Policy

Whistleblower Policy

Statement of Commitment

M3 Integrated Services Pty Ltd is committed to maintaining a workplace culture grounded in integrity, transparency, and ethical behaviour. This policy establishes a structured and legally compliant mechanism for individuals to report suspected wrongdoing, misconduct, or improper conduct.

The intent is not only to enable reporting, but to ensure that individuals feel safe, supported, and protected when doing so. The organisation recognises that early reporting is critical to identifying risks, preventing harm, and maintaining trust across our workforce, clients, and stakeholders.

Scope

This policy applies broadly to any person connected to M3is operations, including employees, contractors, suppliers, and relevant associated parties.

It is specifically designed for reporting serious or systemic matters, including fraud, corruption, safety risks, and significant breaches of policy or law.

This policy does not replace:

Routine workplace grievance processes (refer to Grievance Policy)

Routine workplace grievance processes (refer to Grievance Policy)

Routine workplace grievance processes (refer to Grievance Policy)

Employee discipline processes (refer Conduct & Disciplinary Policy)

Employee discipline processes (refer Conduct & Disciplinary Policy)

Employee discipline processes (refer Conduct & Disciplinary Policy)

Confidentiality and privacy obligations

Confidentiality and privacy obligations

Confidentiality and privacy obligations

Definitions

Whistleblower: A person who reports suspected misconduct with reasonable grounds.

Whistleblower: A person who reports suspected misconduct with reasonable grounds.

Whistleblower: A person who reports suspected misconduct with reasonable grounds.

Disclosable Matter: Conduct that represents serious wrongdoing or an improper state of affairs under applicable legislation.

Disclosable Matter: Conduct that represents serious wrongdoing or an improper state of affairs under applicable legislation.

Disclosable Matter: Conduct that represents serious wrongdoing or an improper state of affairs under applicable legislation.

Authorised Recipient: A designated individual permitted to receive disclosures under this policy.

Authorised Recipient: A designated individual permitted to receive disclosures under this policy.

Authorised Recipient: A designated individual permitted to receive disclosures under this policy.

Detrimental Conduct: Any action that causes harm, disadvantage, or retaliation as a result of a disclosure.

Detrimental Conduct: Any action that causes harm, disadvantage, or retaliation as a result of a disclosure.

Detrimental Conduct: Any action that causes harm, disadvantage, or retaliation as a result of a disclosure.

Policy Statement

M3is actively encourages individuals to raise concerns where they suspect misconduct or unethical behaviour.

All disclosures will be:

Managed confidentially and respectfully

Managed confidentially and respectfully

Managed confidentially and respectfully

Assessed objectively and without bias

Assessed objectively and without bias

Assessed objectively and without bias

Investigated where appropriate in a timely and professional manner

Investigated where appropriate in a timely and professional manner

Investigated where appropriate in a timely and professional manner

Handled in compliance with legislative obligations

Handled in compliance with legislative obligations

Handled in compliance with legislative obligations

The organisation has zero tolerance for retaliation. Any person who attempts to victimise or disadvantage a whistleblower will face serious disciplinary action, up to and including termination.

Importantly, individuals who make a report in good faith will be protected, even if the allegation is ultimately not substantiated.

Roles & Responsibilities

Role
Responsibilities
Evidence / Records
Workers
Raise concerns honestly and in good faith
Disclosure submission
Managers
Recognise and escalate disclosures appropriately
Escalation records
Authorised Recipients
Receive, protect, and triage disclosures
Disclosure register
HR / Compliance
Manage investigation and protections
Investigation file
Executives
Oversight, governance, and culture leadership
Board reporting
Role
Responsibilities
Evidence / Records
Workers
Raise concerns honestly and in good faith
Disclosure submission
Managers
Recognise and escalate disclosures appropriately
Escalation records
Authorised Recipients
Receive, protect, and triage disclosures
Disclosure register
HR / Compliance
Manage investigation and protections
Investigation file
Executives
Oversight, governance, and culture leadership
Board reporting

Requirements / Controls

To ensure this policy operates effectively, M3is will:

Maintain multiple reporting options, including verbal, written, and anonymous disclosures

Maintain multiple reporting options, including verbal, written, and anonymous disclosures

Maintain multiple reporting options, including verbal, written, and anonymous disclosures

Clearly identify and train authorised recipients

Clearly identify and train authorised recipients

Clearly identify and train authorised recipients

Ensure strict confidentiality and identity protection controls

Ensure strict confidentiality and identity protection controls

Ensure strict confidentiality and identity protection controls

Assess all disclosures promptly to determine appropriate action

Assess all disclosures promptly to determine appropriate action

Assess all disclosures promptly to determine appropriate action

Conduct investigations that are fair, impartial, and evidence-based

Conduct investigations that are fair, impartial, and evidence-based

Conduct investigations that are fair, impartial, and evidence-based

Document all decisions and outcomes

Document all decisions and outcomes

Document all decisions and outcomes

Monitor for and act on any signs of retaliation

Monitor for and act on any signs of retaliation

Monitor for and act on any signs of retaliation

Escalate serious matters to regulators where required

Escalate serious matters to regulators where required

Escalate serious matters to regulators where required

Training & Competency

All personnel will receive training appropriate to their role, including:

Awareness of whistleblower protections and reporting pathways

Awareness of whistleblower protections and reporting pathways

Awareness of whistleblower protections and reporting pathways

Manager responsibilities for escalating concerns

Manager responsibilities for escalating concerns

Manager responsibilities for escalating concerns

Specialist training for those responsible for investigations

Specialist training for those responsible for investigations

Specialist training for those responsible for investigations

This ensures consistency across sites and supports a strong “speak up” culture.

Records & Retention

Record
Owner
Storage
Retention
Audit Use
Disclosure Register
Compliance
Secure system
7 years
Audit trail
Investigation Reports
HR / Compliance
Restricted access
7 years
Evidence
Incident Reports
Operations
Ops Savvy
5+ years
Trend analysis
Record
Owner
Storage
Retention
Audit Use
Disclosure Register
Compliance
Secure system
7 years
Audit trail
Investigation Reports
HR / Compliance
Restricted access
7 years
Evidence
Incident Reports
Operations
Ops Savvy
5+ years
Trend analysis

Records will be managed in line with privacy obligations.

Non-Compliance & Escalation

Any breach of this policy may result in disciplinary action, including termination.

Serious breaches may also be referred to external authorities.

Review Cycle & Continuous Improvement

Any breach of this policy may result in disciplinary action, including termination.

Serious breaches may also be referred to external authorities.

Review Cycle & Continuous Improvement

Annually

Annually

Annually

Following any major incident

Following any major incident

After internal audits or regulatory changes

After internal audits or regulatory changes

After internal audits or regulatory changes

Continuous improvement ensures ongoing compliance and operational effectiveness.

Compliance & Legislative Alignment

Record
Owner
Storage
Corporations Act 2001 (Cth)
Whistleblower protections
Confidential reporting channels, identity protection
Privacy Act 1988 (Cth)
Protect personal information
Restricted access to records
Fair Work Act 2009
Preventing adverse action
Anti-retaliation controls
WHS Legislation (all states)
Manage risks and report conduct
Reporting safety breaches
Record
Owner
Storage
Corporations Act 2001 (Cth)
Whistleblower protections
Confidential reporting channels, identity protection
Privacy Act 1988 (Cth)
Protect personal information
Restricted access to records
Fair Work Act 2009
Preventing adverse action
Anti-retaliation controls
WHS Legislation (all states)
Manage risks and report conduct
Reporting safety breaches

Procedure

To provide a clear and consistent process for managing disclosures from receipt through to closure.

Workflow

Step 1 – Making a Disclosure

A worker may raise a concern verbally, in writing, or anonymously. They are encouraged (but not required) to provide detailed information such as dates, individuals involved, and supporting evidence.

Step 2 – Receipt and Initial Assessment

Once received, the authorised recipient will assess whether the matter qualifies as a disclosable matter under this policy.

Where it does not, it may be redirected to the appropriate process (e.g. grievance).

Step 3 – Protection Measures

Immediate steps are taken to protect the whistleblower, including:

• Confidential handling of identity

• Limiting access to information

• Monitoring any risk of retaliation

Step 4 – Investigation

If required, an investigation will be conducted in an impartial and structured manner.

This includes gathering evidence, interviewing relevant individuals, and assessing findings objectively.

Step 5 – Outcome & Action

Following investigation, appropriate actions are taken, which may include disciplinary action, process improvements, or external escalation.

Step 6 – Closure & Recordkeeping

The matter is formally closed with documentation retained securely for audit and compliance purposes.