To help organisations getting started with an analysis of vulnerabilities at the position level, the Dutch Whistleblowers Authority (Huis voor Klokkenluiders) publishes a brochure on analysing risk-sensitive roles, including a Risk analysis for organisations.

When promoting integrity, it is important for organisations to pay attention to risks in the workplace. Especially at the position level, organisations may have blind spots where integrity violations — and perhaps even wrongdoing — may eventually arise. Due to their positioning, often distanced from the primary work activities, it can be difficult for management or the board to gain insight into these blind spots.

Employees themselves, due to their daily work and routines, often do not notice where they may be at risk, or how attractive the resources, powers, or information they have access to, are to people with bad intentions. Moreover, circumstances within the organisation and in employees' personal lives can make them more vulnerable to integrity risks.

How likely is it that someone will approach an employee who has access to commercially sensitive information in order to obtain that information? To what extent do employees apply safety measures when there is high time pressure to get something done? Does a representative still make choices in the interest of the organisation when they have a close bond with clients? It is important to critically examine both the nature of the position and the consequences of personal conduct.

Risk analysis for organisations

The Authority recommends that organisations carry out a risk analysis of sensitive roles. Those who are aware of what could happen can more easily prepare and take measures to avoid or reduce risks in order protect both the organisation’s own operations and the wellbeing of its employees.

The Authority distinguishes the following steps in the analysis of vulnerabilities at the position level:

  1. Identifying the different role types within an organisation;
  2. Mapping, for each role type, which tasks and powers are susceptible to misuse by the employees, or by one or more third parties;
  3. Identifying the vulnerabilities that may increase this risk;
  4. Identifying existing measures that reduce this risk;
  5. Determining which measures still need to be taken to reduce the risk.

The brochure gives companies insight into the process and guidance for the actual implementation. Setting up a small working group to bring together different areas of expertise can lead to a better analysis. Small organisations may consider bringing in external expertise.

Brochure — digital and PDF

The brochure can be read as a magazine or downloaded as a PDF.