Our approach to risk management
continued
Information and technology
governance
MTN acknowledges that information and
technology are integral strategic assets to
enable the delivery of ‘a bold new digital world’
to our customers. Our commitment to sound
governance is evident in our continuing
efforts to embed the King IV principles and
recommendations, with specific focus on
technology
governance
through
the
establishment of various responsibilities,
processes
and
supporting
governance
structures.
In 2017, we further strengthened our group
information security function, with enhanced
tools and more resources. We continued
to implement our new security plan, which aims
to use security as a business enabler, by creating
trust in the digital world and proactively
managing cyber and privacy risk.
Fraud risk management
Our approach to fraud risk management
continues to evolve to meet changes in
international fraud risk trends, and we are
placing more emphasis on proactive fraud
prevention. We work towards the effective
integration of fraud risk management within a
combined assurance environment, the rollout of
MTN’s ethics framework and greater
organisational fraud awareness.
We have dedicated forensic personnel in 13 MTN
opcos; the remaining opcos are supported
through the local internal audit and enterprise
risk management functions or the group fraud
risk management function.
Employees reportmost identified fraud incidents
via internal channels as they prefer to report
potential fraud incidents directly to the
investigation team. However, we continue to
provide employees and relevant stakeholders
with access to an anonymous reporting facility
managed by Deloitte. We investigate all
whistleblowing reports and provide feedback to
the group audit and risk committee structures
to ensure that we maintain independent
governance.
In 2017, MTN Group’s top fraud risks were:
•
•
Procure-to-pay associated fraud risks.
•
•
Products and services-related fraud risks
(including distribution channels).
•
•
Financial services-related fraud risks.
•
•
Cybercrime and confidential information
leakage.
Internal audit
The group’s internal audit provides independent,
objective non-assurance and consulting
activities designed to add value and improve the
operations of MTN. It helps the business
accomplish its objectives by bringing a
systematic, disciplined approach to evaluate
and improve the effectiveness of governance,
risk management and control processes.
Internal audit coverage is extended to all
operations and all high-risk processes in line
with the internal audit methodology. The MTN
Group and all its subsidiaries embrace the
principles of the King IV Report and recognise
the significant opportunities that present
themselves to companies that do so.
Internal audit continues to play the role of an
objective and independent value-adding
assurance provider. It takes into consideration
the risks that may hamper the achievement of
strategic objectives and risk profile of the
organisation to determine the effectiveness of
the internal control environment and risk
management.
In
2017,
internal
audit
implemented an internal quality assessment
programme across a number of opcos to ensure
its various internal audit teams comply with best
practice standards.
MTN’s internal audit has adopted a combined
assurance model as a co-ordinated approach
by three lines of defence and has dedicated
teams that perform internal audits across the
group.
In 2018 all internal audit and forensic teams will
report directly to the group audit committee,
which further enhances the independence
of the function. The function will report
administratively to the group CFO.
78
MTN Group Limited
Integrated Report 2017




