Whistleblowing Policy

Proposed Whistleblowing Policy Framework

PROPOSED — requires approval before external publication.

Policy Statement

MSI is committed to accountability, transparency, integrity, professionalism, independence, fairness and regulatory compliance. MSI encourages the prompt reporting of suspected misconduct and will handle reports impartially, confidentially and with appropriate protection against retaliation.

Purpose

  • Provide safe and accessible channels for reporting suspected misconduct.
  • Enable early detection, independent assessment, investigation and corrective action.
  • Protect persons who make reports honestly and in good faith.
  • Support the Board's oversight of integrity, risk, compliance and internal control.

Scope

Applies to directors, committee members, employees, secondees, interns, contractors, consultants, members, suppliers, service providers, programme participants and other stakeholders who obtain information concerning MSI-related conduct.

Reportable Concerns

  • Fraud, bribery, corruption, embezzlement, theft or misuse of MSI resources.
  • Undisclosed conflicts of interest, abuse of authority, favouritism or improper influence.
  • Financial misstatement, procurement irregularity, false claims or manipulation of records, data, assessments or reports.
  • Material breach of law, regulation, contract, MSI policy, delegated authority or Board-approved requirements.
  • Serious technical, quality, safety, environmental, privacy, cybersecurity or regulatory misconduct.
  • Obstruction of audit or investigation, destruction or concealment of evidence, or deliberate failure to report material misconduct.
  • Retaliation, intimidation, harassment or adverse action against a person who makes or supports a good-faith report.

Reporting and Escalation Structure

Channel Recipient When to use / implementation note
Normal channel Designated GRCA whistleblowing officer / secure channel General reports; approved contact arrangements to be inserted.
Alternative channel Chair of the Governance, Risk and Compliance Committee Reports involving the CEO, GRCA leadership, conflict in the normal channel or inadequate response.
Board-level channel Chairperson of the Board or Chair of the Audit Committee Reports involving a Board Committee Chair, multiple senior officers, significant financial misconduct or systemic governance failure.
External authority Relevant regulator, enforcement agency or law-enforcement body Where required by law, urgent public harm is involved, or MSI lacks jurisdiction or independence.

Anonymous reports may be accepted where the approved reporting system permits. Reporters should provide as much factual detail and supporting evidence as reasonably available; incomplete evidence should not prevent a good-faith report.

Confidentiality and Protection from Retaliation

  • Reporter identity and identifying information should be restricted to persons who need the information for assessment, investigation, legal obligations or procedural fairness.
  • MSI should not tolerate dismissal, demotion, disadvantage, threats, harassment, discrimination or other retaliation connected with a good-faith report or participation in an investigation.
  • Suspected retaliation should be reported and investigated as a separate serious breach.
  • Protection does not prevent legitimate action for unrelated misconduct or poor performance, provided the action is demonstrably independent of the report.

Assessment, Investigation and Decision

  1. Receipt and secure registration — record the report in a restricted register and preserve evidence.
  2. Conflict and jurisdiction check — confirm independence, immediate protective action and any need for referral.
  3. Preliminary assessment — assess credibility, materiality, risk, available evidence and the appropriate process.
  4. Investigation — appoint an impartial and competent investigator with defined scope, authority, confidentiality and reporting requirements.
  5. Findings and action — submit findings to the authorised decision-maker and implement appropriate disciplinary, control, recovery, disclosure, referral or remediation action.
  6. Closure and feedback — inform the reporter, where practicable and lawful, that the matter has been addressed without disclosing protected information.
  7. Monitoring and learning — track corrective actions, systemic issues, retaliation risk and lessons for policies, controls and training.

Roles and Oversight

Role Responsibility
Board of Directors Approves the policy, receives material reporting and ensures independent oversight.
Governance, Risk and Compliance Committee Primary policy oversight, trend review, protection monitoring and escalation to the Board.
Audit Committee Oversight where reports concern financial reporting, internal control, audit or significant financial misconduct.
Chief Executive Officer Ensures implementation and resources, except for matters involving the CEO or requiring independent Board handling.
GRCA Unit Maintains channels, register, triage, governance, confidentiality, investigation coordination, reporting and corrective-action tracking.
FAHR / relevant Unit Heads Support employment, finance, procurement, IT, records or operational actions without compromising independence.
All personnel and stakeholders Report concerns honestly, preserve confidentiality, cooperate with investigations and avoid retaliation.

Good Faith, Malicious Reports and Procedural Fairness

A report made honestly and with reasonable grounds should remain protected even if it is not substantiated. Knowingly false, fabricated or malicious reports may result in disciplinary or contractual action. Persons who are the subject of allegations must be treated fairly, and conclusions should be based on evidence and an impartial process.

Records, Reporting and Review

  • Maintain a secure register of reports, assessments, investigations, decisions, disclosures, corrective actions and retaliation concerns.
  • Provide periodic anonymised reporting to the Governance, Risk and Compliance Committee and material escalation to the Board or Audit Committee as appropriate.
  • Retain records in accordance with applicable law, MSI's document-control requirements and the sensitivity of the matter.
  • Review the policy at least once every three years, or earlier following material legal, governance, organisational or incident-related change.

Approval Items to Complete Before Adoption

1. Confirm the approving authority and Committee ownership.

2. Insert the designated officer, secure email/portal, postal address and emergency contact arrangements.

3. Define acknowledgement, assessment, investigation and reporting service standards.

4. Align the policy with the MSI Constitution, Delegation of Authority, HR policy, disciplinary procedures, data protection, records management, investigation protocol and applicable Malaysian law.

5. Establish independence, conflict-check, external-investigator and regulator-referral procedures.

6. Brief the Board, Management and employees and publish an accessible stakeholder reporting notice.

Concluding Institutional Position

MSI is presented as an institution in transition: from a principally consultative and secretariat role toward an integrated national platform for policy intelligence, implementation coordination, technical services, capability development and institutional assurance. This evolution remains anchored in MITI policy direction, Board governance, documented authority, stakeholder trust and measurable delivery.