Only a third (32%) of FTSE 100 companies are providing ‘tangible’ metrics on risks or their mitigation within the strategic report, according to the Chartered Institute of Internal Auditors (CIIA)
The measures missing from the report included the placing of specific values on debt and credit risk, IT risks and service levels across IT systems, and information on the amount invested and number of staff placed in training targeting the mitigation of particular risks or issues.
It also found that 52% of FTSE 100 companies failed to provide any qualitative information on the changes to risks year-on-year. They failed to state whether risks outlined were new, removed or had been upgraded or downgraded.
Institute chief executive Dr Ian Peters said: ‘A clear picture on risk is central to a full understanding of a company’s position, the quality of its earnings and potential long-term outlook. It is therefore imperative that the company has rigorous measures to assess risk and that these are reported.’
The Companies Act 2006 requires large listed companies to include a strategic report within their annual report as of September 2013. Information provided should include financial and non-financial key performance indicators (KPIs) ‘to the extent necessary for an understanding of the development, performance or position of the company's business’.
Dr Peters said: ‘The strategic report should allow for full review of risk and mitigation strategies. Simply outlining or describing risks faced is not enough – but this is what the majority of companies currently limit themselves to.
‘Full transparency means placing a tangible measure or value on the risk and providing meaningful detail on what it means for the business.’
Report by Kevin Reed