WHISTLEBLOWER POLICY [ORGANIZATION NAME] A [STATE] Nonprofit Corporation Adopted by the Board of Directors on [Month Day, Year] =============================================================================== HOW TO USE THIS DOCUMENT - This policy lets staff, volunteers, and board members report suspected financial misconduct, fraud, or a legal violation without fear of being punished for it. The IRS Form 1023 application asks whether your organization has one, and adopting it is a basic governance step for any nonprofit or church. - Fill in every [BRACKETED] placeholder. The two that matter most are the named contact a report normally goes to, and the SECOND, independent contact a person uses when the concern involves that first person. - Approve it by a board vote, record the vote in the minutes, and give a copy to everyone it covers. A policy nobody has seen protects no one. - This is a general template, not legal advice (see the footer). =============================================================================== ------------------------------------------------------------------------------- 1. PURPOSE ------------------------------------------------------------------------------- [ORGANIZATION NAME] expects everyone who works for it or serves it to act honestly and to follow the law and the organization's own policies. This policy gives those people a safe, clear way to raise a concern when they believe that standard is being broken — and it protects them for doing so. The goal is to surface a problem early, while it is still small, and to make sure no one is discouraged from speaking up because they are afraid of what it will cost them. ------------------------------------------------------------------------------- 2. WHO IS COVERED ------------------------------------------------------------------------------- This policy covers every: - Employee of [ORGANIZATION NAME], full-time or part-time; - Volunteer, including committee members; - Officer and member of the Board of Directors; - [Contractor / vendor working on the organization's behalf — optional]. Anyone in these groups may make a report under this policy and is protected by it. ------------------------------------------------------------------------------- 3. WHAT TO REPORT ------------------------------------------------------------------------------- Report any activity you reasonably believe is improper, including but not limited to: - Theft, fraud, or embezzlement of the organization's money or property; - Falsifying or destroying financial records, contracts, or other documents; - Improper accounting, or misuse of restricted or designated funds; - A conflict of interest that was hidden rather than disclosed; - A violation of law, the organization's bylaws, or its policies; - Endangering the health or safety of any person; - Pressuring or helping someone else to do any of the above. You do not need to be certain, and you do not need proof. You need only a good-faith, reasonable belief that something is wrong. Knowingly making a false report is itself a violation of this policy — but an honest report that later turns out to be mistaken is fully protected. ------------------------------------------------------------------------------- 4. HOW AND WHOM TO REPORT TO ------------------------------------------------------------------------------- Report your concern to the Compliance Officer: Name/role: [COMPLIANCE OFFICER NAME OR ROLE — e.g. Treasurer, Board Chair] Email: [CONFIDENTIAL EMAIL — e.g. compliance@example.org] Phone/mail: [CONFIDENTIAL PHONE OR MAILING ADDRESS] You may report in writing or in person. You may report anonymously, though an anonymous report is harder to investigate because we cannot ask you follow-up questions. A CHANNEL THAT BYPASSES THE PERSON INVOLVED. If your concern is about the Compliance Officer, or about someone that person reports to, do not send it there. Send it instead to the [Chair of the Audit Committee / Board Chair / independent director]: Name/role: [SECOND, INDEPENDENT CONTACT NAME OR ROLE] Email: [SEPARATE CONFIDENTIAL EMAIL] Phone/mail: [SEPARATE CONFIDENTIAL PHONE OR MAILING ADDRESS] The point of this second route is that a report can always reach someone who is not the subject of the complaint. ------------------------------------------------------------------------------- 5. NO RETALIATION ------------------------------------------------------------------------------- No one may retaliate against a person who, in good faith, makes a report under this policy or takes part in an investigation. Retaliation includes firing, demotion, cutting pay or hours, reassignment, exclusion, harassment, or any other adverse action taken because the person spoke up. Anyone who retaliates is subject to discipline, up to and including dismissal from their position or removal from the board. A person who believes they are being retaliated against should report it the same way they would report any other violation under Section 4. ------------------------------------------------------------------------------- 6. CONFIDENTIALITY ------------------------------------------------------------------------------- Reports will be kept confidential to the extent possible. The identity of the person reporting, and the details of the report, will be shared only with those who need to know to investigate and resolve the matter — or where disclosure is required by law. The organization will not try to identify a person who reports anonymously. ------------------------------------------------------------------------------- 7. HOW REPORTS ARE INVESTIGATED ------------------------------------------------------------------------------- 1. ACKNOWLEDGE. The Compliance Officer (or the independent contact, where the report went there) acknowledges the report promptly — within [number] days where the reporter is known. 2. REVIEW. The matter is reviewed objectively. Anyone with a conflict of interest in the subject of the report steps aside and takes no part in the investigation. 3. INVESTIGATE. Facts are gathered. The investigation may involve interviews, a review of records, and where the matter is serious, outside professionals such as an accountant or attorney. 4. RESOLVE. If the concern is substantiated, the organization takes corrective action — which may include discipline, repayment, a change in controls, or referral to authorities. 5. REPORT TO THE BOARD. The Compliance Officer reports the matter and its outcome to the [Audit Committee / Board of Directors]. Reports that touch accounting, internal controls, or auditing go to the [Audit Committee / Board] directly. 6. CLOSE THE LOOP. Where the reporter is known, they are told, to the extent appropriate, that the matter was reviewed and handled. ------------------------------------------------------------------------------- 8. ROLE OF THE COMPLIANCE OFFICER AND THE BOARD / AUDIT COMMITTEE ------------------------------------------------------------------------------- The COMPLIANCE OFFICER administers this policy, receives reports, oversees or arranges their investigation, and keeps the records of each report and its outcome. [The Compliance Officer is _________ and reports to the Board.] The BOARD OF DIRECTORS, acting through its [Audit Committee, if one exists], has final oversight of this policy. It makes sure reports are handled properly, reviews any report that involves the Compliance Officer or a board member, and sees that the organization's accounting and auditing concerns are addressed independently of management. This is the same oversight role the board exercises over the annual audit and the organization's internal controls. ------------------------------------------------------------------------------- 9. NO DESTRUCTION OF RECORDS ------------------------------------------------------------------------------- No one may alter, destroy, conceal, or falsify any record, document, or object with the intent to obstruct or influence an investigation, an audit, or a legal proceeding. This applies to financial records, emails, and any other materials relevant to a report. Knowingly doing so is a serious violation of this policy and may also be a federal crime. ------------------------------------------------------------------------------- 10. ADOPTION ------------------------------------------------------------------------------- This Whistleblower Policy was adopted by the Board of Directors of [ORGANIZATION NAME] on [Month Day, Year] and remains in effect until amended or replaced by the Board. Signed: _______________________________ _______________________________ [Board Chair name] [Secretary name] Board Chair Secretary Date: __________________ Date: __________________ =============================================================================== NOTES FOR CHURCHES - This policy fits a church without changes. A church that is incorporated is a nonprofit, and the same protection that lets an employee report misuse of a charity's money lets a staff member, volunteer, or member report misuse of the congregation's offerings. - Use the names your church already uses. The "Board of Directors" may be your vestry, session, elder board, deacons, or trustees; the "Compliance Officer" may be your treasurer or business administrator. Keep the second, independent contact a different person than the first — often the [Board Chair / senior warden / moderator] — so a concern about the treasurer can still reach someone. - Tie the report-to-the-board step to whoever oversees the church's books and its annual review, so a financial concern lands with the people who already watch the money. =============================================================================== DISCLAIMER This is a general template provided for convenience, not legal advice, and it does not create an attorney-client relationship. Whistleblower protections vary by state, and some states require specific language. Before adopting this policy, have it reviewed by a qualified attorney and confirm it fits your organization's situation and your state's law. ===============================================================================