• No results found

Key features of the Group’s risk management programme

The Group’s risk management programme forms a core part of the Company’s overall framework for managing risks and maintaining internal control. It includes:

• Ownership of the programme by the Board, supported by the Group Company Secretary and General Counsel with sponsorship from the Group Chief Financial Officer; • An appointed Group Head of Risk to lead and continually

improve risk management;

• A network of Risk Directors across the Group to develop risk management in their businesses;

• A Group Risk Management policy, applicable throughout the Group and reviewed annually;

• A standard set of risk categories and risk definitions; • A standardised and automated risk assessment and

reporting tool, including standard risk assessment criteria, evaluation of “gross” and “net” risks and the determination of risk appetite by setting a “target” score for each major risk; • Consolidation of risk assessments for each business at

Group level to identify organisation-wide impacts and trends; • A six-monthly risk assessment, action planning and

reporting cycle, including the review by senior

management, the Audit Committee and the Board of key risks and their mitigation;

• Reporting by the chairman of the Audit Committee to the Board on any matters which have arisen from the Committee’s review of the way in which the risk management and internal control processes have been applied and on any breakdowns in, or exceptions to, these processes; and

• Periodic reviews of business units’ risk mitigation by the Group Head of Risk and by Group Internal Audit. During the year, this programme was further strengthened through a number of initiatives, including:

• Risk appetite definition updated and cascaded by means of revised risk assessment and escalation scales; • A global Wolseley risk management conference, bringing

together risk specialists from across the Group to share ideas and best practices;

• Launch of an updated and improved risk assessment tool, reflecting improvements requested by business units; • Updated risk management policy;

• The development of a more integrated approach to Governance, Risk Management and Control within the IT function; and

• The ongoing development of key risk indicators to support qualitative assessments of the top risks affecting the Group.

Significant risks to the Company’s performance

The nature of the industry in which we operate and our chosen strategy expose the Company to a number of risks. Listed on pages 41 to 43 are risks which senior management have identified as the most significant, which have action plans for their mitigation and which are subject to regular review. The colouring (red, amber, green) shows the Company’s estimate of the inherent risk level before any mitigation. It should be noted that these risks are difficult to estimate with accuracy. The materialisation of these risks could have an adverse effect on the Group’s results or financial condition. Various mitigation strategies are employed to reduce these inherent risks to an acceptable level. The Company also faces many other risks which, although important and subject to regular review, have been assessed as less significant and are not listed here. This includes some risks (such as the impact of restructuring activity or product price volatility), which were reported in last year’s Annual Report and which through changes in external factors and careful management are no longer material to the Group as a whole.

However, many risk factors remain beyond the direct control of the Company and the risk management programme can only provide reasonable but not absolute assurance that key risks are managed to an acceptable level.

Find out more about Wolseley’s risk management and internal control activities in this section and elsewhere in the Annual Report:

Financial risk management: see page 37 in the Financial review and pages 114 and 115 in the notes to the consolidated financial statements

– Provisions: (see notes to the consolidated financial statements page 116).

– Contingent liabilities: (see notes to the consolidated financial statements page 127 and page 150 in the Company financial statements).

– Provisions for self insured risks (see page 93). – Derivative financial instruments (see page 110). Key risks (see pages 41 to 43).

The Board and its Committees – see the “Corporate governance” section on pages 56 to 70, including the Report from the Audit Committee: see pages 69 and 70.

Inherent risk

and trend Definition Mitigation

Market conditions

Inherent risk level: high Increased risk

The Group’s results depend on the levels of activity in the new construction and property repair and remodelling markets. In light of the debt levels in Europe and concerns about economic recovery in the US, there continues to be a risk that markets may fluctuate rapidly or experience a second downturn. Factors influencing this risk include: • the general rate of GDP growth;

• consumer confidence;

• the availability of credit to finance customer investment; • mortgage and other interest rates;

• the level of government initiatives to stimulate economic activity;

• inflation; and • unemployment.

These factors are out of the Group’s control and are difficult to forecast.

The majority of underperforming businesses have been identified through the resource allocation process and have been turned around or are being exited. This has made the Company intrinsically better placed to withstand a second downturn.

A more conservative approach has been taken to the balance sheet. Adjusted net debt has been reduced, new financing facilities have been arranged and there are tighter controls on capital expenditure.

Market conditions are considered in detail during the Strategic Planning process, which includes forecasting and budgeting relating to the current economic climate. Performance is constantly monitored through reviews with each business. Internal visibility of monthly business performance is being enhanced. Most businesses have now completed organisational structure changes, which have created defined business groups with clear cost accountability. Cost reduction and pricing initiatives continue to be developed where possible, and there is greater knowledge sharing on these topics across the businesses. Competitive pressures and margin erosion

Inherent risk level: high Increased risk

Current market conditions have further increased competition during the period under review which, if not mitigated, could lead to downward pressure on sales prices and profit margins.

There is a risk that such competitive pressures will continue and could be exacerbated by factors such as levels of economic activity, customer or vendor consolidation, manufacturers shipping directly to customers, other changes in the route to market, and changes in technology.

Gross margin improvement initiatives are a strategic priority for all Wolseley businesses. All businesses are focused on continuous improvement in customer service, product availability and product mix. Examples of recent initiatives include:

• Improvements in the visibility of gross margin across the Group through the use of Hyperion HFM software, which went live in October 2010;

• Knowledge sharing webcasts on pricing for the Company’s senior staff, sponsored by the CEO. For example, webcasts on the use of dynamic pricing and pricing matrices by Wolseley UK and DT Group;

• In the US, there is greater emphasis on the development of counters, showrooms, E-commerce and private label sales. Matrix pricing efforts are contributing to greater consistency; • In Canada, a major training programme for branch

managers and counter/showroom staff was launched; • Wolseley France continues to focus on the optimisation of

product mix and customer mix and undertakes regular reviews of its pricing and discount matrix systems. It has also implemented pricing projects and negotiated improved purchasing terms and conditions; and

• In Central Europe, terms have been renegotiated with unprofitable or low margin customers.

Litigation

Inherent risk level: medium Increased risk

The international nature of Wolseley’s operations exposes it to the potential for litigation from third parties, and such exposure is considered to be greater in the US than in Europe. Litigation can arise in such areas as workers’ compensation, general employer liability, product liability and environmental and asbestos litigation.

There is a risk that the number of claims made against the Company may increase as a result of the changes in economic conditions, changes in purchasing practices or other factors. For example, an increase in the number of own label products offered by the Group may result in a greater risk of product warranty claims.

Although the number of claims made against the Company has increased during the year as an expected consequence of the environment in which it has operated, there has been no material change in the level of litigation in which the Group is involved. For more information on specific litigation to which the Company is exposed, see pages 93 and 116.

Levels of litigation are monitored by individual operating companies and by Group functions. A comprehensive liability insurance programme is maintained and insurance policy terms, conditions and limits were reviewed at the start of the last financial year.

The Company is closely monitoring ongoing product litigation relating to historical operations in the US and has recently resolved a number of employment practice complaints in that country. HR and product quality assurance procedures will be kept under regular review as the Company works through current turbulent market conditions and expands its private label range of products. In the case of claims related to exposure to asbestos, Wolseley employs independent professional advisers to actuarially determine its potential gross liability. Wolseley has insurance which significantly exceeds the current estimated liability relating to asbestos claims. For more information on the Company’s exposure to asbestos-related litigation, see pages 93, 109 and 116.

Risk management and internal control continued

Inherent risk

and trend Definition Mitigation

People

Inherent risk level: medium No change

Wolseley’s ability to provide leadership and products and services to customers depends on retaining sufficiently qualified, experienced and motivated personnel. In order to increase productivity, and be able to take growth opportunities when markets improve, Wolseley must maintain the skills and experience of its existing management and continue to develop the managers of the future.

The current difficult conditions experienced in certain markets, and the Group’s response to them, have resulted in somewhat increased staff turnover and may demotivate remaining staff.

The Company will continue to closely monitor staff turnover across all grades in all businesses. Retention data relating to the top 100–150 staff receives particular attention. Reward packages are being comprehensively reviewed and updated where necessary. A set of core values for the Group has been defined and communicated, and a new programme of employee engagement surveys has been launched. Quarterly talent reviews across all businesses seek to identify high performing staff with potential. Clear succession plans have been developed and are reviewed every six months by the Executive Committee and the Board. There is greater career planning for counter and other front line staff and a greater focus on effective performance management and appraisals at half year and year end.

Specific examples of counter-measures applied by business units include a greater use of market salary benchmarks in Canada, a review of the pay and benefits structure in the UK, enhanced communications on career development in France, reinstatement of 401k pension contributions in the US and improved succession planning in the Nordic region. Operational resilience

Inherent risk level: medium No change

The Group can only carry on business as long as it has the people, the information technology and the physical infrastructure to do so. The safe and continued operation of these resources is threatened by natural and man-made perils and is affected by the level of investment available to improve them. For example,

• some of the Company’s physical assets are located in areas exposed to natural catastrophe risks; • the Group remains reliant on a variety of different

technology systems across the Group, some of which have been operating for many years;

• to optimise costs and supply chain efficiency, some companies within the Group have also centralised their distribution network and are therefore reliant on a smaller number of larger distribution centres; and

• the level and sophistication of IT security threats is constantly evolving.

Core IT systems and data centres for DT Group, Ferguson, Wolseley France, and Wolseley UK have documented plans which are tested regularly. An annual testing schedule of these plans is agreed by Group IT. Some businesses, such as Wolseley UK, have disaster recovery contracts with a third party to relocate to a back up facility. Options are being reviewed to further improve levels of resilience in Europe. In North America, proposals are being considered to accelerate the relocation of existing systems to a higher security facility in Cincinnati.

The Company operates an IT governance framework including dedicated IT security policies. Specific operational controls for IT security include intrusion detection, penetration testing, wireless remediation of issues, log and configuration management and in-flight projects to reduce the likelihood of an incident. Future plans include an intrusion prevention project and improvements in the monitoring of compliance with existing IT policies. A review of “e-data” risks and opportunities, focusing on data protection issues, is planned.

The loss of a physical site is naturally hedged by the diversified nature of our locations, customers and suppliers. The Company has formally documented and tested plans for those distribution centres, head office buildings and data centres where the risk exposure is deemed to be greatest. Some of these were successfully put into action following natural catastrophe incidents in the US (see case study on page 23). A comprehensive insurance programme is purchased, including coverage for property damage, business interruption and “cyber” risks. A reassessment of the Company’s business interruption risks has led to a reduction in the level of coverage purchased.

Inherent risk

and trend Definition Mitigation

Capital expenditure and return on investment

Inherent risk level: medium/ low

Increased risk

A core element of the Company’s strategy is a focus on organic growth with “bolt-on” acquisitions only where significant benefits and synergies are available. In light of this strategy, the ability of the Company’s management to control organic capital expenditure and to identify, value and integrate any such acquisitions can have a significant impact on the return on investment obtained by investors in the Company.

The Company’s resource allocation process targets future capital allocation to those businesses capable of generating the highest return on investment. Capital expenditure approval limits were lowered in 2009 and all acquisitions irrespective of size require approval from the Group CEO and CFO. Both have been actively involved in reviewing recent acquisitions. Since the last year end report in August 2010, the Company’s capital expenditure and disposals policy has been updated (October 2010) and going forward this will include guidance on expected M&A practices, a standard financial model and narrative requirements. Governmental regulations, including anti-trust and bribery laws

Inherent risk level: medium/ low

No change

The Group’s operations are affected by various statutes, regulations and laws in the countries and markets in which it operates. The amount of such regulation and the penalties can change.

While the Group is not engaged in a highly regulated industry, it is subject to the laws governing businesses generally, including laws relating to competition, international trade, corruption and fraud, land usage, zoning, the environment, health and safety, transportation, labour and employment practices (including pensions), data protection, payment terms and other matters. In addition, building codes or particular tax treatments may affect the products Wolseley’s customers are allowed to use and, consequently, changes in these may affect the saleability of some Wolseley products.

The Group monitors regulations across its markets to ensure that the effects of changes are minimised and that compliance with all applicable regulation is continually sought. During the course of the year, a number of initiatives have been undertaken to respond to new or updated laws and regulations. These include, for instance, the launch in August 2010 of an updated compliance programme for the prevention of fraud, bribery and corruption. The Company reviewed its policies against the guidance raised by the UK Ministry of Justice regarding compliance with the UK Bribery Act, which came into force in July 2011. The Company continued to deploy online competition law training throughout Wolseley’s European operations.

Liquidity and funding risks

Inherent risk level: medium/ low

Decreased risk

Wolseley’s current bank facilities include a covenant that its net debt should not exceed 3.5 times its annualised earnings before interest, taxes, depreciation and amortisation (“EBITDA”). A breach of this covenant could result in a significant proportion of the Group’s borrowings becoming payable immediately.

There is a risk that the Group might have to take actions to reduce costs or preserve cash that it would not otherwise have chosen to do, or that it might not have the resources to exploit opportunities it would otherwise have pursued. There are also risks relating to the Company’s ability to maintain sufficient working capital, for example, increases in bad debt.

The Company’s liquidity position has strengthened through the successful syndication of two five-and-a-quarter-year revolving credit facilities totalling £822 million. Reduction of the Group’s adjusted net debt from £1,195 million (31 July 2010) to £705 million (31 July 2010) provides greater financial flexibility. The Group’s committed facilities currently provide significant headroom. The Group purchases insurance to protect itself against trade credit risks and seeks to ensure no special payment terms are agreed. The Company is monitoring plans for the implementation of the EU Late Payment Directive into the domestic laws of EU member states, but has no specific mitigation in place at present given the uncertainty regarding implementation. Due to the low risk levels, further mitigation is not planned beyond the continued monthly monitoring and re- forecasting activity.

Further information can be found in the Financial review section on pages 34 to 37.