
Improving IT Systems and Cyber
Security
The Group implemented a complex
Enterprise Resource Planning ('ERP’)
transformation in February 2023 in the
Matthew Clark and Bibendum (‘MCB’)
business, further aligning and streamlining
our technology infrastructure across
the Group. This is a key step in our
digital transformation and optimisation
of the business which will enable further
automation and simplification of our
business processes.
The implementation of the ERP has taken
longer and has been significantly more
challenging and disruptive than originally
envisaged, with a consequent material
impact on service and profitability within
MCB. Service levels had largely returned
to normal levels by the end of March 2023,
however continuing system implementation
challenges, impacted by greater seasonal
trading volume, saw a deterioration in
service levels in April 2023. An improvement
through May 2023 is being achieved by
investing in material additional cost and
resources, ahead of a system fix being
implemented to restore service to normal
levels permanently. We will undertake a
thorough review of the implementation,
system fixes and mitigation plans to ensure
the Company has the required level of
planning, capability and resilience in its
systems to avoid any reoccurrence in the
future.
We continued to review our information
security and cyber preparedness policies
and procedures and further enhanced
our Information Technology systems
and controls. In the field of information
technology and security, the Company
undertakes a regular security assurance
programme, testing controls, identifying
weaknesses and prioritising remediation
activities where necessary. This includes
periodic best practice specialist security
testing by a leading third-party provider
and regular system scanning to identify
security weaknesses. Issues are assessed
for risk and are comprehensively managed
as part of the Company’s risk management
programme. The Committee is presented
with regular detailed Information
Security Reports by the Technology and
Transformation Director and Group Head
of IT, which includes recommendations for
further reinforcements, and a roadmap for
further risk reduction. As a demonstration of
our commitment to tackling cyber security
we continue to pursue Cyber Essentials
Plus accreditation from the National
Cyber Security Centre (‘NCSC’). Further
reassurance and support was provided
through the results of a third-party cyber
controls assessment, which confirmed that
the direction of the improvement project
was correct, with the results shared with the
Board.
Internal Audit
The Committee is responsible for
monitoring and reviewing the operation and
effectiveness of the Internal Audit function
including its focus, work plan, activities and
resources.
At the beginning of the financial year, the
Committee reviewed and approved the
Internal Audit plan for the year having
considered the principal areas of risk in the
business and the adequacy of staffing levels
and expertise within the function. During
the year, the Committee received regular
verbal and written reports from the Head
of Internal Audit summarising findings from
the work of Internal Audit and the responses
from management to deal with the findings.
The Committee monitors progress on the
implementation of any action plans arising
on significant findings to ensure these are
completed satisfactorily and meets with
the Head of Internal Audit in the absence of
management.
The FY2024 audit plan was designed with
reference to the Group’s principal risks. It
was informed by an assessment of the risk
profile of the different areas of the business
and has considered all existing and
emerging risks, incorporating both elements
where appropriate.
The Committee remains satisfied that the
Internal Audit function has the necessary
resources, objectivity, and competency
to fulfil its mandate. It is also satisfied that
the Internal Audit function has adequate
standing and is free from management
influence or other restrictions.
External Audit
It is the responsibility of the Committee to
monitor the performance, objectivity and
independence of Ernst and Young (‘EY’), the
External Auditor. In December 2022, we met
with EY to agree the audit plan for the year
end, highlighting the key financial statement
and audit risks, to ensure that the audit was
appropriately focused. In addition, EY’s
letter of engagement and independence
was reviewed by the Committee in advance
of the audit.
In May 2023, in advance of the finalisation
of the financial statements, we received a
report from EY on their key audit findings,
which included the key areas of risk and
significant judgements referred to above
and discussed the issues with them for
the Committee to form a judgement on
the financial statements. In addition, we
considered the Letter of Representation
that the External Auditor requires from the
Board.
The Committee meets with the External
Auditor privately at least once a year to
discuss any matters they may wish to raise
without management being present.
Assessment of Effectiveness of
External Audit
During the year, the Committee reviewed
EY’s fees for its services, its effectiveness
and whether the agreed audit plan had
been fulfilled and the reasons for any
variation from the plan. The review included
a formal evaluation process including the
completion of a short questionnaire by
each member of the Committee, the Group
Chief Financial Officer, the Director of Group
Finance and applicable senior finance
personnel across the business.
The Committee also considered the
robustness of the FY2023 audit, the
degree to which EY was able to assess
key accounting and audit judgements and
the content of the audit committee report
issued by the External Auditor. On the
basis of the Committee’s evaluation and
considering the views of other key internal
stakeholders, the Committee concluded
that both the audit and the audit process
were effective, having been carried out in an
independent, professional, organised and
Corporate Governance
Business & Strategy Financial Statements
103