BARRAMUNDI L IMITED RISK MANAGEMENT POLICY



Similar documents
GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS

Operational Risk Publication Date: May Operational Risk... 3

Audit, Risk and Compliance Committee Charter

ISO27001 Controls and Objectives

PART I - PRELIMINARY...1 Objective...1 Applicability...2 Legal and Regulatory Provision...2

RISK MANAGEMENT MATRIX FOR ACADEMIES. Contents. Introduction. Mission/objectives. Law and regulation. Governance and management.

GUIDELINES ON COMPLIANCE FUNCTION FOR FUND MANAGEMENT COMPANIES

Internal Control Systems and Maintenance of Accounting and Other Records for Interactive Gaming & Interactive Wagering Corporations (IGIWC)

INFORMATION TECHNOLOGY SECURITY STANDARDS

Isle of Man Financial Supervision Commission. Business Plan Guidance for Licence Applicants

Financial Services Guidance Note Outsourcing

Statement of Guidance

HIGHFIELD RESOURCES LIMITED AUDIT, BUSINESS RISK & COMPLIANCE COMMITTEE CHARTER

AMP Capital Investors Limited ABN AFSL AMP Capital Derivatives Risk Statement

ISO Controls and Objectives

Care Providers Protecting your organisation, supporting its success. Risk Management Insurance Employee Benefits Investment Management

Advisory Guidelines of the Financial Supervisory Authority. Requirements regarding the arrangement of operational risk management

Guidance Note on Credit and Credit Control for Credit Unions. October Office of the Registrar of Credit Unions

APPLICATION OF KING III CORPORATE GOVERNANCE PRINCIPLES 2014

APPLICATION OF THE KING III REPORT ON CORPORATE GOVERNANCE PRINCIPLES

i-control Holdings Limited 超 智 能 控 股 有 限 公 司 (incorporated in the Cayman Islands with limited liability) (the Company )

GUIDANCE FOR MANAGING THIRD-PARTY RISK

WEST LOTHIAN COUNCIL INFORMATION SECURITY POLICY

Audit and Risk Committee Charter. Knosys Limited ACN (Company)

Head of Information & Communications Technology Responsible work team: ICT Security. Key point summary... 2

on Asset Management Management

A Guide to Corporate Governance for QFC Authorised Firms

NOTICE 158 OF 2014 FINANCIAL SERVICES BOARD REGISTRAR OF LONG-TERM INSURANCE AND SHORT-TERM INSURANCE

Audit, Business Risk and Compliance Committee Charter

INVESTMENT POLICY April 2013

RISK MANAGEMENT AND COMPLIANCE

Finansinspektionen s Regulatory Code

Interim Audit Report. Borough of Broxbourne Audit 2010/11

IS INFORMATION SECURITY POLICY

Risk Management Programme Guidelines

POLICY STATEMENT AND GUIDANCE NOTES ON: (1) OUTSOURCING; AND

Practice Note. 23Revised. October 2009 AUDITING COMPLEX FINANCIAL INSTRUMENTS INTERIM GUIDANCE

Audit, Business Risk and Compliance Committee Charter Pact Group Holdings Ltd (Company)

APB ETHICAL STANDARD 5 (REVISED) NON-AUDIT SERVICES PROVIDED TO AUDITED ENTITIES

Mapping of outsourcing requirements

Managing Outsourcing Arrangements

RISK MANAGEMENt AND INtERNAL CONtROL

Advisory Guidelines of the Financial Supervision Authority. Requirements for Organising the Business Continuity Process of Supervised Entities

Risk Management guide

Information Security Policies. Version 6.1

How To Protect Decd Information From Harm

Statement of Principles

Audit, Risk Management and Compliance Committee Charter

GUIDELINE ON THE APPLICATION OF THE OUTSOURCING REQUIREMENTS UNDER THE FSA RULES IMPLEMENTING MIFID AND THE CRD IN THE UK

Service Children s Education

Guidelines for Financial Institutions Outsourcing of Business Activities, Functions, and Processes Date: July 2004

FUND MANAGER CODE OF CONDUCT

Audit, Business Risk and Compliance Committee Charter. Spotless Group Holdings Limited ACN

FMCF certification checklist (incorporating the detailed procedures) certification period. Updated May 2015

Regulation for Establishing the Internal Control System of an Investment Management Company

ULH-IM&T-ISP06. Information Governance Board

Guidance notes: Financial Planning & Managing Risk

Newcastle University Information Security Procedures Version 3

FINAL May Guideline on Security Systems for Safeguarding Customer Information

Good Practice Checklist

Part A OVERVIEW Introduction Applicability Legal Provision...2. Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...

University of Sunderland Business Assurance Information Security Policy

GUIDANCE NOTE ON OUTSOURCING

Guidance note on Outsourcing/Delegation of Functions and inward outsourcing

Outsourcing Risk Guidance Note for Banks

Audit, Business Risk and Compliance Committee charter

SIPP operator guidance

Tabcorp Holdings Limited

Application for a Banking Authority Foreign Bank Branches Prudential Statement J2

SPG 223 Fraud Risk Management. June 2015

Guidelines. ADI Authorisation Guidelines. Australian Prudential Regulation Authority. April 2008

SESSION 3 AUDIT PLANNING

TIANGONG INTERNATIONAL COMPANY LIMITED (the Company ) TERMS OF REFERENCE OF AUDIT COMMITTEE

Authorisation Requirements and Standards for Debt Management Firms

Best practice guidelines for depositary banks in relation to the safekeeping of assets from UCITS funds held through the traditional custody network

INTERNAL AUDIT FRAMEWORK

ICT NETWORK AND INFRASTRUCTURE FILE SERVER POLICY

Coventry Resources Inc. Corporate Governance Statement (current as at 30 June 2015)

SUPERVISORY AND REGULATORY GUIDELINES: PU GUIDELINES ON MINIMUM STANDARDS FOR THE OUTSOURCING OF MATERIAL FUNCTIONS

Clearing and Settlement Procedures. New Zealand Clearing Limited. Clearing and Settlement Procedures

Prudential Practice Guide

SMARTONE TELECOMMUNICATIONS HOLDINGS LIMITED

Regulations on Information Systems Security. I. General Provisions

Client Asset Requirements. Under S.I No.60 of 2007 European Communities (Markets in Financial Instruments) Regulations 2007

3.6 - REPORT BY THE CHAIRMAN OF THE BOARD OF DIRECTORS ON CORPORATE GOVERNANCE, RISK MANAGEMENT AND INTERNAL CONTROLS

Capital Requirements Directive Pillar 3 Disclosure. December 2015

MLC Derivatives Policy

F I N A N C I A L R E G U L A T I O N S

Disposal Schedule for Functional records of Retirement Benefits Fund. Disposal Authorisation No. 2416

University of Liverpool

BERMUDA MONETARY AUTHORITY

Version 1.0. Ratified By

How To Set Up A Committee To Check On Cit

Information Governance Strategy & Policy

Internal controls Guidance for trustees

E Lighting Group Holdings Limited 壹 照 明 集 團 控 股 有 限 公 司 (incorporated in the Cayman Islands with limited liability) Stock Code : 8222

Charities & Not for Profit Protecting your organisation, supporting its success. Risk Management Insurance Employee Benefits Investment Management

Audit, Business Risk and Compliance Committee Charter

RIT Capital Partners plc Shareholder Disclosure Document January 2015

Solvency Assessment and Management: Pillar II Sub Committee Governance Task Group Discussion Document 81 (v 3)

Transcription:

BARRAMUNDI L IMITED RISK MANAGEMENT POLICY Last updated: 25 August 2014

THE OBJECTIVES OF RISK MANAGEMENT Risk management is the systematic process of managing an organisation's risk exposures to achieve its objectives in a manner consistent with public interest, human safety, environmental factors, and the law. It consists of the planning, organising, leading, coordinating, and controlling activities undertaken with the intent of providing an efficient pre-loss plan that minimises the adverse impact of risk on the organisation's resources, earnings, and cash flows. The Barramundi Risk Management Policy will be incorporated within the normal management and governance processes and will focus on the following: Effective and efficient continuity of operations; Safeguarding of shareholders investments and the company s assets; Maintenance of a positive reputation; Reliability of internal and external reporting; Compliance with applicable laws and regulations. WHOSE RESPONSIBILITY IS RI SK MANAGEMENT? The ultimate responsibility for risk management rests with the Board. The Board in conjunction with the Corporate Manager implements and operates risk identification measures, risk mitigation plans and key controls. In fulfilling its responsibilities, management should identify and evaluate the risks faced by the Company for consideration by the Board and design, operate and monitor a suitable system of risk management. These responsibilities lie with the Managing Director Fisher Funds and the Corporate Manager Barramundi. Everyone involved with the business must take personal responsibility for managing risk to the business in their area of influence and take positive action when risk is identified. RISK MANAGEMENT TOOLS The risk management tools used by Barramundi include: 1. Strong corporate governance; 2. Audit and Risk Committee; 3. Outsourcing of certain functions to experts; 4. Internal controls, procedures and processes; 5. Reporting systems to monitor risk; 6. Business continuity planning; 7. Insurance; and 8. Acceptance of the risk. 2

Some risks will be identified, assessed and accepted as risks without any active mitigation of the risk. This is the most appropriate strategy where the net cost of mitigating the risk is greater than the risk of loss. Acceptance of any risk must be a conscious, active decision rather than a passive acceptance of the risk. 1. CORPORATE GOVERN ANCE The company retains a Board of Directors to ensure best practice corporate governance and to ensure that shareholder interests are held paramount. The majority of the Board will be independent. The minimum number of directors is three and the maximum number is seven. The Board must be kept informed of key risks to the business on a continuing basis (see Reporting Systems to Monitor Risk below). The Board meets a minimum of six times a year and is provided with accurate timely information on all aspects of the company s operations. 2. AUDIT AND RISK COMMITTEE An Audit and Risk Committee has been established to focus on discharging its responsibilities relative to financial reporting and regulatory conformance. The committee may have in attendance such members of management including the Barramundi Corporate Manager, a representative from the Manager and such other persons including the external auditors, as it considers necessary to provide appropriate information and explanations. Meetings shall be held not less than twice a year having regard to the company s reporting and audit cycle. Any member of the committee, the Managing Director Fisher Funds, the Barramundi Corporate Manager or the external auditors may request a meeting at any time if they consider it necessary. The responsibilities of the committee are as follows: liaison with external auditors; review of the annual audit plan with the external auditors; review of audit findings, the annual financial statements and the annual report; review of interim financial information including any findings from interim review performed by the external auditor; prior clearance of public releases of financial information to the media; review of accounting policies; oversight of compliance with statutory responsibilities relating to financial and tax legislation requirements; review of the frequency and significance of all transactions between the company and related parties and assessment of their propriety; 3

review of the appointment of the external auditors and their fees; review of the independence of the external auditors and the appropriateness of any non-audit services they undertake for the company; review of the adequacy and effectiveness of the company s risk management including an annual review of the Risk Management Policy; undertaking a regular assessment of the internal controls operating within the company; review of assessment of the custodians (Trustees Executors) internal control processes (known as negative assurance work) at each half year (additional to the annual external audit process) including a review of the custodian s auditors negative assurance letters which should come direct to Barramundi Limited, which describe any weaknesses in internal controls and systems that may have come to the attention of the auditor; and supervision of special investigations when requested by the Board. In addition, the committee shall examine any other matters referred to it by the Board. The committee shall maintain direct lines of communication with the external auditors and with management generally including those responsible for non-financial risk management. The Corporate Manager shall be responsible for drawing to the committee s immediate attention any material matter that relates to the financial condition of the company, any material breakdown in internal controls, and any material event of fraud or malpractice. 3. OUTSOURCING Barramundi s policy is to minimise risk and to ensure independence and separation from the Manager by seeking specialist help from experts whenever best practice skills are not retained within the business: Key areas where Barramundi engages specialist help include: Investment Management Legal advice Tax planning and review of tax calculations Custody Services and Investment Accounting services Registry Services (Computershare) Outsourcing offers protection to reduce the risk of either not identifying a major risk, making a significant error in key processes, not being able to provide adequate segregation of duties or making uninformed decisions where we do not retain specialist expertise in-house. Additional protection is provided through the ability to take legal action against any suppliers who provide services or advice that is inadequate. Suppliers will be selected on the basis that they use best practice, are experienced, skilled and have substance behind them to support any claim Barramundi may make. 4

A Service Level Agreement between Barramundi and its custody services provider has been established and agreed covering the detailed level of service and internal controls that exist in relation to custody services and investment accounting. Barramundi requires its custodian to conduct an annual assessment of their internal control processes (known as negative assurance work) at each half year in addition to the annual, year end external audit process. The custodian s auditor provides negative assurance letters direct to Barramundi Limited, which describe any weaknesses in internal controls and systems that may have come to the attention of the auditor in the conduct of their review of accounting records and systems of internal control. The Corporate Manager is responsible for monitoring supplier relationships and updating the Board on any issues. 4. KEY INTERNAL CONTROLS Key controls are: The definition of responsibilities and delegated authorities. These are contained in the Corporate Manager s position description, The Management Agreement with Fisher Funds Management Limited and the Services Agreement and Service Level Agreement with the Custodian. The Board ensures that the management team is properly qualified and experienced to enable them to effectively discharge their duties. An internal controls document exists and is reviewed, developed and updated at least annually and when changes to process and procedures occur. In relation to the custodial and investment accounting function outsourced, Barramundi receives a bi-annual report from the Custodian s auditors highlighting the following key areas: Control policies and procedures (including segregation of duties) Accuracy and completeness of records Physical security of assets Standards for Independence Registration and segregation of clients investments Valuation and accounting of assets Accuracy of tax information Security and Integrity of computer information systems. Review and approval by the Board of all significant business issues including authorisation by at least one board member of all expenses. The Corporate Manager is responsible for monitoring and developing adequate control systems. 5

5. RISK REPORTING S YSTEMS Reporting systems will remain in place at all times to: Encourage focus on the identification of risks; Ensure a programme for managing compliance obligations is in place and monitored; Highlight mitigation plans required to manage risk on a regular basis; Ensure the Board is kept informed of business, operational and compliance risks. The following reports shall be provided to the Board to meet these objectives: Compliance Plan; a list of all legal and regulatory compliance requirements for Barramundi Limited (quarterly); Monthly Board Papers incorporating: Corporate Manager s Report, which includes a section on current business risks, mitigation plans and likely impact on the business. Financial Statements, budgets/forecasts and Performance Fee calculation. Monthly Manager s Report including Investment Mandate compliance and Directors Certificate in accordance with the Management Agreement. A review of internal controls and their effectiveness (bi-annually); Audit and Risk Committee report and Auditor s/accountants report from the external auditor bi-annually. 6. BUSINESS CONTINU ITY PLANNING The Manager - Fisher Funds will maintain adequate disaster recovery and continuity processes to ensure that their business is not severely adversely impacted by loss of computer systems or other technology. Significant events that could cause such a loss have been categorised into four areas: 1. Man-made threats; 2. Loss of applications or technology; 3. Short-term loss of access to the premises (up to 3 days); 4. Long-term loss of access to the premises (more than 3 days). Fisher Funds would remain operational and not under serious threat if the technology was unavailable for a number of hours, or even days. Barramundi has relatively low technology and premises needs, so could continue to operate for days if unavailable. Custody and investment accounting is outsourced to our Custodian, based in Wellington. As a result, loss of Barramundi s technology would not create settlement default risk or operational risk. The manager would still be able to effect transactions provided access to a phone was possible, settlements could occur and processing of registry transactions could be delayed (for up to seven days) if systems were unavailable. 6

Barramundi has reviewed the custodian s disaster recovery and business continuity plans and is comfortable that they provide adequate protection for their own recovery from a disaster. This has been confirmed by their external auditors, Deloitte, as part of their audit of Systems of Internal Control. The primary applications and technology that Barramundi requires are: 1. Telephones and faxes 2. Access to the NZX MAP System 3. Access to portfolio spreadsheets and Barramundi work papers 4. Access to Companies Office website (to update records on-line). Protections against man-made threats (such as sabotage and cyber-terrorism) include: All computers are password protected, with authentication controlled by the file server. Nightly data backups are rotated off-site, so if equipment is stolen or vandalised we are able to re-establish the business with minimal loss of information. Physical security is in place to limit unauthorised access to the office. Anti-virus software is installed and regularly updated on all computers. Remote LAN access is password protected and restricted to senior personnel. If our website was compromised and/or altered, we could simply turn it off with no impact to the business. Certain key documents are also located with advisers off-site, including: Legal records (Solicitor, Auckland) Current portfolio data and all historic accounting records (Custodian, Wellington) Audited annual accounts (Auditor, Auckland) Audited annual accounts (Companies Office, Auckland) Barramundi would rely on Fisher Funds to ensure alternative premises and technology was available in the event of extended business interruption. Fisher Funds has its own business continuity plan. 7. INSURANCE Where a significant risk has been identified and other risk management tools prove to be too expensive or not as effective, we shall seek to mitigate that risk through insurance. Insurance is not our key risk protection mechanism as we will firstly seek to avoid adverse events occurring, but it does play a part in our overall risk management strategy. It is our policy to take advice from professional insurance brokers as to the type and level of cover that is considered best practice for organisations of our size and nature. Insurances held include: Directors and officers; and Statutory Liability It is policy to review Barramundi insurance requirements at least every 18 months. 7

Key Risk Area 1. Financial/Operational Risk How can it Occur? Lack of Internal Control/ Corporate Governance 2. Tax Risk Variations in taxation law 3. Liquidity Risk Lack of internal control 4. Borrowing / Interest Rate Risk Increased Interest rates 5. Human Resources Risk Loss of Key personnel 6. Market/Investment Risk Market conditions, regulatory restrictions 7. Legal / Compliance Risk Lack of Internal controls/policies and procedures. Claims by employees, shareholders and others 8. Business continuity Risk (includes IT Risk) Failure of key utilities, natural disaster, fire, flood etc Consequence Exposure to avoidable financial risk Impact on Shareholder returns Inaccurate, unreliable Information for decision making Non compliance with appropriate accounting principles Exposure to loss, fraud and litigation Material effect on operation results and impact on shareholder returns Insolvency/Going concern issues Increased borrowing costs Impact on Barramundi value and value of companies that Barramundi invests in Loss of specialised knowledge base Impact on Shareholder returns Legal Costs Reputation issues Breach/fines from regulatory authorities Inability to continue basic business operations Risk Management Strategy Assessme nt* Low Strong Corp Governance Outsourcing of key functions to experts Internal controls and reporting systems in place Key agreements with Manager and Custodian Insurance to mitigate loss Low Audit and Risk Committee Engaging Tax expertise Low Daily cash monitoring, weekly, monthly review to ensure that operating within prescribed guidelines Low Borrowing constraints up to a maximum value of 20% of the GAV Manager s Investment Strategy Low Manager s ownership structure Good working environment Med Management Agreement Manager s Investment strategy and parameters Low Strong Corp Governance, Outsourcing of key functions to experts Internal controls and reporting systems in place Insurance coverage to mitigate financial impact Low Refer detailed Plan in Risk Assessment Document Policy covered under Manager s Risk Management Policy 9. Health and Safety Risk Unsafe work environment Legal Claims Low To be incorporated into Manager s Health and Safety policy 10. Physical Security Unsafe work environment Loss & damage to property Non compliance with legislation Low Covered under Manager s Physical security policy *net of mitigation 8