
GETTING STARTED
IN YOUR OWN ORGANISATION
The approach described above can be applied to organisations in various industries and sectors, regardless of the size of the workforce. While small organisations struggle with overlapping roles between different employees, large organisations struggle with mapping all activities related to the various roles. In that case, one option is to start, for example, with the roles within a particular department. In practice, the approach may differ on certain points, but it is important that all steps described are reflected in the organisation-specific approach.
It is also important to use the analysis as a preventive tool. That means preferably before there are any signals of possible integrity violations. Only then can an organisation identify risks and take action at the earliest possible stage. This allows the analysis to be used as efficiently as possible as a tool to help prevent integrity violations and wrongdoing.
Who should carry out the analysis depends on how the organisation is structured and what expertise is available. In larger organisations, it makes sense for the analysis to be carried out by an officer responsible for overseeing integrity policy, or by an employee from the Risk & Control department or a comparable department. What matters is that the people carrying out the analysis understand the various roles and processes, and that knowledge regarding assessing integrity risks is available. Setting up a small working group to bring together different areas of expertise can lead to a better analysis. Small organisations may consider engaging external expertise.
Another point to consider is designing the process in such a way that vulnerabilities within roles are examined critically and constructively. It must not become a box-ticking exercise or a copy-and-paste job. For this reason, the Authority has chosen not to provide a fully developed analysis. As described above, an appendix with examples is available for anyone looking for inspiration and examples of work areas, tasks, powers, vulnerabilities and measures.