Group-Wide Opportunities and Risk Management System

Conscientious management of risks and opportunities is part of responsible corporate governance and forms the basis for sustainable growth and financial success. This includes the ability to systematically identify and take advantage of opportunities while avoiding risks to the company’s success. The entrepreneurial decisions we make daily in the course of business processes are based on balancing opportunities and risks. We therefore regard the management of our opportunities and risks as an integral part of our business management system rather than as the task of a specific organizational unit.

Opportunities and risk management system

Opportunities and risk management system (graphic)

Our opportunity and risk management begins with strategy and planning processes, from which relevant external and internal opportunities and risks of an economic, ecological or social nature are derived. Opportunities and risks are identified by observing and analyzing trends along with macroeconomic, industry-specific, regional and local developments. The identified opportunities and risks are subsequently evaluated and incorporated into our strategic and operational processes. We attempt to avoid or mitigate risks by taking appropriate countermeasures, or to transfer them to third parties (such as insurers) to the extent possible and economically acceptable. At the same time, we strive to take maximum advantage of opportunities by incorporating them into our entrepreneurial decisions as appropriate. We consciously accept and bear manageable and controllable risks that are in reasonable proportion to the anticipated opportunities. We regard them as the general risks of doing business. Opportunities and risks are continuously monitored using indicators so that, for example, changes in the economic or legal environment can be identified at an early stage and suitable countermeasures can be initiated, if necessary.

To enable the Board of Management and the Supervisory Board to monitor material business risks as legally required, the following systems are in place: an ensuring proper and effective financial reporting pursuant to Section 289, Paragraph 4 and Section 315, Paragraph 4 of the (HGB); a compliance management system; and a risk early warning system pursuant to Section 91, Paragraph 2 of the (AktG).

The various management systems are based on different risk types, risk levels and timelines. Different processes, methods and IT systems are therefore applied to identify, evaluate, manage and monitor risks. The principles underlying the various systems are documented in Group policies that are integrated into our central document control processes and are accessible to all employees via the Covestro intranet. The overall responsibility for the effectiveness and appropriateness of the system as a whole lies with the Chief Financial Officer.

The various systems are described below.

Internal control system for (Group) accounting and financial reporting (Report pursuant to Section 289, Paragraph 4 and Section 315, Paragraph 4 of the German Commercial Code)

The purpose of our internal control system (ICS) is to ensure proper and effective accounting and financial reporting in accordance with Section 289, Paragraph 4 and Section 315, Paragraph 4 of the German Commercial Code.

The ICS is designed to guarantee timely, uniform and accurate accounting for all business processes and transactions based on applicable statutory regulations, accounting and financial reporting standards, and the internal Group regulations that are binding on all consolidated companies.

The concept is based on the Committee of the Sponsoring Organizations of the Treadway Commission (COSO) Internal Control – Integrated Framework (2013) and the Control Objectives for Information and Related Technology (COBIT) framework and addresses the risk of misreporting of the consolidated financial statements. Risks are identified and evaluated, and steps are taken to counter them. Mandatory ICS standards such as system-based and manual reconciliation processes and functional separation have been derived from these frameworks and promulgated throughout the Covestro Group by Group Accounting.

The management of each Covestro Group company holds responsibility for implementing the ICS standards at the local level. Bayer Shared Service Centers continued to handle certain activities in the first half of 2018 on account of several fixed-term transitional agreements in the scope of the carve-out. These services are no longer used, however, and all accounting activities have been handled in-house since May 2018.

The effectiveness of the ICS processes for accounting and financial reporting is evaluated on the basis of a cascaded self-assessment system that starts with the persons directly involved in the processes, then involves the principal responsible managers and ends with the Board of Management. In addition, an external audit is performed to ensure and attest to its proper functioning. An IT system in use throughout the Covestro Group ensures the uniform and audit-proof documentation and transparent presentation of the risks, controls, and effectiveness evaluations associated with all ICS-relevant business processes. It should generally be noted that, however carefully designed, an internal control system cannot provide absolute assurance that material misstatements in the accounting will be avoided or identified in a timely manner.

The Chief Financial Officer of Covestro AG has confirmed the criteria and the effective functioning of the internal control system for accounting and financial reporting for fiscal 2018.

Internal control system to ensure compliance

Compliance risks are systematically identified and assessed as part of Covestro’s Group-wide risk management. Risk owners assess the compliance risks that have been identified. A risk matrix is used to define focal points of compliance tasks at Covestro. The findings of a risk-based analysis enabled Covestro to identify three key topics: antitrust law, corruption, and foreign trade law. The General Counsel /Chief Compliance Officer is the risk owner responsible for the risks of “breaches of antitrust law” and “corruption”; the Export Control Officer is the risk owner of “breaches of foreign trade law.” With respect to corruption, areas including gifts/invitations, contributions/sponsoring and working relationships with certain business partners such as customs officials/sales agents were identified as being especially risk-relevant.

Many controls have been implemented at both the Group-wide and local levels to reduce the number of compliance risks. To the extent possible, we integrate the compliance controls into our internal control system. In the reporting period, the controls aimed at preventing corruption were globally standardized and, where necessary, additional controls were integrated into business processes.

The effectiveness of the compliance controls is evaluated – as are the ICS processes for accounting and financial reporting – on the basis of a cascaded self-assessment system. The results of the effectiveness evaluations are documented in the global system for the ICS processes. In addition, Corporate Audit carries out dedicated compliance checks.

Risk early warning system
(Report pursuant to Section 91, Paragraph 2 of the German Stock Corporation Act)

Covestro implemented a structured process for the early identification of any potentially disadvantageous developments that could have a material impact on the company or endanger its continued existence. This process satisfies the legal requirements regarding an early warning system for risks pursuant to Section 91, Paragraph 2 of the German Stock Corporation Act. Covestro’s risk management process is based on the international risk management standard COSO II Enterprise Risk Management – Integrated Framework (2004). A central unit defines, coordinates, and monitors the framework and standards for this risk early warning system.

Throughout the year, various global subcommittees provide new and updated information about identified risks. The Covestro Corporate Risk Committee meets four times a year to review the risk landscape as well as the various risk management and monitoring mechanisms that are in place, and to take any necessary measures.

Risks are evaluated using estimates of the potential impact, the likelihood of their occurrence and their relevance for our external . All material risks and the respective countermeasures are documented in a company-wide database. The risk early warning system is reviewed regularly over the course of the year. Significant changes must be promptly entered in the database and reported to the Board of Management. In addition, a report on the risk portfolio is submitted to the Audit Committee several times a year and to the Supervisory Board at least once a year. The following matrix illustrates the financial and indirect financial criteria for rating a risk as high, medium or low.

Rating Matrix

Rating Matrix (graphic)

1 An individual risk that could have both a financial and indirect financial impact of different severities and is always classified based on the higher level of risk.

 

 

 

 

 

 

 

Indirect financial impact

Moderate

 

High

 

Significant

 

Critical

Moderate effect on achieving outcome objectives/national reporting

 

High effect on achieving outcome objectives/national reporting

 

Significant effect on achieving outcome objectives/major outlets reporting internationally

 

Critical effect on achieving outcome objectives/major outlets constantly reporting internationally

Process-independent monitoring

The effectiveness of our management systems is audited and evaluated at regular intervals by the Corporate Audit unit, which performs an independent and objective audit function focused on verifying compliance with laws and policies. Corporate Audit also supports the company in achieving its goals by systematically evaluating the efficiency and effectiveness of governance, risk management and control processes, and helping to improve them. The selection of audit targets follows a risk-based approach. Corporate Audit performs its tasks according to internationally recognized standards and delivers reliable audit services. This was confirmed in an external audit conducted in accordance with Auditing Standard 983 of the Institute of Public Auditors in Germany () in fiscal 2017. A report on the internal control system and its effectiveness is presented annually to the Audit Committee of the Supervisory Board.

Risks in the areas of occupational health and safety, plant safety, environmental protection and product quality are assessed through specific (health, safety, environment and quality) audits.

In addition, the external auditor, as part of its audit of the annual financial statements, assesses the basic suitability of the early warning system for identifying at an early stage any risks that could endanger the company’s continued existence so that suitable countermeasures can be taken. The auditor also reports at regular intervals to the Board of Management and the Supervisory Board on the results of the audit and any weaknesses identified in the internal control system. Audit outcomes are also taken into account in the continuous improvement of our management processes.

ICS/internal control system
Internal control system to ensure compliance with directives by means of technical and organizational rules
HGB/German Commercial Code
Comprises much of the German accounting legislation
AktG/German Stock Corporation Act
Regulates the legal provisions pertaining to German stock corporations
ICS/internal control system
Internal control system to ensure compliance with directives by means of technical and organizational rules
Stakeholders
Internal and external interest groups which are directly or indirectly impacted by the company’s corporate activities and/or may be so in the future
IDW/Institut der Wirtschaftsprüfer in Deutschland e.V.
A professional association of German Public Auditors and German Public Audit Firms that represents the interests of its members and supports their work
HSEQ/health, safety, environment, quality
Health, safety, environment and quality