Ethics and compliance- certSIGNEthics and compliance. Our success also depends on good business practices and anti-corruption policy.

Ethics
and compliance
Our success also depends on good business practices and anti-corruption policy.
Highest standards of integrity and compliance
At certSIGN, acting with integrity means more than complying with national and international laws and regulations. In the company’s business dealings, we attach equal importance to both the quality of the solutions we provide and the highest standards of integrity and compliance as key elements of our business strategy.
We have developed and implemented a program to prevent, identify and address any suspected breaches of integrity rules, to which all certSIGN employees contribute and are encouraged by management to identify and report any violations.
Our reputation is an important resource and it is vital that we protect it. The credibility of our company as well as the trust of our customers, suppliers, partners and the public are significantly influenced by the honest attitude of the company and each individual employee.
Code of
conduct and ethics
certSIGN’s Code of Business Conduct and Ethics sets out the expectations of integrity that the company has towards its employees and third parties acting on behalf of the company. Anti-bribery and anti-corruption policy
certSIGN prohibits the taking/offering of bribes in any form, whether direct or indirect, regardless of the amount. certSIGN employees must act in accordance with the highest standards of integrity in all business transactions. Our internal regulations reflect the importance of the individual responsibility of each member of the certSIGN team. These regulations include a prohibition on making payments, giving gifts, granting sponsorships and charitable contributions in order to facilitate a benefit for the company, establishing ethical relationships with suppliers and partners, zero tolerance policy towards any involvement in acts with a risk of corruption, etc. certSIGN applies the highest standards of ethical behavior by combating and countering bribery in all countries where it implements projects and is certified according to ISO 37001:2016 (International Anti-Bribery Management System), which confirms the highest standards of integrity.certSIGN has successfully met the recertification requirements of the ISO 37001:2016 anti-bribery management system, whose main purpose is the prevention and management of high-risk corruption activities – see the certificate here.
Reporting integrity incidents
Any report concerning possible violations of anti-corruption rules can be sent to compliance@certsign.ro. . All reports received are carefully investigated and action is taken in accordance with applicable national laws and internal company regulations.Compliance with legal requirements and internal regulations is paramount and any misconduct must be identified, investigated and remedied. This involves providing reporting channels so that employees and external parties (business partners, customers and other third parties) can report any possible breaches of the law obtained in a professional context.
The Integrity Incident Reporting Application, within the meaning of Law No. 361 of 2022, is a dedicated channel through which a whistleblower, an individual, company employee or third party, is given the opportunity to report a specific situation of which he/she becomes aware, which does not comply with applicable laws and regulations, internal policies and the company’s Code of Business Conduct and Ethics.
What is a public interest whistleblower
A public interest whistleblower is an individual who reports or publicly discloses information about breaches of the law obtained in a professional context.
Who can be a whistleblower
Whistleblowers can be (but are not limited to):
- Company employees
- Shareholders and representative of the administrative, managerial or supervisory bodies of a company, including non-executive members of the board of directors
- Paid or unpaid volunteers and trainees
- Any person working under the supervision and direction of the natural or legal person with whom a contract has been concluded, its subcontractors and suppliers
- Persons whose employment relationship has not yet commenced and who report through internal or external reporting channels or publicly disclose information on breaches of the law obtained during the recruitment process or other pre-contractual negotiations or where the employment or service relationship has ended
- Persons who report or publicly disclose information on breaches of law anonymously
To benefit from whistleblower protection, the person making the report must act impartially, in good faith, and provide factual and clear information so that the report can be properly processed and investigated.
What can be reported
Reporting may relate to:
- Breaches of law in areas such as: public procurement, services, products and financial markets, prevention of money laundering and terrorist financing, product safety and compliance, transportation safety, environmental protection, radiological protection and nuclear safety, food and feed safety, animal health and welfare, public health, consumer protection, privacy and personal data protection and network and information systems security
- Any serious threat to the public interest
- Reasonable suspicion of actual or potential breaches of the law which have occurred or are likely to occur within the company in which the public interest whistleblower works or has worked or with which he or she is or has been in contact through his or her work, and information about attempts to conceal such breaches
- Breaches of the company’s internal regulations
- Conduct that contravenes the Company’s Code of Business Conduct and Ethics
How to process a report
For a report to be processed, it must fulfill the conditions mentioned below.
- Reports can be submitted anonymously or the person making the report can assume their identity.
- In the case of an identified whistleblower, the company is obliged to protect their identity.
- Non-anonymous reporting shall include, at a minimum, the following: the full name and contact details of the whistleblower in the public interest, the professional context in which the information was obtained, the person concerned, if known, a description of the fact likely to constitute a breach of the law, and evidence supporting the report.
- A report that does not include the name, surname, contact details or signature of the public interest whistleblower will be examined and dealt with to the extent that it contains prima facie indications of violations of the law.
- In both cases, checks will be initiated in order to establish the veracity and severity of the reported facts. To this end, the elements constituting the report must be precise and demonstrable. The report should cover five basic questions: Who? Who? What? When? How? Where?
- The time needed to process each referral depends on the complexity of the case, the evidence and the documents under analysis.
- Strict confidentiality of information is guaranteed throughout the process, in accordance with legal and internal regulations.
- The whistleblower is protected against any reprisals, discriminatory measures or sanctions.
- The whistleblower must act in good faith, without intent to cause harm or defame others. If a report is found to be false or made with a clear intent to defame, the company will take the action required by internal or legal regulations.
Who will process the report
Access to the information included in the report is on a need-to-know basis and is limited to the person designated by the company or the group of companies, possible authorized internal experts and commissioned external experts.
Confidentiality requirements also apply to external experts who may receive the report to provide guidance or conduct investigations.
Other reporting channels
If for any reason you do not agree with the use of this reporting channel, you can access the following alternative reporting channels:
By email at compliance@certsign.ro
In hardcopy at the correspondence address: TIU Research and Development Center, 107A Oltenitei Av, S4, Bucharest

To submit a report, follow the instructions in the form.
After submitting the report, you will receive a confirmation code. Within 7 calendar days, you will receive confirmation of receipt of the report.
The confidentiality of your data is guaranteed throughout the entire reporting period.
Within a maximum of 3 months (90 days) from the date of confirmation of receipt, you will be informed about the status of the next actions, as well as whenever we record developments, except in the case where the information could jeopardize their implementation.
Throughout the processing period of a report, we may request additional information from you.
If the report does not contain sufficient information, other than the identification of the whistleblower, and the person designated to process the report has requested additional information, the report will be closed if the whistleblower has not submitted the requested information within 15 days.

Ethics
and compliance
Our success also depends on good business practices and anti-corruption policy.
Highest standards of integrity and compliance
At certSIGN, acting with integrity means more than complying with national and international laws and regulations. In the company’s business dealings, we attach equal importance to both the quality of the solutions we provide and the highest standards of integrity and compliance as key elements of our business strategy.
We have developed and implemented a program to prevent, identify and address any suspected breaches of integrity rules, to which all certSIGN employees contribute and are encouraged by management to identify and report any violations.
Our reputation is an important resource and it is vital that we protect it. The credibility of our company as well as the trust of our customers, suppliers, partners and the public are significantly influenced by the honest attitude of the company and each individual employee.
Code of
conduct and ethics
Anti-bribery and anti-corruption policy
certSIGN has successfully met the recertification requirements of the ISO 37001:2016 anti-bribery management system, whose main purpose is the prevention and management of high-risk corruption activities – see the certificate here.
Reporting integrity incidents
Compliance with legal requirements and internal regulations is paramount and any misconduct must be identified, investigated and remedied. This involves providing reporting channels so that employees and external parties (business partners, customers and other third parties) can report any possible breaches of the law obtained in a professional context.
The Integrity Incident Reporting Application, within the meaning of Law No. 361 of 2022, is a dedicated channel through which a whistleblower, an individual, company employee or third party, is given the opportunity to report a specific situation of which he/she becomes aware, which does not comply with applicable laws and regulations, internal policies and the company’s Code of Business Conduct and Ethics.
What is a public interest whistleblower
A public interest whistleblower is an individual who reports or publicly discloses information about breaches of the law obtained in a professional context.
Who can be a whistleblower
Whistleblowers can be (but are not limited to):
- Company employees
- Shareholders and representative of the administrative, managerial or supervisory bodies of a company, including non-executive members of the board of directors
- Paid or unpaid volunteers and trainees
- Any person working under the supervision and direction of the natural or legal person with whom a contract has been concluded, its subcontractors and suppliers
- Persons whose employment relationship has not yet commenced and who report through internal or external reporting channels or publicly disclose information on breaches of the law obtained during the recruitment process or other pre-contractual negotiations or where the employment or service relationship has ended
- Persons who report or publicly disclose information on breaches of law anonymously
To benefit from whistleblower protection, the person making the report must act impartially, in good faith, and provide factual and clear information so that the report can be properly processed and investigated.
What can be reported
Reporting may relate to:
- Breaches of law in areas such as: public procurement, services, products and financial markets, prevention of money laundering and terrorist financing, product safety and compliance, transportation safety, environmental protection, radiological protection and nuclear safety, food and feed safety, animal health and welfare, public health, consumer protection, privacy and personal data protection and network and information systems security
- Any serious threat to the public interest
- Reasonable suspicion of actual or potential breaches of the law which have occurred or are likely to occur within the company in which the public interest whistleblower works or has worked or with which he or she is or has been in contact through his or her work, and information about attempts to conceal such breaches
- Breaches of the company’s internal regulations
- Conduct that contravenes the Company’s Code of Business Conduct and Ethics
How to process a report
For a report to be processed, it must fulfill the conditions mentioned below.
- Reports can be submitted anonymously or the person making the report can assume their identity.
- In the case of an identified whistleblower, the company is obliged to protect their identity.
- Non-anonymous reporting shall include, at a minimum, the following: the full name and contact details of the whistleblower in the public interest, the professional context in which the information was obtained, the person concerned, if known, a description of the fact likely to constitute a breach of the law, and evidence supporting the report.
- A report that does not include the name, surname, contact details or signature of the public interest whistleblower will be examined and dealt with to the extent that it contains prima facie indications of violations of the law.
- In both cases, checks will be initiated in order to establish the veracity and severity of the reported facts. To this end, the elements constituting the report must be precise and demonstrable. The report should cover five basic questions: Who? Who? What? When? How? Where?
- The time needed to process each referral depends on the complexity of the case, the evidence and the documents under analysis.
- Strict confidentiality of information is guaranteed throughout the process, in accordance with legal and internal regulations.
- The whistleblower is protected against any reprisals, discriminatory measures or sanctions.
- The whistleblower must act in good faith, without intent to cause harm or defame others. If a report is found to be false or made with a clear intent to defame, the company will take the action required by internal or legal regulations.
Who will process the report
Access to the information included in the report is on a need-to-know basis and is limited to the person designated by the company or the group of companies, possible authorized internal experts and commissioned external experts.
Confidentiality requirements also apply to external experts who may receive the report to provide guidance or conduct investigations.
Other reporting channels
If for any reason you do not agree with the use of this reporting channel, you can access the following alternative reporting channels:
By email at compliance@certsign.ro
In hardcopy at the correspondence address: TIU Research and Development Center, 107A Oltenitei Av, S4, Bucharest

To submit a report, follow the instructions in the form.
After submitting the report, you will receive a confirmation code. Within 7 calendar days, you will receive confirmation of receipt of the report.
The confidentiality of your data is guaranteed throughout the entire reporting period.
Within a maximum of 3 months (90 days) from the date of confirmation of receipt, you will be informed about the status of the next actions, as well as whenever we record developments, except in the case where the information could jeopardize their implementation.
Throughout the processing period of a report, we may request additional information from you.
If the report does not contain sufficient information, other than the identification of the whistleblower, and the person designated to process the report has requested additional information, the report will be closed if the whistleblower has not submitted the requested information within 15 days.
