A whistleblowing policy is the constitution of your speak-up programme: it defines what can be reported, by whom, with what protection, and what happens next. This template walks through the twelve clauses every Saudi company’s policy should contain — and the drafting decisions behind each.
The 12 clauses of a complete whistleblowing policy
1) Purpose and commitment — board-level statement that speaking up is protected and expected. 2) Scope of reportable concerns — fraud, corruption, harassment, safety, data misuse, conflicts of interest; and what belongs in grievance channels instead. 3) Who may report — employees, contractors, vendors, and optionally the public. 4) Channels — list every intake route: portal, QR, hotline, email, WhatsApp, in person. 5) Anonymity and confidentiality — the modes offered and the technical guarantee behind them. 6) Non-retaliation — explicit prohibition, with consequences for retaliators. 7) Triage and investigation process — stages, SLAs and segregation of duties. 8) Conflict-of-interest handling — recusal rules for case handlers. 9) Reporter feedback — what reporters are told, and when. 10) Data protection — PDPL basis, retention periods, residency. 11) Governance — programme owner, audit-committee oversight, reporting cadence. 12) Escalation to authorities — when cases involve NAZAHA or other regulators.
Drafting for a bilingual workforce
In Saudi Arabia the policy must live in Arabic and English as equals — not an English original with a rough translation. Draft the two versions together, keep sentences short enough to survive translation, and state which version prevails in interpretation. The reporting channels themselves must match: a bilingual policy pointing to an English-only portal undermines both.
Aligning the policy with PDPL and NAZAHA
Two clauses deserve legal review above all. The data-protection clause should name the lawful basis for processing report data, the retention schedule, and where data resides — in-Kingdom residency simplifies every sentence of it. The escalation clause should acknowledge cooperation with NAZAHA and other authorities without promising specifics that operations cannot honour.
From paper to practice
A policy nobody can execute is a liability in an audit. Every clause should map to a system capability: anonymity clause → architectural anonymity; SLA clause → workflow timers; recusal clause → automated conflict checks; records clause → immutable audit log. This mapping — policy line to platform feature — is exactly what Raqeeb’s configuration workshop produces during implementation.
- Twelve clauses make a complete policy — from scope and channels to PDPL and NAZAHA escalation.
- Draft Arabic and English as equal versions, and say which prevails.
- Every policy clause should map to an enforcing system capability.
- Have PDPL and escalation clauses reviewed by counsel.
Frequently asked questions
What should a Saudi whistleblowing policy include?
At minimum: purpose, scope of reportable concerns, eligible reporters, channels, anonymity commitments, non-retaliation, the investigation process with SLAs, conflict-of-interest recusal, reporter feedback, PDPL-compliant data handling, governance ownership and authority escalation.
Should the policy promise anonymity or confidentiality?
Offer both and let reporters choose per case. Promise only what your system technically enforces — an anonymity promise without architectural anonymity is a credibility risk.
How often should the policy be reviewed?
Annually, and after any material regulatory change or serious case that exposes a gap. Version the policy and keep prior versions retrievable for audits.
Whistleblowing, case management, conflict-of-interest and gifts registers — one Arabic-first platform, hosted entirely in the Kingdom.