managing-whistleblower-programs

Structures whistleblower program operations with intake, investigation, and anti-retaliation documentation. Use when managing whistleblower reports, investigating complaints, or documenting anti-retaliation measures.

11 stars

Best use case

managing-whistleblower-programs is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Structures whistleblower program operations with intake, investigation, and anti-retaliation documentation. Use when managing whistleblower reports, investigating complaints, or documenting anti-retaliation measures.

Teams using managing-whistleblower-programs should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/managing-whistleblower-programs/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/finance/managing-whistleblower-programs/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/managing-whistleblower-programs/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How managing-whistleblower-programs Compares

Feature / Agentmanaging-whistleblower-programsStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Structures whistleblower program operations with intake, investigation, and anti-retaliation documentation. Use when managing whistleblower reports, investigating complaints, or documenting anti-retaliation measures.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Managing Whistleblower Programs

Structures whistleblower program operations across intake, triage, investigation tracking, and anti-retaliation compliance documentation.

## When To Use

- Standing up or overhauling a whistleblower intake and case-management process
- Documenting the lifecycle of a whistleblower complaint from receipt through resolution
- Preparing anti-retaliation monitoring plans for reporters and witnesses
- Generating status reports for the audit committee, board, or regulators on open complaints
- Coordinating between compliance, legal, HR, and internal audit on active investigations
- Responding to regulatory inquiries about program adequacy (e.g., SEC, DOJ, OSHA reviews)

## Inputs To Gather

- **Program charter or policy**: Existing whistleblower policy, hotline vendor contract, and board-approved charter
- **Complaint record**: Date received, channel (hotline, email, in-person, regulator referral), verbatim summary, reporter identity or anonymity status
- **Applicable regulatory framework**: Dodd-Frank §922, SOX §806, EU Whistleblower Directive 2019/1937, or sector-specific rules [VERIFY jurisdiction and statute applicability]
- **Organizational chart**: Reporting lines relevant to the allegation (to identify conflict-of-interest and recusal needs)
- **Prior investigations**: Related past complaints, audit findings, or enforcement actions
- **Anti-retaliation baseline**: Reporter's current role, compensation, performance ratings, and reporting chain at time of complaint (for later comparison)
- **Investigation resources**: Available internal investigators, approved outside counsel or forensic firms, budget constraints

## Workflow

1. **Intake & Logging**
   - Assign a unique case ID; log date, channel, anonymity election, and complaint category (fraud, safety, discrimination, retaliation, other)
   - Classify urgency: imminent harm → immediate escalation; financial misstatement → expedited; policy violation → standard
   - Confirm reporter acknowledgment within required timeframe [VERIFY: Dodd-Frank has no mandated acknowledgment; EU Directive requires acknowledgment within 7 days]

2. **Conflict-of-Interest Screen**
   - Map accused individuals against compliance, legal, HR, and executive leadership
   - Recuse any conflicted parties from investigation oversight; document recusal in the case file
   - If the allegation involves C-suite or board members, route directly to the audit committee chair or independent outside counsel

3. **Investigation Scoping**
   - Define allegations to be investigated, relevant time period, custodians, and document sources
   - Select investigation team: internal compliance, outside counsel, forensic accountants as needed
   - Set target milestones: preliminary findings (15–30 days), final report (60–90 days) [VERIFY company policy timelines]
   - Issue preservation notices for relevant documents and electronic data

4. **Investigation Execution & Tracking**
   - Maintain an investigation log: interviews conducted, documents reviewed, evidence collected, chain-of-custody records
   - Track against milestones; flag delays with root cause and revised target dates
   - Brief the audit committee or designated oversight body at agreed intervals (typically biweekly for high-priority cases)

5. **Anti-Retaliation Monitoring**
   - Freeze adverse employment actions for the reporter without documented, pre-existing justification unrelated to the report
   - Establish periodic check-ins (30 / 60 / 90 / 180 / 365 days post-report) comparing role, compensation, performance ratings, and workload against baseline
   - Document each check-in result; any negative change triggers an independent review before proceeding
   - Extend monitoring to witnesses and cooperators identified during the investigation

6. **Findings & Remediation**
   - Prepare a written investigation report: scope, methodology, factual findings, conclusions, and recommended corrective actions
   - Classify outcome: substantiated, partially substantiated, unsubstantiated, or inconclusive
   - If substantiated, document remediation plan (disciplinary action, process changes, control enhancements) with owners and deadlines
   - If financial misstatement found, coordinate with external auditors and evaluate disclosure obligations [VERIFY SEC reporting timelines]

7. **Case Closure & Reporting**
   - Notify the reporter of outcome to the extent permitted by law and policy [VERIFY: EU Directive requires feedback within 3 months]
   - Archive the complete case file with access restricted to compliance and legal
   - Update aggregate program metrics: complaint volume, category breakdown, time-to-close, substantiation rate, retaliation findings
   - Report program metrics to the audit committee quarterly and include in the annual compliance report

## Output

The deliverable is a **Whistleblower Program Management Report** containing:

- **Case Register Summary**: Table of open and recently closed cases with ID, category, status, days open, and assigned investigator
- **Investigation Status Updates**: Per-case narrative covering current phase, recent actions, upcoming milestones, and escalation flags
- **Anti-Retaliation Monitoring Log**: Reporter-by-reporter tracking grid showing baseline vs. current employment status at each check-in interval
- **Program Metrics Dashboard**: Complaint volume trends, channel utilization, average time-to-close, substantiation rates, and retaliation incident count
- **Remediation Tracker**: Substantiated-case corrective actions with owners, deadlines, and completion status
- **Regulatory Compliance Checklist**: Confirmation of adherence to applicable statute requirements (acknowledgment timing, feedback obligations, confidentiality protections)

## Quality Checks

- Every complaint has a unique case ID, timestamped intake record, and assigned handler within the documented SLA
- Conflict-of-interest screening is documented for each case, including "no conflict found" entries
- Anti-retaliation baselines are captured before any investigation activity that could alert the accused
- Investigation milestones include specific calendar dates, not just duration ranges
- Aggregate metrics are reconciled against the case register (complaint count matches, no orphaned records)
- Jurisdiction-specific obligations are marked [VERIFY] and confirmed against the applicable statute before finalizing
- Reporter notification timing complies with applicable legal requirements
- Case file access is restricted and access logs are reviewed for unauthorized views

Related Skills

managing-wound-care

11
from CaseMark/skills

Guides wound assessment, classification, and treatment selection with documentation requirements. Use when managing surgical wounds, classifying wound types, or selecting wound care protocols.

managing-wound-assessment-nursing

11
from CaseMark/skills

Structures wound assessment with measurement, staging, and treatment plan documentation. Use when assessing wounds, staging pressure injuries, or documenting wound care.

managing-workplace-safety-healthcare

11
from CaseMark/skills

Tracks OSHA healthcare requirements including bloodborne pathogen, TB, and violence prevention programs. Use when managing OSHA compliance, implementing safety programs, or documenting exposure incidents.

managing-workers-compensation-rehabilitation

11
from CaseMark/skills

Structures workers comp rehab documentation with functional capacity evaluation and return-to-work planning. Use when managing work injury rehab, performing FCEs, or documenting return-to-work status.

managing-vestibular-rehabilitation

11
from CaseMark/skills

Structures vestibular assessment with positional testing and customized exercise programs. Use when evaluating vestibular disorders, performing Dix-Hallpike testing, or designing vestibular exercise programs.

managing-venous-thromboembolism-prophylaxis

11
from CaseMark/skills

Applies VTE risk assessment (Padua, Caprini) with appropriate prophylaxis selection. Use when assessing VTE risk, selecting prophylaxis regimens, or documenting DVT prevention.

managing-valvular-heart-disease

11
from CaseMark/skills

Guides valve disease severity assessment with intervention criteria and surveillance schedules. Use when evaluating valve disease, assessing surgical/interventional timing, or monitoring valve function.

managing-vaccine-schedules

11
from CaseMark/skills

Applies CDC immunization schedules with catch-up protocols and contraindication screening. Use when managing vaccinations, creating catch-up schedules, or documenting immunization decisions.

managing-vaccination-campaigns

11
from CaseMark/skills

Plans mass vaccination campaigns with logistics, cold chain management, and adverse event monitoring. Use when planning vaccination drives, managing immunization logistics, or monitoring VAERS.

managing-traumatic-brain-injury-rehabilitation

11
from CaseMark/skills

Structures TBI rehab with Rancho Los Amigos scoring and cognitive rehabilitation protocols. Use when managing TBI rehab, tracking Rancho levels, or implementing cognitive therapy.

managing-trauma-assessments

11
from CaseMark/skills

Conducts structured primary and secondary trauma surveys following ATLS methodology. Use when assessing trauma patients, documenting trauma workups, or coordinating trauma team activations.

managing-transplant-evaluations

11
from CaseMark/skills

Guides transplant candidacy evaluation with organ-specific criteria and listing documentation. Use when evaluating transplant candidates, documenting listing criteria, or coordinating transplant workups.