ENTERPRISE RISK MANAGEMENT

Our robust risk management protects our ability to achieve strategic objectives and identify opportunities.

The Board and its sub-committees oversee the Group’s risk management.

AfroCentric has various governance structures across the Group to manage risk. These structures are chaired by the most senior members of the management team and are accountable to the Board sub-committees. The Group Risk Management function ensures that risk management systems are effectively governed and managed.

We strive to embed robust risk management processes to mitigate risks and identify opportunities.

Enterprise Risk Management Framework

AfroCentric’s Enterprise Risk Management (ERM) Framework is aligned to King IV principles, the Committee of Sponsoring Organisations of the Treadway Commission’s (COSO) ERM Framework, and the International Organization for Standardization (ISO) 31000:2018 Risk Management Framework. This provides a structured and systematic enterprise-wide approach to risks within the Group.

To thoroughly understand our risk landscape, we consider factors in our external and internal environments which could impact the Group’s strategic objectives.

Risk management process

Reporting, communication and consultation

The Board and senior management receive regular reports on the risk profile.

Training promotes risk management across the Group.

 

 

Identification

Strategic risks are identified at Group level and cascaded down to the business units. Business units identify operational risk through their respective operational risk registers.

Various IT, economic growth, people, regulatory and compliance, financial, legal, and internal fraud and external fraud risks and opportunities are identified.


Analysis

The Group assesses the likelihood of the risks in the absence of controls, and it provides a residual risk rating. The Group has Board-approved risk quantification levels to measure the potential impact of the risks.


Evaluation

The Group regularly assesses the risk management system and implements internal controls for each risk. We rely on the BarnOwl risk management system to evaluate each control.


Categorising residual risks

The Group categorises each residual risk as high, medium or low impact.


Formulation of risk mitigation strategies

The Board approves the risk management policy and framework.

These define the Group’s risk appetite and tolerance levels.

 

Monitoring and reviewing risks

We consistently monitor ERM and regularly conduct comprehensive risk assessments.

 

Risk appetite and tolerance

The Group has a detailed Board-approved risk appetite statement for individual risk categories. The statement applies to all entities within the Group.

The Group did not encounter any material breaches, or undue, unexpected or unusual risks outside of risk appetite levels during the year.

Combined Assurance

Our combined assurance framework is underpinned by a three lines of defence model that specifies and delegates accountability for managing, overseeing and independently assuring risks across the Group.

The duties of each line of defence are described below:

The combined assurance framework has been developed to provide principles and guidelines that will be utilised in implementing combined assurance across the Group, and will continue to evolve as this process is embedded and matures across the business.

1
First line of defence
 
Business unit management
The Group risk management team appoints, trains and guides risk champions within each business unit. Risk champions are the decision-makers and risk owners who identify, manage and monitor risks in their respective business units.

2
Second line of defence
 
Risk management and compliance functions
Our risk management and compliance functions develop a risk management framework. They coordinate and monitor the first line’s implementation of the Group’s risk management framework.

3
Third line of defence
 
Internal and external audit
Internal and external audit provide independent assurance on the effectiveness and consistency of the first and second line functions. Internal and external audit report to the Audit and Risk Committee.

 

The Board of AfroCentric Group is committed to the maintenance and upholding of sound corporate governance practices as imperative to the success of the Group and its subsidiaries, and to the adherence of sound corporate principles in the management of its business.