General Risk Control and 20/10/15

Similar documents
GENERAL RISK CONTROL AND MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT (ERM) POLICY Republic Glass Holdings Corporation. Purpose. Goals

REGULATION. on Internal Governance Arrangements, the Management body and the Internal Capital Adequacy Assessment Process for Banks and Savings banks

GENERAL RISK CONTROL AND MANAGEMENT POLICY

Goodman Group. Risk Management Policy. Risk Management Policy

DRAFT SOUND COMMERCIAL PRACTICES GUIDELINE

Treasury Management Policy. Treasury Management Policy. Working Together. August Borders College 24/10/2011.

SOL PLAATJE MUNICIPALITY

ANTI BRIBERY AND CORRUPTION POLICY

Risk Management Policy Coface Singapore

CARIBBEAN DEVELOPMENT BANK STRATEGIC FRAMEWORK FOR INTEGRITY, COMPLIANCE AND ACCOUNTABILITY PILLARS I AND II INTEGRITY AND ETHICS POLICY

Risk Appetite Statement

Risk Management Policy

TREASURY MANAGEMENT POLICY

CORPORATE SOCIAL RESPONSIBILITY POLICY

Habib Bank AG Zurich. Annual disclosures according to Basel III (Year 2014)

RISK MANAGEMENT FRAMEWORK OVERVIEW

Santiago Principles Self-Assessment

IBERDROLA FRAMEWORK FOR GREEN FINANCING

GUERNSEY FINANCIAL SERVICES COMMISSION CODE OF PRACTICE FOR BANKS. Effective 24 November 2003

RISK MANAGEMENT POLICY October 2015

RISK APPETITE OVERVIEW

Risks and uncertainties facing the business

Treasury Management Policy

IBERDROLA FRAMEWORK FOR GREEN FINANCING (the Framework )

MEMORANDUM. To: From: Metrolinx Board of Directors Robert Siddall Chief Financial Officer Date: September 14, 2017 ERM Policy and Framework

APPENDIX 1. Transport for the North. Risk Management Strategy

SOLVENCY AND FINANCIAL CONDITION REPORT EUROLIFE LTD

Additional reporting and disclosures

Risk Management Strategy January NHS Education for Scotland RISK MANAGEMENT STRATEGY

HEALTH RESEARCH CAPACITY STRENGTHENING INITIATIVE. Program Risk Management Policy. September Imperial : +265 (0)

Precious Metals Supply Chain Policy

Prudential Standard GOI 3 Risk Management and Internal Controls for Insurers

14 July Company By-Laws of Iberdrola Generación España, S.A., Sociedad Unipersonal

Strategic policy. Policy purpose The purpose of this policy is to:

Response of St Anthony s & Claddagh Credit Union To Consultation paper CP109 Potential Changes to the Investment Framework for Credit Unions

Managing And Mitigating Risk In PT Pertamina (Persero) to balance Aggressive Growth Strategies with Prudent Risk Management Frameworks

Tilman Brewin Dolphin Limited Pillar 3 Disclosures

Key risks and mitigations

RISK MANAGEMENT FRAMEWORK

Risk Management Policy

RISK COMMITTEE CHARTER THE CHARLES SCHWAB CORPORATION

The Operational Risk Management in Banking Evolution of Concepts and Principles, Basel II Challenges

MONEY-LAUNDERING PREVENTION SANTANDER GROUP GLOBAL POLICY

Treasury Management Policy

UBS Saudi Arabia (A SAUDI JOINT STOCK COMPANY) Pillar III Disclosure As of 31 December 2014

ANTI-CORRUPTION POLICY

Fraud, Bribery and Corruption Control Policy

ICAAP Pillar 3 Disclosure

Pillar 3 Disclosure. Sumitomo Mitsui Trust Bank (Thai) Public Company Limited. March 31 st, Pillar 3 Disclosures 31 March 2018

SOLVENCY AND FINANCIAL CONDITION REPORT EUROLIFE LTD

Governing Policy for Power Supply Hedging Program. REQUEST: Approval of Revised Governing Policy for Power Supply Hedging Program

HUMAN CAPITAL FRAUD AND CORRUPTION PREVENTION

Pillar 3 Disclosure November 2016

ICBC LONDON Tax Strategy

Strategic Monitoring and Business and Management Plan

Romanian Court of Accounts RISK MANAGEMENT 24 April 2012 Warsaw, Poland

REPORT MARKET DISCIPLINE REPORT FINANCIAL YEAR Made in accordance with the Cyprus. Securities and Exchange Commission. Directive DI

PROCUREMENT IN WORLD BANK INVESTMENT PROJECT FINANCE PROCUREMENT POLICY (DRAFT)

MONEY-LAUNDERING AND TERRORISM FINANCING PREVENTION SANTANDER GROUP GLOBAL POLICY

TREASURY MANAGEMENT POLICY The Association s Treasury Management Policy will be operated by the following principles:

Corporate Social Responsibility Policy

Ashmore Group plc Pillar 3 Disclosures as at 30 June 2018

Risk Management: Process and Culture in ESB

UBS Saudi Arabia (A SAUDI JOINT STOCK COMPANY) Pillar III Disclosure As of 31 December 2017

Risk and Growth: Thrive, Survive or Fail

West Coast District Municipality. Risk Management Policy

Network Rail Limited (the Company ) Terms of Reference. for. The Audit and Risk Committee of the Board

Risk Management. Financial Risk. Asset and liability management

Global Tax Strategy November 2017

ITrade Global (CY) Ltd Regulated by the Cyprus Securities and Exchange Commission License no. 298/16

BANKING CONVENTIONAL. Overview

Pillar 3 Disclosure ICAP Europe Limited

EMERGO WEALTH LTD (Regulated by the Cyprus Securities & Exchange Commission, License Number 232/14)

Treasury and Investment Policy

FUNDS MANAGED BY GOLDMAN SACHS ASSET MANAGEMENT - FAIR PROCESSING NOTICE EFFECTIVE DATE: 25 MAY 2018

ENTERPRISE RISK MANAGEMENT POLICY FRAMEWORK

CORPORATE RISK MANAGEMENT POLICY

Ashmore Group plc Pillar 3 Disclosures as at 30 June 2016

BERMUDA MONETARY AUTHORITY THE INSURANCE CODE OF CONDUCT FEBRUARY 2010

CBRE Clarion Securities UK Limited PILLAR 3 RISK DISCLOSURES April 2017

REINSURANCE RISK MANAGEMENT GUIDELINE

Treasury Management Policy

University Risk Management Policy

CARIBBEAN DEVELOPMENT BANK STRATEGIC FRAMEWORK FOR INTEGRITY, COMPLIANCE AND ACCOUNTABILITY PILLARS I, II AND III WHISTLEBLOWER POLICY

Treasury Management Policy Statement

5. Ethics Ethics and Integrity: Summary, Objectives and General Principles

ANTI-CORRUPTION POLICY

Risk Management Policy

University of the Sunshine Coast (USC) Risk Appetite Statement

Appendix B - Treasury Management Policy 2019/20

Risk Management Policy

Contents Investment Policy

Risk Management Policy

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 291 thereof,

RISK MANAGEMENT POLICY

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ).

Amadeus Global Report 2016 A business, financial and sustainability overview. Corporate risk management

Outline Capital Investment Strategy

DECISION ON RISK MANAGEMENT BY BANKS

Transcription:

General Risk Control and Management Policy 20/10/15

CONTENTS GENERAL RISK CONTROL AND MANAGEMENT POLICY 3 1. Purpose 3 2. Scope 3 3. Risk Factors - Definitions 3 4. Basic Principles 4 5. Comprehensive Risk Control and Management System 4 6. Risk Policies and Limits 5 2

GENERAL RISK CONTROL AND MANAGEMENT POLICY The Board of Directors of IBERDROLA, S.A. (the Company ) is responsible for establishing the General Risk Control and Management Policy, identifying the principal risks facing the Company and the other companies included within the group of which the Company is the controlling entity, within the meaning established by the law (the Group ) and organising appropriate internal monitoring and information systems, as well as carrying out a periodic monitoring of such systems. The General Risk Control and Management Policy rests upon the following pillars: 1. Purpose The purpose of the Company s General Risk Control and Management Policy is to establish the basic principles and general framework for the control and management of all kinds of risks facing the Company and the Group, and which must be applied in accordance with the mission, vision and values of the Group approved by the Company s Board of Directors. The General Risk Control and Management Policy is further developed and supplemented by the Corporate Risk Policies and the Specific Risk Policies that may be established for certain businesses and/or companies within the Group. For purposes of implementing the duty of the country subholding companies to disseminate, implement, and ensure the monitoring of the general policies, strategies, and guidelines of the Group in each of the countries in which it operates and with respect to the businesses grouped within each of them, taking into account the characteristics and particularities thereof, each country subholding company must adopt these Risk Policies, with a specification, if applicable, of the companies included within the scope thereof, and to approve the appropriate guidelines on risk limits, and the head of business companies must approve within their corresponding management decision-making bodies the specific risk limits applicable to each of them and implement the control systems required to ensure compliance therewith. 2. Scope The General Risk Control and Management Policy applies to all companies that make up the Group, including the companies that are not part of the Group in which the Company has an interest and over which it has effective control, within the limits established by the laws applicable to the regulated activities carried out by the Group in the various countries in which it operates Excluded from the scope of this policy are listed subsidiaries which, as such, have their own Corporate Policies approved by their competent bodies. At those companies in which the Company has an interest and to which the General Risk Control and Management Policy does not apply, the Company shall promote principles, guidelines, and risk limits consistent with those established in the General Risk Control and Management Policy and in its supplemental Risk Policies and shall maintain appropriate channels of information to ensure a proper understanding of risks. 3. Risk Factors - Definitions From a general viewpoint, a risk is considered to be any threat that an event, action, or omission may prevent the Group from reaching its objectives and successfully carrying out its strategies. The risk factors to which the Group is subject generally are listed below: a) Corporate Governance Risks: the Company accepts the need to achieve the fulfilment of the corporate interest and the sustained maximisation of the economic value of the Company and its long-term success, in accordance with the Group s corporate interest, culture, and corporate vision, taking into account the legitimate public and private interests that converge in the conduct of all business activities, particularly those of the various stakeholders and communities and regions in which the Company and its employees act. A fundamental requirement for the foregoing is compliance with the Company s Corporate Governance System, made up of the By-Laws, the Corporate Policies, the internal corporate governance rules, and the other internal codes and procedures approved by the competent decision-making bodies of the Company and inspired by the good governance recommendations generally recognised in international markets. b) Market Risks: defined as the exposure of the Group s results and net worth to changes in market prices and variables, such as exchange rates, interest rates, commodity prices (electricity, gas, CO 2 emission allowances, other fuel, etc.), prices of financial assets, and others. c) Credit Risks: defined as the possibility that a counterparty fails to perform its contractual obligations, thus causing an economic or financial loss to the Group. Counterparties can be end customers, counterparties in financial or energy markets, partners, suppliers, or contractors. d) Business Risks: defined as the uncertainty regarding the performance of key variables inherent in the business, such as the characteristics of demand, weather conditions, and the strategies of different players. e) Regulatory Risks: defined as those arising from regulatory changes made by the various regulators, such as changes in compensation of regulated activities or in the required conditions of supply, or in environmental or tax regulations. f) Operational Risks: defined as those related to direct or indirect economic losses resulting from inadequate internal procedures, technical failures, human error, or as a consequence of certain external events, including the economic, social, environmental, and reputational impact thereof, as well as legal and fraud risks. Operational risks include those associated with information technology and cybersecurity, among others. g) Reputational Risks: potential negative impact on the value of the Company resulting from conduct on the part of the Company that is below the expectations created among various stakeholders, as defined in the Stakeholder Relations Policy. 3

4. Basic Principles The Group is subject to various risks inherent in the different countries, industries, and markets in which it does business and in the activities it carries out, which may prevent it from achieving its objectives and successfully implementing its strategies. Aware of the significance of this issue, the Board of Directors of the Company undertakes to develop all of its capabilities in order for the significant corporate risks to all the activities and businesses of the Group to be adequately identified, measured, managed, and controlled, and to establish through the General Risk Control and Management Policy the mechanisms and basic principles for appropriate management of the risk/opportunity ratio, at a risk level that makes it possible to: a) attain the strategic objectives formulated by the Group with controlled volatility; b) provide the maximum level of assurance to the shareholders; c) protect the results and reputation of the Group; d) defend the interests of customers, shareholders, other groups interested in the progress of the Company, and society in general; and e) ensure corporate stability and financial strength in a sustained fashion over time. In the implementation of the aforementioned commitment, the Board of Directors and its Executive Committee have the cooperation of the Audit and Risk Supervision Committee, which, as a consultative body, monitors and reports upon the appropriateness of the system for assessment and internal control of significant risks, acting in coordination with the audit and compliance committees existing at other companies of the Group. In addition, the duty of implementing and ensuring the monitoring of the Risk Policies is also carried out through the country subholding companies, which group together the equity interests of the energy head of business companies in their respective countries. In particular, these country subholding companies are assigned the duty of specifying the application of the Specific Risk Policies of the Various Business of the Group, given the characteristics and particularities of each country. All actions aimed at controlling and mitigating risks shall conform to the following basic principles: a) Integrate the risk/opportunity vision into the Company s management, through a definition of the strategy and the risk appetite and the incorporation of this variable into strategic and operating decisions. b) Segregate functions, at the operating level, between risk-taking areas and areas responsible for the analysis, control, and monitoring of such risks, ensuring an appropriate level of independence. c) Guarantee the proper use of risk-hedging instruments and the maintenance of records thereof as required by applicable law. d) Inform regulatory agencies and the principal external players, in a transparent fashion, regarding the risks facing the Group and the operation of the systems developed to monitor such risks, maintaining suitable channels that favour communication. e) Ensure appropriate compliance with the corporate governance rules established by the Company through its Corporate Governance System and the update and continuous improvement of such system within the framework of the best international practices as to transparency and good governance, and implement the monitoring and measurement thereof. f) Act at all times in compliance with the law and the Company s Corporate Governance System and, specifically, with due observance of the values and standards reflected in the Code of Ethics and under the principle of zero tolerance for the commission of unlawful acts and situations of fraud set forth in the Crime Prevention and Anti-Fraud Policy. 5. Comprehensive Risk Control and Management System The General Risk Control and Management Policy and the basic principles underpinning it are implemented by means of a comprehensive risk control and management system, supported by a Corporate Risk Committee and based upon a proper definition and allocation of duties and responsibilities at the operating level and upon supporting procedures, methodologies and tools, suitable for the various stages and activities within the system, including: a) The ongoing identification of significant risks and threats, taking into account their possible impact on key management objectives and the accounts (including contingent liabilities and other off-balance sheet risks). b) The analysis of such risks, both at each corporate business or function and taking into account their combined effect on the Group as a whole. c) The establishment of a structure of policies, guidelines, and limits, as well as of the corresponding mechanisms for the approval and implementation thereof. d) The measurement and control of risks following homogenous procedures and standards common to the entire Group. e) The analysis of risks associated with new facilities, as an essential element in risk/return-based decision-making. f) The maintenance of a system for internal monitoring of compliance with policies, guidelines, and limits, by means of appropriate procedures and systems, including the contingency plans needed to mitigate the impact of the materialisation of risks. g) The periodic monitoring and control of profit and loss account risks that might have a significant impact in order to control the volatility of the annual income of the Group. 4

h) The ongoing evaluation of the suitability and efficiency of applying the system and the best practices and recommendations in the area of risks for eventual inclusion thereof in the model. i) The audit of the comprehensive risk control and management system by the Internal Audit Division. 6. Risk Policies and Limits The General Risk Control and Management Policy is further developed and supplemented by the Corporate Risk Policies and the Specific Risk Policies established in connection with certain businesses of the Group, which are listed below and are also subject to approval by the Board of Directors of the Company. Structure of Risk Policies of the Group General Risk Control and Management Policy Corporate Risk Policies: - Corporate Credit Risk Policy. - Corporate Market Risk Policy. - Operational Risk in Market Transactions Policy. - Insurance Policy. - Investment Policy. - Financing and Financial Risk Policy. - Treasury Share Policy. - Risk Policy for Equity Interests in Listed Companies. - Reputational Risk Framework Policy. - Information Technology Policy. - Cybersecurity Risk Policy. - Procurement Policy. Specific Risk Policies for the Various Group Businesses: - Risk Policy for the Networks Businesses of the Iberdrola Group. - Risk Policy for the Renewable Energy Businesses of the Iberdrola Group. - Risk Policy for the Liberalised Businesses of the Iberdrola Group. - Risk Policy for the Non-Energy Businesses of the Iberdrola Group. This General Risk Control and Management Policy was initially approved by the Board of Directors on 18 December 2007, and was last amended on 20 October 2015.