Our risks

Our robust risk management approach supports our strategy's implementation and enables us to identify opportunities.

AfroCentric's risk management is overseen by the Board and its sub-committees and managed by governance structures. These structures are chaired by senior management team members and are accountable to Board sub-committees. Risk management systems are effectively governed and managed by the Group risk management function.

We strive to mitigate risks and identify opportunities with our robust risk management processes.

Enterprise Risk Management framework

AfroCentric's Enterprise Risk Management (ERM) framework is aligned with King IV principles, the Committee of Sponsoring Organisations of the Treadway Commission's (COSO's) ERM framework, and the International Organization for Standardization (ISO) 31000:2018 risk management framework. The ERM framework provides a structured and systematic enterprise-wide approach to risks within the Group.

We gain insight into our risk landscape by considering external and internal factors that could positively or negatively influence our strategic objectives.

Reporting, communication and consultation

The Board and senior management receive regular reports on the risk profile.

Training promotes risk management across the Group.

Identification

Strategic risks are identified at Group level and cascaded down to business units which identify operational risk through their respective risk registers.

IT, cybersecurity, economic/growth, people, regulatory and compliance, financial, legal, and internal fraud and external fraud risks and opportunities are identified.

Analysis

The Group assesses the likelihood of the risks in the absence of controls and provides a residual risk rating. The Group has Board-approved risk quantification levels to measure the potential impact of risks.

Evaluation

The risk management system is regularly assessed by the Group, which implements internal controls for each risk. The BarnOwl Risk Management System Software is used to evaluate each control.

Categorising residual risks

Each residual risk is categorised as high, medium or low impact.

Formulation of risk mitigation strategies

The Board approves the risk management policy and framework that define the Group's risk appetite and tolerance levels.

Monitoring and reviewing risks

We consistently monitor ERM and regularly conduct comprehensive risk assessments.

Overview of our top risks

Please see our material matter discussion on page 38 for information on how our top risks are integrated into our materiality process.

Remains unchanged

Trend improving

Trend worsening

IT RISKS

Risk description Root cause Inherent rating Existing controls Previous residual rating Current residual rating Movement
Resource constraint/people risk: Heavy reliance on certain individuals with critical technical skills to support business demand
  1. Unavailability of skilled/dedicated resources
20
  1. New IT operating model
  2. Business prioritisation forum
  3. Upskilling where possible
  4. Appointment of relevant technical resources
  5. Panel of service providers
  6. Resource and knowledge shared among the team
9 10 Worsened
IT Infrastructure: Obsolete and legacy IT infrastructure that has reached end of life and is no longer supported
  1. Further investment required to support system stability and availability
20
  1. Extended support and maintenance with vendors
  2. Data migration project steerco established
  3. Implementation of new infrastructure equipment
12 16 Worsened
System stability/availability: Unavailability and unreliability of critical IT systems, leading to business disruption
  1. Reliance on third parties
  2. Enhanced system maintenance required
20
  1. Supplier contracted to provide managed services for IT operations
  2. Timeous software upgrades to minimise the risk of ageing technologies
  3. Monitoring tools to detect vulnerability
  4. Regular maintenance schedules
6 16 Worsened
Cybersecurity vulnerabilities: Ineffective cyber defence controls and mechanisms to protect critical infrastructure, systems and data against malicious cyber attacks
  1. Additional investment in infrastructure required
25
  1. Information security strategy, framework, related policies and procedures
  2. Cybersecurity service improvement programme
  3. Ongoing vulnerability and maturity assessments
  4. Security monitoring tools upgraded
  5. New firewall implemented
12 12 Unchanged
Technologies: Inability to remain relevant in the face of new disruptive technologies
  1. Enhanced requirement for research and development
  2. Need for enhanced technology architecture
20
  1. Digital strategy plan
  2. New enterprise architecture
  3. Best technologies implemented (Telemedicine/ Virtual Care, Mobile App, Lead Management Systems/Brokers Portal for schemes)
  4. Key digital solutions implemented
  5. Biannual sessions with strategic partners
6 6 Unchanged

Remains unchanged

Trend improving

Trend worsening

ECONOMIC/GROWTH RISKS

Risk description Root cause Inherent rating Existing controls Previous residual rating Current residual rating Movement
NHI: Possible substantial reduction of the scope and size of Medscheme's offering, client base, and revenue should NHI be implemented. There will be a similar impact on the EssentialMed and Sanlam Gap businesses
  1. Provisions of the NHI Bill
  2. Long duration of NHI implementation
25
  1. Communication plan
  2. Engagement with the NDoH and the Presidency on policy direction
  3. Engagement with Provincial Departments of Health for revenue diversification
12 12 unchanged
Membership: Inability to attract/retain members for our clients
  1. People unable to afford high medical costs
25
  1. Growth and retention strategy with targets
  2. Dedicated retention unit
  3. Amalgamations for membership growth
  4. AMP (Wellness + Loyalty) product launched
  5. Technology-based option with lower contributions launched
  6. Sanlam Health solution launched
16 12 improved
Loss of clients: Loss of clients (Reduction of client base)
  1. Competitive tariffs
  2. Market consolidation of small schemes
20
  1. Extensive negotiation strategy
  2. Network management strategy
  3. Amalgamations
  4. Stakeholder management framework
  5. Early notification of contract renewals
  6. Executive support refocused to support open schemes through the revised approved health risk management structure
  7. SmartCare, SmartServices, SmartWork strategy implemented
9 9 unchanged

BUSINESS/REPUTATIONAL RISKS

Risk description Root cause Inherent rating Existing controls Previous residual rating Current residual rating Movement
COVID-19 risk: Failure to implement COVID-19 regulations and ensure continuity of the business
  1. Global Pandemic
20
  1. Education and counselling support services offered by Group for employees
  2. Ongoing adherence to related legislation and best practice
  3. OHS Committee to oversee and address risks
9 6 improved
Business continuity risks: Failure to ensure proper business continuity in the event of a disaster/ crisis
  1. IT system and connectivity failures
  2. Water and power supply failures
  3. Environmental threats, such as fire, gas, bomb threats or natural disasters
  4. Physical threats: security or political unrest
20
  1. BCM policy, plans and procedures
  2. Business Continuity Oversight Committee
  3. Multiple generators per site and mobile generators
  4. Water reservoirs
  5. Portable sanitation resources
4 4 unchanged

Risk appetite and tolerance

A detailed Board-approved risk appetite statement for individual risk categories applies to all Group entities. The Group did not experience any material breaches or undue, unexpected or unusual risks beyond risk appetite levels in 2022.