Back to:
STEP-BY-STEP NJ-COMPLIANT WHISTLEBLOWER INVESTIGATION OUTLINE FOR NONPROFITS
Date: August 18, 2025
Online Intergroup of Alcoholics Anonymous, Inc. (OIAA) Whistleblower Complaint Investigation
This document is not legal advice.
This outline addresses the goals of: Prompt resolution of allegations (ethical misconduct, possible
harassment, and potential misuse of funds) with recognition of any improprieties, avoidance of
unnecessary escalation, strict confidentiality, anti-retaliation measures, and protection for
whistleblowers and observers.
1. LEGAL FRAMEWORK OVERVIEW
- New Jersey CEPA Protections: CEPA prohibits retaliation against employees (and potentially
extends to volunteers in certain contexts) who report or object to activities they reasonably
believe violate laws, regulations, or public policy (e.g., fraud, harassment, misuse of funds).
Protected activities include internal reports, disclosures to authorities, or refusing to
participate in illegal acts. Retaliation includes demotion, harassment, or termination. Remedies
include reinstatement, back pay, damages, and attorney fees. Nonprofits must investigate good-faith
reports promptly to avoid CEPA violations. - Federal Applicability: Sarbanes-Oxley Act (18 U.S.C. § 1514A) protects nonprofit
whistleblowers reporting financial improprieties or fraud; prohibits retaliation and evidence
destruction. - Your Policy Alignment: Your OIAA policy requires prompt investigation by the Board
of Trustees, confidentiality, no retaliation, and good-faith reporting. It covers broader concerns
(e.g., ethical violations, harassment) than CEPA alone. - Key Risks: Mishandling could lead to CEPA lawsuits (1-year statute of limitations), reputational
damage, or loss of tax-exempt status. Maintain defensible records to show fairness.
2. STEP-BY-STEP INVESTIGATION PROCESS
Follow this structured process to ensure compliance, fairness, and de-escalation. As the assigned
board member, you lead but can delegate per your policy (e.g., to a neutral board committee or
external experts like legal counsel). Document every step in a secure, confidential log (see
Evidence Tracking below). Aim to complete within 30-60 days, unless complex; update parties on
progress without revealing details.
STEP 1: INITIAL INTAKE AND PLANNING (DAYS 1-5 POST-RECEIPT)
Review Complaint: Assess the written complaint and 5 observations for specifics (e.g., dates,
witnesses, evidence). Confirm it meets “good faith” under your policy (reasonable belief in
violation).
Acknowledge Receipt: Ensure acknowledgments reference no-retaliation protections and
confidentiality.
Assemble Investigation Team: As per your policy, notify the full Board of Trustees in writing
(via secure channel, e.g., encrypted email). Designate a lead investigator (you or delegate) who is
impartial (not implicated). If needed, engage external experts (e.g., attorney for legal advice,
accountant for funds misuse) – budget [Insert Budget Allocation if Known; Otherwise Leave Blank
[]].
Conflict Check: Ensure no team member has conflicts (e.g., relationship to accused).
Plan Scope: Define focus (ethical misconduct, harassment, funds misuse). Identify key issues,
witnesses (including the 5 observers), and evidence needed. Create a timeline and protocol for
interviews.
Interim Measures: To prevent escalation/retaliation, consider temporary separations (e.g., limit
contact between accused and whistleblower) or suspension if risks are high.
STEP 2: GATHER EVIDENCE (DAYS 6-20)
Document Review: Collect relevant records (e.g., financial statements for misuse claims, emails
for harassment). Retain per your Records Retention Policy.
Interviews: Conduct private, confidential interviews with the whistleblower, observers, accused,
and witnesses. Use the template below. Record notes (not audio without consent); aim for fact-based
responses.
Site/Data Review: If applicable, review financial logs or meeting minutes related to Allegations.
External Input: If needed, consult authorities anonymously (e.g., NJ Attorney General for fraud)
without breaching confidentiality.
STEP 3: ANALYZE FINDINGS (DAYS 21-30)
Evaluate Evidence: Weigh credibility, consistency, and corroboration. Determine if allegations
are substantiated (preponderance of evidence standard).
Legal Review: Consult counsel to assess CEPA/public policy violations.
Recommendations: Propose resolutions (e.g., corrective action, training, no action if unfounded).
Focus on de-escalation: If minor, suggest mediation; if serious, escalate to full Board.
STEP 4: RESOLUTION AND CLOSURE (DAYS 31-45)
Board Review: Present findings to Board (anonymized if needed). Vote on resolution per your
policy.
Implement Actions: E.g., discipline (up to termination), policy updates, or acknowledgment of
improprieties.
Notify Parties: Inform whistleblower/observers of outcome (high-level, without details). Follow
up for closure.
Monitor Post-Resolution: Track for retaliation (e.g., 6-month check-ins).
Documentation: Retain all records confidentially for [Insert Retention Period per Policy; e.g., 7
Years []].
3. CONFIDENTIALITY MEASURES
- Limit Access: Share details only on a “need-to-know” basis (e.g., investigation team, legal
counsel). Use secure platforms (e.g., password-protected files; avoid group emails). - Anonymous Options: Honor anonymous reports; protect identities unless required for Investigation.
- Board/Member Communication: Do NOT discuss specifics in board meetings or emails unless in an
executive session. Prohibit sharing with non-board members. Violations could breach CEPA and your
policy. - Breach Response: If confidentiality is compromised, investigate and discipline per policy.
- CEPA Tie-In: Disclosures under seal (e.g., in lawsuits) are protected; remind all of trade secret
protections (18 U.S.C. § 1833).
4. ANTI-RETALIATION MEASURES
- Written Reminders: Send a non-retaliation memo to all involved, referencing your policy and CEPA
(e.g., “No adverse actions for good-faith reports”). - Protections for Observers: Treat the observers as protected; monitor their treatment (e.g., no changes in roles/volunteer status).
- Monitoring: Assign a neutral board member to oversee (e.g., anonymous feedback surveys).
- Reporting Retaliation: Direct concerns to a designated board contact (e.g., chair@aa-
intergroup.org). Investigate any claims promptly. - Training: Post-investigation, provide board/volunteer training on CEPA and your policy to prevent
future issues.
