Risk Management
Enterprise Risk Management (ERM) can be defined as a process
effected by an entity’s board of directors, management and other
personnel, applied in strategy setting and across the enterprise,
designed to identify potential events that may affect the entity, and
manage risks to be within its risk appetite, to provide reasonable
assurance regarding the achievement of entity objectives.*
* Committee of Sponsoring Organisations (COSO) Enterprise Risk Management – Integrated Framework. |
|
 |
RISK STRATEGY
The Board has overall responsibility for
the adoption, oversight and reporting of
Growthpoint’s risk management framework.
The Board is assisted in this by the Risk
Management Committee, which meets
quarterly. Growthpoint’s ERM framework
encompasses four distinct categories:
| • |
Strategic risk |
| • |
Operations risk |
| • |
Reporting risk |
| • |
Compliance risk |
STRATEGIC RISK |
Risk is an event that could inhibit an
organisation’s ability to achieve its strategic
objectives. The manner in which the Board
and management choose to respond to such
strategic risks establishes the organisation’s risk
management philosophy and culture.
The risk philosophy and culture adopted is
influenced by Growthpoint’s vision, mission,
objectives and values, which likewise define
the company’s risk appetite (the extent of risk
that the Board and management are willing to
accept in pursuit of value) and risk tolerance
(the acceptable level of deviation from
that risk).
Strategic, as well as potential operational risks
are identified annually by Growthpoint’s Chief
Executive Officer in consultation with certain
members of executive management.
Nonetheless, given that strategic risk
assessment is an ongoing process throughout
the financial year, the Risk Management
Committee is able to add additional risks,
reassess existing risks, or remove risks as
required.
A key outcome of this process is that an
appropriate response is determined for each
strategic risk.
The strategic risks identified for FY15 are
reflected within the Key Risks and
Opportunities section of the report, as are
management’s responses thereto.
OPERATIONS RISK
The operational risks are identified in the same
manner as the strategic risks. However, due
to the nature of the operational risks, they are
managed in a more intense manner.
The key operational risks identified are assessed
in terms of their probability, as well as their
impact on the organisation.
Strategies are pinpointed to mitigate the
impact of the risks, if and when they arise. Risk
management strategies focus on one of four
approaches:
| • |
Control |
| • |
Tolerate |
| • |
Terminate |
Where management opts to control an
operational risk, the relevant control is
identified, as is the person accountable, the
monitoring frequency and the key performance
indicator.
Risk information needs to be processed
and communicated in a timely manner, to
ensure an appropriate response. At
Growthpoint, property information is
generated monthly by key business processes
and is accessible at numerous levels: from
data on individual buildings, to sector
business units, and sectors. This excludes
the V&A Waterfront and GOZ, who each
have their own risk management approach.
Fund-related information is generated by
the Group finance function either monthly
or quarterly.
A pivotal role of Growthpoint’s Risk
Management Committee is to ensure that
the controls implemented by management
are effective. While executive management
identifies the metrics used to monitor such
controls, it is the internal audit and risk
management function that collates the results
and presents a quarterly report to the Risk
Management Committee.
Furthermore, Internal Audit assists
management in assessing whether or not
systems of internal control are adequate and
effective.
The key operational risks identified for
FY15 are reflected within the Key Risks
and Opportunities section of the report, as are
the appropriate mitigation strategies and the
relevant performance measures.
REPORTING RISK
Reporting risk is the risk that financial-related
information is unintentionally altered, or
deliberately manipulated.
Executive and financial management have
established systems of internal control
to provide reasonable assurance of the
validity, accuracy, completeness and timely
accumulation of financial data. Such internal
controls are subject to independent assessment
by Internal Audit when performing regular
business process reviews. These reviews
typically assess the adequacy and effectiveness
of controls pertaining to financial data at
general ledger and management reporting
level.
Reliance is placed on external auditors to ensure
the fair presentation of the financial information
at a statutory reporting level. In addition,
controls in the form of analytical reviews and
reconciliations to sources independent of the
financial system are performed by the Group
finance function. These controls are subject to
review and assessment by Internal Audit.
COMPLIANCE RISK
Primary legislation affecting Growthpoint is
identified and documented by the company
secretarial function in conjunction with the in-house
legal team. The purpose of the exercise
is to determine responsibility for the legislation
that impacts on Growthpoint operations.
Where necessary, or if prescribed by legislation,
Compliance Officers are appointed to oversee
adherence to the relevant Acts.
Growthpoint appoints employees to positions
based on their expertise and experience.
Employees are expected to keep abreast of
legislation and compliance requirements
that affect their particular area of
responsibility.
Take the example of Growthpoint’s Risk
Information Management System (RIMS),
developed because of the property focus of the
company’s operation. The software program
encompasses the following legislation.
| • |
Building regulations |
| • |
Occupational Health and Safety/Compensation for Occupational Injuries
and Diseases Acts |
| • |
Fire compliance |
Facilities personnel complete an electronic
checklist for each building, each quarter.
The results thereof can be analysed on a
building, sector business unit, sector and/or
geographic basis. This readily facilitates the
identification of common issues that require
management’s attention.
Compliance with the aforementioned
legislation is the responsibility of a dedicated
Risk Officer who:
| • |
performs independent visits to buildings on a
regular basis |
| • |
liaises with tenants when conducting
building inspections |
| • |
liaises with both facilities and property
personnel |
| • |
liaises with insurers |
| • |
initiates training interventions, where
required |
The work of the Risk Officer is complemented
by Growthpoint’s insurers, an independent
external party, who undertake inspections
of buildings on a regular basis to ensure that
the insurable cover is commensurate with the
insurable risk that they have underwritten.
Other examples of how Growthpoint actively
manages compliance issues include
| • |
The in-house Legal Department is expected
to remain abreast of new and/or amended
legislation and, where applicable bring
such legislation to the attention of the Risk
Management Committee and the Board |
| • |
The Company Secretary is responsible for
compliance with the Companies Act and JSE
Listings Requirements |