Competency Management in Shared Roles Policy
This policy establishes the governance protocol for evaluating, restructuring, and distributing specialized competencies, diplomas, or professional qualifications across a team when an operational role is not filled by a single, dedicated employee. Designed around ISO/IEC 27001:2023 (A.06.02 - Terms and Conditions of Employment, A.06.08 - Information Security Roles and Responsibilities) and NIS 2 guidelines, this policy provides a structured approach to personnel risk management and business continuity under Dutch labor frameworks.
This policy undergoing mandatory evaluation and re-validation annually or immediately following key updates to the corporate Risk Inventory and Evaluation (RI&E).
1. Core Principles & Strategic Scope
To maintain organizational agility within tight labor markets or shifting research paradigms, anDREa B.V. (anDREa) permits the distribution of centralized functional duties across a distributed team mesh. This framework ensures that adjusting job parameters to match internal realities never introduces compliance gaps, operational blind spots, or degradation in our core cloud delivery planes.
2. Structural Restructuring Procedure
Before any vacant or complex organizational role is officially decoupled and shared among the team, Human Resources paired with the Management Team (MT) must execute a four-stage vetting pipeline:
┌────────────────────────────────────────────────────────┐
│ STAGE 1: JOB PROFILE CRITIQUE │
│ Validate relevance of formal certificates & diplomas │
└───────────────────────────┬────────────────────────────┘
▼
┌────────────────────────────────────────────────────────┐
│ STAGE 2: STATUTORY COMPLIANCE │
│ Check alignment with GDPR, Arbowet, and ISO matrices │
└───────────────────────────┬────────────────────────────┘
▼
┌────────────────────────────────────────────────────────┐
│ STAGE 3: THE PERIODIC CONTROLS REGISTER │
│ Map atomized tasks to individuals with MT auditing │
└───────────────────────────┬────────────────────────────┘
▼
┌────────────────────────────────────────────────────────┐
│ STAGE 4: FORWARD CAPABILITY SHIFT │
│ Re-write profile based on experience over credentials │
└────────────────────────────────────────────────────────┘
Phase 1: Critical Job Profile Evaluation
The existing blueprint for the target position must undergo a formal structural critique. Evaluators must explicitly document answers to the following operational questions:
- Are the historical criteria (such as specific university diplomas or platform-level certifications) strictly necessary in light of updated cloud architecture patterns?
- Can the underlying tasks be modularized and shared to cleanly exploit the existing technical skills of current staff?
- Which specific sub-competencies are Essential for secure baseline operations, and which are merely Desirable functional additions?
- Does splitting this role create immediate training or patch-qualification requirements for the receiving employees?
Phase 2: Statutory Compliance Mapping
Every modified shared position layout must perfectly honor applicable Dutch laws, including the GDPR/AVG and local health and safety standards under the Working Conditions Act (Arbowet). The evaluation panel must formally verify that sector-specific or international certification baselines (such as ISO 27001 audit compliance) remain completely unaffected by the operational shift.
Phase 3: Task Redistribution & The Periodic Controls Sheet
When a role is dissolved into shared responsibilities, individual tasks are explicitly assigned to validated team members.
- The Audit Trail Requirement: Every distributed sub-task must be formally logged inside the centralized Periodic Security Controls or Periodic Controls MT.
- Owner Assignment: Each ledger line must be explicitly mapped to a named custodian.
- Ultimate Liability Floor: The ultimate legal and operational liability for ensuring the tasks are executed flawlessly remains with the corporate Management Team. An MT member must periodically inspect and sign off on the Periodic Controls Sheet logs.
Phase 4: Skill-Based Profile Revision
If formal credentials or high-level diplomas are determined to be non-essential for daily operations, the primary job description will be formally revised. Required parameters will focus strictly on verifiable knowledge, technical dexterity, and practical cloud experience rather than structural formal schooling. These adaptations, along with the precise rationale for criteria relaxation, must be permanently archived in writing.
4. Continuity, Training, & Periodic Audit Cycles
- Redundancy Uplift: The primary strategic objective of distributing responsibilities is to maximize organizational redundancy and permanently eliminate dangerous single-person dependencies (lowering human resource single points of failure).
- On-Demand Rescaling: If a dedicated employee is recruited to reclaim the centralized role in the future, the job description must be reviewed again to ensure it mirrors then-current architectural parameters.
- Supportive Delta Training: All adjustments to role configurations must be transparently communicated to affected team members. Employees assuming newly distributed responsibilities must be given tailored delta training and corporate funding for skill augmentation.
- Annual Review Loop: At least once per calendar year, or immediately upon a shift in European cybersecurity or privacy legislation, the MT must re-evaluate every active shared-role layout to verify that platform quality, service delivery standards, and strict compliance boundaries remain fully intact.
Single-Policy Evaluation Review
When assessing a specific vacant position or restructuring an internal function today, in Phase 1 determine which parts of that role can be cleanly mapped to the Periodic Security Controls or Periodic Controls MT. When applicable, update anDREa's Role & Responsibilities matrix.