Background
Based on the Group’s approach to managing a sustainable business, its strategic objectives, stakeholder engagement and risk management, the Group has identified material risks or issues that could potentially prevent the business from achieving its objectives. The Group Risk Committee (GRC) is responsible for the overall monitoring, assessing and mitigation of risks within Super Group. In addition, the Group ensures that sufficient insurance cover is purchased to mitigate all the significant risks.
The risk categories
Super Group classifies the risks that have a material impact on the Group into six strategic categories: Strategic, Human Resources, Financial, Operations, Compliance and IT.
The risk categories can be described as follows:
| Risk categories | Overview |
Strategic |
The strategic risk considers the brand and reputation of the Group, the Group’s strategy, initiatives, communication and investor relations. |
Human Resources |
The Human Resources risks are associated with capacity requirements, employment of skills, compensation and benefits as well as the culture of the organisation. |
Financial |
The financial risks pertain to the accounting, tax and reporting structures of the Group. |
Operational |
Operational risks are associated with sales and marketing, customer service, and service delivery to meet our customers’ expectations. |
Compliance |
Compliance risks are those that consider the adherence to and compliance with governance, legal and regulatory issues. |
IT |
IT risks contemplate the application development, availability, security, continuity and the data integrity of the Group’s IT systems. |
The risk identification process
Each division is responsible for identifying, recording and assessing risks that would hinder the division from achieving its objectives. Appropriate control procedures are introduced aimed at mitigating these risks to an acceptable level. The Group Audit and Risk Officer facilitates risk sessions with each division and ensures that the risks identified have been correctly assessed and mitigated. Risks are assessed based on the potential impact on the business, financial position and reputation. A scale of 1 to 5 is used where 1 is “Minor” and 5 “Catastrophic”. Risks are also assessed on the likelihood of the risk occurring after taking into account controls in place to mitigate them. A scale of 1 to 5 is used, where 1 is “Rare” and 5 is “Almost certain”.
The GRC sets out the risk policy in its Charter detailing the objectives, scope, approach and roles and responsibilities of the committee members. The GRC meets twice a year and is chaired by an independent non-executive director. The membership of this committee comprises two non-executive directors, the CEO and CFO. The Group Audit and Risk Officer, the Group Legal Manager and the CIO are invited to the meeting.
The Board reviews the list of strategic and critical risks regularly, as required by King IV™, and approves the risk tolerance of the Group.
Management and mitigation of major risks to the Group

Risk level 2020 |
Risk level 2019 |
Risk |
Context |
Mitigating factors |
|
|
– |
Impact of Covid-19:
|
|
|
|
|
|
Highly competitive local markets, adverse macroeconomic conditions, political turmoil, industry unrest and deteriorating business confidence hinder growth in and place margin pressure on operations. |
|
|
|
|
|
African socio-economic environment, including commodity cycles. |
|
|
|
|
|
The attacks on trucks in South Africa. |
|
|
|
|
|
Changing regulatory environment. |
|
|
|
|
|
Customer concentration. |
|
|
|
|
|
Retention of critical management, succession planning for key personnel, skills development and gender diversity. |
|
|
|
|
|
The long-term effect of Brexit on the UK and Eurozone economies. | Brexit D-Day was 31 October 2019, however, the exact way in which the trade agreements are going to be structured to “divorce” the UK and Eurozone countries, is still uncertain. | Continuing to monitor developments closely. |
|
|
|
The threat of cyber-attacks and data breaches. | The threat of cyber-attacks and data breaches is alarming, and is set to escalate as hackers become more daring and tools more sophisticated. | Continuing to invest heavily in measures to ensure that any future attacks are mitigated. The Group’s cyber-security forum meets monthly to evaluate and discuss new and better ways of combatting this global threat. |
|
|
|
Development in the IT/Technology space in terms of on-line trading, telematics, Internet-of-Things (IoT), Artificial Intelligence (AI) and electric cars. |
|
|