ISO-37002-10.1 | Nonconformity and corrective action | 11 |
ISO-37002-10.2 | Continual improvement | 16 |
ISO-37002-4.1 | Understanding the organization and its context | 14 |
ISO-37002-4.2 | Understanding the needs and expectations of interested parties | 10 |
ISO-37002-4.3 | Determining the scope of the whistleblowing management system | 3 |
ISO-37002-4.4 | Whistleblowing management system | 0 |
ISO-37002-5.1 | Leadership and commitment | 15 |
ISO-37002-5.2 | Whistleblowing policy | 0 |
ISO-37002-5.3 | Organizational roles, responsibilities and authorities | 12 |
ISO-37002-6.1 | Actions to address risks and opportunities | 11 |
ISO-37002-6.2 | Whistleblowing management system objectives and planning | 0 |
ISO-37002-7.1 | Resources | 1 |
ISO-37002-7.2 | Competence | 0 |
ISO-37002-7.3 | Awareness and training | 1 |
ISO-37002-7.4 | Communication | 5 |
ISO-37002-7.5 | Documented information | 14 |
ISO-37002-8.1 | Receiving reports of wrongdoing | 0 |
ISO-37002-8.2 | Assessing reports of wrongdoing | 0 |
ISO-37002-8.3 | Addressing reports of wrongdoing | 0 |
ISO-37002-8.4 | Concluding whistleblowing cases | 0 |
ISO-37002-8.5 | Protection of whistleblowers | 0 |
ISO-37002-9.1 | Monitoring, measurement, analysis and evaluation | 11 |
ISO-37002-9.2 | Internal audit | 14 |
ISO-37002-9.3 | Management review | 15 |
ISO37002-10.1 | Continual Improvement | 16 |
ISO37002-10.2 | Nonconformity and Corrective Action | 11 |
ISO37002-4.1 | Organizational Context for Whistleblowing | 0 |
ISO37002-4.2 | Needs and Expectations of Interested Parties | 9 |
ISO37002-4.3 | Scope of the WBMS | 0 |
ISO37002-5.1 | Leadership and Commitment | 15 |
ISO37002-5.2 | Whistleblowing Policy | 0 |
ISO37002-5.3 | Roles, Responsibilities, Authorities | 12 |
ISO37002-6.1.2 | Whistleblowing Risk Assessment | 0 |
ISO37002-6.2 | Whistleblowing Objectives | 0 |
ISO37002-7.2 | Competence | 0 |
ISO37002-7.3 | Awareness | 1 |
ISO37002-7.4 | Communication | 5 |
ISO37002-7.5 | Documented Information | 14 |
ISO37002-8.2 | Receiving Reports of Wrongdoing | 1 |
ISO37002-8.3 | Assessing Reports | 0 |
ISO37002-8.4 | Addressing Reports of Wrongdoing | 0 |
ISO37002-8.5 | Concluding Whistleblowing Cases | 0 |
ISO37002-8.6 | Protection Against Detriment | 1 |
ISO37002-8.7 | Confidentiality and Data Protection | 3 |
ISO37002-9.1 | Monitoring, Measurement, Analysis, Evaluation | 10 |
ISO37002-9.2 | Internal Audit | 14 |
ISO37002-9.3 | Management Review | 15 |
10 | 10 Improvement | 0 |
10.1 | 10.1 Continual improvement | 0 |
10.2 | 10.2 Nonconformity and corrective action | 0 |
4 | 4 Context of the organization | 0 |
4.1 | 4.1 Understanding the organization and its context | 0 |
4.2 | 4.2 Understanding the needs and expectations of interested parties | 0 |
4.3 | 4.3 Determining the scope of the whistleblowing management system | 0 |
4.4 | 4.4 Whistleblowing management system | 0 |
5 | 5 Leadership | 0 |
5.1 | 5.1 Leadership and commitment | 0 |
5.1.1 | 5.1.1 Governing body | 0 |
5.1.2 | 5.1.2 Top management | 0 |
5.2 | 5.2 Whistleblowing policy | 0 |
5.3 | 5.3 Roles, responsibilities and authorities | 0 |
5.3.1 | 5.3.1 Top management and governing body | 0 |
5.3.2 | 5.3.2 Whistleblowing management function | 0 |
5.3.3 | 5.3.3 Delegated decision-making | 0 |
6 | 6 Planning | 0 |
6.1 | 6.1 Actions to address risks and opportunities | 0 |
6.2 | 6.2 Whistleblowing management system objectives and planning to achieve them | 0 |
6.3 | 6.3 Planning of changes | 0 |
7 | 7 Support | 0 |
7.1 | 7.1 Resources | 0 |
7.2 | 7.2 Competence | 0 |
7.3 | 7.3 Awareness | 0 |
7.3.1 | 7.3.1 General | 0 |
7.3.2 | 7.3.2 Personnel training and awareness measures | 0 |
7.3.3 | 7.3.3 Training for leaders and other specific roles | 0 |
7.4 | 7.4 Communication | 0 |
7.5 | 7.5 Documented information | 0 |
7.5.1 | 7.5.1 General | 0 |
7.5.2 | 7.5.2 Creating and updating documented information | 0 |
7.5.3 | 7.5.3 Control of documented information | 0 |
7.5.4 | 7.5.4 Data protection | 0 |
7.5.5 | 7.5.5 Confidentiality | 0 |
8 | 8 Operation | 0 |
8.1 | 8.1 Operational planning and control | 0 |
8.2 | 8.2 Receiving reports of wrongdoing | 0 |
8.3 | 8.3 Assessing reports of wrongdoing | 0 |
8.3.1 | 8.3.1 Assessing the reported wrongdoing | 0 |
8.3.2 | 8.3.2 Assessing and preventing risks of detrimental conduct | 0 |
8.4 | 8.4 Addressing reports of wrongdoing | 0 |
8.4.1 | 8.4.1 Addressing the reported wrongdoing | 0 |
8.4.2 | 8.4.2 Protecting and supporting the whistleblower | 0 |
8.4.3 | 8.4.3 Addressing detrimental conduct | 0 |
8.4.4 | 8.4.4 Protecting the subject(s) of a report | 0 |
8.4.5 | 8.4.5 Protecting relevant interested parties | 0 |
8.5 | 8.5 Concluding whistleblowing cases | 0 |
9 | 9 Performance evaluation | 0 |
9.1 | 9.1 Monitoring, measurement, analysis and evaluation | 0 |
9.1.1 | 9.1.1 General | 0 |
9.1.2 | 9.1.2 Indicators for evaluation | 0 |
9.1.3 | 9.1.3 Information sources | 0 |
9.2 | 9.2 Internal audit | 0 |
9.2.1 | 9.2.1 General | 0 |
9.2.2 | 9.2.2 Internal audit programme | 0 |
9.3 | 9.3 Management review | 0 |
9.3.1 | 9.3.1 General | 0 |
9.3.2 | 9.3.2 Management review inputs | 0 |
9.3.3 | 9.3.3 Management review results | 0 |
STANDARD | ISO 37002:2021: scope, the three principles, the four steps and the harmonized structure | 0 |
STATUS | Status: guidance, not certifiable; the EU Whistleblower Directive beside it | 0 |