For companies listed on the Saudi Exchange, whistleblowing stopped being optional the moment governance regulations made audit committees accountable for how irregularities are reported and handled. This guide sets out what listed-company compliance teams should require from their whistleblowing system.
The governance baseline for listed companies
The CMA’s corporate-governance framework assigns audit committees responsibility for internal control effectiveness — explicitly including arrangements that enable employees to report irregularities confidentially, and ensuring those reports receive independent, fair follow-up. In practice this means a listed company must be able to show: a channel, a policy, an investigation process, and records proving all three operate.
What the audit committee must be able to evidence
Four artefacts satisfy most board and external-audit inquiries: 1) the approved whistleblowing policy with review dates; 2) programme statistics — report volumes, categories, channel mix, SLA performance, outcomes; 3) case records demonstrating independence, segregation of duties and conflict recusal; and 4) an immutable audit trail showing that records were not altered after the fact. Committee-ready dashboards and exportable evidence packs are what turn a quarterly scramble into a ten-minute agenda item.
Independence and senior-management cases
The hardest test of a listed company’s programme is a report naming senior management. The system must support routing that bypasses implicated executives, committee-only visibility, and external-investigator access where needed — with all of it logged. If your current tool cannot guarantee an implicated CFO never sees the case, you do not yet meet the spirit of the framework.
Practical requirements checklist
For RFPs, listed companies typically require: bilingual (Arabic/English) reporter experience; anonymous reporting with sealed follow-up dialogue; configurable taxonomy and SLAs; segregation of duties and auto-recusal; committee dashboards and regulator-ready exports; immutable, time-stamped audit logs; KSA data residency under the PDPL; and SSO for case teams only — never for reporters. Raqeeb ships each of these as standard.
- CMA governance rules make audit committees accountable for irregularity reporting arrangements.
- Keep four evidence artefacts ready: policy, statistics, case records, immutable audit trail.
- Senior-management cases are the real test — bypass routing and committee-only visibility are mandatory.
- Put KSA residency, bilingual UX and auto-recusal in every RFP.
Frequently asked questions
Are listed companies in Saudi Arabia required to have a whistleblowing channel?
Governance regulations require arrangements enabling confidential reporting of irregularities with independent follow-up, overseen by the audit committee. A formal channel and policy are the accepted way to meet this.
What should the audit committee see each quarter?
Volumes and trends by category and channel, SLA performance, aging of open cases, substantiation rates and outcomes, plus any senior-management or high-severity cases — with drill-down available on request.
How do external auditors test the whistleblowing programme?
Typically: policy review, walkthrough of a sample case from intake to closure, verification of segregation of duties and recusal, and inspection of the audit trail’s integrity. An append-only, time-stamped log answers the hardest of these by design.
Whistleblowing, case management, conflict-of-interest and gifts registers — one Arabic-first platform, hosted entirely in the Kingdom.