Doc ref: LQMS-ISMS-PO-XX
Owner: Compliance & Information Security
1. Purpose
This policy sets out how LQMS identifies, reports, assesses, and resolves incidents affecting employees, operations, information security, or company conduct — including incidents raised anonymously through this portal.
2. Scope
Applies to all employees, contractors, and third parties working on behalf of LQMS. Covers health & safety events, harassment or discrimination, ethics and conduct violations, fraud, information security incidents, quality/process deviations, and retaliation.
3. Reporting channels
Incidents may be reported anonymously through this Support Portal channel, or through a named report to a manager, HR, or the compliance team. Anonymous reports receive the same level of review as named ones.
4. Confidentiality
This portal does not collect names, email addresses, or device/IP identifiers. Where a reporter's identity is known through another channel, it is shared only on a need-to-know basis with those directly investigating the case.
5. Non-retaliation
LQMS prohibits retaliation of any kind against anyone who reports an incident in good faith, even if the concern is later found unsubstantiated. Retaliation is itself treated as a reportable incident.
6. Review process
Every report moves through intake, triage, investigation, findings & decision, and resolution & closure. See "How reports are reviewed" for the full breakdown and expected timeframes.
7. Record keeping
Case records are retained for as long as required for investigation, audit, and legal purposes, then disposed of in line with LQMS's data retention schedule.
8. Policy review
This policy is reviewed annually, or sooner following a significant incident or regulatory change, by the Compliance & Information Security function.
This summary is provided for quick reference inside the portal. The full, controlled version of this policy is maintained by Compliance & Information Security.