Enterprise risk management
Our philosophy
Effective risk management is critical in managing Telkom’s
risk profile. The realisation of our strategy depends on our
ability to take calculated risks that do not jeopardise the
direct interests of our shareholders, employees, customers,
regulators, broader society and other stakeholders.
Sound risk management helps us anticipate and respond
to changes in our environment and to make informed
decisions under conditions of uncertainty.
At Telkom, we are committed to optimising risk
management in order to achieve our vision and objectives,
and protect our core values. Doing this requires a strategic
and functional approach to risk management. Telkom’s
NGNEC project and the recent investment in Telkom Mobile
were the most significant risks to the Group from a strategy
perspective. The main focus of ERM for 2013 has thus
been to de-risk these strategies as far as possible to provide
sustainable value to the Group.
Telkom has adopted a group-wide approach to risk
management where each risk is managed in an integrated,
structured and systematic process within a unitary framework
aligned with Telkom’s corporate governance responsibilities.
The Board is committed to a process that complies
with the principles of the King III Report on Corporate
Governance 2010 and the COSO Integrated Enterprise Risk
Management Framework of 2004. All divisions, supporting
functions, processes, projects and other controlled entities
are subject to the Enterprise Risk Management Policy.
Telkom’s board of directors holds ultimate responsibility for
the Group’s risk management process and the evaluation
of its effectiveness. Executive management is accountable
for identifying major risks, designing, implementing and
monitoring the risk identification process, and integrating
it into the Group’s day-to-day activities.
It is important that risk management processes become
embedded in the Group’s systems and processes to
ensure current and dynamic responses to risk. All key risks
associated with major changes and significant actions by
Telkom fall within the processes of risk management.
The enterprise risk management
division
The ERM division set out to achieve the following key
objectives:
Oversight: All critical risks are identified group-wide and
are managed and monitored under a holistic approach
consistent with the Risk Committee approved risk appetite
statement.
Ownership and responsibility: The ownership of risk is
assigned to management individuals who are responsible
for identifying, evaluating, mitigating and reporting risk
exposures.
Assurance: The Board, Exco, Risk Committee, Telkom
Executive Risk Management Council and management
have reasonable assurance that the risk is being
appropriately managed within defined levels to bring value
to the organisation.
To achieve these high-level objectives the Group employs
the following tactics:
| • |
De-risking all business plans based on risk appetite and
risk bearing capacity (RBC), through regular assessment
and monitoring with management; |
| • |
Ensuring timely identification of all risks; |
| • |
Completing timely, accurate and relevant risk reporting
and monitoring of key risk indicators (KRIs); |
| • |
Quantifying loss events (Business Continuity
Management (BCM) and insurance); |
| • |
Assessing unpredictable risks with management and
the Group’s exposure to these risks; |
| • |
Proactively identifying and addressing bottlenecks in
performance with management; and |
| • |
Tracking action plans on a monthly basis for
effective mitigation. |
In order to optimise the risk management process, Telkom
applies all resources used in its risk management process in
an economic manner. This is to ensure:
| • |
The highest standards of service delivery; |
| • |
A management system that aims to minimise risk and
costs in the interest of all stakeholders; |
| • |
Education and training of all our staff to ensure
continuous improvement in knowledge, skills and
capabilities to maintain conformance with stakeholders
expectations; and |
| • |
An environment that promotes the right attitude
and sensitivity towards internal and external
stakeholder satisfaction. |
Risk management process
The ERM process is driven by a series of activities and events
designed to integrate ERM within business processes across
the enterprise and ensure that there is standardisation
across all these occurrences.
ERM is not strictly a serial process, where one component
affects only the next. It is a multi-directional, iterative process
in which almost any component can and does influence
another. It is also important to ensure that the ERM process
and risks are re-evaluated and updated on an ongoing
basis to reflect new information and experiences so that all
significant risks are appropriately identified and addressed
and that any material opportunities are not overlooked.
The following cyclical flow depicts the critical enterprise
functional risk management responsibilities undertaken on
an ongoing basis:

Maturity
The rising prominence of governance and risk management is a response to the increasing complexity of large and global
organisations, corporate scandals and the collapse of the banking sector. The table below contextualises GRECS (Governance,
risk, ethics, compliance and sustainability) convergence:
| |
Current state |
To prevent business failure and non-compliance, companies have expanded their
governance, risk, ethics, compliance and sustainability departments, often resulting
in a web of unco-ordinated structures, policies, committees and reports.
To improve this, internal auditors, risk officers and compliance officers have begun
to work closely to find commonalities among disparate GRECS projects. Some
organisations have formed GRECS committees. Such efforts have increasingly come
under the banner of GRECS convergence.
GRECS convergence is a way to rationalise risk management and controls, providing
management with the information needed to improve business performance and
achieve compliance. |
| |
Internal and external influences |
Business complexity, a desire to reduce organisational risk exposure and improve
corporate performance is fuelling GRECS convergence.
Recent economic events have rekindled interest in corporate governance and
operational risk management among regulators, ratings agencies, politicians, media
and the public.
Executive management and regulators are the main driving forces behind GRECS
convergence across publicly listed companies and State-owned organisations. |
| |
Costs and benefits |
Key benefits of GRECS convergence include the ability to identify and manage risks
more quickly, improve corporate performance and help reduce the costs of duplication.
Rationalising GRECS through integration could go a long way to reduce the ultimate
GRECS cost.
Any move towards GRECS convergence is likely to be a lengthy process that requires
an accompanying shift in corporate culture. |
Telkom’s current state risk maturity
A crucial element of a successful and effective ERM
programme is assessing and enhancing the maturity
of the programme across the Group. In this context, as
emphasised in King III, risk is positioned as a cornerstone
of corporate governance and risk governance.
Telkom’s risk appetite has been developed and calculated
and is still to be fully implemented into the business. Because
Telkom’s risk appetite has not been fully operationalised
there might be a misalignment between strategic direction
and risk taking.
During the current year we enhanced our risk methodology
to integrate BCM, insurance and risk finance, compliance
and fraud management into a single risk and reporting
framework.
Key achievements and initiatives
in 2013
The two most significant strategic initiatives undertaken
from a risk perspective during 2013 were Telkom’s NGNEC
project and the ongoing investment in Telkom Mobile.
NGNEC
The NGNEC project was undertaken to modernise Telkom’s
network in order to defend and grow our position in a highly
competitive market. It is therefore critical that this highly
intensive capital investment yields a sustainable outcome
and creates opportunities for the Group. This required ERM
to be implemented throughout the life cycle of the project,
which allowed us to achieve the following:
| • |
Strong presence on all steering committees; |
| • |
Identification, assessment and monitoring of all risks; |
| • |
Integration of NGNEC risks into business unit’s
risk registers; |
| • |
Reporting on the risks to all interested parties; and |
| • |
Actively identifying opportunities. |
Telkom mobile
Telkom Mobile was established to offset the decline in fixedline
voice revenues. Given the significant amount of capital
invested in this business, it is imperative that ERM has a
strong presence in the Mobile division. The ERM function
has helped facilitate the following:
| • |
Creating a strong presence on all committees
and projects; |
| • |
De-risking growth in pre-paid, post-paid and data; |
| • |
Assisting with the identification, assessment and
monitoring of all risks; |
| • |
Reporting on the risks to all interested parties; and |
| • |
Focusing on identifying and seizing opportunities. |
During the financial year under review we continued
to make progress towards an enhanced ERM programme.
Notable achievements for 2013 include:
| • |
Completion of the GRECS convergence project in
November 2012, which has since been operationalised
as business as usual; |
| • |
Successful integration of business continuity
management (BCM) with the ERM methodology, with
88% of all business continuity plans completed; |
| • |
Development of a risk appetite framework and
associated monitoring in order to increase the
effectiveness and maturity of risk management; |
| • |
Development of an enhanced report on risk indicators; |
| • |
Effectively increased the maturity of ERM; |
| • |
The formation of a new dedicated Risk Committee,
where previously ERM was dealt with by the Audit and
Risk Committee; |
| • |
The Risk Committee developed a new Risk Charter,
which monitors BCM, capital expenditure, IT
governance and fraud; |
| • |
An Asset and Liability Committee (ALCO) was formed
during the year due to manage, monitor and address
the Group’s financial risks. ALCO manages all financial
risk which includes interest rate risk, liquidity risk,
funding, foreign currency exposure risk, treasury credit
risk, credit ratings, and asset and liability management; |
| • |
An IT Governance Council was established to ensure
the effective and efficient use of IT in enabling Telkom
to achieve its goals, and maintain compliance with
King III Code. It includes a process to ensure effective
evaluation, selection, prioritisation, and funding of
competing IT investments for business benefits; and |
| • |
Feedback from the 2013 ERM survey, which aimed to
assess the effectiveness of Telkom’s ERM programme
revealed that 77.31% of respondents felt they were
increasingly realising the value that ERM adds to Telkom
as an organisation. This was based on a sample of
119 surveys of which 92 responded compared to only
54 respondents in 2012. |
Risk appetite and risk bearing capacity
Risk appetite is a measure of the amount of risk the Group is
willing to take in the pursuit of value. Risk bearing capacity
is the maximum amount of risk that Telkom can bear before
it is damaged beyond repair or will at least not be able to
continue the business in a similar fashion as before.
In order to integrate a risk dimension into a business, the
business needs to know how much risk it is willing to take
on and how it wants to balance risks and opportunities.
Defining risk appetite is thus an essential element of an
organisation’s ERM as it establishes a direct link between
its strategic and functional objectives.
A risk appetite framework is therefore a key business
performance tool and is central to strategic planning,
delegation of authorities and establishment of aligned
roles and responsibilities within the Group. Implementation
of processes within the Group requires substantial effort
and resources.
A risk appetite framework is used to evaluate and monitor
Telkom’s risk appetite. This involves:
| • |
Development of a risk appetite statement on an
annual basis; |
| • |
Determination of performance metrics and risk
tolerance limits based on the risk appetite statement; |
| • |
Embedding the risk appetite framework in risk based
decision-making to monitor performance of the Group
using the metrics and tolerance limits identified; |
| • |
Reporting of these results to the various governance
structures; and |
| • |
Revision of risk appetite statements if necessary. |
Commitments
One of the key objectives for the 2014 financial year is
to continue growing the effectiveness of ERM across the Group. While significant progress has been made over the
past 12 months, the focus areas for the year ahead include:
| • |
Continue to ensure NGNEC and Telkom Mobile result in
sustainable outcomes and opportunities; |
| • |
Ensure that convergence results in sustainable
outcomes and opportunities; |
| • |
Facilitate enhanced risk communication, awareness
and training; |
| • |
Implement risk appetite, RBC and risk tolerance levels
within the Group; and |
| • |
Reflect a more holistic risk profile in co-operation with
other risk disciplines. |
Governance structure
The implementation of an ERM structure that supports the achievement of the enterprise management objectives is essential.
The following diagram depicts the Group ERM structure:

The board of directors drives total enterprise risk
management through the approval of the ERM policy and
framework.
The Risk Committee convenes on a quarterly basis and
assists the Board in fulfilling its corporate governance
responsibilities by monitoring and reviewing the
identification and management of strategic and functional
risks associated with the Group’s business.
The Executive Committee convenes on a monthly basis
to discuss the strategic risks associated with the Group’s
business, monitors the effectiveness of the risk response
strategies implemented and considers the impact of the
risk profile on future strategic decisions.
The Telkom Executive Risk Management Council convenes on a quarterly basis to examine the risk profile
of the Group, monitors the implementation of actions and
KRIs and gives effect to the risk response strategies.
Enterprise risk management is driven from a centralised
group enterprise risk management division within
the Corporate Centre under the auspices of corporate
governance. The role of this division is to implement,
facilitate and monitor the ERM process, with management,
across all business units of the Group.
Management is the ultimate owner of the risk and
responsible for managing the risk exposure within the
defined risk appetite as approved by the board of directors.
In order to ensure effective reporting and management
of risks, risk has been incorporated into the operating
committees of the various business units. This provides
management of the respective businesses with the
responsibility and accountability to effectively manage
the risk within their domains. This requires a risk profile
submission from the relevant managing directors or chiefs
to the ERM division.
Monitoring and reporting
Monitoring of the ERM process and plan is an ongoing
initiative where the relevant committees convene on a
regular basis and interact with management as part of the
combined assurance process.
Furthermore, Telkom’s risk exposure is continually monitored
through the identification and analysis of appropriate
KRIs. KRIs act as early warning signals by highlighting any
changes to the Group’s risk profile. KRIs, controls and action
plans are fundamental components of a comprehensive
and sound risk management practice, which help reduce
losses and prevent risk exposure by proactively dealing with
a risk threat before an event actually occurs.
Reporting of risk information takes place on an ongoing
basis as depicted in the diagram below:

ETHICAL CONDUCT AND ANTI-CORRUPTION
Telkom recognises that organisations which conduct
business in an ethical manner, have a far greater potential
for continued success and a sustainable future, than those
that are not. We also recognise that ethical, non-corrupt
employees are vital to Telkom’s success.
The profound negative consequences of unethical conduct
and corrupt behaviour adversely affect companies in a
number of ways (financial losses, fines, penalties and
reputational damage), and it is therefore vital to proactively
manage ethical performance. As such, we are committed to
raising and maintaining our ethics levels across all aspects
of our business.
Progress towards achieving the required level of ethical
behaviour is attained through ongoing employee awareness
and education efforts, and a “zero tolerance” approach to
ethical misconduct. In order to prevent unethical conduct
and corrupt behaviour, and the associated negative
consequences, Telkom has put the following in place to
educate, create awareness, provide advice, and provide
opportunities in reporting unethical behaviour:
| • |
Fraud risk assessments are performed per service
organisation and cover all types of fraud risks and
violations of the business Code of Ethics. Line
management will assist with the implementation of
relevant controls to mitigate the risks; |
| • |
Business Code of Ethics and the supplementary
policies such as the Prevention of Fraud and Corruption
Policy, took place as part of the ethics programme.
Through this programme, a total of 5,230 employees
completed online training, and 467 employees received
training through the induction sessions. The continued
implementation of our programme of measures to raise
awareness, understanding and management of fraud
and corruption during the 2013 financial year should
have a positive impact in reducing the likelihood of this
risk; |
| • |
Extensive awareness and training sessions are run
throughout the year to communicate critical and
general areas of fraud concerns, the business Code of
Ethics, and the Telkom Crime Hotline. Furthermore, the
whistle-blowing policy has been reviewed and updated
to conform to relevant sections of the Companies Act
of 2008. Awareness of the whistle-blowing hotline has
been improved through a marketing campaign; and |
| • |
This is also supported through our independent whistle-blowing
hotline, for reporting of matters relating to
unethical behaviour, fraud and corruption. The hotline
received 1,865 calls during the reporting period,
compared to 2,232 calls in the previous period. Our
anti-corruption mailboxes received 988 messages in
the reporting period and 1,119 in the previous period.
The reasons for the decrease in incident reporting
will be investigated in 2014. |
Our Ethics Mailbox provides staff with advice on ethical
dilemmas. This mailbox received 90 matters in the 2013
year (only three of which are still to be finalised), compared
to 56 in the previous reporting period. The table below describes the types of matters that were
dealt with in 2013:
ETHICAL CONDUCT AND ANTI-CORRUPTION
| |
Type of ethics matters reported |
|
2013 |
|
2012 |
|
| |
Conflict of interest/Private work |
|
13 |
|
7 |
|
| |
Unfair treatment |
|
7 |
|
10 |
|
| |
Gifts |
|
9 |
|
5 |
|
| |
Share dealing |
|
7 |
|
3 |
|
| |
Unethical behaviour of management |
|
4 |
|
5 |
|
| |
Telkom Retirement Fund |
|
1 |
|
5 |
|
| |
Other, i.e. sponsorships, dress code |
|
36 |
|
21 |
|
| |
Ethics training |
|
8 |
|
0 |
|
| |
Compliance |
|
5 |
|
0 |
|
In line with the King III Report’s recommendations for the
management of ethics, Telkom conducted an Ethical Risk
Assessment during the reporting period. The assessment
looked at respondents’ perceptions of the following
key areas: Clarity; Positive role-modelling; Feasibility;
Supportability/Commitment; Transparency; Discussability;
Approachability; and Sanctionability/Enforcement.
The average score for Telkom, across all the dimensions
was 67%. This is an indication that there is room to
improve Telkom’s climate for ethical conduct. The
strongest dimensions were Clarity and Supportability/Commitment. This means that employees are familiar with
and understand Telkom’s standards of conduct and are
generally motivated to act in ethically responsible ways.
They receive information and guidance with regard to the
ethical expectations at Telkom. They also feel that Telkom’s
values reflect their own, and that they will find support for
ethical behaviour among their peers.
The weakest dimensions were Sanctionability/Enforcement
and Transparency. This indicates that employees are less
convinced that management is aware of what happens
in the organisation. They believe that the existing controls
may not be adequate for detecting violations, and that it
is possible to conceal misconduct within the organisation.
Staff are also not convinced that transgressions will
be consistently sanctioned, or that ethical behaviour
is recognised. Feasibility highlighted concerns around
unrealistic targets being set by senior executives which
compromise ethics. This pressure to achieve business
targets is an important motivator of unethical conduct
in a business environment. Approachability can also be
described as accountability, and refers to the degree to
which employees feel comfortable in reporting misconduct.
Employees felt most comfortable in reporting misconduct
to their direct line manager or the Telkom Crime hotline.
ETHICAL RISK ASSESSMENT
The eight ethical dimensions results
Telkom’s average scoring over the 8 key ethical dimensions is 67%. Below is a visual overview of the different dimensions and
the results for each.

Going forward
In order to address unethical and corrupt behaviour and
the associated negative consequences, Telkom Asset and
Revenue Protection Services (TARPS) and the Telkom Ethics
Office are currently implementing the following:
| • |
Further analysis to determine the reasons for the
decline in calls to the whistle-blowing hotline; |
| • |
Continue to conduct regular reviews of the business
Code of Ethics and supplementary ethics policies; |
| • |
Evaluate the reports received from the Telkom Crime
Hotline; |
| • |
Provide advice on matters referred to the ethics
mailbox; |
| • |
Promote whistle-blowing at Telkom and among
its stakeholders; |
| • |
Conduct investigations into suspected fraudulent and
irregular conduct; |
| • |
Ensure that collaborative efforts with stakeholders are
embarked upon to promote ethical conduct and good
corporate citizenship; and |
| • |
Ensure that internal and external ethics performance is
aligned around the same ethical standards. |
Business continuity management (BCM)
Business continuity is an integral part of good management
practice and corporate governance at Telkom. The
focus of BCM is to constitute, organise and improve the
management, performance and alignment of business
continuity and disaster recovery related activities, services,
functions, operations, systems, structures and networks
group-wide. BCM is an integrated management process
that identifies potential threats to the organisation and the
consequences to the business if they occur. BCM provides
a framework for building a resilient organisation capable
of responding effectively to protect the interest of its key
stakeholders, its reputation, and business activities which
create value.
|