If a company has already put a whistleblowing channel in place to satisfy the Bribery Act 2016, it is easy to assume the job is done. It is not, quite. The Bribery Act’s whistleblower protections, the duty to report suspected bribery to the Ethics and Anti-Corruption Commission and the protection from retaliation that comes with it, are specifically about bribery. An employee who instead raises internal fraud, safety failures, or financial misconduct that does not amount to bribery is relying on a much thinner, more scattered set of protections, and knowing that gap matters for any employer deciding how far to build a whistleblowing policy.
Kenya has no single whistleblower protection law
A Whistleblower Protection Bill has been in various forms of draft before the Senate since 2023, intended to consolidate protection into one statute the way similar laws work in other jurisdictions. It has not been enacted. In its absence, protection for someone reporting wrongdoing in Kenya is spread across several different laws, each covering a different situation, rather than one general rule that applies whatever the employee reports.
What actually covers what
The Bribery Act 2016 and the Bribery Regulations, 2022 cover reports of bribery and corruption specifically, with a clear duty to report to the EACC and real protection against retaliation once that happens. The Anti-Corruption and Economic Crimes Act, 2003 protects informants who report corruption and economic crimes more broadly than bribery alone. The Public Officer Ethics Act, 2003 protects whistleblowers in the public sector, which does not help a private company at all. The Witness Protection Act, 2006 offers more serious protections, including relocation in extreme cases, but is aimed at witnesses in active legal proceedings rather than an employee raising an internal concern for the first time. Outside these specific categories, an employee reporting something else, poor safety practices, financial irregularities that fall short of bribery, or harassment, is left relying on the Employment Act’s general prohibition on discrimination and unfair dismissal, which offers real protection but was not written with whistleblowing in mind.
Why this matters for building your own policy
A whistleblowing channel built only to satisfy the Bribery Act’s section 9 procedures will, by design, be scoped to bribery reports. If your actual concern is broader, protecting an employee who reports theft, safety violations, or ordinary financial dishonesty, the statutory floor genuinely is lower, and the practical protection has to come from your own policy rather than being assumed from the law. A well-drafted internal whistleblowing policy extends confidentiality and non-retaliation commitments to any good-faith report of wrongdoing, not only the categories the law happens to protect, and says so explicitly, since employees rarely know which statute would apply to their particular report before they make it.
What a broader policy should actually say
At minimum: who a concern can be raised with, including a route that does not go through the person’s direct manager if that manager is the subject of the concern, a commitment to confidentiality that goes beyond what any specific statute requires, an explicit statement that no adverse action will be taken against someone who reports in good faith, and a defined process for what happens after a report is made. None of this is legally mandatory outside the bribery-specific context. It is the difference between a company that can point to a real policy when something goes wrong, and one that can only point to what the Bribery Act happened to require.



