
SOUTH EASTERN POWER NETWORKS PLC
CORPORATE GOVERNANCE STATEMENT FOR THE YEAR ENDED 31 MARCH 2024
The Group Board (through its Audit Committees) is responsible for the oversight of risk management
and internal controls across the Group. The responsibility for the risk management framework and
internal controls cascades from the CEO and the EMT to senior management teams responsible for
risk assessment and the implementation of appropriate mitigation. Managers are responsible for the
identification of risks and the deployment of appropriate controls within their business Directorate.
Policies are established, reviewed regularly and made available on the Group intranet to assist the
managers with establishing an appropriate control environment. The involvement of qualified and
competent employees with the appropriate level of expertise throughout the business is a key factor
for implementing an effective internal control environment.
The role of the Directorate risk review meetings is to assess new risks, review existing risks and
monitor control improvement actions. Each identified risk is defined and assessed by the risk owner.
This includes an assessment of the likelihood of the risk occurring and the associated impact, key
mitigating controls, and an assessment of the adequacy of those controls. Where appropriate control
improvement actions are defined. Significant risks and delivery of control improvement actions are
monitored and reported to the Executive and Senior Management Teams on a regular basis, and
actively managed by the designated risk owners.
Risk management is embedded into the organisational structure, with specialist teams established to
manage certain key risk areas. Specifically, there are long established teams reporting to senior
managers, responsible for health and safety, regulatory compliance, employees, cyber security,
financial reporting, procurement and legal compliance.
Emerging and principal risks are regularly reported to the Group Board facilitating the oversight of the
risk management process of the Group. Pages 15 to 20 of the Strategic report outline the key risks
and the related mitigating actions by the Group.
Internal control framework
Control procedures have been implemented throughout the Group and are designed to achieve
complete and accurate accounting for financial transactions, to safeguard the Group’s assets and for
compliance with laws and regulations. These control procedures form the Integrated Management
System, a controlled framework of policy and procedural documentation. Control procedures are
subject to regular review and formal ratification and approval. As part of the Integrated Management
System, procedural implementation and compliance is subject to regular monitoring. The Group Board
has established an internal audit function which is responsible for reviewing the effectiveness of the
Group’s systems of internal control and reports to the Audit Committee of the Group Board.
Internal audit
The Internal Audit function has responsibility for providing independent assurance to the CEO and the
Audit Committee as to the effectiveness of the policies, procedures and standards which constitute
the system of internal control, including; risk management; corporate governance; and compliance
with relevant laws and regulations. Internal Audit has a reporting line to the Audit Committee.
The relationship between Internal Audit and management requires management to be primarily
responsible for ensuring that the systems of internal control are implemented and operated so as to
provide reasonable assurance that the objectives of the business will be met and that the risks or
threats to the business are mitigated. In addition to providing independent review, the Internal Audit
function provides advice and guidance to management on the appropriateness of internal control
mechanisms and systems.
Page 42