General Safeguards
fade-up
fade-up
container
- Lay down the policy and procedure for the company’s various business functions.
- Define clearly the roles and responsibilities of each level of staff or post and the authorities for making decisions in various functions.
- Ensure that the guidelines are understood by the staff concerned through briefing or training.
- Update the policies, guidelines and procedures to suit the company’s operation as necessary.
fade-up
container
- Segregate duties in important business processes as far as practicable.
- Ensure that important processes performed by a single staff member are counter-checked at random (or in full) and audited as resources permit.
fade-up
container
- Require the staff to keep proper record of the activities carried out and their decisions.
- Safeguard important records and documents to prevent tampering.
fade-up
container
- Classify the company’s information (i.e. confidential and open information) and make sure that all staff are aware of the classification of the information they handle.
- Define information access authorities and require staff to take measures to protect the information in their possession (e.g. lock up documents or activate personal password control in the computer).
- Build in security safeguards to protect data and records in the computer system (e.g. restriction on data amendments and access control).
fade-up
container
- Require supervisors to make spot checks on the operations and business transactions as appropriate to deter and detect irregularities.
- Establish an information management system whereby the staff are required to report regularly the major business activities and trends to the senior management and the board of directors, as appropriate, to facilitate monitoring.
fade-up
container
- Establish a user-friendly channel, pledging confidentiality for complaint/feedback from both customers and staff on the activities or operations of the company.
- Assign an independent staff member at the appropriate level to investigate into any irregularities reported to ensure impartiality.
- For any suspected corruption or other crimes, remind staff to report to appropriate law enforcement agency (e.g. ICAC) as appropriate.
fade-up
container
- Put in place an internal audit function to independently evaluate the effectiveness of risk management, control and governance processes.
- Ensure that the internal audit function:
- is independent from the operation under audit, sufficiently staffed by staff of appropriate qualification and training, has unfettered access to all records, and can obtain and explanations as necessary.
- develops an audit programme setting out the auditing assignments to be performed and conducts regular review on the programme based on risks.
- reports directly to the Audit Committee, if established, or the senior management and draws their immediate attention to any significant irregularities detected.
- Give due consideration to the findings of the internal audit function and take timely actions in response to its recommendations.