Our risks
Our robust risk management approach supports our strategy's implementation and enables us to identify opportunities.
AfroCentric's risk management is overseen by the Board and its sub-committees and managed by governance structures. These structures are chaired by senior management team members and are accountable to Board sub-committees. Risk management systems are effectively governed and managed by the Group risk management function.
We strive to mitigate risks and identify opportunities with our robust risk management processes.
Enterprise Risk Management framework
AfroCentric's Enterprise Risk Management (ERM) framework is aligned with King IV principles, the Committee of Sponsoring Organisations of the Treadway Commission's (COSO's) ERM framework, and the International Organization for Standardization (ISO) 31000:2018 risk management framework. The ERM framework provides a structured and systematic enterprise-wide approach to risks within the Group.
We gain insight into our risk landscape by considering external and internal factors that could positively or negatively influence our strategic objectives.
Reporting, communication and consultation
The Board and senior management receive regular reports on the risk profile.
Training promotes risk management across the Group.
Identification
Strategic risks are identified at Group level and cascaded down to business units which identify operational risk through their respective risk registers.
IT, cybersecurity, economic/growth, people, regulatory and compliance, financial, legal, and internal fraud and external fraud risks and opportunities are identified.
Analysis
The Group assesses the likelihood of the risks in the absence of controls and provides a residual risk rating. The Group has Board-approved risk quantification levels to measure the potential impact of risks.
Evaluation
The risk management system is regularly assessed by the Group, which implements internal controls for each risk. The BarnOwl Risk Management System Software is used to evaluate each control.
Categorising residual risks
Each residual risk is categorised as high, medium or low impact.
Formulation of risk mitigation strategies
The Board approves the risk management policy and framework that define the Group's risk appetite and tolerance levels.
Monitoring and reviewing risks
We consistently monitor ERM and regularly conduct comprehensive risk assessments.
Overview of our top risks
Please see our material matter discussion on page 38 for information on how our top risks are integrated into our materiality process.
Remains unchanged 
Trend improving 
Trend worsening 
IT RISKS
| Risk description | Root cause | Inherent rating | Existing controls | Previous residual rating | Current residual rating | Movement | ||||||
| Resource constraint/people risk: Heavy reliance on certain individuals with critical technical skills to support business demand |
|
20 |
|
9 | 10 | ![]() |
||||||
| IT Infrastructure: Obsolete and legacy IT infrastructure that has reached end of life and is no longer supported |
|
20 |
|
12 | 16 | ![]() |
||||||
| System stability/availability: Unavailability and unreliability of critical IT systems, leading to business disruption |
|
20 |
|
6 | 16 | ![]() |
||||||
| Cybersecurity vulnerabilities: Ineffective cyber defence controls and mechanisms to protect critical infrastructure, systems and data against malicious cyber attacks |
|
25 |
|
12 | 12 | ![]() |
||||||
| Technologies: Inability to remain relevant in the face of new disruptive technologies |
|
20 |
|
6 | 6 | ![]() |
Remains unchanged 
Trend improving 
Trend worsening 
ECONOMIC/GROWTH RISKS
| Risk description | Root cause | Inherent rating | Existing controls | Previous residual rating | Current residual rating | Movement | ||||||
| NHI: Possible substantial reduction of the scope and size of Medscheme's offering, client base, and revenue should NHI be implemented. There will be a similar impact on the EssentialMed and Sanlam Gap businesses |
|
25 |
|
12 | 12 | ![]() |
||||||
| Membership: Inability to attract/retain members for our clients |
|
25 |
|
16 | 12 | ![]() |
||||||
| Loss of clients: Loss of clients (Reduction of client base) |
|
20 |
|
9 | 9 | ![]() |
BUSINESS/REPUTATIONAL RISKS
| Risk description | Root cause | Inherent rating | Existing controls | Previous residual rating | Current residual rating | Movement | ||||||
| COVID-19 risk: Failure to implement COVID-19 regulations and ensure continuity of the business |
|
20 |
|
9 | 6 | ![]() |
||||||
| Business continuity risks: Failure to ensure proper business continuity in the event of a disaster/ crisis |
|
20 |
|
4 | 4 | ![]() |
Risk appetite and tolerance
A detailed Board-approved risk appetite statement for individual risk categories applies to all Group entities. The Group did not experience any material breaches or undue, unexpected or unusual risks beyond risk appetite levels in 2022.





