Fiducia e imparzialità
Il sistema deve essere progettato per guadagnare e mantenere la fiducia di tutti gli stakeholder. Le segnalazioni sono gestite in modo imparziale, senza pregiudizi o parzialità.

La ISO 37002:2021 fornisce linee guida internazionali per istituire, implementare e mantenere un sistema di gestione del whistleblowing efficace. La piattaforma di Ashio è costruita in allineamento con questi principi — aiutando le organizzazioni a raggiungere il più alto standard globale di protezione dei segnalanti.
Panoramica
La ISO 37002:2021 è lo standard internazionale pubblicato dall'International Organization for Standardization (ISO) che fornisce linee guida per i sistemi di gestione del whistleblowing. Pubblicata a luglio 2021, offre un quadro per ricevere, valutare e agire sulle segnalazioni di illeciti — proteggendo i segnalanti dalle ritorsioni e garantendo il giusto processo. La ISO 37002 completa la Direttiva UE sul whistleblowing fornendo uno standard di sistema di gestione volontario rispetto al quale le organizzazioni possono essere verificate.
Principi chiave
La ISO 37002 definisce sei principi fondanti alla base di un sistema di gestione del whistleblowing efficace:
Il sistema deve essere progettato per guadagnare e mantenere la fiducia di tutti gli stakeholder. Le segnalazioni sono gestite in modo imparziale, senza pregiudizi o parzialità.
I segnalanti devono essere protetti da ogni forma di ritorsione — diretta (licenziamento, retrocessione) o indiretta (molestie, esclusione).
L'identità del segnalante deve essere protetta. Le segnalazioni anonime devono essere accettate e trattate con la stessa diligenza di quelle nominative.
Il canale di segnalazione deve essere comunicato chiaramente e accessibile a tutte le parti interessate — inclusi dipendenti, collaboratori, fornitori e altri stakeholder.
Le segnalazioni devono essere confermate tempestivamente e trattate entro tempi definiti. I segnalanti devono essere informati sui progressi.
Il sistema deve essere rivisto, monitorato e migliorato regolarmente. I cicli di feedback garantiscono che il processo evolva con le esigenze organizzative e i rischi emergenti.
Contesto
Mentre la Direttiva UE sul whistleblowing (UE) 2019/1937 crea un obbligo legale per le organizzazioni negli Stati membri UE, la ISO 37002 fornisce un quadro volontario e riconosciuto a livello internazionale per la best practice. La Direttiva dice cosa richiede la legge; la ISO 37002 dice come farlo bene. Molte organizzazioni usano la ISO 37002 come riferimento anche dove la Direttiva UE non si applica — coprendo giurisdizioni in tutto il mondo e andando oltre la conformità legale minima.
| Framework | Scope | Mandatory? | Overlaps with ISO 37002 |
|---|---|---|---|
| ISO 37002:2021 | Whistleblowing management — global | Voluntary | — (baseline) |
| EU Directive 2019/1937 | EU member states, 50+ employees | Yes (EU) | High — ISO 37002 = compliant w/ directive |
| BSI PAS 1999:2020 | UK, voluntary | Voluntary | Very high — predecessor, fully compatible |
| NIST SP 800-53 §3.6 | US federal information systems | Yes (US federal) | Partial — covers reporting, narrower scope |
Structure
ISO 37002 has 9 main clauses plus annexes. Clauses 1-3 are scope, normative references, and definitions. Clauses 4-10 are the actionable content — context, leadership, planning, support, operation, performance evaluation, improvement. Most implementations focus on clauses 6 (planning), 8 (operation), and 10 (improvement).
Defines the boundary of the standard — applies to organizations of all sizes that want to establish, implement, maintain, and improve a whistleblowing management system.
References to ISO 37000 series, ISO 26000 (social responsibility), and other standards referenced in the body.
Defines core terms: whistleblowing, whistleblower, report, investigation, retaliation, welfare check, etc. Aligns with ISO 704 terminology where possible.
Identifies internal and external issues that affect the system's intended outcomes. Includes stakeholder analysis — employees, contractors, suppliers, customers, regulators, public.
Top management must demonstrate commitment, establish policy, assign roles and responsibilities. Includes protection against retaliation as a leadership commitment, not just an operational one.
Address risks and opportunities, set objectives, plan changes. Risk assessment focuses on both operational risks (when an issue is raised) and integrity risks (when an issue is suppressed).
Resources, competence, awareness, communication, documented information. Includes training needs analysis for both investigators and management.
The largest clause. Covers receiving reports, assessing and acknowledging, investigating, communicating outcomes, closing. Includes both formal reports and informal concerns.
Monitoring, measurement, analysis, evaluation, internal audit, management review. Includes both system-level metrics and individual case metrics.
Nonconformity, corrective action, continual improvement. Includes lessons learned from each case, pattern analysis across cases.
Implementation
Most organizations complete a working ISO 37002-aligned system in 60-90 days when using a focused framework. The roadmap below is what mature compliance teams follow.
Identify scope, secure top management commitment per clause 5, document the policy. Map internal and external stakeholders per clause 4.
Identify integrity risks per clause 6: where could issues arise, who could be affected, what channels currently exist, where are the gaps.
Implement or upgrade the reporting channel per clause 8 — intake, acknowledgement, investigation, communication, closure. Document the procedure.
Per clause 7: train investigators, brief managers, communicate to all employees. Make the policy visible, in local languages, at the point where reports are most likely to be considered.
Launch. Per clause 9: set KPIs, run an internal audit within 60 days, hold a management review within 90 days. Report early metrics to leadership.
Per clause 10: pattern analysis across cases, root cause analysis for nonconformities, year-end management review. Update policy and procedures as needed.
How Ashio helps
You don't need to start from scratch. Ashio implements the operational parts of ISO 37002 out of the box. Here's the clause-by-clause mapping.
Configurable policy text in 11 languages, published alongside the report form. Single sign-on for investigators with role-based permissions and full audit trail.
Configurable categories mirror the risk taxonomy. Channel reaches internal employees, contractors, suppliers, customers — all stakeholder groups ISO requires you to consider.
Ashio handles the technical platform; we provide ready-to-use training materials for investigators and employees. All documentation is in ISO 27001-certified data centers.
End-to-end case management: receive, acknowledge, investigate, communicate, close. The two mandatory timelines (7 days acknowledgement, 3 months feedback) are automatic. Anonymity built in.
Automatic KPIs: time-to-acknowledge, time-to-close, case volume, category distribution. Exportable for management review per ISO requirement.
Pattern analysis across cases, root cause workflows, year-end management review templates. Continuous improvement built in.
Certification
Short answer: no, not directly. ISO 37002 is a guidance document, not a certifiable management system standard. The certifiable system standard for compliance is ISO 37301. However, ISO 37002 alignment is often a proxy requirement, and certification bodies offer ISO 37002 alignment attestations.
It is a Type B guidance standard, not a Type A certifiable management system standard. Look for ISO 37301 if you need a certifiable compliance framework.
BSI, TÜV, DNV, Bureau Veritas, SGS and others offer independent assessments of ISO 37002 alignment. Useful for vendor due diligence and customer trust.
Per clause 9, you must run internal audits at planned intervals. A first-year organization typically audits twice; mature organizations once a year.
Reports on time-to-acknowledge, time-to-close, pattern analysis — all the inputs an external auditor or your own internal audit will need.
Key metrics
Clause 9 of ISO 37002 requires monitoring, measurement, and evaluation. Here are the metrics mature compliance teams track.
Target: <7 days per EU Directive and clause 8.2. Below 3 days is excellent. Measures responsiveness to reporters and signals system health.
Target: <3 months per EU Directive. Below 1 month is excellent. Tracks investigation efficiency and feedback cycles. Distinguish closure (information given) from full resolution (action taken).
Industry benchmark: 1-3 reports per 100 employees per year. Significantly below: possible under-reporting. Significantly above: possibly a serious problem OR a strong speak-up culture.
ISO 37002 clause 8.1 requires multiple channels. Track what % comes via each. If 95% comes from one source, diversity is poor and you may be missing entire categories of reports.
Official sources
Per verificare i tuoi obblighi e leggere i testi originali. L'organizzazione internazionale di normazione, la direttiva UE e gli standard complementari del sistema di gestione sono elencati di seguito.
L'abstract ufficiale, lo scopo e le informazioni sul comitato dell'Organizzazione internazionale per la normazione.
iso.org/standard/80095Lo standard di sistema di gestione certificabile che ISO 37002 completa. Raccomandato come passo successivo per le organizzazioni che cercano la certificazione formale.
iso.org/standard/75080Per le organizzazioni che implementano ISO 37002 con un canale digitale, ISO 27001 fornisce il quadro certificabile per la sicurezza delle informazioni che completa il sistema di segnalazione.
iso.org/standard/27001A chi è rivolta
La ISO 37002 è progettata per organizzazioni di ogni dimensione, in tutti i settori, in tutto il mondo. È particolarmente rilevante per:
Pista di audit
La pista di audit è uno dei requisiti più importanti della ISO 37002 — senza di essa non è possibile dimostrare la conformità alla norma. Ashio fornisce fin dal primo giorno una pista di audit completa e immutabile: ogni azione è registrata con timestamp, non può essere modificata a posteriori ed è pronta per l'audit di certificazione.
Ogni azione — creazione di una segnalazione, cambio di stato, aggiunta di un commento, caricamento di un file — viene registrata con timestamp in un registro immutabile. Il revisore vede chi ha fatto cosa e quando, senza possibilità di manipolazione a posteriori.
Dalla ricezione della segnalazione fino alla sua chiusura, Ashio documenta ogni passaggio con responsabile, timestamp e motivazione. Durante l'audit puoi ricostruire in pochi secondi l'intero ciclo di vita di un caso.
La direttiva UE e il D.Lgs. 24/2023 richiedono una conferma di ricezione entro 7 giorni e una risposta entro 3 mesi. Ashio documenta automaticamente entrambe le scadenze — se il revisore chiede se sono state rispettate, hai subito la prova.
Tutte le segnalazioni, le attività e le piste di audit possono essere esportate in PDF e CSV — ideali per revisori esterni, enti di certificazione o controllo interno. Nessun lock-in del fornitore, nessun formato proprietario.
FAQ
No. A differenza della Direttiva UE sul whistleblowing o delle leggi nazionali come l'HinSchG tedesco, la ISO 37002 è uno standard volontario. Rappresenta la best practice internazionale — le organizzazioni la adottano per dimostrare un impegno verso l'eccellenza nella gestione del whistleblowing oltre i requisiti legali minimi.
La ISO 37002 è uno standard per i sistemi di gestione, non una certificazione di prodotto. Le organizzazioni implementano e gestiscono un sistema allineato alla ISO 37002 — il software supporta quel sistema. Ashio fornisce l'infrastruttura tecnica per mettere in pratica le linee guida della ISO 37002, ma lo standard riguarda il sistema di gestione complessivo, non un singolo strumento.
La ISO 37001 è lo standard per i sistemi di gestione anti-corruzione. La ISO 37002 la completa fornendo indicazioni specifiche sul whistleblowing — componente chiave di qualsiasi programma anti-corruzione. Le organizzazioni certificate ISO 37001 adottano spesso le linee guida ISO 37002 per rafforzare i propri meccanismi di segnalazione.
La piattaforma di Ashio fornisce la documentazione, le tracce di audit e la struttura di processo che supportano la conformità ISO 37002. Sebbene Ashio non sia un ente di certificazione, i nostri registri attività e i flussi di gestione dei casi danno agli auditor le prove necessarie per verificare i tuoi processi di whistleblowing.
No. ISO 37002:2021 is a guidance document, not a certifiable management system standard. For certifiable compliance frameworks, see ISO 37301. However, certification bodies offer ISO 37002 alignment attestations, and internal audits against ISO 37002 are expected per clause 9.
No. ISO 37002 is voluntary. However, the EU Whistleblowing Directive 2019/1937 is mandatory in EU member states for organizations with 50+ employees, and a system aligned with ISO 37002 will substantially meet those mandatory requirements.
ISO 37002 is an international, voluntary standard for whistleblowing management systems, published by ISO. The EU Whistleblowing Directive (2019/1937) is binding EU law that requires member states to transpose it by 17 December 2021 and applies to organizations with 50+ employees. ISO 37002 is broader in scope (all sectors, all sizes) but the EU Directive is the legal floor. A system aligned with ISO 37002 substantially meets the EU Directive requirements.
A focused implementation using a structured framework typically takes 60-90 days for an initial compliant system. Mature continuous improvement and full clause coverage (especially 8, 9, 10) typically take 6-12 months. Using a platform like Ashio can compress initial implementation to 1-2 weeks for clauses 6-9.
Yes. ISO 37002 is applicable to organizations of all sizes, including small businesses. However, the standard notes that some requirements may not be applicable to very small organizations. The EU Whistleblowing Directive (which ISO 37002 helps satisfy) applies to organizations with 50+ employees in EU member states.
ISO 37002 aligns with ISO 37301 (compliance management systems), ISO 27001 (information security), and ISO 45001 (occupational health and safety). It also integrates with the EU Whistleblowing Directive (2019/1937) in EU member states, the UK Bribery Act 2010, and the US Sarbanes-Oxley Act Section 806.
ISO 37002 defines the whistleblower as a person who makes a report or disclosure about a concern. The standard requires protection of the whistleblower from retaliation, preservation of confidentiality, and access to remedies if retaliation occurs.
EU directives covered
Explore Ashio's coverage of each EU regulation.
One platform for every EU directive — NIS2, AI Act, CSRD, CSDDD, Pay Transparency, ISO 37002.
Read moreRequirements, deadlines, and penalties under Directive 2019/1937.
Read moreCybersecurity incident reporting timelines and internal channels.
Read moreNo IP, no cookies, no fingerprinting. End-to-end encrypted.
Read moreConfigura un sistema di whistleblowing che soddisfa i più alti standard internazionali. Processi allineati alla ISO 37002, conformità GDPR e hosting svizzero — tutto in un'unica piattaforma.