When a Supplier or Tender Asks for Your Whistleblowing Policy

What They Want Is a Working Channel + Policy, Not Just a PDF
A request from a client or tender committee for your whistleblowing policy can feel like a compliance checkbox. But what they're really asking for—and what actually protects your organisation—is not a PDF in a folder somewhere. It's a functioning system that lets employees raise concerns safely and see them resolved. The good news: organisations with 50+ employees are legally required under the EU Whistleblowing Directive to have one. Those with under 50 employees face contractual obligations instead—but both need a real, working system, not just paperwork.
Understanding What "Whistleblowing Policy" Actually Means
When a prospective client requests your whistleblowing policy, they're evaluating your governance maturity. They want reassurance that:
- Your organisation has a formal, documented process for handling serious concerns (wrongdoing, breaches of law, unethical conduct).
- You can demonstrate that employees—and ideally suppliers, contractors, and external parties—can report concerns without fear of retaliation.
- You have a functioning channel and supporting procedures, not just a policy document sitting on an intranet.
- They're assessing risk: if your organisation later becomes involved in a scandal, fraud, or regulatory breach that could have been reported earlier, will they be implicated by association?
This is why a policy alone isn't enough. Clients and tender bodies increasingly want evidence of implementation: training records, acknowledgement procedures, feedback mechanisms, and audit trails.
Legal Requirements Under EU Law
The EU Whistleblowing Directive (Directive 2019/1937) sets out the baseline, though national laws vary. Understanding what's legally mandatory versus good practice is crucial.
The 50-Employee Threshold
If your organisation has 50 or more employees, you are legally required to establish an internal reporting channel. Article 8 of the Directive states:
"Member States shall ensure that legal entities in the public sector, and those with 50 or more employees in the private sector, establish one or more internal reporting channels."
An internal reporting channel means a documented process—ideally a dedicated contact person or team, a confidential system, or both—where employees can submit a concern about a breach of EU or national law. The policy document itself is secondary; the channel and process are what matters.
Under 50 Employees: No Legal Obligation, But Contractual Risk
If your organisation has fewer than 50 employees, there is no legal obligation under the Directive to establish an internal channel. However, you must still provide access to an external channel (typically a national competent authority or regulator). More importantly, if a supplier or client contractually requires a whistleblowing policy as a condition of doing business with you, you must meet that contractual obligation regardless of your headcount. This is where many smaller organisations get caught: they assume size exempts them, then lose a contract when they can't demonstrate compliance.
Your Obligations Once a Report Is Made
If you receive a whistleblowing report, the Directive requires you to:
- Acknowledge receipt of the report within seven days (Article 9).
- Provide feedback on the progress and outcome of the investigation within three months, or explain why that timeline cannot be met.
- Protect the reporting person from retaliation, including dismissal, demotion, suspension, or other adverse treatment.
- Maintain confidentiality of the reporter's identity unless they consent to disclosure or it becomes necessary for the investigation.
These timelines and protections need to be embedded in your policy and, critically, enforced in your organisation's culture and systems. A policy that exists on paper but isn't resourced, monitored, or backed by leadership becomes a liability rather than a safeguard.
National Transpositions Matter
The Directive was transposed into national law across EU member states by December 2021. If your organisation operates in multiple countries, the national laws of those jurisdictions apply. For example, France, Germany, Spain, and Italy all have national laws that implement the Directive, but with some variations in timelines, scope, and protections.
If you're headquartered in the UK, post-Brexit you are not bound by the Directive unless you operate in EU member states or have clients that require EU compliance. However, the Directive has become a global reference standard, and many non-EU clients now expect compliance with its terms regardless.
Action: Check which countries your organisation operates in and which laws bind you. A policy that meets only UK standards may not be sufficient if you work with EU clients or tender for contracts in the EU. This is often where understanding regulatory differences across jurisdictions becomes critical.
Policy Versus System: What Actually Works
A Whistleblowing Policy (Document)
A whistleblowing policy is a written document outlining:
- What concerns can be reported (breaches of law, ethics, safety, financial wrongdoing, etc.).
- Who can report and how (employees, contractors, suppliers, customers).
- Channels available (internal and external).
- Timelines for acknowledgement and feedback.
- Protections against retaliation.
- How confidentiality will be maintained.
- What happens if the reporter is identified or the concern proves unfounded.
This is necessary but insufficient. A policy sitting on an intranet with no staffing, no training, and no follow-through signals to employees that the organisation isn't serious.
A Whistleblowing System (Practice)
A functioning system includes:
- A dedicated reporting channel (phone line, online form, secure email, or third-party service).
- A designated person or team responsible for handling reports.
- A documented process for receipt, acknowledgement, investigation, and closure.
- Training for staff on their roles and the policy.
- Regular audits and metrics on report handling.
- Leadership endorsement and visible support.
- External reporting channels for cases involving senior management or the board.
This is what tender committees and clients are actually evaluating. They want to see that your organisation has the infrastructure and discipline to respond to concerns in real time, not in theory.
How to Respond to a Supplier or Tender Request
1. Be Honest About Your Current State
If you don't have a formal policy or channel yet, say so. Explain what you're putting in place and your timeline. Clients trust transparency more than bluster.
2. Provide the Policy Document
Submit the written policy, but frame it as part of a system. Explain how the policy is communicated, to whom, and how often it's reviewed.
3. Include Evidence of Implementation
If you have it, provide:
- Training records showing employees have been briefed.
- Details of your reporting channel(s) and who manages them.
- A summary of how reports have been handled (without breaching confidentiality).
- Your escalation and investigation procedures.
- The approval and ownership of the policy at board or senior leadership level.
4. Address Their Specific Concerns
Tender documents often specify what they want to see. Respond directly to each requirement. If they ask for external reporting channels, confirm whether you use a third-party service or direct access to a regulator. If they ask about protection against retaliation, explain your disciplinary procedures and how they align with the Directive.
Building a Compliant System from Scratch
For Organisations with 50+ Employees
- You have a legal obligation. Treat it as non-negotiable.
- Establish an internal reporting channel (dedicated email, phone, online form, or contracted third-party service).
- Designate a person or small team to manage reports and investigations.
- Document your process for intake, acknowledgement (within 7 days), investigation, feedback (within 3 months), and closure.
- Create a whistleblowing policy that complies with the Directive and your national law.
- Communicate the policy to all employees, contractors, and relevant external parties.
- Train managers on their responsibilities and how to respond to concerns.
- Review and audit your system annually.
- Consider using a third-party service (like Xono) for secure reporting and audit trails.
For Organisations with Under 50 Employees
- You have no legal obligation under the Directive, but check your national law (some countries have lower thresholds).
- However, any contractual requirement must be met. If a tender asks for a whistleblowing policy, you must provide one.
- You can use an external channel (regulator, ombudsman, or third-party service) as your primary channel, but it should be accessible and clearly communicated.
- Consider developing a simple internal process to handle concerns that fall outside regulatory scope (e.g., misconduct, ethics breaches, health and safety).
- Document your process and communicate it to employees.
- You may also want to implement a system now rather than waiting for a legal or contractual trigger—it's often easier than retrofitting later.
The Role of Third-Party Services
Many organisations use external whistleblowing platforms or services to manage reporting and investigations. This can be effective because:
- It creates independence (reports don't go to the person's manager).
- It provides a confidential channel that employees may trust more.
- It generates audit trails and documentation for compliance.
- It ensures timely acknowledgement and progress tracking.
- It can include external investigation support.
However, the service is a tool, not a substitute for your system. You still need a policy, training, leadership commitment, and internal ownership. A third-party service won't work if your organisation doesn't take the reports seriously or follow through on investigations.
When responding to a tender, be clear about which channels you offer. If you use a third-party service, name it and explain how it meets the requirements. If you don't have one yet but use a direct reporting channel, that's fine—just make sure it's documented and functional. For more details on selecting and implementing a compliant system, review our whistleblowing compliance checklist.
Common Mistakes to Avoid
- Having a policy but no channel: A policy without a functioning way to report is worse than useless—it signals you don't mean it.
- Ignoring the seven-day acknowledgement deadline: Not acknowledging receipt of a report quickly enough is a breach of the Directive.
- Failing to protect confidentiality: If a reporter's identity is revealed unnecessarily, you've failed the core purpose of whistleblowing.
- Using informal processes: "Talk to your manager" or "email the director" isn't a compliant channel. You need documented, secure, confidential processes.
- Assuming one channel is enough: Employees may not feel safe reporting to someone they know or their line manager. Provide multiple routes (internal and external).
- Not training staff: Managers and HR staff need to understand their roles and the timelines required.
- Never following up: Failing to provide feedback on an investigation within three months (or explain why you can't) is a breach.
Frequently Asked Questions
Not under EU law—the Directive applies only to organisations with 50 or more employees. However, you must still comply with any contractual requirements from clients or tender bodies. If a supplier or tender explicitly asks for a whistleblowing policy, you must provide one regardless of your size. Additionally, you may be subject to national laws that have lower thresholds than the EU Directive. Always check your national requirements and any contractual obligations.
An internal reporting channel is a mechanism within your organisation (a dedicated email, phone line, online form, or person) where employees can report concerns. An external reporting channel is outside your organisation—typically a national regulator, ombudsman, or third-party service. The Directive requires organisations with 50+ employees to have an internal channel. Organisations with under 50 employees must provide access to an external channel. Many organisations provide both to give employees options and build confidence in the system.
Under the EU Whistleblowing Directive, you must acknowledge receipt of a report within seven days. This is a hard deadline. Acknowledging means confirming that you've received the report and outlining what the next steps will be. Failure to acknowledge within seven days is a breach of the Directive and will count against you in regulatory inspections or tender evaluations.
No. The Directive protects reporters' right to anonymity. You can accept anonymous reports and investigate them. However, some investigations may require the reporter to be identified to protect the reporter's rights or to carry out a fair investigation. In such cases, you must obtain the reporter's explicit consent before disclosing their identity, unless it becomes necessary for legal or investigative reasons. Your policy should explain how you balance confidentiality with the practical needs of investigation.
The Directive explicitly protects reporters from retaliation, including dismissal, demotion, suspension, wage reduction, negative performance appraisals, harassment, and exclusion. It also protects colleagues and family members who may suffer retaliation for association with a reporter. Your policy must clearly state these protections. More importantly, your organisation must enforce them. If a reporter is retaliated against, they can pursue legal action, and your organisation faces regulatory penalties. Training managers on what constitutes retaliation and why it's prohibited is essential.
Ready to Build a Compliant Whistleblowing System?
Ensure your organisation meets tender requirements and legal obligations with a functioning whistleblowing system. Explore our whistleblowing solution or book a demo to see how Xono helps you respond confidently to supplier and tender requests.
Book a Demo Start Free Trial