1 2 3

Pick n Pay Stores Limited
Corporate governance report continued

  Chapter and principle    Application    Comments 
  Chapter 3 – Audit committees        
  The Board should ensure that the Company has an effective and independent audit committee.   ✓     Refer to the audit and risk committee report.
  The audit committee members should be suitably skilled and experienced independent non-executive directors.   ✓  
  The audit committee should be chaired by an independent non-executive director.   ✓  
  The audit committee should oversee integrated reporting.   ✓  
  The audit committee should ensure that a combined assurance model is applied to provide a co-ordinated approach to all assurance activities.   #     The Board and audit and risk committee worked with a qualified, independent third party to develop a comprehensive combined assurance approach, to ensure the integrity of financial and non-financial data contained within the report. This approach is being implemented by management.  
  The audit committee should satisfy itself of the expertise, resources and experience of the Company’s finance function.   ✓     Refer to the audit and risk committee report.
  The audit committee should be responsible for overseeing of internal audit.   ✓  
  The audit committee should be an integral component of the risk management process.   ✓  
  The audit committee is responsible for recommending the appointment of the external auditor and overseeing the external audit process.   ✓  
  The audit committee should report to the Board and shareholders on how it has discharged its duties.   ✓  
  Chapter 4 – The governance of risk        
  The Board should be responsible for the governance of risk.   ✓     Refer to the risk management report.
  The Board should determine the levels of risk tolerance.   ✓  
  The risk committee or audit committee should assist the Board in carrying out its risk responsibilities.   ✓  
  The Board should delegate to management the responsibility to design, implement and monitor the risk management plan.   ✓  
  The Board should ensure that risk assessments are performed on a continual basis.   ✓  
  The Board should ensure that frameworks and methodologies are implemented to increase the probability of anticipating unpredictable risks.   ✓  
  The Board should ensure that management considers and implements appropriate risk responses.   ✓  
  The Board should ensure continual risk monitoring by management.   ✓  
  The Board should receive assurance regarding the effectiveness of the risk management process.   ✓  
  The Board should ensure that there are processes in place enabling complete, timely, relevant, accurate and accessible risk disclosure to stakeholders.   ✓  
  Chapter 5 – The Governance of information technology        
  The Board should be responsible for information technology (IT) governance.   ✓     The Board, through its audit and risk committee, risk management and executive reporting, takes responsibility for IT governance. The management of information technology systems has been delegated to the Deputy CEO.

An information technology services (IT) governance function has been established within the IT division. The IT governance function is implementing various initiatives in order to achieve compliance with King III where feasible.

The Group aligns its practices and processes to COBIT 5, which is the latest edition of ISACA’s globally accepted framework, providing an end-to-end business view of the governance of enterprise IT.  
  IT should be aligned with the performance and sustainability objectives of the Company.   ✓     Information technology systems are aligned with the strategy, objectives and reporting requirements of the Group.  
  The Board should delegate to management the responsibility for the implementation of an IT governance framework.   ✓     The management of IT governance has been delegated to the Deputy CEO who implements governance structures, systems and controls through the IT governance function.  
  The Board should monitor and evaluate significant IT investments and expenditure.   ✓     The Board annually considers and approves all IT investment and expenditure.  
  IT should form an integral part of the Company’s risk management.   ✓     The information technology systems form part of the internal and annual external audit programme, which also considers risks to the Group. The information technology systems governance function is developing a risk management framework to focus and manage IT-specific risks. Refer to the risk management report.
  The Board should ensure that information assets are managed effectively.   ✓     Pick n Pay has policies and procedures to manage the storage, control, monitoring and confidentiality of all data. Policies and procedures are continually monitored and improved where necessary.  
  A risk committee and audit committee should assist the Board in carrying out its IT responsibilities.   ✓     IT audit items and risks are regularly reported to the Group audit and risk committee.  
  Chapter 6 – Compliance with laws, rules, codes and standards        
  The Board should ensure that the Company complies with applicable laws and considers adherence to non-binding rules, codes and standards.   ✓     Refer to the legal report and to the risk management report.
  The Board and each individual director should have a working understanding of the effect of the applicable laws, rules, codes and standards on the Company and its business.   ✓  
  Compliance risk should form an integral part of the Company’s risk management process.   ✓  
  The Board should delegate to management the implementation of an effective compliance framework and processes.   ✓  
  Chapter 7 – Internal audit        
  The Board should ensure that there is an effective risk-based internal audit.   ✓     Refer to the audit and risk committee report and to the risk management report.
  Internal audit should follow a risk-based approach to its plan.   ✓  
  Internal audit should provide a written assessment of the effectiveness of the Company’s system of internal controls and risk management.   ✓  
  The audit committee should be responsible for overseeing internal audit.   ✓  
  Internal audit should be strategically positioned to achieve its objectives.   ✓  
  Chapter 8 – Governing stakeholder relationships        
  The Board should appreciate that stakeholders’ perceptions affect a Company’s reputation.   ✓     Refer to the engagement with stakeholders.
  The Board should delegate to management to proactively deal with stakeholder relationships.   ✓  
  The Board should strive to achieve the appropriate balance between its various stakeholder groupings, in the best interests of the Company.   ✓  
  Companies should ensure the equitable treatment of shareholders.   ✓  
  Transparent and effective communication with stakeholders is essential for building and maintaining their trust and confidence.   ✓  
  The Board should ensure that disputes are resolved as effectively, efficiently and expeditiously as possible.   ✓  
  Chapter 9 – Integrated reporting and disclosure        
  The Board should ensure the integrity of the Company’s integrated report.   ✓     The audit and risk committee reviews the financial statements and the integrated annual report and makes a recommendation to the Board for approval.  
  Sustainability reporting and disclosure should be integrated with the Company’s financial reporting.   ✓  
  Sustainability reporting and disclosures should be independently assured.   ✗     The Board and audit and risk committee worked with a qualified, independent third party to develop a comprehensive combined assurance approach, to ensure the integrity of financial and non-financial data contained within the report.  

Notes to King III principles
Note 1
Chairman

King III acknowledges that there may be sound reasons for a company to appoint a Chairman who does not meet all the criteria for independence, but requires such a company to justify this decision and to put further checks in place to ensure no real or perceived conflicts of interest arise.

The Ackerman family owns approximately 51% of the shares in the holding company, Pick n Pay Holdings Limited RF, giving them a holding of 27.3% in the Group. Chairman Gareth Ackerman is not independent by virtue of his indirect shareholding. Perceptions of conflicts of interest may arise regarding his decisions relating to the Group and its shareholders.

Hugh Herman has been appointed as Lead Independent Director (LID). The main function of an LID is to provide leadership and advice to the Board when the Chairman has a conflict of interest, without detracting from the authority of the Chairman. The LID provides an important point of contact for the broader investment and stakeholder community should they have concerns with the running of Stores or potential conflicts of interest. All members of the Board have unfettered access to the LID when required.

In addition to the role of the LID, and to ensure good governance, the chairmanship of four of the six Board committees is held by other independent directors.

Consistent with the King III guidelines, Gareth Ackerman:
  • is not a member of the audit and risk committee;
  • does not chair the remuneration committee, but is a member; and
  • is not a member of the social and ethics committee.

1 2 3