Governance of risk
Structure
The Board accepts its responsibility for the governance of risk, which includes the total process of risk management and the formation of its opinion on the effectiveness of the process. The Board forms its opinion on the process of risk management based on the recommendations of the ARCC and is satisfied with the effectiveness of the risk management process. The ARCC is responsible for ensuring that the Group has implemented an effective policy and plan for risk management and that the risk disclosures are comprehensive, timely and relevant. The Board and committees' responsibilities are documented in the Blue Label Integrated Risk Assurance Policy and Framework.
Management is accountable to the Board for designing, implementing and monitoring the process of risk management. The Internal Risk and Compliance Committee function (IRCC), established by management, supports the enterprise-wide risk approach by identifying, evaluating and measuring Group-wide risks and compliance in all functional areas of the Group, as well as maintaining adequate internal controls. The IRCC reports to the ARCC bi-annually in this regard, which oversees the effectiveness of risk management arrangements.
Process
Group-wide strategic risk assessments are conducted bi-annually. These assessments are facilitated by the internal auditor, which plays an important role in evaluating the risk management process and guiding management to continuing improvement. The internal auditor does not take any direct responsibility for making risk management decisions or managing the risk management function. The risk assessment process incorporates value drivers that guide the Group's strategic pursuits. The risk assessments conducted involve risk identification and prioritisation at subsidiary and holding company level, followed by interviews with Senior Management at subsidiary level and key members of Executive Management to confirm risks, their descriptions and prioritisation. Each risk is evaluated in terms of the potential impact, the likelihood of occurrence and the perceived effectiveness of controls in place to manage the risks according to set criteria. The Group has identified its strategic risks and acknowledges that its appetite to accept risk varies across those identified. The assessment process includes the setting of risk appetite and tolerance on a qualitative basis. The outcome of the risk assessments is integral in refining our strategic response and in developing a plan for internal audit engagements for the forthcoming year. Action plans are documented in response to risk appetite and tolerance thresholds that are breached. The Integrated Risk Assurance Policy and Framework will be updated to incorporate the identification and management of opportunities. The Group's material risks are listed here.