
IDENTIFY ADDITIONAL MEASURES
STEP 5
Now that you have identified which tasks and powers are susceptible to misuse, which factors may increase vulnerability to integrity risks and which measures your organisation has already taken to reduce those risks, it is important to assess whether the risks have been sufficiently avoided and/or mitigated.
Whether the identified measures are effective depends on circumstances such as their relationship with existing measures and the organisational culture. It is also important that the measures are known to those concerned and that they are up to date.
Organisations can often reduce integrity risks through small adjustments. For example, by assigning a particular control task to another officer. For example, an organisation that conducts internal checks on money flows can take additional measures by ensuring that the decision-making and control processes for expenditure do not rest with one person, but that at least two people carry out the necessary checks at different points in the process. This is an example of segregation of duties. For an extensive, non-exhaustive list of examples of measures, see the appendix.
When adding new measures, carefully consider whether their scope and impact are appropriate to the risks, i.e. proportionate, and check whether there are less intrusive measures that could achieve the same effect, i.e. whether they are subsidiary. You do not want to burden employees unnecessarily with checks and must guard against unnecessary infringements of employees’ privacy.
In the case of the sales representative, the following additional measures could be taken, for example: mandatory screening of new customers by a department or employee other than the representative, and the presence of two employees during crucial negotiations with the potential customer.