URL: /1024/en/corporate_governance/Internal_Risk_Management_and_Control_Procedures/Internal_Risk_Management_and_Control_Procedures.html
DATE: 2008-07-02T21:09+0200
 

Internal Control and Risk Management Systems

Status: 2007 Registration Document

Overview

One of Management’s fundamental goals is to ensure an effective Internal Control (“IC”) and Risk Management (“RM”) environment at EADS, in accordance with corporate governance requirements and best practices in the Netherlands, France, Germany and Spain. Faced with continuing changes in the multi-jurisdictional legal and regulatory provisions applicable to it, EADS began to implement a coherent, group-wide IC and RM system in 2004. This system is based on the Internal Control and Enterprise Risk Management Frameworks of the Committee of Sponsoring Organisations of the Treadway Commission (“COSO”).

The IC and RM system provides Management with a framework for attempting to manage the uncertainty and associated risks inherent in EADS’ business. It serves as the basis for all sub-IC and sub-RM procedures present throughout EADS at the divisional and Business Unit (“BU”) levels.

Limitations

No matter how well designed, all IC and RM systems have inherent limitations, such as vulnerability to circumvention or management overrides of the controls in place. Consequently, no assurance can be given that EADS’ IC and RM system and procedures are or will be, despite all care and effort, entirely effective.

Developments in 2007 and outlook

During 2007, EADS sought primarily to increase awareness of IC and RM principles at the divisional, BU and Headquarters (“HQ”) level. This included the rollout across several Divisions and BUs of standardised IC and RM training covering basic and refresher concepts. In addition, process coordinators benefited from individual coaching sessions and workshops relating to the performance of yearly IC procedures. Working groups were also established throughout 2007 in order to enhance cross-departmental and cross-organisational knowledge exchange.

During the second half of 2007, most Divisions, BUs and HQ departments conducted a self-assessment of their IC systems to evaluate the design and operational effectiveness of internal controls. The results are currently being analysed. Moreover, independent reviews of the IC & RM systems were performed to substantiate the self-assessment during 2007.

EADS is in the process of reviewing the IC and RM system in place at Airbus in order to further align it with that of the Group as a whole. Pending the completion of this review, Airbus has continued to operate the IC and RM system that was in place prior to BAE Systems’ divestment of its stake in 2006.

Building on the comprehensive IC and RM review and evaluation procedures carried out in 2007, EADS will assess the results over the course of 2008. As a result of the ongoing monitoring activities of the IC and RM systems’ effectiveness, further modifications to the IC and RM systems and integration efforts are expected throughout 2008.

Responsibility for the IC and RM System - Interaction with EADS Management

Overall responsibility for the IC and RM system and the related reporting to stakeholders lies with the Board of Directors. EADS’ Chief Executive Officer and Chief Financial Officer are responsible for ensuring that the IC and RM system and related procedures are implemented throughout the Group. In addition, the Audit Committee oversees the Group-wide functioning of the IC and RM system.

A general management principle at EADS is the delegation of entrepreneurial responsibility and powers to the operational units. This principle of subsidiarity entails a clear separation of responsibilities between EADS Headquarters and the Divisions or BUs. EADS Corporate sets the overall strategic and operational targets for EADS and assumes the ultimate responsibility for the process. The Divisions and BUs retain responsibility for all operational matters and activities within their scope, subject to audit. Consequently, the responsibility for operating and monitoring the IC and RM system and for risk and IC reporting lies with the respective management of the Divisions, BUs and HQ departments. They must seek to ensure transparency and effectiveness of their local sub-IC and RM systems and the adherence to the objectives defined by the Board of Directors. The management of Divisions, BUs and HQ departments is responsible for the implementation of appropriate mitigation activities to reduce the probability and impact of risk exposures and for the communication of risks that affect others within EADS.

In principle, risk and IC management as well as ensuring overall effectiveness of the IC and RM system is the responsibility of all members of the staff. The Group seeks to integrate risk and IC management into all activities when conducting business transactions.

Sources and Standards for IC and RM System and Procedures

The core policies, procedures and thresholds that define EADS’ IC and RM environment are communicated throughout the Group through:

External standards influencing the EADS IC and RM system include the IC and Enterprise Risk Management (ERM) Frameworks of COSO, as well as industry-specific standards as defined by the International Standards Organisation (ISO).