Policies and Governance System

Architecture of trust and safety

An overview of the comprehensive policies and governance system of the NGO Carpathian Agency of Human Rights VESTED — from values and statutory authority to everyday decisions that protect people.

Why we do this

Policies matter when they protect

We are adopting the highest international governance standards. These 18+ new policies are not bureaucracy. They are our deliberate safety architecture, ensuring that we do no harm, manage resources transparently and create an environment where staff, partners and participants feel protected.

Trust emerges where protection of people, integrity and standards intersect.
System framework

Governance and hierarchy of rules

The Statute defines authority. Policies turn it into a predictable system of decisions, checks and accountability.

A coloured three-dimensional governance pyramid. The General Assembly sets strategy and is the highest governing body; the Board provides oversight and resolves conflicts; the Chair of the Board provides operational management.

Order of precedence

Laws of Ukraine
Statute of the Organization
Decisions of the General Assembly and the Board
Specific policies
Project procedures and instructions

Important. If donor rules are stricter than internal rules, the donor rules apply, provided they do not conflict with Ukrainian law.

Flexibility with control

Delegation and risk management

Flexibility

Delegated authority. Project managers administer budgets within approved authority matrices.

Control

Segregation of duties. No one approves their own expenses. A decision undergoes at least two independent checks — the four-eyes principle.

Initiation
Review
Approval
Payment
Low Managed through routine controls.
Medium Requires defined measures and regular oversight.
High Escalated to management level with a dedicated response plan.
Critical A threat to life, corruption or a safeguarding concern — activities stop immediately until the risk is addressed.
Code of Conduct and GESI

The foundation of our culture

Respect and equality

Zero tolerance for discrimination, harassment and bullying. Reasonable accommodation ensures equal access and participation.

Integrity

Zero tolerance for corruption, fraud and bribery. Potential conflicts of interest are declared in advance.

Accountability

The rules apply at work, during travel and events, and online. Status or position never excuses misconduct.

Protection matrix

Four policies — four layers of protection

The shared principle is that human dignity and safety come first. Specific policies define whom the system protects and from which risks.

Policy Primary focus Who is protected Key rule
Safeguarding Overall safe operations and the do-no-harm principle. Everyone involved in the Organization’s activities. A person’s safety takes precedence over a project or reputation.
Child protection Prevention of harm and safe interaction with children. Every person under the age of 18. The best interests of the child and visible interactions: no hidden or isolated contact.
PSEAH Prevention of sexual exploitation, abuse and harassment. Everyone, especially people in vulnerable situations. Zero tolerance. Consent is not valid where there is a power imbalance or dependence on assistance.
Counter-trafficking Prevention of forced labour, debt bondage and exploitation. Staff, programme participants and people in the supply chain. Withholding documents, recruitment debt and the use of hazardous labour are prohibited.
Safe reporting

How to speak up when you see misconduct

Reporting routes for misconduct: depending on whom the complaint concerns, it is directed to the Designated Officer, Chair of the Board, Board or General Assembly.
Anonymity

Anonymous reports are accepted for review.

Protection from retaliation

Retaliation for a good-faith report is prohibited. Information about possible retaliation is reviewed separately.

You do not have to prove it

A reporting person is not required to collect evidence independently — it is enough to report a reasonable concern.

Human Resources Policy

People: the full cycle of responsible engagement

Transparent recruitment

Merit-based competitive recruitment, free from discriminatory practices, with mandatory declaration of conflicts of interest.

Safe onboarding

Mandatory briefings on the Code of Conduct, safeguarding and information security before working with sensitive data or people.

Support and performance review

Fair pay, reasonable workloads, regular performance review and clear feedback.

Respectful offboarding

Advance notice, final settlement, secure handover, return of assets and closure of access rights.

Procurement and assets

Operational integrity

Procurement thresholds

Procurement thresholds: up to UAH 20,000 — direct purchase; UAH 20,000–100,000 — market comparison; UAH 100,000–500,000 — request for quotations; above UAH 500,000 — open competition.
Rule: We select the best value for money. Artificial splitting of procurements is strictly prohibited

Asset life cycle

Asset life cycle: receipt, use for the Organization’s purposes, inventory and secure disposal.
Information and technology

Digital security is also protection of people

Information security

Mandatory two-factor authentication, strong passwords, regular backups and individual user accounts.

Personal data protection

We collect only the minimum data necessary. Once the purpose is achieved, the data is securely deleted — nothing is retained “just in case”.

Artificial intelligence is only a tool; final responsibility remains with a person. Personal data, information about programme participants and sensitive documents must not be entered into open AI systems.
Monitoring, evaluation, accountability and learning

MEAL: data that helps us improve

MEAL cycle: planning, data collection, analysis, learning and adjustment.

We measure what matters

We do not collect data for the sake of volume: every indicator has a clear purpose.

Accountability

People affected by our assistance have a safe and understandable channel for feedback or complaints.

Ethical practice

We do not use general surveys to collect sensitive information about violence — such cases are referred through safeguarding channels.

Learning

We document failures and lessons and adjust projects on the basis of real data.

Practical steps

Emergency response

In a crisis, it is important not to improvise: safety comes first, followed by recording and passing information to the responsible person.

Physical danger
or an air-raid alert

  1. A person’s safety is the absolute priority.
  2. Stop work and follow the instructions.
  3. Do not post sensitive staff lists in open chats during roll calls.

Safeguarding
or a risk to a child

  1. Ensure immediate physical safety.
  2. Listen without judgement or leading questions.
  3. Do not investigate independently. Immediately pass the information to the Designated Officer.

Digital incident
or data breach

  1. Immediately disconnect the device from the network.
  2. Change passwords and terminate suspicious sessions.
  3. Do not conceal the incident — notify the person responsible for information security or the Chair of the Board.
Trust architecture

Four golden rules

Even if the details of many policies are forgotten, these principles should guide every decision.

01

Do no harm

People’s physical and psychological safety always matters more than operational speed or reputation.

02

Declare conflicts of interest

Unsure about your own or related interests? Declare them before taking action.

03

The four-eyes principle

No one initiates, reviews and approves their own work or expenses alone.

04

No retaliation

A good-faith report of a concern, misconduct or reasonable suspicion is always protected.

The system blueprint

Policies, rules and tools

Each document defines the limits of authority, the sequence of actions and protection mechanisms. Each language version of the website displays the corresponding edition of the public documents.

01 Governance and culture 8 documents
STATUTEStatute of the Organization — 2025 revised editionPurpose, areas of activity, membership, governing bodies, authority and decision-making procedures
A-RES-53-144UN Declaration on Human Rights DefendersInternational values framework for human rights work: the right to defend human rights, act collectively, share information, provide assistance, and be protected from pressure and retaliation
EU-HRD-2008EU Guidelines on Human Rights DefendersEU practical framework for supporting and protecting human rights defenders: risk monitoring, diplomatic action, particular attention to women human rights defenders, access to resources and urgent protection
COC-01 Code of Conduct Common minimum standards of professional and ethical conduct for everyone acting on behalf of VESTED.
INT-01 Integrity Policy Prevention of corruption, fraud and misuse of resources, and management of conflicts of interest.
GESI-01 Gender Equality and Social Inclusion Policy Equal rights and opportunities, non-discrimination, removal of barriers and recognition of people’s different needs.
MAP-01 Governance and Relationships Map Who decides, implements, reviews and escalates decisions in key processes.
GOV-DEL-01 Delegation of Authority Framework Limits of authority, approval matrices, segregation of duties and risk escalation.
02 Protection of people and safe reporting 5 documents
SFG-01 Safeguarding Policy Prevention of harm to people arising from the Organization’s activities, decisions and representatives’ conduct.
CHD-01 Child Protection Policy Safe interaction with children and response to concerns about abuse, exploitation or neglect.
PSEAH-01 PSEAH Policy Prevention of sexual exploitation, sexual abuse and sexual harassment.
THB-01 Counter-Trafficking in Persons Policy Zero tolerance for forced labour, debt bondage, exploitation and the worst forms of child labour.
CMP-01 Complaints and Reporting Policy An accessible and safe process for submitting, routing and reviewing complaints and reports of misconduct.
03 Operational management 7 documents
HR-01 Human Resources Policy Workforce planning, recruitment, onboarding, support, performance review and offboarding.
FIN-01 Financial Policy Planning, use, control, accounting and reporting of the Organization’s funds.
PRC-01 Procurement Policy Procurement planning, supplier selection, competition, contracts and acceptance of deliverables.
AST-01 Asset Management Policy Receipt, registration, transfer, use, inventory, return and disposal of assets.
PRG-01 Programme and Project Management Policy Design, approval, implementation, amendment, suspension and closure of programmes and projects.
RSK-01 Risk Management Policy Identification, assessment, treatment, monitoring and escalation of risks to people, mission and resources.
MEL-01 MEAL Policy Monitoring, evaluation, accountability and learning in programmes, projects and individual activities.
04 Information and technology 3 documents
DAT-01 Personal Data Protection Policy Collection, use, storage, transfer, correction and secure deletion of personal data.
SEC-01 Information Security Policy Minimum rules for protecting information, devices, accounts, digital services and backups.
AI-01 Responsible Use of AI Policy Use of AI without harming human rights, privacy, information integrity or reputation.

We act with dignity.
We protect rights.

The trust architecture works when every rule becomes practice