A company's whistleblower policy is often written once, filed away, and never tested. That's a risk — both because a badly designed policy fails exactly when you need it most, and because Malaysia's legal landscape around whistleblowing has recently moved. Amendments to the Whistleblower Protection Act 2010 were passed by the Dewan Rakyat, strengthening protection in ways that directly affect how employers should design internal reporting channels.

What changed — and why it matters for your policy

Two changes stand out. First, the removal of a provision that previously disqualified whistleblowers if their disclosure was prohibited under other secrecy laws — meaning protection can now extend further than before. Second, a new provision gives enforcement agencies discretion to maintain protection even where the whistleblower was themselves implicated in the wrongdoing, encouraging insiders closest to a problem to come forward. For employers, the practical implication is the same: your internal whistleblowing channel needs to be credible and safe enough that people actually use it, rather than waiting for an external route.

What ISO 37002 asks for in a whistleblowing system

ISO 37002 provides guidelines for a Whistleblowing Management System built on three pillars:

  • Trust — employees must genuinely believe reports will be taken seriously and handled fairly.
  • Impartiality — investigations must be conducted without bias toward the reporter or the accused.
  • Protection — safeguards against retaliation, including confidentiality of the reporter's identity.

What a working policy actually includes

  • A clear, accessible reporting channel — ideally more than one option (hotline, email, in-person).
  • A defined investigation process with realistic timelines.
  • Explicit anti-retaliation protections, communicated clearly to all staff, not buried in a handbook.
  • Regular review — a policy that hasn't been tested or updated in years is a red flag during any audit.

Whistleblowing and MACC Section 17A

A working whistleblowing system is also one of the practical building blocks of "adequate procedures" under MACC Section 17A — see our guide to Section 17A and adequate procedures — and is often implemented alongside ISO 37001 as part of a single anti-bribery and governance programme.

Building this capability internally

Designing a whistleblowing system that people will actually trust and use is a specific skill — covered directly in our Anti-Corruption, Governance & Legal Compliance program, customised to your organisation's structure and risk profile.

Frequently asked questions

Is ISO 37002 certification mandatory in Malaysia?

No, it is not a legal requirement, but it provides internationally recognised guidelines for building a whistleblowing system employees will trust and actually use.

Do the Whistleblower Protection Act amendments apply to private companies?

The amendments strengthen protections generally within the Malaysian legal framework; regardless of the exact legal scope, they signal that regulators and civil society expect stronger internal whistleblowing systems from employers.

What's the biggest reason whistleblowing policies fail in practice?

Lack of trust — employees who doubt a report will be taken seriously, handled impartially, or kept confidential simply won't use the channel, regardless of what the written policy says.