If your company is required to maintain a CIPA, preventing workplace harassment is no longer just a best practice. Brazil’s Law No. 14,457/2022 introduced specific requirements involving reporting channels, internal policies and employee training.
There is a big difference between saying that a company does not tolerate harassment and actually having a process in place to deal with it when it happens.
Since 2023, that difference has also become a compliance issue in Brazil.
Law No. 14,457/2022 established a number of requirements for companies required to maintain a CIPA — Comissão Interna de Prevenção de Acidentes e de Assédio, or Internal Commission for Accident and Harassment Prevention.
These requirements include procedures for receiving and following up on reports, internal rules addressing harassment and violence, and regular training and awareness initiatives.
The law originally gave companies 180 days to implement these measures. The Brazilian Ministry of Labor later incorporated the new requirements into the applicable Occupational Health and Safety Regulations, with the changes taking effect on March 20, 2023.
For companies that fall under the CIPA requirements, this is no longer something that can simply be postponed.
Where did Law No. 14,457/2022 come from?
The law created the Emprega + Mulheres Program, a broader set of measures designed to support women’s participation and retention in the workforce.
One of its areas of focus is the prevention of sexual harassment and other forms of workplace violence.
There is an important distinction, however.
Although the legislation originated within a program focused on women in the workplace, the measures companies are required to implement are not limited to female employees. Reporting procedures and prevention policies must work for the workplace as a whole.
The change was significant enough to affect the commission’s official name.
What was previously known as the Internal Commission for Accident Prevention became the Internal Commission for Accident and Harassment Prevention, while keeping the acronym CIPA. Brazil’s NR-5 regulation was updated accordingly.
What exactly does a company need to do?
Article 23 of the law establishes four main areas of action.
The first is to include rules of conduct regarding sexual harassment and other forms of workplace violence in the company’s internal policies, and to make sure those rules are properly communicated to employees.
Adding a few paragraphs to a policy document that nobody reads is not enough. Communication is part of the requirement.
The second is to establish procedures for receiving and following up on reports, investigating allegations and applying disciplinary measures when appropriate, while protecting the anonymity of the person making the report.
This is where the reporting channel becomes particularly important.
The law does not require companies to use a specific technology or provider. What matters is whether the process actually allows employees to report concerns and whether anonymity can be preserved.
That changes the way some common workarounds should be evaluated.
An email sent directly to HR, for example, identifies the sender. An internal form that requires employees to log in may leave records linked to the employee. Even a physical suggestion box placed in a high-traffic area can undermine anonymity in practice.
So the relevant question is not simply whether the company can say, “We have a reporting channel.”
The better question is: what information does the system collect, and who can access it?
The third requirement is to include harassment and workplace violence prevention in the activities and practices carried out by the CIPA itself.
The fourth is to provide training, guidance and awareness activities at least once every 12 months covering violence, harassment, equality and diversity.
These initiatives must include employees at every level of the organization, which naturally includes managers and senior leadership.
Training the workforce while leaving managers out of the conversation misses an important part of the purpose of the law.
Is my company required to maintain a CIPA?
That question comes first.
The requirement to establish a CIPA cannot be reduced to a simple rule such as “companies with more than 20 employees.”
Under Brazil’s NR-5 framework, requirements are generally determined at the establishment level and take into account factors such as the number of employees and the risk category associated with the company’s economic activity. Specific industries may also be subject to additional rules.
Companies should therefore confirm their classification under NR-5 with the professionals responsible for occupational health and safety before starting the compliance process.
What happens if the company does nothing?
It is tempting to look at Law No. 14,457/2022 and ask only one question:
“How much is the fine?”
That is not necessarily the best way to look at the issue.
These requirements have been incorporated into Brazil’s occupational health and safety framework, including NR-1 and NR-5, and form part of the obligations applicable to organizations that fall within their scope.
There is also a practical issue.
Imagine that a company faces a serious harassment complaint and needs to demonstrate what preventive measures were already in place.
Were employees given clear rules?
Had they received training?
Was there a safe way to report concerns?
Who received the reports?
How were those reports handled?
When none of those processes exist, it becomes much harder to show that the company had a structured approach to preventing and addressing workplace misconduct.
There is an even simpler problem.
Without a reliable internal reporting mechanism, the company may first learn that something is wrong only after the issue has already left the organization.
That may happen through litigation, an external complaint or the resignation of an employee.
At that point, the opportunity to understand and address the situation internally may already have been lost.
How to comply without turning it into a months-long project
The technology itself is usually the easiest part.
The process behind it deserves more attention.
Start by confirming whether the establishment falls within the CIPA requirements under NR-5.
Then establish a reporting mechanism. If anonymity is part of the proposal, look carefully at what information the platform records. IP addresses, access logs and user identification deserve particular attention.
Next, determine who will receive and manage the reports. Avoid placing the entire process in the hands of a single person, and establish in advance what happens if someone responsible for handling reports is named in a complaint.
Once the process is defined, communicate it. Employees need to know that the channel exists and how to use it. Internal emails, onboarding materials, intranet pages, QR codes in common areas and training sessions are all practical ways to make the channel accessible.
Training should then become part of the company’s recurring routine, including employees at every level of the organization.
Finally, update internal policies and keep records showing how and when those policies were communicated.
For most companies, putting a reporting channel online is not the difficult part.
The question that tends to require more discussion comes immediately afterward:
Who receives the report when one actually arrives?
That answer should exist before the first complaint does.
A reporting channel should not exist only because the law requires one
Law No. 14,457/2022 created clear obligations for Brazilian companies that fall under the CIPA requirements.
But building the entire process just to check a compliance box wastes much of its potential value.
A well-designed reporting channel gives a company the opportunity to learn about problems while there is still time to understand what happened, investigate the facts and decide how to respond.
In the end, perhaps the most useful question is also the simplest:
If someone at your company needed to report something serious today, would they know where to go — and would they trust the process?
If the answer is unclear, it may be worth reviewing the process before it becomes necessary.
