PHIG Policy Framework v1.2 · Policy 23 · Adopted 1 September 2026 · References: ASF Policy 14; EU MGA Art. 11 and 25; USAID mandatory disclosures (2 CFR 200.113) and ADS 596; WHO contractor reporting obligations
1. Purpose and scope
To ensure that incidents — safety, security, safeguarding, PSEAH, fraud, data breaches, loss of assets, reputational events — are recorded, investigated, resolved and learned from, and that donors are informed as their rules require. Applies to the Board, the Director, staff, consultants, volunteers, experts, partners and suppliers of PHIG and all platforms of its network.
2. Policy
- Every incident is reported to the Director within 24 hours of becoming known (safeguarding and PSEAH to the Safeguarding Lead; integrity matters through the Whistleblowing Procedure).
- Incidents are logged in a register with date, nature, persons involved (coded), immediate action, investigation, outcome and lessons.
- Investigations are proportionate, impartial, confidential and completed within 30 working days where possible; persons concerned are heard.
- Serious incidents are reported to the Board without delay and to donors as required (see Disclosure to Donors).
- Data breaches follow the Data Protection Policy (72-hour notification); crimes are reported to the police.
- Lessons are reviewed quarterly and controls adjusted.
3. Procedures
- Incident form; register; quarterly review; annual summary to the Board.
Responsibilities
Director; Safeguarding Lead; Integrity Officer; Board.
Review
Every two years and when donor rules change.
Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).