Your IP : 216.73.217.79


Current Path : /var/www/cesa.co.za/echasl23/pdfexport/
Upload File :
Current File : /var/www/cesa.co.za/echasl23/pdfexport/rptADQFirm1469.html

<html><head>
<style>
.printhide { display:none; }
</style>
</head>
<body>
    <style>
        .adecqtable tr td {
            border:1px solid #333333;
            /*	border-width:0px 1px 0px 1px; */
            padding:5px !important;
        }
    </style>

    
    <h1>The CESA Management System Declaration (MSD) for a FIDIC Integrity Management System (FIMS)</h1>
    <h2>DNA Consulting Engineers & Project Managers</h2>
            <h3>MSD Submitted on 2023-02-20                , Score: 94.12%
                                , Verified on 2023-10-30                                    , Verified Score: 100.00%
                            </h3>
            <form method="post" action="rptADQFirm.php">
        <input type="hidden" name="go" value="Audit">
        <input type="hidden" name="ADQFirmID" value="1469">
        <table border="1" cellspacing="0" cellpadding="5" width="100%" class="adecqtable">
                                <tr>
                        <td><b>No.</b></td><td><b>Ref1</b></td><td><b>Ref2</b></td><td width="40%"><b>Declaration</b></td><td colspan="5"><b>Level of System Development</b></td>
                    </tr>
                    <tr><td colspan="4"><p>
                                Please consult the '<strong>Procedure: CESA Management System Declarations (MSDs)</strong>'
                                for guidance on how to complete the Management System Declaration.
                                <a href="https://www.cesa.co.za/uploads/20201114_-_CESA_MSD_Procedure_-_Final_draft_CC_DL_review.pdf" target="_blank">Click here</a>
                                to view the Procedure.
                            </p></td><td><b>Answer</b></td><td><b>If yes, have evidence for verification</b></td><td><b>If NA, give justification</b></td>
                        <td><b>Review</b></td></tr>
                                            <tr>
                            <td valign="top">0</td>
                            <td valign="top"></td>
                                                            <td valign="top"></td>
                                                        <td valign="top">Has your organisation been certified by an independent body to a set of internationally recognised integrity management requirements such as the ISO 37001 standard? Please note ISO9001:2015 does not qualify as certification of an integrity management system incorporating an anti-bribery framework. For more information please refer to Part III - FIMS and ISO 37001 Procedures 1st Edition which can be downloaded <a href="https://fidic.org/sites/default/files/FIMS%20III_OCTOBER%202019_FINAL%20VERSION.pdf" target="_blank">here</a> for free.<br><br>
                                <i></i>
                            </td>
                            <td valign="top" align="center">
                                No                            </td>
                            <td valign="top"></td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">1</td>
                            <td valign="top">5, 7</td>
                                                            <td valign="top">3.2</td>
                                                        <td valign="top">Has top management documented an integrity policy statement which considers the strategic objectives of the organisation?<br><br>
                                <i>The integrity policy should be developed in consultation with middle and senior managers and should outline the concept and objectives with regard to integrity management.  The strategic objectives of the company should be considered as these can impact on the policy e.g. working with governments or in countries which have significant reputations for corruption.  When new lines of business or new countries of operation are identified, the policy statement should be reviewed and updated accordingly.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Integrity policy is documented and signed by CEO.</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">2</td>
                            <td valign="top">7</td>
                                                            <td valign="top">4.1, 5</td>
                                                        <td valign="top">Has the company appointed a management representative / ethics and compliance officer who is responsible for the administration and communication of the integrity management system?<br><br>
                                <i>The representative / officer should be a senior member of the company who has the independence and authority to report directly to the CEO, Partners, Board of Directors etc.  The representative / officer must demonstrate willingness to take necessary actions if an integrity issue arises.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">A Quality Management System Representative is appointed, and is currently responsible for the administration and communication of the management system. There are also policies in place, such as an ethics policy, which each staff member is required to sign and adhere to.</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">3</td>
                            <td valign="top">5, 7</td>
                                                            <td valign="top">4, 4.2, 4.2.2</td>
                                                        <td valign="top">Has the company identified potential areas of integrity risks that the company faces, and incorporated action plans into their integrity management system to overcome these risks?<br><br>
                                <i>The company should consider how corrupt practises could impact their business and what mitigating action should be taken if these risks should arise.  The company can then design their integrity management system around these potential risks.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Risk register being maintained</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">4</td>
                            <td valign="top">5, 7, 8, App B</td>
                                                            <td valign="top">3.1, 4.3<br />
5<br />
5.1<br />
5.4<br />
App A<br />
</td>
                                                        <td valign="top">Does the company have a documented, internal code of conduct?<br><br>
                                <i>The code of conduct should explicitly prohibit the following corrupt practises :<br />
<b>&middot;</b> Bribery (giving/offering bribes/facilitations payments etc.)<br />
<b>&middot;</b> Collusion (price fixing/manipulation of prices/specs etc.)<br />
<b>&middot;</b> Fraud (concealing/submitting false credentials etc.)<br />
<b>&middot;</b> Extortion (threatening a third party etc.)<br />
<b>&middot;</b> Conflict of interest (ignoring existing relationships etc.)<br />
</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Internal code of conduct signed by all staff on appointment </td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">5</td>
                            <td valign="top">6, 7</td>
                                                            <td valign="top">5.3</td>
                                                        <td valign="top">Does the company have sufficient documentation in place detailing disciplinary actions taken against staff violating the requirements of the code of conduct? <br><br>
                                <i>The company can also consider positive incentives for employees observing and promoting the code of conduct within the organisation.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Disciplinary code signed by each staff member on appointment</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">6</td>
                            <td valign="top"></td>
                                                            <td valign="top">5, 5.2, 5.3</td>
                                                        <td valign="top">Does the company have a mechanism in place for the detection of corrupt practices?<br><br>
                                <i>Detection can include an anonymous reporting mechanism for employees to report wrongdoing by internal or external persons, centralisation of gift registries for the logging of items received etc.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Check sheets in place . Discussed at monthly meetings. Immediate notification to senior manager</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">7</td>
                            <td valign="top">6, 8</td>
                                                            <td valign="top">4, 4.3, 5.4<br />
App B<br />
</td>
                                                        <td valign="top">Does the company induct / train / communicate the importance of the integrity management system to its staff?<br><br>
                                <i>The company should ensure that new employees as well as existing employees are aware of the contents of the system with special emphasis on Integrity Policy Statement, Integrity procedures, Code of Conduct, consequences of violating the Code of Conduct, reporting mechanisms used by the company to identify corrupt practises etc.  Evidence should be retained in the form of training records, minutes of meetings etc.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Part of induction and annual training review</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">8</td>
                            <td valign="top">6, 8</td>
                                                            <td valign="top">4<br />
4.2.1<br />
5, 5.4<br />
</td>
                                                        <td valign="top">Does the company conduct training for senior management on integrity risk identification and planning on projects?<br><br>
                                <i>The company should be able to identify projects which could pose a potential integrity risk to the organisation and should appoint competent, senior staff to oversee these projects.  These staff should have appropriate training or experience in dealing with integrity risk.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Is part of our training programme</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">9</td>
                            <td valign="top"></td>
                                                            <td valign="top">4<br />
4.2<br />
4.2.1<br />
4.3<br />
5.1<br />
5.4<br />
App B<br />
</td>
                                                        <td valign="top">Does the company identify projects which could pose a potential integrity risk to the firm and does the company analyse the impact of these risks on the organisation projects prior to committing to the project?<br><br>
                                <i>The analysis can include an initial risk assessment which can consider geographical location, type of client / funder, type of contract, mechanism for selection, type and level of sub-contracting, industry reputations of key stakeholders etc.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Supplier risk register maintained and reviewed by management</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">10</td>
                            <td valign="top">8</td>
                                                            <td valign="top">4.2.1 4.2.2<br />
4.3<br />
5.1<br />
5.4<br />
App B<br />
</td>
                                                        <td valign="top">Does the company conduct due diligence assessments on clients, contracting parties, sub-consultants, suppliers etc. to ensure that the company enters into agreements with ethical parties?<br><br>
                                <i>The company must ensure that appropriately structured contracts are put into place, including anti-corruption provisions especially on contracts that bind parties who jointly bid on projects.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Supplier assessments carried out after each transaction and scored.</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">11</td>
                            <td valign="top"></td>
                                                            <td valign="top">4.2.3<br />
App B<br />
</td>
                                                        <td valign="top">Does the company identify situations of potential conflicts of interest on projects?<br><br>
                                <i>Conflicts of interest can arise in the following situations:<br />
<b>&middot;</b> Conflict between consulting activities and procurement of goods, works or services<br />
<b>&middot;</b> Conflict among consulting assignments<br />
<b>&middot;</b> Conflict among relationships with a client's staff etc.<br />
Should conflict of interest arise on a project, this disclosure should be documented and addressed on the project.<br />
</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Declaration by team members sign to declare any conflict of interest on every meeting register.</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">12</td>
                            <td valign="top"></td>
                                                            <td valign="top">4, 4.2.2<br />
4.3 5.4<br />
App B<br />
</td>
                                                        <td valign="top">Should it be identified that a third party has a reputation for corruption and the company enters into an agreement with this third party or that a conflict of interest does exist, does the company manage these risks through each stage of project delivery?<br><br>
                                <i>The risk identified can be captured onto the project plan or risk assessment and action plans must be put into place to mitigate these risks.  These plans / assessments must be reviewed on a regular basis and the effectiveness of actions taken must be evaluated to ensure that the risk can be effectively closed out.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Reviewed after each stage on project checklist</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">13</td>
                            <td valign="top">8</td>
                                                            <td valign="top">4<br />
4.2.1<br />
4.2.2<br />
5.2<br />
App B<br />
</td>
                                                        <td valign="top">Does the company audit projects, especially those with a high integrity risk to the firm, in order to detect potential corruption?<br><br>
                                <i>Audits should include a review of financial records, project records (such as risk assessments, project plans etc.).  These audits can be conducted by the integrity representative or internal auditor, depending on the company.  Outcomes form the audit must be documented and communicated to the project team.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Audited and signed off by senior engineer after each stage</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">14</td>
                            <td valign="top">7</td>
                                                            <td valign="top">5.3<br />
5.5<br />
</td>
                                                        <td valign="top">Does the company monitor compliance to the Integrity Policy, Integrity Procedures and Code of Conduct?<br><br>
                                <i>Compliance can be reviewed in the employee's performance review.  KPIs associated with integrity management can be established and employees can be rewarded or sanctioned based on the achievement of the agreed KPIs.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Each member signs a code of conduct as part of employment contract</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">15</td>
                            <td valign="top">5, 6</td>
                                                            <td valign="top"></td>
                                                        <td valign="top">Does the company respond to alleged or actual wrongdoing and take appropriate action to ensure that corruption is removed and that relevant disciplinary actions are undertaken, and sufficient records are maintained?<br><br>
                                <i>Detection methods can include whistle blowing, registries, audits etc.  In all case where corruption is detected, the company must ensure that detailed documentation relating to the nature of the corruption and associated actions are retained.  In the event of criminal behaviour, the company should immediately report the corruption to the relevant law enforcement authorities.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">All members you have potential of conflict is moved out of project. Warnings given per disciplinary code signed by each staff member</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">16</td>
                            <td valign="top">7</td>
                                                            <td valign="top">5, 5.4<br />
5.5<br />
</td>
                                                        <td valign="top">Are the results of monitoring and incidents of alleged or actual wrongdoing reported to management at an annual review so the that improvements to the system can be agreed and implemented? <br><br>
                                <i>Top management should meet on a regular basis to review results and document recommendations for improvement which can be made to the integrity management system.</i>
                            </td>
                            <td valign="top" align="center">
                                No                            </td>
                            <td valign="top">It is communicated privately to senior management and shared with staff through lessons learnt.</td>
                            <td valign="top"></td>
                            <td>
                                Verified<p></p>                            </td>
                        </tr>
                                                <tr>
                            <td valign="top">17</td>
                            <td valign="top">5</td>
                                                            <td valign="top">5.5</td>
                                                        <td valign="top">Is the company aware of and does it comply to local laws and client guidelines, rules and regulations regarding corruption?<br><br>
                                <i>Links to some statutory and regulatory requirements are included below.<br />
<br />
South Africa's primary legislation on corruption:<br />
<a href="https://www.gov.za/sites/default/files/gcis_document/201409/a12-04.pdf">Prevention and Combating of Corrupt Activities, Act 12 of 2004</a><br />
<br />
CESA<br />
<a href="https://www.cesa.co.za/cesa-founding-documents/">CESA Code of Conduct</a><br />
<a href="https://www.cesa.co.za/wp-content/uploads/2010/06/110728-Revised-CESA-Disciplinary-Procedure-November-2010-1.pdf">Disciplinary Actions for violations to the Code of Conduct</a><br />
<br />
It is important that the company is aware of new developments and/updates to anti-corruption legislation and that these are included into the Integrity Management System and communicated to interested parties.</i>
                            </td>
                            <td valign="top" align="center">
                                Yes                            </td>
                            <td valign="top">Unethical behavior document and training conducted. </td>
                            <td valign="top"></td>
                            <td>
                                Verified With Comments<p>General recommendation: consider adding a specific reference to Integrity Management in existing company documentation. Also, consider the forms and workflow examples in "Guidelines for Integrity Management System in the Consulting Industry (1st Edition) 2015 Part 2" for future improvement.</p>                            </td>
                        </tr>
                                                <tr>
                            <td colspan="4" valign="top">Name of competent person completing the MSD<br><br>
                                <i>Member firms must ensure that the integrity declaration is completed by the relevant functional head / manager for integrity or similar competent person. Member firms must ensure that this competent person, is available at the verification review, if such is requested by CESA.  During the verification review, the competent person will be asked to present evidence or justification to verify each declaration made on the MSD.</i></td>
                            <td colspan="5" valign="top">
                                Dayalen Naidoo                            </td>
                        </tr>
                                </table>
            </form>
    </body></html>