50
BLUE LABEL INTEGRATED ANNUAL REPORT 2015
marked increase in new requests for technology
enhancements. A process has been implemented to
ensure that the efforts are focused on developments
that will assist our customers to meet their
objectives, while maintaining acceptable
performance levels from our systems.
In order to gear the technology function to support
the growing business environment, a number of
governance, risk and compliance objectives have
been set. The governance framework was
developed by initially identifying generic technology
risks and the policies developed aligned to the
framework are in some cases more Group specific.
A policy framework has been implemented to
manage these risks and an implementation plan is
being executed to complete the roll-out of the
policy framework.
Blue Label’s compliance function oversees the
discharge of legal and regulatory responsibilities.
The function monitors, researches and reports on
the regulatory environment in which the Group
operates. The compliance function reports to the
Audit, Risk and Compliance Committee.
The process of compliance reporting encompasses:
•
•
identifying and prioritising all acts and regulations
at a national level applicable to Blue Label;
•
•
incorporating regulatory requirements into
control measures such as standard operating
procedures or processes, manuals or policies;
•
•
recommending corrective measures or steps to
ensure compliance; and
•
•
monitoring compliance through the adequacy
and effectiveness of control measures, which
includes the use of best industry practice
compliance tools and active involvement by Blue
Label’s internal auditors to actively monitor and
manage business units’ compliance against
regulations on a continual basis.
There have been no material instances of
non-compliance by the Group or its Directors during
the past financial year.
COMPLIANCE REPORT
GOVERNANCE OF RISK
CONTINUED
driving a number of programmes across the
organisation to ensure it is effectively communicated
and that all Group companies are informed of the
framework and associated policies. Management is
implementing a number of controls to ensure that
the policies are effectively adopted and maintained
across the organisation.
A number of areas relating to technology
governance have progressed. There has been a
significant drive to formalise controls in order to
ensure consistent and adequate risk management.
The operation’s environment has been assessed to
ascertain the process requirements from both an
enhancement as well as a compliance perspective.
On the disaster recovery side, progress has been
made to deal with multi-node failure and
location outages.
On the project and system changes side, processes
have been formalised to streamline work activity as
well as ensure focus is maintained appropriately.
With the growth in business there has been a




