Whistle Blower Policy in Banks: Protected Disclosure and Vigil Mechanism
A robust whistle blower policy in banks is the backbone of ethical governance, giving employees, vendors and customers a safe channel to report suspected fraud, corruption or misconduct without fear of reprisal. For IIBF Ethics in Banking candidates, examiners frequently test the interplay between the Companies Act 2013 vigil mechanism, SEBI LODR Regulation 22 disclosure norms, the Whistle Blowers Protection Act 2014, and the CVC's Public Interest Disclosure and Protection of Informer (PIDPI) Resolution. This guide breaks down each instrument, shows how protected disclosures actually move through a bank, and closes with exam-ready MCQs and FAQs.
📢 What Is a Whistle Blower Policy in Banks
A whistle blower policy in banks is a formal, board-approved framework that lets an insider — a staff member, contractor, or sometimes a customer — flag a genuine concern about fraud, financial irregularity, insider trading, or breach of the code of workplace ethics to someone above the immediate chain of command. Unlike a routine grievance redressal system, its defining feature is protection: the complainant's identity is shielded, and the policy explicitly bars any adverse HR action — demotion, transfer, denial of increment, or termination — that can be traced to the disclosure.
RBI supervisory guidance on frauds and internal controls expects every bank to operate such a mechanism as part of its fraud risk management framework. The policy usually sits alongside the vigilance and internal audit functions, and — for public sector banks — the Chief Vigilance Officer's office, so a single disclosure can trigger investigation and, where warranted, escalation to the regulator.
A bank sits at the intersection of four legal regimes — company law, securities law, service law for public servants, and central vigilance rules — so no single statute covers whistle blowing on its own. Candidates must know which instrument governs which class of bank and complainant, a distinction covered section by section below.
💡 Exam Tip: When a question asks "which law applies," first check two facts — is the bank listed, and is the complainant a public servant. Those two filters usually point straight to the correct statute.
⚖️ Companies Act 2013 – Section 177(9)-(10) Vigil Mechanism
Section 177(9) of the Companies Act 2013 requires every listed company, and every company that accepts public deposits or has borrowed above the prescribed limit from banks and financial institutions, to establish a vigil mechanism for directors and employees to report genuine concerns. Since virtually every scheduled commercial bank meets one of these thresholds, the mechanism is effectively mandatory across the sector. Full text is on the government's official repository, indiacode.nic.in.
The mechanism is overseen by the Audit Committee (or the board, where none exists). Section 177(10) adds the safety-valve clause: in exceptional cases the mechanism must allow direct access to the chairperson of the Audit Committee, bypassing the normal reporting line — the one concrete escalation right the section guarantees, and the point most often tested in MCQs.
Rule 7 of the Companies (Meetings of Board and its Powers) Rules 2014 adds that the mechanism must ensure adequate safeguards against victimisation, while repeated or frivolous complaints can themselves attract disciplinary action. Listed banks must also disclose the vigil mechanism's salient features on their website and board's report — a duty that dovetails with SEBI LODR Regulation 22, covered next.

📋 SEBI LODR Regulation 22 – Obligations for Listed Banks
Regulation 22 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 places a parallel — and in some respects tighter — obligation on every listed bank. It requires the listed entity to formulate a vigil mechanism or whistle blower policy so that directors and employees can report genuine concerns, and it explicitly states that the mechanism must provide adequate safeguards against victimisation, including direct access to the chairperson of the Audit Committee in exceptional cases, echoing the Companies Act language almost word for word.
Where Regulation 22 goes further is disclosure: the listed bank must affirm in its annual report that no personnel has been denied access to the Audit Committee, and must host the policy on its own website. Auditors and proxy advisory firms specifically check for this affirmation, which is why listed banks now publish detailed, standalone whistle blower policy documents rather than a token paragraph in the code of conduct.
Remember that Regulation 22 applies only to listed entities, while the Companies Act vigil mechanism also catches large unlisted deposit-taking or borrowing companies — a bank can be covered by the Companies Act limb without being covered by LODR. Full regulatory text is at the primary source, sebi.gov.in.
⚠️ Common Mistake: Students often assume SEBI LODR and the Companies Act vigil mechanism are the same rule repeated twice. They are separate legal obligations with separate applicability tests — LODR is listing-based, the Companies Act trigger is size/deposit-based.
🛡️ Whistle Blowers Protection Act 2014 and the CVC's PIDPI Resolution
The Whistle Blowers Protection Act, 2014 gives public servants — including employees of public sector banks — a statutory route to report corruption, wilful misuse of power, or a criminal offence by a public servant. A complaint goes to a "Competent Authority," the complainant's identity is kept confidential, and revealing it or victimising the complainant is itself an offence, while a false complaint made in bad faith is penalised too. Because implementing rules took years to fully operationalise, most public-sector whistle blowing on corruption in practice still routes through the older CVC mechanism below — but the Act remains the statutory framework examiners expect candidates to name correctly.
The Central Vigilance Commission's Public Interest Disclosure and Protection of Informer (PIDPI) Resolution, first notified in 2004 and periodically updated, has actually carried the bulk of India's corruption-related whistle blowing in government and public sector banks. Under PIDPI, any person can send a sealed complaint marked "Complaint under the Public Interest Disclosure" directly to the CVC, which acts as the "Designated Agency." Identity is not disclosed unless the complainant reveals it or a court directs otherwise.
The practical distinction candidates must hold onto: the Companies Act and SEBI LODR mechanisms are internal corporate-governance channels aimed at any genuine concern, while the Whistle Blowers Protection Act and PIDPI are external, statutory channels specifically for corruption and misuse of public office, primarily serving public servants and PSU bank staff.

🔍 How Banks Operationalise Protected Disclosure
On the ground, a bank's whistle blower policy usually layers several channels: a dedicated email or portal to the Audit Committee chairperson, a toll-free helpline sometimes outsourced to an independent ombudsman firm for anonymity, and an internal Vigilance or Ethics Committee that triages complaints by severity. Public sector banks also route corruption-specific complaints through the Chief Vigilance Officer, who reports periodically to the CVC, closing the loop with the PIDPI framework above.
Good policy design, of the kind explored in the chapter on building an ethical organization, treats the channel as a culture signal, not a compliance checkbox: leadership commits publicly to non-retaliation, complaints are tracked to closure, and anonymised statistics go to the Audit Committee every quarter. Banks that get this wrong show the same pattern seen in cases of corruption, bribery and white-collar crime — an early complaint went unacknowledged and resurfaced later as a much larger fraud.
Anti-retaliation safeguards are what examiners probe hardest: a genuine mechanism must protect against subtler victimisation too — a sudden negative appraisal, an inconvenient transfer, exclusion from projects — soon after a protected disclosure, and banks must be able to show the Audit Committee that any such action was unconnected to it.
📌 Remember: Internal mechanism = Companies Act s.177 / SEBI LODR Reg 22. External statutory mechanism for corruption = Whistle Blowers Protection Act 2014, administratively backed by the CVC's PIDPI Resolution.

📊 Whistle Blower Instruments Compared
| Instrument | Applies To | Reporting Route | Identity Protected |
|---|---|---|---|
| Companies Act 2013, s.177(9)-(10) | Listed cos. + large deposit/borrowing cos. (most banks) | Audit Committee; chairperson in exceptional cases | ✔ |
| SEBI LODR Regulation 22 | Listed banks only | Vigil mechanism disclosed on website + annual report | ✔ |
| Whistle Blowers Protection Act 2014 | Public servants, incl. PSU bank staff | Complaint to statutory Competent Authority | ✔ (offence to disclose) |
| CVC PIDPI Resolution | Any person, corruption/misuse of office | Sealed complaint direct to CVC as Designated Agency | ✔ unless self-disclosed |
Understanding how these four instruments interlock is useful context for related topics such as corporate governance in banks, since the Audit Committee receiving vigil-mechanism complaints is the same committee responsible for wider governance oversight, the bank's broader anti-corruption policy, and how well a branch runs fraud prevention, since most disclosures start as a frontline observation.
🌐 Whistle Blowing Beyond the Bank
Whistle blower protection is not unique to banking; it appears wherever a process depends on stakeholders reporting irregularities honestly. Candidates studying the Insolvency and Bankruptcy Code will recognise the same underlying principle — protecting a party raising a genuine objection — in how a committee of creditors voting process handles dissent from a minority creditor.
Within Ethics in Banking, whistle blowing sits close to adjacent themes IIBF papers test together: the chapter on banking ethics and changing dynamics covers how technology has made it easier both to raise genuine concerns and to spread malicious complaints, while ethical marketing in banking applies a parallel disclosure logic to customer-facing conduct. Browse more on the Ethics in Banking tag hub.
🧠 Practice MCQs: Whistle Blower Policy in Banks
Q1. Which section of the Companies Act 2013 mandates a vigil mechanism for listed companies and large deposit-taking or borrowing companies? (a) Section 134 (b) Section 149 (c) Section 177(9)-(10) (d) Section 178
Answer: (c) — Section 177(9) mandates the vigil mechanism and 177(10) adds the direct-access-to-chairperson safeguard.
Q2. Under SEBI LODR, the requirement for listed entities to have a vigil mechanism/whistle blower policy is contained in which regulation? (a) Regulation 17 (b) Regulation 22 (c) Regulation 30 (d) Regulation 4
Answer: (b) — Regulation 22 of the SEBI (LODR) Regulations, 2015 covers the vigil mechanism and its website/annual-report disclosure.
Q3. In which year was the Whistle Blowers Protection Act enacted? (a) 2011 (b) 2013 (c) 2014 (d) 2016
Answer: (c) — The Whistle Blowers Protection Act was enacted in 2014 to protect public servants who report corruption or misuse of power.
Q4. Complaints under the CVC's Public Interest Disclosure and Protection of Informer (PIDPI) Resolution are addressed to which body acting as the Designated Agency? (a) SEBI (b) RBI (c) Central Vigilance Commission (d) IBBI
Answer: (c) — The CVC is the Designated Agency under the PIDPI Resolution and receives sealed complaints directly.
Q5. Under the Companies Act 2013 vigil mechanism, in what circumstance can an employee bypass the normal reporting line and approach the Audit Committee chairperson directly? (a) Every complaint, without exception (b) Only in exceptional cases (c) Never; all complaints go through HR (d) Only if the RBI approves
Answer: (b) — Section 177(10) reserves direct access to the Audit Committee chairperson for exceptional cases, not routine complaints.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
Is a whistle blower policy legally compulsory for every bank in India?
Most banks are covered either because they are listed (triggering SEBI LODR Regulation 22) or because they accept public deposits or borrow above the prescribed threshold (triggering the Companies Act 2013 vigil mechanism under Section 177), so in practice almost every scheduled bank must have one.
Does the Whistle Blowers Protection Act 2014 protect private bank employees?
The Act is aimed primarily at public servants, including employees of public sector banks; private bank employees are instead protected mainly through the bank's own internal vigil mechanism required under the Companies Act and SEBI LODR.
Can a whistle blower's identity be revealed under the PIDPI Resolution?
No, unless the complainant voluntarily discloses their own identity or a court of law directs disclosure; the CVC is expected to keep the identity confidential throughout the process.
What safeguards exist if a bank employee faces retaliation after a protected disclosure?
The vigil mechanism must build in safeguards against victimisation, and a genuine grievance of retaliation can be escalated to the Audit Committee chairperson or, for corruption-related matters, reported further to the CVC.
A well-designed whistle blower policy in banks is not a single form or a single law — it is four overlapping instruments, each triggered by a different fact pattern, working together to make protected disclosure practical rather than theoretical. Reinforce these distinctions with timed practice on iibf.store/tests, or work through the full JAIIB/CAIIB syllabus on the JAIIB course page before exam day.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.