The key participants in Sodexo's risk management and internal control system are organized according to the Three Lines of Defense model, which defines the roles and responsibilities for managing and overseeing risk. The diagram below illustrates how these three lines work together.
SODEXO’S RISK MANAGEMENT AND INTERNAL CONTROL MODEL
Structure of Sodexo’s risk management and internal control system
Board of Directors / Audit Committee
Role: Oversee the risk-management and internal-control process.
Sodexo Executive Committee
Lines of defence
External auditors / Regulatory bodies
Participate in assessing and validating internal control and provide an external view of the company’s risk-management practices.
The first line of defense is primarily composed of operational directors and managers, who are responsible for identifying and managing risks within their activities. They put controls and action plans in place for the risks identified.
The second line of defense consists of global support functions who are there to support operators with their risk management. They define the procedures and standards and provide standardized tools and processes to enable operational staff to put in place the appropriate controls.
The third line of defense is Internal Audit, which provides an independent assessment of the risk management and internal control system to the Sodexo Leadership Team and Board of Directors. It issues recommendations to the first and second lines of defense to strengthen risk management and internal control, and monitors the related action plans (see 6.6).