Your IP : 216.73.217.79


Current Path : /var/www/cesa.co.za/echasl23/pdfexport/
Upload File :
Current File : /var/www/cesa.co.za/echasl23/pdfexport/rptADQFirm371.html

<html><head>
<style>
.printhide { display:none; }
</style>
</head>
<body>
<style>
.adecqtable tr td {
	border:1px solid #333333;
/*	border-width:0px 1px 0px 1px; */
padding:5px !important;
}
</style>
<p class="printhide"><a href="rptADecQuestionnaires.php?id=1">Return to Report</a></p>
<p class="printhide"><a href="exportpdf.php?from=rptADQFirm371.html&to=rptADQFirm371&o=landscape" target="_blank">Export to PDF</a></p>

<h1>The CESA Management System Declaration (MSD) for a FIDIC Integrity Management System (FIMS)</h1>
<h2>SCIP</h2>
<h3>Completed on 2022-03-07	, Score: 94.12%
	</h3>
<table border="1" cellspacing="0" cellpadding="5" width="100%" class="adecqtable">
				
<tr><td><b>No.</b></td><td><b>Ref1</b></td><td><b>Ref2</b></td><td width="40%"><b>Declaration</b></td><td colspan="5"><b>Level of System Development</b></td></tr>
<tr><td colspan="4"><p>
    Please consult the '<strong>Procedure: CESA Management System Declarations (MSDs)</strong>'
    for guidance on how to complete the Management System Declaration.
<a href="https://www.cesa.co.za/uploads/20201114_-_CESA_MSD_Procedure_-_Final_draft_CC_DL_review.pdf" target="_blank">Click here</a>
    to view the Procedure.
</p></td><td><b>Answer</b></td><td><b>If yes, have evidence for verification</b></td><td><b>If NA, give justification</b></td></tr>
<tr><td valign="top">1</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Has your organisation been certified by an independent body to a set of internationally recognised integrity management requirements?<br><br>
<i></i></td>
<td valign="top" align="center" style='background-color:red;color:white'>
No</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">2</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Certificate File<br><br>
<i>* please submit the certification; AND<br />
* In addition to answering the questions in the declaration, provide the following information:</i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">3</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Name of international requirements or standard<br><br>
<i></i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">4</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Name of independent certification body<br><br>
<i></i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">5</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Certificate Registration Number<br><br>
<i>(if available)</i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">6</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Validity from<br><br>
<i>(if applicable)</i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">7</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Validity to<br><br>
<i>(if applicable)</i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">8</td><td valign="top"></td>
<td valign="top"></td>
<td valign="top">Date of first certification<br><br>
<i></i></td>
<td valign="top" align="center">
</td>
<td valign="top"></td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">1</td><td valign="top">5, 7</td>
<td valign="top">3.2</td>
<td valign="top">Has top management documented an integrity policy statement which considers the strategic objectives of the organisation?<br><br>
<i>The integrity policy should be developed in consultation with middle and senior managers and should outline the concept and objectives with regard to integrity management.  The strategic objectives of the company should be considered as these can impact on the policy e.g. working with governments or in countries which have significant reputations for corruption.  When new lines of business or new countries of operation are identified, the policy statement should be reviewed and updated accordingly.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Documented Code of Business Conduct and Ethical Business Practice Policy</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">2</td><td valign="top">7</td>
<td valign="top">4.1, 5</td>
<td valign="top">Has the company appointed a management representative / ethics and compliance officer who is responsible for the administration and communication of the integrity management system?<br><br>
<i>The representative / officer should be a senior member of the company who has the independence and authority to report directly to the CEO, Partners, Board of Directors etc.  The representative / officer must demonstrate willingness to take necessary actions if an integrity issue arises.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Appointment</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">3</td><td valign="top">5, 7</td>
<td valign="top">4, 4.2, 4.2.2</td>
<td valign="top">Has the company identified potential areas of integrity risks that the company faces, and incorporated action plans into their integrity management system to overcome these risks?<br><br>
<i>The company should consider how corrupt practises could impact their business and what mitigating action should be taken if these risks should arise.  The company can then design their integrity management system around these potential risks.</i></td>
<td valign="top" align="center" style='background-color:red;color:white'>
No</td>
<td valign="top"></td>
<td valign="top">A formal business risk assessment must be executed</td>
</tr>				
<tr><td valign="top">4</td><td valign="top">5, 7, 8, App B</td>
<td valign="top">3.1, 4.3<br />
5<br />
5.1<br />
5.4<br />
App A<br />
</td>
<td valign="top">Does the company have a documented, internal code of conduct?<br><br>
<i>The code of conduct should explicitly prohibit the following corrupt practises :<br />
<b>&middot;</b> Bribery (giving/offering bribes/facilitations payments etc.)<br />
<b>&middot;</b> Collusion (price fixing/manipulation of prices/specs etc.)<br />
<b>&middot;</b> Fraud (concealing/submitting false credentials etc.)<br />
<b>&middot;</b> Extortion (threatening a third party etc.)<br />
<b>&middot;</b> Conflict of interest (ignoring existing relationships etc.)<br />
</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Documented Code of Business Conduct and Ethical Business Practice Policy</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">5</td><td valign="top">6, 7</td>
<td valign="top">5.3</td>
<td valign="top">Does the company have sufficient documentation in place detailing disciplinary actions taken against staff violating the requirements of the code of conduct? <br><br>
<i>The company can also consider positive incentives for employees observing and promoting the code of conduct within the organisation.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Company disciplinary policy</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">6</td><td valign="top"></td>
<td valign="top">5, 5.2, 5.3</td>
<td valign="top">Does the company have a mechanism in place for the detection of corrupt practices?<br><br>
<i>Detection can include an anonymous reporting mechanism for employees to report wrongdoing by internal or external persons, centralisation of gift registries for the logging of items received etc.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">We are currently using our Non-Conformance system</td>
<td valign="top">An anonymous reporting mechanism will be considered in our improvement and development plan </td>
</tr>				
<tr><td valign="top">7</td><td valign="top">6, 8</td>
<td valign="top">4, 4.3, 5.4<br />
App B<br />
</td>
<td valign="top">Does the company induct / train / communicate the importance of the integrity management system to its staff?<br><br>
<i>The company should ensure that new employees as well as existing employees are aware of the contents of the system with special emphasis on Integrity Policy Statement, Integrity procedures, Code of Conduct, consequences of violating the Code of Conduct, reporting mechanisms used by the company to identify corrupt practises etc.  Evidence should be retained in the form of training records, minutes of meetings etc.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Attendance Registers</td>
<td valign="top">We are currently working on the implementation of an induction programme and IM will form part of this programme. 
 Training is planned for later in the year</td>
</tr>				
<tr><td valign="top">8</td><td valign="top">6, 8</td>
<td valign="top">4<br />
4.2.1<br />
5, 5.4<br />
</td>
<td valign="top">Does the company conduct training for senior management on integrity risk identification and planning on projects?<br><br>
<i>The company should be able to identify projects which could pose a potential integrity risk to the organisation and should appoint competent, senior staff to oversee these projects.  These staff should have appropriate training or experience in dealing with integrity risk.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Training matrix and Course certificates</td>
<td valign="top">Training will be conducted later in the year</td>
</tr>				
<tr><td valign="top">9</td><td valign="top"></td>
<td valign="top">4<br />
4.2<br />
4.2.1<br />
4.3<br />
5.1<br />
5.4<br />
App B<br />
</td>
<td valign="top">Does the company identify projects which could pose a potential integrity risk to the firm and does the company analyse the impact of these risks on the organisation projects prior to committing to the project?<br><br>
<i>The analysis can include an initial risk assessment which can consider geographical location, type of client / funder, type of contract, mechanism for selection, type and level of sub-contracting, industry reputations of key stakeholders etc.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Indicated in Project Engineer Checklist</td>
<td valign="top">Formal risk assessment must be set up for high risk projects. This forms part of our improvement and development of our IMS.</td>
</tr>				
<tr><td valign="top">10</td><td valign="top">8</td>
<td valign="top">4.2.1 4.2.2<br />
4.3<br />
5.1<br />
5.4<br />
App B<br />
</td>
<td valign="top">Does the company conduct due diligence assessments on clients, contracting parties, sub-consultants, suppliers etc. to ensure that the company enters into agreements with ethical parties?<br><br>
<i>The company must ensure that appropriately structured contracts are put into place, including anti-corruption provisions especially on contracts that bind parties who jointly bid on projects.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Appropriately structured contracts</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">11</td><td valign="top"></td>
<td valign="top">4.2.3<br />
App B<br />
</td>
<td valign="top">Does the company identify situations of potential conflicts of interest on projects?<br><br>
<i>Conflicts of interest can arise in the following situations:<br />
<b>&middot;</b> Conflict between consulting activities and procurement of goods, works or services<br />
<b>&middot;</b> Conflict among consulting assignments<br />
<b>&middot;</b> Conflict among relationships with a client's staff etc.<br />
Should conflict of interest arise on a project, this disclosure should be documented and addressed on the project.<br />
</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Confirmation of appointment letter</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">12</td><td valign="top"></td>
<td valign="top">4, 4.2.2<br />
4.3 5.4<br />
App B<br />
</td>
<td valign="top">Should it be identified that a third party has a reputation for corruption and the company enters into an agreement with this third party or that a conflict of interest does exist, does the company manage these risks through each stage of project delivery?<br><br>
<i>The risk identified can be captured onto the project plan or risk assessment and action plans must be put into place to mitigate these risks.  These plans / assessments must be reviewed on a regular basis and the effectiveness of actions taken must be evaluated to ensure that the risk can be effectively closed out.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">We do this through out the project life cycle but currently it is not a formal process and not documented</td>
<td valign="top">Action plans and risk assessments must be formalised and documented, this forms part  of our improvement and development of our IMS.</td>
</tr>				
<tr><td valign="top">13</td><td valign="top">8</td>
<td valign="top">4<br />
4.2.1<br />
4.2.2<br />
5.2<br />
App B<br />
</td>
<td valign="top">Does the company audit projects, especially those with a high integrity risk to the firm, in order to detect potential corruption?<br><br>
<i>Audits should include a review of financial records, project records (such as risk assessments, project plans etc.).  These audits can be conducted by the integrity representative or internal auditor, depending on the company.  Outcomes form the audit must be documented and communicated to the project team.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Internal audits, but is not currently formalised and documented</td>
<td valign="top">A intenral audit report must be formalised and documented, this forms part  of our improvement and development of our IMS.</td>
</tr>				
<tr><td valign="top">14</td><td valign="top">7</td>
<td valign="top">5.3<br />
5.5<br />
</td>
<td valign="top">Does the company monitor compliance to the Integrity Policy, Integrity Procedures and Code of Conduct?<br><br>
<i>Compliance can be reviewed in the employee's performance review.  KPIs associated with integrity management can be established and employees can be rewarded or sanctioned based on the achievement of the agreed KPIs.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">By means of non-conformance process</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">15</td><td valign="top">5, 6</td>
<td valign="top"></td>
<td valign="top">Does the company respond to alleged or actual wrongdoing and take appropriate action to ensure that corruption is removed and that relevant disciplinary actions are undertaken, and sufficient records are maintained?<br><br>
<i>Detection methods can include whistle blowing, registries, audits etc.  In all case where corruption is detected, the company must ensure that detailed documentation relating to the nature of the corruption and associated actions are retained.  In the event of criminal behaviour, the company should immediately report the corruption to the relevant law enforcement authorities.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Record of actions put in place including solutions</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">16</td><td valign="top">7</td>
<td valign="top">5, 5.4<br />
5.5<br />
</td>
<td valign="top">Are the results of monitoring and incidents of alleged or actual wrongdoing reported to management at an annual review so the that improvements to the system can be agreed and implemented? <br><br>
<i>Top management should meet on a regular basis to review results and document recommendations for improvement which can be made to the integrity management system.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Included in management review meeting agenda</td>
<td valign="top"></td>
</tr>				
<tr><td valign="top">17</td><td valign="top">5</td>
<td valign="top">5.5</td>
<td valign="top">Is the company aware of and does it comply to local laws and client guidelines, rules and regulations regarding corruption?<br><br>
<i>Links to some statutory and regulatory requirements are included below.<br />
<br />
South Africa's primary legislation on corruption:<br />
<a href="https://www.gov.za/sites/default/files/gcis_document/201409/a12-04.pdf">Prevention and Combating of Corrupt Activities, Act 12 of 2004</a><br />
<br />
CESA<br />
<a href="https://www.cesa.co.za/cesa-founding-documents/">CESA Code of Conduct</a><br />
<a href="https://www.cesa.co.za/wp-content/uploads/2010/06/110728-Revised-CESA-Disciplinary-Procedure-November-2010-1.pdf">Disciplinary Actions for violations to the Code of Conduct</a><br />
<br />
It is important that the company is aware of new developments and/updates to anti-corruption legislation and that these are included into the Integrity Management System and communicated to interested parties.</i></td>
<td valign="top" align="center">
Yes</td>
<td valign="top">Circulation of relevant laws and discussions during meetings</td>
<td valign="top"></td>
</tr>				
<tr>
<td colspan="4" valign="top">Name of competent person completing the MSD<br><br>
<i>Member firms must ensure that the integrity declaration is completed by the relevant functional head / manager for integrity or similar competent person. Member firms must ensure that this competent person, is available at the verification review, if such is requested by CESA.  During the verification review, the competent person will be asked to present evidence or justification to verify each declaration made on the MSD.</i></td>
<td colspan="5" valign="top">
Philip Booyens</td>
</tr>				
</table>
</body></html>