Maxis Berhad | Annual Report 2013
64 Maxis Berhad | Annual Report 2013 2. Audit Committee (continued) The Audit Committee also reviews and reports to the Board the engagement and independence of the external auditors and their audit plan, nature, approach, scope and other examinations of the external audit matters. It also reviews the effectiveness of the internal audit function which is further described in the following section on Internal Audit. The Audit Committee continues to meet regularly and has full and unimpeded access to the internal and external auditors and all employees of the Group. The Chairman of the Audit Committee provides the Board with reports on all meetings of the Audit Committee. Further details of the activities undertaken by the Audit Committee are set out in the Audit Committee Report on pages 59 to 61. 3. Internal Audit The Internal Audit department continues to independently, objectively and regularly review key processes, check compliance with policies/procedures, evaluate the adequacy and effectiveness of internal control, risk management and governance processes established by Management and/or the Board within the Group. It highlights significant findings and corrective measures in respect of any non-compliance to Senior Management and the Audit Committee on a timely basis. Its work practices are governed by the Internal Audit Charter, which is subject to revision on an annual basis. The annual audit plan, established primarily on a risk-based approach, is reviewed and approved by the Audit Committee annually and an update is given to the Audit Committee every quarter. The Audit Committee oversees the Internal Audit department’s function, its independence, scope of work and resources. The Internal Audit department also maintains a quality assurance and improvement programme and continuously monitors its overall effectiveness through internal self-assessment and independent external assessment. The Internal Audit function meets the requirements of the latest International Standards for the Professional Practice of Internal Auditing of the Institute of Internal Auditors Inc. Further activities of the Internal Audit function are set out in the Audit Committee Report on pages 59 to 61. 4. Code of Business Practice The Group is committed to conducting business fairly, impartially and ethically and in full compliance with all laws and regulations. To this end, there are two detailed Maxis Code of Business Practices (“the Code”); one for Directors and employees and another for third parties, which stipulate how Directors and employees as well as external parties such as vendors, dealers and business partners should conduct themselves in all business matters. All Directors and employees are required to declare that they are in compliance with the Code upon joining the Group and on an annual basis. External parties such as vendors, dealers and business partners who conduct business with the Group are required to sign a declaration that they have read and will adhere to the contents of the Code. To support the implementation and effectiveness of the Code, there is an established Office of Business Practice to provide policy guidance and to facilitate compliance. The Office of Business Practice will continuously look at ways to enhance the Group’s highest standards of business conduct and ethics, and to benchmark these against best practices. In addition, there is also an Ethics Hotline, which serves as a safe and effective channel to allow employees or parties dealing with us to report any observed behavioural inconsistencies which are not in accordance with the general standards and business ethics. 5. Revenue Assurance The Revenue Assurance department is responsible for the continuous monitoring of potential revenue leakage that may arise from day-to-day operations. Processes and controls within the revenue cycle are reviewed on a rotational basis to ensure they function effectively and efficiently. This includes performance and examination of regular test calls, reconciliations of chargeable transactions from network and IT systems to the billing systems and independent rating of key services via automated tools. These findings and corresponding actions taken are reported to the Management on a quarterly basis. Key issues on identified revenue leakages and mitigation action taken are reported to the Audit Committee on a half-yearly basis. The Revenue Assurance department meets key stakeholders on an ongoing basis to address key revenue assurance issues and drive revenue assurance initiatives across the Group. 6. Subscriber Fraud Management The Subscriber Fraud Management (“SFM”) function complements the Revenue Assurance function. While the Revenue Assurance function reviews controls within the revenue cycle as indicated above, the SFM function monitors daily subscriber calls on a near real-time basis. Appropriate actions are taken immediately for suspected fraudulent calls, using an industry developed system to monitor call patterns on a 24/7 basis throughout the financial year and other manual reporting investigations. It also reviews key new services and products for possible fraud risk and recommends counter-measures. Fraud findings with remedial actions taken are reported on a monthly basis to Management and presented half-yearly to the Audit Committee. STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL Continued
Made with FlippingBook
RkJQdWJsaXNoZXIy ODU0MjU5