Criterion: Protection of Identity and Non-Retaliation
Requirements for whistleblower protection and non-retaliation policies
Full Description
D6. Protection of Identity and Non-Retaliation
Code 7.0
Programs that ensure the confidentiality, anonymity and protection of supplier and employee whistleblowers are to be maintained unless prohibited by law. Participants should have a communicated process for their personnel to be able to raise any concerns without fear of retaliation.
Elements to Demonstrate Compliance to RBA Code
1. Policy
Ensure adequate and effective policy and procedures ensuring protection of identity and non-retaliation are in place, including the following elements:
- a. Safeguards are in place to prevent reduced protection of identity and retaliation.
- b. Monitoring procedures related to protection of identity and retaliation are in place.
- c. Adequate and effective policy and procedures to ensure protection of whistleblowers and/or users of the grievance mechanism(s) (internal and external).
2. Procedures & Practices
Procedures & Practices are in place such that:
- a. The gathering, follow-up, and investigation of reports of ethical or legal misconduct are done while protecting the identity of the reporting source.
- b. There are clear communications channels so that workers are comfortable reporting violations or issues of concern without fear of reprisal.
- c. There is adherence to policies that prohibit retaliation for worker reporting.
3. Controls & Monitoring
Controls & Monitoring should include:
- a. Investigation and sanctions findings are listed in D1.1.
- b. Findings on grievance mechanisms (internal and external) are listed in E8.1.
- c. Management can demonstrate how retaliation is prevented and monitored.
- d. Workers confirm management has assured them of non-retaliation and that they are unaware of any retaliation case.
4. Rating
- Major: No detailed and understandable policy and procedures implemented.
- Minor: Partial policy or procedures or implementation.
Profiles using this criterion
RBA Assessment Program
- VAP Full Assessment | 7.0.0
Conformity Alignment
Priority
Pass: No
Definition: "Critical non-conformance requiring immediate action"
Remediation: 30 days
Major
Pass: No
Definition: "Significant non-conformance requiring corrective action"
Remediation: 90 days
Minor
Pass: Yes
Definition: "Non-conformance with limited impact"
Conditions: Corrective action plan required
Remediation: 180 days
Opportunity
Pass: Yes
Definition: "Opportunity for improvement identified"
Conformance
Pass: Yes
Definition: "Full conformance with criterion requirements"
Related Criterion
VAP: Business Integrity and No Improper Advantage
Relationship: Related
Reporting ethical violations without retaliation
VAP: Privacy
Relationship: Related
Protection of personal identity information
VAP: Ethics Management System
Relationship: Parent
Management system for ethics practices
VAP: Labor Management System
Relationship: Related
Worker grievance mechanisms
Change Log
1.0.0 (2021-01-01)
Changed
- Initial historical baseline — Protection of Identity and Non-Retaliation (RBA Code of Conduct 7.0): Earliest imported version (provision D6). Programs ensuring confidentiality, anonymity and protection of supplier and employee whistleblowers, and a communicated process for personnel to raise concerns without fear of retaliation. Rated on documentary policy/procedure completeness only — Priority was Not Applicable; the worst rating was Major ('No detailed and understandable policy and procedures implemented'), with Minor for partial policy/procedures/implementation. No evidence-based confirmed-retaliation or identity-breach Priority trigger yet existed.