Whistleblower Policies Under Section 1317AI: What Australian Startups Have to Have and When the Obligation Kicks In

Whistleblower Policies Under Section 1317AI: What Australian Startups Have to Have and When the Obligation Kicks In

Whistleblower compliance sounds like big-company territory, and for one obligation that’s half true: the requirement to have a whistleblower policy only bites at a defined size threshold. But the whistleblower protections — the rules about confidentiality and victimisation that produced a $7.5 million penalty against TerraCom in 2025 — apply to every Australian company from the day it’s registered, policy or no policy. Founders tend to learn the two halves of that sentence in the wrong order. Here’s the right one.

Who Actually Has to Have a Policy

Section 1317AI of the Corporations Act 2001 (Cth) requires three kinds of company to have a whistleblower policy and make it available to their officers and employees:

  1. Public companies — all of them, listed or not;
  2. Large proprietary companies; and
  3. Proprietary companies that are trustees of registrable superannuation entities (not a startup scenario, with respect to the founders building super products — the trustee there is rarely your operating Pty Ltd).

The obligation has applied since 1 January 2020, and ASIC’s Regulatory Guide 270 sets out in detail what the regulator expects a compliant policy to look like. The only carve-out worth knowing: ASIC has granted relief to small not-for-profit companies limited by guarantee with annual revenue under $1 million.

So a garden-variety startup — a small proprietary company limited by shares — has no statutory obligation to have a whistleblower policy. The interesting question is when that stops being true.

When a Startup Crosses the Line

Trigger one: you become a large proprietary company. Under section 45A, a proprietary company is large for a financial year if it satisfies at least two of three tests, measured on a consolidated basis with the entities it controls:

  • $50 million or more in consolidated revenue;
  • $25 million or more in consolidated gross assets at year end;
  • 100 or more employees at year end.

Founders read that list and file it under “someday”. Look again at the second and third limbs. Gross assets includes the cash you just raised. A startup that closes a $30 million Series B holds $25 million-plus in gross assets the moment the money lands, whatever its revenue. And headcount reaches 100 well before revenue reaches $50 million in most venture-backed models. Two limbs, test satisfied: a loss-making, pre-profit scale-up can be a “large proprietary company” — with the audited financial reporting obligations that status drags along — while still burning investor cash. The consolidation point matters too: subsidiaries’ numbers count, so a group structure doesn’t dilute the test.

The timing rule is more forgiving than the test: because large status is assessed at the end of a financial year, a company that becomes large must have its policy in place within six months after the end of the first financial year in which it qualifies. Tip over the thresholds during FY2027 and the policy is due by 31 December 2027. That’s a real runway — but only for companies that are actually watching the thresholds.

Trigger two: you become a public company. Convert to an unlisted public company ahead of an IPO, because the register is heading past the 50 non-employee shareholder limit, or as part of a restructure — and the policy obligation applies from the conversion, with no six-month grace period. A whistleblower policy belongs on the conversion checklist alongside the constitution and the board composition work.

Failing to have (or make available) a compliant policy when required is a strict liability offence — no intent required — carrying 60 penalty units, currently $21,840 at the $364 Commonwealth penalty unit value that has applied since 1 July 2026. The bigger cost is reputational: this is an easy, visible compliance miss for an investor’s due diligence team or ASIC to spot.

What the Policy Must Contain

Section 1317AI(5) prescribes the minimum content. The policy must set out information about:

  • the protections available to whistleblowers under the law;
  • to whom disclosures can be made, and how;
  • how the company will support whistleblowers and protect them from detriment;
  • how the company will investigate disclosures;
  • how the company will ensure fair treatment of employees who are mentioned in disclosures; and
  • how the policy will be made available to officers and employees.

RG 270 fleshes out each element, and ASIC’s expectations have hardened since. Report 827, published in December 2025 off the back of a questionnaire of 134 companies, found that plenty of companies have a policy on paper but no functioning program behind it — and ASIC has said it will contact companies whose practices fall short. The consistent message: a policy downloaded from a template bank, never trained on and never tested, is compliance theatre the regulator is now explicitly looking through.

The Part That Applies to You Right Now, Policy or Not

Here’s the half founders skip. The whistleblower protections in Part 9.4AAA of the Corporations Act apply to every company — there is no small-company exemption. From your first hire:

  • Eligible whistleblowers are a wide class: current and former employees, officers, contractors and suppliers (and their employees), and relatives of any of them. A disgruntled ex-co-founder or a terminated contractor can be a protected whistleblower.
  • A disclosure is protected if it’s made to an eligible recipient — which includes any officer or senior manager of the company, not just a hotline — about misconduct or an improper state of affairs. Anonymous disclosures are protected. Purely personal work-related grievances are generally carved out, but the carve-out is narrower than employers assume: a grievance mixed with broader misconduct, or involving victimisation, is back inside the protections.
  • Revealing a whistleblower’s identity without consent (outside narrow exceptions such as disclosure to ASIC or a lawyer) and victimising a whistleblower — causing or threatening detriment because you believe or suspect they made or could make a protected disclosure — are both offences and civil penalty provisions. For a company, the maximum civil penalty runs to the greater of $18.2 million, three times the benefit derived, or 10% of annual turnover (capped).

That’s not theoretical. In ASIC v TerraCom Ltd (No 3) [2025] FCA 1017, the Federal Court ordered TerraCom to pay $7.5 million plus $1 million in costs — ASIC’s first civil penalty outcome under the victimisation provisions — over ASX announcements and a shareholder letter that disparaged a former employee who had raised coal-quality falsification concerns. The court confirmed “detriment” extends to hurt, humiliation and distress. Every startup board that has ever wanted to “push back publicly” on an ex-employee’s allegations should read that case first.

What to Actually Do

Pre-threshold: you don’t need a policy, but you do need to not breach Part 9.4AAA. Brief your leadership team — every officer and senior manager is an eligible recipient whether they know it or not — on the two cardinal rules: protect identity, never retaliate. Loop in your lawyers before responding to any internal allegation that smells like a disclosable matter, especially in the heat of a founder or employee exit.

Approaching the thresholds: watch consolidated gross assets and headcount after every raise, and calendar the six-month window off your financial year end. Converting to a public company? The policy is due at conversion.

At or past them: adopt a policy that genuinely maps to RG 270, train the people named in it as recipients, and review it periodically — Report 827 makes clear that ASIC now measures programs, not paperwork. Done properly, it’s also a governance asset: investors’ due diligence increasingly treats whistleblower arrangements as a proxy for how seriously a board takes its obligations generally.


This article is general information only, not legal advice — whether and when the policy obligation applies turns on your structure, your consolidated numbers and your financial year. Viridian Lawyers advises Australian startups and scale-ups on corporate governance, capital raising and employment issues. If your last round pushed your balance sheet toward the thresholds — or an internal complaint has you drafting a response — get in touch first.

Recent Articles

blog-image
Whistleblower Policies Under Section 1317AI: What Australian Startups Have to Have and When the Obligation Kicks In

Whistleblower compliance sounds like big-company territory, and for one obligation that’s half true: the requirement to have a whistleblower policy only bites at a defined size threshold. But …

blog-image
CASA Part 101 and Beyond Visual Line of Sight: What Drone and UAV Startups Need to Fly Commercially in Australia

Most drone startups don’t really sell drones. They sell inspections, deliveries, surveys, security patrols — services whose unit economics only work when one operator can supervise many aircraft …

blog-image
Space Licensing in Australia: The Regulatory Path Space-Tech Startups Must Navigate Before Launch

Australian space-tech stopped being hypothetical a while ago. In July 2025, Gilmour Space’s Eris became the first Australian-made orbital rocket to lift off from Australian soil — the test …