8.10 - Investigating and dealing with cases of bribery : Confidentiality of investigation results

ISO 37001

 The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.

 How to Answer the Question

Defining Confidential Procedures : To safeguard the confidentiality of investigations and their outcomes, organizations need to:

-   Develop Specific Protocols  : Establish clear guidelines that define who has access to information related to investigations. For guidance on creating these protocols, check the [SHRM guide on conducting workplace investigations](https://www.shrm.org).

-   Secure Communication Channels  : Use secure platforms for sharing sensitive information during investigations. For examples of secure communication tools, visit the [University of Illinois System’s page on confidential reporting structures](https://www.ethics.uillinois.edu).

-   Training  : Ensure that all involved parties are trained on the importance of confidentiality and the specific measures in place to maintain it. Resources for confidentiality training can be found at [Financial Crime Academy](https://financialcrimeacademy.org).

Why It's Important  

Maintaining the confidentiality of investigation processes and results is critical for:

-   Protecting the Integrity of the Investigation  : Confidentiality prevents the contamination of the investigative process and helps in gathering unbiased and truthful information.

-   Safeguarding Individual Privacy  : It protects the privacy of all parties involved and encourages openness in reporting wrongdoing without fear of retaliation.

-   Preventing Unnecessary Harm  : It helps to avoid reputational damage to individuals and the organization that could arise from unverified or sensitive allegations.

For more on balancing confidentiality with transparency, visit [LinkedIn’s article on the subject](https://www.linkedin.com).

Examples  

-   Example A  :

 -   Context  : A finance company discovers a potential embezzlement case.

 -   Action  : The investigation is conducted under strict confidentiality with details accessible only to the compliance team and senior management.

 -   Outcome  : The careful handling of sensitive information prevented undue panic and preserved the reputational integrity of the involved parties and the firm.

 - For similar strategies, refer to the [University of Nevada’s guidelines on maintaining data confidentiality](https://www.unr.edu).

-   Example B  :

 -   Context  : A healthcare provider deals with allegations of patient data mishandling.

 -   Action  : An internal committee is formed, and all communications are encrypted to ensure that investigation details remain confidential.

 -   Outcome  : The privacy of the individuals involved was protected, and the investigation concluded without any breach of confidentiality.

 - Explore [University of Delaware’s resources](https://www1.udel.edu) on managing data confidentiality for more information.

These examples illustrate how effectively managed confidentiality can protect both the integrity of the investigative process and the privacy of individuals involved. For further reading on ensuring confidentiality during investigations, the [Lexology article](https://www.lexology.com) offers practical tips on maintaining investigation confidentiality in various scenarios.