Governance

Whistleblowing & Speak-Up

Staff, workers and contractors are encouraged to raise genuine concerns about wrongdoing without fear of retaliation. This route is separate from the public vulnerability-disclosure channel and ordinary customer complaints.

What can be raised

Concerns may include suspected fraud, bribery or corruption, unlawful or seriously unethical conduct, deliberate concealment of security incidents or vulnerabilities, falsification/suppression of compliance evidence, conflicts of interest, privacy/data misuse, retaliation against a reporter, or deliberate concealment of such matters.

How to speak up

Raise the concern confidentially with an appropriate manager, director or governance contact who is not implicated. If the normal route is conflicted or unsafe, escalate directly to another director/senior governance contact. Provide relevant facts, dates and supporting information where possible.

Confidentiality & non-retaliation

Reports are handled as confidentially as reasonably possible. Raeburn does not tolerate retaliation, victimisation or detrimental treatment for raising a genuine concern in good faith or on reasonable grounds. Anonymous concerns may be considered, although anonymity can limit investigation and follow-up.

Investigation

Concerns are assessed for urgency, conflicts, evidence preservation, safeguarding and legal/regulatory implications. People implicated in a concern must not control its investigation. Findings and actions are documented proportionately and access-restricted.

External rights

Nothing in this route prevents a person from seeking independent legal advice, reporting suspected crime, making a protected disclosure to an appropriate prescribed person/body or exercising other rights under applicable law.

Separate specialist routes

External security vulnerabilities should go to security@theraeburngroup.com. Privacy matters should go to dpo@theraeburngroup.com. Customer complaints should use the published Complaints & Escalation procedure.