67
Our business
Operating context
Delivering on our strategy
Our governance structure
Administration
Shareholder relations
Vodacom proactively communicates its strategy and activities to
shareholders through a planned investor relations programme
which includes:
g
g
Formal presentations of annual and interim results;
g
g
Briefing meetings with major institutional shareholders after the
release of results; and
g
g
Hosting investor and analyst sessions.
Risk management
Management continuously develops and enhances its risk and
control procedures to improve risk identification, assessment and
monitoring. The Board considers business risks when setting
strategies, approving budgets and monitoring progress against
budgets.
A division reporting to the Chief Risk Officer assists in identifying,
assessing and recording the risks facing the Group and, where
appropriate, monitors mitigating actions.
vodacom
The key risks that are currently being managed by the
Group are detailed in the Risk management report.
www.vodacom.comInternal control
Management implements internal controls, which comprise
policies, procedures and processes, to provide reasonable
assurance on safeguarding assets, preventing and detecting
errors, the accuracy and completeness of accounting records,
and the reliability of financial statements. Internal audit provides
independent, objective assurance of the system of internal
controls within the Group.
Technology and information governance
In line with King IV, technology and information governance forms
part of our governance structures, policies and procedures. It
forms part of the Group’s strategic and business processes and is
managed by the Chief Technology Officer.
The Vodacom Technology Governance Framework and Charter,
which are mapped to the IT governance principles of King IV, have
continued to be reinforced in the organisation. Each framework
element is substantiated through demonstrable processes to align
technology strategy and business needs, deliver value and
manage performance, and to strengthen information security
management, information management, risk management,
business continuity management and compliance.
Our attention in the past year has focused on putting mechanisms
in place to ensure independent assurance of services provided by
outsourced providers, and moving towards compliance of the
Protection of Personal Information (PoPI) Act. King IV
acknowledges the rapid advances in technology and its potential
to result in significant disruption, opportunity and risks. King IV
recommends practices to assist the governing body with
technology and information governance. The Board will consider
the need to receive periodic independent assurance on the
effectiveness of the organisation’s technology and information
arrangements, including outsourced services.
The key areas of focus during the period included:
g
g
Independent assurance of outsourced services;
g
g
Protection of Personal Information Act; and
g
g
Technology security, more specifically cybersecurity.
The planned areas of future focus relating to information and
technology governance include:
g
g
Maturity journey to King IV alignment and application;
g
g
Continued focus on independent assurance of wider outsourced
services; and
g
g
Cybersecurity.




