Risk management

The Board of Directors of Sampo plc is responsible for ensuring that the Group’s risks are properly managed and controlled.

The Board establishes both the risk manage­ment principles and closely connected remuneration principles and provides guidance on the risk management governance structure and internal control in the business areas. Working within the framework of these principles and guidelines, the subsidiaries tailor their risk manage­ment practices to take account of the special features of their respective business activities. The Board makes decisions on strategy, return targets and the general levels of risk and capitalization of the subsidiaries.

Risk is generally defined as the effect of uncertainty on objectives. Risk management means, in particular, making decisions about what risks to take and what risks are not to be taken. Risk management requires knowledge of risks and the ability to assess them. Integral parts of risk management are business continuity management and compliance with internal and external guidelines.

Principles and responsibilities in risk management

Sampo Group's parent company, Sampo plc is a holding company, and it does not have any business activities of its own. The Group’s business activities are conducted in four business areas, which manage the risks related to their operations and continuously assess the capital required to cover their risks. In addition, Sampo plc manages key financial strength metrics and solvency for the consolidated group and the parent company. Sampo plc steers the subsidiaries by setting targets for their profitability and by defining the main preconditions for the subsidiaries’ operations in the form of group-wide principles of which the most important are Code of Conduct, Internal Control Policy, Risk Management Principles, Remuneration Principles, Compliance Principles and Disclosure Policy. The subsidiaries approve their own more detailed policies and instructions and organize their reporting to management bodies by themselves.

Managing risk includes first and second line roles. First line roles include business functions, most directly aligned with the delivery of products and services to clients, and portfolio management and support functions. Second line roles, including risk management and compliance functions, provide complementary expertise, support, monitoring and challenge related to the management of risk.

The third line consists of the Internal Audit function.

Risk management reporting

Group companies have internal and group-wide reporting responsibilities. At group-level profits, risks and capital are reported at least quarterly and reporting shall mainly be based on reporting undertaken in sub-groups. Reporting must take into account the specific features of companies’ business activities and their business environment.

Risk management governance framework in Sampo Group

Classification of risks

In Sampo Group the risks associated with its business activities fall into three main categories: (i) business risks, (ii) reputational risks and (iii) risks inherent in business operations, as shown in the picture below.