IT Governance Charter



Similar documents
SABPP IT GOVERNANCE COMMITTEE TERMS OF REFERENCE

IT Charter and IT Governance Framework

Board means the Board of Directors of each of Scentre Group Limited, Scentre Management Limited, RE1 Limited and RE2 Limited.

Hunter Hall International Limited

APPLICATION OF THE KING III REPORT ON CORPORATE GOVERNANCE PRINCIPLES

APPLICATION OF KING III CORPORATE GOVERNANCE PRINCIPLES 2014

EXECUTIVE COMMITTEE TERMS OF REFERENCE

How To Manage A Board In The Kandijan Germany

Application of King III Corporate Governance Principles

Risk Management Committee Charter

REMUNERATION COMMITTEE

Westfield Corporation Human Resources Committee Charter. Westfield Corporation Limited (ABN ) (ABN )

JOE MOROLONG LOCAL MUNICIPALITY IT GOVERNANCE FRAMEWORK


BOARD OF DIRECTORS MANDATE

Corporate Governance Code for Captive Insurance and Captive Reinsurance Undertakings

BOARD CHARTER Link Administration Holdings Limited ("Company") ABN

WEST COAST DISTRICT MUNICIPALITY IT GOVERNANCE FRAMEWORK IT CHARTER

BOARD CHARTER. Its objectives are to: provide strategic guidance for the Company and effective oversight of management;

Issue 1.0. UoG/ILS/IS 001. Information Security and Assurance Policy. Information Security and Compliance Manager

Rolls Royce s Corporate Governance ADOPTED BY RESOLUTION OF THE BOARD OF ROLLS ROYCE HOLDINGS PLC ON 16 JANUARY 2015

Ramsay Health Care Limited ACN Board Charter. Charter

Application of King III Corporate Governance Principles

LEEDS BECKETT UNIVERSITY. Information Security Policy. 1.0 Introduction

A Guide to Corporate Governance for QFC Authorised Firms

1. Purpose. 2. Membership and Organization. 3. Meetings. Canadian Imperial Bank of Commerce Risk Management Committee Mandate

Authorisation Requirements and Standards for Debt Management Firms

Information governance strategy

Business Continuity & Crisis Management

Corporate governance statement

Internal Audit Terms of Reference

Operations. Group Standard. Business Operations process forms the core of all our business activities

U.S. Department of Education. Office of the Chief Information Officer

IT Governance Regulatory. P.K.Patel AGM, MoF

Infratil Limited - Board Charter. 1. Interpretation. 1.1 In this Charter:

IT Governance. What is it and how to audit it. 21 April 2009

CONFIGURATION COMMITTEE. Terms of Reference

CONSULTATION PAPER CP 41 CORPORATE GOVERNANCE REQUIREMENTS FOR CREDIT INSTITUTIONS AND INSURANCE UNDERTAKINGS

Macquarie Group Limited Board Charter

Consequence Management

Corporate Governance Statement

CODE GOVERNANCE COMMITTEE CHARTER. 1 Functions and responsibilities of the Code Governance Committee

Chayuth Singtongthumrongkul

Risk Committee Charter

KUMBA IRON ORE LIMITED (Registration number 2005/015852/06) ( Kumba or the Company )

Financial Services Guidance Note Outsourcing

EQT HOLDINGS LIMITED BOARD CHARTER (ACN )

Board Charter. HCF Life Insurance Company Pty Ltd (ACN ) (the Company )

Business Continuity Management Policy

USAID Management Operations Council Charter

The City of Nottingham and Nottinghamshire Economic Prosperity Committee. Constitution (terms of reference, membership and procedure rules)

AUDIT COMMITTEE TERMS OF REFERENCE

Information Governance Management Framework

Direct Line Insurance Group plc (the Company ) Board Risk Committee (the Committee ) Terms of Reference

ANGLOGOLD ASHANTI LIMITED

Internal Audit Quality Assessment Framework

House of Commons Corporate Governance Framework

REGULATORY AND COMPLIANCE (GAMING COMPLIANCE) COMMITTEE CHARTER

Colorado Integrated Criminal Justice Information System (CICJIS) Program CHARTER and BYLAWS

CORPORATE GOVERNANCE - BOARD CHARTER PART A DEFINING GOVERNANCE ROLES

University of Sunderland Business Assurance Information Security Policy

Audit, Risk Management and Compliance Committee Charter

ANGLOGOLD ASHANTI LIMITED Reg No:1944/017354/06. Board Charter

How To Ensure Health Information Is Protected

Information Integrity & Data Management

INFORMATION TECHNOLOGY SECURITY STANDARDS

Principles for the audit committee s role in performance management

Corporate Governance Charter

Information Governance Strategy and Policy. OFFICIAL Ownership: Information Governance Group Date Issued: 15/01/2015 Version: 2.

MINNESOTA MUTUAL COMPANIES, INC. Guidelines of the Audit Committee of the Board of Directors

GOVERNANCE AND ACCOUNTILIBILITY FRAMEWORK

Risk Management. Group Standard

The CIPM certification is comprised of two domains: Privacy Program Governance (I) and Privacy Program Operational Life Cycle (II).

Echo Entertainment Group Limited (ABN ) Risk and Compliance Committee Terms of Reference

SBERBANK OF RUSSIA. Regulations on Sberbank Supervisory Board Committees

Corporate Governance Statement

PUBLIC FINANCE MANAGEMENT ACT, 1999: DRAFT TREASURY REGULATIONS

Governance, Risk and Compliance Charter

Corporate Governance Framework June 2015

Terms of Reference - Board Risk Committee

Sample risk committee charter

Fund Management Companies Guidance

King Report on Corporate Governance for South Africa. What it means to you

FIRST REPUBLIC BANK DIRECTORS ENTERPRISE RISK MANAGEMENT COMMITTEE CHARTER

Audit Committee Terms of Reference

Information Governance Strategy

State of Minnesota IT Governance Framework

Director of Asset Management and Repairs

Notion VTec Berhad (Company No D) Board Charter

Effective Internal Audit in the Financial. Services Sector. Non Executive Directors (NEDs) and the Management of Risk

THE BOARD OF DIRECTORS OF THE DEPOSITORY TRUST & CLEARING CORPORATION MISSION STATEMENT

Revised May Corporate Governance Guideline

BROCK UNIVERSITY FINANCIAL PLANNING AND INVESTMENT COMMITTEE CHARTER

OVERSTRAND MUNICIPALITY

Transcription:

Version : 1.01 Date : 16 September 2009 IT Governance Network South Africa USA UK Switzerland www.itgovernance.co.za info@itgovernance.co.za 0825588732 IT Governance Network, Copyright 2009 Page 1

1 Terms of Reference 1.1 PURPOSE: Communicate the primary responsibilities and delegated authority of the [IT Steering Committee / CIO / Executive Management] for the effective and efficient management of IT resources to facilitate the achievement of corporate objectives. 1.2 THE DELEGATION OF AUTHORITY: Authority delegated to the [IT Steering Committee / CIO / Executive Management] is founded on the following principles: 1. Does not divest the Board of Directors of their responsibilities concerning the exercise of the delegated power or the performance of the assigned duties herein. 2. Is given to a committee whose membership integrates both IT and business knowledge (or a CIO who is to include relevant representation from the business in decision making). 3. Is subject to the statutory and legal limitations, recorded herein, and such other lawful limitations as may be applicable to the company from time to time. 4. Is subject to any limitations, conditions, policies and/or directives that may be developed and implemented by executive management at the request of the Board of Directors in the exercise of such delegated powers. 5. May at any time be revoked or varied by the Chief Executive Officer. 6. The Board of Directors may confirm, vary or revoke any decision taken by the [IT Steering Committee / CIO / Executive Management] as a result of a delegation in terms hereof, subject to any rights that may have become vested as a consequence of the decision. 7. Unless otherwise specified, the [IT Steering Committee / CIO / Executive Management] is hereby authorised, in writing, and subject to paragraphs 1 to 6 above: a. To delegate further any powers and authority delegated to the [IT Steering Committee / CIO / Executive Management] to an officer, employee, any person or committee and to allow subdelegation of such powers only once and, where necessary, in terms of the needs of the business, subject to the policies, directives and conditions that the Board of Directors may from time to time prescribe, and the reporting of such authority. b. To impose any limits or conditions in such further delegation to ensure good governance and controls with regard to the exercise of such powers and may, in writing, confirm, vary or revoke any decision taken subject to any rights that may have become vested as a consequence of such decision. 8. The [IT Steering Committee / CIO / Executive Management] shall ensure that any further delegation or sub delegation is to a functionary with the appropriate seniority, skill, expertise and knowledge to exercise such authority in an effective manner, and shall ensure that such authorities are reviewed on a regular basis. 9. The [IT Steering Committee / CIO / Executive Management] or any other person with delegated powers may only exercise those powers in respect of the responsibilities and functions allocated to them from time to time, in terms of a performance agreement or specific instructions or mandates. 10. Where power is delegated to more than one IT Steering Committee / CIO / Executive Management, it is on the basis of different functional responsibility and expected process outcomes. 11. Reporting is to follow the delegation process i.e. any approvals need to be reported to the next level of authority. Non conformance with the delegated powers shall be reported to the next higher level of authority. 1.3 MEMBERS: Chair: Name, Contact Information IT Governance Network, Copyright 2009 Page 2

Non Executive Director 1: Name, Contact Information Roles (e.g. rep. of specified business interests) Non Executive Director 2: Name, Contact Information Roles (e.g. rep. of specified business interests) Non Executive Director 3: Name, Contact Information Roles (e.g. rep. of specified business interests) Chief Executive Officer : Name, Contact Information Roles (e.g. rep. of specified business interests) Chief Financial Officer : Name, Contact Information Roles (e.g. rep. of specified business interests). 1.4 GOALS: 1. Manage business risks 2. High service availability 3. Agility in responding to changing business requirements 4. Automate and integrate the enterprise value chain 5. Compliance with internal policies, selected industry standards, external laws and regulations. 1.5 RESPONSIBILITIES (BASED ON KING III): Organisational structure, relationships, frameworks and processes Develop and implement an IT governance charter and policies Implement a suitable organisational structure and define terms of reference Implement an accountability framework to assign decision making rights Establish a bridge between IT and the business Implement IT processes and governance mechanisms Implement IT frameworks, policies, procedures and standards Provide transparency through regular reporting to the board Encourage the desirable use of IT by requiring managers to provide timely information, comply with the direction given and to conform to the principles of good governance Incorporate IT governance in corporate governance Create an awareness of the maturity levels of governance. Strategic Alignment Have a strategic approach and facilitate the integration of IT into business strategic thinking Implement a strategic IT planning process that is integrated with the business strategy development process Sustain and enhance the company s strategic objectives Integrate IT plans with the business plans Define, maintain and validate the IT value proposition Enable the improvement of the company s performance and sustainability Align IT operations with business operations Align IT activities with environmental sustainability objectives Implement a robust process to identify and exploit, where appropriate, opportunities to improve performance and sustainability of the company in line with triple bottom line objectives Include relevant representation from the business in oversight structures Have regard for the legislative requirements that apply to IT Understand business requirements and long term strategy Translate business requirements into efficient and effective IT solutions IT Governance Network, Copyright 2009 Page 3

Support the business and governance requirements in a timely and accurate manner through the acquisition of people, process and technology. Value Delivery Enable IT to add value to the business and mitigate risks Incorporate IT into the business processes in a secure, sustainable manner Ensure that the business value proposition is proportional to the level of investment Deliver the expected return from IT investments Measure and manage the amount spent on and the value received from technology Implement an ethical IT governance and management culture Build management skills and competencies to govern and promote a common language Promote sharing and re use of IT assets Ensure all parties in the chain from supply to disposal of IT services and goods apply good governance principles Monitor and enforce good governance across all suppliers. Resource Management Exercise care and skill over the design, development, implementation and maintenance of sustainable IT solutions Optimise resources usage and leverage knowledge Protect information and intellectual property Conduct post implementation reviews to learn from each implementation Manage information assets effectively Ensure the integrity and availability of information and information systems in a timely manner Implement information records management and ensure information assets are identified, classified, retained, stored, archived, protected and made available when required for business and legal purposes Obtain independent assurance that outsourced service providers have applied the principles of IT governance Obtain independent assurance that the basic elements of appropriate project management principles are applied to all IT projects Regularly demonstrate to the Board of Directors that the company has adequate business resilience arrangements in the event of a disaster affecting IT. Risk Management Minimise risks Implement a risk management process based on the boards risk appetite Select and use an appropriate framework for managing risk (e.g. COSO) Comply with applicable laws and regulations Maintain an IT risk register, including IT legal risks Design, implement and monitor the IT risk management plan Implement an IT controls framework Obtain assurance on the effectiveness of the IT control framework Obtain independent assurance of the effectiveness of the IT controls framework implemented by service providers Perform continual risk assessments Consider and implement appropriate risk responses IT Governance Network, Copyright 2009 Page 4

Implement an information security strategy Implement an information security management system in accordance with an appropriate information security framework Establish a business continuity programme for the company s information and successful execution of the business activities Identify all personal information processed by the company and treat this as an important business asset, including being processed in accordance with applicable laws Provide the Audit and Risk Committees with relevant information about IT risks and the controls in place. Performance Management Measure, manage and communicate IT performance Implement processes to ensure that reporting to the board is complete, timely, relevant, accurate and accessible Report to the [IT Steering Committee / Board of Directors] on IT performance. 1.6 DELIVERABLES Agendas for meetings Minutes of meetings Criteria for decision making IT governance framework Accountability framework Framework of authorities Authorised policies Authorised standards, procedures and practices Defined value proposition for IT Cascade of business goals to IT process activity goals Criteria for evaluating IT performance Criteria for aligning IT activities with environmental sustainability objectives Integrated IT and business plans Information record management IT controls framework Strategic IT planning process integrated with business strategy development process Business value proposition statements Process to identify and exploit opportunities for IT to improve company s performance and sustainability Report on the amount spent and benefits received from information technology Report on the principles of IT governance applied by all service providers Report on the effectiveness of service provider internal control framework Project assurance report Process based risk management Register of statutory, regulatory and contractual obligations IT risk register Information security strategy Information security management system Business continuity programme IT Governance Network, Copyright 2009 Page 5

Report on internal controls Report to Risk Committee Report to Audit Committee IT performance report. 1.7 SCOPE / JURISDICTION The [IT Steering Committee / CIO / Executive Management] is responsible for directing, controlling and measuring the IT activities and processes of the company. The accountability of the [IT Steering Committee / CIO / Executive Management] spans: Operational / business as usual activities that comprise the processes within the scope of its authority Transformation programmes and projects that affect the processes within the scope of its authority All improvement initiatives that affect the processes within the scope of its authority. The [IT Steering Committee / CIO / Executive Management] is required to ensure sufficient organizational capability exists to enable the processes within its scope to perform and deliver the results expected by the business. The primary role of the [IT Steering Committee / CIO / Executive Management] is to exercise its authority in support of the IT process owner s endeavours to achieve the outcomes expected and to periodically evaluate performance and monitor remedial actions to remedy instances of poor performance. The [IT Steering Committee / CIO / Executive Management] will work with the IT process owners to identify suitable criteria that are to be used for decision making within the processes. 1.8 GUIDANCE FROM THE BOARD In working towards the achievement of the business goals through the development and execution of the IT processes defined to be within scope, the [IT Steering Committee / CIO / Executive Management] will need to respond to the direction provided by the Board of Directors and seek approval of the goals being targeted in the short and long term. 1.9 RESOURCES AND BUDGET The [IT Steering Committee / CIO / Executive Management] is required to ensure that the IT processes within the scope of its authority remain within the approved budgets at all times. 1.10 GOVERNANCE Governance of this [IT Steering Committee / CIO / Executive Management] is provided by the Board of Directors. IT Governance Network, Copyright 2009 Page 6

1.11 ADJUSTMENTS AND APPROVAL The [IT Steering Committee / CIO / Executive Management] is to review recommended adjustments to these terms of reference at least once within every 12 month period. These terms of reference cannot be adjusted without approval of the Board of Directors. 1.12 MANAGEMENT RELATIONSHIPS AND DUTIES 1.12.1 Official Members Committee membership shall be comprised of directors and executive management from the business. If for some reason, a member is unable to commit to participation, (s)he shall designate another senior level business leader from within the Division/Subsidiary/Company. 1.12.2 The Chair [Role] will serve as the Chair. The Chair shall have the authority to delegate functions and responsibilities to the extent that this Charter does not expressly prohibit such delegation. The Chair shall set agendas for, and preside over, meetings of the [IT Steering Committee / Executive Management]. The Chair shall ensure that the actions of [IT Steering Committee / Executive Management] meetings are recorded and distributed. 1.12.3 The Vice-chair The Chair shall appoint a Vice chair, who shall preside over [IT Steering Committee / Executive Management] meetings in the Chair s absence. 1.12.4 Meetings The Chair shall establish a schedule for the regular meetings of the [IT Steering Committee / Executive Management]. The Chair may call ad hoc meetings upon written notice of no less than two (2) business days. Written notices may be in the form of email. 1.12.5 Voting Members Directors and officers of the following principal divisions and subsidiaries are voting members of the [IT Steering Committee / Executive Management]: [position] [position] [position]. 1.13 QUORUM AND VOTING A quorum, for conducting business and making recommendations regarding actions for items coming before the [IT Steering Committee / CIO / Executive Management], shall consist of two thirds of voting members. A simple majority of those voting in favour of the motion shall pass a motion. The Chair shall only vote in the event of a tie vote among voting members. IT Governance Network, Copyright 2009 Page 7

1.14 ADDITIONAL NOTES Relationships to other committees Where shared information, such as plans and contact information, will be stored. IT Governance Network, Copyright 2009 Page 8