While on leave from their place of employment as Chief Financial Officer, it was alleged that the Member accessed the employer’s computer system remotely, to make computer entries which benefitted themselves and other persons without authorization, and used the computer access of another employee to complete statutory documentation.
The Member denied the allegations. While the Member admitted that employees shared passwords, the Committee did not accept the Member’s denial that they utilized other employee’s passwords. However, with no objective evidence to support the allegations made against the Member by the Complainant, the Committee found that the Member breached professional responsibilities in failing to ensure that the employer had, and utilized, appropriate password protocols. The Member should have ensured that appropriate computer controls were in place to prevent the sharing of passwords.
The Investigation Committee determined the Member contravened the following Rules of the CPABC Code of Professional Conduct:
201.1 - Maintenance of the good reputation of the profession
202.1 - Due care
The Investigation Committee recommended the Member:
- Accept a reprimand; and
- After the Member re-enters the workforce in a professional capacity, successfully attend and complete a course in internal controls acceptable to the Director, Professional Conduct.
In making this recommendation, the Committee took into account the current personal circumstances of the Member.