OUR BUSINESS

Risk and opportunity management

VALUE CREATION THROUGH ENTERPRISE-WIDE RISK MANAGEMENT
INTEGRATING ERM INTO BUSINESS ACTIVITIES AND ORGANISATIONAL CULTURE
RISK MATURITY
KEY FOCUS AREAS FOR 2024

RISK GOVERNANCE

Risk management and opportunity identification form part of every discussion throughout the business, spanning from one-on-one performance management / feedback sessions to divisional meetings, management and executive committee meetings, and Board sub-committee meetings.

Significant risks are reported on and considered at every Audit and Risk Committee meeting and reported at every Board meeting. Internal audit and other appointed assurance providers are contracted to provide independent assurance to assist management and the Board in ensuring that the control environment improves and objectives are achieved.

There is clear accountability and ownership of risk through SAICA’s governance structures depicted below:

Board of Directors

The SAICA Board sets the tone for risk management and assumes ultimate accountability, but delegates oversight of risk management to the Audit and Risk Committee and the day-to-day risk management activities to management. They ensure that assurance services and functions enable an effective control environment and support the integrity of information for internal decision-making and of the organisation’s external reports

Executive Management

Management is charged with the responsibility for taking appropriate risks within the risk appetite framework approved by the Board to create value. The Board receives quarterly reports on the status of existing as well as emerging risks and opportunities

Enterprise-wide Risk Management Function

Establishes the policies and procedures for managing risk, as well as promoting a culture of risk awareness and control The SAICA ERM policy and frameworks adopted by the Board govern ERM in the organisation and clearly define the roles and responsibilities of the Board, Board sub-committees, and various lines of assurance providers, promoting a sound risk culture. Risk is integrated with performance management and aligned to strategic objectives and performance goals

Risk Owners

Risk owners are the staff who are directly accountable for ensuring that risks are managed effectively by implementing actions required to treat the risks

Internal Audit

Internal audit and other appointed assurance providers are contracted to provide independent assurance to assist management and the Board in ensuring that the control environment improves and objectives are achieved

External Audit

External auditors provide an additional line of assurance. Their role is to provide reasonable independent assurance on the integrity of financial statements, as well as the effectiveness of internal controls in mitigating risks

OUR RISK APPETITE GUIDES OUR DECISION-MAKING

The Risk Appetite and Tolerance Framework provides guidance on developing and implementing risk appetite, risk tolerance levels and the risk-bearing capacity (which collectively form the risk thresholds of the SAICA Group), linked to and derived from the organisation’s strategic pillars and short-, medium- and long-term objectives. The realisation of SAICA’s strategy depends on the ability to take calculated risks in a manner that creates sustainable value for the SAICA Group. The framework provides guidelines for tracking and monitoring key risk indicators (KRIs) which provide an early warning signal of increasing risk exposures, enabling management to intervene in a timely manner through appropriate risk-mitigating responses.

Emerging risks

The main drivers escalating the risk environment include the following emerging risks and events:

Risk/Event Mitigating actions Related strategic risk/s

Artificial intelligence (AI) and its impact on the accountancy profession

An impact analysis on how AI technology and its generative capability are impacting the accountancy profession is currently being undertaken by the Standards division

  • Knowledge sharing and informal discussions
  • A formal task team / steering committee which includes divisional representation to assess the full impact of AI on the accountancy profession

AI IT security

Although the introduction of AI software, applications and robotics presents many opportunities, there is a probability that it will also introduce threats or intensify the impact of current threats such as hacking, which could lead to more cyberattacks/breaches. It is important to investigate the impact of AI on IT networks and organisations’ IT infrastructure and systems

  • IT Security Framework
  • ERM risk event escalation and reporting process
  • Ongoing training and awareness to improve staff maturity in relation to cyber threats

Power supply and maintenance

Continued power outages are causing a disruption in business operations

  • Continuous revision and implementation of SAICA’s business continuity practices
  • Exploration and consideration of alternative power solutions and connectivity

SAICA’s evolving role as a regulator

The proposed changes to the registered controlling body (RCB) criteria by SARS to monitor CPD compliance of tax practitioners will strain SAICA’s resources, as it could result in SAICA performing a dual role as member body and regulator

  • Continuous engagement with regulators to clarify SAICA’s role and align expectations with regulators

Disciplinary processes of tax practitioners

From a compliance and potentially discipline perspective, the management and monitoring of tax practitioners by SAICA may become unduly burdensome

  • Update the by-laws and disciplinary processes to build efficiencies into the disciplinary processes
  • Identify non-compliance and enforce policies and procedures
  • A member compliance and disciplinary process audit is in progress

A decline in the number of transformation student passes at third-year and CTA levels

  • Detailed research into the causes is in progress to identify an appropriate response strategy

The current 14 strategic risks are illustrated in the heatmap below.

Low
Moderate
High
Extreme
Risk is increasing
Risk is reducing
Risk is stable
New Risk
Low
Moderate
High
Extreme
Risk is increasing
Risk is reducing
Risk is stable
New Risk

Drop us a Message