95
INTEGRATED REPORT 2017
During the year under review, there were no compliance
concerns in respect of Directors’ dealings. This follows the
commitment made to the JSE to strengthen its internal controls
and processes relating to trading in AfroCentric’s securities. An
information and share dealings policy is in place. Controls are in
place and the Board was inducted on the JSE rules in respect
of share dealings. Constant updates are provided to the Board
via the Company Secretary.
INTERNAL CONTROLS
Organisational policies, procedures, structures and approval
frameworks provide direction, accountability and segregation
of responsibilities and contain self-monitoring mechanisms.
Operational and executive management closely monitor the
controls and actions taken to correct weaknesses as they are
identified. The Head of Group Finance reports directly to the
Group Chief Financial Officer, who is responsible for the overall
financial control and reporting.
Standards of disclosure increased significantly and internal
governance structures and roles were reviewed and improved,
where necessary, to reflect best practices. This occurred at
Board and management levels.
INTERNAL AUDIT
AfroCentric Internal Audit is an independent function governed
by an internal audit charter which is approved by the Audit and
Risk Committee and is reviewed annually. The Internal Audit
Charter defines the role, organisational status authority,
responsibilities and scope of the Internal Audit Activity (“IAA”). It
also includes the principles underlying the realisation of the
objectives of the IAA and the translation thereof into operational
activities. The General Manager: Internal Audit reports at each
Audit and Risk Committee meeting and has a direct reporting
line to the Chairperson of the Audit and Risk Committee. The
Internal Audit function operates independently of executive
management and is not authorised to perform any operational
duties in the Group. For administrative purposes, the General
Manager: Internal Audit reports to the Group Chief Executive
Officer. The internal audit team collectively possesses the
knowledge, skills, experience, tenure and other competencies
needed to fulfil its mandate in an effective and competent
manner. Where specific specialist skills or additional resources
are required, these are obtained from third parties.
The vision of Internal Audit is to add value on a proactive,
objective and independent basis and assist with the
achievement of the Group’s business strategy and objectives
while upholding the core values of mutual respect, accountability,
empowerment, integrity, innovation, accessibility, commitment,
efficiency, proactiveness and professionalism. According to its
core values, AfroCentric’s Internal Audit endeavours to comply
with the highest professional standards of integrity, sound
practice and transparency to build trust and maintain the
interests of client schemes and shareholders at the forefront of
our corporate agenda.
Internal Audit assists AfroCentric to accomplish its strategic
objectives by bringing a systematic, disciplined approach
to evaluating and improving the effectiveness of risk
management, control, and governance processes. This is
achieved by managing the significant risk exposures and
control issues, corporate governance issues and other matters.
These detailed reports of specific results and their action plans
are available on request from the Audit and Risk Committee.
Detailed reports on all audit projects are distributed to executive
management. Management action plans to audit findings are
communicated in detailed form.
The Institute of Internal Auditors (“IIA”) standards require that an
external quality assessment be conducted on the IAA of
an entity at least every five years. AfroCentric Internal Audit has
been subjected to two independent external quality assessment
reviews in 2011 and recently in August 2016. The overall rating
as assessed by the IIA was “Generally Conforms” in both years
and thus the function is entitled to use the “in accordance with
the Standards” statement in their internal audit reports. IAA
aims to meet and exceed the IIA Standards and Code of Ethics.
INFORMATION AND SECURITY GOVERNANCE
IT governance is defined in King III as the “effective and efficient
management of IT resources to facilitate the achievement of
corporate objectives”. It exists to inform and align decision-
making for IT strategy, planning, policy and operations to meet
business objectives and to ensure that risks are managed
appropriately.
The AfroCentric Group applies the principles of King III and is
working towards full compliance with King IV in its governance
frameworks, as far as it is appropriate, and also incorporates
the requirements of Cobit, ISO 27001, ITIL, ISO 38500:2015
and ISAE 3402 in the governance of IT. The Group adopted
a formal IT Governance Framework, which aims to provide
standardisation of IT practices across the organisation and
formalise the good governance requirements stipulated in
Chapter 5 of King III. Security and prevention of data loss
or leakage, remains a core focus.




