7.5.3 - Documented information : Documented information protection
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Answer the Question
When ensuring the availability, suitability, and adequate protection of documented information as part of an anti-corruption management system, organizations should:
1. Establish Robust Documentation Policies :
- Define what constitutes necessary documentation, including what should be recorded, how it should be maintained, and the duration for retention.
2. Implement Security Measures :
- Apply physical and digital security practices to protect documented information from unauthorized access, alteration, loss, or destruction.
3. Regular Audits and Updates :
- Conduct regular audits to ensure the documentation practices meet the required standards and update the documentation procedures as needed to address any identified gaps or vulnerabilities.
These strategies are supported by guidelines like ISO 37001, which provide frameworks for protecting critical information in an anti-corruption context.
Why It's Important
The protection of documented information is critical for:
- Ensuring Compliance : Proper documentation supports compliance with legal requirements and helps in demonstrating the organization’s commitment to anti-corruption efforts.
- Facilitating Audits : Well-maintained and protected records streamline the auditing process, making it easier to verify the integrity and effectiveness of the anti-corruption measures.
- Enhancing Transparency : Secure and accessible documentation ensures transparency in the organization's operations and supports accountability among stakeholders.
Examples
- Example A :
- Context : A financial institution recognized the need to enhance the security of its anti-bribery documentation.
- Action : It implemented encrypted digital storage solutions and established controlled access protocols.
- Outcome : The new system not only safeguarded sensitive information but also facilitated quicker retrieval during compliance audits.
- Example B :
- Context : A manufacturing company faced challenges with the physical storage of compliance documents, which were susceptible to damage.
- Action : The company transitioned to a cloud-based document management system, applying strict access controls and regular backups.
- Outcome : This change ensured the durability and availability of documentation, reducing the risk of loss and improving response times during legal inquiries.
For further guidelines on managing documented information within an anti-corruption framework, resources such as [ISO’s standards on documentation](https://www.iso.org) and the [International Anti-Corruption Academy’s best practices](https://www.iaca.int) can provide additional insights.