
Platform resilience and innovation
continued
STRATEGIC REPORT
60 61
OCADO GROUP PLC Annual Report and Accounts 2022
STRATEGIC REPORT
OCADO GROUP PLC Annual Report and Accounts 2022
RESPONSIBLE BUSINESS
Materiality:
Business & Ethics
Maintaining and building on our
compliance framework is critical to
supporting our aspiration to conduct
business to the highest standards of
honesty and integrity. Plans for, and
results of, this work, including key
compliance metrics, are regularly
reported to the Board, Audit
Committee and Risk Committee.
In 2022, our focus was on ensuring
that our framework continues to
mature in line with the needs of our
growing organisation by:
– Reviewing a number of our
existing compliance policies to
ensure they remain fit for purpose
and updating them as required
to reflect global requirements.
– Improving accessibility by
translating a number of compliance
policies and training modules into
the core language requirements
of our employees.
– Updating our compliance
platform, which brings together
all compliance materials in one
carefully designed location.
– Launching a new conflicts of
interest training module and
refreshing our annual code of
conduct module.
– Increasing the maturity of our fraud
compliance framework by updating
our policies and guidance and
running a training programme to help
embed the key principles at Ocado.
– Evolving our communication
approach in line with the way we
communicate as a business, with
a focus on bespoke messaging
across core audiences and trialling
different formats to increase
knowledge and awareness of
core compliance topics.
Encouragingly, the results of
our business-wide compliance
survey showed another increase
in knowledge and awareness
of compliance topics across the
board. The survey also provided an
opportunity for employees to feed
back on the compliance framework
and related activities; information
which will be used with other sources
to inform the compliance roadmap
for the year ahead.
Materiality:
Cybersecurity
We risk the loss of critical assets and
sensitive information as a result of a
cyber attack, insider threat, or a data
breach. This could result in business
disruption, reputational damage,
significant fines or the loss of
confidential business information.
The continued evolution and growth of
Ocado as a global technology solution
provider has increased the likelihood
of Ocado being the target of a cyber
attack. Cyber attacks have continued
to evolve, globally, in 2022, increasing
in both frequency and sophistication.
These changes, as well as the
uncertainty due to the war in Ukraine
have led to an increase in the risk of
a cyber incidents.
To address this risk, we have a
security program in place that covers
both our corporate systems and the
Ocado Smart Platform and includes:
A defined security governance
framework, overseen by the
Information Security Committee
– External audit of our security
framework through our SOC 2
compliance program
– A proactive awareness program
to educate all employees on
cybersecurity risks
– A dedicated security operations
team to detect and respond to
security incidents
– A vendor assurance program to
manage third party cyber risks.
– Regular security testing of our
applications and infrastructure.
– Secure by design: baking
security into our software
development process.
Our Code of Conduct
Our Code of Conduct supports
our rapidly-growing business by
cementing and expressing the
importance of the principles we live
and work by, as well as setting out
our mission, values and Company
policies all in one place.
Our Code of Conduct, which was
refreshed during the year, explains
how it is important for all of our
employees to comply with our
minimum standards and expectations.
It is also a useful reference point for
aspects relating to individual conduct,
working relationships and company
property and resources.
Find this online
https://ocadogroup.com/media/2b4lfrqn/
code-of-conduct-2022.pdf
Whistleblowing
We are committed to practising
good business and we do this
through creating an open and
transparent culture in which to work.
To help our employees understand
what whistleblowing is and how to
make a report without the fear of
retaliation or reprisal, we have our
Whistleblowing Policy.
Our awareness campaign this year
focused on encouraging employees
globally to report wrongdoing to
either their manager or their People
Partner, or by using our confidential
whistleblowing service operated by
independent third-party specialist,
Navex Global. Our whistleblowing
initiative, known internally as “Speak
Up”, allows employees and third parties
to report a concern by phone or the
website 24/7 throughout the year.
Anti-Bribery and Anti-Corruption
Our Anti-Bribery and Anti-Money
Laundering policies were reviewed and
remain fit for purpose. These policies
and our public-facing Anti-Bribery
Statement reiterate our zero-tolerance
approach to bribery and money
laundering and outline the standards
we expect of those working for us.
The Anti-Bribery policy also details
our position in respect of giving and
receiving gifts and hospitality and how
to report and record such matters and
is further supported with practical
guidance. The policy also details key
principles to apply when contracting
with third parties, which is supported
by an update to the supplier set up
form made during the year. New
starters receive training to help them
identify and manage the risk of bribery
as part of their induction and existing
employees receive refresher training on
the topic both biennially as part of our
topic- specific refresh programme, and
annually as part of our wider Code of
Conduct training programme. Our
expected standards in respect of
anti-bribery and other compliance
topics are set out in our standard
purchasing terms and conditions and
our Code of Conduct and confidential
reporting channels are provided.
You can view key corporate policy
statements on our website.
Find this online
https://www.ocadogroup.com/our-
responsible-business/corporate-
statements/
Materiality:
Ethics of AI and Robotics
As our business increasingly makes
use of AI or robotic systems to support
decision making and deliver tasks, it
is important that we do so in a
responsible way. This means holding
these systems to the same standards
we expect of Ocado employees.
It also helps us prepare for forthcoming
regulation like the EU AI Act.
Bringing together a range of
disciplines – including data,
engineering, product, UX, research,
legal, risk, privacy – resulted in the
following commitments:
When developing and deploying AI &
robotic AI systems at Ocado, we will:
Fairness
– Use high quality & representative
datasets, and mitigate against
unfair bias.
Transparency & Explicability
– Ensure these systems are well-
documented, and that we are able
to demonstrate reliability and track
back issues.
– Provide an easily understandable
explanation of how these systems
work to users.
Governance
– Ensure appropriate accountability
structures are in place before
internal or third party systems
are deployed.
– Regularly monitor systems to
check performance.
Robustness & Safety
– Make privacy and security integral
to design.
– Assess safety considerations and
build in appropriate safeguards.
Impact
– Ensure any interaction with people
(directly or indirectly) is conducted
with respect and empathy.
– Consider the impact of automation
on affected staff, communicate
in an upfront way and provide
opportunities for reskilling
where possible.
Ocado teams will incorporate these
commitments into their ways of
working and take responsibility for
any appropriate actions. A team-
centric approach ensures our
approach is flexible, practical and
proportionate to the risk level of
the project in question.
Our responsibility commitments are
already having an impact on how
we document and explain AI and
Robotics systems. The Technology
team has developed a comprehensive
internal registry of projects to support
better governance. And we’re working
to boost explainability of machine
learning (ML) models, which is business
critical for addressing any adoption
concerns our clients might have.
Materiality:
Product quality
and governance
One of our key responsibilities in
providing OSP is delivering hardware
for clients. Delivering a high quality
product means good platform longevity,
and customer satisfaction, as low cost.
To successfully do this requires
the right practice and organisation
as well as PLM (product lifecycle
management) applications.
PLM applications are used at an
enterprise level, to manage ‘product
defining data’ through the entire
product lifecycle. They act as a central
repository for data shared across the
enterprise – in our case, from Ocado
Technology through to Engineering
Supply Chain (PI) into Engineering
Operations (CS) – and are designed
to allow effective integration into
other tools, to facilitate sharing
and validation of Engineering Data
whilst reducing errors in data sets.
This application improves data quality
across all applications and processes
that drive delivery to clients,
minimising downstream interventions,
which can create service disruption
and additional unplanned costs.
In 2022 we progressed a
more sophisticated PLM strategy,
to significantly reduce downstream
costs of supporting products on site,
leveraging two concepts:
– digital thread which, through
processes and tools used for
communicating data in a connected
way through an asset’s lifecycle,
enable us to recreate the product
at any point in time throughout
it’s life
– digital twin which, is a
representation of the product
virtually at any point in time
For all products where Ocado owns
the IP, we establish the ‘digital thread’
across the lifecycle, connecting
initial business requirements
through design & manufacture to
maintenance, repairs & operational
performance in the field at Client
Sites. In being able to determine
the configuration of any deployed
product at any point during its life
cycle, we can then use the same
functionality to assess possible future
configurations and so accurately
predict impacts. This supports us
to provide leading customer service
across our OSP platform, whilst
eliminating wasted time, effort
and cost re-inventing solutions.
Contents
Contents