Skip to content

Evidence request lists

ISO 37002:2021 - Whistleblowing Management Systems

Evidence request list. 47 controls, 47 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Clause 10: Improvement

ISO-37002-10.1
Nonconformity and corrective action

Requires reacting to nonconformities, determining causes, implementing corrective actions, and reviewing effectiveness.

Artefacts an auditor will ask for
  • Feedback loop documentation
  • Innovation maturity reassessment
  • Lessons learned reports
  • Root cause analysis records
  • Process improvement proposals tracker
Where this commonly fails
  • Nonconformities not logged or trended
  • Maturity reassessment skipped year over year
  • Feedback loops from operations back to strategy missing
  • Corrective actions closed without verifying effectiveness
  • Root cause analysis stops at symptom level
ISO-37002-10.2
Continual improvement

Requires continual improvement of the suitability, adequacy, and effectiveness of the whistleblowing management system.

Artefacts an auditor will ask for
  • Continual improvement register
  • Nonconformity and corrective action log
  • Lessons learned reports
Where this commonly fails
  • Lessons learned stored but never reused
  • Improvement register stale, items older than 12 months unactioned
  • Feedback loops from operations back to strategy missing

Clause 4: Context of the Organization

ISO-37002-4.1
Understanding the organization and its context

Requires determining external and internal issues relevant to the purpose of the whistleblowing management system.

Artefacts an auditor will ask for
  • IMS scope statement signed by leadership
  • Innovation maturity baseline assessment
  • Competitor innovation benchmark
Where this commonly fails
  • Stakeholder map omits external innovation partners (universities, startups)
  • Context analysis treated as one-off, not refreshed annually
  • Trend scanning is ad hoc and undocumented
ISO-37002-4.2
Understanding the needs and expectations of interested parties

Requires identifying interested parties and their requirements relevant to the whistleblowing management system.

Artefacts an auditor will ask for
  • Competitor innovation benchmark
  • Market and technology radar
  • PESTEL/SWOT analysis covering innovation landscape
  • Trend and foresight scan report
  • IMS scope statement signed by leadership
Where this commonly fails
  • Strategic intelligence not feeding into innovation decisions
  • Stakeholder map omits external innovation partners (universities, startups)
  • Trend scanning is ad hoc and undocumented
  • Internal capability gaps not assessed against strategy
  • IMS scope undefined or inconsistent across business units
ISO-37002-4.3
Determining the scope of the whistleblowing management system

Requires determining the boundaries and applicability of the whistleblowing management system.

Artefacts an auditor will ask for
  • Interested-party requirements log
  • Trend and foresight scan report
  • Innovation maturity baseline assessment
Where this commonly fails
  • Innovation maturity baseline never established
  • Context analysis treated as one-off, not refreshed annually
  • IMS scope undefined or inconsistent across business units
ISO-37002-4.4
Whistleblowing management system

Requires establishing, implementing, maintaining, and continually improving the whistleblowing management system.

Artefacts an auditor will ask for
  • Trend and foresight scan report
  • Interested-party requirements log
  • PESTEL/SWOT analysis covering innovation landscape
  • Stakeholder map with innovation interests
Where this commonly fails
  • Stakeholder map omits external innovation partners (universities, startups)
  • Context analysis treated as one-off, not refreshed annually
  • Strategic intelligence not feeding into innovation decisions
  • Internal capability gaps not assessed against strategy
  • Trend scanning is ad hoc and undocumented

Clause 5: Leadership

ISO-37002-5.1
Leadership and commitment

Requires top management to demonstrate leadership and commitment by promoting a speak-up/listen-up culture.

Artefacts an auditor will ask for
  • Approved innovation policy
  • Leadership innovation commitments register
  • Culture assessment results
  • Innovation council terms of reference
  • Board minutes referencing innovation strategy
Where this commonly fails
  • Executive sponsorship limited to lip service, no time committed
  • Innovation strategy disconnected from corporate strategy
  • Culture barriers to risk-taking not addressed by leadership
  • No clear accountability for innovation outcomes
  • Roles and responsibilities for innovation undefined
ISO-37002-5.2
Whistleblowing policy

Requires establishment of a whistleblowing policy that promotes a speak-up/listen-up culture and provides protection.

Artefacts an auditor will ask for
  • Executive innovation charter
  • Innovation council terms of reference
  • Culture assessment results
  • Board minutes referencing innovation strategy
  • Strategic alignment matrix linking innovation to business goals
Where this commonly fails
  • Executive sponsorship limited to lip service, no time committed
  • Innovation strategy disconnected from corporate strategy
  • Governance forum lacks decision-making authority
  • Roles and responsibilities for innovation undefined
  • No clear accountability for innovation outcomes
ISO-37002-5.3
Organizational roles, responsibilities and authorities

Requires assignment and communication of roles and responsibilities for the whistleblowing management system.

Artefacts an auditor will ask for
  • Strategic alignment matrix linking innovation to business goals
  • Innovation vision and strategy document
  • RACI for innovation roles
Where this commonly fails
  • Innovation strategy disconnected from corporate strategy
  • Innovation policy not formally approved or communicated
  • Roles and responsibilities for innovation undefined

Clause 6: Planning

ISO-37002-6.1
Actions to address risks and opportunities

Requires identifying risks and opportunities related to the whistleblowing management system and planning actions to address them.

Artefacts an auditor will ask for
  • Opportunity and risk register
  • Resource allocation plan
  • Change management plan for innovation initiatives
  • Initiative prioritisation scorecard
  • Innovation objectives with measurable targets
Where this commonly fails
  • Roadmap not updated when strategy changes
  • Opportunities and risks tracked separately with no link to objectives
  • Portfolio biased toward horizon 1 incremental projects
ISO-37002-6.2
Whistleblowing management system objectives and planning

Requires establishing measurable objectives for the whistleblowing management system with plans to achieve them.

Artefacts an auditor will ask for
  • Opportunity and risk register
  • Action plans tied to innovation objectives
  • Innovation portfolio dashboard
Where this commonly fails
  • Opportunities and risks tracked separately with no link to objectives
  • Risk treatment plans absent for high-uncertainty bets
  • No resource plan tied to portfolio priorities

Clause 7: Support

ISO-37002-7.1
Resources

Requires providing resources needed for establishment, implementation, maintenance, and improvement of the system.

Artefacts an auditor will ask for
  • Innovation infrastructure inventory
  • Document control register for IMS
  • Partnership and collaboration agreements
  • Strategic intelligence repository
  • Communication plan (internal/external)
  • Competence matrix for innovation roles
Where this commonly fails
  • Time allocation for innovation crowded out by BAU
  • Strategic intelligence siloed in one team
  • Partnership agreements lack IP and confidentiality clauses
ISO-37002-7.2
Competence

Requires ensuring persons performing whistleblowing-related functions have the necessary competence.

Artefacts an auditor will ask for
  • Partnership and collaboration agreements
  • Document control register for IMS
  • Knowledge repository / lessons learned database
  • Competence matrix for innovation roles
  • IP register and assignment agreements
  • Innovation tools and methods catalogue
Where this commonly fails
  • Strategic intelligence siloed in one team
  • Tools and methods inconsistent across teams
  • Knowledge from past projects not captured or reused
  • Innovation budget not ring-fenced from operating budget
  • Competence requirements for innovation roles not defined
ISO-37002-7.3
Awareness and training

Requires ensuring all personnel are aware of the whistleblowing policy and their rights and obligations.

Artefacts an auditor will ask for
  • IP register and assignment agreements
  • Innovation tools and methods catalogue
  • Time-allocation policy (e.g., 10% innovation time)
Where this commonly fails
  • Competence requirements for innovation roles not defined
  • Knowledge from past projects not captured or reused
  • Strategic intelligence siloed in one team
ISO-37002-7.4
Communication

Requires internal and external communication to build awareness and trust in the whistleblowing system.

Artefacts an auditor will ask for
  • IP register and assignment agreements
  • Time-allocation policy (e.g., 10% innovation time)
  • Knowledge repository / lessons learned database
  • Communication plan (internal/external)
Where this commonly fails
  • Partnership agreements lack IP and confidentiality clauses
  • Time allocation for innovation crowded out by BAU
  • IP register incomplete, ownership disputes likely
  • Competence requirements for innovation roles not defined
  • Innovation budget not ring-fenced from operating budget
ISO-37002-7.5
Documented information

Requires creating, updating, and controlling documented information for the whistleblowing management system.

Artefacts an auditor will ask for
  • Communication plan (internal/external)
  • Knowledge repository / lessons learned database
  • Partnership and collaboration agreements
  • Innovation tools and methods catalogue
Where this commonly fails
  • Partnership agreements lack IP and confidentiality clauses
  • IP register incomplete, ownership disputes likely
  • Innovation budget not ring-fenced from operating budget

Clause 8: Operation - Whistleblowing Process

ISO-37002-8.1
Receiving reports of wrongdoing

Requires establishing accessible and secure channels for receiving reports of wrongdoing from whistleblowers.

Artefacts an auditor will ask for
  • Inventory of intake channels covering hotline, web form, email, postal, in person and external regulator routes
  • Anonymous reporting option with secure two way communication where law permits
  • Acknowledgement to reporter within seven days as expected by EU Directive 2019/1937
  • Triage record capturing receipt, channel, reporter category and initial classification
  • Confidentiality undertaking signed by all handlers
Where this commonly fails
  • Anonymous channel removed by vendor change without notice
  • Acknowledgement window slips past statutory expectations
  • Receipt logged with reporter identity in non confidential systems such as helpdesk tickets
ISO-37002-8.2
Assessing reports of wrongdoing

Requires a systematic process for assessing received reports including initial triage and determination of actions.

Artefacts an auditor will ask for
  • Documented assessment procedure with criteria for accepting, redirecting or closing reports
  • Conflict of interest screening before assignment
  • Risk based prioritisation criteria covering harm severity, urgency, regulatory exposure and protection needs
  • Assessment outcome record with rationale and decision maker
  • Reporter feedback at the assessment outcome stage where appropriate
Where this commonly fails
  • Reports closed at triage as out of scope without rationale documented
  • Assignment decisions made without conflict screening
  • Urgent protection needs not surfaced during triage
ISO-37002-8.3
Addressing reports of wrongdoing

Requires investigation of substantiated reports and implementation of corrective and preventive actions.

Artefacts an auditor will ask for
  • Investigation plan tailored to the report including objectives, scope, evidence sources, interviewees and timeline
  • Evidence chain of custody log
  • Interview records with consent and confidentiality notices
  • Independence statement from investigator and any external counsel
  • Periodic update to reporter and subject as appropriate within confidentiality limits
  • Quality review of investigation by a second qualified reviewer
Where this commonly fails
  • Investigations conducted by line manager of the subject
  • No quality review so flawed conclusions reach decision makers
  • Subjects denied procedural fairness creating legal exposure
ISO-37002-8.4
Concluding whistleblowing cases

Requires formal closure of cases with documented outcomes, feedback to whistleblowers, and lessons learned.

Artefacts an auditor will ask for
  • Final report with findings, evidence basis, conclusions and recommended actions
  • Decision record by an authorised body covering disciplinary, control and remediation outcomes
  • Feedback to reporter on outcome at the level permitted by confidentiality and law
  • Notification to regulators or law enforcement where required
  • Lessons learned register feeding control improvements
  • Closure record with reporter protection follow up scheduled
Where this commonly fails
  • Reporter never informed of outcome
  • Conclusions reached without referenced evidence
  • Lessons learned not fed into control owners so the same issue recurs
ISO-37002-8.5
Protection of whistleblowers

Requires protecting whistleblowers from retaliation and providing support throughout and after the process.

Artefacts an auditor will ask for
  • Protection plan from the moment of receipt covering identity protection, employment protection and welfare support
  • Retaliation risk assessment refreshed at intake, during investigation and after closure
  • Burden of proof reversal procedure aligned to EU Directive 2019/1937 Article 21
  • Anti retaliation training for managers of areas where reporters work
  • Support services such as employee assistance, occupational health and external counsel access
  • Retaliation incident handling procedure with separate investigation track
Where this commonly fails
  • Protection focuses only on identity confidentiality and ignores employment outcomes such as performance ratings
  • No mechanism to reverse the burden of proof in alleged retaliation
  • Post closure check ins not scheduled so late retaliation goes unnoticed

Clause 9: Performance Evaluation

ISO-37002-9.1
Monitoring, measurement, analysis and evaluation

Requires monitoring and measuring the effectiveness of the whistleblowing management system.

Artefacts an auditor will ask for
  • Audit nonconformity log
  • Measurement and evaluation procedure
  • Benchmarking study results
Where this commonly fails
  • Management reviews skip innovation as an agenda item
  • Internal audits of IMS not scheduled
  • Customer feedback not systematically captured
ISO-37002-9.2
Internal audit

Requires conducting internal audits at planned intervals to verify conformance and effectiveness.

Artefacts an auditor will ask for
  • Audit nonconformity log
  • Benchmarking study results
  • Customer and partner feedback summary
Where this commonly fails
  • Benchmarking against peers absent
  • KPIs measure activity (idea count) not outcomes (revenue, adoption)
  • Evaluation criteria differ across portfolio without rationale
  • Lagging indicators only, no leading indicators
ISO-37002-9.3
Management review

Requires top management to review the whistleblowing management system for continuing suitability and effectiveness.

Artefacts an auditor will ask for
  • Innovation analytics report
  • Innovation KPI dashboard
  • Audit nonconformity log
  • Benchmarking study results
Where this commonly fails
  • Lagging indicators only, no leading indicators
  • Management reviews skip innovation as an agenda item
  • Customer feedback not systematically captured
  • Internal audits of IMS not scheduled

Context

ISO37002-4.1
Organizational Context for Whistleblowing

Determine internal and external context affecting whistleblowing risk and the management system's ability to function.

Artefacts an auditor will ask for
  • Context analysis document
  • Jurisdictional whistleblowing law register
  • Cultural readiness assessment
  • Operating model overview
Where this commonly fails
  • Country-specific legal differences ignored
  • No cultural readiness assessment
  • External reporting routes unmapped
ISO37002-4.2
Needs and Expectations of Interested Parties

Identify whistleblowers, recipients, investigators, regulators, and other interested parties and their requirements.

Artefacts an auditor will ask for
  • Stakeholder register
  • Regulator expectations log
  • Whistleblower needs analysis
  • Communication plan
Where this commonly fails
  • Contractor and supplier whistleblowers omitted
  • Regulator notification timelines unknown
  • No external stakeholder engagement
ISO37002-4.3
Scope of the WBMS

Determine the boundaries and applicability of the whistleblowing management system across the organization.

Artefacts an auditor will ask for
  • Documented scope
  • Subsidiary and JV inclusion list
  • Exclusion rationale
  • Scope review schedule
Where this commonly fails
  • JVs and contractors excluded
  • Scope not aligned with EU directive
  • No periodic review

Improvement

ISO37002-10.1
Continual Improvement

Continually improve the suitability, adequacy, and effectiveness of the WBMS based on monitoring and reviews.

Artefacts an auditor will ask for
  • Continual improvement register
  • Trend-driven actions
  • Best practice adoption
  • Improvement KPIs
Where this commonly fails
  • Improvements ad hoc
  • No trend-driven changes
  • No innovation tracking
ISO37002-10.2
Nonconformity and Corrective Action

Identify nonconformities, conduct root cause analysis, and implement corrective actions with verified effectiveness.

Artefacts an auditor will ask for
  • NC register
  • RCA records
  • Corrective action plans
  • Effectiveness verification
Where this commonly fails
  • Symptom-only fixes
  • No RCA
  • Effectiveness not verified

Leadership

ISO37002-5.1
Leadership and Commitment

Top management and governing body demonstrate leadership and commitment to the whistleblowing management system.

Artefacts an auditor will ask for
  • Board minutes referencing WBMS
  • CEO communications
  • Resource allocation
  • Management performance objectives
Where this commonly fails
  • Leadership silent on whistleblowing
  • Insufficient resources
  • No board reporting
ISO37002-5.2
Whistleblowing Policy

Establish and communicate a whistleblowing policy that encourages reporting, protects whistleblowers, and prohibits retaliation.

Artefacts an auditor will ask for
  • Whistleblowing policy
  • Multi-language versions
  • Acknowledgement records
  • Public website posting
Where this commonly fails
  • Policy too legalistic
  • No translation
  • Acknowledgements not tracked
ISO37002-5.3
Roles, Responsibilities, Authorities

Assign and communicate responsibilities and authorities for the whistleblowing management system including independence.

Artefacts an auditor will ask for
  • WBMS roles matrix
  • Function charter
  • Independence safeguards
  • Authority documentation
Where this commonly fails
  • Roles informal
  • Independence undermined by reporting line
  • Authorities insufficient

Operation

ISO37002-8.2
Receiving Reports of Wrongdoing

Provide accessible reporting channels with options for anonymity and confidentiality across multiple media and languages.

Artefacts an auditor will ask for
  • Hotline and web portal
  • Multi-language support
  • Anonymity safeguards
  • Channel availability metrics
Where this commonly fails
  • One channel only
  • No anonymous option
  • Languages limited
ISO37002-8.3
Assessing Reports

Assess reports promptly to determine credibility, scope, urgency, and appropriate handling pathway.

Artefacts an auditor will ask for
  • Triage procedure
  • Assessment template
  • Severity matrix
  • Triage decisions log
Where this commonly fails
  • No triage criteria
  • Inconsistent severity
  • Triage by untrained staff
ISO37002-8.4
Addressing Reports of Wrongdoing

Address reports through investigation, mediation, or other appropriate action with documented findings and corrective measures.

Artefacts an auditor will ask for
  • Investigation procedure
  • Case files
  • Closure reports
  • Corrective action records
Where this commonly fails
  • Investigations led by conflicted persons
  • No closure
  • Corrective actions not tracked
ISO37002-8.5
Concluding Whistleblowing Cases

Conclude cases with appropriate outcomes, communication to the whistleblower, and lessons learned capture.

Artefacts an auditor will ask for
  • Outcome decision records
  • Whistleblower closure letters
  • Lessons learned register
  • Trend analysis
Where this commonly fails
  • Whistleblower never informed of outcome
  • No lessons capture
  • Cases linger open
ISO37002-8.6
Protection Against Detriment

Protect whistleblowers and others involved from retaliation and other detrimental treatment through active monitoring.

Artefacts an auditor will ask for
  • Anti-retaliation policy
  • Retaliation monitoring procedure
  • Remediation records
  • Manager training on non-retaliation
Where this commonly fails
  • No active monitoring
  • Subtle retaliation missed
  • No remediation
ISO37002-8.7
Confidentiality and Data Protection

Protect the identity of whistleblowers and personal data throughout the case lifecycle in line with applicable law.

Artefacts an auditor will ask for
  • Confidentiality procedure
  • Data protection impact assessment
  • Privacy notice for whistleblowers
  • Breach response plan
Where this commonly fails
  • Identity revealed in investigation
  • No DPIA
  • Breach response missing

Performance

ISO37002-9.1
Monitoring, Measurement, Analysis, Evaluation

Monitor and measure the WBMS for effectiveness including case throughput, outcomes, and whistleblower experience.

Artefacts an auditor will ask for
  • WBMS KPI dashboard
  • Whistleblower satisfaction survey
  • Trend reports
  • Benchmarking data
Where this commonly fails
  • Volume metrics only
  • No experience measurement
  • No trend analysis
ISO37002-9.2
Internal Audit

Conduct internal audits at planned intervals to evaluate WBMS conformity and effective implementation.

Artefacts an auditor will ask for
  • Audit charter
  • Risk-based audit plan
  • Audit reports
  • Findings tracker
Where this commonly fails
  • Audit lacks WB expertise
  • Findings not closed
  • No follow-up audits
ISO37002-9.3
Management Review

Top management reviews WBMS at planned intervals to ensure suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Review agenda
  • Review pack
  • Minutes
  • Action tracker
Where this commonly fails
  • Review descriptive only
  • No challenge
  • Actions not tracked

Planning

ISO37002-6.1.2
Whistleblowing Risk Assessment

Assess risks and opportunities related to whistleblowing including risks to whistleblowers and the management system.

Artefacts an auditor will ask for
  • Risk assessment
  • Retaliation risk analysis
  • Confidentiality risk register
  • Mitigation plans
Where this commonly fails
  • Retaliation risk not assessed
  • No confidentiality threat modelling
  • Risks not tracked
ISO37002-6.2
Whistleblowing Objectives

Establish measurable whistleblowing objectives consistent with the policy and plan how to achieve them.

Artefacts an auditor will ask for
  • Documented objectives
  • KPI dashboard
  • Resource plan
  • Progress reviews
Where this commonly fails
  • No objectives
  • Objectives qualitative only
  • No progress tracking

Support

ISO37002-7.2
Competence

Ensure receivers, investigators, and decision makers have the competence to perform whistleblowing roles effectively.

Artefacts an auditor will ask for
  • Competency profiles
  • Training records
  • Investigator certifications
  • Periodic assessments
Where this commonly fails
  • Untrained receivers
  • No interviewer training
  • Bias awareness missing
ISO37002-7.3
Awareness

Make personnel and relevant parties aware of the whistleblowing policy, channels, and their protections.

Artefacts an auditor will ask for
  • Awareness plan
  • Posters and intranet content
  • Onboarding inclusion
  • Awareness survey results
Where this commonly fails
  • Awareness one-off at onboarding
  • No measurement
  • External parties unaware
ISO37002-7.4
Communication

Determine internal and external communications relevant to the whistleblowing management system including with whistleblowers.

Artefacts an auditor will ask for
  • Communication plan
  • Status update templates
  • Regulator notification protocol
  • Communication log
Where this commonly fails
  • Whistleblowers not updated
  • No regulator protocol
  • External comms ad hoc
ISO37002-7.5
Documented Information

Maintain documented information with strict confidentiality, retention, and access controls appropriate to sensitivity.

Artefacts an auditor will ask for
  • Case management system
  • Access control logs
  • Retention schedule
  • Encryption standards
Where this commonly fails
  • Shared drives used
  • Excessive access
  • No retention enforcement
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.