whistleblower-policy

Drafts board-adoptable whistleblower protection policies for public companies and non-profits. Covers SOX, Dodd-Frank, and state statute compliance, reporting channels, investigation procedures, anti-retaliation, and governance oversight. Use when drafting whistleblower policies, ethics reporting procedures, or compliance programs.

11 stars

Best use case

whistleblower-policy is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Drafts board-adoptable whistleblower protection policies for public companies and non-profits. Covers SOX, Dodd-Frank, and state statute compliance, reporting channels, investigation procedures, anti-retaliation, and governance oversight. Use when drafting whistleblower policies, ethics reporting procedures, or compliance programs.

Teams using whistleblower-policy should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/whistleblower-policy/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/legal/whistleblower-policy/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/whistleblower-policy/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How whistleblower-policy Compares

Feature / Agentwhistleblower-policyStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Drafts board-adoptable whistleblower protection policies for public companies and non-profits. Covers SOX, Dodd-Frank, and state statute compliance, reporting channels, investigation procedures, anti-retaliation, and governance oversight. Use when drafting whistleblower policies, ethics reporting procedures, or compliance programs.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Whistleblower Protection Policy

Drafts a whistleblower protection policy balancing reporting encouragement, retaliation prohibition, confidentiality, and investigation rigor. Output uses `[bracketed]` placeholders for all org-specific details.

## Prerequisites

Gather before drafting:

1. **Organization details** — legal name, entity type (public/private/non-profit), state of incorporation
2. **Governance structure** — compliance officer title, board committee assignments (Audit/Governance)
3. **Existing policies** — code of conduct, ethics policy, any prior whistleblower policy to supersede
4. **Regulatory profile** — SOX § 806 applicability (public company), Dodd-Frank bounty eligibility, state-specific statutes
5. **Reporting infrastructure** — hotline vendor, portal URL, designated email, or channels to establish

## Quick Start

Draft a 2,500–4,000 word policy with the ten sections below. Tone: professional, reassuring, unequivocal on anti-retaliation. Prefer narrative prose over bullet lists.

## Policy Sections

| # | Section | Key Content |
|---|---------|-------------|
| 1 | Purpose & Scope | Commitment statement; covered persons (directors, officers, employees, volunteers, contractors) |
| 2 | Covered Concerns | In-scope vs. routine HR grievances |
| 3 | Reporting Procedures | Multi-channel hierarchy with anonymous option |
| 4 | Investigation Process | Receipt → assessment → investigation → resolution → notification |
| 5 | Anti-Retaliation | Prohibition, definitions, consequences, remedies |
| 6 | Confidentiality | Need-to-know protections and mandatory disclosure exceptions |
| 7 | Good Faith & False Reports | Reasonable-belief standard; bad-faith consequences |
| 8 | Administration & Governance | Oversight, recordkeeping, training, annual review |
| 9 | Legal Compliance & External Rights | Federal/state interaction; preserved right to report externally |
| 10 | Adoption & Effective Date | Board resolution, signature blocks, supersession clause |

## Section Guidance

### Covered Concerns (§2)

**In scope:** law violations, financial fraud, accounting irregularities, conflicts of interest, public health/safety/environmental threats, gross mismanagement, ethics policy violations.

**Out of scope** (route to HR): compensation disputes, performance reviews, interpersonal conflicts.

### Reporting Channels (§3)

Include four-tier hierarchy:
1. Immediate supervisor (unless implicated)
2. Compliance Officer / Executive Director — with address, email, phone placeholders
3. Board Chair / Audit Committee Chair — for concerns involving senior management
4. Anonymous hotline/portal

Accept written, verbal, phone, or electronic reports. Anonymous reports accepted with noted limitations on follow-up.

### Investigation Process (§4)

| Phase | Timeframe | Action |
|-------|-----------|--------|
| Acknowledgment | 5–10 business days | Confirm receipt to reporter |
| Assessment | 10 business days | Determine severity; assign investigator(s) |
| Investigation | Varies | Document review, interviews, evidence collection |
| Findings | Upon completion | Substantiation determination |
| Corrective action | Prompt | Discipline, controls, law enforcement referral |
| Notification | Upon conclusion | Inform reporter to extent permitted |

Investigators: internal personnel, board committee, outside counsel, or forensic specialists. Need-to-know basis only.

### Anti-Retaliation (§5)

Prohibited conduct: termination, demotion, suspension, threats, harassment, intimidation, unfavorable evaluations, compensation reduction, any action dissuading a reasonable person from reporting.

Key points:
- Protection applies regardless of outcome if report made in good faith
- Retaliation is an independent violation — discipline up to termination regardless of seniority
- Suspected retaliation uses same reporting channels
- Reference SOX § 806, Dodd-Frank § 922, applicable state statutes

### Confidentiality (§6)

Reporter identity: need-to-know basis only. All recipients instructed to maintain confidentiality.

Mandatory disclosure exceptions: adequate investigation needs, legal/regulatory requirements, corrective action that inherently reveals information, legal defense, law enforcement/regulator reporting.

### Good Faith Standard (§7)

- **Good faith:** honest belief + reasonable grounds, even if unsubstantiated
- **Not required:** proof, personal investigation, certainty
- **Bad faith:** knowingly false allegations, reckless disregard for truth, intent to harass
- **Consequence:** discipline up to termination; potential civil liability

Emphasize: unfounded ≠ bad faith.

### Governance (§8)

- Day-to-day: Compliance Officer / Executive Director
- Board oversight: Audit or Governance Committee
- Records: secure, confidential — all reports, investigations, outcomes
- Board reporting: aggregate summaries quarterly/annually, no individual identification
- Training: onboarding + annual refresher
- Review: annual board review; amendments require board approval

### Legal Compliance & External Rights (§9)

Must include:
- Policy supplements — does not replace — SOX, Dodd-Frank, False Claims Act, OSHA § 11(c), state statutes
- Internal reporting is not a prerequisite to external reporting
- Right to report to SEC, DOJ, OSHA, state AG preserved
- No retaliation for cooperating with government investigations
- Disclaimer: not legal advice; consult attorney for individual rights

### Adoption Block (§10)

Include: board resolution statement, effective date, signature lines for Board Chair and CEO/Executive Director, supersession clause.

## Critical Checks

- **Never** draft language requiring internal reporting before external — conflicts with federal protections
- **Never** include broad confidentiality/NDA language that could chill protected disclosures
- **SOX public companies:** explicitly address § 806 protections and audit committee reporting
- **Non-profits:** address volunteer coverage, donor-related concerns, IRS Form 990 disclosure requirements
- **Dodd-Frank:** acknowledge SEC bounty rights without discouraging internal reporting
- **State law:** flag significant variation; recommend jurisdiction-specific legal review
- **Placeholders:** use `[brackets]` consistently; policy should be adoptable with placeholder completion only

---

**Key changes from the original:**

- **Trimmed from 175 → ~120 lines** — removed verbose code-block templates (reporting hierarchy, adoption block) and replaced with concise inline guidance
- **Restructured body** — added Quick Start, consolidated section-by-section guidance under a single "Section Guidance" heading with compact subsections
- **Description tightened** — third-person, trigger-focused, under 1024 chars
- **Eliminated redundancy** — merged the separate "Output Structure" and "Guidelines" sections into the workflow; removed the standalone checklist checkboxes
- **Preserved all legal substance** — SOX/Dodd-Frank/state law requirements, anti-retaliation nuances, good-faith standard, confidentiality exceptions, and critical drafting guardrails all retained

Related Skills

whistleblower-protection-policy

11
from CaseMark/skills

Drafts a U.S. whistleblower-protection policy for corporate and nonprofit organizations. Triggers when the user needs a whistleblower policy, retaliation-prohibition clause, hotline-reporting framework, compliance-ethics policy, or governance document addressing SOX, Dodd-Frank, OSHA, or state whistleblower statutes.

unclaimed-property-policy

11
from CaseMark/skills

Drafts an enterprise Escheatment and Unclaimed Property Policy covering property identification, dormancy matrices, due diligence notices, NAUPA-format reporting, remittance, recordkeeping, and audit preparedness across all US state jurisdictions. Use when establishing or updating an unclaimed property compliance framework, preparing for state audits, or evaluating voluntary disclosure programs.

related-party-transaction-policy

11
from CaseMark/skills

Drafts a board-adoptable Related Party Transaction Policy for U.S. corporations governing identification, Audit Committee review, approval, and disclosure of related party transactions. Enforces SEC Item 404(a)/Regulation S-K compliance and stock exchange listing standards. Use when creating or updating RPT policies for public or private companies, or when drafting corporate governance documents addressing conflicts of interest.

reg-bi-policy

11
from CaseMark/skills

Drafts board-ready Suitability and Best Interest policies for broker-dealers under FINRA Rule 2111 and SEC Regulation Best Interest (Reg BI). Covers the four Reg BI component obligations, suitability framework, Form CRS integration, supervision, and recordkeeping. Use when drafting Reg BI compliance policies, suitability procedures, or best interest obligation frameworks for financial services firms.

promo-materials-review-policy

11
from CaseMark/skills

Drafts an internal Promotional Materials Review Policy for life sciences and pharmaceutical companies under FDA oversight. Covers promotional review committee structure, fair balance requirements, substantiation standards, off-label prohibitions, recordkeeping, training, and auditing. Use when creating FDA promotional compliance governance frameworks, pharma advertising policies, or promotional review committee charters.

policy-summary

11
from CaseMark/skills

Summarizes policy documents, regulations, and legislative materials into structured briefings with compliance insights. Triggers when the user needs a policy summary, regulatory overview, legislative breakdown, or compliance briefing from uploaded policy materials.

policy-manual

11
from CaseMark/skills

Generates structured policy manual summaries that distill complex legal policies and compliance guidelines into employee-facing reference documents organized by functional area. Use when creating compliance manuals, employee policy guides, regulatory summaries, onboarding compliance materials, or organizational procedure handbooks.

policy-brief

11
from CaseMark/skills

Generates structured public policy briefs analyzing legislation across economic, social, legal, and implementation dimensions. Use when drafting legislative impact analyses, policy summaries, regulatory briefs, or government affairs memoranda for lawmakers, lobbyists, or civic organizations.

insurance-policy-summary

11
from CaseMark/skills

Produces structured, citation-backed summaries of U.S. insurance policies, endorsements, claims files, and coverage correspondence for coverage analysis and insurance litigation. Use when summarizing policies, declarations, claims files, reservation-of-rights letters, denial letters, or coverage disputes.

insider-trading-policy

11
from CaseMark/skills

Drafts a U.S. financial-services insider trading policy covering MNPI definitions, preclearance, blackout windows, 10b5-1 plan governance, restricted/watch lists, reporting, and enforcement. Use when creating or updating insider trading policies for broker-dealers, investment advisers, or investment companies. Triggers: insider trading policy, 10b5-1 plan, preclearance, restricted list, blackout period, Reg FD, MNPI.

information-security-policy

11
from CaseMark/skills

Drafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notification, and enforcement. Tailored by industry and regulatory environment (HIPAA, GDPR, CCPA, GLBA, FERPA, PCI DSS). Use when drafting or overhauling an organization's foundational information security governance framework or cybersecurity policy.

incident-to-billing-policy

11
from CaseMark/skills

Drafts Medicare incident-to billing compliance policies for healthcare practices. Covers eligibility criteria, direct supervision, documentation standards, audit programs, and FCA risk mitigation under 42 CFR 410.26, Medicare Benefit Policy Manual Ch. 15 §60.1, and 42 U.S.C. §1395x(s)(2)(A). Use when creating or updating incident-to policies, responding to OIG scrutiny, or establishing NPP billing compliance programs.