managing-whistleblower-programs
Structures whistleblower program operations with intake, investigation, and anti-retaliation documentation. Use when managing whistleblower reports, investigating complaints, or documenting anti-retaliation measures.
Best use case
managing-whistleblower-programs is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
Structures whistleblower program operations with intake, investigation, and anti-retaliation documentation. Use when managing whistleblower reports, investigating complaints, or documenting anti-retaliation measures.
Teams using managing-whistleblower-programs should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/managing-whistleblower-programs/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How managing-whistleblower-programs Compares
| Feature / Agent | managing-whistleblower-programs | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Structures whistleblower program operations with intake, investigation, and anti-retaliation documentation. Use when managing whistleblower reports, investigating complaints, or documenting anti-retaliation measures.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
SKILL.md Source
# Managing Whistleblower Programs Structures whistleblower program operations across intake, triage, investigation tracking, and anti-retaliation compliance documentation. ## When To Use - Standing up or overhauling a whistleblower intake and case-management process - Documenting the lifecycle of a whistleblower complaint from receipt through resolution - Preparing anti-retaliation monitoring plans for reporters and witnesses - Generating status reports for the audit committee, board, or regulators on open complaints - Coordinating between compliance, legal, HR, and internal audit on active investigations - Responding to regulatory inquiries about program adequacy (e.g., SEC, DOJ, OSHA reviews) ## Inputs To Gather - **Program charter or policy**: Existing whistleblower policy, hotline vendor contract, and board-approved charter - **Complaint record**: Date received, channel (hotline, email, in-person, regulator referral), verbatim summary, reporter identity or anonymity status - **Applicable regulatory framework**: Dodd-Frank §922, SOX §806, EU Whistleblower Directive 2019/1937, or sector-specific rules [VERIFY jurisdiction and statute applicability] - **Organizational chart**: Reporting lines relevant to the allegation (to identify conflict-of-interest and recusal needs) - **Prior investigations**: Related past complaints, audit findings, or enforcement actions - **Anti-retaliation baseline**: Reporter's current role, compensation, performance ratings, and reporting chain at time of complaint (for later comparison) - **Investigation resources**: Available internal investigators, approved outside counsel or forensic firms, budget constraints ## Workflow 1. **Intake & Logging** - Assign a unique case ID; log date, channel, anonymity election, and complaint category (fraud, safety, discrimination, retaliation, other) - Classify urgency: imminent harm → immediate escalation; financial misstatement → expedited; policy violation → standard - Confirm reporter acknowledgment within required timeframe [VERIFY: Dodd-Frank has no mandated acknowledgment; EU Directive requires acknowledgment within 7 days] 2. **Conflict-of-Interest Screen** - Map accused individuals against compliance, legal, HR, and executive leadership - Recuse any conflicted parties from investigation oversight; document recusal in the case file - If the allegation involves C-suite or board members, route directly to the audit committee chair or independent outside counsel 3. **Investigation Scoping** - Define allegations to be investigated, relevant time period, custodians, and document sources - Select investigation team: internal compliance, outside counsel, forensic accountants as needed - Set target milestones: preliminary findings (15–30 days), final report (60–90 days) [VERIFY company policy timelines] - Issue preservation notices for relevant documents and electronic data 4. **Investigation Execution & Tracking** - Maintain an investigation log: interviews conducted, documents reviewed, evidence collected, chain-of-custody records - Track against milestones; flag delays with root cause and revised target dates - Brief the audit committee or designated oversight body at agreed intervals (typically biweekly for high-priority cases) 5. **Anti-Retaliation Monitoring** - Freeze adverse employment actions for the reporter without documented, pre-existing justification unrelated to the report - Establish periodic check-ins (30 / 60 / 90 / 180 / 365 days post-report) comparing role, compensation, performance ratings, and workload against baseline - Document each check-in result; any negative change triggers an independent review before proceeding - Extend monitoring to witnesses and cooperators identified during the investigation 6. **Findings & Remediation** - Prepare a written investigation report: scope, methodology, factual findings, conclusions, and recommended corrective actions - Classify outcome: substantiated, partially substantiated, unsubstantiated, or inconclusive - If substantiated, document remediation plan (disciplinary action, process changes, control enhancements) with owners and deadlines - If financial misstatement found, coordinate with external auditors and evaluate disclosure obligations [VERIFY SEC reporting timelines] 7. **Case Closure & Reporting** - Notify the reporter of outcome to the extent permitted by law and policy [VERIFY: EU Directive requires feedback within 3 months] - Archive the complete case file with access restricted to compliance and legal - Update aggregate program metrics: complaint volume, category breakdown, time-to-close, substantiation rate, retaliation findings - Report program metrics to the audit committee quarterly and include in the annual compliance report ## Output The deliverable is a **Whistleblower Program Management Report** containing: - **Case Register Summary**: Table of open and recently closed cases with ID, category, status, days open, and assigned investigator - **Investigation Status Updates**: Per-case narrative covering current phase, recent actions, upcoming milestones, and escalation flags - **Anti-Retaliation Monitoring Log**: Reporter-by-reporter tracking grid showing baseline vs. current employment status at each check-in interval - **Program Metrics Dashboard**: Complaint volume trends, channel utilization, average time-to-close, substantiation rates, and retaliation incident count - **Remediation Tracker**: Substantiated-case corrective actions with owners, deadlines, and completion status - **Regulatory Compliance Checklist**: Confirmation of adherence to applicable statute requirements (acknowledgment timing, feedback obligations, confidentiality protections) ## Quality Checks - Every complaint has a unique case ID, timestamped intake record, and assigned handler within the documented SLA - Conflict-of-interest screening is documented for each case, including "no conflict found" entries - Anti-retaliation baselines are captured before any investigation activity that could alert the accused - Investigation milestones include specific calendar dates, not just duration ranges - Aggregate metrics are reconciled against the case register (complaint count matches, no orphaned records) - Jurisdiction-specific obligations are marked [VERIFY] and confirmed against the applicable statute before finalizing - Reporter notification timing complies with applicable legal requirements - Case file access is restricted and access logs are reviewed for unauthorized views
Related Skills
managing-wound-care
Guides wound assessment, classification, and treatment selection with documentation requirements. Use when managing surgical wounds, classifying wound types, or selecting wound care protocols.
managing-wound-assessment-nursing
Structures wound assessment with measurement, staging, and treatment plan documentation. Use when assessing wounds, staging pressure injuries, or documenting wound care.
managing-workplace-safety-healthcare
Tracks OSHA healthcare requirements including bloodborne pathogen, TB, and violence prevention programs. Use when managing OSHA compliance, implementing safety programs, or documenting exposure incidents.
managing-workers-compensation-rehabilitation
Structures workers comp rehab documentation with functional capacity evaluation and return-to-work planning. Use when managing work injury rehab, performing FCEs, or documenting return-to-work status.
managing-vestibular-rehabilitation
Structures vestibular assessment with positional testing and customized exercise programs. Use when evaluating vestibular disorders, performing Dix-Hallpike testing, or designing vestibular exercise programs.
managing-venous-thromboembolism-prophylaxis
Applies VTE risk assessment (Padua, Caprini) with appropriate prophylaxis selection. Use when assessing VTE risk, selecting prophylaxis regimens, or documenting DVT prevention.
managing-valvular-heart-disease
Guides valve disease severity assessment with intervention criteria and surveillance schedules. Use when evaluating valve disease, assessing surgical/interventional timing, or monitoring valve function.
managing-vaccine-schedules
Applies CDC immunization schedules with catch-up protocols and contraindication screening. Use when managing vaccinations, creating catch-up schedules, or documenting immunization decisions.
managing-vaccination-campaigns
Plans mass vaccination campaigns with logistics, cold chain management, and adverse event monitoring. Use when planning vaccination drives, managing immunization logistics, or monitoring VAERS.
managing-traumatic-brain-injury-rehabilitation
Structures TBI rehab with Rancho Los Amigos scoring and cognitive rehabilitation protocols. Use when managing TBI rehab, tracking Rancho levels, or implementing cognitive therapy.
managing-trauma-assessments
Conducts structured primary and secondary trauma surveys following ATLS methodology. Use when assessing trauma patients, documenting trauma workups, or coordinating trauma team activations.
managing-transplant-evaluations
Guides transplant candidacy evaluation with organ-specific criteria and listing documentation. Use when evaluating transplant candidates, documenting listing criteria, or coordinating transplant workups.