Certification, or registration, to a standard is the outcome of a successful assessment by an independent third party like DNV. There are certain steps to get you started.
Experience has shown that some simple tips, often seemingly trivial, have proven invaluable to companies seeking certification. As you set out, keep these in mind:
- Make sure you begin the process with the right attitude.
- Have a complete understanding of the concept set forth in the standard, and use the standard as a guide template to define your security system.
- Know what application and implications of the standard will mean to your company.
- Use the standard as a tool for improvement.
- Select your partner (certification body/registrar) carefully.
What steps should I follow?
Below you will find 6 steps that will take you down the road to certification:
- Obtain a standard
Obtain and read a copy of the standard to familiarise yourself with the requirements. Members of WLA can obtain a copy of the WLA Security Control Standards© on the World Lottery Association’s website. - Assemble a team and define your strategy
The adoption of a security system needs to be the strategic decision of the whole organisation. It is vital that your senior management is involved in the creation process, in addition to a dedicated team to develop and implement your security system. - Develop a security system manual
Your security system manual should describe the policies and operations of your company. Through the manual, you will provide an accurate description of the organisation and the best practice adopted to consistently satisfy stakeholders’ expectations. - Develop procedures
Procedures describe the processes of your organisation, and the best practice to achieve success in these processes. These procedures should answer the following questions about each process:
- why
- who
- when
- where
- what
- how - Implement your security system
Communication and training are keys to a successful implementation. During the implementation phase, your organisation will be working according to the procedures that were developed to document and demonstrate the effectiveness of the security system. - Select a certification body/registrar
Your business relationship with the certification body/registrar will be in place for many years, as your certification has to be maintained. In this age of corporate scrutiny, it is imperative to choose a registrar with a reputation beyond reproach.
When you have implemented your security system and prepared it for certification, you are ready to begin the certification process.
