IAR
 
AFS
 
AGM
   
INTEGRATED ANNUAL REPORT
30 JUNE 2015

Risk Management

Enterprise Risk Management (ERM) can be defined as a process effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.*

* Committee of Sponsoring Organisations (COSO) Enterprise Risk Management – Integrated Framework.

  Steffen Nizetich

RISK STRATEGY

The Board has overall responsibility for the adoption, oversight and reporting of Growthpoint’s risk management framework. The Board is assisted in this by the Risk Management Committee, which meets quarterly. Growthpoint’s ERM framework encompasses four distinct categories:

Strategic risk
Operations risk
Reporting risk
Compliance risk

STRATEGIC RISK

Risk is an event that could inhibit an organisation’s ability to achieve its strategic objectives. The manner in which the Board and management choose to respond to such strategic risks establishes the organisation’s risk management philosophy and culture.

The risk philosophy and culture adopted is influenced by Growthpoint’s vision, mission, objectives and values, which likewise define the company’s risk appetite (the extent of risk that the Board and management are willing to accept in pursuit of value) and risk tolerance (the acceptable level of deviation from that risk).

Risk Management StructureStrategic, as well as potential operational risks are identified annually by Growthpoint’s Chief Executive Officer in consultation with certain members of executive management.

Nonetheless, given that strategic risk assessment is an ongoing process throughout the financial year, the Risk Management Committee is able to add additional risks, reassess existing risks, or remove risks as required.

A key outcome of this process is that an appropriate response is determined for each strategic risk.

The strategic risks identified for FY15 are reflected within the Key Risks and Opportunities section of the report, as are management’s responses thereto.

OPERATIONS RISK

The operational risks are identified in the same manner as the strategic risks. However, due to the nature of the operational risks, they are managed in a more intense manner.

The key operational risks identified are assessed in terms of their probability, as well as their impact on the organisation.

Strategies are pinpointed to mitigate the impact of the risks, if and when they arise. Risk management strategies focus on one of four approaches:

Control
Tolerate
Terminate

Where management opts to control an operational risk, the relevant control is identified, as is the person accountable, the monitoring frequency and the key performance indicator.

Risk information needs to be processed and communicated in a timely manner, to ensure an appropriate response. At Growthpoint, property information is generated monthly by key business processes and is accessible at numerous levels: from data on individual buildings, to sector business units, and sectors. This excludes the V&A Waterfront and GOZ, who each have their own risk management approach. Fund-related information is generated by the Group finance function either monthly or quarterly.

A pivotal role of Growthpoint’s Risk Management Committee is to ensure that the controls implemented by management are effective. While executive management identifies the metrics used to monitor such controls, it is the internal audit and risk management function that collates the results and presents a quarterly report to the Risk Management Committee.

Furthermore, Internal Audit assists management in assessing whether or not systems of internal control are adequate and effective.

The key operational risks identified for FY15 are reflected within the Key Risks and Opportunities section of the report, as are the appropriate mitigation strategies and the relevant performance measures.

REPORTING RISK

Reporting risk is the risk that financial-related information is unintentionally altered, or deliberately manipulated.

Executive and financial management have established systems of internal control to provide reasonable assurance of the validity, accuracy, completeness and timely accumulation of financial data. Such internal controls are subject to independent assessment by Internal Audit when performing regular business process reviews. These reviews typically assess the adequacy and effectiveness of controls pertaining to financial data at general ledger and management reporting level.

Reliance is placed on external auditors to ensure the fair presentation of the financial information at a statutory reporting level. In addition, controls in the form of analytical reviews and reconciliations to sources independent of the financial system are performed by the Group finance function. These controls are subject to review and assessment by Internal Audit.

COMPLIANCE RISK

Primary legislation affecting Growthpoint is identified and documented by the company secretarial function in conjunction with the in-house legal team. The purpose of the exercise is to determine responsibility for the legislation that impacts on Growthpoint operations.

Where necessary, or if prescribed by legislation, Compliance Officers are appointed to oversee adherence to the relevant Acts.

Growthpoint appoints employees to positions based on their expertise and experience. Employees are expected to keep abreast of legislation and compliance requirements that affect their particular area of responsibility.

Take the example of Growthpoint’s Risk Information Management System (RIMS), developed because of the property focus of the company’s operation. The software program encompasses the following legislation.

Building regulations
Occupational Health and Safety/Compensation for Occupational Injuries and Diseases Acts
Fire compliance

Facilities personnel complete an electronic checklist for each building, each quarter. The results thereof can be analysed on a building, sector business unit, sector and/or geographic basis. This readily facilitates the identification of common issues that require management’s attention.

Compliance with the aforementioned legislation is the responsibility of a dedicated Risk Officer who:

performs independent visits to buildings on a regular basis
liaises with tenants when conducting building inspections
liaises with both facilities and property personnel
liaises with insurers
initiates training interventions, where required

The work of the Risk Officer is complemented by Growthpoint’s insurers, an independent external party, who undertake inspections of buildings on a regular basis to ensure that the insurable cover is commensurate with the insurable risk that they have underwritten.

Other examples of how Growthpoint actively manages compliance issues include

The in-house Legal Department is expected to remain abreast of new and/or amended legislation and, where applicable bring such legislation to the attention of the Risk Management Committee and the Board
The Company Secretary is responsible for compliance with the Companies Act and JSE Listings Requirements