Risks relating to the execution of a client contract: poor service delivery, non-fulfilment of contractual and performance obligations, over delivery of additional services not defined in the contract, poor management of food and labor costs.
Poor service delivery to clients or non-fulfilment of contract obligations could lead to client dissatisfaction, possible contractual penalties and ultimately the loss of the client.
Over-delivery of additional services not defined in the contracts and without related invoicing could lead to a shortfall in revenues and loss of profitability on the contract.
Poor management of food and labor costs could result in reduced profitability on the contract.
In addition, the outbreak of the Covid-19 pandemic has led to significant variations in the scope and level of services delivered in existing contracts. Poor contract management could lead to costs being incurred, but with reduced revenue, leading to reduced profitability on the contract.
Risks around managing the confidentiality, availability and integrity of Sodexo’s information technology assets; managing cloud systems and third-party suppliers, managing Sodexo and client data; risks from external cyber threats.
On a daily basis, Sodexo IT systems across 64 countries process the data of 420,000 Sodexo employees and 100 million consumers; including patients in hospitals and children in Childcare.
In addition, the demand for new innovative and efficient services creates a fast changing and highly interconnected architecture, while the scale of operations also makes Sodexo a target for cyber criminals who want to exploit its weaknesses and gain access to the data of the thousands of clients and suppliers, to whom Sodexo is connected.
Within this challenging environment, information security issues such as poor data integrity, loss of data confidentiality and lack of availability of key systems, or collaboration services, could result in high cost and/or high-volume impacts such as:
Moreover, the outbreak of the Covid-19 pandemic has resulted in an increase in cyber related criminal activity focused on key infrastructure and core IT services, as well as significant demand for remote working services.