Le référentiel
Une architecture à trois niveaux de contrôle
Notre référentiel de gestion des risques repose sur une architecture à trois niveaux de contrôle, intégrant conformité, risk management, audit interne et contrôle permanent.
Consulter la documentationGOVERNANCE BODIES AND ENTITIES(a)
MANAGEMENT
FIRST LEVEL
Identification and management of risks of competence and related controls
LINE MANAGEMENT
/RISK OWNER
/RISK OWNER
(BUSINESS & SUPPORT PROCESS)
SECOND LEVEL
Monitoring of main risk categories and adequacy of controls
SPECIALIST FUNCTIONS
Integrated Compliance
Integrated Risk Management
Financial Reporting Officer
Corporate Affairs and Governance
HSE
Process Owner
Planning and Control
Dedicated/Risk specialist functions or functions from Compliance Models
(e.g. Security, Asset Integrity, Cyber, Health, Officer, Organization)
INTERNAL AUDIT
THIRD LEVEL
Assurance and independent advice on the first and second level of control and ICRMS(b) as a whole
INTERNAL AUDIT FUNCTION
EXTERNAL ASSURANCE PROVIDERS
FIRST LEVEL SUPPORT
ADVICE TO FIRST AND SECOND LEVEL
LEGEND:
Direction, delegation, oversight, resources
Accountability, reporting, assurance
Communication, coordination, cooperation
(a) They include: Board of Directors, Control and Risk Committee, Board of Statutory Auditors, 231 Supervisory Board, Chairman of the BoD, and CEO.
(b) ICRMS - Internal Control and Risk Management System.