Strategic risk management
Risk management at Datatec is not viewed as a task that is performed in isolation. It is part of the day-to-day practices and staff at all levels are familiar with Datatec's risk policy. The Board is responsible for Datatec's strategy, leadership and decision-making which are all impacted by risk. Risk-based leadership is therefore fundamental to Datatec.
Board
- The Board determines the level of risk tolerance and limits of risk appetite are set as part of the strategic direction of the Group
- The Board is ultimately responsible for the governance of risk
ARCC
- Monitors risk management activities at the Group and subsidiary level on an ongoing basis
Group Chief Risk Officer
- Ensures that the risk management framework is operating effectively in the divisions
- Chairs bi-annual inter-divisional risk forum
Divisions – divisional boards and executive committees
- Regularly review strategic and emerging risks and identify and prioritise high-risk areas on risk maps based on impact and likelihood
- Analyse high-risk areas to identify potential root causes
- Identify mitigating controls and associated monitoring/ assurance activities for each high-risk area
Divisional chief risk officers
- Ensure divisional risk procedures are in accordance with and support the Group's risk management framework
- Oversee management's response to matters identified as requiring improvement
The Board is responsible for approving Datatec's risk appetite and when the risk tolerance is exceeded, it is management's responsibility to take action.
Datatec's aim is for the risk register to be a management tool driving the following two critical areas:
- Business-driven goals via strategic planning
- Compliance-driven goals via risk managers and internal audit
Risk-based leadership with the Board at its apex is fundamental to Datatec's approach to its operations. In line with the King IV Code, the Board governs risk in a way that supports the organisation in setting and achieving its strategic objectives.
Our risk management process
The Group's risk management process has three key steps:
0 1
0 2
0 3
How do we identify risks?
Our risks are identified as threats that can impact the Group's ability to deliver its objectives and its strategy. Our risks are regularly reviewed in the context of our operating environment.
How do we respond to our risks?
Our risks are assessed and prioritised. The relationship between the impact and likelihood of risks is recorded in risk registers. Key risk responses are identified and reviewed to ensure that our process continually improves and evolves.
Risk oversight
RISK MANAGEMENT FRAMEWORK
ORGANISATION
Datatec Board
POLICY AND PROCEDURES
Risk policy
Risk management procedures
DELIVERABLES
Risk registers
Risk mapss
Assurance plans
ASSURANCE AND GUIDANCE
Internal audit
Organisation
Policy and procedures
Deliverables
Assurance and guidance
Our key risks
- Supply chain
- Technological market disruption
- Dependence on key vendors
- Internal technological risks – cyber security
- Risk of failure to fund working capital needs sufficiently
- Risk of overdependence on key personnel
As an ICT group with operations and activities across both established and emerging markets, we face challenging risks as well as numerous opportunities. The strategic objectives affected by each key risk are illustrated using our strategic objectives icons.
Datatec Group
| Key risk | Our strategic response | ||||
Supply chain
|
|||||
| At the start of FY23, the supply chain situation was problematic with various factors, including the war in Ukraine, Covid-19 lockdowns in China and global inflationary pressures, which impacted freight costs, disrupting the supply chain. During the year, this disruption was seen to ease with signs of improvement noted. However, the supply chain remains a key risk area for all the Group's businesses. |
|
||||
Technological market disruption
|
|||||
| The Group's operations focus on the higher value, faster growing products and services in the ICT supply chain. It is essential to anticipate the impact of the rapid technological change which is a feature of the sector. |
|
||||
Dependence on key vendors
|
|||||
| The Group is dependent on certain vendors, particularly Cisco, whose products and services accounted for a significant proportion of the Group's revenue. If any one of the Group's principal vendors terminates, fails to renew or adversely changes its agreement or arrangements with the Group materially, it could significantly reduce the Group's revenue and operating profit and thereby seriously harm the Group's business, financial condition and results of operations. |
|
||||
Internal technological risks – cyber security
|
|||||
| The Group's internal systems are at risk, both from planned changes leading to business interruption and disruption by external "cyber" threats. The Group continued to face the threat of financial crime attempted by "phishing" emails and "social engineering". The Group has high dependence on its key information systems. |
|
||||
Risk of failure to fund working capital needs sufficiently
|
|||||
| The Group's business is working capital intensive; this is particularly relevant for Westcon International. Westcon International's financing facilities are utilised to finance accounts receivable and inventories. The availability of these facilities and any material changes thereto may affect the business's ability to fund its working capital requirements. |
|
||||
Risk of overdependence on key personnel
|
|||||
| The Group's future success depends largely on the continued employment of its executive directors, senior management and key sales, technical and marketing personnel. Certain key employees have relationships with principal vendors and customers which are particularly important to the business of the Group. The executive directors, senior management team and key technical personnel would be difficult to replace and the loss of any of these key employees could harm the business and prospects of the Group. |
|
Westcon International
Impact of global semiconductor shortages
Response:
Implement advanced ordering and increase safety stock of critical stock-keeping units. Additional focus on non-device-based solutions.
Global supply chain disruption
Response:
Constantly monitor supply routes and options. Additional focus on non-device-based solutions.
Liquidity and financing – availability of working capital funding
Response:
Regularly monitor funding availability, sales and collection forecasts; and engage in regular communication with providers of funding. Primary European facility term secured through September 2026.
Inventory management – fast moving high obsolete inventory resulting in excessive write-offs
Response:
Ensure stringent inventory management controls and monthly inventory reviews; and include stock rotation rights in vendor contracts.
Foreign exchange – impact of fluctuations on results and management of exposures
Response:
Ensure that Westcon International is appropriately hedged.
Macroeconomic environment
Response:
Conduct thorough market analyses and monitor macroeconomic factors in all key markets.
Failure to manage payment discounts, product rebates and allowances
Response:
Oversight over prompt payment discounts, product rebates, allowances and vendor-based programmes. Monitor growth and actively manage growth in strategic areas. Maintain strong and transparent relationships with vendor partners.
Dependence on key vendors
Response:
Maintain strong and transparent relationships.
Cyber security threats
Response:
Threat prevention and detection policies, tools and procedures are continuously being enhanced. Threats are actively monitored and addressed. Disaster recovery and business continuity plans are formally documented, reviewed and tested. Phishing campaigns and mandatory security awareness training are conducted regularly throughout Westcon International.
Logicalis International
Supplier delivery delays
During FY23, Logicalis International has continued to see lead times remain at longer levels than historic norms for many vendors, including Cisco, presenting a challenge to its operations.
Response:
Logicalis International continues to collaborate with vendors and put in place mitigation actions until the situation normalises.
Customers moving to public cloud as part of hybrid cloud strategies
Response:
Build skills and capability in public cloud as well as enhance relationships with major providers. Logicalis International continues to make efforts to standardise the core components of its global lifecycle solutions across key markets, making them more scalable.
Dependence on key vendors
Response:
Logicalis International will continue its programme of diversification of vendor portfolio to reduce reliance on any one specific vendor and maintain strong and transparent relationships with them.
Liquidity management
Response:
Focus on optimising Logicalis International for the current environment which will include cost and liquidity management. Logicalis International will continue to assess its ongoing funding requirements as trading conditions change in future and growth opportunities arise, but it is envisaged that the credit capacity currently used across Logicalis International remains adequate for the short to medium term.
Macroeconomic environment
Response:
Conduct thorough market analyses and monitor the macroeconomic factors in volatile markets.
Cyber security threats
Response:
Threat prevention and detection policies, tools, procedures, and internal controls are continuously being enhanced and audited. Threats are actively monitored and addressed. Disaster recovery, business continuity plans, and incident response are formally documented, reviewed and tested. Phishing campaigns and mandatory security awareness training are conducted regularly.
Retention and acquisition of talent
Response:
Logicalis International continues to review its tools (career bands and performance management, engagement scores, employee value proposition) to ensure it remains attractive in the market.
Logicalis Latin America
Supplier delivery delays
During FY23, Logicalis Latin America has seen delays in delivery times by Cisco and other vendors, presenting a challenge to its operations.
Response:
Logicalis Latin America will continue collaborating with vendors and implementing mitigation actions until the situation normalises.
Customers moving to the public cloud as part of hybrid cloud strategies
Response:
Build skills and capability in the public cloud and enhance relationships with major providers.
Dependence on key vendors
Response:
Logicalis Latin America will continue its programme of diversification of vendor portfolio to reduce reliance on any one specific vendor and maintain strong and transparent relationships with all of them.
Liquidity management
Response:
Focus on optimising Logicalis Latin America for the current environment, including cost and liquidity management. Logicalis Latin America will continue to assess its ongoing funding requirements as trading conditions change in the future and growth opportunities arise. However, it is envisaged that the credit capacity currently used across Logicalis Latin America remains adequate for the short to medium term.
Macroeconomic environment
Response:
Conduct thorough market analyses and monitor the macroeconomic factors in volatile markets, including the impact of inflation and hyperinflation.
Cyber security threats
Response:
Threat prevention and detection policies, tools, procedures, and internal controls are continuously being enhanced and audited. Threats are actively monitored and addressed. Disaster recovery, business continuity plans, and incident response are formally documented, reviewed and tested. Phishing campaigns and mandatory security awareness training are conducted regularly.
Retention and acquisition of talent
Response:
Logicalis Latin America continues to monitor its HR departments and tools (career bands, performance management, and survey platforms) to ensure it remains attractive in the market.
Downloads
Glossary




