Telkom SA SOC Limited
Integrated Report 2017
For the year ended 31 March 2017

Value creation

Banner
  • Download Center

  • Compare to Last Year

What is material in our value-creation process? |
Enterprise risk management (ERM)

The objective of Telkom’s ERM programme is to effect an ERM process to reduce the total cost of risk, add maximum sustainable value to all activities of the group, and assist in achieving key strategic objectives.

Our ERM model is continuously maturing, and is reviewed to ensure that it aligns to our group strategy. Our ERM team conducted intensive risk assessments to ensure that the group identifies the risks it faces, in line with our current strategy. The realisation of our strategy depends on us being able to take calculated risks in a manner that does not jeopardise the direct interests of stakeholders.

Sound management of risk will enable us to anticipate and respond to changes in our environment, as well as to enable us to make informed decisions under conditions of uncertainty.

Telkom adopted a risk management process that provides a converged view of the risks in relation to risk management, corporate compliance and business continuity management.


The board committed Telkom to a process of risk management aligned to the principles of King III, the Committee of Sponsoring Organisations of the Treadway Commission (COSO) Integrated ERM Framework of 2004 and ISO 31000. ERM methodologies are refined through continued research and development, and benchmarked against international best practice.

The board, through the risk committee, is responsible for the total process of risk management and takes ultimate accountability.

We adopted a decentralised risk management approach during the year. This places greater responsibility on the management of the respective business units to implement and report on the policies, frameworks and requirements of the group ERM function. Through the adoption of this approach, it is imperative to maintain and enhance the current maturity of ERM across the group.



The board, through the risk committee, is responsible for the total process of risk management and takes ultimate accountability.

Our risk governance structure

Group risk develops the ERM policy and framework, annual risk management plan and risk appetite framework. It is further responsible for the aggregation of risks, monitoring the risk landscape, communication of emerging risks, and reporting them.

The business units facilitate the implementation of the ERM policy, and framework, risk management plan, and the risk appetite framework.

They implement and maintain the risk registers, identify mitigating controls, implement action plans and operationalise the business unit assurance forum. Each business unit performs ongoing risk exposure analysis in consultation with ERM, who in turn produces a risk profile report, demonstrating the management of key risks and opportunities identified.

The various risk profiles are consolidated for presentation to the business unit assurance forum, risk committee and executive committee. Data generated by ERM assists management in its decision-making. This is an ongoing process, and reports are updated through monitoring the internal and external environment. Risk dashboards and key risk indicators have been developed and implemented to ensure that the risk landscape is effectively monitored.

The business unit assurance forum is a dedicated assurance forum appointed to give effect to the ERM framework through the implementation of an effective process of risk management and combined assurance to optimise risk-taking.

Telkom’s risk appetite

The risk appetite statement and tolerance levels are calibrated against Telkom’s broad financial targets, including dividend policy and operational effectiveness. The statement is prepared annually as part of Telkom’s planning process, combining a top-down view of the group’s risk capacity, with a bottom-up view of the group’s risk profile.

Risk appetite is determined directly in relation to Telkom’s strategy and considered in:

  • strategy setting
  • resource allocation in proportion to the contribution of risk
  • key management decisions and actions

Key actions taken to enhance risk management

  • aligned the risk management programme to Telkom’s new operating model and established risk management functions within the respective business units. The risk governance structure was enhanced by establishing business unit assurance forums
  • enhanced the risk quantification and assessment methodology to support combined assurance and developed a technology-enabled risk assessment application
  • developed and implemented a regulatory universe for the respective business units from a compliance perspective and compiled compliance risk management plans for all priority legislation in the business units
  • developed an ERM risk training module, which was rolled out to senior management

Future focus

In order to maintain our current maturity and improve where possible, growth and maintenance strategies will be implemented. Our focus includes:

  • working on the transitional elements from the current ERM model to the next-generation model, which addresses the transition, risk appetite model and combined assurance, King IV best practice, and redefining operational processes including roles and responsibilities
  • maintaining a converged approach by aligning frameworks across all disciplines, allowing for a common risk language
  • a greater emphasis on the first line of defence and combined assurance
  • revising the risk appetite model’s alignment to strategy, value drivers and business model
  • ownership of risk appetite at group and business unit level
  • deploying our technology-based risk assessment tool


Our risk heatmap


  • 1  Revenue growth and profitability
  • 2  Customer experience
  • 3  Voice revenue decline
  • 4  Human capital health
  • 5  Procurement and property
  • 6  Regulatory and compliance
  • 7  Financial stability
  • 8  Inefficient outdated IT systems
  • 9  Information security
  • 10  Operating model not sustainable
  • 11  Non-compliance with Competition Commission settlement agreement
  • 12  Network transformation
  • 13  Business continuity
  • 14  B-BBEE rating