Control self-assessment
Our Group-wide CSA Programme and process risk registers support the combined assurance framework. The business processes, risks and controls within each business segment are documented, and employees and supervisors use this to assess the adequacy of the controls within their operation and to identify gaps. Over 3 650 employees are involved in some form of CSA on a monthly basis. The programme is designed to standardise and benchmark minimum requirements across the Group, improving the control environment, providing proof of oversight and allowing for early detection of key concerns so that they are quickly addressed. Oversight takes place at operational management level for all business areas with additional monitoring for larger operations. This is then collated into business segment reporting. The CSA Programme incorporates financial and operational controls, including the controls used to manage our ESG-related risks.
The CSA Programme is providing a better understanding of our business operations, cultivating a stronger awareness of risk practices and reinforcing our governance framework. In addition, it limits the need for extensive audits, and reduces auditor fatigue and assurance overload.
The programme is in place across the Group other than Australia where a different process that is more relevant to that operation has been implemented.
2022 performance and key objectives
- Nothing came to Group internal audit's attention to indicate any material breakdown in internal controls during 2022. Group internal audit is of the view that Motus' governance processes, risk management and system of internal controls are adequate and effective.
- This year we focused on developing an adequate level of reporting against the CSA. The overall completion rate for the year was 93% (target: over 90%) and the overall compliance rate was 97% (target: over 95%) across 10 areas, excluding Australia.
Our approach to managing climate-related risks
We consider our climate-related risks in alignment with the recommendations formulated by the TCFD. The SES Committee receives a quarterly risk assessment on our climate-related risks, which includes risk impacts, our responses and relevant key performance indicators (KPIs). Climate change-related risks, both current and emerging, are identified for our operations, suppliers and the rest of the value chain. Our risk assessment process considers strategic, business and operational risks that could occur as far as 10 years into the future. Each operation identifies the risks to its business and quantifies the potential impact. This is recorded in the business segment or regional risk register, which covers predominantly operational risks. Risks are reviewed by the FRRCs quarterly and elevated to Group-level. The business segment or regional risk registers and the Group-level risks are reported to ARC. Strategic risks are discussed with business segments and regions to ensure alignment.
Managing our risks and opportunities, including our top business risks.