
Acea for World Energy Saving Day
An essential element of Acea’s Corporate Governance, the Internal Control And Risk Management System (ICRMS) makes it possible to identify, measure, manage and monitor the main risks pertaining to the business. The ICRMS takes into account the recommendations of the Corporate Governance Code and is based on national and international best practices, in particular the CoSO Internal Control model and CoSO Framework, issued by the Committee of Sponsoring Organisations of the Treadway Commission.
The "Internal Control and Risk Management System Guidelines " (Italian version), which describe the system, were revised in 2019 and were approved by the Board of Directors in January 2020.
The formulation of an appropriate ICRMS enables:
The ICRMS guidelines, which are applicable to all the group’s companies, aim to:
Risk management in the Acea Group is a structured, continual process, created in order to assess and handle using integrated logic the risks of the entire organisation, according to the risk appetite expressed, with a view to ensuring that management is provided with the information necessary to take the most appropriate decisions for the achievement of strategic and business objectives and for the protection, enhancement and creation of business value.
The ICRMS is based on the following principles:
BoD
Determines the SCIGR guidelines so as to ensure that the main risks for Acea and its subsidiaries are identified, measured and managed
CHIEF EXECUTIVE OFFICER
Implements the ICRMS guidelines and, also utilising the Audit and Risk Management, Compliance & Sustainability Departments, ensures identification of the main corporate risks and periodically brings them to the attention of the BoD.
INTERNAL BOARD COMMITTEES
Ensure an adequate advisory, proactive and instruction activity to support assessments and decisions on the part of the Board of Directors in connection with the ICRMS
BOARD OF STATUTORY AUDITORS
Monitors the legislative and procedural compliance and correctness on the part of administration.
COMPANY STAFF
Intervenes with varying responsibilities, from management to employees, to maintain an efficient process of risk identification and management, operating in observance of procedures and performing line control activities
MANAGER RESPONSIBLE FOR PREPARING THE COMPANY’S FINANCIAL REPORTS
Responsible for setting up and maintaining the Financial Information Internal Control System.
RISK MANAGEMENT, COMPLIANCE & SUSTAINABILITY - ERM
Defines the methodology for risk evaluation and prioritisation and coordinates management of the periodical Risk Assessment procedure.
SUPERVISORY BODY
Responsible, with powers of initiative and intervention, for the functioning of the Organisational, Management and Control model (MOG 231)
SPECIFIC CONTROL BODIES
These include, for example, the DPO (Data Protection Officer), responsible for monitoring the business organisation’s compliance with Regulation (EU) 2016/679; the Anti-corruption Manager, responsible for coordinating, developing and maintaining the corruption prevention Framework and management system; the Antitrust Contact Person, responsible for the planning, implementation and monitoring of the Antitrust Compliance Programme
INTERNAL AUDIT
Carries out independent audits on the operations and suitability of the IARMS, using a risk based audit plan approved by the BoD, and monitors execution of the action plans issued following the audits performed
Function Risk Management, Compliance & Sustainability
Key missions:
Manager Responsible
The Manager Responsible for preparing the company’s financial reports (the "Manager Responsible") pursuant to Italian Law 265/05 is in charge of setting up and maintaining the system of internal control financial ireporting and issuing an appropriate certification together with the Chief Executive Officer. The system of internal control over financial reporting is subject to a specific Regulation approved by the Board of Directors and supported by the Management and Control Model in accordance with Law 262/05.
Risk management is a cross-cutting process, widespread responsibilities that involve all company levels.
Conducted by those
responsible for the
operating activities where the risk lies.
First level controls are intended to ensure business processes are correctly carried out in order to prevent risks via appropriate mitigation actions.
Conducted by corporate
structures, with the aim of ensuring that the first level, checks are
adequate and operational
Second level controls comprise ongoing monitoring to assess the effectiveness of controls defined for the performance of business operations.
Independent checks
conducted by the Audit
function to verify the adequacy and operation of the SCIGR
Third level controls are entrusted to the Internal Audit Department and consist of independent assessments regarding the design and running of the internal control system and the monitoring of improvement plans defined management.
Whistleblowing
Acea has set up a specific procedure for receiving, analysing and processing reports of alleged violations.
Discover the latest news and initiatives of the Acea Group
Acea for World Energy Saving Day
Visit the virtual museum about the history of the Acea Group
The channel for the commercial requests on land urbanisation
Acea turns the spotlight on the Rome Film Festival 2023
Acea is in the "Gold class" in the .trust research
Read more about our culture of inclusiveness