Référentiel

Le référentiel

Une architecture à trois niveaux de contrôle

Notre référentiel de gestion des risques repose sur une architecture à trois niveaux de contrôle, intégrant conformité, risk management, audit interne et contrôle permanent.

Consulter la documentation

GOVERNANCE BODIES AND ENTITIES(a)

MANAGEMENT

FIRST LEVEL

Identification and management of risks of competence and related controls

LINE MANAGEMENT
/RISK OWNER
(BUSINESS & SUPPORT PROCESS)

SECOND LEVEL

Monitoring of main risk categories and adequacy of controls

SPECIALIST FUNCTIONS
Integrated Compliance
Integrated Risk Management
Financial Reporting Officer
Corporate Affairs and Governance
HSE
Process Owner
Planning and Control
Dedicated/Risk specialist functions or functions from Compliance Models
(e.g. Security, Asset Integrity, Cyber, Health, Officer, Organization)

INTERNAL AUDIT

THIRD LEVEL

Assurance and independent advice on the first and second level of control and ICRMS(b) as a whole

INTERNAL AUDIT FUNCTION
EXTERNAL ASSURANCE PROVIDERS
FIRST LEVEL SUPPORT
ADVICE TO FIRST AND SECOND LEVEL
LEGEND:
Direction, delegation, oversight, resources
Accountability, reporting, assurance
Communication, coordination, cooperation

(a) They include: Board of Directors, Control and Risk Committee, Board of Statutory Auditors, 231 Supervisory Board, Chairman of the BoD, and CEO.
(b) ICRMS - Internal Control and Risk Management System.