Risk management

Our risk management framework is embedded in the day-to-day operations of the Group. It promotes responsible risk-taking, aids better understanding of the potential impact of risks and opportunities, including those related to ESG, on our strategic objectives and the likelihood of these risks materialising. It also identifies effective action plans to mitigate risks and realise opportunities.

Governance and structure

Risk management framework

Provides the foundations and organisational arrangements for designing, implementing, monitoring, reviewing and continually improving risk management.

The board and its sub-committees

Responsible for the governance of risk and ensuring that formal processes are implemented to effectively manage the risks facing the Group.

Executive Committee and the divisional finance and risk review committees (FRRCs)

Responsible for managing all risks and implementing relevant risk governance processes, standards, policies and frameworks.

The board delegates the responsibility for the implementation and execution of risk management to the Executive Committee and FRRCs. The board and its committees oversee the effectiveness of risk management, receiving regular reports and periodic assurance.

Risk management processes

Risk culture

Communication and
consultation

Risk appetite and tolerance

Risk
assessment

Risk
response

Risk taxonomy

Monitoring
and review

The risk appetite sets out the amount and type of risk that the Group is prepared to pursue, retain or take in pursuit of its objectives and the creation of value. Our risk management policies, procedures and practices are systematically applied to the above activities.

Risk controls

Additional measures to enhance the effectiveness of risk management include internal controls, control self-assessments (CSAs), head office monitoring and oversight, and Group compliance and risk forums.

Our internal control hierarchy

Monitoring

Documented monitoring of processes, routines and controls.

Implementing policies and procedures

Management controlled activities, including development of strategies, action plans and budgets as well as principles, rules and procedures.

Ensuring sound governing principles

This includes our values, ethics guidelines, Code of Ethics, delegation of roles and responsibilities and oversight committees. Our leaders are expected to lead by example.

Three lines of defence

Our combined assurance framework provides a co-ordinated Group-wide approach to risk management to ensure its effectiveness.

FIRST LINE OF DEFENCE – management

Responsible for the identification and management of risks in line with agreed risk policies, appetite and tolerance levels, and controls at an operational level.

SECOND LINE OF DEFENCE – risk management, compliance, legal, quality control functions

Responsible for overseeing and monitoring various risks and developing appropriate tools to effectively manage these risks.

THIRD LINE OF DEFENCE – internal audit, external audit, independent assurance providers

Assurance providers and auditors offer oversight and assurance to the board and management on the adequacy and effectiveness of the controls implemented. External auditors provide an opinion on the fair presentation of the consolidated and separate annual financial statements in accordance with IFRS and the Companies Act.

All three lines of defence report to the board; either directly or through ARC and the SES Committee. Both committees are responsible for overseeing various ESG aspects (see ESG governance framework.)

People, process, data, systems, infrastructure

Risk culture and values

Our values require that we are honest, transparent and communicate the level of exposure we take in the pursuit of value creation and preservation and the extent to which we guard against value erosion.

Control self-assessment

Our Group-wide CSA Programme and process risk registers support the combined assurance framework. The business processes, risks and controls within each business segment are documented, and employees and supervisors use this to assess the adequacy of the controls within their operation and to identify gaps. Over 3 650 employees are involved in some form of CSA on a monthly basis. The programme is designed to standardise and benchmark minimum requirements across the Group, improving the control environment, providing proof of oversight and allowing for early detection of key concerns so that they are quickly addressed. Oversight takes place at operational management level for all business areas with additional monitoring for larger operations. This is then collated into business segment reporting. The CSA Programme incorporates financial and operational controls, including the controls used to manage our ESG-related risks.

The CSA Programme is providing a better understanding of our business operations, cultivating a stronger awareness of risk practices and reinforcing our governance framework. In addition, it limits the need for extensive audits, and reduces auditor fatigue and assurance overload.

The programme is in place across the Group other than Australia where a different process that is more relevant to that operation has been implemented.

2022 performance and key objectives

  • Nothing came to Group internal audit's attention to indicate any material breakdown in internal controls during 2022. Group internal audit is of the view that Motus' governance processes, risk management and system of internal controls are adequate and effective.
  • This year we focused on developing an adequate level of reporting against the CSA. The overall completion rate for the year was 93% (target: over 90%) and the overall compliance rate was 97% (target: over 95%) across 10 areas, excluding Australia.
Page 24 admin image

Our approach to managing climate-related risks

We consider our climate-related risks in alignment with the recommendations formulated by the TCFD. The SES Committee receives a quarterly risk assessment on our climate-related risks, which includes risk impacts, our responses and relevant key performance indicators (KPIs). Climate change-related risks, both current and emerging, are identified for our operations, suppliers and the rest of the value chain. Our risk assessment process considers strategic, business and operational risks that could occur as far as 10 years into the future. Each operation identifies the risks to its business and quantifies the potential impact. This is recorded in the business segment or regional risk register, which covers predominantly operational risks. Risks are reviewed by the FRRCs quarterly and elevated to Group-level. The business segment or regional risk registers and the Group-level risks are reported to ARC. Strategic risks are discussed with business segments and regions to ensure alignment.

Managing our risks and opportunities, including our top business risks.