SECTION VIII – MONITORING, EVALUATION AND CONTINUOUS IMPROVEMENT
Chapter 30 – Risk Monitoring and Institutional Peace Indicators
CHAPTER 30 – RISK MONITORING AND INSTITUTIONAL PEACE INDICATORS
1. General Provisions
30.1 Purpose of this Chapter
This Chapter establishes HGT’s system for risk monitoring and institutional peace indicators, in order to:
a) track the overall “health” of HGT beyond finances and artifact protection;
b) identify early warning signs of conflict, harm or organisational breakdown; and
c) support timely, constructive responses that strengthen peace, ethics and resilience.
30.2 Foundations
This Chapter is guided by:
a) peace studies concepts of early warning, negative and positive peace, structural and cultural violence, and conflict transformation;
b) governance and risk management principles, including enterprise risk monitoring and continuous improvement;
c) HGT’s doctrinal-ethical framework, including Buddhist values of non-harm, right speech, mindful awareness and community harmony; and
d) the Compliance and Risk Management provisions in Chapter 9 and related chapters on safeguarding, HR, finance and heritage.
30.3 Scope
a) This Chapter applies to all departments and sites of HGT.
b) It covers:
i. development and use of institutional peace indicators;
ii. regular risk and wellbeing monitoring (including surveys);
iii. reporting to the Board, the Executive Director and the Ethics & Peace Committee; and
iv. integration of findings into decision-making and improvement plans.
2. Institutional Peace and Early Warning
30.4 Institutional Peace Concept
a) For HGT, “institutional peace” includes:
i. absence of open conflict, harassment and serious misconduct;
ii. presence of trust, cooperation and respectful dialogue;
iii. fair procedures, accountability and non-discrimination;
iv. effective safeguarding of people, heritage and faith.
b) Institutional peace is not only the absence of visible problems but the presence of positive conditions that allow HGT to serve its mission harmoniously.
30.5 Early Warning and Risk Signals
a) Peace studies emphasise that conflict often builds gradually, with early warning signs such as:
i. rising tension, rumours, cliques or polarisation;
ii. repeated minor complaints or grievances;
iii. exclusion of certain groups;
iv. silencing or fear of speaking up.
b) HGT shall pay attention to such signals and respond early with dialogue, mediation and structural adjustments where needed.
30.6 Relationship to Risk Management
a) Institutional peace indicators form part of HGT’s broader risk monitoring system (Chapter 9), complementing financial, legal, environmental and heritage risk indicators.
b) They help the Board and leadership see where internal culture and relationships may be at risk, even if formal compliance appears strong.
3. Institutional Peace Indicators
30.7 Indicator Framework
a) HGT shall develop and maintain a set of indicators to track institutional peace and wellbeing.
b) Indicators may be both quantitative (numbers, rates) and qualitative (narrative assessments, observations).
30.8 Core Indicator Areas
Institutional peace indicators may include, but are not limited to:
a) Complaints and Grievances
i. number and type of complaints received (HR, safeguarding, ethics, heritage, community relations);
ii. seriousness and patterns (e.g. repeated issues in one department);
iii. response times and resolution rates.
b) Staff and Volunteer Turnover
i. turnover rates by department or role;
ii. reasons for departure (from exit interviews or surveys);
iii. patterns suggesting burnout, dissatisfaction or conflict.
c) Participation and Inclusion
i. participation of different groups (gender, age, backgrounds) in committees, programmes and leadership pipelines;
ii. feedback on inclusion and fairness from staff, volunteers and community members.
d) Incident Trends
i. frequency and type of incidents (safeguarding, security, health and safety, heritage incidents);
ii. trends over time (increasing, decreasing, stable);
iii. recurrence of similar issues without adequate remedy.
e) Wellbeing and Morale
i. survey results on stress, workload, trust in leadership and perceived fairness;
ii. anecdotal reports of exhaustion, fear or conflict.
f) External Relations
i. feedback from partners and communities;
ii. recurring external criticisms or praise;
iii. media or public concerns related to HGT’s culture and conduct.
30.9 Disaggregation and Sensitivity
a) Where possible and lawful, indicators shall be disaggregated (e.g. by gender, role, site) to identify structural or cultural inequalities.
b) Analysis shall be sensitive and avoid revealing identities in small groups; safeguarding and privacy obligations must be respected.
30.10 Flexible and Evolving List
a) The list of indicators may evolve over time as HGT learns which measures are most meaningful.
b) The Ethics & Peace Committee and Compliance / Risk Officer may propose additions or modifications.
4. Regular Risk and Wellbeing Monitoring
30.11 Routine Data Collection
a) Departments shall collect and provide data relevant to institutional peace indicators, including:
i. HR data (turnover, grievances, absenteeism);
ii. safeguarding and complaints data (anonymised and aggregated);
iii. incident logs (security, health and safety, heritage);
iv. participation data in trainings, programmes and committees.
b) Data shall be summarised periodically (e.g. quarterly, annually) for analysis.
30.12 Wellbeing and Climate Surveys
a) HGT may conduct confidential surveys of staff, volunteers and, where appropriate, programme participants or community partners, to assess:
i. wellbeing and workload;
ii. perceptions of fairness, inclusion and safety;
iii. trust in conflict resolution mechanisms;
iv. experiences or perceptions of harassment or discrimination.
b) Surveys shall be designed to protect anonymity, especially for sensitive questions, and be conducted in a safe and voluntary manner.
30.13 Qualitative Feedback and Reflection
a) HGT shall complement numeric indicators with qualitative feedback, such as:
i. focus group discussions;
ii. reflective sessions in departments;
iii. feedback from spiritual and pastoral care conversations (respecting confidentiality).
b) Facilitators shall be trained to encourage honest sharing and handle sensitive topics respectfully.
30.14 Frequency of Monitoring
a) At minimum, key institutional peace indicators shall be reviewed annually at organisation-wide level.
b) Some indicators (e.g. serious incident trends) may be reviewed more frequently (e.g. quarterly) by relevant committees.
5. Analysis and Reporting
30.15 Analysis Responsibilities
a) The Compliance / Risk Officer, in collaboration with HR & Safeguarding and the Executive Director, shall coordinate analysis of institutional peace indicators.
b) The Ethics & Peace Committee shall play a central role in interpreting findings from an ethical and peace perspective.
30.16 Internal Reporting Lines
a) A consolidated Institutional Peace and Risk Report shall be prepared at least annually, summarising:
i. key indicator trends;
ii. areas of concern and areas of improvement;
iii. early warning signs and proposed responses.
b) This report shall be submitted to:
i. the Executive Director;
ii. the Board of Trustees;
iii. the Ethics & Peace Committee;
iv. the Audit & Risk Committee (where relevant to risk and control).
30.17 Presentation to Board and Committees
a) The Board shall receive a clear, accessible overview of institutional peace indicators linked to the broader risk register.
b) The Ethics & Peace Committee may provide an accompanying commentary, focusing on ethical culture, conflict dynamics and peace-building implications.
30.18 Feedback to Departments and Staff
a) Relevant findings shall be fed back to departments, sites and staff, in an anonymised and constructive way.
b) The goal is not to blame, but to encourage learning, transparency and shared responsibility for improvement.
6. Response and Continuous Improvement
30.19 Triggering Responses
a) Significant negative trends or early warning signs (e.g. rising harassment complaints, sharp turnover in a department, repeated safeguarding incidents) shall trigger appropriate responses, which may include:
i. dialogue and facilitated meetings;
ii. targeted training or supervision support;
iii. review of workloads, roles or procedures;
iv. external mediation or expert consultation;
v. formal investigations where necessary.
b) The level of response shall match the severity and nature of the risk.
30.20 Integration with Risk Register and Action Plans
a) Institutional peace indicators shall feed into HGT’s risk register (Chapter 9), with explicit entries for internal culture, safeguarding climate and community relations.
b) For significant risks, HGT shall develop documented action plans specifying responsibilities, timelines and follow-up measures.
30.21 Learning from Incidents and Trends
a) Individual serious incidents (e.g. major conflicts, abuse cases, public scandals) shall be analysed not only at case level but also for what they reveal about broader patterns.
b) Lessons learned may lead to policy revisions, structural adjustments, training programmes or new guidance.
30.22 Positive Reinforcement and Recognition
a) Indicators are not only for detecting problems; they also help identify positive developments (e.g. improved participation, lower conflict, greater inclusion).
b) HGT should recognise and reinforce good practices, so that institutional peace is celebrated and made visible as a shared achievement.
7. Ethics, Confidentiality and Participation
30.23 Ethical Use of Indicators
a) Institutional peace indicators must not be used to punish honesty or intimidate staff and communities.
b) Data shall be used in an ethical manner, supporting improvement, accountability and compassion, not surveillance or control for its own sake.
30.24 Confidentiality and Privacy
a) Collection and analysis of indicators must comply with Data Protection and Privacy policies (Chapter 29).
b) Reports to leadership shall be anonymised where necessary to protect individuals, especially in small teams or sensitive contexts.
30.25 Participation in Designing Indicators
a) Where feasible, staff, volunteers and representatives from key stakeholder groups should be consulted in designing or revising indicators and surveys.
b) Participation enhances relevance, trust and buy-in.
30.26 Protection from Retaliation
a) No one shall be punished or disadvantaged for contributing honest feedback, survey responses or concerns used in institutional peace monitoring.
b) Retaliation is a serious breach and shall be addressed under HR and safeguarding procedures.
8. Review and Evolution of the System
30.27 Periodic Review of Indicators and Processes
a) The Ethics & Peace Committee, together with the Compliance / Risk Officer and HR & Safeguarding, shall periodically review the adequacy of institutional peace indicators and related processes.
b) They may recommend additions, simplifications or changes based on experience and evolving best practice.
30.28 Integration with Strategic Planning
a) Findings from institutional peace monitoring shall inform HGT’s strategic planning, including priorities for capacity-building, governance reforms, staff support and community engagement.
b) Over time, HGT may set high-level peace and wellbeing goals with measurable targets, consistent with its mission and resources.
30.29 Amendment
a) This Chapter may be amended as HGT gains experience in monitoring institutional peace and as legal, social or doctrinal contexts evolve.
b) Amendments shall be approved in accordance with Chapter 3 and communicated to the Board, Ethics & Peace Committee and all relevant departments.
Chapter 31 – Evaluation, Learning and Policy Review
CHAPTER 31 – EVALUATION, LEARNING AND POLICY REVIEW
1. General Provisions
31.1 Purpose of this Chapter
This Chapter sets out HGT’s approach to evaluation, learning and policy review, in order to:
a) ensure HGT continually learns from experience, cases and incidents;
b) strengthen alignment between practice, doctrine, peace goals and governance standards; and
c) keep this Policy Manual and related procedures up to date, relevant and effective.
31.2 Foundations
This Chapter is guided by:
a) Buddhist principles of reflection, mindfulness, confession, self-correction and gradual cultivation;
b) good governance norms of periodic review, evidence-based reform and stakeholder participation;
c) HGT’s risk management and institutional peace framework (Chapters 9 and 30); and
d) HGT’s broader commitment to ethical custodianship, peace-building and SDG alignment.
31.3 Scope
a) This Chapter applies to:
i. internal and external evaluations of HGT’s programmes and operations;
ii. learning processes built around cases, incidents and experiences;
iii. formal review and amendment of this Policy Manual and related SOPs.
b) It covers all departments and sites, with specific responsibilities assigned below.
2. Evaluation Principles
31.4 Learning Orientation
a) Evaluation shall be approached primarily as a learning exercise, not as a tool for blame or humiliation.
b) Honest acknowledgement of limitations and mistakes is encouraged, consistent with Buddhist practice of self-examination and reform.
31.5 Participation and Respect
a) Wherever appropriate, evaluations shall involve the views of those affected by HGT’s work, including staff, volunteers, monastics in HGT roles, participants, community members and partners.
b) Participation must respect dignity, cultural context and safeguarding requirements.
31.6 Evidence and Reflection
a) Evaluations should combine:
i. evidence – data, observations, documented cases; and
ii. reflection – ethical, doctrinal and peace-oriented analysis of what the evidence means.
b) Findings should link back to HGT’s mission, H96 custodian ideals and the three-lens governance philosophy (Buddhist, peace, good governance).
3. Internal Evaluations of Programmes and Operations
31.7 Programme-Level Evaluation
a) Major programmes (e.g. education, peace training, heritage projects, community engagement) shall undergo periodic internal evaluations, which may include:
i. review of objectives and outcomes;
ii. analysis of participation and inclusion;
iii. feedback from participants and partners;
iv. assessment of unintended positive or negative effects.
b) Evaluations may be light or in-depth depending on the scale and risk of the programme.
31.8 Operational and Site Evaluations
a) Operational areas (e.g. site management, visitor services, relic custodianship, HR processes) may also be evaluated to assess:
i. efficiency and effectiveness;
ii. compliance with policies and law;
iii. impacts on staff wellbeing, institutional peace and community relations.
b) Site managers and department heads are responsible for cooperating with such evaluations.
31.9 Use of External Evaluations
a) Where required by donors, regulators or strategic needs, HGT may commission external evaluations for major projects or periods.
b) External evaluators shall be selected with attention to competence, independence and understanding of HGT’s religious and cultural context.
31.10 Evaluation Planning and Timing
a) Evaluations should be planned at the design stage of major programmes, including timing, questions and methods.
b) As a general guide, long-running programmes should be reviewed at least every few years, or sooner if serious issues emerge.
4. Use of Cases, Incidents and Experience as Learning Tools
31.11 Cases and Incidents as “Teachers”
a) HGT recognises that cases and incidents (e.g. conflicts, safeguarding issues, heritage problems, financial irregularities, near-misses) can serve as valuable teachers.
b) Each significant case or cluster of cases should be analysed not only to determine responsibility but to uncover systemic lessons.
31.12 After-Action Reviews and Learning Sessions
a) For major incidents or completed projects, HGT may conduct after-action reviews or learning sessions that ask:
i. what happened;
ii. what went well;
iii. what did not go well;
iv. what should be done differently next time.
b) These sessions shall be conducted in a spirit of constructive reflection, guided by facilitators who encourage open, non-retaliatory discussion.
31.13 Anonymised Case Libraries
a) Where appropriate and safe, HGT may develop anonymised case summaries (stripping out identifying details) to be used in training of staff, volunteers and H96 custodians.
b) Case libraries may illustrate good practice, typical risks and common mistakes in areas such as relic custody, safeguarding, financial integrity and community engagement.
31.14 Integration with Training and Policy Development
a) Lessons from cases and evaluations shall inform:
i. updates to training curricula (e.g. induction, ethics, peace skills);
ii. revisions to SOPs and checklists;
iii. revisions to policy chapters where gaps or ambiguities become evident.
5. Policy Review Procedures
31.15 Levels of Policy Instruments
For clarity:
a) This Policy Manual sets out core principles and rules approved at Board level.
b) Standard Operating Procedures (SOPs), guidelines and templates provide practical implementation details at departmental level.
c) All must be consistent with governing documents and law.
31.16 Routine Policy Review Cycle
a) HGT shall establish a policy review cycle, under which each major Section of this Manual is reviewed at least every 3–5 years, or sooner if needed.
b) The Compliance / Legal Officer, in coordination with department heads, shall maintain a schedule specifying review dates and responsible leads.
31.17 Triggers for Interim Review
a) Policies may be reviewed and amended earlier if:
i. significant legal or regulatory changes occur;
ii. major incidents reveal serious gaps or contradictions;
iii. organisational structure or activities change substantially;
iv. external evaluations or audits strongly recommend changes.
b) Emergency interim measures may be adopted as temporary guidance while a full review is conducted.
31.18 Review Process and Consultation
a) Policy review should include:
i. analysis of relevant incidents, evaluations and risk assessments;
ii. consultation with affected departments and, where appropriate, community or partner input;
iii. consideration of doctrinal, peace and governance implications via the Ethics & Peace Committee and Saṅgha Advisory Council where relevant.
b) Legal compliance must be verified by the Compliance / Legal Officer.
31.19 Approval of Policy Changes
a) Substantive amendments to this Policy Manual require approval at the level defined in Chapter 3 (typically the Board, possibly on recommendation of relevant committees).
b) Minor technical updates (e.g. references, contact details) may be approved at a delegated level, as long as they do not change substance.
6. Communication and Implementation of Changes
31.20 Communication of Policy Changes
a) Once approved, policy changes shall be communicated clearly to all relevant stakeholders, indicating:
i. what has changed;
ii. why it has changed (link to lessons learned, law, or strategy);
iii. from when the changes take effect;
iv. where to find updated documents and templates.
b) Communication channels may include internal circulars, email, meetings, training sessions and updates on notice boards or intranet.
31.21 Updating SOPs and Templates
a) Departments are responsible for updating their SOPs, forms and templates to align with revised policies.
b) Old versions should be archived and marked as superseded, to avoid confusion.
31.22 Training on New or Revised Policies
a) Where changes are significant, targeted training or briefings shall be provided for staff, volunteers, monastics in HGT roles and others affected.
b) Training shall focus on practical implications for daily work and decision-making, and include opportunities for questions and clarification.
31.23 Monitoring Implementation
a) After major changes, HGT shall monitor whether new policies are being implemented as intended, using audits, surveys, interviews or site visits.
b) Implementation challenges may lead to further adjustments or practical guidance.
7. Roles and Responsibilities
31.24 Board of Trustees
The Board is responsible for:
a) overseeing the overall system of evaluation, learning and policy review;
b) approving substantive revisions to this Manual;
c) ensuring that lessons from evaluations and crises are addressed at strategic level.
31.25 Executive Director
The Executive Director is responsible for:
a) ensuring that evaluations are carried out as planned;
b) encouraging a culture of honest reflection and learning;
c) allocating resources and support for review processes and training.
31.26 Compliance / Legal Officer and Risk Officer
These roles (or functions) are responsible for:
a) coordinating policy review schedules and documentation;
b) ensuring coherence between policies, law and risk assessments;
c) supporting departments in incorporating evaluation findings into policies.
31.27 Ethics & Peace Committee and Saṅgha Advisory Council
These bodies are responsible for:
a) bringing ethical, doctrinal and peace perspectives into evaluation and policy review;
b) reviewing proposals for significant changes affecting religious practice, relic custodianship, or peace-building work;
c) advising the Board and Executive Director on moral and spiritual dimensions of institutional learning.
31.28 Departments and Site Management
Department heads and site managers are responsible for:
a) conducting or participating in programme and operational evaluations;
b) using cases and incidents as learning tools within their teams;
c) implementing policy changes and providing feedback on their practicality.
8. Review and Amendment of this Chapter
31.29 Periodic Review
a) This Chapter itself shall be reviewed in line with the overall policy review cycle or sooner if evaluation processes prove inadequate or overly burdensome.
b) Feedback from staff, committees and external reviewers may be used to improve the system.
31.30 Amendment Procedures
a) Amendments to this Chapter shall follow the procedures set out in Chapter 3 for policy modification and approval.
b) Any change in evaluation requirements that significantly affects workloads or reporting duties should be consulted with affected departments in advance.
Chapter 32 – Policy Review and Internal Audit of the Manual and Compliance Checks
CHAPTER 32 – POLICY REVIEW AND INTERNAL AUDIT OF THE MANUAL AND COMPLIANCE CHECKS
1. General Provisions
32.1 Purpose of this Chapter
This Chapter establishes HGT’s system for internal audit of this Policy Manual and compliance checks, in order to:
a) verify that what is written in the Manual is actually applied in practice;
b) detect gaps, inconsistencies and areas of non-compliance; and
c) ensure that policy review (Chapter 31) is informed by reliable, evidence-based findings.
32.2 Foundations
This Chapter is guided by:
a) good governance principles of internal control, audit and accountability;
b) the ethical expectation, rooted in Buddhist discipline, that rules adopted for the benefit of the community are actually lived, not only recited;
c) recognised internal audit standards adapted to HGT’s size and context; and
d) HGT’s risk management and institutional peace framework (Chapters 9 and 30).
32.3 Scope
a) This Chapter applies to all Sections of the Policy Manual and related Standard Operating Procedures (SOPs).
b) It covers:
i. planning and carrying out internal audits;
ii. compliance checks of selected policies and procedures;
iii. documentation, reporting and follow-up on audit findings;
iv. links between audits, risk registers and policy revision.
2. Internal Audit Objectives and Principles
32.4 Objectives of Internal Audit
HGT’s internal audit of policies aims to:
a) check whether key policies are understood, implemented and effective;
b) confirm that legal and regulatory obligations linked to policies are being met;
c) identify weaknesses in controls and areas where practice has diverged from policy (or policy from reality);
d) support continuous improvement and not merely identify faults.
32.5 Principles
Internal audit and compliance checks shall be conducted according to the following principles:
a) Independence and Objectivity – auditors should be sufficiently independent from the activities they review; where this is not fully possible (small teams), safeguards should be used (e.g. cross-site audits, external support).
b) Fairness and Respect – staff and volunteers shall be treated respectfully; the focus is on systems, not on blame.
c) Evidence-Based – conclusions are based on documented evidence, not rumours.
d) Confidentiality – sensitive information discovered during audits must be handled in line with Data Protection and Safeguarding policies.
e) Constructive Use – findings are used to strengthen HGT’s integrity, peace and service, not to create fear or retaliation.
3. Internal Audit Structure and Responsibilities
32.6 Audit & Risk Committee
a) The Audit & Risk Committee of the Board oversees internal audit and compliance checks at HGT.
b) It is responsible for:
i. approving internal audit plans and priorities;
ii. receiving and reviewing audit reports;
iii. monitoring implementation of corrective actions;
iv. advising the Board on the adequacy of internal controls and compliance.
32.7 Internal Audit Function or Assigned Staff
a) Depending on HGT’s size and resources, internal audit may be carried out by:
i. a dedicated Internal Auditor or small internal audit team; or
ii. designated staff or external professionals assigned specific audit tasks.
b) Individuals performing audits should, as far as possible, not audit their own direct work and must receive appropriate training.
32.8 Compliance / Legal Officer and Departments
a) The Compliance / Legal Officer supports internal audit by:
i. helping map legal and policy requirements;
ii. providing guidance on compliance questions;
iii. ensuring that audit findings feed into policy review and risk registers.
b) Department heads are responsible for cooperating with audits and acting on recommendations within their areas.
4. Audit Planning and Risk-Based Approach
32.9 Annual / Multi-Year Audit Plan
a) HGT shall prepare an Internal Audit Plan (annual or multi-year) that:
i. identifies priority areas for review (e.g. safeguarding, donations, relic custody, HR, data protection);
ii. aligns with the risk register (Chapter 9) and institutional peace indicators (Chapter 30);
iii. considers external obligations (e.g. donor requirements, regulator focus).
b) The plan shall be approved by the Audit & Risk Committee.
32.10 Risk-Based Prioritisation
a) Audit resources shall be focused on:
i. areas with high inherent risk (e.g. safeguarding, relic and heritage, cash handling);
ii. areas where incidents have occurred or complaints have risen;
iii. new or rapidly growing activities;
iv. policies linked to serious legal or reputational consequences if breached.
b) Lower-risk areas may be reviewed less frequently or through lighter touch checks.
32.11 Audit Scope for Each Review
For each audit assignment, the scope shall be defined, for example:
a) which policies and sections of the Manual will be examined;
b) which sites, departments or time periods are covered;
c) which questions will be asked (e.g. compliance, effectiveness, documentation quality);
d) what methods will be used (document review, interviews, observations, sampling).
5. Conducting Internal Audits and Compliance Checks
32.12 Audit Methods
Typical audit methods include:
a) Document Review – checking policies, SOPs, records, registers, minutes, contracts and forms against requirements in the Manual and law;
b) Interviews and Discussions – speaking with staff, volunteers, monastics in HGT roles and sometimes community members to understand how policies are understood and applied;
c) Observation – visiting sites, events or offices to see actual practice (e.g. visitor management, handling of cash, safeguarding signage, relic security);
d) Sampling – examining a sample of transactions or cases (e.g. selected donations, HR files, complaints, heritage loans) to test compliance.
32.13 Compliance Checklists
a) For major policy areas, auditors may use checklists derived from the Manual and relevant laws, for example:
i. Donations & Sponsorship Policy compliance;
ii. HR and safeguarding requirements;
iii. relic custody and heritage security standards;
iv. data protection and privacy measures.
b) Checklists shall be updated when policies or laws change.
32.14 Respectful Engagement with Staff
a) Auditors shall explain the purpose and scope of audits clearly to those involved.
b) Staff and volunteers should feel free to speak honestly, knowing that good-faith participation is protected from retaliation.
32.15 Documentation of Findings
a) Auditors shall document:
i. what was reviewed;
ii. evidence examined;
iii. examples of compliance and good practice;
iv. non-compliance, weaknesses or ambiguities;
v. root cause hypotheses;
vi. recommendations (priority and timeframe).
b) Draft findings may be discussed with responsible managers to check factual accuracy before finalisation, while preserving auditor independence.
6. Reporting and Follow-Up
32.16 Internal Audit Reports
a) Each audit shall result in a written Internal Audit Report summarising:
i. scope and methods;
ii. key findings;
iii. level of compliance with relevant sections of the Manual and laws;
iv. recommendations for corrective actions and improvements.
b) Reports shall be shared with:
i. relevant department heads;
ii. the Executive Director;
iii. the Audit & Risk Committee;
iv. other committees where appropriate (e.g. Ethics & Peace Committee for ethical or peace-related issues, Relic & Heritage for custodianship issues).
32.17 Management Responses and Action Plans
a) For each report, relevant managers shall prepare a Management Response that:
i. agrees or comments on findings;
ii. proposes concrete actions, responsibilities and deadlines;
iii. identifies any resources or support required.
b) The Audit & Risk Committee shall review these responses for adequacy.
32.18 Tracking Implementation
a) Implementation of agreed actions shall be tracked, for example via an Audit Action Log maintained by the Compliance / Legal Officer or Internal Auditor.
b) Overdue or repeatedly ignored actions shall be escalated to the Executive Director and, where necessary, to the Board.
32.19 Link to Disciplinary or Corrective Measures
a) While the primary aim of audit is improvement, serious or repeated non-compliance uncovered in audits may require:
i. disciplinary action under HR and safeguarding policies;
ii. notification to regulators or funders, where required;
iii. revisions to delegation of authority or staff roles.
b) Decisions of this kind shall be made by appropriate leadership bodies, not by auditors alone.
7. Integration with Policy Review and Learning
32.20 Feeding into Policy Review (Chapter 31)
a) Audit findings are a key input into policy review. They help identify:
i. policies that are unclear, unrealistic or not widely understood;
ii. areas where practice has evolved beyond written rules;
iii. contradictions or overlaps between different sections.
b) The Compliance / Legal Officer shall summarise recurrent audit themes for use in scheduled policy reviews.
32.21 Learning from Good Practice
a) Audits should highlight not only problems but also examples of good practice and creative solutions found by teams.
b) These examples may be shared across HGT (e.g. via internal notes, training) to encourage peer learning.
32.22 Risk Register and Institutional Peace Indicators
a) Serious or systemic non-compliance identified through audits should be reflected in the risk register (Chapter 9) and, where relevant, in institutional peace indicators (Chapter 30).
b) This ensures that governance bodies see audit outcomes as part of the overall risk and peace picture.
8. Ethics, Confidentiality and Protection
32.23 Ethical Conduct of Auditors
a) Auditors must act with integrity, objectivity, confidentiality and professional care.
b) They shall avoid conflicts of interest and declare any potential bias to the Audit & Risk Committee.
32.24 Confidentiality and Data Protection
a) Information collected during audits, especially personal or sensitive data, must be handled according to Data Protection and Privacy policies (Chapter 29).
b) Reports should anonymise individuals where possible and focus on systemic issues.
32.25 Protection of Those Who Cooperate
a) Staff, volunteers and others who provide honest information to auditors, including about weaknesses or breaches, shall be protected from retaliation.
b) Retaliation is prohibited and may itself be treated as misconduct.
9. Review of the Internal Audit System
32.26 Periodic Review of Audit Effectiveness
a) The Audit & Risk Committee shall periodically review the effectiveness of the internal audit and compliance check system, asking:
i. whether the scope is appropriate;
ii. whether audits are timely and useful;
iii. whether recommendations are implemented;
iv. whether staff perceive audits as fair and constructive.
b) Feedback may be gathered from audited departments, leadership and, where relevant, external stakeholders.
32.27 External Assessment of Audit Function
a) From time to time, and when resources allow, HGT may seek an external review of its internal audit arrangements (e.g. peer review by another institution or professional advice) to strengthen independence and quality.
b) Recommendations from such reviews shall be considered in updating audit practices.
32.28 Amendment of this Chapter
a) This Chapter may be amended based on experience, changes in governance structures, legal requirements or best practices in internal audit.
b) Amendments shall be approved in line with Chapter 3 and communicated to all relevant staff, auditors and committees.