| Chapter and principle |
Application |
Comments |
|
|
|
|
|
|
|
|
|
| Chapter 3 – Audit committee |
|
|
| The Board should ensure that the Company has an effective and independent audit committee. |
✓ |
Refer to the audit committee report on here. |
| The audit committee members should be suitably skilled and experienced independent non-executive directors. |
✓ |
Refer to CVs on here. |
| The audit committee should be chaired by an independent non-executive director. |
✓ |
|
| The audit committee should oversee integrated reporting. |
✓ |
|
| The audit committee should ensure that a combined assurance model is applied to provide a co-ordinated approach to all assurance activities. |
# |
Refer to note 5. |
| The audit committee should satisfy itself of the expertise, resources and experience of the Company’s finance function. |
✓ |
Refer to the audit committee report on here. |
| The audit committee should be responsible for overseeing of internal audit. |
✓ |
|
| The audit committee should be an integral component of the risk management process. |
✓ |
|
| The audit committee is responsible for recommending the appointment of the external auditor and overseeing the external audit process. |
✓ |
|
| The audit committee should report to the Board and shareholders on how it has discharged its duties. |
✓ |
|
| Chapter 4 – The governance of risk |
|
|
| The Board should be responsible for the governance of risk. |
✓ |
Refer to the risk management report here. |
| The Board should determine the levels of risk tolerance. |
✓ |
|
| The risk committee or audit committee should assist the Board in carrying out its risk responsibilities. |
✓ |
|
| The Board should delegate to management the responsibility to design, implement and monitor the risk management plan. |
✓ |
|
| The Board should ensure that risk assessments are performed on a continual basis. |
✓ |
|
| The Board should ensure that frameworks and methodologies are implemented to increase the probability of anticipating unpredictable risks. |
✓ |
|
| The Board should ensure that management considers and implements appropriate risk responses. |
✓ |
|
| The Board should ensure continual risk monitoring by management. |
✓ |
|
| The Board should receive assurance regarding the effectiveness of the risk management process. |
✓ |
|
| The Board should ensure that there are processes in place enabling complete, timely, relevant, accurate and accessible risk disclosure to stakeholders. |
✓ |
|
| Chapter 5 – The governance of information technology |
|
|
| The Board should be responsible for information technology (IT) governance. |
✓ |
Refer to note 6.
The Board, through its audit committee, risk management and executive reporting, takes responsibility for IT governance. The management of IT systems has been delegated to the Deputy CEO. |
| IT should be aligned with the performance and sustainability objectives of the Company. |
✓ |
IT systems at Pick n Pay are aligned with the strategy, objectives and reporting requirements of the Company. |
| The Board should delegate to management the responsibility for the implementation of an IT governance framework. |
✓ |
The management of IT governance has been delegated to the Deputy CEO who implements governance structures, systems and controls through the IT governance function. |
| The Board should monitor and evaluate significant IT investments and expenditure. |
✓ |
The Board annually considers and approves all IT investment and expenditure. |
| IT should form an integral part of the Company’s risk management. |
✓ |
Pick n Pay’s IT systems form part of the internal and annual external audit programme, which also considers risks to the Group. The IT systems governance function is developing a risk management framework to focus and manage IT-specific risks. |
| The Board should ensure that information assets are managed effectively. |
✓ |
Pick n Pay has policies and procedures to manage the storage, control, monitoring and confidentiality of all data. Policies and procedures are continually monitored and improved where necessary. |
| A risk committee and audit committee should assist the Board in carrying out its IT responsibilities. |
✓ |
IT audit items and risks are regularly reported to the Group audit committee, which reviews these risks according to the Group’s risk appetite. |