Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Trust & firm

Trust & firm

Confidentiality

No engagement information is communicated to the supplier's client or third party without explicit written authorisation, except where legally required.

Decide who can see what

Confidentiality becomes a circulation rule: every recipient, every purpose and every transmission must be authorised.

Before any substantive analysis, the file is defined by its owners, authorised recipients and permitted uses; the supplier retains control over any sharing with their client.

No implicit transmission

An item received to qualify an engagement cannot be reused, shown to the end client or handed to a third party as a matter of convenience.

Authorisation workflow

Mission information never changes recipient as a matter of mere convenience.

01

Confidentiality review before substantive processing

02

Confidentiality agreement where relevant

03

Authorised recipients and purposes

04

Minimisation, retention and deletion

Putting into practice

Control the recipients of each piece of information shared.

Classify

Identify the owner, sensitivity and restrictions attached to the information.

Authorise

Establish the recipients and the permitted use before sharing.

Submit

Limit content to actual need and retain the decision on whether to share it.

Remove

Revoke access and handle copies once the purpose has ended.

Checkpoints

01

Information

Element or set precisely concerned.

02

Recipient

Person, entity or role authorised to consult it.

03

Authorisation

Written decision and purpose of the sharing.

04

Trace

Date, scope, restriction and any withdrawal.

Movement within the client's premises

Trace why and with whom information was shared.

The register retains the owner, the restriction and the authorisation; the trust room only publishes items expressly selected for a given audience.

Review sharing decisions →
European client → Contract → Requirement
Promise → Policy → Practice → Platform
Evidence → Verification → Exception
Technical drift → Affected commitment
Remediation → Residual risk → Deadline

Preliminary exchange

Define the information-sharing rules from the very first exchange.

Specify the information concerned, its possible recipients and any restrictions already imposed by the contract or your organisation.

Ask a question