Corporations Act Part 9.4AAA: Whistleblower Policy Requirements for Australian Companies
Part 9.4AAA of the Corporations Act 2001 requires certain Australian entities - public companies, large proprietary companies, and corporate trustees of registrable superannuation entities - to have a whistleblower policy in place, and it isn't satisfied by any document that happens to use the word "whistleblower." The Act specifies content requirements, and a policy missing them isn't compliant regardless of intent.
What has to be in the policy
Broadly, a compliant policy needs to cover: the protections available to eligible whistleblowers under the Act, how and to whom a disclosure can be made (including to a company officer, senior manager, auditor, actuary, or a regulator like ASIC or APRA directly), how the company will support whistleblowers and protect them from detriment, how investigations will be conducted, how the company will ensure fair treatment of any employee mentioned in a disclosure, how the policy is made available to officers and employees, and any other matters prescribed by regulation.
This is a genuinely specific list - not "have a hotline and a general anti-retaliation statement." Companies that adapt a generic global whistleblowing policy without checking it against Part 9.4AAA specifically are one of the more common gaps we hear about from Australian compliance officers evaluating case management vendors.
Who counts as an "eligible whistleblower" - and why it's broader than employees
The Act's protections extend beyond current employees: former employees, officers, contractors, suppliers, associates, and in some cases their relatives, can qualify as eligible whistleblowers if they make a disclosure that meets the Act's requirements. A reporting system built only around "employee submits a report while logged into a company system" misses a meaningful slice of who's actually entitled to protection under the Act.
This is part of why an anonymous, no-login reporting path matters structurally, not just as a nice-to-have UX choice - a former contractor or supplier representative reporting misconduct has no company account to log into in the first place. If a system architecturally requires authentication to file a report, it's quietly excluding a category of people the law is written to protect.
What software can and can't do about this requirement
A case management platform doesn't write your whistleblower policy for you, and any vendor implying their software alone makes you Part 9.4AAA compliant is overstating what a reporting tool does. What software can do: provide the accessible, no-login reporting mechanism the policy needs to actually describe accurately, maintain the documented investigation trail the policy commits to following, and support the confidentiality and anti-detriment protections in practice - encrypted identity storage, restricted access to identifying information, and an audit trail of who accessed what and why.
Where Rectifia's jurisdiction configuration fits
When AU is selected in a company's jurisdiction configuration, the reporting flow, access model, and documentation trail are built around obligations like these - not retrofitted from an EU Directive template with Australian terminology swapped in. That said, whether your specific policy document itself satisfies Part 9.4AAA's content requirements is a question for the lawyer drafting or reviewing it, not for the software underneath it.
The practical takeaway
If you're a public company, large proprietary company, or corporate trustee evaluating reporting software, ask your legal team to review your actual policy document against Part 9.4AAA's requirements directly - separately from any vendor evaluation. Then ask any vendor whether their reporting mechanism actually supports the full range of eligible whistleblowers the Act protects, including people who were never issued a company login.