ATO Assistant Commissioner and Chief Risk Officer Karmin Van Grossen
Integrity is built at scale through everyday decisions, visible leadership and strong controls. Karmin Van Grossen, ATO Assistant Commissioner, Chief Risk Officer, shares her thoughts on maintaining integrity, hard and soft integrity controls, and building an integrity culture.
‘Integrity is shaped more by everyday decisions than formal policies. From my perspective as the ATO’s Chief Risk Officer, Integrity at scale implies that there is a strong culture of integrity throughout the organisation. As with any large organisation there can be many different sub-cultures across branches and teams. To achieve integrity at scale I’d expect there to be a consistent foundation of a pro-integrity culture regardless of area or function’.
The role of leadership
Leadership and role modelling from the top are vital to maintaining integrity consistently, at scale. People need to see integrity in action, through every decision and more generally through how people behave. ‘Ultimately,’ says Karmin, ‘a strong integrity culture would empower staff to call out and challenge non-integrous behaviours.’
‘It is absolutely vital that senior leaders act with integrity in how they conduct themselves, and practice what they preach. Highlighting expectations for staff around what integrity looks like in practice, utilising case studies to illustrate expectations and consequences at every opportunity. Creating a psychosocial environment where staff are encouraged and feel safe to speak-up. Where there is disagreement or difference of opinion is a good sign that there is a healthy culture of integrity.’
Risk and control frameworks to support integrity
Karmin notes that risk and control frameworks that support integrity in practice can generally fall under ‘hard’ or ‘soft’ controls – hard controls actually prevent actions such as a system access control, whereas soft controls rely on people following processes or policies. In people-related decisions there are both hard controls, such as pre-engagement integrity checks, and soft controls, for example policy expectations of merit-based decisions.
Karmin explains: ‘It is important that we have sufficient risk management practices and effective controls in place to manage integrity related risks. Control testing is an area that I believe organisations need to spend more time on to ensure that controls are working as intended to prevent risks occurring.’
‘For HR professionals and hiring managers, pre-engagement integrity checks are an obvious integrity control to prevent recruitment of staff that may pose integrity risks. Also setting clear integrity expectations with onboarded staff upfront, to embed an integrity culture, such as APS Values and Code of Conduct.’
Responsiveness, agility and assurance
A challenge to be explored is how to balance the need to be responsive and agile with the need to uphold strong governance and assurance, especially with the added challenges that AI brings. Organisations need to move quickly but also ensure that adequate safeguards are in place.
‘There is emerging thinking around adoption of more agile governance practices i.e. how can organisations embed iterative decision making, close to real-time risk/performance metrics and continuous assurance,’ says Karmin.
The speed of data and digital transformation is also creating challenges for organisations, across many fronts especially the management of appropriate governance processes to ensure risk appetite is considered and consistently applied. From a personnel security perspective, access and audit logging controls are areas that require attention to ensure the right people have access to the right systems and data in accordance with their role and duties.
One last piece of advice
Karmin has a final piece of advice for HR professionals working to strengthen integrity in their systems, processes, and decision making. ‘I think most importantly, the one piece of advice I would offer is to undertake insider threat risk assessments, identify the critical controls that manage these risks and test the effectiveness of those controls. Too often organisations can become complacent in believing controls are working as intended to minimise risk, without actually validating that to be true, resulting in overconfidence and underestimation of risk exposure.’