Information Risks, Strengths and Weaknesses Statement and Final Assurance Plan April 2021
Total Page:16
File Type:pdf, Size:1020Kb
Information risks, strengths and weaknesses statement and final assurance plan April 2021 wessexwater.co.uk Contents Introduction 2 1 Background and context 3 2 Our assurance framework 5 3 Process for identifying risks, strengths and weaknesses 8 4 Target areas 10 5 Final assurance plans for target areas 14 6 Next steps 18 Introduction Who we are We are a regional water and 7 sewerage business serving Stroud 2.8 million customers across the Cotswold south west of England including South 5 Gloucestershire Dorset, Somerset, Bristol, most of Bristol Wessex Wiltshire and parts of Water Chippenham North Gloucestershire and Hampshire. Somerset Bath BANES Devizes Our purpose: Weston-super-Mare Trowbridge 2 Wiltshire Sedgemoor Mendip Customers Warminster 6 West Bridgwater To provide our customers and Somerset 1 communities with excellent Salisbury service and value for money Taunton Taunton 4 Yeovil Environment South Somerset North To protect and improve the Dorset East New Forest environment Key West Dorset Dorset 3 1 Wessex Water Employees Dorchester Poole To provide our employees with 2 Bristol Water Christchurch the opportunity for personal 3 Bournemouth Water Purbeck Bournemouth development and a satisfying 4 South West Water Weymouth Weymouth career 5 Thames Water and Portland Investors 6 Cholderton and District Water To provide our investors with a 7 Severn Trent Water fair return for their investment About this document We regularly report and publish data and information about our performance. This data and information comes from a range of systems, assets and processes. This document is part of the framework we use to give our customers trust and confidence that the data and information is reliable, accurate, and complete. It sets out: • our view of the risks, strengths and weaknesses in relation to the information we will report and publish in 2021-22; and • the data assurance processes we will put in place to mitigate any risks or weaknesses. Have your say Please let us know your thoughts. We welcome any comments you may have on this document or our approach to reporting on our performance more generally. Tell us what you think Your feedback is important to us so please get in touch. Email us at: [email protected] 2 1 Background and context We have a well-established assurance framework, which is led by our board. Being honest and ethical in the way we conduct our business is one of our core values. Board statement on accuracy and completeness of data and information For data reported from 2020-21 onwards, Ofwat requires companies to provide a board statement on accuracy and completeness of data and information. This statement must be signed by, or on behalf of, our board, stating that the data and information which the company has provided to Ofwat in the reporting year and/or which we have published in our role as a water company is accurate and complete, and setting out any exceptions. We will also provide a description of the activities which the board has carried out to allow it to make the statement. We will be making this statement in our annual review and this document is one of the activities the board carries out. Our assurance reporting framework We have a well established framework that all water companies in England and Wales have followed for several years. This includes: Element Requirement Risks, strengths and • Carry out an exercise with stakeholders to target issues to be addressed weaknesses • Publish a risks, strengths and weaknesses statement Assurance plans • Publish and consult on draft assurance plans to resolve the issues identified • Publish a final assurance plan We continue to use the same framework to help ensure the data and information we report or publish is accurate. In November 2020 we published a combined risks, strengths and weaknesses statement and draft assurance plan for consultation. This document now finalises our assessment of risks, strengths and weaknesses and our assurance plans in relation to the target areas identified. 3 Document structure The remainder of this document sets out: 2 Our assurance 3 Process for framework identifying risks, strengths and Details of our overall approach to assessing weaknesses and managing business risk and our How we identify risks information to the reliability, assurance processes. accuracy and completeness of the data we will provide to customers and stakeholders. 5 8 4 Target areas 5 Final assurance Progress we have plans made in relation to The actions to the issues we manage or mitigate identified last year the weaknesses and our new target and/or risks in the areas. target areas. 10 14 6 Next steps How to get in touch and let us know your thoughts on this document or our approach to reporting on our performance more generally. 18 4 2 Our assurance framework Risk management Our overall approach to assessing and managing business risk is governed by our business risk assurance map, published here. This is based on three levels of defence. First level of defence Director and Management oversight of Business as Usual risk mitigation measures covered by policies and procedures Second level of defence Functions that oversee or specialise in risk management and/or compliance eg, Risk Management Group, Security Management Group Third level of defence Functions that provide independent assurance e.g. Internal Audit, Audit and Risk Committee We use this process to inform our approach to information assurance so that all our data and information undergoes the appropriate level of defence. Information assurance The following groups and processes are in place as part of our approach to information assurance. Wessex Water Services Limited (WWSL) Board It is the responsibility of the board to ensure the company meets its regulatory and legal obligations. Board ownership is key to providing a strong assurance process. The WWSL board has overall responsibility for the accuracy and completeness of the data and information which we provide or publish in our role as a water company. Audit and Risk Committee The Audit and Risk Committee assists the board in monitoring the company’s obligations in relation to financial reporting, internal control and audit, and compliance and risk management systems. Part of the Committee's role is to review the company's financial statements and Annual review, including the Annual performance report. Customer Challenge Group The Customer Challenge Group is an independent body that plays a key role in representing the interests and needs of Wessex Water's customers. This includes: • monitoring and reporting on Wessex Water's delivery of all aspects of its 2020 to 2025 business plan from the perspective of its customers • providing advice and challenging Wessex Water on any plan to share outperformance with customers over and above the level approved in the business plan • offering advice and challenging the company on policy areas such as customer engagement, customer service, affordability and tariffs. External audit Our external technical auditors (currently Mott MacDonald) provide assurance on our regulatory submissions including our Annual performance report and charges schemes. Our financial auditors (currently EY) audit the financial statements and Annual report and accounts. We also gain additional specialist advice where needed. Internal audit Internal audit provides assurance to the board and the Audit and Risk Committee about the adequacy and effectiveness of internal controls. The team delivers a flexible, risk-based programme of audits, which are reported to the Audit and Risk Committee. Information risk register Strategic We identify risks at a strategic, tactical and operational level. These risks are monitored in risk registers at each level. We maintain an information risk register, which details the Tactical likelihood and impact of the data and information we report and/or publish being misreported. This covers five areas: Operational • regulatory submissions and publications (Ofwat) 5 • financial statements • other regulatory reporting (EA, DWI, CCW) • information to promote competition and markets • communication or information provided direct to customers. Regulatory Assurance Manual We maintain a regulatory assurance manual to help ensure we provide the appropriate level of assurance to the information we report and publish. The manual includes details of the Annual performance report certification process and the confidence grades we used to assess the reliability and accuracy of the reporting of our performance commitments. iComply Our company certification process (iComply) requires employees to confirm awareness of, and compliance with, the company’s rules, policies and procedures, including around data reporting where relevant to their role. The results are reported to the Audit and Risk Committee. Annual performance report certification process We also have a certification process to manage and assure the data reported as part of the Annual performance report. We use a SharePoint workflow for this with roles defined in our Regulatory assurance manual. The workflow includes the external audit by our technical and financial auditors. The flow of data is illustrated below and, at each stage, colleagues are required to confirm they have followed our assurance process. Originator Compiler Owner External audit Reviewer Confidence grades We use the Ofwat confidence grades to assess the reliability and accuracy of the reporting of our performance commitments. The reliability is assessed