TRContact Us
Policies

Internal Control and Process Improvement Policy

This policy defines how operational risks, existing controls, and corrective actions are reviewed and tracked.

Last updated: July 19, 2026Policy document

Purpose and scope

The purpose of this policy is to identify operational risks, review how existing controls operate, and track any necessary corrective actions.

This document does not mean that the company has a separate or independent internal audit department. The method and people responsible for a review are determined according to the matter’s impact, the expertise required, and any potential conflicts of interest.

Selecting matters for review

Areas for review are selected with regard to risk level, process changes, security or service incidents, customer feedback, and previous findings.

  • Priority is given to high-impact or recurring issues.
  • The purpose, scope, and required records are defined at the outset of the review.
  • Where appropriate, input is obtained from a specialist other than the people directly responsible for the matter.

Risk and control assessment

Risks are assessed with regard to likelihood, business impact, customer impact, and existing controls. The presence of a control in documentation alone is not treated as sufficient; suitable evidence is used to check whether it is operating in practice.

Conducting a review

A review uses documents, records, system outputs, interviews, and sample checks where appropriate. Findings are based on observable circumstances and evidence rather than personal opinion.

The person responsible for the process under review is given an opportunity to explain a finding and provide missing information.

Findings and corrective-action tracking

The impact, proposed corrective action, responsible person, and target date are recorded for each finding. Critical matters are escalated to the relevant senior owner, and completed action is checked separately to determine whether it resolved the issue.

Objectivity and confidentiality

If the person conducting the review has a conflict of interest in the matter, it is disclosed and responsibilities are reconsidered. Customer, employee, and company information accessed during a review is used only for the relevant purpose.

Process improvement

Improvement is not limited to closing errors. Repetitive manual work, unclear responsibilities, unnecessary approvals, inadequate records, and process steps whose performance is not measured may also be considered for improvement.

Review

This policy is reviewed when there is a material change to the relevant service, process, organisational structure, or applicable law. After any necessary revisions, the current text and revision date are published on this page.