ISO 37002 supports. Recommended as the next step for organizations seeking formal certification.

iso.org/standard/75080

ISO 27001 (Information security)

For organizations implementing ISO 37002 with a digital channel, ISO 27001 provides the certifiable information security framework that complements the whistleblowing system.

iso.org/standard/27001

Who it's for

Who benefits from an ISO 37002-aligned system?

ISO 37002 is designed for organizations of all sizes, in all sectors, worldwide. It is particularly relevant for:

  • Multinational corporations seeking a consistent global standard for whistleblowing across jurisdictions
  • Organizations in countries without specific whistleblowing legislation who want to follow international best practice
  • Compliance teams looking to benchmark their existing whistleblowing program against a recognized standard
  • Public sector bodies, NGOs, and international organizations committed to transparency and accountability

Audit trail

Audit trail: documentation ready for ISO 37002 certification.

The audit trail is one of the most important ISO 37002 requirements โ€” without it, you cannot demonstrate conformity. Ashio gives you a complete, tamper-proof audit trail from day one: every action is timestamped, cannot be altered after the fact, and is ready for your certification audit.

Immutable activity log

Every action โ€” report creation, status change, comment added, file uploaded โ€” is timestamped in an immutable log. Auditors see who did what and when, with no way to tamper with the records afterwards.

Full report lifecycle documentation

From report intake to closure, Ashio documents every step with the responsible person, timestamp and rationale. During an audit you can reconstruct the full lifecycle of any case in seconds.

Automatic 7-day and 3-month tracking

The EU Directive and national whistleblower laws require acknowledgment within 7 days and feedback within 3 months. Ashio documents both deadlines automatically โ€” if the auditor asks whether deadlines were met, the proof is already there.

Export for the certification body

All reports, activities and audit trails can be exported as PDF and CSV โ€” ideal for external auditors, certification bodies or internal compliance teams. No vendor lock-in, no proprietary formats.

FAQ

Common questions about ISO 37002

Is ISO 37002 a legal requirement?+

No. Unlike the EU Whistleblowing Directive or national laws like the German HinSchG, ISO 37002 is a voluntary standard. It represents international best practice โ€” organizations adopt it to demonstrate a commitment to excellence in whistleblowing management beyond minimum legal requirements.

Can a software product be 'ISO 37002 certified'?+

ISO 37002 is a management system standard, not a product certification. Organizations implement and operate an ISO 37002-aligned system โ€” software supports that system. Ashio provides the technical infrastructure to operationalize ISO 37002's guidelines, but the standard is about the overall management system, not any single tool.

How does ISO 37002 relate to ISO 37001?+

ISO 37001 is the anti-bribery management system standard. ISO 37002 complements it by providing specific guidance on whistleblowing โ€” which is a key component of any anti-bribery program. Organizations with ISO 37001 certification often adopt ISO 37002 guidelines to strengthen their reporting mechanisms.

Does Ashio help with ISO 37002 audits or certification?+

Ashio's platform provides the documentation, audit trails, and process structure that support ISO 37002 compliance. While Ashio itself is not a certification body, our activity logs and case management workflows give auditors the evidence they need to verify your whistleblowing processes.

Is ISO 37002 certification available?+

No. ISO 37002:2021 is a guidance document, not a certifiable management system standard. For certifiable compliance frameworks, see ISO 37301. However, certification bodies offer ISO 37002 alignment attestations, and internal audits against ISO 37002 are expected per clause 9.

Is ISO 37002 mandatory?+

No. ISO 37002 is voluntary. However, the EU Whistleblowing Directive 2019/1937 is mandatory in EU member states for organizations with 50+ employees, and a system aligned with ISO 37002 will substantially meet those mandatory requirements.

What is the difference between ISO 37002 and the EU Whistleblowing Directive?+

ISO 37002 is an international, voluntary standard for whistleblowing management systems, published by ISO. The EU Whistleblowing Directive (2019/1937) is binding EU law that requires member states to transpose it by 17 December 2021 and applies to organizations with 50+ employees. ISO 37002 is broader in scope (all sectors, all sizes) but the EU Directive is the legal floor. A system aligned with ISO 37002 substantially meets the EU Directive requirements.

How long does ISO 37002 implementation take?+

A focused implementation using a structured framework typically takes 60-90 days for an initial compliant system. Mature continuous improvement and full clause coverage (especially 8, 9, 10) typically take 6-12 months. Using a platform like Ashio can compress initial implementation to 1-2 weeks for clauses 6-9.

Does ISO 37002 apply to small businesses?+

Yes. ISO 37002 is applicable to organizations of all sizes, including small businesses. However, the standard notes that some requirements may not be applicable to very small organizations. The EU Whistleblowing Directive (which ISO 37002 helps satisfy) applies to organizations with 50+ employees in EU member states.

How does ISO 37002 relate to other compliance frameworks?+

ISO 37002 aligns with ISO 37301 (compliance management systems), ISO 27001 (information security), and ISO 45001 (occupational health and safety). It also integrates with the EU Whistleblowing Directive (2019/1937) in EU member states, the UK Bribery Act 2010, and the US Sarbanes-Oxley Act Section 806. Many organizations map their ISO 37002 implementation to these related frameworks.

What is the role of the whistleblower under ISO 37002?+

ISO 37002 defines the whistleblower as a person who makes a report or disclosure about a concern. The standard requires protection of the whistleblower from retaliation, preservation of confidentiality, and access to remedies if retaliation occurs. The whistleblower is treated as a stakeholder per clause 4, with specific protection requirements in clauses 5 (leadership commitment) and 8 (operational controls).

EU directives covered

Related compliance guides.

Explore Ashio's coverage of each EU regulation.

Ready to align with ISO 37002 best practice?

Set up a whistleblowing system that meets the highest international standards. ISO 37002-aligned processes, GDPR compliance, and Swiss hosting โ€” all in one platform.