Legal & compliance centre

HLD Group

Whistleblower & speak-up

How to report suspected misconduct, fraud, or serious policy violations — the channels available to you, the legal protections that apply, and what happens after you speak up.

Last updated: 24 July 2026

Version 2.0 · Review cycle: 365 days · View all frameworks

1. Policy statement and purpose

HLD Group is committed to the highest standards of honest, ethical, and lawful conduct. We depend on people speaking up when something is wrong. A person who raises a concern in accordance with this policy is doing exactly what we ask of them, and will be protected and supported for doing so.

This policy explains what can be reported, who can report, how to report, the legal protections that apply to the person reporting, how we handle a disclosure, and what a discloser can expect from us. It is designed to give effect to our obligations under the whistleblower protection regimes described in section 4 and to meet the mandatory policy content requirements of ASIC Regulatory Guide RG 270 and Directive (EU) 2019/1937.

Retaliation against a person who makes, or is believed to have made, a disclosure is a serious breach of this policy and, in most of the jurisdictions in which we operate, a contravention of law that can attract civil and criminal liability for both the individual and the company. We treat it as gross misconduct.

This policy is available to all officers, employees, and contractors, and is published publicly so that suppliers, customers, and members of the public can use it. It is approved by the board or equivalent governing body of HLD Group and cannot be varied by any individual manager, contract, or agreement.

2. Who is protected by this policy

This policy applies broadly. You do not need to be a current employee to be protected, and you do not need to know whether you meet a particular statutory definition before you speak up. If you are unsure, report anyway and we will apply the protections.

  • Current and former officers, directors, and employees, whether permanent, fixed-term, part-time, or casual
  • Contractors, consultants, subcontractors, secondees, agency workers, interns, volunteers, and work experience participants
  • Suppliers and their employees, including former suppliers, and any person who supplies goods or services to HLD Group whether paid or unpaid
  • Associates of HLD Group, including related entities and their personnel
  • Relatives, dependants, and spouses or partners of any of the people above, and dependants of their spouse or partner
  • Job applicants and people who acquired information during a recruitment or pre-contractual negotiation process
  • Customers, users, and members of the public who become aware of reportable conduct
  • Any person who facilitates a report, is named as a witness, or is connected to a discloser and could suffer detriment as a result

Anonymous disclosers

You may make a disclosure anonymously, and you may remain anonymous throughout the assessment, the investigation, and after it concludes. You are not required to identify yourself in order to be protected. Anonymity can limit our ability to investigate effectively or to give you feedback, so we encourage you to provide a means of contact — a pseudonymous email address is sufficient — but the choice is yours and a decision to stay anonymous will never be held against you.

3. Our commitments to you

  • We will not tolerate retaliation, and we will act against anyone who retaliates
  • We will protect your identity in accordance with section 9 and the law
  • We will take every report seriously, assess it objectively, and act on what we find
  • We will keep you informed within the timeframes in section 12, so far as we lawfully can
  • We will never require you to prove your concern before you raise it — a reasonable suspicion is enough
  • We will not penalise you if your concern turns out, after investigation, to be mistaken, provided you raised it honestly
  • We will not use confidentiality agreements, employment contracts, or settlement terms to stop you from reporting to a regulator or law enforcement

HLD Group operates across several jurisdictions. The protections below apply according to where you are, where the conduct occurred, and which entity is involved. We apply the most protective available standard as our internal baseline, so that a discloser is never worse off because of which office or entity they dealt with.

Australia

  • Corporations Act 2001 (Cth) Part 9.4AAA, sections 1317AA to 1317AJ, as amended by the Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 — the primary corporate whistleblower regime, covering eligible whistleblowers, disclosable matters, eligible recipients, confidentiality, immunity, and protection from detriment
  • Section 1317AAE of the Corporations Act, which makes unauthorised disclosure of a whistleblower’s identity a criminal offence
  • Sections 1317AC and 1317AD, which prohibit detriment and give access to compensation, reinstatement, injunctions, and exemplary damages, with the burden of proof reversed onto the person alleged to have caused the detriment
  • ASIC Regulatory Guide RG 270 Whistleblower policies, which sets the mandatory content of this document
  • Taxation Administration Act 1953 (Cth) Part IVD, sections 14ZZT to 14ZZZE, for disclosures about tax affairs and misconduct
  • Fair Work Act 2009 (Cth) Part 3-1, including sections 340 and 341, protecting the exercise of workplace rights against adverse action
  • Public Interest Disclosure Act 2013 (Cth) and equivalent state and territory public interest disclosure legislation, where a disclosure concerns a Commonwealth or state public sector program we support
  • Work Health and Safety Act 2011 (Cth) and corresponding state Acts, which prohibit discriminatory or coercive conduct against a person raising a work health and safety concern
  • Criminal Code Act 1995 (Cth), Divisions 70 and 141, concerning bribery of Commonwealth and foreign public officials
  • Privacy Act 1988 (Cth) and the Australian Privacy Principles, governing how we handle personal information in a disclosure
  • Modern Slavery Act 2018 (Cth), in relation to grievance and remediation mechanisms across our operations and supply chains

United States

  • Sarbanes-Oxley Act of 2002, section 806 (18 U.S.C. § 1514A), protecting employees of issuers and their contractors who report securities fraud, and section 1107 (18 U.S.C. § 1513(e)), which makes retaliation against a person providing truthful information to law enforcement a federal crime
  • Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010, section 922 (15 U.S.C. § 78u-6), establishing the Securities and Exchange Commission whistleblower program, anti-retaliation cause of action, and monetary awards
  • SEC Rule 21F-17(a), which prohibits any action impeding a person from communicating directly with SEC staff about a possible securities law violation, including through a confidentiality agreement
  • False Claims Act (31 U.S.C. §§ 3729–3733), including the qui tam provisions and the anti-retaliation protection in section 3730(h), relevant to any work funded by United States government contracts or grants
  • 41 U.S.C. § 4712 and 10 U.S.C. § 4701, protecting employees of federal contractors, subcontractors, and grantees who disclose gross mismanagement, gross waste, abuse of authority, substantial danger to public health or safety, or a violation of law relating to a federal contract
  • Defend Trade Secrets Act of 2016, 18 U.S.C. § 1833(b), which gives immunity from trade secret liability for confidential disclosure of a trade secret to a government official or attorney solely for the purpose of reporting a suspected violation of law
  • Occupational Safety and Health Act section 11(c) and the statutes administered by OSHA under 29 CFR Part 1980, together with applicable state whistleblower statutes

European Union and EEA

  • Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law, together with the national laws transposing it, which require secure internal reporting channels, acknowledgement of a report within seven days, feedback within three months, strict confidentiality, and a prohibition on retaliation
  • Article 21(5) of that Directive, which reverses the burden of proof so that detriment suffered by a reporting person is presumed to be retaliation unless the organisation proves otherwise
  • Articles 10 and 15 of that Directive, governing external reporting to competent authorities and the conditions for protected public disclosure
  • Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 14, and 32, governing lawfulness, transparency, and security in the processing of personal data contained in a report
  • Directive (EU) 2015/849 and successors, for disclosures concerning money laundering and terrorist financing

United Kingdom

  • Public Interest Disclosure Act 1998, which inserted Part IVA into the Employment Rights Act 1996, protecting qualifying disclosures made in the public interest
  • Section 43B of the Employment Rights Act 1996, defining a qualifying disclosure, and section 43F, permitting protected disclosure to a prescribed person such as the Financial Conduct Authority, HMRC, or the Health and Safety Executive
  • Sections 47B and 103A of the Employment Rights Act 1996, giving the right not to suffer detriment and making dismissal for a protected disclosure automatically unfair, with no qualifying period and no statutory cap on compensation
  • Bribery Act 2010, in particular the section 7 adequate procedures defence, of which a functioning speak-up mechanism is an accepted component

Canada and other jurisdictions

  • Criminal Code (R.S.C., 1985, c. C-46) section 425.1, which makes employer retaliation against an employee who reports an offence a criminal offence
  • Canada Business Corporations Act and applicable provincial securities legislation whistleblower programs, including the Ontario Securities Commission program
  • Public Servants Disclosure Protection Act (S.C. 2005, c. 46), where a disclosure concerns work for a federal public sector entity
  • Local whistleblower, anti-corruption, and labour protections in any other jurisdiction in which HLD Group personnel are engaged

International standards

  • ISO 37002:2021 Whistleblowing management systems — guidelines, against which this policy is structured
  • ISO 37001:2016 Anti-bribery management systems, clause 8.9 (raising concerns)
  • ISO 37301:2021 Compliance management systems
  • United Nations Convention against Corruption, Articles 8, 13, and 33
  • OECD Guidelines for Multinational Enterprises on Responsible Business Conduct

5. What you can report

You can report any conduct you reasonably suspect is improper. You do not need proof, you do not need to be right, and you do not need to identify which law may have been broken. A reasonable suspicion, honestly held, is enough to attract the protections in this policy.

Reportable conduct includes, but is not limited to, the following. Conduct does not have to be unlawful to be reportable — conduct that represents a danger, an improper state of affairs, or a serious breach of our own standards is equally within scope.

Dishonesty and financial misconduct

  • Fraud, theft, misappropriation, or embezzlement
  • Bribery, kickbacks, secret commissions, or facilitation payments
  • Corruption, undisclosed conflicts of interest, or improper influence over a decision
  • Money laundering, terrorist financing, or sanctions evasion
  • Falsification, concealment, or destruction of financial or business records
  • Misstatement of accounts, revenue recognition irregularities, or misleading financial reporting
  • Insider trading, market manipulation, or misuse of price-sensitive information
  • Tax evasion, or the facilitation of tax evasion by another person

Legal and regulatory breaches

  • Breach of any law, regulation, licence condition, or court order
  • Breach of export control, defence trade control, or sanctions obligations
  • Breach of privacy or data protection law, including concealment of a notifiable data breach
  • Breach of anti-competitive conduct law, including cartel conduct, bid rigging, or market sharing
  • Breach of a government contract requirement, including gross mismanagement or gross waste of public funds
  • Deliberate provision of false or misleading information to a regulator, auditor, customer, or investor
  • Obstruction of an audit, investigation, or regulatory inquiry

Harm to people

  • Conduct that represents a danger to the health or safety of any person
  • Bullying, harassment, sexual harassment, or workplace violence
  • Discrimination or victimisation on the basis of a protected attribute
  • Modern slavery, forced labour, child labour, or human trafficking in our operations or supply chain
  • Conduct that endangers the public or the environment
  • Failure to act on a known and material safety risk

Information security, technology, and integrity

  • Serious breach of our information security, access control, or acceptable use policies
  • Deliberate concealment of a security incident, vulnerability, or compromise
  • Misuse of customer, defence, or classified data, or unauthorised access to it
  • Deployment of technology known to be unsafe, unlawful, or materially misrepresented to a customer
  • Misrepresentation of a system’s capability, security posture, accreditation, or compliance status
  • Circumvention of change control, audit logging, or segregation of duties

Conduct that undermines this policy

  • Retaliation, or the threat of retaliation, against a person who raises a concern
  • Pressure on a person not to make, or to withdraw, a disclosure
  • Unauthorised disclosure of the identity of a discloser
  • Interference with, or attempted influence over, an investigation under this policy
  • Deliberate failure by a manager to escalate a concern raised with them

6. Matters handled under other processes

Some concerns are better and faster resolved through a different process. Directing you elsewhere is not a rejection of your concern — it is a route to the people equipped to fix it.

Under Australian law, a personal work-related grievance is generally not a protected disclosure under the Corporations Act unless it also concerns detriment for making a disclosure, involves a breach of the whistleblower provisions, or has significant implications for HLD Group beyond your own employment. A personal work-related grievance is a grievance about your own employment that has implications for you personally — for example, a decision about your role, your pay, a transfer, a promotion, a performance process, or an interpersonal conflict with a colleague.

These matters should be raised through the grievance, performance, or complaints processes, or with People and Culture. Importantly, this does not apply if the conduct involves bullying, harassment, discrimination, or a safety risk of a kind listed in section 5 — those are reportable under this policy, and where a grievance and a reportable matter are mixed together we will treat the reportable part under this policy rather than send the whole matter away.

  • Customer service complaints, which are handled under our complaints handling procedure
  • Security vulnerabilities in our products, which are handled under our responsible disclosure policy
  • Privacy requests and privacy complaints, which are handled under our privacy policy
  • Individual performance, pay, leave, or rostering decisions, which are handled by People and Culture
  • Routine policy questions or requests for guidance, which should go to the relevant policy owner

7. How to make a report

You may use any of the channels below. You are not required to report internally first, and you do not lose any protection by going straight to a regulator or law enforcement. Choose whichever channel you are most comfortable with.

Internal channels

  • The Whistleblower Protection Officer at compliance@hldgroup.org — the primary and recommended channel, monitored by our compliance function independently of line management
  • Any director or officer of HLD Group or of a related body corporate
  • A senior manager, being a person who makes or participates in decisions affecting a substantial part of the business
  • The Chief Information Security Officer, for matters involving security, privacy, or data
  • The People and Culture lead, for matters involving conduct toward people
  • Our internal or external auditor, or a member of an audit team
  • An actuary of HLD Group or of a related body corporate, where one is appointed

If your concern involves the people who would normally receive it

If your concern involves a director, an officer, the Whistleblower Protection Officer, or anyone in the internal reporting line, do not use that channel. Report to another director, to the chair of the board or equivalent governing body, or directly to an external channel under this section. We will route the matter so that no person investigates or decides on a report concerning themselves, their direct reports, or a matter in which they have an interest.

Anonymous and confidential reporting

Reports may be submitted anonymously by email from an address that does not identify you, or by post marked to the Whistleblower Protection Officer. Where we operate an independent third-party speak-up service, its details are published on our internal channels and are available on request. You may also ask to be contacted only through a pseudonym or a nominated intermediary.

Disclosure to a legal practitioner

You may disclose the matter to a legal practitioner for the purpose of obtaining legal advice or representation about the whistleblower protection provisions. That disclosure is protected even if it later turns out the matter was not a disclosable matter, and we will not treat obtaining legal advice as a breach of confidentiality or of any agreement with us.

External and regulatory channels

You may report directly to a regulator or law enforcement body at any time. Where the relevant regime requires it, external reporting attracts the same statutory protections as internal reporting. Depending on the subject matter and jurisdiction, the appropriate body may include:

  • Australian Securities and Investments Commission, the Australian Prudential Regulation Authority, or a Commonwealth authority prescribed for the purpose
  • Australian Taxation Office, for disclosures about tax affairs
  • Australian Federal Police or a state police service, for suspected criminal conduct
  • Office of the Australian Information Commissioner, for privacy and data breach matters
  • Fair Work Ombudsman, Safe Work Australia, or the relevant state work health and safety regulator
  • United States Securities and Exchange Commission, Department of Justice, Office of Inspector General, or OSHA
  • The competent national authority designated under Directive (EU) 2019/1937 in the relevant member state
  • A prescribed person under section 43F of the Employment Rights Act 1996 in the United Kingdom

Public interest and emergency disclosures

Australian law allows a discloser, in defined circumstances, to make a protected public interest disclosure to a member of parliament or a journalist where at least ninety days have passed since a disclosure to a regulator, the discloser reasonably believes no action is being taken, and written notice has been given. It also allows an emergency disclosure where there are reasonable grounds to believe the information concerns a substantial and imminent danger to health, safety, or the environment.

These routes carry technical conditions, and the protections can be lost if the conditions are not met. We strongly encourage you to obtain independent legal advice before making such a disclosure. Seeking that advice is itself protected, and we will not regard it as an adverse act against HLD Group.

8. What to include in a report

Give us as much as you can, but do not delay a report because you think you lack detail. A partial report made early is more useful than a complete report made late.

  • What happened, in your own words, and why you are concerned
  • Who was involved, and who else may know
  • When and where it occurred, and whether it is ongoing
  • Any documents, messages, records, or system references that support the concern
  • Whether you have raised it with anyone else, internally or externally
  • Whether you have any concern about your own safety, position, or exposure
  • How you would like to be contacted, if you wish to be contacted

Please do not

  • Investigate the matter yourself, interview others, or confront the person involved
  • Access systems or records you are not authorised to access in order to gather evidence
  • Remove, copy, or forward customer data, classified material, or export-controlled information outside authorised systems
  • Alter, delete, or conceal records
  • Discuss the concern with colleagues who do not need to know, which can compromise both the investigation and your own confidentiality

9. Confidentiality and protection of your identity

Your identity, and any information likely to reveal your identity, is treated as strictly confidential. In Australia, unauthorised disclosure of the identity of a whistleblower is a criminal offence under section 1317AAE of the Corporations Act, and equivalent duties apply under Directive (EU) 2019/1937 and other regimes.

We will not disclose your identity, or information from which it could be inferred, without your consent, except where the law permits or requires it.

Permitted disclosures of identity

  • To the Australian Securities and Investments Commission, the Australian Prudential Regulation Authority, the Australian Taxation Office, or the Australian Federal Police
  • To a legal practitioner for the purpose of obtaining advice about the whistleblower provisions
  • To another regulator, court, or tribunal where compelled by law
  • To any person, where you have given your express consent

How we protect your identity in practice

  • Information likely to reveal your identity is redacted from investigation material wherever possible
  • Your identity is disclosed within HLD Group only to the minimum number of people strictly necessary, and only where necessary to investigate
  • Where investigation requires information that could identify you, we will discuss it with you first and seek your consent
  • Reports and related records are stored in access-controlled systems separate from personnel files, accessible only to authorised roles
  • Communications about a disclosure use secure channels and do not use your name in subject lines or shared mailboxes
  • People involved in handling a disclosure are bound by a specific confidentiality undertaking, breach of which is a disciplinary matter
  • Where a person who is investigated may be able to infer your identity, we take additional steps to reduce the risk of detriment, including monitoring under section 11

If confidentiality is breached

If you believe your identity has been disclosed without authorisation, tell the Whistleblower Protection Officer at compliance@hldgroup.org immediately, or escalate to a director. We will treat it as a serious incident, investigate it as a matter under section 5, take protective steps, and where a criminal offence may have occurred we will report it. You may also lodge a complaint directly with the relevant regulator.

10. Protection from detriment and retaliation

It is unlawful, and a serious breach of this policy, to cause or threaten detriment to a person because they have made, may make, propose to make, or are suspected of having made a disclosure. This protection extends to people who assist an investigation, act as witnesses, or are related to or associated with a discloser.

Detriment is defined broadly and is not limited to formal employment action. It includes any conduct that disadvantages a person, whether or not the person causing it intended harm.

What counts as detriment

  • Dismissal, termination of engagement, non-renewal of a contract, or forced resignation
  • Demotion, denial of promotion, or loss of duties, seniority, or opportunity
  • Alteration of position, hours, location, or reporting line to the person’s disadvantage
  • Disciplinary action, performance management, or a negative review initiated or influenced by the disclosure
  • Withholding of training, projects, bonuses, references, or career development
  • Harassment, intimidation, ostracism, exclusion, or reputational harm including rumour and innuendo
  • Threats, coercion, or pressure to withdraw or alter a disclosure
  • Blacklisting, or any attempt to harm the person’s future employment or business prospects
  • Legal or contractual action brought against the discloser because of the disclosure
  • Any other conduct causing psychological, financial, or professional harm connected to the disclosure

Burden of proof

Under the Corporations Act and under Article 21(5) of Directive (EU) 2019/1937, where a discloser establishes that they made a disclosure and suffered detriment, the detriment is presumed to be because of the disclosure and the burden falls on the person or organisation alleged to have caused it to prove otherwise. HLD Group applies this presumption internally as well. If you suffer detriment after raising a concern, you do not have to prove why.

Remedies available to a discloser

  • Compensation for loss, damage, or injury, including in some jurisdictions uncapped compensation
  • Reinstatement, or restoration of a position, duties, or entitlements
  • Injunctions, apologies, and orders to prevent or stop detrimental conduct
  • Exemplary damages against a person who caused detriment
  • Civil penalties and, for identity breaches and some retaliation, criminal penalties against the individual and the company
  • Access to statutory whistleblower award programs, where one applies to the disclosure

Consequences within HLD Group

Any officer, employee, or contractor found to have caused or threatened detriment will face disciplinary action up to and including summary dismissal or termination of engagement, referral to the relevant regulator or police, and personal liability at law. This applies equally to a manager who fails to act on a report of retaliation of which they were aware.

11. Additional safeguards and support

  • A risk assessment for each disclosure identifying the specific detriment risks to the discloser and any witnesses
  • Where warranted, protective measures such as adjusting reporting lines, restricting access, or relocating work arrangements — always with the discloser’s consent and never in a way that itself disadvantages them
  • Ongoing welfare check-ins with the discloser during and after the investigation, at a frequency the discloser chooses
  • Access to confidential counselling and employee assistance support, at our cost
  • Reimbursement of reasonable costs of obtaining independent legal advice about the whistleblower protections
  • Independent review by a person outside the reporting line where the discloser requests it
  • Monitoring of the discloser’s treatment, engagement status, and performance record for a defined period after closure, to detect detriment that surfaces later

12. How we handle a report

Every disclosure is recorded, assessed, and closed with a documented outcome. Investigations are conducted fairly, objectively, confidentially, and by people independent of the matter and of any person involved in it.

Timeframes

  • Acknowledgement of receipt within seven calendar days, unless the report is anonymous and no contact channel has been provided
  • Initial assessment of whether the matter qualifies under this policy, and whether an investigation is required, within fourteen calendar days
  • Immediate escalation and containment where a report indicates a risk to safety, a live criminal act, a data breach, or destruction of evidence
  • Feedback to the discloser on the progress and outcome of the report within three months of acknowledgement, and at reasonable intervals thereafter for longer investigations
  • Notification of closure, including the outcome at a level of detail that does not compromise confidentiality or legal obligations

Investigation principles

  • Independence — no person investigates a matter in which they are involved, implicated, or have an interest, and external investigators are appointed where independence cannot be assured internally
  • Objectivity — evidence is gathered and weighed without assumption about the outcome, and both supporting and contradicting evidence is recorded
  • Confidentiality — information is shared strictly on a need-to-know basis, including with senior leadership
  • Timeliness — investigations proceed as quickly as thoroughness allows, with delays explained to the discloser
  • Documentation — findings, evidence, reasoning, and decisions are recorded so the process can withstand external scrutiny
  • Legal privilege — external legal advice is obtained where the matter is complex, involves potential criminal conduct, or may lead to litigation
  • Preservation — relevant records and systems are placed under a preservation hold as soon as a disclosure is received

What we can and cannot tell you

We will keep you informed so far as we lawfully and practically can. There are limits: we may not be able to share details that would identify others, compromise an ongoing investigation, breach privacy or confidentiality obligations owed to another person, or prejudice a regulatory or criminal process. Where we cannot tell you something, we will tell you that, and why, rather than leave you without a response.

13. Fair treatment of people mentioned in a disclosure

A disclosure is an allegation, not a finding. People named in a disclosure are treated fairly and are presumed to have done nothing wrong unless and until an investigation finds otherwise. Protecting the discloser and treating the subject of an allegation fairly are not in conflict, and we do both.

  • The subject of an allegation is advised of the substance of the allegations at an appropriate point in the process, unless doing so would prejudice the investigation, risk evidence destruction, or endanger a person
  • They have a reasonable opportunity to respond to the allegations before any finding is made
  • Their response is recorded and considered in the findings
  • They may be accompanied by a support person at any interview
  • They are told the outcome as it affects them, and of any right of review
  • Their identity and the existence of the allegation are kept confidential, and unsubstantiated allegations do not appear on their record
  • They are offered welfare support, which can be as necessary for them as for the discloser
  • They are not to be told the identity of the discloser, and are prohibited from attempting to identify them

14. Outcomes and remediation

Where an investigation substantiates a concern, we act. Fixing the underlying problem matters as much as dealing with the individuals involved, and we look for the systemic cause in every substantiated case.

  • Disciplinary action, up to and including summary dismissal or termination of a contract
  • Recovery of losses, and correction of financial records or public statements
  • Referral to a regulator, law enforcement, or a professional body, and self-reporting where a legal obligation to notify exists
  • Notification of affected customers, individuals, or authorities where a breach requires it
  • Changes to controls, systems, training, or policies to prevent recurrence
  • Termination or remediation of a supplier or partner relationship
  • Publication of de-identified lessons learned internally, so the organisation improves from the report

If a report is not substantiated

A report that is not substantiated is not a failure and does not reflect on the person who made it. Where we cannot substantiate a concern, we record the assessment, tell the discloser, and all protections under this policy continue to apply in full. Many reports that cannot be substantiated still reveal control weaknesses worth fixing, and we act on those.

If you are unhappy with the outcome

You may request an internal review by a person independent of the original investigation, by writing to compliance@hldgroup.org or to any director. You may also, at any time and regardless of our findings, take the matter to a regulator or law enforcement body listed in section 7. Doing so remains fully protected and we will not treat it as a breach of any obligation to us.

15. Reports made in bad faith

The protections in this policy apply to anyone who raises a concern on the basis of a reasonable suspicion, honestly held. They apply even if the concern turns out to be mistaken, and even if the discloser was themselves involved in the conduct reported.

They do not extend to a person who knowingly makes a false report, fabricates evidence, or uses this policy to harass another person or to frustrate a legitimate performance or disciplinary process. Knowingly false reporting is a disciplinary matter and may be a criminal offence.

We set this bar deliberately high. A person will only be treated as having acted in bad faith where it is established that they knew the report was false at the time they made it. A concern that is mistaken, incomplete, poorly expressed, or based on a misunderstanding is not a bad faith report, and being wrong is never punished under this policy. If you are worried about getting it wrong, report anyway.

16. Roles and responsibilities

Board or governing body

  • Approves this policy and oversees its operation
  • Receives regular reporting on disclosures, themes, and outcomes
  • Is informed directly of any material disclosure and of any disclosure concerning an officer
  • Ensures adequate resourcing and independence of the whistleblower function

Whistleblower Protection Officer

  • Is the primary contact for disclosures and the custodian of this policy
  • Safeguards the identity and welfare of disclosers, and conducts the detriment risk assessment
  • Determines whether a matter qualifies and assigns an independent investigator
  • Maintains the confidential disclosure register and reports to the board
  • Operates independently of line management in respect of any disclosure

Managers and officers

  • Must escalate any concern raised with them to the Whistleblower Protection Officer, promptly and confidentially
  • Must not investigate a disclosure themselves, or attempt to identify an anonymous discloser
  • Must not discourage, delay, or filter a report, and must not require a person to report to them first
  • Must protect the confidentiality of the discloser and act against any sign of retaliation in their team

All personnel

  • Are expected to report conduct of the kind described in section 5
  • Must cooperate honestly with an investigation, and must not destroy or alter records
  • Must maintain confidentiality about a disclosure they become aware of
  • Must never retaliate against, or attempt to identify, a discloser

17. Records, privacy, and data protection

  • Disclosures are recorded in a confidential register held separately from personnel records, with access restricted to authorised roles and all access logged
  • Personal information in a disclosure is processed only for the purpose of assessing, investigating, and resolving the matter, and for meeting legal obligations
  • Records are retained for a minimum of seven years from closure, or longer where litigation, regulatory action, or a legal hold requires it, and are then securely destroyed
  • Subject access, correction, and other data subject rights are honoured to the extent they do not reveal the identity of a discloser or prejudice an investigation, consistent with applicable privacy law
  • Cross-border transfer of disclosure records is limited to what is necessary and is subject to appropriate safeguards
  • Statistical and de-identified reporting on disclosure volumes, categories, and outcomes is provided to the board and may be published in our transparency reporting

18. No contracting out of your rights

Nothing in any employment contract, contractor agreement, confidentiality or non-disclosure agreement, settlement agreement, deed of release, or company policy operates to prevent or discourage you from making a protected disclosure to a regulator, law enforcement body, or legal practitioner. Any term purporting to do so is void to that extent and will not be enforced by HLD Group.

This includes, expressly, that no confidentiality obligation owed to us restricts communication with the Securities and Exchange Commission or any other regulator about a possible violation of law, consistent with SEC Rule 21F-17(a), and that no such obligation requires you to notify us before or after doing so, or to seek our consent.

Under 18 U.S.C. § 1833(b), you may not be held criminally or civilly liable under any federal or state trade secret law for disclosing a trade secret in confidence to a government official or to an attorney solely for the purpose of reporting or investigating a suspected violation of law, or in a document filed under seal in a legal proceeding.

You do not require our permission to make a disclosure, and you are not required to tell us that you have made one.

19. Availability, training, and awareness

  • This policy is published publicly and is made available to all officers, employees, and contractors at induction and on request
  • All personnel complete speak-up training at induction and refresher training annually
  • Managers and officers receive additional training on receiving a disclosure, confidentiality obligations, and recognising and preventing retaliation
  • Investigators and the Whistleblower Protection Officer receive role-specific training on investigation practice, procedural fairness, and the statutory protections
  • The policy is provided to suppliers and partners as part of onboarding, and speak-up rights are referenced in our supplier code
  • Reporting channels are displayed on internal channels and in this public policy so that the route to report is never unclear

20. Monitoring and review

  • This policy is reviewed at least annually, and immediately following a material incident, a regulatory change, or a change in our corporate structure
  • The effectiveness of the speak-up framework is assessed each cycle, including disclosure volumes, time to acknowledgement and feedback, substantiation rates, and any reported detriment
  • A low volume of reports is treated as a warning sign about trust in the channel, not as evidence that nothing is wrong
  • Findings from investigations are analysed for systemic and cultural causes and reported to the board
  • Version history is maintained in the compliance repository, and material changes are communicated to all personnel

21. Definitions

  • Discloser — a person who makes, or is believed to have made, a report under this policy, also referred to as a whistleblower or reporting person
  • Eligible whistleblower — a person within the categories protected by the applicable statute, which this policy extends to everyone listed in section 2 regardless of statutory status
  • Eligible recipient — a person to whom a protected disclosure may be made under the applicable statute, including those listed in section 7
  • Disclosable matter — information giving rise to a reasonable suspicion of misconduct or an improper state of affairs, as described in section 5
  • Reasonable suspicion — a suspicion an ordinary person in the same position could hold on the information available, which requires no proof and no legal analysis
  • Detriment — any conduct disadvantaging a person because of a disclosure, as described in section 10
  • Personal work-related grievance — a grievance about a person’s own employment with implications personal to them, as described in section 6
  • Whistleblower Protection Officer — the officer responsible for receiving disclosures, safeguarding disclosers, and administering this policy
  • Emergency disclosure — a disclosure permitted where there are reasonable grounds to believe the information concerns a substantial and imminent danger to health, safety, or the environment
  • Public interest disclosure — a disclosure to a member of parliament or a journalist permitted under the statutory conditions described in section 7

For contractual attestations or audit packs, contact security@hldgroup.org.