Our approach to risk management

Our risk management process

The efficient and effective management of risk is critical to the delivery of MTN's strategy and supports our investment case. The MTN board is accountable for all risks and delegates the responsibility for overseeing the effectiveness of risk management to the committees of the board.

Aligning risk management, compliance and corporate governance

MTN's risk management frameworks guide the operation of our business units, with whom primary responsibility for risk management resides. In 2017, we further enhanced key risk frameworks and methodologies to ensure consistent application across the organisation and conducted training and awareness programmes across regions and in key markets.

The business risk management (BRM) function continued on its three-year transformation journey (which commenced in 2016) to create a world-class function that caters to MTN current and future business needs in an effective and efficient manner. We continued to focus on the following three pillars to achieve the desired level of risk maturity:

Governance - We started separating the second and third lines of assurance in the company by splitting out internal audit and forensics and combining risk and compliance. We calculated risk-bearing capacity and applied this through the revised risk tolerance and appetite framework. We enhanced the risk-escalation process with stronger oversight from the group. We revised the terms of reference of internal governance structures to enhance the focus on risk management and related oversight activities.

People - We acquired additional specialist skills and increased the capacity of the assurance, risk management and compliance functions, boosting the capability of the group function significantly.

Methods and practices - We revised the tools, policies and frameworks to enhance the efficiency, effectiveness, co-ordination and reporting of assurance and risk management activities and placed greater emphasis on monitoring of top risks at the top governance structures.

 
  During 2018, the focus will be on:
 
  • Separating second and third lines of defence.
  • Strengthening the ‘centre of excellence’ for all assurance providers in line with revised structures and roles.
  • Implementing the risk and compliance transformation roadmap in the opcos.
  Successful implementation requires that we continue to have:
 
  • The right tone at the top, at the group and all opcos.
  • Clear measures of success together with regular and robust monitoring of performance.
  • Strong relationships at all levels of the business.

MTN operates in a complex, dynamic and fluid compliance environment. We made significant progress in 2017 to implement a multi-faceted approach to the management of compliance. Through our regional vice presidents and regional compliance officers, the group provides strong compliance oversight, while in-country compliance officers are responsible for ensuring that compliance matters are attended to timeously.

In 2017, the board approved a revised compliance target operating model and gave the go ahead for the recruitment in 2018 of additional compliance resources. This will ensure that the compliance function is further strengthened and enable it to deliver on its strategic focus areas.

Business continuity management and crisis risk management

Our group-wide BCM programme enables us to develop our capability to prevent, respond and recover from business interruptions. We have developed continuity plans for our key markets and continue to make progress in all our markets. However, we would like to increase our focus on the maturity of these processes in certain markets and have placed this as a priority for the group operating committee.

Our BCM approach leverages the ISO 22301 standards and the Business Continuity Institute Good Practice Guidelines and enables us to put in place adequate measures to protect our brand and reputation and comply with statutory, regulatory and contractual obligations.

Furthermore, we continue to strengthen our crisis management structures to effectively deal with incidents and crisis events across the MTN Group, and have an ongoing project to implement a crisis management tool to further strengthen our response capability.

Insurance and risk transfer

The MTN Group insurance programme is built around the close connection between risk management, risk retention and insurance using an annual assessment of risk exposures at each operating company. To achieve this, there is a strong commitment to the risk management assessment process, improving operational management's adoption of risk management best practice and to reduce risks across the entire insurance programme.

The programme covers physical/material damage to assets, business interruption, political violence, political risk, public liability, directors' and officers' liability, commercial crime, professional indemnity and cyber liability. The limits of indemnity for these covers have been structured to maintain an appropriate balance between external insurance and internal risk retention/self-insurance to manage the total cost of risk and demonstrate value for money.

To optimise risk retention, the insurance programme is supported by a cell captive, which continues to build its capacity and improve the cost effectiveness of the MTN Group insurance programme.

We have no political violence cover in place for Syria and Sudan and no political risk cover in place for Syria, Sudan or South Sudan. Other operations that are not covered under this placement are South Africa, Botswana, Cyprus and Swaziland, where we perceive risk as low. Afghanistan is covered under a Multilateral Investment Guarantee Agency placement and Iran is covered under an Export Credit Insurance Guarantee policy.

Information and technology governance

MTN acknowledges that information and technology are integral strategic assets to enable the delivery of 'a bold new digital world' to our customers. Our commitment to sound governance is evident in our continuing efforts to embed the King IV principles and recommendations, with specific focus on technology governance through the establishment of various responsibilities, processes and supporting governance structures.

In 2017, we further strengthened our group information security function, with enhanced tools and more resources. We continued to implement our new security plan, which aims to use security as a business enabler, by creating trust in the digital world and proactively managing cyber and privacy risk.

Fraud risk management

Our approach to fraud risk management continues to evolve to meet changes in international fraud risk trends, and we are placing more emphasis on proactive fraud prevention. We work towards the effective integration of fraud risk management within a combined assurance environment, the rollout of MTN's ethics framework and greater organisational fraud awareness.

We have dedicated forensic personnel in 13 MTN opcos; the remaining opcos are supported through the local internal audit and enterprise risk management functions or the group fraud risk management function.

Employees report most identified fraud incidents via internal channels as they prefer to report potential fraud incidents directly to the investigation team. However, we continue to provide employees and relevant stakeholders with access to an anonymous reporting facility managed by Deloitte. We investigate all whistleblowing reports and provide feedback to the group audit and risk committee structures to ensure that we maintain independent governance.

In 2017, MTN Group's top fraud risks were:

  • Procure-to-pay associated fraud risks.
  • Products and services-related fraud risks (including distribution channels).
  • Financial services-related fraud risks.
  • Cybercrime and confidential information leakage.

Internal audit

The group's internal audit provides independent, objective non-assurance and consulting activities designed to add value and improve the operations of MTN. It helps the business accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of governance, risk management and control processes. Internal audit coverage is extended to all operations and all high-risk processes in line with the internal audit methodology. The MTN Group and all its subsidiaries embrace the principles of the King IV Report and recognise the significant opportunities that present themselves to companies that do so.

Internal audit continues to play the role of an objective and independent value-adding assurance provider. It takes into consideration the risks that may hamper the achievement of strategic objectives and risk profile of the organisation to determine the effectiveness of the internal control environment and risk management. In 2017, internal audit implemented an internal quality assessment programme across a number of opcos to ensure its various internal audit teams comply with best practice standards.

MTN's internal audit has adopted a combined assurance model as a co-ordinated approach by three lines of defence and has dedicated teams that perform internal audits across the group.

In 2018 all internal audit and forensic teams will report directly to the group audit committee, which further enhances the independence of the function. The function will report administratively to the group CFO.