Our own servers in Europe · GDPR · Support in your language

Module 3 of 5 · ISO 19600 · Section 3

Implementation: controls, training and whistleblowing channel

The guidance recommends three implementation pieces: controls proportionate to risk, tailored training and an accessible whistleblowing channel.

Content reviewed on

Compliance controls

Controls proportionate to each area's risk level, built into existing processes.

Training and awareness

Training tailored to each role's risk, with periodic reminders for the most exposed areas.

Whistleblowing channel

An accessible, confidential channel for reporting noncompliance, with protection from retaliation.

What an auditor usually asks for

  • Compliance controls documented by risk area
  • A compliance training plan by role
  • An operational, confidential whistleblowing channel
  • A whistleblower protection procedure

How to cover implementation in Kimobox

  1. 1Document compliance controls on the process map.
  2. 2Log each employee's compliance training in the employee portal.
  3. 3Manage the whistleblowing channel with confidentiality and case traceability.

Every report stays logged with confidentiality and traceability, not in an email that could get lost.

See Kimobox's employee portal

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 19600:2014 — Compliance management systems. Guidelines (withdrawn) ISO · Withdrawn
  2. ISO 37301:2021 — Compliance management systems. Requirements ISO · April 2021