0% found this document useful (0 votes)
3 views99 pages

SBL Notes

The document discusses the essential qualities of effective leadership, emphasizing the importance of communication, judgment, conceptual skills, and resilience in strategy formulation and change management. It also explores the concepts of entrepreneurship and intrapreneurship, highlighting their roles in innovation and strategic opportunity exploitation. Additionally, it outlines ethical values underpinning governance, the impact of culture on organizational purpose and strategy, and the significance of responsible leadership in creating public value.

Uploaded by

intali45
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views99 pages

SBL Notes

The document discusses the essential qualities of effective leadership, emphasizing the importance of communication, judgment, conceptual skills, and resilience in strategy formulation and change management. It also explores the concepts of entrepreneurship and intrapreneurship, highlighting their roles in innovation and strategic opportunity exploitation. Additionally, it outlines ethical values underpinning governance, the impact of culture on organizational purpose and strategy, and the significance of responsible leadership in creating public value.

Uploaded by

intali45
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Section A – Leadership

A1 – Qualities of Leadership
A1a – The Role of Effective Leadership
Explain the role of effective leadership and identify the key leadership traits effective in the successful
formulation and implementation of strategy and change management. [3]
A leader provides vision and direction by influencing others to follow their lead. Effective leadership is
critical to both the formulation of strategy (deciding where the organisation should go) and its
implementation (making it happen through people).
Key leadership traits:

Ability to communicate, delegate, motivate and inspire others - essential for


People skills:
implementing strategy through people
Making sound decisions under pressure with incomplete information - critical
Judgement:
in strategy and change management
Thinking long-term and strategically - seeing the big picture beyond day-to-
Conceptual skill:
day operations

Technical competence: Business literacy, commercial acumen and knowledge of the relevant field

Ability to manage setbacks, maintain composure and sustain momentum


Resilience:
through change

Trait theory assumes leaders are born, not made, which is widely challenged.
Situational leadership argues that no single set of traits is universally effective; what matters is adapting
style to the situation. Traits alone do not guarantee success; context, culture and timing all moderate whether
a trait becomes a strength or a liability (e.g. resilience can become stubbornness in a rapidly changing
environment).
For strategy formulation, leaders must be able to analyse the environment, identify opportunities and
threats, and make strategic choices.
For strategy implementation, leaders must communicate the strategy clearly, motivate people to deliver it,
and manage resistance to change.

A1b – Entrepreneurship and Intrapreneurship


Apply the concepts of entrepreneurship and ‘intrapreneurship’ to exploit strategic opportunities and to
innovate successfully. [3]
Entrepreneurship is when a person takes a business risk in order to make a profit. They identify
opportunities, commit resources and drive innovation, often creating entirely new businesses or markets. Key
traits include risk tolerance, creativity, opportunity recognition and decisiveness.
Intrapreneurship is when managers, directors and employees of the company think like entrepreneurs for
the benefit of the organization. They identify opportunities, challenge the status quo and drive innovation.
Why this matters for governance and strategy:

● Intrapreneurship allows established organisations to innovate and respond to disruption without the
risk of starting from scratch

● Boards should create an environment that encourages intrapreneurial behaviour through culture,
incentives and tolerance of calculated risk
● The tension between governance (control and accountability) and intrapreneurship (risk-taking and
innovation) must be actively managed; too much control stifles innovation, too little creates
unacceptable risk
Organisations that encourage entrepreneurial thinking without genuinely restructuring authority, resources or
risk tolerance will find that intrapreneurs are incentivised to generate ideas but not empowered to execute
them. The concept requires structural enablement, not just cultural encouragement.

A1c – Ethical and Professional Values Underpinning Governance


Apply, in the context of organisation governance and leadership qualities, the key ethical and professional
values underpinning governance. [3]
* This is separate from leadership traits which is about cognitive skills and capability. Good governance
values are about obligation of the role and conduct*

Values underpinning good governance are (‘I RID OF AJ’):


• Integrity: acting ethically and with moral courage even when not observed or legally required to do
so. Financial information is presented without intentional misrepresentation.
• Responsibility: directors may delegate tasks, but not responsibility; they remain accountable for
company performance
• Independence: freedom from undue influence; includes independent non-executive directors and
independent external auditors
• Diversity: a range of skills, experience, and perspectives on the board helps challenge decisions and
avoid groupthink
• Openness: transparency in reporting; information should be disclosed unless there are valid
commercial reasons not to
• Fairness: all shareholders should be treated equally (e.g. one share = one vote)
• Accountability: directors are answerable to shareholders for company performance (e.g. through
audited financial statements)
• Judgement: directors should apply their skills and experience to make sound, professional decisions

A2 – Leadership and Organisational Culture


A2a – Leadership in Defining and Managing Culture
Discuss the importance of leadership in defining and managing organisational culture. [3]
Organisational culture is the collective identity of an organisation; the body of values, beliefs and behaviours
that shape how business is conducted.
Leadership does not just reflect culture, it creates it. The board and senior management set the tone from
the top. When leaders behave ethically, communicate openly and reward the right behaviours, that culture
cascades downward.
Leaders can manage culture through:

● Modelling behaviour: Leadership is the primary driver of culture. The actions, decisions and stated
values of executives and the board signal to the rest of the organisation what is truly valued. The gap
between stated values and actual behaviour visible in the cultural web elements, symbols, rituals and
stories is where cultural problems are found.

● Reward and control systems: what gets measured and rewarded becomes the culture. Reward systems
need to reflect performance criteria that includes non-financial targets.

● Sustained intervention: culture changes over years, not months. Leaders must intervene across all
elements of the cultural web, not just surface-level communications, and resist declaring success before
new behaviours have fully embedded.
A2b – Leadership Styles for Managing Strategic Change
Advise on the style of leadership appropriate to manage strategic change. [2]
Transformational leadership is most appropriate for managing strategic change, because strategic change
requires people to behave differently, not just do more of the same. Instruction and reward alone
(transactional leadership) will not shift deeply held behaviours and cultural norms.
Transformational leadership — the leader articulates a compelling vision, challenges people to think
differently and motivates through inspiration rather than reward and punishment. It directly addresses the two
biggest barriers to strategic change: employee resistance and lack of genuine commitment to the new
direction.
Transactional leadership — based on exchange: reward for performance, punishment for failure. Effective
for maintaining routine operations during a change programme but insufficient for driving the change itself.
In practice, a leader managing strategic change will rarely use one style exclusively. Transformational
leadership drives the vision and commitment; democratic elements bring in expertise and build buy-in at key
decision points; autocratic elements may be needed in a crisis or when pace is critical. The skill is in knowing
which to apply and when.

Style Approach When appropriate


Leader makes decisions alone and Crisis situations; when speed is essential; when
Autocratic
directs others followers lack experience
Leader involves others in decision- When buy-in is important; when team has
Democratic
making valuable expertise; complex strategic decisions
Leader delegates fully and steps Highly skilled, self-motivated teams; creative
Laissez-faire
back environments

A2c – Analysing Culture Using the Cultural Web


Analyse the culture of an organisation, to recommend suitable changes, using appropriate models such as
the cultural web. [3]
The Cultural Web determines the underlying culture of an organisation by assessing six interrelated visible
characteristics (SPROCS):

Characteristics Suitable changes


narratives and myths that communicate create new narratives that celebrate the
Stories: important values. Past events that are behaviours the new culture requires; retire
immortalised internally and externally. old myths that reinforce the old paradigm
formal and informal distribution of
ensure those with informal power support
Power authority; where power is concentrated
the change; if key power holders resist,
structures: and who has the greatest influence over
change will stall
decisions and strategic direction
daily, regular and repetitive behaviours redesign day-to-day processes to embed
Rituals and
accepted and endorsed by management; new behaviours; remove rituals that
routines:
they reinforce cultural norms reinforce the old culture
defined by the organisational chart and
Organisational restructure where necessary; culture and
unwritten lines of power, including
structures: structure must change together
reporting lines and formal systems
mechanisms that measure, reward or
realign performance management and
Control punish behaviour, such as financial
reward systems to measure and
systems: controls and performance management
incentivise what the new culture values
systems
visual representations of the company
change visible signals (office layout, titles,
Symbols: including logos, office layout and dress
dress code) to reinforce the new culture
code
At the centre of the web sits the paradigm: the core set of assumptions and beliefs that underpin the culture.
All six elements reinforce the paradigm.
When to use: apply this framework when a question asks you to analyse an organisation's culture, do not
analyse culture in isolation; consider whether the organisation’s structure supports or blocks the culture and
strategy. Identify cultural barriers to change, or recommend how culture should be changed.
● Simple structure: power concentrated at the top; fast decisions; common in entrepreneurial/founder-
led businesses.
● Machine bureaucracy: formalised, standardised, control-heavy; efficient in stable environments but
slower to change.
● Professional bureaucracy: relies on skilled professionals; flatter structure and more autonomy;
common in accounting, legal or consultancy firms.
Exam use: link the structure to the culture and strategy. For example, a machine bureaucracy may clash
with an innovation strategy, while a simple structure may become unsuitable as the organisation grows and
needs stronger governance.
The cultural web can be used in these scenarios:
● Culture clash — particularly in mergers where two incompatible configurations are combined e.g. an
entrepreneurial start-up acquired by a large corporate. Neither naturally adapts and the merger
destroys value
● Inappropriate culture — when strategy changes but culture does not e.g. a company pursuing
innovation with a culture that punishes risk-taking. The strategy fails not because it is wrong but
because the culture cannot deliver it
● Lifecycle change — culture must evolve as organisations grow. A founder-led business successful
as a simple structure will struggle when it lists and must adopt governance and controls. The founder
and early staff may resist this transition
● Change management — any structural or cultural change requires communication, education and
participation to overcome resistance

A2d – Impact of Culture on Organisational Purpose and Strategy


Assess the impact of culture on organisational purpose and strategy. [3}
Impact on purpose - an organisation can have a clearly stated purpose but if culture does not reinforce it,
that purpose remains aspirational rather than operational. Culture shapes employee actions and decision-
making day-to-day. It either reinforces organisational purpose or actively undermines it.
Impact on strategy - strategy sets direction but culture controls pace and can override it. Where culture
conflicts with strategy, implementation will fail regardless of how well the strategy is designed. Common
barriers include:

● Employee resistance: where mistakes are punished, employees default to safe actions, directly
limiting innovation-led strategies. It also suppresses useful feedback that management needs to refine
strategy over time.

● Misaligned rewards: if reward structures are not aligned with strategy, employees optimise for what
they are paid to do, not what the organisation needs. Individual performance bonuses undermine
collaboration; unrewarded innovation suppresses intrapreneurship. Misaligned rewards do not just
fail to motivate; they actively build a culture that works against the strategy.

● Decision-making pace and organisational structure: culture and structure jointly determine
execution speed. In high-ownership cultures with wide-flat structures, employees decide at their level
and execution is fast. In low-ownership cultures with tall-narrow structures, decisions escalate through
multiple layers, creating bottlenecks that slow delivery regardless of strategic clarity. A strategy
requiring rapid market responses will fail in a centralised, hierarchical organisation even if the strategy
itself is sound. You cannot change culture without considering structure, and vice versa.
● Management behaviour: the board sets strategy but middle management determines whether it
reaches the operating core. Where middle managers lack commitment, capability or incentive to
champion the change, board-level intent is filtered, diluted or blocked before it reaches front-line staff.
Culture and strategy are mutually reinforcing. Strategy emerges from culture, and culture is reinforced by
strategy, creating a feedback loop where the two become indistinguishable over time.
Before implementing a new strategy, leaders should use the cultural web to assess whether the existing
culture supports or undermines it. If there is a mismatch, culture change must be managed alongside strategy
implementation, which is significantly harder and slower than changing the strategy itself.

A3 – Professionalism, Ethical Codes and the Public Interest


A3a – Responsible Leadership and Public Value
Critically evaluate the concept of responsible leadership and the creation of public value by acting in the
public interest. [3]
Three core behaviours of Responsible Leadership;

● Focus on the broader needs of others rather than personal interests


● Consider the societal and moral implications of decisions
● Base decisions on the long-term rather than satisfying immediate priorities at the expense of future
success

In practice: considering the impact of decisions on all stakeholders; being transparent and accountable
beyond minimum compliance; building long-term trust with society which sustains the organisation's licence
to operate.
When linked with strategy, organisational reputation grows when responsibility is embedded rather than used
for marketing purposes.
Maak and Pless — Responsible Leader Role Models
A responsible leader plays several roles simultaneously:
● Steward: takes responsibility for the organisation and its stakeholders
● Citizen: contributes to society beyond the organisation's immediate interests
● Coach: develops others rather than treating them as subordinates
● Visionary: creates a shared paradigm and long-term direction
● Storyteller and meaning enabler: builds a shared culture and values
Public Value is the broader benefit organisations create for society beyond financial returns, including
economic contribution, employment, environmental stewardship and social trust.
How public value differs by context:

● Listed company: Long-term shareholder value balanced against stakeholder interests; ESG
commitments; avoiding reputational harm to markets
● Public sector body: Delivering services efficiently and equitably; stewardship of public funds;
democratic accountability
Responsible leadership can conflict with short-term shareholder expectations. A leader who absorbs short-
term costs to act responsibly may face pressure from investors focused on quarterly returns.
"Public value" can be used as reputational window-dressing (greenwashing, ethics-washing) without
substantive change. Leaders must ensure it is embedded in decision-making, not just communicated
externally.
A3b – IESBA Code of Ethics
Assess management behaviour against the codes of ethics relevant to accounting professionals including
the IESBA (IFAC) or professional body codes. [3]
The IESBA (International Ethics Standards Board for Accountants), operating under IFAC, sets out the Code
of Ethics for professional accountants. The five fundamental principles are:
● Integrity: Be straightforward and honest in all professional and business relationships
● Objectivity: Do not allow bias, conflicts of interest or undue influence to override professional
judgement
● Professional competence and due care: Maintain professional knowledge and skill; act diligently
in accordance with applicable standards
● Confidentiality: Do not disclose information acquired through professional work and relationships
without authority
● Professional behaviour: Comply with relevant laws and regulations; avoid actions that discredit the
profession

A3c – Conflicts of Interest and Ethical Conflicts


Analyse the reasons for conflicts of interest and ethical conflicts in organisations and recommend resolutions.
[3]
Conflict of interest — director or manager has a personal interest that conflicts with their duty to act in the
best interests of the organisation. E.g. A director awarding a contract to a company in which they hold shares
or a CEO negotiating their own remuneration package
Ethical conflicts — individuals face pressure to act in a way that conflicts with their professional or personal
values. E.g. Being asked by a superior to falsify financial information or being pressured to sign off on a
misleading sustainability report

Reasons for conflict Resolutions

Short-term bonus structures reward behaviours that


Redesign reward systems to
Incentive conflict with long-term ethical conduct. Executives
include ethical conduct criteria
misalignment: are incentivised to maximise near-term earnings
alongside financial targets.
even at the cost of integrity.
Junior employees face pressure to comply with Escalate to a higher authority
Power superiors even when instructions conflict with audit committee/board chairman
imbalances: professional values. The cost of refusal is career or use formal whistleblowing
risk; the benefit of compliance is job security. procedures.
Pressure to deliver results quickly makes cutting
Seek independent legal or
Short-termism: ethical corners appear rational, particularly when
ethical advice before acting.
detection risk seems low.
Where an individual occupies multiple roles e.g. a Disclose the conflict and recuse
Role director who is also a significant shareholder, or a from the relevant decision.
ambiguity: CFO who chairs the audit committee — boundaries Resignation from one of the
of loyalty and duty become unclear. roles may be necessary.

When a conflict or ethical dilemma cannot be resolved through the approaches above, the following
frameworks provide a structured way to work through the decision:
The AAA Model (American Accounting Association) — 7 Steps:
A logical framework for working through an ethical decision systematically:
1. Establish the facts - State clearly what is happening. Remove ambiguity before analysis begins
2. Identify the ethical issues - What ethical problems arise from those facts?
3. Identify norms, principles and values - What professional codes, social expectations or legal
standards apply?
4. Identify alternative courses of action - List all options without filtering, include even inappropriate
ones
5. Evaluate options against norms - Overlay Step 3 onto Step 4 — which options comply with the
norms and which do not?
6. Consider consequences of each option - What are the outcomes for each stakeholder if each option
is chosen?
7. Make the decision - Choose the option most consistent with the norms and with acceptable
consequences
Key point: the model forces you to be explicit about your values before evaluating options, preventing post-
hoc rationalisation of a convenient choice.
Tucker's 5-Question Model
Tests a proposed decision against five criteria. Unlike the AAA model, Tucker is not purely sequential, the
five questions can be applied simultaneously and the answers weighed against each other:
● Is it profitable? Does it generate an acceptable financial return? Note: compared to what alternative?
● Is it legal? Does it comply with the law? Note: legal does not mean ethical — weak legal frameworks
can allow oppressive behaviour
● Is it fair? Is it equitable to all affected stakeholders? Note: depends on whose perspective you adopt
● Is it right? Does it accord with ethical principles? Note: a deontological answer may differ from a
teleological one
● Is it sustainable / environmentally sound? Does it consider long-term environmental and social
impact?

Key point: Tucker is particularly useful for corporate decisions involving multiple stakeholders with competing
interests, where the five questions will produce conflicting answers that must be weighed against each other.

A3d – Ethical Threats and Safeguards


Assess the nature and impact of different ethical threats and recommend appropriate safeguards to prevent
or mitigate such threats. [3]
The five ethical threats apply broadly to any professional in a governance or management role, not just
auditors:

Threat Mitigation
Personal or financial interest influences Independent NEDs; transparent
Self-interest: judgement e.g. Director owns shares in a supplier disclosure and shareholder
under consideration oversight

Evaluating one's own previous work or decisions


Separation of roles; rotation of key
Self-review: e.g. CFO reviewing financial statements they
roles
prepared

Promoting a position so strongly that objectivity is


Independent NEDs; codes of
Advocacy: compromised e.g. Director publicly championing
conduct and ethics training
an acquisition they personally support

Close relationship leads to loss of professional


Rotation of key roles;
Familiarity: scepticism e.g. Audit committee chair becomes
whistleblowing policies
too close to the CFO over time

Pressure or threats undermine professional


Whistleblowing and protected
Intimidation: judgement e.g. CEO pressures a director to
disclosure; codes of conduct
approve a decision they have reservations about
A3e – Fraud, Bribery and Corruption
Recommend best practice for reducing and combating fraud, bribery and corruption to increase public
confidence and trust in organisations. [3]
Fraud: intentional deception to gain an unfair or unlawful advantage, typically financial. E.g. falsifying financial
statements, misappropriating assets or insider trading.
Bribery: offering, giving, receiving or soliciting something of value to influence the actions of an official or
person in a position of trust. The UK Bribery Act 2010 makes it a criminal offence for companies to fail to
prevent bribery by persons associated with them.
Corruption: the abuse of entrusted power for private gain. Can include nepotism, cronyism, misuse of public
funds.
Best practice for reducing and combating fraud, bribery and corruption:

● Tone from the top — board and senior management must visibly demonstrate zero tolerance for fraud,
bribery and corruption
● Strong internal controls — segregation of duties, authorisation limits, regular reconciliations
● Whistleblowing policies — protected channels for employees to report concerns without fear of
retaliation
● Anti-bribery policies — clear policies on gifts, hospitality and facilitation payments; compliance with the
UK Bribery Act
● Due diligence — screening of third parties (suppliers, agents, joint venture partners) for corruption risk
● Training and awareness — regular ethics training for all staff
● Internal audit — independent review of controls and compliance
● External audit — independent verification of financial statements reduces the risk of financial fraud going
undetected
Key point: The board is ultimately responsible for the ethical culture of the organisation. Fraud and corruption
are not just legal risks; they destroy public trust, which is far harder to rebuild than financial losses.
B. Governance & Sustainability
Section B1 – Agency
B1a – The Principal-Agent Relationship
Discuss the nature of the principal-agent relationship in the context of governance. [3]
Agency Theory - relationship between owners of the company (principals) and its directors (agents), who
have a fiduciary duty of trust and care to the shareholders.
The separation exists because shareholders provide capital but lack the time and expertise to manage the
business day-to-day so they delegate control to directors. This delegation is the foundation of the governance
problem: directors may not always act in the best interests of those who appointed them.

B1b – Separation of Ownership and Control


Analyse the issues connected with the separation of ownership of an organisation from control over its
activities. [3]
In large public companies, the people who own the company (shareholders) are not the same people who
run it (directors/managers) which creates the basis of the principal-agent problem.

Issue Detail Governance Response


Managers have far more information about the
Mandatory financial
Information company's true position than shareholders who rely on
reporting; external audit;
asymmetry disclosures (annual report, auditor's report) which may
integrated reporting
be incomplete or delayed.

Managers take excessive risks as they do not bear the


Moral hazard / full financial consequence of failure. If remuneration is Long-term incentive plans
short-termism linked to short-term profit, managers are incentivised to (LTIPs); clawback provisions;
take short-term decisions that harm long-term value.
Over time, managers may take actions that make it Independent NEDs;
Managerial hard to remove them; building loyal teams, resisting nominations committee;
entrenchment board refreshment, or making themselves regular board evaluation;
indispensable. term limits
Perquisite Managers may consume company resources for Audit committee; transparent
consumption personal benefit (lavish offices or excessive remuneration reporting;
('Perks') entertainment) that do not benefit shareholders. shareholder approval

Stewardship theory —It assumes directors are not automatically self-interested agents, but may act as
responsible stewards of the organisation, motivated by achievement, reputation, professional duty and long-
term organisational success. Governance should therefore not only control directors, but also empower them
to exercise judgement. Agency theory supports monitoring and control mechanisms; stewardship theory
supports trust, empowerment and long-term leadership. In practice, good governance balances both.

Note: Governance mechanisms can reduce agency problems but never eliminate them. The goal is therefore
an acceptable balance; enough control to protect shareholders and enough freedom for directors to manage
effectively. Too many controls stifle entrepreneurship; too few allow abuse.

Section B2 – Stakeholder Analysis and Social Responsibility


B2a – Stakeholder Power and Interest (Mendelow's Matrix)
Discuss, and critically assess, the concept of stakeholder power and interest using the Mendelow model and
apply this to strategy and governance. [3]
A stakeholder is anyone who can influence the organisation or be influenced by it. They can make demands
known as stakeholder claims. Examples: suppliers, customers, employees, government, the environment.
Stakeholder Theory - Directors are not just accountable to shareholders, but to a broad range of
stakeholders. Some companies are so powerful (economically, socially, and politically) that the unrestrained
use of their power can damage the rights of others.
Mendelow's Matrix maps stakeholders by power and interest to determine how they should be managed:

Keep Satisfied Manage Closely

Powerful but not particularly engaged day-to- Most important stakeholders; their support is
day. Dangerous if they become dissatisfied. critical and their opposition can derail strategies.
High
e.g. passive major shareholders, government e.g. major shareholders, large institutional
Power
bodies, large creditors. investors, key lenders, government regulators.
Give them enough information to stay Involve them in decisions, consult regularly,
content. build relationships.
Keep Informed
Minimal Effort
Very interested but lack power to directly
Neither powerful nor particularly interested. influence. Can become a nuisance if ignored;
Low e.g. general public, minor suppliers. may lobby, campaign, or combine with more
Power powerful stakeholders. e.g. employees, local
Basic communication only; monitor in case community groups, small shareholders,
their position changes. pressure groups.
Regular communication and transparency.
Low Interest High Interest

Positions are not fixed — a previously passive shareholder who hears about a controversial acquisition may
suddenly become a Key Player. Good management monitors these shifts.

Low power stakeholders can combine, especially via social media, a group of "Keep Informed" stakeholders
can collectively become very powerful. Never fully dismiss them.

Application to Strategy: before implementing a major decision, management should map all affected
stakeholders on the matrix and tailor its engagement strategy accordingly. Failure to manage a Key Player
can derail the strategy entirely.

Application to Governance: The board is ultimately accountable for stakeholder management. NEDs in
particular should ensure voiceless or indirect stakeholders (e.g. the environment, future generations) are
represented in board-level decisions.

B2b – Stakeholder Roles, Claims, Conflicts and Resolution


Evaluate the stakeholders’ roles, claims and interests in an organisation and how they may conflict and be
resolved. [3]
Important Stakeholder Groups:

Stakeholder Role / Claim Potential Conflict


Pension funds, insurance companies; hold
Institutional May prioritise short-term returns vs
large shareholdings giving significant voting
investors board's long-term strategy
power
Represent employee interests; can organise
May conflict with board over pay,
Trade unions workforce compliance and assist in managing
redundancies or restructuring
change
Speak for voiceless stakeholders (e.g.
Pressure May oppose strategies that harm
environment, communities); can attract
groups environmental or social interests
significant media attention
Government / Set legal and regulatory framework; can May restrict commercial freedom in
regulators impose fines or restrictions pursuit of public interest
Provide revenue; demand quality, value and May conflict with cost-cutting
Customers
ethical behaviour strategies
Provide inputs; dependent on fair payment May conflict with pressure to cut
Suppliers
terms and continuity costs or switch suppliers

Stakeholder conflicts arise when different groups have incompatible claims — e.g. shareholders want higher
dividends while employees want higher wages; or a company wants to expand while local communities
oppose development.
Resolving stakeholder conflicts and what goes wrong with it:
• Prioritise by Mendelow position: Key Players take precedence over Minimal Effort stakeholders.
However, systematically deprioritising low-power stakeholders can lead to their interests being chronically
ignored, leading to reputational and regulatory risk as ignored groups find ways to amplify their voice (e.g.
social media, regulatory complaints, coalition-building).

• Negotiation and compromise: engage directly with conflicting parties to find an acceptable middle
ground. However, this assumes parties are willing to engage in good faith. In practice, entrenched
positions or power imbalances mean negotiation often favours the more powerful party.

• Transparent communication: explain decisions clearly to those who will be affected

• Governance structures: board committees (e.g. audit, remuneration) exist partly to resolve conflicts
between executives and shareholders, however are poorly equipped to resolve conflicts involving external
stakeholders (e.g. local communities, environmental groups) who have no formal representation in
governance mechanisms.

• CSR policy: a clear corporate social responsibility framework sets out how competing claims will be
balanced, however can become a public relations exercise particularly in instrumentally motivated
companies where CSR is used to manage perception rather than resolve substantive conflicts.

• Legal compliance: where conflict cannot be resolved, the law sets a minimum standard all parties must
accept

B2c – Social Responsibility in the Context of Governance


Explain social responsibility in the context of governance and sustainability for the public good. [2]
Carroll's Pyramid — defines four levels of corporate responsibility, building from the foundation upward. A
company cannot genuinely pursue philanthropic goals if it is not first profitable and legal.

Level Type What it means


Be a good corporate citizen. Contribute to community; support causes
4 (Top) Philanthropic
beyond legal or ethical obligation. Discretionary.

Do what is right, fair and just, even when not required by law. Reflects
3 Ethical
societal norms and expectations.

Obey the law. Comply with regulations governing employment, safety,


2 Legal
environment and commerce. Minimum expected of all businesses.

1 Be profitable. Without profitability the business cannot survive to fulfil any


Economic
(Base) other responsibilities.

Key point: Carroll's pyramid does not mean companies should only focus on economics, all four levels are
required responsibilities, each building on the one below. Use this to evaluate whether a company is being
socially responsible at each level.
Companies act towards social responsibility based on two main motivations, which exist on a continuum:

Motivation Explanation
Internal, moral drive — the company believes it has a genuine ethical duty to act
Normative
responsibly. CSR is embedded in values, not driven by commercial outcomes.
Driven by commercial outcomes — engages with CSR because it improves
Instrumental
reputation, attracts talent, avoids regulation and builds customer loyalty.
Middle ground — businesses recognise that long-term commercial success
Enlightened self-
depends on a healthy society and environment. Sustainability is in the shareholder's
interest
long-term interest.

Section B3 – Governance Scope and Approaches


B3a – The Role and Influence of Institutional Investors
Analyse and discuss the role and influence of institutional investors in governance systems and structures.
[2]
Institutional investors are organisations that pool money from many individuals and invest it on their behalf
e.g. pension funds (investing workers' retirement savings), insurance companies (investing premiums) and
asset managers (investing on behalf of clients). Because they are investing such large sums, they often hold
large proportions of a company's shares, giving them significant influence and voting rights.
Their influence on governance:

Role Detail

Large shareholdings give institutional investors significant votes at AGMs,


if they act collectively with other institutional investors, they can force the board to
Voting power
change course on major decisions like executive pay, director appointments or
significant acquisitions.
Historically, when dissatisfied, institutional investors would simply sell their shares
(the "Wall Street Walk"). The UK Stewardship Code changed this, requiring them to
Stewardship & actively engage with investee companies — attending meetings, raising concerns
Engagement directly with the board and publicly disclosing how they vote — rather than exiting
when things go wrong. Engagement is preferred over exit because it creates
sustained accountability; selling shares simply passes the problem to the next
shareholder.
As institutional investors represent millions of ordinary people (pensioners, savers),
they are particularly sensitive to excessive executive pay. They will often vote against
Remuneration
remuneration reports they consider unjustified, and a significant protest vote, even if
scrutiny
it doesn't technically defeat the resolution, creates serious reputational pressure on
the board to reconsider.
Increasingly, Institutional investors are under pressure from their own clients and
regulators to invest responsibly. They now routinely assess companies on
environmental, social and governance criteria before investing or continuing to hold
ESG pressure
shares. A company with poor ESG credentials may find institutional investors
reducing their holdings, which pushes the share price down and raises the cost of
capital, pressuring companies to improve sustainability and governance standards

Key point: Institutional investors sit in the High Power, High Interest quadrant of Mendelow's Matrix — they
must be managed closely. Their support is critical for major strategic decisions such as acquisitions; capital
raises or significant restructurings.

B3b – Rules vs Principles-Based Approaches


Compare rules versus principles-based approaches to governance and advise when they may each be
appropriate. [3]
Governance frameworks can be designed in two fundamentally different ways; you will often be asked to
recommend which approach is more suitable given a scenario.
Rules-Based Approach: Sets out specific, mandatory legal requirements that companies must follow. Non-
compliance results in legal sanctions and penalties (e.g. fines, criminal liability). This gives high certainty.
Everyone knows exactly what is required but flexibility is low as rules apply regardless of company size or
context. Compliance costs can be very high. The risk is that companies 'tick the box' without genuine change.
Best known example is the US Sarbanes-Oxley Act (SOX), enacted in 2002 following the Enron and
WorldCom scandals.
Recommend when: trust in management has broken down; major governance failures have occurred; strong
consistent investor protection is needed; and there is a large diverse investor base with limited ability to
scrutinise 'explain' statements
Principles-Based Approach: Sets out broad best-practice recommendations on a 'comply or explain' basis.
Companies can tailor governance to their circumstances, making it more flexible and generally lower cost.
Certainty is lower as principles are open to interpretation. Investor protection relies on shareholders
scrutinising explanations, and explanations can become boilerplate over time. Best known example is the UK
Corporate Governance Code (FRC).
Recommend when: companies differ significantly in size, structure and context; sophisticated institutional
investors are present; flexibility to explain is genuinely valued; and the market is mature enough to hold
boards accountable for their explanations
Governance culture point: Rules and principles only work if supported by the organisation’s culture. A rules-
based system can create box-ticking, while a principles-based system can produce vague explanations if the
board lacks genuine accountability. Effective governance depends on internal values as well as external
regulation.

B3c – Models of Organisational Ownership


Discuss different models of organisational ownership that influence different governance regimes (family
firms versus joint stock company-based models) and explain how they work in practice. [2]
The way a company is owned has a direct effect on how it is governed. The two principal models are the joint
stock (public) company and the family firm.

Joint Stock (Public) Company Family Firm


Dispersed among many shareholders; Concentrated in family/founder hands; may
Ownership
freely transferable shares extend to listed companies
Reduced owner-manager problem but new
Agency Classic owner-manager problem:
problem emerges between family and
problem shareholders delegate to directors
minority shareholders
NEDs may struggle to be genuinely
Board NEDs and committees required to
independent if family dominates
independence manage agency problem
appointments
Institutional investors hold large stakes; Minority shareholders may be
Investor
stewardship codes encourage active marginalised; limited ability to challenge
engagement
engagement the family
High — listed companies must disclose
Transparency Lower — less scrutiny if not listed
extensively to the market
Discipline Hostile takeovers act as a check on Market for corporate control less effective;
mechanism underperforming boards family can resist takeover
Agency costs; short-termism; collective
Tunnelling; succession risk; entrenchment
Key risk action problems when challenging the
of family interests
board
Primary May balance family interests with business
maximising shareholder value
objective objectives
Other ownership models:

● State-owned enterprise — owned and controlled by the government, which acts as principal and
sets objectives. Accountability runs to taxpayers through politicians rather than market mechanisms,
which weakens governance discipline; there is no share price to fall, no takeover threat and no profit
motive. The key risk is that political objectives (e.g. keeping a loss-making service running for electoral
reasons) conflict with efficiency. Examples: BBC, Network Rail.

● Mutual / cooperative — owned by members, either customers or employees. No external


shareholders, so the primary objective is serving members' interests rather than maximising profit.
Governance is democratic; members vote, similar to shareholders. The key risk is that with thousands
of members each holding a small stake, engagement is weak and professional management can
accumulate unchecked power, recreating the agency problem.

Key exam point: Always link ownership structure to governance risks. Family firm → minority shareholder
protection. Dispersed shareholders → agency costs and board accountability. State-owned → political
interference vs public interest.

B3d – ICGN Global Governance Principles


Apply the general principles of the International Corporate Governance Network (ICGN)’s Global Governance
Principles to organisations’ corporate governance. [2]
UK Corporate Governance Code (FRC) applies only to UK-listed companies. It is regulator-led by the FRC
and operates on a comply or explain basis, enforced through the Listing Rules. The focus is on board
composition, accountability and transparency. Sustainability is increasingly referenced but remains less
explicit than the ICGN.
The International Corporate Governance Network (ICGN) is a global organisation of institutional investors
(pension funds, asset managers, insurers) that sets out principles for good corporate governance applicable
worldwide. They carry no legal force and are entirely voluntary. The focus is on shareholder rights and long-
term stewardship, with a strong explicit emphasis on sustainability and ESG. Unlike,

ICGN Principle What it means


The board is responsible for the long-term success of the company — strategic
1. Board
leadership, oversight of management, risk management and accountability to
Responsibilities
shareholders
Appropriate mix of skills, experience, independence and diversity; majority of
2. Board Composition independent NEDs recommended; regular board refreshment prevents
entrenchment
Board sets and monitors culture, values and ethics; 'tone from the top' is
3. Corporate Culture
essential; culture must align with long-term strategy
4. Senior Executive Pay linked to long-term performance; transparent and justifiable; shareholders
Remuneration should have a meaningful say on remuneration policy
Board sets risk appetite and ensures robust risk management — financial,
5. Risk Oversight operational, reputational, environmental and social; cannot simply delegate risk
to management
6. Audit, Internal
Board ensures integrity of financial reporting; maintains effective internal
Controls & Financial
controls; oversees independence and effectiveness of external auditors
Statements
7. Corporate Transparent, timely and accurate reporting on financial and non-financial
Reporting matters including ESG; consistent with integrated reporting
8. Shareholder Rights Shareholders have rights to vote and engage; institutional investors have
& Stewardship stewardship responsibilities to actively monitor investee companies
Exam tip: The ICGN will usually appear when a question concerns an international company, cross-border
governance, institutional investor responsibilities, or ESG reporting. Apply the relevant principles to the
scenario, you don't need to list all eight.

Section B4 – Reporting to Stakeholders


B4a – Factors Determining Reporting Policies
Discuss the factors that determine organisational policies on reporting to stakeholders, including stakeholder
power and interests. [3]
Mandatory disclosures — components of the annual report required by law or accounting standards (e.g.
statement of comprehensive income, statement of financial position, statement of cash flows, statement of
changes in equity, auditor's report). These must be reviewed and certified by independent auditors.
Voluntary disclosures — components not required by law but which the company chooses to disclose.
Narrative rather than numerical (e.g. risk information, operating review, social and environmental
information). Provides a fuller picture of the company including its strategy, values and activities. Makes the
annual report more forward-looking rather than purely historical. Can also be used to address specific
shareholder concerns.
Factors that determine how much and what a company chooses to report:

Factor Explanation
High power, high interest stakeholders (e.g. institutional investors, regulators)
Stakeholder power
can demand greater disclosure — companies respond to avoid losing their
and interest
support
Legal and
Minimum mandatory disclosures are non-negotiable; sector-specific regulations
regulatory
(e.g. financial services, extractives) may require additional disclosures
requirements
Competitive Companies may withhold certain information if disclosure would damage their
sensitivity competitive position
Reputational Companies with strong CSR commitments may voluntarily disclose more to
considerations build trust and enhance reputation
Investor Institutional investors increasingly expect ESG and sustainability disclosures as
expectations part of their stewardship responsibilities
Preparing additional disclosures is costly — smaller companies may disclose
Cost of disclosure
less due to resource constraints
Normatively driven companies are more likely to disclose beyond the minimum;
Corporate culture instrumentally driven companies disclose only when it benefits them
commercially

B4b – Role and Value of Integrated Reporting and Accounting for Sustainability
Assess the role and value of integrated reporting and evaluate the issues concerning accounting for
sustainability.[2]
Integrated Reporting (IR) — an aspect of voluntary reporting. Focuses on how risk is managed within the
business environment and how an organisation creates value over time. Considers financial performance
alongside corporate social responsibility and investor relationships.

For the organisation For stakeholders


Forces clearer strategic thinking More complete picture of organisational health
Enhances reputation and trust with stakeholders Better basis for long-term investment decisions
Improves internal communication and joined-up
Greater accountability from management
decision making
Attracts long-term investors who care about Clearer understanding of risks beyond financial
sustainability ones

Accounting for sustainability — traditional financial reporting only captures financial capital, ignoring
environmental degradation, social impacts and resource depletion. Sustainability accounting attempts to
capture these wider costs and benefits, giving stakeholders a more complete picture of organisational
performance. This is directly addressed by the six capitals framework within IR.

B4c – Guiding Principles, Content Elements and Six Capitals of IR


Advise on the guiding principles, the typical content elements and the six capitals of an integrated report,
and discuss the usefulness of this information to stakeholders. [3]
Guiding Principle of IR

⮚ Strategic focus and future orientation: how strategy in linked to value creation
⮚ Connectivity of information: how the six capitals, business activities and external factors are
interconnected
⮚ Stakeholder relationships: Nature and quality of relationships with key stakeholders and how their
needs are addressed
⮚ Materiality: Only include matters that substantively affect the organisation's ability to create value
⮚ Conciseness: Report should be concise, not a data dump
⮚ Reliability and completeness: Include all material matters, both positive and negative, in a balanced
way
⮚ Consistency and comparability: Information should be presented consistently over time to allow
comparison
The Six Capitals — IR recognises that organisations use and affect six forms of capital in creating value:

funds available to the organisation (equity, debt, retained earnings).


Financial Capital
Traditional financial reporting covers this well already
physical infrastructure used in operations (buildings, machinery, equipment,
Manufactured Capital
technology)
knowledge-based intangibles (patents, brand reputation, proprietary systems,
Intellectual Capital
R&D)
Human Capital people (skills, competencies, experience, motivation, loyalty, staff wellbeing)
Social and relationships with stakeholders (community ties, brand trust, supplier
Relationship Capital relationships, social licence to operate)
environmental resources (water, land, minerals, ecosystems the organisation
Natural Capital
depends on or affects)
Content Elements of IR:

Organisational overview & What the organisation does, its ownership and operating structure,
external environment and the external environment it operates in
How the governance structure supports the organisation's ability to
Governance
create value in the short, medium and long term
How the organisation transforms inputs (the six capitals) through its
Business model
activities into outputs and outcomes
Key risks and opportunities affecting the ability to create value, and
Risks and opportunities
how the organisation responds
Strategy and resource Where the organisation wants to go, how it intends to get there, and
allocation how it will allocate resources
How the organisation performed against its strategy, including
Performance
effects on the six capitals
Challenges and uncertainties ahead and potential implications for
Outlook
the business model
What matters are included, how materiality was determined, and
Basis of preparation
how elements were quantified

B4d – Social and Environmental Impacts of Economic Activity


Describe and assess the social and environmental impacts that economic activity can have (in terms of
social and environmental ‘footprints and environmental reporting). [3]
Economic activity creates impacts beyond financial returns, referred to as an organisation's social and
environmental footprint.

− Environmental footprint — the total environmental impact of an organisation's activities, including:


Carbon emissions and greenhouse gases, Energy and water consumption, Land use and biodiversity
loss, Waste generation and pollution, Depletion of natural resources (links to Natural Capital in IR)

− Social footprint — the total impact of an organisation's activities on people and communities, including:
Employment conditions, health and safety, and labour rights, Impact on local communities (noise,
congestion, displacement), Supply chain practices (e.g. use of child labour, exploitation), Contribution to
public services and infrastructure
Why this matters for governance: the board is responsible for understanding and managing the
organisation's footprint. Failure to do so creates reputational, regulatory and financial risk. Stakeholders
increasingly expect companies to measure, disclose and reduce their footprint, reflected in ESG reporting,
GRI standards and TCFD disclosures.
Environmental reporting: organisations can report their environmental footprint through voluntary narrative
disclosures in the annual report. Standalone sustainability reports (using GRI standards). Carbon reporting
(mandatory for large UK listed companies). Integrated reporting (natural capital within the six capitals
framework)
Assessing the governance implications of failing to manage footprints:

● Regulatory risk — governments are increasingly legislating on environmental and social impacts (e.g.
mandatory carbon reporting, modern slavery statements, TCFD disclosures). Boards that fail to measure
and manage their footprint face growing compliance risk as the regulatory perimeter expands.

● Financial risk — environmental liabilities (e.g. contamination, carbon penalties) and social failures (e.g.
supply chain scandals) can crystallise into material financial losses that were invisible in traditional
financial reporting. Boards that ignore non-financial footprints are therefore also failing in their financial
oversight duty.
● Reputational risk — in an era of social media and ESG scrutiny, a single supply chain scandal or
environmental incident can cause lasting reputational damage disproportionate to the underlying event.
The board cannot manage what it does not measure.

● The governance gap — most board oversight frameworks are built around financial capital. The six
capitals framework exists precisely because natural, social and human capital were systematically
ignored by traditional reporting. A board that only monitors financial performance has a structural blind
spot that footprint reporting is designed to correct.

B4e – Internal Management Systems: EMAS and ISO 14000


Describe the main features of internal management systems for underpinning environmental and
sustainability accounting such as EMAS and ISO 14000. [2]
Internal management systems help organisations measure, manage and report on their environmental
performance.
ISO 14001 — an international voluntary standard for environmental management systems (EMS), applying
to any organisation globally regardless of size or sector. Provides a framework to identify and control
environmental impacts, set objectives and targets, monitor performance and continually improve. Certification
is awarded by an independent third party, signalling to stakeholders that the organisation takes environmental
management seriously. Public disclosure is not required and legal compliance is best practice rather than
mandatory.
EMAS (Eco-Management and Audit Scheme) — a voluntary EU scheme designed to go beyond ISO
14001, applying primarily to EU-based organisations. Requires organisations to produce a publicly available
environmental statement verified by an independent accredited verifier, comply with all relevant
environmental legislation, and actively involve employees in environmental management. Places significantly
greater emphasis on transparency, public disclosure and legal accountability than ISO 14001.

B4f – Audit of Integrated Reports


Examine how the audit of integrated reports can provide adequate assurance of the relevance and
reliability of to stakeholders. [2]
Unlike financial statements, IR is currently not subject to mandatory independent audit.
Why assurance matters for IR:

● IR contains both financial and non-financial information: stakeholders need confidence that non-
financial disclosures are reliable and not just 'greenwashing' for marketing purposes
● Assurance enhances the credibility and usefulness of the report to investors and other stakeholders

Levels of assurance:

Reasonable High level of confidence that the information is free from material misstatement —
assurance equivalent to a standard audit opinion
Limited Lower level — auditor concludes nothing has come to their attention to suggest the
assurance information is materially misstated (less rigorous than reasonable assurance)

Challenges of auditing IR:

● Non-financial information (e.g. human capital, social impact) is harder to measure and verify than
financial data
● No single mandatory global standard for IR assurance — different frameworks and levels of rigour
apply
● Subjectivity in determining materiality and measuring the six capitals makes verification difficult
Key point: The credibility of IR depends significantly on the quality of assurance provided. Limited assurance
is currently most common in practice, but stakeholder pressure is pushing towards reasonable assurance
over time.

Section B5 – The Board of Directors


B5a – Duties, Roles and Tone from the Top
Assess the duties and roles of directors and functions of the board (including setting a responsible ‘tone’
from the top and being accountable for the performance and impact of the organisation): [3]
Role and responsibilities of the board of directors

● Define the purpose, values and strategy of the company and identify key stakeholders
● Provide entrepreneurial leadership alongside prudent and effective controls to assess and manage risk
● Monitor and control the company's performance and activities
● Maintain effective dialogue with shareholders, particularly institutional investors
● Set the ethical tone of the organisation 'tone from the top' by modelling the values and behaviours
expected throughout the business. If the board behaves unethically, that culture permeates the whole
organisation.
● Demonstrate accountability to shareholders through: annual reports and audited financial statements; the
AGM where shareholders can question directors and vote on key resolutions; remuneration reports
subject to shareholder vote; and the ability of shareholders to remove directors. Without these
mechanisms, accountability exists in principle but not in practice.

Directors' Duties and Rights:

● Authority to manage the company, enter contracts, and delegate responsibilities


● Entitled to appropriate remuneration and as employees, are bound by service contracts/employment law
● Duty of care — must act with reasonable skill and competence
● Fiduciary duty — must act in the best interests of the company
● Must avoid conflicts of interest and disclose any personal interests
● Must not compete with the company
● Certain roles (e.g. CEO, Chairman) may have fixed-term contracts under the company's constitution

CEO Chairman
Leads the board of directors: Facilitates strong
Responsible for day-to-day management
relationships between executive and non-executive
and running of the business
directors
Ensures the board operates effectively and in the interests
Implements board decisions
of shareholders
Develops and manages strategy and risk Maintains communication with shareholders (e.g. AGM,
management processes annual report). Sets board agenda, regular meetings etc
Review’s organisational structure and Represents the company to investors and external
operational performance stakeholders

Why CEO and Chairman Must Be Separate: Concentration of both roles in one person creates a significant
governance risk. No single individual should have unchecked authority over both board decisions and
company operations. Separation ensures the chairman can objectively evaluate the CEO's performance.
The UK Corporate Governance Code specifically recommends separation. When one person holds both
roles, it is called a combined role and is generally considered poor governance practice.
B5b – Unitary vs Two-Tier Board Structures
Evaluate the case for and against unitary and two-tier board structures. [3]
Unitary Board: a single board of directors responsible for all aspects of the company. All directors share
equal legal status and collective responsibility. All equally accountable for all board decisions regardless of
position. Common in the UK, USA and Japan.
Two-Tier Board: separates oversight and management into two distinct boards:

● Supervisory Board — responsible for overall oversight. Made up entirely of NEDs. Has no executive
function. Reviews strategy and direction and safeguards stakeholder interests. Chaired by the
company chairman.
● Management (Operational) Board — responsible for day-to-day running of the business. Made up
of executive directors appointed by the supervisory board. Headed by the CEO.

Advantage Disadvantage



Faster decision-making; decisions do not
No true NED independence as working
have to pass between two separate
closely alongside executives over time
boards
creates familiarity that erodes objectivity

− better information flow between − NEDs may become too close to


Unitary executives and NEDs as they work executives and reluctant to challenge
closely together them



risk of groupthink where collective
collective responsibility means all
responsibility becomes a reason to avoid
directors are equally accountable for
dissent
board decisions

− Clear separation of oversight and


management: the supervisory board can − Slower decisions as matters must pass
challenge the operational board without between two boards, creating delays
being involved in the decisions it is

scrutinising
potential communication gap as the
supervisory board may not fully
Two-Tier − stronger NED independence as understand operational realities
supervisory board members have no

executive function
supervisory board may lack the detailed
operational knowledge needed to
− reduced conflict of interest between those scrutinise management decisions
running the business and those effectively
overseeing

B5c – Non-Executive Directors (NEDs)


Describe and assess the purposes, responsibilities and performance of Non-Executive Directors (NEDs).
[3]
Non-Executive Directors - members of the board but not part of day-to-day management. Provide
independent oversight, challenge and advice to executive directors. Usually part-time. Commonly sit on audit,
remuneration and nomination committees. Help balance potential conflicts between executives and
shareholders.

Role of NEDs Limitations of NEDs


Strategy contribute to successful strategy development and
● May lack detailed operational
constructively challenge strategic direction. Ensure the
company is operating effectively and to its full knowledge of the business.
potential. Bring external experience and independent ● May become too familiar with
perspective executives over time, losing
Scrutiny monitor performance of executive directors and ensure genuine independence
accountability to shareholders. Represent
● Part-time role means limited
shareholders interest and protect shareholder value.
time and access to
Risk ensure financial information is accurate and that information
effective risk management systems are in place
Provide advice to identify opportunities and risks ● May lack detailed operational
knowledge of the business
People
● Appointment process can be
determine executive remuneration and play a key role influenced by the CEO,
in appointments, removals and succession planning. undermining independence
Support independence of board committees ● Remuneration in shares can
compromise objectivity

NED independence is not absolute. A NED may be formally independent but still lack practical independence
if they are too close to executives, rely heavily on management information, have long tenure, receive
significant remuneration, hold share options, or were appointed through executive influence.
Measures to improve NED independence: transparent appointment process led by the nomination
committee, fixed terms, regular board refreshment, majority independent NEDs, access to independent
professional advice, sufficient induction and training, and avoiding remuneration structures that compromise
objectivity.

B5d – Induction, Performance Appraisal and CPD


Describe and assess the importance of induction, performance appraisal and the continuing professional
development of directors on the board. [3]

Importance
should include strategy briefings, management meetings, governance framework
overview and site visits. NEDs may defer to executive directors on substantive issues
Induction because they lack the contextual knowledge to push back if they haven’t been
inducted which makes them ineffective in practice, creating a false sense of
governance assurance.
Annual evaluation should cover performance against objectives, risk management
contribution, delegation effectiveness and director conduct. Without regular appraisal,
Board underperforming directors remain in post indefinitely, skills gaps go unidentified and
Appraisal the board gradually loses the capacity to provide effective oversight. Appraisal also
disciplines the board collectively. A board that never evaluates itself is unlikely to hold
management to account rigorously.

should cover emerging risks (cybersecurity, climate), regulatory changes and


CPD leadership development. Without CPD, directors make decisions based on outdated
(continuous knowledge. A director appointed for their expertise in 2015 may be ill-equipped to
professional oversee cybersecurity risk or climate disclosure obligations in 2025. In a rapidly
development) changing environment, knowledge decay is a genuine governance risk and one that is
largely invisible until a crisis exposes it.

B5e – Board Diversity


Explain the meaning of ‘diversity’ and critically evaluate issues relating to diversity on the board of directors.
[3]
Diversity refers to having a range of different people on the board in terms of gender, ethnicity, age,
professional background, skills, experience and ways of thinking.
Why diversity matters:

● Reduces groupthink — a homogeneous board is more likely to reach consensus without adequate
challenge
● Broader range of perspectives improves the quality of strategic decision-making and better reflects
the company's stakeholder base (customers, employees, communities)
● Increasingly expected by institutional investors and reflected in ESG assessments
● Linked to concepts of good governance — fairness and independence

Arguments for diversity targets / quotas:

● Voluntary approaches have been slow to deliver change — targets create accountability
● Evidence suggests more diverse boards perform better
● Sends a clear signal that the company takes diversity seriously

Arguments against diversity targets / quotas:

● Risk of appointing directors to meet a target rather than on merit and targets may create a perception
that certain directors are token appointments
● Board composition should be driven by skills and experience, not demographics
● 'Diversity of thought' (cognitive diversity) matters more than demographic diversity alone

The UK Corporate Governance Code and the ICGN both encourage board diversity. The nominations
committee is responsible for ensuring the board has an appropriate mix and for addressing identified gaps.

B5f – Board Committees


Assess the importance, roles, purposes and accountabilities of the main board committees in respect of
effective governance: [3]
The UK Corporate Governance Code requires three main committees, with a fourth optional:
Remuneration Committee — comprised entirely of NEDs to ensure independence:

● Determines remuneration policy on behalf of the board and shareholders to prevents executive
directors from influencing their own pay
● Sets pay structures (e.g. basic salary, performance-related pay, bonuses) and defines conditions &
timing for performance-related rewards
● Ensures directors are fairly but responsibly rewarded & reports remuneration decisions to
shareholders in the annual report

Nominations Committee — responsible for ensuring the board has the right balance, structure and
composition:

● Balance between executive directors and independent NEDs & the size and structure of the board
● Assesses the Leadership needs of the organisation for succession planning & continuity
● Skills Audit identifies the skills, knowledge and experience required by the board. Assesses whether
the current board has the appropriate balance. Can highlight gaps and inform training or recruitment
decisions.
Audit Committee — made up of at least three NEDs (excluding the chairman), with at least one member
having relevant financial experience:
● Monitors the integrity of financial statements & reviews internal controls (financial, operational and
compliance) and risk management systems
● Reports to shareholders at least annually and oversees the effectiveness of the internal audit function
● Recommends appointment and remuneration of external auditors & monitors external auditors'
independence, objectivity and effectiveness
● Appointments typically for 3 years, extendable up to two additional 3-year terms, subject to continued
independence

Risk Committee (Optional):

● Ensures key risks are identified, assessed and managed appropriately - requires regular reporting
systems across the organisation
● Ensures important risk-related information is escalated to the board
● May operate as a separate committee or as part of the audit committee

B5g – General Principles of Remunerating Directors


Describe and assess the general principles of remunerating directors and modifying directors’ behaviour to
align with stakeholder interests: [3]
The role of the remuneration committee is to attract, retain and motivate directors of sufficient quality to run
the business. As agents of the company, directors should always act in the best interests of the company;
remuneration structures should reinforce this.
Performance measures should be: (1) Identifiable and not easy to manipulate (2) Focused on long-term
success rather than short-term metrics such as annual profit or EPS (3) Aligned with shareholder interests to
reduce the agency problem
Components of a remuneration package:

● Basic salary and benefits in kind (private medical insurance, company cars)
● Performance-related pay and bonuses
● Share option schemes - link to performance over the long term. Subject to prior shareholder approval.
Their operation, rationale and cost should be fully explained so shareholders can make an informed
judgement.
● Pension entitlements — should be dealt with carefully as they can be a major cost not linked to
performance

Evaluating whether remuneration structures succeed in modifying director behaviour:


Where they work: long-term incentive plans (LTIPs) tied to multi-year performance metrics and share price
genuinely align executive interests with shareholder value over time, particularly when combined with
clawback provisions that remove the reward if performance is later found to have been misstated.
Where they fail:

● short-termism — bonus structures linked to annual earnings can incentivise directors to maximise
near-term profit at the expense of long-term value (e.g. cutting R&D, deferring maintenance,
aggressive accounting.

● gaming — Directors may manage performance measures rather than create genuine value. E.g. if
bonuses are linked to EPS, directors can increase EPS through share buybacks, reducing the
number of shares without improving underlying profits or business performance.

● The fundamental tension — remuneration is the primary tool for aligning agent and principal
interests, but the remuneration committee itself is composed of NEDs who were often appointed
through a process influenced by the executives whose pay they are setting. Genuine independence
is structurally difficult to guarantee.

B5h – Regulatory, Strategic and Labour Market Issues in Directors' Remuneration


Explain and analyse the regulatory, strategic and labour market issues associated with determining
directors’ remuneration. [3]
Regulatory issues:

● The remuneration committee must produce a remuneration report disclosed in the annual report -
shareholders vote on this (advisory vote in the UK) giving them a direct check on executive pay
● The UK Corporate Governance Code requires remuneration to be linked to long-term performance
and discourages rewards for failure
● Clawback provisions — regulators and governance codes increasingly require that bonuses can be
reclaimed if performance targets were based on misstated figures or if misconduct is later discovered

Strategic issues:

● Remuneration must support the company's long-term strategy — pay structures that reward short-
term profit can incentivise decisions that harm long-term value
● Long-term incentive plans (LTIPs) are designed to align director behaviour with long-term strategic
objectives
● Remuneration should reflect the risk appetite of the organisation — excessive risk-taking incentivised
by short-term bonuses is a governance failure

Labour market issues:

● Directors operate in a global labour market — remuneration must be competitive enough to attract
and retain talent
● Benchmarking against comparable roles is used to justify pay levels, but can create a ratchet effect
where pay continuously rises
● The gap between executive pay and average employee pay is increasingly scrutinised by
stakeholders and the media — reputational risk if seen as excessive and pressure from institutional
investors to justify

Section B6 – Public Sector Governance


B6a – Forms of Organisation
Discuss public sector, private sector, charitable status and non-governmental (NGO and quasi-NGOs)
forms of organisation, including agency relationships, stakeholders’ objectives and performance criteria. [2]

Key Performance
Description Agency Relationship
Stakeholders Criteria
Run by the state. Delivers
Managers (agents) Taxpayers,
public goods/services that Three Es —
accountable to service users,
Public cannot or should not be economy,
government/taxpayers government,
sector provided by for-profit efficiency,
/citizens ((principals) employees,
businesses. e.g. NHS, effectiveness
who fund and use it lobby groups,
HMRC
Shareholders,
Profit,
Exists to generate profit for Directors (agents) customers,
Private shareholder
shareholders. Operates in accountable to employees,
sector value, return on
competitive markets shareholders (principals) suppliers,
investment
regulators,
Achievement of
Provide support or raise Trustees (agents) Donors,
charitable
funds for those in need. accountable to donors, beneficiaries,
Charities objectives;
Overseen by a board of beneficiaries and regulators,
efficient use of
trustees regulators (principals) employees,
donations
Neither exist to make a Leadership accountable Members,
Mission
profit nor deliver a service to members, donors and donors,
NGOs achievement;
on behalf of the state e.g. the communities they governments,
social impact
Red Cross serve communities,
Value for
Management Government,
Funded by government but money; delivery
QuANGO accountable to public,
operate independently of government
s government (funder) and regulated
e.g. Environment Agency policy
the public (beneficiary) industries
objectives

B6b – Strategic Objectives, Leadership and Governance: Public vs Private Sector


Assess and evaluate the strategic objectives, leadership and governance arrangements that are specific to
public sector organisations as contrasted with the private sector. [3]

Public Sector Private Sector


deliver public value, meet social needs maximise shareholder value and profit, with
Primary
and achieve policy objectives growth, market share and competitive
Objective
(economy, efficiency and effectiveness) advantage as secondary objectives.
government, taxpayers and citizens shareholders through market mechanisms;
Policy direction is set by elected poor performance results in falling share
Accountabilit
ministers and politicians, with price, takeover risk or loss of customers.
y to
professional managers responsible for Strategy is set by the board of directors and
implementation. implemented by the CEO.
overseen by government departments, regulated by corporate governance codes
Governance regulators and public audit bodies such and market discipline.
as the National Audit Office.
Performance non-financial terms (service quality, primarily on financial terms; profit, EPS
is measured accessibility and social impact) as well (earnings per share) and return on equity.
by as cost (the three E’s)
low as public funds must be protected
variable as shareholders accept risk in
Risk Appetite and failure carries political
exchange for returns.
consequences.
high, with organisations subject to
Disclosure is mandatory to shareholders but
Transparency freedom of information requests and
voluntary beyond that.
public scrutiny.
governance is driven by the market;
governance relies on democratic
Key poor performance results in falling
accountability, regulation and audit because
difference share price, takeover risk or loss of
market mechanisms do not apply.
customers

B6c – Democratic Control, Political Influence and Policy Implementation


Explain democratic control, political influence and policy implementation in public sector organisations. [3]
Democratic control — in the private sector, shareholders own the company and ultimately call the shots. In
the public sector, citizens play that role indirectly.
Citizens vote for politicians, politicians set government policy, and public sector managers have to deliver it.
This means a hospital manager or a school headteacher cannot just decide their own objectives, they have
to follow what the government tells them, even if they professionally disagree. Their boss is ultimately the
taxpayer, via a long chain of accountability.
Political influence — because public sector organisations are run by governments, politics bleeds into
management decisions in a way it never would in a private company.
Three practical problems arise from this:
1. Short-termism: Decisions get made to win votes rather than because they are the best long-term
solution.
2. Conflicting Priorities: Government changes bring new policies forcing public sector to change strategies
overnight
3. Scrutiny: unlike private sector, public sector managers face constant pressure and scrutiny from the
public and media since there are taxpayer’s funds being used
Policy implementation — Government announces the policy but managers who have to practically
implement it often lack resources or are given conflicting instructions. Additionally, when targets are set,
managers naturally focus on hitting the target rather than the underlying objective. E.g. a hospital emergency
room given a target of four-hour maximum waiting times may rush patients through without thorough
diagnosis or adequate care.
When things go wrong, politicians blame the managers for poor implementation, while managers blame
politicians for unrealistic policy so accountability becomes blurred.

B6d – The Three Es and Public Value


Discuss obligations of public sector organisations to meet the economy, effectiveness and efficiency (the 3
E’s) criteria and promote public value. [3]
Public sector organisations are assessed against value for money measured by The Three Es:

Obtaining inputs at the lowest cost consistent with acceptable quality — 'spending less',
Economy:
e.g. Procuring medical supplies at the lowest cost
Getting the maximum output from given inputs — 'spending well' e.g. Treating the most
Efficiency:
patients per pound spent
Effectiveness Achieving the intended outcomes and objectives — 'spending wisely' e.g. Reducing
: waiting times and improving patient outcomes

All three must be balanced; an organisation that is economical and efficient but fails to achieve its objectives
is not delivering value for money.
Public value goes beyond the three Es. It refers to the broader benefit that public sector organisations create
for society as a whole. It includes:

● Direct services — Public sector organisations exist to deliver services to citizens that the private
sector either cannot or should not provide (healthcare, education, roads, defence)

● Trust and legitimacy — Public institutions only work if citizens trust them. E.g. If people don't trust
the police, they don't report crimes. If people don't trust the NHS, they don't seek treatment early. It
can be destroyed by scandal or poor governance

● Wider social and economic benefits — These are spillover benefits that go far beyond the direct
service being delivered e.g. a well-educated population produces more economic growth. A healthy
workforce is more productive. Good infrastructure attracts investment.
Public value cannot be measured by financial performance alone. It requires assessment of social outcomes,
citizen satisfaction and the long-term wellbeing of communities. This is why integrated reporting and non-
financial performance measurement are increasingly relevant to the public sector.
C – Strategy
C1 – Concepts of Strategy
C1a – The Fundamental Importance of Strategy
Explain the fundamental importance of strategy and strategic decisions within different organisational
contexts. [2]
Strategy and strategic decisions determine the long-term direction and scope of an organisation.
Organisation’s success and viability depend on its strategy. Without a clear strategic direction, resources are
misallocated and the organisation cannot respond effectively to its environment.
Strategic decision-making covers six areas:

● Adapting activities to fit the environment


● Defining the scope of the organisation
● Exploiting unique resources and special competences
● Gaining a competitive advantage
● Meeting the values and expectations of stakeholders
● Selecting long-term direction — how we compete

C1b – Johnson, Scholes and Whittington: The Strategic Management Model


Apply the Jhonson, Scholes and Whittington model of strategic management – strategic analysis, strategic
choices and strategic implementation. [3]
Johnson, Scholes and Whittington (JSW) describe strategic management as a continuous process of three
interconnected elements:

Element What it involves Key tools


Understanding the strategic position of the
Strategic PESTEL, Porter’s Five Forces,
organisation; its environment, capabilities
Analysis SWOT, Mendelow’s Matrix
and stakeholder expectations.
Identifying, evaluating and selecting strategic Ansoff Matrix, BCG Matrix, Porter’s
Strategic Choice
options available to the organisation Generic Strategies, SAF criteria
Putting the chosen strategy into practice; Change management,
Strategic
organising resources, managing change and organisational structure, resource
Implementation
embedding the strategy allocation

The model assumes strategy is deliberate and rational, but emergent strategies often arise organically from
everyday decisions. While analysis must precede choice, the three stages are cyclical rather than linear;
implementation regularly feeds new insights back into earlier stages, and since strategies most often fail at
execution, this forces a return to environmental analysis.
Strategic choice must be evaluated using the SAF criteria, is the strategy
o Suitable (does it address the strategic position?)
o Acceptable (to stakeholders in terms of risk and return?), and
o Feasible (can it be delivered with available resources?)
Levels of strategy:

⮚ Corporate level: overall purpose and scope of the organisation; how value is added to different parts.
Requires long-term external information.
⮚ Business level: how to compete successfully in a particular market. Requires a mix of long and medium-
term external and internal information.
⮚ Operational level: how components of the organisation deliver effectively. Requires shorter-term internal
information.
Strategy can be created in three ways:

Strategy as design Strategy as experience Strategy as ideas

treats it as a rational, top-down draws on what has worked sees strategy emerging bottom-up from
process where senior managers before; iterative and shaped across the organisation, driven by staff
exclusively analyse, evaluate by culture and past innovation, requiring trust, freedom to
and decide success. fail, and time.

C2 – Environmental Issues
C2a – PESTEL Analysis
Assess the macro-environment of an organisation using appropriate models such as PESTEL. [3]
PESTEL is used to assess the macro-environment of an organisation. These factors are largely outside the
organisation’s control. Organisations must identify which factors are most significant as key drivers of change
and ensure their strategy is positioned to address them.

Factor Examples Strategic implication


Government policy, public spending, road Changes in government priorities can
Political
pricing, wars, trade agreements create or remove markets overnight
Interest rates, inflation, exchange rates, Economic downturns reduce demand;
Economic
unemployment, economic growth, taxation interest rate rises increase cost of capital
Lifestyle trends, consumer attitudes, Shifting demographics change customer
Social population demographics, ethnic and bases; social attitudes affect brand
religious factors perception
Wireless networks, e-business, intellectual Disruptive technology can make existing
Technological
property, global communication, AI products or business models obsolete
Climate change, renewable resources, Environmental regulation and consumer
Environmental greenhouse gas emissions, natural expectations increasingly constrain
resource depletion strategy
Employment law, competition law, health Non-compliance creates fines,
Legal and safety, data privacy, environmental reputational damage and loss of
regulation operating licences

Not all PESTEL factors carry equal weight; key drivers are those with both high likelihood and high impact,
and will be organisation and industry-specific.
Factors also interact; a single political decision can simultaneously carry economic, environmental and legal
implications, making some drivers interdependent.
For a complete environmental assessment, PESTEL should be used alongside Porter's Five Forces, which
covers industry-level competitive dynamics where PESTEL only covers the macro-environment.

C2b – Strategic Drift


Assess the implications of strategic drift. [3]
Strategic drift occurs where strategies progressively fail to address the strategic position of the organisation
and performance consequently deteriorates. It happens gradually rather than through a single dramatic
failure.
Why strategic drift occurs:
• Managers are often unable to see beyond the current organisational culture, especially in
environments where there has been little change and long periods of stability.
• Past success creates overconfidence; strategies that worked previously are continued even as the
environment changes around them.
• Incremental change feels safer than strategic transformation; organisations make small adjustments
rather than the fundamental rethinking the environment demands. As strategic drift is invisible in its
early stages, small changes feel appropriate until the cumulative gap becomes impossible to close.
• Culture compounds this; deeply embedded assumptions about "how we do things here" resist the
changes needed to realign with a shifting environment.
Governance implication: the board is responsible for identifying strategic drift before it reaches the flux stage.
This requires genuine independence and willingness to challenge management's strategic assumptions,
which is why NED independence and board diversity matter.
Stages of strategic drift:

⮚ Incremental change: the organisation makes small adjustments that broadly keep pace with
environmental change. Strategy remains broadly aligned.
⮚ Strategic drift begins: the pace of environmental change accelerates but the organisation’s strategy
continues to change only incrementally. A growing gap opens between strategy and environment.
⮚ Flux: poor performance becomes visible. The organisation recognises the problem but struggles to
respond, often trying multiple initiatives simultaneously without coherent direction.
⮚ Transformational change or death: the organisation either makes a fundamental strategic
transformation or fails entirely. Many organisations at this stage are acquired, restructured or cease to
exist.

C2c – External Key Drivers of Change


Evaluate the external key drivers of change likely to affect the structure of a sector or market.[3]
Key drivers of change are the PESTEL factors most likely to change the structure and competitive dynamics
of an industry or a market.
How to identify key drivers:
Assess which factors have the highest potential impact on the industry’s structure and competitive dynamics
or are most uncertain; high impact combined with high uncertainty defines the most strategically significant
drivers. Also consider how drivers interact e.g. technological disruption combined with changing social
attitudes can be far more powerful than either driver in isolation

Driver type Example Structural impact


Streaming services Eliminates entire segments of the value
Technological disruption replacing physical chain; creates new entrants with no legacy
media costs
GDPR data privacy Raises compliance costs; creates barriers to
Regulatory change
regulation entry for smaller players
Ageing population in Shifts demand patterns; creates new markets
Demographic shift
developed economies and reduces others
Carbon pricing and net Strands assets in carbon-intensive industries;
Climate and sustainability
zero commitments creates new markets in clean energy
Globalisation/deglobalisatio Supply chain reshoring Changes cost structures and competitive
n post-COVID dynamics across entire industries
Identifying drivers is necessary but insufficient; the board must assess how quickly each driver will have
impact and whether the organisation’s current strategy is robust to these changes. Drivers that appear
gradual can accelerate suddenly e.g. COVID-19 compressed a decade of digital adoption into months.
Organisations that had not ide notified digital disruption as a key driver were caught entirely unprepared.

C2d – Porter’s Diamond: National Competitiveness


Apply Porter’s Diamond to explore the influence of national competitiveness on the strategic position of an
organisation. [3]
Porter’s Diamond explains why some countries are more successful than others in particular industries
(factors which give them a national and geographical advantage). The four elements are interlinked; a
weakness in one undermines the others.

Climate, land, raw materials, labour, skills, education, infrastructure, knowledge


Factor conditions and technology e.g. Germany’s engineering education system supports its
automotive industry
Domestic market demand drives innovation, quality improvement and growth
Demand conditions e.g. Japanese consumers’ high expectations for electronics drove Sony and
Toyota’s global competitiveness
Related &
A cluster of industries that help produce the specific product or service e.g.
supporting
Silicon Valley’s concentration of tech firms, universities and venture capital
industries
Local conditions affect strategy; intense domestic competition drives innovation
Strategy, structure
and upgrading of competitive advantage e.g. Italy’s competitive fashion industry
and rivalry
is driven by intense rivalry between domestic firms

Governments can stimulate the diamond through improved performance standards, acting as a customer to
increase demand, enforcing competition laws to stimulate rivalry, and investing in universities, infrastructure
and R&D. Factor disadvantages can also drive innovation; resource scarcity forces efficiency, as seen in
Japan's lean manufacturing.
The diamond applies most clearly to manufacturing. In digital and service industries, national location is less
determinative of competitive advantage. Globalisation further weakens its explanatory power, as firms can
access factor conditions, demand and supporting industries from anywhere, reducing the advantage
conferred by national location.

C2e – Scenario Planning


Assess scenarios reflecting different assumptions about the future environment of an organisation. [3]
Scenario planning involves constructing pictures of possible future environments, based on different
assumptions about how key drivers of change will develop. It is used when the future is too uncertain for a
single forecast to be reliable.
How to build scenarios:

⮚ Identify the two or three most significant and most uncertain key drivers of change
⮚ Define the extreme positions for each driver (e.g. high regulation vs low regulation; rapid
technological change vs slow)
⮚ Combine these into a small number of distinct, plausible future scenarios — typically three to four
⮚ For each scenario, assess the implications for the organisation’s strategy, competitive position
and resource requirements
⮚ Identify strategic options that are robust across multiple scenarios (‘no-regret moves’) and those
that only make sense under specific scenarios
Importance of scenario planning
It forces the board to consider futures that challenge their assumptions, not just project current trends forward.
It identifies strategic options that are resilient across a range of futures, reducing the risk of being caught
unprepared by an unexpected development. It encourages strategic flexibility; organisations that have
planned for multiple scenarios can respond faster when the environment shifts.
Scenario planning is only as good as the scenarios constructed; if the scenarios do not genuinely challenge
assumptions or if they converge around a preferred future, the exercise provides false comfort rather than
real insight. Scenario planning is resource intensive and requires significant management time and expertise.
Smaller organisations may struggle to conduct it rigorously.

C3 – Competitive Forces
C3a – Porter’s Five Forces
Evaluate the sources of competition in an industry or sector using Porter’s Five Forces framework. [3]
Porter’s Five Forces explains why some industries are more profitable than others. The five forces determine
the microenvironment and affect an organisation’s ability to serve customers and make a profit. A significant
change in any force requires a reassessment of competitive strategy.

Force What determines it Strategic implication


Barriers to entry: patents, economies of High barriers protect profitability; low
Threat of new
scale, brand equity, switching costs, capital barriers invite competition that erodes
entrants
requirements, access to distribution margins
Buyer propensity to substitute, substitute
Threat of Close substitutes cap the prices an
performance, switching costs, product
substitutes industry can charge
differentiation
Bargaining Number of suppliers, degree of input Powerful suppliers extract value from
power of differentiation, presence of substitute the industry through higher input
suppliers inputs, cost of switching supplier prices
Bargaining
Buyer volume, availability of substitutes, Powerful customers force prices down
power of
buyer price sensitivity, buyer concentration and demand higher quality or service
customers
Competitive Number of competitors, rate of industry Intense rivalry drives down prices and
rivalry growth, product differentiation, exit barriers margins across the industry

The model treats all competitors as equal, in practice, different competitors have very different strategic
positions and capabilities within the same industry. It focuses on competition rather than collaboration; value
networks and strategic alliances mean that suppliers, customers and even competitors can be partners as
well as adversaries.
Use alongside PESTEL. Five Forces analyses the industry structure; PESTEL analyses the broader macro-
environment that shapes that structure.

C3b – Customers and Market Segmentation


Analyse customers and markets including market segmentation. [2]
Market segmentation looks at the wider market, while customer segmentation focuses on the organisation’s
existing customer base using internal customer data.
Market segmentation is the process of dividing a broad market into distinct subgroups of customers who have
common needs, characteristics or behaviours, and who will respond similarly to a marketing strategy.
Segmentation can be based on:

● Demographic: Age, gender, income, occupation, family size e.g. A bank offering different products to
students, working adults and retirees
● Geographic: Country, region, urban vs rural, climate e.g. A clothing retailer stocking heavier fabrics
in colder regions
● Psychographic: Lifestyle, values, attitudes, personality e.g. A car manufacturer targeting
environmentally conscious buyers with an EV range
● Behavioural: Purchase occasion, loyalty, usage rate, benefits sought e.g. An airline offering
loyalty programmes to frequent business travellers
Why segmentation matters strategically:

⮚ Allows organisations to target resources at the most profitable segments


⮚ Enables differentiation: by understanding specific segment needs, the organisation can tailor its offering
to create greater value for that segment
⮚ Informs the Ansoff matrix: market development involves identifying new segments for existing products;
market penetration requires understanding which segments to prioritise

C3c – Porter’s Value Chain


Apply Porter’s value chain to assist organisations to identify value adding activities in order to create and
sustain competitive advantage. [2]
The value chain breaks an organisation down into its individual activities and examines each one separately
to see which create value for the customer and which drive up costs. Competitive advantage comes from
performing these activities more efficiently or distinctively than competitors.

Activity type Activities


Inbound logistics (receiving and storing inputs)
Primary activities
Operations (converting inputs into the final product) e.g. Manufacturing
(directly create the
Outbound logistics (delivering the product to the customer) e.g. distribution
product/service)
Marketing and sales (generating demand) e.g. after-sales support

Procurement (purchasing inputs) e.g. supplier management


Support activities
Technology development (R&D, process improvement)
(enable primary
Human resource management (recruiting, training, rewarding staff),
activities)
Firm infrastructure (finance, legal, management) e.g. IT systems

To effectively apply the value chain


• identify which activities create the most value for customers: these are the activities the organisation
should invest in and protect.
• Identify which activities are performed below industry standard: these are candidates for
improvement or outsourcing
• Look for linkages between activities: improving one activity often creates value in another (e.g. better
procurement reduces operations costs)
• Link to competitive advantage: an organisation pursuing cost leadership should focus on eliminating
cost from every activity; an organisation pursuing differentiation should invest in the activities that
create distinctiveness

C3d – Value Networks


Advise on the role and influence of value networks. [3]
A value network extends the value chain concept beyond a single organisation to include the entire system
of organisations that collaborate to create value for the end customer. No organisation creates value in
isolation; value is created through relationships with suppliers, distributors, partners and even competitors.
Key features of value networks:
⮚ Organisations in the network are interdependent: the quality of the end product depends on every
participant in the network performing effectively
⮚ Value can be created or destroyed at any point in the network: a weak supplier or a poor distribution
partner undermines the value created by the focal organisation
⮚ Relationships within the network can be a source of competitive advantage: exclusive supplier
relationships, preferential distribution agreements or platform ecosystems create advantages that
competitors cannot easily replicate
Strategic implications:
• outsourcing a non-core activity is only beneficial if the external provider adds more value than the
organisation would internally
• Digital platforms create new value network dynamics: Amazon, Uber and Airbnb are value networks
where the platform connects participants rather than directly producing the product or service
• Supply chain resilience — COVID-19 demonstrated that disruption anywhere in a value network
affects the entire system; organisations must map and manage network dependencies, not just their
own internal activities
Value networks increase complexity. The more extended the network, the harder it is to monitor quality,
manage risk and protect intellectual property. Dependence on network partners creates vulnerability. If a
critical supplier fails or a key distribution partner is acquired by a competitor, the entire strategy can be
undermined.

C3e – Opportunities and Threats from the Competitive Environment


Evaluate the opportunities and threats posed by the competitive environment of an organisation. [2]
Evaluating the competitive environment requires synthesising the outputs of PESTEL, Five Forces and value
chain analysis to identify the most significant opportunities and threats facing the organisation.

Source Opportunities Threats


New markets opened by regulatory change; Regulatory tightening; economic downturn
PESTEL
technology enabling new products/lower costs reducing demand; technological disruption
Five Weakening competitor rivalry; declining New entrants; increasing supplier power;
Forces substitute threat; reduction in buyer power growing substitute threat
Value New partnership opportunities; digital platform Supplier consolidation; distributor
network access; supply chain improvements disintermediation; partner failure

Opportunities and threats are only meaningful in the context of the organisation’s specific capabilities. An
opportunity that the organisation lacks the resources to exploit is not a real opportunity; a threat the
organisation is uniquely positioned to withstand is not a significant threat. This is why external and internal
analysis (SWOT) must always be combined.

C4 – Internal Resources, Capabilities and Competences


C4a – Strategic Capability
Identify and evaluate an organisation’s strategic capability, its threshold resources, threshold competences,
unique resources and core competences. [3]
Strategic capability refers to the resources and competences an organisation needs to survive and prosper.
It determines what the organisation can do and therefore which strategies are feasible.

Concept Definition Example


The minimum resources needed to exist in a A law firm must have qualified
Threshold
market: without these the organisation cannot solicitors; a hospital must have
resources
compete at all medical equipment
The minimum activities and processes needed A retailer must be able to process
Threshold
to meet customer requirements: below this payments and manage stock
competences
standard the organisation loses customers reliably
Resources that are rare, difficult to imitate and A patented drug formula; a prime
Unique
provide competitive advantage above the city centre location; a proprietary
resources
threshold level algorithm
Activities and processes that are performed at Apple’s product design capability;
Core
a level that is difficult for competitors to imitate Toyota’s lean manufacturing
competences
and that deliver competitive advantage system; Amazon’s logistics

Threshold capabilities are necessary but not sufficient. Meeting the minimum standard keeps the organisation
in the market but does not create competitive advantage. Sustained advantage comes from unique resources
and core competences. Core competences can become core rigidities; capabilities that drove past success
can blind organisations to the need to develop new ones. The VRIN framework tests whether a resource or
competence is a genuine source of sustainable competitive advantage, it must be Valuable, Rare, Inimitable
(hard to copy) and Non-substitutable.
6Ms to assess internal resource constraints:

● Money: finance available, cost of capital, gearing, ability to raise funds


● Machinery: technology, equipment, capacity and risk of obsolescence
● Manpower: skills, efficiency, staffing levels, succession and labour turnover
● Markets: strength of current markets, emerging markets and brand position
● Materials: cost, availability, supplier power and resource depletion
● Make-up: organisational structure and culture, including whether they support or limit growth
Exam use: use this as a quick checklist when assessing whether a strategy is feasible.

C4b – Capabilities Required to Sustain Competitive Advantage


Discuss the capabilities required to sustain competitive advantage. [2]
Sustaining competitive advantage requires capabilities that competitors cannot easily replicate. The VRIN
framework identifies the characteristics that make a capability sustainable:

Characteristic Meaning Why it matters


The capability creates value for A capability that customers do not value cannot
Valuable
customers or reduces costs generate competitive advantage
The capability is not widely If all competitors have the same capability, it is a
Rare
held by competitors threshold competence, not a source of advantage
The capability is difficult for Imitable capabilities are only temporary advantages;
Inimitable
competitors to copy competitors will replicate them
If a competitor can achieve the same outcome
Non- There is no equivalent
through a different route, the advantage is
substitutable capability that could replace it
undermined

Capabilities are hard to imitate for three reasons: (1) capabilities built from many interdependent activities
are harder to replicate than a single skill (2) capabilities built over years of experience cannot be acquired
overnight
(3) when it is unclear exactly what creates the advantage, competitors cannot effectively target their imitation

C4c – Organisational Knowledge and Strategic Capability


Discuss the contribution of organisational knowledge to the strategic capability of an organisation. [2]
Organisational knowledge is a critical component of strategic capability. It exists in two forms:

Type Definition Implication


Knowledge that can be written down,
Explicit Easier to share but easier for competitors to
codified and transferred; manuals,
knowledge replicate or acquire
processes, data
Knowledge embedded in people’s skills, Harder for competitors to imitate; form of
Tacit
experience and judgment that is difficult unique resource and a more durable source
knowledge
to articulate or transfer of competitive advantage

Knowledge loss through staff turnover is a strategic risk; when experienced employees leave, they take tacit
knowledge with them. Knowledge management systems attempt to convert tacit knowledge into explicit
knowledge but this conversion is imperfect and the richest competitive advantages often remain tacit.

C4d – SWOT Analysis


Identify and evaluate the strengths and weaknesses of an organisation and formulate an appropriate SWOT
analysis. [2]
SWOT synthesises the outputs of internal analysis (strengths and weaknesses) and external analysis
(opportunities and threats) into a single framework that informs strategic choice.

Strengths Weaknesses
Internal capabilities and resources that provide areas where the organisation underperforms
competitive advantage relative to competitors

Opportunities Threats
Externa
external developments the organisation external developments that could harm the
l
can exploit organisation’s competitive position
Positive Negative

A long SWOT list is not useful; identify the three to four most significant factors in each quadrant. Match
strengths to opportunities; these combinations indicate where the most attractive strategic options lie. Convert
weaknesses into strengths before pursuing opportunities that require them. Use strengths to mitigate threats;
identify which existing strengths can be deployed defensively.
Limitation: SWOT is only as good as the analysis that feeds it. A SWOT produced without rigorous PESTEL,
Five Forces and capability analysis will reflect management assumptions rather than strategic reality.

C5 – Strategic Choices
C5a – Strategic Options
Assess and advise on the different strategic options available to an organisation. [3]
The available options are Market development, Diversification, Market penetration or Product development
or Withdrawal / divestment (see C5e)
Having chosen a direction, the organisation must choose how to pursue it:

⮚ Organic growth: build internally. Slower but preserves culture and control. Lower risk.
⮚ Acquisition: buy an existing business. Faster but expensive and integration risk is high.
⮚ Strategic alliance / joint venture: share resources and risk with a partner. Useful where neither party
has the full capability alone.
For multi-product or multi-service organisations, the BCG matrix guides resource allocation across the
portfolio: investing in Stars, milking Cash Cows, resolving Question Marks, and exiting Dogs.
Strategic options are assessed using the SAF criteria:
Criterion Question it answers How to assess
Does the strategy address the
Does it exploit opportunities, build on strengths,
Suitability strategic position identified in the
address weaknesses and mitigate threats?
analysis?
Is the strategy acceptable to key What are the financial returns? What risks does
Acceptabilit
stakeholders in terms of risk and it introduce? How will shareholders, employees
y
return? and regulators respond?
Can the strategy be delivered with the
Does the organisation have the financial, human
Feasibility resources and competences
and operational capability to implement it?
available?

*Organisations overestimate their ability leading to implementation failure. *

C5b – Diversification: National, Multinational and Global


Assess the opportunities and potential problems of pursuing different strategies of product/market
diversification from a national, multinational and global perspective. [3]
Diversification involves moving into new products or new markets. It can be pursued at different geographic
scales, each with distinct opportunities and risks.

Level Description Opportunities Risks


Leverage existing brand and
Diversifying within Limited growth potential; may
National distribution; reduce dependence
the domestic market cannibalise existing business
on single product/market
Complexity of managing
Operating in multiple Access new markets; spread
Multinationa across cultures and
countries with locally risk across geographies; exploit
l regulations; currency risk;
adapted strategies cost advantages
political risk
Treating the world as
Ignores local differences;
a single market with Economies of scale; consistent
Global regulatory barriers; cultural
a standardised brand; efficiency in operations
mismatch
strategy

Related vs unrelated diversification:

● Related diversification — moving into areas that share resources, capabilities or markets with the
existing business. Lower risk as the organisation leverages existing strengths.
● Unrelated diversification — moving into entirely new areas with no connection to the existing business.
Higher risk but potentially higher reward; used to spread risk or exploit financial synergies.

C5c – The 7 Ps, Price-Based Strategies, Differentiation and Lock-In


Advise on how the 7 P’s, price-based strategies, differentiation and lock-in can help an organisation sustain
its competitive advantage. [3]
These are the tools through which organisations sustain competitive advantage at the market level.
The 7 Ps of the Marketing Mix

⮚ Product: Differentiation through product design and innovation e.g. Features, quality, branding,
packaging
⮚ Price: Positioning relative to competitors; margin management e.g. Pricing strategy, discounts,
payment terms
⮚ Place: Accessibility and convenience as competitive advantage e.g. Distribution channels, logistics,
market coverage
⮚ Promotion: Building brand awareness and customer loyalty e.g. Advertising, PR, sales promotion,
digital marketing
⮚ People: Service differentiation; tacit knowledge as competitive advantage e.g. Staff skills, culture,
customer service
⮚ Process: Operational excellence; reducing cost while maintaining quality e.g. How the service is
delivered; efficiency and consistency
⮚ Physical evidence: Managing customer perception, particularly in service industries e.g. Tangible
cues of service quality (premises, uniforms, packaging)
Price-Based Strategies

● Cost leadership: compete on price by achieving the lowest cost base. Requires efficiency across the
value chain. Sustainable only if the cost advantage is based on unique resources or scale that
competitors cannot easily replicate.
● Hybrid: good value at a reasonable price. Sustainable only if the cost base genuinely supports the
lower price point.
● No-frills: stripping the product to its core and pricing at the bottom of the market. Attracts highly price-
sensitive customers but relies on volume.
● Penetration pricing: set a low price to gain market share quickly, then raise prices once established.
● Price skimming: launch at a high price to capture high-willingness-to-pay customers first, then
reduce over time.
● Promotional pricing: temporary reductions to drive volume or clear stock.
● Predatory pricing: temporarily price below cost to drive competitors out of the market. Often illegal.
Price war risk: competing solely on price is dangerous unless the organisation has a genuine and
sustainable cost advantage. Matching a competitor's price cut without a lower cost base simply destroys
margin.
Differentiation: compete on perceived superior value by customers who are willing to pay a premium for it.
Reduces price sensitivity but vulnerable to imitation. E.g. product features, brand, customer service, reliability,
design, after-sales support, ethical credentials.
Focused differentiation: apply either cost leadership or differentiation to a narrow segment. Suited to
organisations without the scale to compete broadly. same logic but targeting a specific niche segment rather
than the broad market.
Value-based pricing: closely linked to differentiation; price according to what the customer perceives the
product is worth rather than cost.
Lock-in occurs when customers face high switching costs that make it difficult or expensive to move to a
competitor, creating a highly durable structural advantage e.g. long-term contracts, high integration costs
(e.g. ERP systems), and network effects.
Network effects are the most powerful form of lock-in. Platforms like LinkedIn or WhatsApp become more
valuable as more people use them, making it very difficult for a new entrant to attract users away.

C5d – BCG Matrix and Public Sector Portfolio Matrix


Apply the Boston Consulting Group (BCG) and public sector portfolio matrix models to assist organisations
in managing their portfolios. [3]
Portfolio matrix helps organisations manage a portfolio of products, business units or investments by
assessing their relative performance and strategic potential.
Stars
Question Marks
Market leaders in growing markets. Generate
High Weak position in growing markets. Require
revenue but require significant investment to
Market significant investment but uncertain future.
maintain position.
Growth Strategy: Selective investment in those with
Strategy: Invest to maintain market share; these
potential to become Stars; divest the rest
are tomorrow’s cash cows

Dogs
Cash Cows
Weak position in mature markets. Neither
Low Market leaders in mature markets. Generate
generate significant cash nor require
Market more cash than they need to maintain position.
significant investment.
Growth Strategy: Harvest cash to fund Stars and
Strategy: Consider divestment unless there
Question Marks; defend market share
is a strategic reason to retain
Low Market Share High Market Share

Market share is not the only determinant of profitability; a Dog in a niche market may be highly profitable even
with low absolute market share. The model implies a natural lifecycle that may not apply — some Stars never
become Cash Cows; some Dogs are strategically essential even if financially marginal.
In the public sector, the equivalent matrix replaces market share with or service quality and market growth
with public sector need or political priority.

Question Mark Stars


High public need but poorly delivered. High public need and well delivered.
High Political
Service has political support but is Flagship services with strong political
Attractivenes
underperforming. backing.
s / Public
Need
Strategy: Invest to fix or risk reputational Strategy: Protect funding and invest to
damage. sustain.

Dog Cash Cow


Low public need and poor performance. Low public need but efficient and well-run.
Low Political
No political support and inefficient Low priority but a reliable source of savings.
Attractivenes
delivery.
s / Public
Strategy: Maintain efficiency, avoid over-
Need
Strategy: Discontinue, transfer to another investment, and redirect surplus resource
provider, or stop funding. elsewhere.
Low Service Performance High Service Performance

C5e – Ansoff Growth Vector Matrix


Recommend generic development directions using the Ansoff growth vector matrix. [2]
The Ansoff matrix recommends generic development directions based on whether the organisation is
pursuing new or existing products in new or existing markets.

Market development
Diversification
Take existing products into new markets (new
Bring new products into new markets
geographies, new segments or new distribution
New channels) Best When: Existing markets are
Markets declining; the organisation has
Best When: Existing markets are saturated; new
resources to fund entry into new areas;
markets offer growth; the product meets needs in
strategic synergies exist (Highest Risk)
those markets (Medium Risk)
Market penetration Product development
Increase market share with existing products in Develop new products for existing
existing markets through competitive pricing, markets)
Existing advertising and promotions
Markets Best When: Organisation has strong
Best When: Market is growing; competitors are R&D capability; existing customers have
weak; there is scope to increase usage among unmet needs; brand loyalty supports
existing customers (Lowest Risk) new product adoption (Medium Risk)

Existing Products New Products

C5f – Internal Development, Business Combinations, Strategic Alliances and Partnering


Assess how internal development, business combinations, strategic alliances and partnering can be used to
achieve business growth. [3]

Method Description Advantages Risks


Internal
Building new capabilities Preserves culture and Slow; limited by existing
development
within the business using control; no integration resource base, may miss
(organic
existing resources risk the market window
growth)
Speed; acquires
Combining with or acquiring Integration failure, cultural
established
Mergers and another organisation to gain clash and overpayment can
capabilities and
acquisitions capabilities, market share or destroy shareholder value
market position
access rather than create it
immediately

organisations share resources Shared risk and Shared returns, risk of


Strategic and activities to pursue a resources, access to surrendering competitive
alliances strategy without merging. partner’s capabilities, knowledge, conflict if
Requires aligned objectives flexibility to exit objectives diverge

Parties create a new entity by Clearer governance Complex to manage,


contributing equity and than alliance, shared disagreements between
Joint ventures
sharing revenue, expenses commitment through partners, exit can be
and control equity stake difficult

Franchisor provides proven


Rapid expansion with Reputational risk if
business methods to
Franchising low capital, franchisee franchisee underperforms,
franchisee for a fee and
bears operational risk less control over quality
percentage of revenue

the licensor allows another low-cost expansion,


less control than direct
licensee to use intellectual access to new
ownership, quality and
property, technology, brand, markets, income from
Licensing reputation risk, limited
product design or know-how intellectual property
support compared with
for a limited period in return without direct
franchising,
for a fee or royalty. investment.

Delegating non-core activities Focus on core Loss of control,


to an external specialist competences, cost dependency on supplier,
Outsourcing
Requires careful judgment efficiency, access to risk of losing capability
about what is truly non-core specialist expertise permanently
Transferring functions to Significant cost Quality control challenges,
Offshoring another country for cost or savings, access to political and currency risk,
resource advantages large labour pools reputational risk
Section D – Risk
D1 – Identification, Assessment and Measurement of Risk
D1a – Relationship Between Organisational Strategy and Risk Management Strategy
Discuss the relationship between organisational strategy and risk management strategy. [3]
Risk management is not separate from strategy - it is embedded within it. Every strategic decision a company
makes carries new risks, and the organisation's risk management strategy should evolve alongside its
corporate strategy. E.g. company accepts new political, currency and competitive risks when it enters a new
market, when it launches a new product, it accepts operational, reputational and financial risks
The board is responsible for setting both the corporate strategy and the risk appetite; the two must be aligned.
A company with a low-risk appetite should not pursue high-risk strategies; a company in a high-growth phase
must accept higher risk as part of its strategy.
Risk management strategy therefore determines:

● Which risks are acceptable given the strategic objectives


● How much resource is devoted to risk mitigation
● Which risks should be avoided, transferred, reduced or accepted (TARA)
A company that manages risk well does not avoid all risk; it takes the right risks in pursuit of its strategic
objectives while managing downside exposure to an acceptable level.
When strategy and risk management are misaligned:

● Risk appetite misalignment with strategy: If risk appetite is set too low for the chosen strategy, an
internal contradiction emerges as business units take on risks the board has not sanctioned and the
risk framework becomes irrelevant.

● Risk management as a compliance exercise: When risk management is treated as box-ticking


exercise rather than a strategic input, the board makes decisions without understanding the risk
implications. Strategic failures occur as foreseeable risks were never properly evaluated.

● Strategy outpacing the risk framework: In fast-moving environments, strategy is updated


frequently but risk appetite and controls are not. The framework lags behind, leaving the board
believing it is operating within its risk appetite while actual exposure has quietly exceeded it.

D1b – Enterprise Risk Management (ERM)


Apply the enterprise risk management (ERM) approach to risk management and for establishing risk
management systems. [2]
ERM is a structured, organisation-wide approach to identifying, assessing and managing all risks that could
affect the achievement of strategic objectives. Unlike traditional risk management, which tends to manage
risks in departmental silos reactively, ERM takes a holistic view across the entire organisation and treats risk
as integral to strategy rather than a compliance exercise. Risk appetite is set at board level and cascades
down through the organisation, with all significant risks captured in a single risk register and risk management
embedded in culture and processes.
The COSO ERM Framework
COSO visualises ERM as a three-dimensional cube covering objectives (strategic, operational, reporting and
compliance) across all organisational units, through eight components: internal environment → objective
setting → event identification → risk assessment → risk response → control activities → information and
communication → monitoring.
The internal environment is the foundation; the board sets the tone, influencing risk appetite and ethical
values. A weak or unbalanced board therefore compromises the entire framework before any risks are
assessed. Notably, event identification captures opportunities as well as threats, which should feed back into
strategy rather than being ignored.
COSO also distinguishes between risk appetite (the broad level of risk the board is willing to accept in
pursuing objectives) and risk tolerance (acceptable variation at the individual objective level). The two must
be aligned, as tolerances that collectively exceed appetite create inconsistency.

D1c – Key Risks Including Environmental and Climate-Related Risks


Identify and evaluate key risks, including environmental and climate related risks, and their impact on
organisations and projects. [3]
Categories of Risk

● Strategic risk is caused by the external competitive environment or poor high-level decision-making,
affecting the whole organisation and managed at board level e.g. competitive threats, political
instability and shifting consumer trends.

● Business risk derives from decisions about products or services; developing and marketing them,
economic risks affecting sales and costs, and technological change impacting production.

● Non-business risk does not derive from products or services but from the financial structure of the
organisation, such as risks associated with long-term sources of finance. Strategic in nature but
originating from financing rather than commercial activities.

● Operational risk is caused by internal process failures, human error or system failures such as
cyberattacks or redundant systems.

● Financial risk covers several sub-categories:


o Credit risk: loss from customer or borrower default, resulting in bad debts or delayed cash
flows
o Currency risk: loss from adverse foreign exchange rate movements, particularly relevant for
internationally operating organisations
o Liquidity risk: inability to meet short-term financial obligations, caused by poor cash flow
management or customer defaults
o Gearing risk: high debt relative to equity, creating large fixed interest obligations, measured
by the debt/equity ratio
o Interest rate risk: changes in interest rates increasing borrowing costs

● Political risk arises from instability or changes in the political environment; government policy
changes, trade restrictions, nationalisation or social unrest. Largely external and uncontrollable.

● Compliance/legal risk is the failure to comply with applicable laws and regulations, leading to fines
and legal action.

● Reputational risk arises from poor customer service, product recalls, data breaches or unethical
behaviour, leading to loss of customer trust.
The board's duty of care includes ensuring all material risks are systematically identified and assessed.
Failure to do so represents a governance failure regardless of whether those risks ultimately materialise.
Environmental and Climate-Related Risks (TCFD)
The TCFD identifies three categories of climate-related risk:

⮚ Physical risks arise from the direct impacts of climate change on operations and assets: flooding,
water scarcity, extreme weather; resulting in asset damage, increased insurance costs, supply chain
disruption and reduced productivity. For projects, physical conditions can cause delays, cost
overruns or complete failure.
⮚ Transition risks arise from the shift to a lower-carbon economy: carbon taxes, stranded assets,
new energy efficiency regulations and reputational damage from being seen as environmentally
irresponsible. This results in increased costs, asset write-downs and reduced access to ESG-
focused capital. Projects approved under old regulatory conditions may become unviable as
regulation changes mid-delivery.
⮚ Liability risks arise from legal claims by stakeholders suffering loss due to the organisation's
environmental impact: litigation from affected communities, regulatory fines and compensation
claims from investors where climate risks were not properly disclosed. Projects with significant
environmental impact may face legal challenges that delay or block delivery entirely.
The board is responsible for overseeing all three categories as part of its overall risk oversight. TCFD
requires disclosure of how the board oversees climate risks, how they are integrated into strategy, and
what metrics are used to manage them. Failure to do so is increasingly treated as a governance failure by
institutional investors and regulators.

D1d – Strategic vs Operational Risks


Distinguish between strategic and operational risks. [2]

Strategic Risk Operational Risk


Nature Long-term; affects the whole organisation Short-term; affects day-to-day operations
External environment, competitive forces, Internal process failures, human error,
Cause
poor strategic decisions system failures
Managed Management level: through internal
Board level: part of strategic management
by controls
Failed merger, disruptive new competitor, IT system failure, employee fraud, supply
Examples
regulatory change chain disruption
Usually localised but can escalate if not
Impact Can threaten the survival of the organisation
controlled

D1e – Risk Appetite and Attitudes Towards Risk


Assess attitudes towards risk and risk appetite and how this can affect risk policy. [2]
Risk Appetite is a measure of a company's willingness and capacity to accept risk in pursuit of its objectives.
o Risk Averse: Avoids high risk; accepts risk only with a decent return e.g. public sector; heavily
regulated industries; mature companies
o Risk Seeking: Focuses on profits; willing to accept high risk for high reward e.g. Start-ups; high-
growth & PE companies
Risk appetite is set by the board and must align with the organisation's strategic objectives, stakeholder
expectations and financial capacity. It should be clearly communicated throughout the organisation so that
operational decisions are made within agreed risk boundaries.
How risk appetite affects risk policy:

Low risk appetite High risk appetite


TARA strategies of Accept and Reduce are
TARA strategies of Avoid and Transfer are preferred
preferred
Stricter internal controls and lower tolerance for More flexible controls with higher tolerance
deviations thresholds
Aggressive growth strategies and higher leverage
Conservative investment and financing decisions
accepted
More resources devoted to risk mitigation Resources redirected toward opportunity pursuit
Go errors and stop errors — a risk-seeking organisation may make a go error by pursuing an opportunity
where the downside risk outweighs the expected return. A risk-averse organisation may make a stop error
by rejecting an opportunity that should have been accepted, allowing competitors to capture the benefit.

D1f – The Dynamic Nature of Risk


Discuss the dynamic nature of risk and the ways in which risk varies in relation to the size, structure, industry,
sector and development of an organisation. [2]
Risk is not static — it changes over time and varies depending on the nature of the organisation:

Factor How it affects risk


Larger organisations face more complex risks but have more resources to manage
Size
them; smaller organisations are more vulnerable to individual risk events
Decentralised organisations may have inconsistent risk management; centralised
Structure
structures allow tighter control but may miss local risks
Heavily regulated industries (financial services, healthcare) face significant
Industry / sector
compliance risk; extractive industries face significant environmental risk
Stage of Start-ups face high strategic and financial risk; mature companies face more
development reputational and operational risk

Organisations must continuously monitor their risk environment; risks that were acceptable last year may not
be acceptable today due to changes in the external environment, regulation or strategy.

D1g – Assessing Severity and Probability of Risk


Assess the severity and probability of risk events. [2]
Risk Assessment is based on two dimensions:

● Probability: how likely is the risk to occur?


Risk = Likelihood × Impact
● Impact: how severe would the consequences be if it did?

Inherent vs residual risk — inherent risk is the level of risk before controls or mitigation. Residual risk is the
risk remaining after controls have been applied. The board should focus on whether residual risk is within
risk appetite.

Approach How it works Limitation


Risks scored on descriptive scales Highly subjective: two managers may score the
Qualitative (e.g. high/medium/low) based on same risk differently; results are not comparable
management judgement across organisations

Risks assigned numerical probability


Requires reliable data that may not exist for novel
and financial impact values using
Quantitative or rare risks; false precision-a number gives
historical data, modelling or
confidence that may not be warranted
statistical analysis

Combines accessibility of qualitative with


Numerical scores assigned to
Semi- structure of quantitative, but the numerical output
qualitative categories (e.g. high = 3,
quantitative can still be misleading if the underlying scores are
medium = 2, low = 1) and multiplied
subjective

Risks are then plotted on a heat map to visualise the overall risk profile.

D1i – Related and Correlated Risk Factors


Explain and evaluate the concepts of related and correlated risk factors. [3]
Related risks: risks that share a common cause or are connected in such a way that one risk event can
trigger another e.g. a cyberattack (security risk) can simultaneously cause operational disruption, reputational
damage, regulatory fines and financial loss; four separate risk categories triggered by one event.
Correlated risks: risks that tend to increase or decrease together.
Positive correlation means multiple risks materialise at the same time (e.g. during an economic downturn,
credit risk, liquidity risk and reputational risk all increase simultaneously). This is particularly dangerous
because the organisation faces multiple simultaneous hits rather than isolated incidents.
Negative correlation means one risk decreasing causes another to increase; can be used strategically e.g. a
hotel group operating both ski resorts and beach resorts, peak seasons are opposite, so staff, capital and
marketing resources can be shared across a naturally balanced annual cycle.
Why this matters:

● Risk assessment must consider how risks interact, not just evaluate each risk in isolation
● Diversification as a risk management strategy is less effective when risks are highly correlated;
spreading activities across markets does not help if all markets are affected by the same downturn
● The board needs to understand the organisation's overall risk exposure, not just individual risk events

D2 – Managing, Monitoring and Mitigating Risk


D2a – The Role of a Risk Manager
Explain and assess the role of a risk manager. [3]
A Risk Manager can be appointed to take operational responsibility for risk management across the
organisation. Their role includes:

● Identifying and assessing risks across all parts of the organisation


● Maintaining and updating the risk register
● Collating risk reports from departments and escalating significant risks to the board
● Raising risk awareness and embedding risk management in organisational culture
● Working with management to design and implement internal controls
● Providing guidance to the risk committee on emerging risks

Issues that can arise with the appointment of a risk manager

⮚ The delegation illusion: when a risk manager is appointed, board members and senior executives can
unconsciously treat risk as someone else's responsibility. ERM requires risk ownership at every level; a
risk manager who is seen as "the person responsible for risk" actively undermines this principle.

⮚ Positioning and influence: a risk manager who reports to the CFO rather than directly to the board or
CEO lacks the organisational standing to challenge senior management on risk decisions. Their
effectiveness depends entirely on where they sit in the hierarchy and whether the board genuinely listens
to them.

⮚ Conflict with operational management: risk managers who impose controls on operational managers
create friction. Operational managers are incentivised to hit performance targets; risk controls can feel
like obstacles. Without cultural buy-in, risk managers become isolated compliance functions rather than
embedded strategic advisers.

⮚ The competence gap: in complex organisations, no single risk manager can have sufficient expertise
across all risk categories (financial, cyber, climate, operational, legal). Specialist knowledge is always
distributed across the organisation; the risk manager's value is in coordination and escalation, not
personal expertise in every domain.
A risk manager adds genuine value as a coordinator, framework designer and escalation channel. But their
appointment is only effective if the board retains ownership of risk appetite, operational managers accept risk
responsibility, and the risk manager has sufficient organisational authority to be heard.

D2b – Risk Register and Heat Maps


Evaluate a risk register and use heat maps when identifying or monitoring risk. [3]
Risk Register is a central document recording all identified risks. For each risk it typically includes:

● Description of the risk


● Category (strategic, operational, financial, compliance etc.)
● Probability and impact scores (before and after controls)
● Risk owner: the person responsible for managing it
● Controls currently in place
● Further actions required

A risk register is only as useful as the quality of information in it. Common weaknesses include risks being
recorded at too high a level to be actionable, risk owners not genuinely engaging with their responsibilities,
and the register being updated annually as a compliance exercise rather than maintained as a live
management tool.

Heat Map — a visual tool that plots risks on a grid of likelihood (y-axis, vertical) against impact (x-axis,
horizontal). Colour coding (red/amber/green) indicates priority. Heat maps allow the board and risk committee
to see the overall risk profile of the organisation at a glance and prioritise resources accordingly.
Limitations of heat maps — Risk scoring involves significant subjectivity; two managers may score the
same risk differently. Heat maps also present risks in isolation, failing to capture how correlated risks interact.
They should be used as a guide alongside qualitative judgement, not as a mechanical decision-making tool.
Link to assurance mapping: The risk register is the starting point for assurance mapping (D2g). Assurance
mapping works by taking each principal risk from the register and linking it to the controls operating against
it, the line of defence providing that control, and the KPIs tracking performance. This produces a picture of
risk coverage that the board uses to identify gaps, overlaps and resource priorities. A poorly maintained risk
register therefore undermines assurance mapping. The quality of assurance reporting is only as good as the
quality of the underlying risk register it draws from.

D2c – Embedding Risk in Organisational Culture


Evaluate the concept of embedding risk in an organisation’s culture and values. [3]
Risk management should be embedded in organisational culture from the board downwards (risk culture).
This matters because controls ultimately fail through people rather than poor design. Even well-designed
controls break down if staff ignore them, make mistakes, collude, or if management overrides them.

Genuine embedding Superficial embedding


The board visibly champions risk management Risk appetite is documented but the board overrides
and sets clear risk appetite controls when commercially convenient
Risk awareness is built into day-to-day Risk is considered only at annual risk committee
decision-making at all levels meetings or when something goes wrong
Employees are encouraged to report near- Near-misses are concealed because reporting them is
misses without fear of retribution punished
Risk training is provided across the Risk training is a one-off induction exercise that is never
organisation revisited
Performance management systems reward Performance systems reward financial outcomes only —
good risk management behaviour good risk behaviour goes unrecognised

D2d – Spreading and Diversifying Risk


Explain and analyse the concepts of spreading and diversifying risk and when this would be appropriate. [2]
Risk diversification is spreading risks across multiple areas to reduce the impact of any single risk event:

⮚ Geographic diversification: operating in multiple countries reduces exposure to political or


economic risk in any one market, using multiple suppliers reduces supply chain risk

⮚ Product diversification: offering multiple products reduces the impact of one product failing

⮚ Customer diversification serving multiple customers reduces dependency on any single revenue
source
Diversification is most appropriate when risks are independent of each other, meaning the occurrence of one
does not affect the likelihood of another. If all markets or products are affected by the same event (e.g. a
global recession or pandemic) or risks are correlated, diversification provides limited protection and other
TARA strategies should be considered instead.

D2e – Risk Management Strategies: TARA


Advise on risk management strategies, including the use of the TARA model. [3]
Once risks have been identified and assessed, the TARA framework is used to determine the appropriate
management strategy:

Reduce
Avoid
Take action to lower the likelihood or
Eliminate the risk entirely by not doing the
impact of the risk (e.g. security controls,
High activity that causes it (e.g. not launching in a
staff training, process improvements).
Probability certain market).
Best when the risk is worth taking but
Best when the risk outweighs the benefit of
needs to be managed to an acceptable
the activity
level
Transfer
Accept
Shift the risk to a third party (e.g. insurance,
Acknowledge the risk and consciously
Low outsourcing). Not eliminating the risk, just
decide to live with it.
Probability moving who bears it.
Best when the risk is low enough that
Best when the risk is too costly or complex to
treatment is not cost-effective
handle internally
Low Impact High Impact

TARA evaluates each risk in isolation, ignoring interdependencies between correlated risks, where avoiding
one risk may increase exposure to another. The framework assumes treatment costs can be assessed
against the benefit of risk reduction, the cost of not managing certain risks, particularly reputational or climate-
related, is extremely difficult to quantify.
A single risk rarely calls for one pure TARA response; multiple strategies often apply simultaneously. A
company facing cybersecurity risk might transfer some exposure through insurance, invest in security
controls to reduce it, and accept residual risk below a defined threshold, all at the same time.
TARA strategies must also be linked to risk appetite. The appropriate response is not determined by the risk
alone; the same risk level might be accepted by a high risk appetite organisation and avoided by a low risk
appetite one. In exam scenarios, always link your TARA recommendation to the organisation's stated or
implied risk appetite.

D2f – ALARP Principle


Explain and assess the benefits of incurring or accepting some risk as part of competitively managing an
organisation referring to the ‘as low as reasonably practical’ (ALARP) principle. [3]
ALARP (As Low As Reasonably Practicable) mean a risk should be reduced until the cost of further reduction
is grossly disproportionate to the benefit gained; ‘Do as much as you reasonably can.’
The three zones:

● Unacceptable zone: risk is too high - must be reduced regardless of cost


● ALARP zone: risk is tolerable only if further reduction is impractical or costs are grossly
disproportionate to the benefit
● Broadly acceptable zone: risk is low enough to live with - no action needed

How it links to TARA: ALARP sits within the Reduce option. When you cannot avoid or fully transfer a risk,
you reduce it to an ALARP level- the point where it is tolerable and further mitigation is not cost-justifiable.
Why accepting some risk is essential to competitive management: Eliminating all risk is neither possible
nor desirable. The right question is not "can we reduce this risk further?" but "is it worth reducing it further?"
This shifts risk management from a compliance mindset to a commercial one.
If organisations attempt to eliminate all
By consciously accepting risk within ALARP:
risk:
Reject opportunities that carry uncertainty, Can pursue higher-return strategies that carry
allowing more risk-tolerant competitors to manageable risk rather than defaulting to low-risk, low-
capture them return alternatives

Incur disproportionate control costs that


Can redirect resources saved on over-engineering
destroy the commercial viability of otherwise
controls to value-creating activities
sound activities

Create a disciplined framework where risk is


Slow decision-making to the point where the
consciously evaluated and accepted at a defined
organisation cannot respond to market
threshold — far better governance than either ignoring
changes effectively
risk or refusing all of it

D2g – Assurance Mapping and the Four Lines of Defence


Apply the concept of assurance mapping to modern risk management using the 'four lines of defence' [3]
Assurance mapping is a tool used by boards and audit committees to ensure all significant risks have
appropriate coverage, with no gaps or overlaps in oversight. It takes the form of a visual matrix; rows
represent principal risks from the risk register, columns represent each line of defence, and each cell shows
what control operates and what metric is used to track its effectiveness.
The Four Lines of Defence:

Line Who Role Why They may Fail


Operational own and manage risks day- controls exist on paper but are treated as a
1st
management to-day through normal compliance exercise rather than genuinely
line
and staff operations. embedded in practice.
Risk & sets the risk framework and Independence; if it reports to the same senior
2nd
compliance monitors and challenges the manager as the teams it oversees, it cannot
line
functions first line. challenge them effectively.
Provide independent Selectivity; if internal audit focuses on
3rd assurance to the board that traditional financial controls and ignores
Internal audit
line the first and second lines are emerging risks such as cyber or climate, those
functioning. risks go entirely unchecked.

External auditors are hired and paid by the


Provide the ultimate external
4th External audit organisation they audit, which can compromise
check on governance and
line and regulators rigour, while regulators typically only intervene
financial reporting.
after something has already gone wrong.

The real value of assurance mapping lies in what it reveals to the board. Gaps; risks with no coverage across
any line represent the most serious control failures. Single points of failure; risks covered by only one line are
particularly dangerous because one failure removes all protection. Overlaps on low-risk areas are an
efficiency problem, diverting assurance resources from where they are most needed.
Assurance mapping also directly shapes internal audit resourcing. Where the first two lines provide strong,
evidenced control, internal audit can allocate fewer resources. Where they are weak or absent, internal audit
must fill the gap, making the assurance map a direct input into the audit plan rather than merely a reporting
tool.
Finally, a robust assurance mapping process enables the board to report with greater confidence to external
stakeholders on the effectiveness of internal controls, supporting compliance with governance reporting
requirements such as the UK Corporate Governance Code.
SBL - Section E - Technology and Data Analytics
E1 – Cloud, Mobile and Smart Technology
E1a – Strategic Need to Explore New Technologies
Discuss, from a strategic perspective, the need to explore opportunities for adopting new technologies such
as cloud, mobile and smart technology within an organisation. [3]
Adopting technology has become a strategic necessity. Organisations that fail to do so risk losing competitive
advantage, operational efficiency and the ability to meet stakeholder expectations.
• Competitive advantage: Competitors adopting technology faster will deliver better products, lower costs
or superior customer experience. Technology adoption is both an opportunity and a threat
• Cost efficiency: Cloud, automation and smart technology reduce operating costs, particularly in back-
office functions. Cost leadership strategies depend on it
• Scalability: Cloud and mobile technologies allow organisations to scale operations rapidly without
proportional increases in infrastructure investment
• Innovation: New technologies enable new products, services and business models. Organisations that
explore technology proactively are better positioned to innovate
• Talent attraction: Modern technology environments attract skilled employees. Legacy technology drives
away talent
• Stakeholder expectations: Customers, investors and regulators increasingly expect digital capability in
service delivery, reporting and compliance
• Risk of disruption: Failure to adopt new technologies exposes the organisation to disruption by more
agile competitors or new market entrants
The board must evaluate whether a technology genuinely supports the organisation's strategy before
committing resources. Poorly managed technology adoption creates cost, disruption and risk rather than
value.

E1b – Benefits and Risks of Cloud, Mobile and Smart Technology


Discuss key benefits and risks of cloud, mobile and smart technology. [2]

Technology Key Benefits Key Risks


Data security and privacy,
Reduced infrastructure costs, scalability
dependency on internet connectivity,
on demand, real-time data access,
Cloud computing vendor lock-in, loss of control over
automatic updates, enables remote
data location, compliance risk (data
working, pay-as-you-go pricing
sovereignty)
Enables remote and flexible working, Device security, data leakage if
real-time communication and access to devices lost or stolen, BYOD (bring
Mobile technology information, improved customer your own device) policy challenges,
engagement, faster decision-making, employee distraction, increased
extends reach to mobile-first markets attack surface for cybercrime

Real-time operational data from


connected devices enabling data driven
Security vulnerabilities in connected
decision making and asset utilisation,
Smart technology devices, large volumes of data to
real-time monitoring and predictive
(IoT) manage, system complexity, high
maintenance, automated processes,
implementation cost
improved supply chain visibility, better
customer experience

Impact of new technology on organisational culture


Benefits: Flexibility, productivity, collaboration, employee monitoring
Risks: expectation to respond to emails/messages outside working hours, damaging work-life balance,
morale and wellbeing. Excessive monitoring can reduce trust. Remote working can weaken team spirit and
create misunderstandings because non-verbal cues are missing.
Exam use: when recommending new technology, consider not only cost and efficiency but also cultural
impact

E1c – Cloud as Alternative to Owned Hardware and Software


Assess and advise on using the cloud as an alternative to owned hardware and software technology to
support organisation information system needs. [3]

Organisation's
Cloud Service Models What it provides Example
responsibility
Operating AWS, Microsoft
IaaS (Infrastructure as a Raw computing infrastructure:
system, Azure, Google
Service) servers, storage, networking
applications, data Cloud
PaaS (Platform as a Infrastructure plus operating Applications and Salesforce, Google
Service) system and development tools data only App Engine
SaaS (Software as a Complete software application Data and user Microsoft 365, SAP,
Service) delivered via the internet configuration only Workday

Cloud (IaaS/PaaS/SaaS) Owned Hardware and Software


High: significant upfront capital
Capital cost Low: pay as you go or for usage
investment
High: capacity can be increased or Low: hardware must be purchased in
Scalability
decreased rapidly advance
Organisation's responsibility: requires
Maintenance Provider's responsibility
internal IT capability
Provider manages physical security; shared Organisation has full control but must
Security
responsibility for data invest in security
Vendor Risk of lock-in; price increases; provider No vendor dependency for
dependency failure infrastructure

Cloud can be:


Private: Infrastructure used exclusively by one client hosted on-site or externally. Highest security,
customisation and control; most expensive; requires expert internal IT staff. Best for large organisations with
substantial data needs and high security or compliance requirements
Public: Shared infrastructure used by all clients. Pay-as-you-go; scalable; most affordable. Less
customisation; unplanned downtime affects all clients; less control over data location. Best for smaller
organisations or non-critical workloads where cost-efficiency is the priority.
Hybrid: Combines private and public cloud. Business-critical operations on private cloud; non-core
workloads on public cloud. Most flexible option; allows cost savings without sacrificing security where it
matters most. Best for organisations with a mix of sensitive and non-sensitive workloads.

E2 – Big Data and Data Analytics


E2a – Using IT and Data Analysis to Inform and Implement Strategy
Discuss how information technology and data analysis can effectively be used to inform and implement
organisational strategy. [3]
Data analytics transforms raw data into actionable insight, enabling better strategic decisions and more
effective strategy implementation. Types of data analysis:
Descriptive analytics - What happened? summarises historical data to understand past performance
Diagnostic analytics - Why did it happen? identifies causes and patterns behind past performance
Predictive analytics - What will happen? uses statistical models and machine learning to forecast future
outcomes
Prescriptive analytics - What should we do? recommends actions based on predicted outcomes; the most
strategically valuable form

Strategic use How data analytics adds value


Market and Analysing market trends, competitor pricing and customer behaviour to
competitive analysis identify strategic opportunities and threats
Understanding customer needs, preferences and behaviour to inform
Customer insight
product development, pricing and marketing strategy
Operational Real-time monitoring of KPIs to identify underperformance and take
performance corrective action before problems escalate
Identifying patterns that signal emerging risks — fraud detection, credit
Risk management
risk, supply chain disruption
Scenario modelling and forecasting to test strategic options under
Strategic planning
different conditions
Performance Linking operational data to strategic KPIs so the board can assess
management whether strategy is being delivered
Identifying unmet customer needs or market gaps through data that
Innovation
would not be visible through traditional research methods

Types of Analytics
Data analytics is only as valuable as the quality of the underlying data and the capability to interpret it. Poor
data quality, siloed systems and a lack of analytical skills undermine the value of even the most sophisticated
analytical tools. The board must invest in data governance alongside analytical capability.
Exam Technique: Interpreting Analytics Exhibits
consider whether the underlying data is reliable; whether the analytical technique is appropriate; whether a
correlation is genuinely causal or coincidental; and whether the conclusions drawn by management are
justified. For example, a strong correlation between two variables does not mean one causes the other —
the exam rewards candidates who apply professional scepticism to data rather than accepting it at face value.

E2b – Big Data: Opportunities and Threats


Describe big data and discuss the opportunities and threats big data presents to organisations. [2]
Big data refers to datasets so large, fast-moving or complex that traditional data processing tools cannot
handle them. Characterised by the 5 Vs:

Enormous quantities of data generated from transactions, social media, sensors,


Volume
devices
Velocit
Data generated and needing to be processed in real time or near real time
y
Structured data (databases) and unstructured data (emails, social media, images,
Variety
video)
Veracit
Uncertainty about data accuracy and trustworthiness — not all data is reliable
y
Value The potential insight and commercial value that can be extracted from the data
Opportunities Threats
Deep customer insight enabling Data privacy breaches; risk of regulatory fines (e.g. GDPR)
personalisation and targeted marketing and reputational damage
Real-time operational monitoring and faster Data security; large data stores are attractive targets for
decision-making cybercriminals
Predictive maintenance reducing downtime Storage and processing costs; big data infrastructure
and costs requires significant investment
New revenue streams from data Data quality; large volumes of poor-quality data produce
monetisation misleading insights ('garbage in, garbage out')
Improved risk management through pattern Ethical concerns; use of personal data raises questions
recognition about consent and surveillance
Competitive advantage through superior Skills gap; organisations lack the data scientists and
analytical capability analysts needed to extract value from big data

E2c – Data for Strategic Decisions: Products, Marketing and Pricing


Identify and analyse relevant data for strategic decisions on new product developments, marketing and
pricing. [3]
New Product Development

● Customer behaviour data — what are customers buying, searching for and complaining about?
Identifies unmet needs
● Social media sentiment analysis — what are customers saying about existing products? Identifies gaps
and improvement opportunities
● Market trend data — where is the market growing? Which segments are underserved?
● Competitor product analysis — what features do competitors offer that we do not?
● Prototype and A/B testing data — testing customer response to new product concepts before full launch
Marketing

● Customer segmentation data — grouping customers by behaviour, demographics or value to target


marketing spend effectively
● Campaign performance data — click-through rates, conversion rates, cost per acquisition — which
channels and messages work?
● Customer lifetime value (CLV) analysis — which customers generate the most long-term value? Focus
acquisition and retention spend accordingly
● Churn analysis — which customers are at risk of leaving? Enables targeted retention campaigns
● Attribution modelling — understanding which marketing touchpoints actually drive purchase decisions
Pricing

● Price elasticity data — how sensitive is demand to price changes? Derived from historical sales data
● Competitor pricing data — real-time monitoring of competitor prices enables dynamic pricing responses
● Customer willingness-to-pay data — survey data and conjoint analysis identifies the maximum price
different segments will accept
● Dynamic pricing algorithms — used in airlines, hotels and e-commerce to adjust prices in real time
based on demand and availability
● Margin analysis by product, channel and customer — identifies which are truly profitable after all costs
are allocated

E3 – Machine Learning, AI and Robotics


E3a – Benefits of AI, Robotics and Machine Learning
Explain the potential benefits of using AI, robotics and other forms of machine learning to support strategic
decisions and the pursuit of corporate objectives. [2]
Types of machine learning

⮚ Supervised learning — the system is trained using data where the correct input-output relationship is
already known. Useful for prediction, classification and personalised marketing.
⮚ Unsupervised learning — the system identifies patterns or groupings in data without being told the
correct answer. Useful for customer segmentation and identifying hidden trends.
⮚ Reinforcement learning — the system learns through trial and error by receiving rewards or penalties
for actions. Useful where the best action is learned through interaction with the environment.

Technology Description
Artificial Intelligence Computer systems that perform tasks that normally require human
(AI) intelligence — reasoning, learning, problem-solving, perception
Machine Learning A subset of AI — systems that learn from data and improve their
(ML) performance over time without being explicitly programmed
Robotic Process Software robots that automate repetitive, rule-based tasks by
Automation (RPA) mimicking human interactions with computer systems
Physical robotics Machines that perform physical tasks autonomously — used in
manufacturing, logistics and healthcare
Natural Language AI that understands and generates human language — powers
Processing (NLP) chatbots, voice assistants and document analysis

Benefits

● AI processes data far faster than humans, reducing cycle times and increasing throughput, while
removing human error from repetitive processes such as data entry, reconciliation and compliance
checking.
● RPA and AI deliver significant labour cost savings in transactional functions and operate
continuously without rest, improving customer service and operational efficiency.
● Machine learning identifies patterns in large datasets invisible to humans, improving fraud detection,
predictive maintenance and demand forecasting.
● At the strategic level, AI analyses vast amounts of internal and external data to provide better-
informed strategic options, enables mass personalisation of products and services, and can
accelerate innovation by identifying market opportunities and generating new product concepts.
Sector Applications
In healthcare, AI analyses patient data to identify those at risk and prompt early intervention, and diagnostic
tools detect disease patterns faster and more accurately than human clinicians. In agriculture, algorithms
monitor crop and soil health, considering climate conditions to predict harvest timing and improve resource
allocation. In financial services, AI supports investment decisions and high-speed trading, with some
portfolios managed entirely by AI with no human involvement.
E3b – Risk, Control and Ethical Implications of AI and Robotics
Assess the risk, control and ethical implications of using AI, robotics and other forms of machine learning.
[3]

Risk Detail
Algorithmic bias AI systems trained on biased historical data reproduce and amplify that bias
— leading to discriminatory decisions in hiring, lending or pricing
Lack of Many AI models cannot explain how they reached a decision — creates
transparency accountability problems and regulatory risk
('black box')
Over-reliance Organisations may rely too heavily on AI outputs without sufficient human
oversight — removing the judgement needed to catch errors
Data dependency AI performance depends entirely on data quality — poor, incomplete or
manipulated data produces unreliable outputs
Cybersecurity AI systems are targets for adversarial attacks — deliberately feeding
incorrect data to manipulate outputs
Job displacement Automation displaces workers — creates ethical obligations and potential
reputational and social impact
Regulatory risk AI regulation is evolving rapidly — organisations that deploy AI without
adequate governance may face significant regulatory exposure
Control Implications
AI-generated decisions in high-stakes areas — lending, medical diagnosis, legal — should be subject to
human review before action is taken. Models should be documented, tested, validated and regularly
reviewed for accuracy and bias, with all decisions logged to create auditable trails. Updates to AI models
should follow formal change management processes, and the quality, completeness and security of data
feeding AI systems must be actively governed.
Ethical Implications
AI must not discriminate on the basis of protected characteristics — algorithmic bias must be actively
identified and addressed rather than assumed absent. Individuals affected by AI decisions have a right to
explanation under GDPR, requiring genuine transparency rather than superficial disclosure. Privacy
obligations govern the large volumes of personal data AI systems require. Critically, when AI causes harm
the organisation deploying it cannot hide behind the algorithm — accountability must rest with identifiable
humans. Organisations also have an ethical obligation to support workers displaced by automation through
retraining and transition support.
WEF Additional Ethical Risks
The WEF identifies risks that go beyond standard governance concerns. AI makes its own category of
mistakes — seeing patterns in random data that reflect no real relationship, producing false conclusions
even from good data. An AI system may achieve its precise objective while generating serious unintended
adverse consequences it was not programmed to consider, ignoring harmful side effects outside its
objective function. The ultimate control risk is that as AI capability increases, the assumption that human
oversight will always remain effective may no longer hold. AI optimised for engagement can drive addictive
behaviour as an unintended consequence of its reward mechanism. Finally, the economic benefits of AI
risk concentrating in the hands of capital owners rather than the workers displaced, raising questions about
organisational obligations beyond legal compliance.
Critical Evaluation
The benefits of AI are significant but the governance challenges are equally so. Boards that treat AI purely
as a technology decision rather than a governance and ethical one expose their organisations to
substantial risk. AI strategy should be owned at board level with clear accountability for ethical deployment,
an ethical framework aligned with the organisation's broader values, bias monitoring built in from the design
stage rather than applied retrospectively, and ongoing stakeholder consultation about decisions being
made on their behalf.

E4 – E-Business: Value Chain


E4a – Assessing the Organisation's Approach to E-Business
Assess the organisation's approach to delivering e-business. [3]
E-business refers to the use of internet and digital technologies to conduct business activities — including
selling, purchasing, marketing, customer service, supply chain management and internal operations.
E-Business Models
Model Description
B2C (Business to Selling directly to individual consumers online (e.g. Amazon, ASOS).
Consumer) Requires strong digital marketing, logistics and customer experience
capability
B2B (Business to Selling to other businesses online. Often involves procurement portals, e-
Business) catalogues and automated ordering systems
C2C (Consumer to Platform facilitating transactions between consumers (e.g. eBay, Airbnb).
Consumer) Organisation acts as intermediary
B2G (Business to Supplying goods or services to government through digital procurement
Government) portals

Assessing E-Business Maturity

● Presence: Basic website — information only; no transactional capability


● E-commerce: Online transactions — customers can buy products or services digitally
● E-business: Fully integrated digital operations — supply chain, customer service, finance and HR all
connected
● Digital transformation: Business model fundamentally redesigned around digital capabilities; data-
driven decision-making throughout
E-business is not just a technology investment — it requires redesigning processes, developing digital skills
and changing customer relationships. Organisations that bolt e-commerce onto an unchanged business
model typically underperform. True e-business requires integration across the entire value chain.

E4b – IT Supporting E-Business


Assess and advise on the potential application of information technology to support e-business. [3]

Technology Application in e-business


E-commerce Enables online buying and selling — product catalogue, shopping cart,
platform payment processing, order management
Customer Manages customer interactions, purchase history and preferences —
Relationship enables personalised marketing and service
Management
(CRM)
Enterprise Integrates back-office systems (finance, inventory, HR) with front-end e-
Resource Planning commerce — single source of truth
(ERP)
Supply chain Connects suppliers, manufacturers and distributors digitally — enables
management real-time visibility and automated ordering
systems
Payment gateways Secure processing of online payments — supports multiple payment
methods and currencies
Content Delivery Distributes website content globally to reduce load times — critical for
Networks (CDN) international e-commerce
Analytics and Analyses customer behaviour to personalise product recommendations,
personalisation pricing and content in real time
engines
Chatbots and AI Provides 24/7 automated customer support — reduces cost and improves
customer service response times
Cybersecurity Protects e-business transactions and customer data from fraud and
infrastructure cybercrime

E4c – The 6 I's of E-Marketing


Explore the characteristics of e-marketing using the 6 I's of interactivity, intelligence, individualisation,
integration, industry structure and independence of location. [2]

⮚ Interactivity Unlike traditional media (TV, print), e-marketing enables two-way communication.
Customers can respond, review, share and engage in real time. Organisations can respond to
individual customers directly
⮚ Intelligence Digital channels generate vast amounts of data about customer behaviour,
preferences and responses. This intelligence enables far more targeted and effective marketing
than traditional methods
⮚ Individualisation Marketing messages can be personalised to individual customers based on
their behaviour, preferences and history — at scale. Mass personalisation is only possible digitally
⮚ Integration E-marketing should be integrated with other marketing channels (offline advertising,
PR, in-store) and with internal systems (CRM, inventory) for a consistent customer experience
⮚ Industry structure The internet changes competitive dynamics — it reduces barriers to entry,
enables disintermediation (cutting out intermediaries) and creates new types of competitors
(platform businesses, comparison sites)
⮚ Independence of location Digital marketing and e-business remove geographic constraints.
Organisations can reach global customers; customers can buy from anywhere. This creates
opportunity but also intensifies competition
Exam Technique — How to Apply the 6 I’s
Where the task asks how e-marketing can achieve a goal, lead with practical suggestions for how e-
marketing tools would be used and weave in relevant I's as supporting concepts only where they genuinely
add something.
Where the task asks you to evaluate the benefits of e-marketing for a specific initiative, the 6 I's can work
as sub-headings, but each point must include genuine evaluation — how beneficial will this characteristic
actually be in this context, and are there limitations or disbenefits?
Where the task asks you to evaluate an e-marketing strategy from a financial perspective, the 6 I's are
entirely irrelevant — the response must focus on revenue forecasts, costs and investment appraisal.
One specific watch-out: Industry structure describes a general characteristic of e-marketing —
disintermediation and new competitive models — rather than something the organisation itself does. In
tasks focused on what the organisation can do with e-marketing, it will typically not earn marks and should
be left out unless the question specifically asks about competitive dynamics or e-business strategy.

E4d – Online Branding vs Traditional Branding


Assess the importance of online branding in e-marketing and compare it with traditional branding. [2]
Online Branding Traditional Branding
Medium Digital — website, social media, email, Physical — TV, radio, print, outdoor, in-
search, apps store
Reach Global — no geographic constraint Often local or national; international
requires significant investment
Cost Lower barrier to entry; highly targeted High cost for mass media; less precise
spend possible targeting
Interactivity Two-way — customers can engage, One-way — brand broadcasts to
review and share audience
Speed Real-time — campaigns can be launched Slow — long lead times for production
and modified instantly and placement
Measurement Highly measurable — click rates, Harder to measure — attribution is less
conversions, ROI tracked precisely precise
Customer Customers shape brand perception Brand has greater control over the
control through reviews and social media message
Consistency Risk of brand dilution if digital presence is Easier to maintain consistent brand
not managed carefully identity

Importance of online branding: in an environment where customers research products online before
purchasing, online brand perception is often the first and most influential impression. A strong online brand
builds trust, drives organic traffic through search and social media, and creates customer loyalty. Negative
online reviews or social media incidents can damage brand value rapidly and are very difficult to control.

E4e – Acquiring and Managing Suppliers and Customers Through E-Business


Explore different methods of acquiring and managing suppliers and customers through exploiting e-
business technologies. [2]
Customer Acquisition and Management
Organisations use a range of e-business technologies to acquire and retain customers.

⮚ Search Engine Optimisation (SEO): Improving organic search rankings to attract customers
searching for relevant products or services at low cost for long-term visibility
⮚ Pay-per-click (PPC) advertising: Paid search advertising (e.g. Google Ads) — instant visibility but
cost per click can be high
⮚ Social media marketing: Building brand presence and acquiring customers through social platforms
— organic and paid
⮚ Email marketing: Direct communication with existing customers — highly cost-effective for retention
and upselling
⮚ Affiliate marketing: Third parties promote the organisation's products in exchange for commission on
sales generated
⮚ CRM systems: Managing customer relationships, purchase history and preferences — enables
targeted retention and upselling
⮚ Loyalty programmes: Digital loyalty schemes incentivise repeat purchase and generate customer
behaviour data
Supplier Acquisition and Management

⮚ E-procurement portals enable online tendering and supplier management, reducing costs and
increasing transparency.
⮚ E-procurement portals : Online platforms for tendering, purchasing and managing supplier
relationships — reduces cost and increases transparency
⮚ Electronic Data Interchange (EDI): Automated exchange of business documents (orders, invoices)
between systems — reduces manual processing and errors
⮚ Supplier portals: Online platforms where suppliers can view orders, submit invoices and manage
their relationship with the organisation
⮚ Reverse auctions: Online auctions where suppliers bid for contracts by offering lower prices —
drives cost reduction through competition
⮚ Supply chain visibility platforms: Real-time tracking of inventory and orders across the supply chain
— reduces stock-outs and improves planning
EDI automates the exchange of business documents between systems, reducing manual processing and
errors. Supplier portals allow suppliers to view orders, submit invoices and manage relationships without
staff interaction. Reverse auctions drive cost reduction through competitive bidding. Supply chain visibility
platforms provide real-time tracking of inventory and orders, reducing stock-outs and improving planning.
A prominent application is Just-in-Time inventory control, where systems are linked directly to suppliers so
orders trigger automatically when stock falls below a threshold — eliminating manual ordering delays and
costs.
Social Costs
E-commerce creates wider social costs that must be considered. Local store closures can cause social
deprivation for those without internet access. Automation reduces demand for retail, warehousing and
customer service staff, causing unemployment. Offshoring shifts jobs to lower-cost economies. Cross-
border operations create regulatory enforcement gaps, and data security remains an ongoing challenge as
cyber threats evolve faster than security solutions.

B2B E-Commerce — Overhauling Inefficient Processes


B2B e-commerce is well-established and fast-growing. A key driver is the overhaul of inefficient trading
processes: companies can link directly to suppliers via supplier portals or extranets, check product
availability, place orders and track shipments without delay or human assistance. A prominent application is
Just-in-Time (JIT) inventory control — companies link their systems to suppliers so that orders are triggered
automatically when stock falls below a threshold, eliminating the delay and cost of manual ordering cycles.
The best organisations use e-commerce to clarify customer demand, target marketing more precisely,
tighten business processes and develop new distribution methods.
Intranet vs Extranet
Intranet: a closed, internal network used exclusively within the organisation. Uses the same protocols as
the internet but protected by a firewall that blocks unauthorised external access. Used for internal
communications, knowledge sharing and process management.
Extranet: an extension of the organisation’s intranet made accessible to selected external parties —
suppliers, distributors and corporate customers — via password-controlled access. Many B2B transactions
are conducted over extranets. A supplier can access an organisation’s extranet to view purchase orders,
submit invoices and manage the relationship without needing to interact with internal staff. This is distinct
from the public website: access is restricted and the information available is more sensitive than what is
shown publicly.

E5 – IT Systems Security and Control


E5a – Strategic Need for Information Systems Control
Discuss, from a strategic perspective, the continuing need for effective information systems control within an
organisation. [3]
Effective information systems control is a strategic imperative, not just a technical issue. As organisations
become more data-dependent and digitally integrated, the consequences of control failure become
increasingly severe.
Strategic
Why it matters
reason

Data as a Organisations depend on accurate, reliable data for decision-making. Poor controls
strategic asset over data integrity undermine the quality of every strategic and operational decision

GDPR, financial reporting requirements and sector-specific regulations impose legal


Regulatory
obligations on data protection and system integrity. Non-compliance results in fines,
compliance
sanctions and reputational damage
Business System failures or cyberattacks can halt operations entirely. Effective controls protect
continuity the organisation's ability to continue operating
Stakeholder Customers, investors and partners need confidence that the organisation's systems
confidence are secure and reliable. Control failures destroy trust
Financial Financial systems must be protected against fraud, manipulation and error. System
integrity controls are the first line of defence for financial reporting integrity
Competitive A cyberattack or data breach gives competitors intelligence about the organisation's
risk customers, pricing and strategy

Information systems control is a board-level governance responsibility, not just an IT function issue. The
board must set the organisation's risk appetite for information security, ensure adequate resources are
allocated and receive regular reporting on control effectiveness.

E5b – Adequacy of IT and Systems Security Controls


Assess and advise on the adequacy of information technology and systems security controls for an
organisation. [3]
To assess the adequacy of IT and systems security controls, the organisation should consider whether
controls are proportionate to the risks, operating effectively, and regularly tested.
Key controls include:

● Access controls — use strong passwords, multi-factor authentication, role-based access and
privileged access management to ensure only authorised users can access systems.
● Data controls — encrypt sensitive data, classify data by importance, and maintain reliable backup
and recovery procedures.
● Network controls — use firewalls, intrusion detection systems, network segmentation and VPN
access for remote workers.
● Application controls — use input, processing and output controls to ensure data entered, processed
and reported by systems is accurate and authorised.
● Physical controls — restrict access to server rooms and protect hardware from theft, damage or
unauthorised use.
● Change controls — require system changes to be tested, authorised and documented before
implementation.
● Monitoring controls — maintain audit logs, monitor unusual activity and investigate potential
breaches promptly.
Where weaknesses exist, management should strengthen controls through penetration testing, vulnerability
scanning, internal audit reviews, improved access controls and staff training.

E5c – Promoting Cyber Security


Evaluate and recommend ways to promote cyber security. [3]
Cyber security should be treated as a strategic business risk, not just an IT issue, because attacks are
constantly evolving and technical controls alone are insufficient.
Ways to promote cyber security include:

● Board-level ownership — cyber risk should be on the board agenda, with clear accountability,
risk appetite and adequate resources.
● Employee training and awareness — staff should be trained on phishing, password security
and social engineering, as human error is a common weakness.
● Access controls — use multi-factor authentication, strong passwords and least privilege access
to reduce unauthorised access.
● Patch management and secure configuration — systems should be updated regularly to fix
known vulnerabilities.
● Network and malware protection — use firewalls, anti-malware software, intrusion detection
and monitoring.
● Incident response and recovery planning — maintain tested backups and a documented
response plan to minimise disruption.
● Third-party risk management — assess suppliers’ cyber security because breaches may
originate in the supply chain.
Overall, cyber security controls must be regularly reviewed, tested and updated, as attackers’ methods
change over time.

E5d – Controls Over IT Assets


Evaluate and recommend improvements or changes to controls over the safeguard of information technology
assets, to ensure the organisation meets its business objectives. [3]
IT Asset Categories

● Hardware — servers, workstations, laptops, mobile devices, networking equipment


● Software — operating systems, applications, licences
● Data — customer data, financial records, intellectual property, strategic plans
● Networks — internal networks, internet connections, cloud infrastructure

Control area Current weaknesses to look for Recommended improvements


Maintain a comprehensive, up-to-date IT
Asset No complete register of IT assets,
asset register, Ensure clear policies on use
inventory unauthorised personal devices/software
of personal devices for work
Excessive user privileges, shared Apply least privilege principle, regular
Access
accounts, former employees retaining access reviews, immediate deprovisioning
management
access when staff leave
Unencrypted sensitive data, data stored Encrypt all sensitive data, enforce data
Data
in unapproved locations, unclear data classification policy, implement data loss
protection
retention policies prevention (DLP) tools
Infrequent backups, untested recovery
Backup and Daily automated backups, offsite/cloud
procedures, backups stored in same
recovery backup, regular recovery testing
location as primary data
Restricted access to server rooms, CCTV,
Physical Server rooms accessible to non-IT staff,
hardware security labelling, secure disposal
security hardware not tracked or locked
of decommissioned assets

IT controls must be aligned to the organisation's business objectives:

⮚ If the objective is customer trust; data protection and breach prevention controls are critical
⮚ If the objective is operational efficiency; system availability and performance controls take priority
⮚ If the objective is regulatory compliance; audit trails, access controls and data retention policies are
essential
⮚ If the objective is strategic confidentiality; controls over intellectual property and sensitive commercial
data must be prioritised
IT control frameworks are only effective if they are embedded in the organisation's culture and processes.
Controls that exist on paper but are routinely bypassed because they are too cumbersome or poorly
designed, provide no real protection. The board must balance security with usability, ensuring controls are
proportionate and practical.
SBL - Section F - Organisational Control and Audit
F1 – Management and Internal Control Systems
F1a – The COSO Framework
Evaluate the key features of effective internal control systems such as those included in the COSO
framework. [3]
COSO (ICIF) is used for designing, implementing and evaluating internal control. COSO cube has three
dimensions;
1) Objectives across the top: operations, reporting and compliance. These represent the objectives the
organisation is trying to achieve; operational effectiveness and efficiency, reliable financial reporting, and
compliance with laws and regulations.
2) The five interrelated components of an effective internal control system on the front face:

The foundation of all other components (‘the tone from the top’).
Includes the board's and management's competence and
1. Control
accountability, their commitment to ethics, governance, culture, A weak
Environment
control environment undermines all other controls regardless of how
well they are designed
Identifying and assessing risks that could prevent the objectives from
being achieved; internal and external risks and risks of material
2. Risk Assessment
misstatement in financial reporting. Risk assessment must be ongoing,
not a one-off exercise
The policies and procedures that ensure management directives are
carried out; approvals, authorisation, segregation of duties,
3. Control Activities
reconciliations, reviews of performance and IT controls. These are the
specific controls that mitigate identified risks

Ensuring relevant information is identified, captured and communicated


4. Information and in a timely manner to the right people; internal communication
Communication (management information) and external communication (reporting to
shareholders and regulators)

Ongoing review of whether the five controls are present, working or


5. Monitoring being improved. Includes management oversight, internal audit reviews
Activities and external audit. Weaknesses identified must be communicated and
corrected promptly.

3) Organisational units on the side: The model can be applied to the whole organisation or to specific
divisions, subsidiaries or business units. This means a control weakness identified at one unit level can be
evaluated for its impact on the entity as a whole.
COSO provides reasonable assurance, not absolute assurance; if management treats it as a checklist rather
than embedding it in culture, controls will be weak regardless of their design.
Controls depend on people, so they can fail through human error, poor judgement or be deliberately bypassed
through management override or collusion, even where segregation of duties exists.
Controls must be cost-effective; spending more on a control than the risk is worth makes no commercial
sense, linking to ALARP. They must also be regularly reviewed, as changes in strategy, regulation or the
external environment can make existing controls outdated.

F1b – Information Flows to Management


Assess whether information flows to management are adequate for the purpose of managing internal
control and risk. [3]
For internal controls to work, management must receive timely, relevant and reliable information about what
is happening across the organisation. Inadequate information flows mean control weaknesses go undetected
and risks go unmanaged.
Qualities of Effective Management Information

⮚ Timely: Provided quickly enough to enable corrective action. Major control failures should trigger
immediate escalation; routine reporting may be monthly or quarterly

⮚ Relevant: Pitched at the right level of detail for the recipient. Front-line managers need operational
detail; the board needs summarised strategic-level information

⮚ Reliable: Based on accurate, verified data. Information from unreliable systems or processes cannot
be trusted for control purposes

⮚ Complete: Covers all significant risk areas. Gaps in reporting mean the board has a partial picture

⮚ Comparable: Consistent over time so trends can be identified; benchmarked against targets or
external comparators
Signs of Inadequate Information Flows

● The board is surprised by control failures that operational management was aware of
● Risk registers are not regularly updated or reviewed at board level
● Management information is produced manually with significant time delays
● Different parts of the organisation report the same metrics differently — no single source of truth
● Whistleblowing disclosures reveal problems that formal reporting channels failed to surface
● Internal audit findings consistently identify issues that management was unaware of
Information flows are only as good as the culture that surrounds them. In organisations where bad news is
unwelcome or mistakes are punished, management information will be filtered and sanitised before reaching
the board. The control environment (COSO component 1) must create psychological safety for accurate
upward reporting.

F1c – Effectiveness and Weaknesses of Internal Control Systems


Evaluate the effectiveness and potential weaknesses of internal control systems. [3]

Control area Strength / sign of effectiveness Weakness and consequence

Controls are documented in SOPs, Controls may exist on paper but


Control
communicated clearly and not operate in practice, giving false
documentation and
consistently applied across the assurance and allowing errors or
communication
organisation. misconduct to continue.

No single individual can initiate, Lack of segregation allows one


Segregation of
authorise and record the same person to commit and conceal
duties
transaction. fraud or errors without detection.

Transactions are properly reviewed Inadequate authorisation may lead


Authorisation
and approved before being to unauthorised expenditure,
controls
processed. commitments or transactions.

Regular checks identify errors, If reviews are not performed or


Reconciliations and
omissions and irregularities followed up, errors and control
independent reviews
promptly. failures may remain undetected.
Internal audit findings are acted If audit recommendations are
Audit findings and
upon, with recommendations ignored, known weaknesses
follow-up
implemented and reviewed. persist and may worsen over time.

A weak tone from the top may lead


The board and senior management
Control environment to controls being bypassed, fraud
show genuine commitment to
(‘tone from the top’) going unreported and misconduct
integrity, ethics and control.
becoming normalised.

Technology supports manual Over-reliance on IT controls


IT controls and audit controls, and all actions, approvals without testing may allow
trail and changes are traceable from automated controls to fail silently,
step to step. leaving errors or fraud undetected.

Controls are regularly reviewed, Insufficient monitoring means


Monitoring and
tested and updated to remain controls may deteriorate or become
review
effective. outdated over time.

F1d – Importance of Internal Control and Legal Compliance


Discuss and advise on the importance of sound internal control and legal and regulatory compliance and the
consequences to an organisation of poor control and non-compliance. [2]

Why Internal Control Matters Consequences of Poor Control

⮚ Loss of investor confidence — share price falls, cost of


⮚ Gives shareholders and capital rises
stakeholders confidence in
governance ⮚ Business disruption — cyberattack, regulatory
suspension or fraud investigation can halt operations
⮚ Underpins operational entirely
efficiency — well-controlled
processes run more smoothly ⮚ Legal liability — directors may face personal liability;
and cost-effectively organisation may face civil or criminal prosecution

⮚ Ensures reliability of financial ⮚ Loss of licence to operate - In heavily regulated


and non-financial reporting industries (banking, healthcare, utilities), serious control
failures can result in the regulator withdrawing the
⮚ Enables the board to manage organisation's operating licence
risk within its stated risk
appetite ⮚ Regulatory fines — breach of financial regulations,
GDPR, health and safety or environmental law
⮚ Supports compliance with
laws, regulations and ⮚ Financial loss — fraud, theft and error go undetected;
contractual obligations decisions made on unreliable information

⮚ Protects assets from theft, ⮚ Reputational damage - Control failures become public
fraud and waste — customers, investors and partners lose confidence;
brand value is destroyed

F1e – Recommending New or Improved Internal Controls


Recommend new internal control systems or changes to the components of existing systems to help prevent
fraud, error, waste or harmful environmental impacts. [2]
Prevent fraud: Implement effective operational controls such as segregation of duties, authorisation
procedures and independent reviews. For example, different individuals should be responsible for initiating,
approving and recording payments.
Whistleblowing channels should also be introduced so employees feel safe reporting suspected fraud or
unethical behaviour. The board and senior management must take visible action against fraud so that integrity
and honesty are promoted from the top down.
Prevent error: Train staff, have SOPs accessible with clear guidance and effective management supervision.
Technology can also help prevent errors through automated validation checks, such as completeness
checks, range checks and field type checks. However, system controls should be supported by manual
reviews, because technology can fail or be incorrectly configured.
There should also be a culture where mistakes and bad news are not punished unfairly. This encourages
employees to report control failures early so corrective action can be taken.
Prevent waste: Report on financial variances, investigate material variances and commit to process
improvement. Innovation and implementation of modern systems can also reduce waste by finding more
efficient ways to carry out operational activities, leading to cost savings and better use of resources.
Prevent Environmental Harm: Implement management system, such as ISO 14001 or EMAS, with clear
targets, regular monitoring and reporting of environmental performance. Staff should also be trained on
environmental procedures, and breaches should be investigated promptly.
Controls will only be effective if environmental responsibility is also embedded into strategy and culture. A
normatively driven organisation is more likely to treat environmental protection as a genuine responsibility,
rather than simply doing the minimum required for legal compliance.

F2 – Audit and Compliance


F2a – The Need for an Internal Audit Function
Examine the need for an internal audit function in the light of regulatory and organisational requirements. [3]
Internal audit is an independent, objective assurance and consulting activity that helps improve an
organisation’s operations. It reviews whether risk management, internal control and governance processes
are working effectively. It can identify weaknesses before they lead to fraud, error, waste, regulatory breach
or reputational damage.
Internal audit as the “control of controls” — internal audit does not usually operate day-to-day controls
itself. Instead, it reviews whether the organisation’s risk management, internal control and governance
controls are properly designed and operating effectively. It is therefore a higher-level control over the control
system.
Regulatory Requirements
• The UK Corporate Governance Code does not mandate internal audit for all companies but requires
the audit committee to consider whether one is needed and explain if not
• For listed companies and those in regulated industries (financial services, healthcare), internal audit
is effectively expected as part of good corporate governance
Turnbull Criteria — Assessing Whether Internal Audit Is Needed

Turnbull factor What it indicates


Large, diverse or complex organisations have more control points
Scale, diversity and and higher risk exposure. The board cannot adequately oversee all
complexity of operations of these without dedicated IA resource. In smaller organizations, this
may be managed by the management team
A large workforce increases transaction volume, reporting
Number of employees
complexity and the risk of fraud or error.
The value of assurance and risk reduction should justify the cost.
Cost-benefit
For smaller organisations, outsourced IA may be more cost-effective
considerations
than a full in-house function
Restructuring, acquisitions or new business models create new risks
Changes in
and control gaps — existing controls may no longer be appropriate
organisational structure
or may not cover new entities
Entering new markets, new regulations or new threats (e.g. cyber)
Changes in key risks require a risk management response — IA may be needed to review
whether controls are adequate for the new risk profile
Problems with internal Known weaknesses or failures suggest management monitoring
control systems may be insufficient, so independent review is needed.
Unexplained or Repeated losses, errors, complaints or near-misses indicate
unacceptable events systemic control failure. IA is need to prevent recurrence

Internal audit is only valuable if it is independent, capable, properly resourced and supported by the audit
committee. Its findings must also be acted upon. If recommendations are ignored, or if internal audit becomes
a tick-box compliance function, it may provide false assurance rather than genuine improvement.
Internal audit and CSR/environmental controls — internal audit can review whether CSR and
environmental policies have been implemented effectively, whether performance targets are being
monitored, and whether CSR objectives are aligned with wider corporate strategy. This links IA to
environmental management systems such as EMAS and ISO 14001.
However, internal audit is not a complete solution to strategic-level control failures. It is most effective at
reviewing operational controls, such as whether processes, transactions and procedures are working as
designed. Issues such as management override, poor board decisions or a domineering CEO require
stronger governance, independent non-executive directors and effective board oversight. Internal audit is
therefore complementary, but not sufficient on its own.

F2b – Auditor Independence [Level 3]


Justify the importance of auditor independence in all client-auditor situations (including internal audit) and the
role of internal audit in compliance. [3]
Auditor independence is the cornerstone of audit value. An audit that lacks independence provides no
genuine assurance; it may actually be worse than no audit at all because it creates false confidence.
Independence ensures the auditor's findings reflect reality rather than what management wants to hear. It
protects the auditor from pressure to sign off on inaccurate or misleading information. Without independence,
audit opinions cannot be trusted by shareholders, regulators or the market. Perceived independence
(appearance) matters as much as actual independence. If stakeholders believe the auditor is compromised,
they will discount the audit opinion.
Threats to Auditor Independence: Self-interest, Self-review, Advocacy, Familiarity, Intimidation
Safeguards Against Independence Threats

⮚ Audit partner rotation — prevents familiarity threat building over time


⮚ Prohibition on auditors holding shares in audit clients
⮚ Limits on non-audit services provided to audit clients — prevents self-review and advocacy threats
⮚ Audit committee oversight — NEDs scrutinise the auditor relationship and approve appointment
⮚ Mandatory tendering of audit contracts — reduces client dependency
⮚ Professional body codes (IESBA) — set minimum independence standards globally
Internal audit faces a structural independence challenge; it is part of the organisation it audits. Independence
is maintained through:

Action Reason
Reporting directly to the audit committee If internal audit only reports to management,
(independent NED’s) rather than to managers could hide, soften or influence
management. negative findings about themselves.
The Head of Internal Audit should be able to serious control failures, fraud concerns or
speak directly to the audit committee chair or management interference can be escalated
board if there is a serious issue. without being blocked by management.
stops management from saying “you cannot
formal document setting out internal audit’s role,
audit this area” or “you cannot access these
authority, access rights and reporting lines.
records.”
Prohibition on internal auditors auditing areas
they would be checking their own previous
(departments/processes) they previously
work, which creates a self-review threat
managed
checks that internal audit is competent,
Periodic external review of the internal audit
independent and adding value, rather than
function
becoming weak or tick-box.

Role of Internal Audit in Compliance

● Testing compliance controls to check whether they are properly designed and operating effectively.
● Identifying compliance gaps, such as breaches of law, regulation, company policy or industry standards.
● Reviewing high-risk areas, such as anti-bribery, data protection, health and safety, environmental
controls, financial crime or procurement.
● Reporting findings to the audit committee, so issues are escalated independently from management.
● Recommending corrective action where weaknesses or breaches are found.
● Following up recommendations to check that management has taken action.
● Supporting regulatory readiness by helping ensure the organisation can evidence compliance during
inspections, audits or regulatory reviews.

F2c – The Audit Committee


Justify the importance of having an effective internal audit committee overseeing the internal audit function.
[2]
The audit committee provides independent oversight of the internal audit function, ensuring it remains
genuinely independent of management and that its findings receive appropriate attention at board level.
Composition: the audit committee must be made up of at least three independent NEDs, with at least one
member having relevant financial experience. This ensures the committee has both independence from
management and the expertise to scrutinise audit findings effectively.
Why an Effective Audit Committee Matters

Role Why it matters


Ensures internal audit focuses on the highest-risk areas
Approves internal audit plan
rather than what management prefers to have audited
Provides a direct channel for audit findings to reach the
Reviews internal audit reports
board without being filtered by management
Monitors implementation of Ensures management acts on findings — without this
audit recommendations oversight, recommendations may be ignored
Assesses the effectiveness of Ensures internal audit has adequate resources, capability
the internal audit function and independence to do its job
Approves appointment and
Protects the CAE's independence from management
remuneration of Chief Audit
influence
Executive
Internal auditors can raise concerns with the audit
Provides a safe escalation route committee directly if management is unresponsive or
obstructive
F2d – Responding to Auditors' Recommendations
Assess the appropriate responses to auditors' recommendations. [3]

⮚ Accept and implement: Recommendation is valid, cost-effective and the risk it addresses is material.
Management agrees a remediation plan with clear ownership and timeline. This is the most common
appropriate response
⮚ Accept but defer: Recommendation is valid but implementation requires resources or system
changes that cannot be delivered immediately. An interim mitigating control should be put in place
while awaiting full implementation
⮚ Accept in principle but modify: Management agrees with the underlying concern but proposes an
alternative control that addresses the risk equally effectively. Must be justified to the audit committee
⮚ Reject — risk accepted: Management disagrees that the risk is material or believes the cost of the
recommended control outweighs the benefit. Must be formally documented, approved by the audit
committee and reviewed if circumstances change
Red Flags in Audit Response

● Repeat findings: the same weaknesses appear in successive audit reports, indicating management is not
genuinely implementing recommendations
● Unexplained deferrals: recommendations are accepted but implementation is repeatedly delayed without
valid reason
● Blanket rejection: management routinely rejects findings without engaging with the substance of the
concern
The quality of an organisation's response to audit recommendations is a direct reflection of its control
environment and governance culture. An organisation that consistently accepts, acts on and follows up audit
recommendations demonstrates genuine commitment to good governance. One that repeatedly defers,
modifies or rejects findings, particularly without adequate justification, signals a culture where controls are
treated as a compliance exercise rather than a genuine management tool.

F3 – Internal Control and Management Reporting


F3a – Reports on Internal Controls to Shareholders
Justify the need for reports on internal controls to shareholders. [3]
Shareholders appoint directors to manage the company on their behalf. As principals in the agency
relationship, shareholders need assurance that directors are managing the business responsibly and that
appropriate controls are in place to protect their investment.

Reduces information Shareholders cannot observe day-to-day operations, so control


asymmetry reporting gives them visibility over how management is managing risk.
Directors are responsible for maintaining an effective system of
Accountability internal control. Reporting makes this accountability visible and
enforceable.
Investors and analysts use control disclosures to assess governance
Investor confidence quality. Weak or unclear disclosures may reduce confidence and
increase the cost of capital.
Regulatory/
The UK Corporate Governance Code requires the board to report on
governance
the effectiveness of internal controls (‘comply or explain’)
expectation
Disclosure of control weaknesses allows shareholders to challenge or
Early warning engage with the board before problems escalate into significant
losses
Customers, suppliers, lenders and regulators may also take comfort
Stakeholder trust
from evidence that robust controls are in place.

F3b – Contents of an Internal Control Report


Discuss the typical contents of a report on internal control and internal audit including environmental and
sustainability audits. [2]
A report on internal control and internal audit explains how the organisation manages risk, how controls are
reviewed, and whether any significant weaknesses have been identified.
A report on internal control explains how the organisation manages risk, how controls are reviewed, and
whether significant weaknesses have been identified. It typically contains a

● board responsibility statement confirming the board owns the system of internal control
● a risk management framework explaining how risks are identified, assessed and managed
● a description of key controls over financial reporting, operations, compliance, IT and fraud prevention
● a review of effectiveness explaining how the board assessed controls using internal audit,
management reviews and audit committee oversight
● disclosure of any significant weaknesses and corrective action taken
● an internal audit summary covering areas reviewed, findings and recommendations
● an audit committee report explaining how the committee has overseen the overall control and
reporting framework.
Environmental and Sustainability Audits
Environmental audits assess compliance with environmental laws, review the effectiveness of environmental
management systems such as ISO 14001 and EMAS, and measure performance against agreed metrics
covering:

● emissions (pollution, waste, greenhouse gases)


Together comprising the organisation's
● consumption (energy, water, non-renewable environmental footprint.
feedstocks)

Sustainability audits are broader, assessing performance across all ESG dimensions and verifying
sustainability disclosures. TCFD disclosures are increasingly included, covering board oversight of climate-
related risks and the controls in place to manage them.
These audits matter for three reasons:
1. Environmental issues create financial liability and reputational damage that investors assess when
determining long-term value.
2. Ethical and environmental performance affects both resource markets (employees choose employers
on ethical grounds) and product markets, making it a competitive factor.
3. ESG-focused investment has moved from niche to mainstream, meaning poor environmental
disclosure can directly raise the cost of capital.
Unlike financial audit, environmental and sustainability audit remains largely voluntary and unstandardised,
allowing organisations to select what to report on and which frameworks to apply, making comparison across
organisations difficult.

F3c – Internal Controls Underpinning Reliable Reporting


Assess how internal controls underpin and provide information for reliable financial and sustainable reporting.
[3]
Financial and sustainability reports are only as reliable as the controls that underpin the data and processes
used to produce them. Without effective internal controls, even the most sophisticated reporting frameworks
produce unreliable outputs.
Controls Underpinning Financial Reporting

● Authorisation controls - Ensure transactions are approved by appropriate personnel before


processing. This prevents unauthorised transactions distorting the financial statements
● Segregation of duties - Prevents any individual from initiating, recording and reviewing their own
transactions. This reduces the risk of fraud and error going undetected
● Reconciliations - Regular reconciliation of accounts (bank reconciliations, intercompany
reconciliations) identifies discrepancies before they flow into financial statements
● Period-end close controls - Structured month-end and year-end close processes ensure all
transactions are captured, accruals and prepayments are made and cut-off is correct
● Management review controls - Senior management reviews financial reports for anomalies,
unexpected variances and trends that may indicate errors or manipulation
● IT application controls - Input validation, processing controls and output controls embedded in
financial systems ensure data integrity throughout the reporting process
Controls Underpinning Sustainability Reporting
Sustainability reporting relies on non-financial data (emissions, energy use, social metrics) that is harder to
measure and verify than financial data. Controls must be designed specifically for these data flows:

● Data collection controls: standardised processes for collecting environmental and social data
across the organisation; clear data ownership. Where data cannot be directly measured,
consistent and documented estimation methodologies must be applied
● Validation controls: checking that sustainability data is complete, accurate and consistent with
operational records (e.g. energy bills, waste disposal records)
● Management review: sustainability data should be subject to the same rigour of management
review as financial data
● Internal audit coverage: sustainability reporting should be included in the internal audit plan,
particularly for material ESG metrics
● External assurance: third-party verification of sustainability disclosures (limited or reasonable
assurance) increases their credibility with stakeholders
Currently, sustainability reporting controls are typically far less mature than financial reporting controls,
creating a significant gap in reporting reliability. Boards and audit committees must prioritise closing this gap
as regulatory expectations (EU CSRD, TCFD) raise the bar for sustainability disclosure quality.
SBL — Section G - Finance in Planning and Decision-Making
G1 – Finance Transformation
G1a – Technology Transforming the Finance Function
Discuss how advances in technology are transforming the finance sector and the role and structure of the
finance function within organisations. [2]
Technology is fundamentally changing what the finance function does and how it is structured. Routine
transactional work is being automated, freeing finance professionals to focus on analysis, insight and
business partnering.

Technology What it does Impact on finance function

Automates repetitive, rule-based tasks Reduces headcount in transactional


Robotic Process
(e.g. invoice processing, roles; eliminates human error; speeds
Automation (RPA)
reconciliations, data entry) up processing

Artificial Intelligence Analyses large datasets to identify Enhances forecasting accuracy;


(AI) & Machine patterns, forecast outcomes and flag improves fraud detection; automates
Learning anomalies audit sampling

Delivers finance systems and data Reduces IT infrastructure costs;


Cloud computing storage via the internet rather than on- enables real-time data access;
premise servers supports remote working

Processes and analyses large volumes Enables deeper performance insight;


Big data & analytics
of structured and unstructured data supports real-time decision-making

Potential to transform audit and


Decentralised, tamper-proof ledger for
Blockchain financial reporting; reduces
recording transactions
reconciliation effort

Integrated software systems Single source of truth across the


Enterprise Resource
connecting finance with operations, HR organisation; reduces duplication;
Planning (ERP)
and supply chain improves reporting

Impact on the Role and Structure of the Finance Function

● Shift from transaction processing to value-added analysis and business partnering


● Finance teams become smaller but require higher-level analytical and commercial skills
● Real-time reporting replaces periodic reporting — management can make faster decisions
● Finance becomes more integrated with the wider business rather than operating as a back-office function
● New risks emerge — cybersecurity, data integrity and over-reliance on automated systems

G1b – Alternative Structures for the Finance Function


Evaluate alternative structures for the finance function using business partnering, outsourcing and shared or
global business services. [3]
Structure Description Advantages Disadvantages

Deep understanding of
Finance professionals are the business; finance Risk of losing objectivity;
Business embedded within business finance partner may become
adds direct strategic
Partnering units, working alongside too aligned with the
value; improves quality
operational managers to of decisions business unit they support;
provide financial insight and higher cost than centralised
support decision-making model

Transferring finance Cost reduction; access Loss of control; dependency


processes (e.g. payroll, to specialist expertise; on provider; data security
Outsourcing accounts payable, tax scalability; frees internal risks; difficult to reverse;
compliance) to an external resource for higher- service quality may
provider value work deteriorate

Cost efficiency through One-size-fits-all may not


Consolidating transactional
Shared standardisation and meet specific divisional
finance processes into a
Services economies of scale; needs; cultural resistance;
single internal unit serving
Centre (SSC) consistent processes significant upfront
the whole organisation
across divisions investment to establish

Evolution of SSC operating Greater scale


Global
across international efficiencies; access to Complexity of managing
Business
boundaries, often combining global talent; across time zones, cultures
Services
finance, HR and IT in one standardised processes and regulatory regimes
(GBS)
integrated service model worldwide

the optimal structure depends on the organisation's size, strategy and geographic footprint. Many large
organisations use a hybrid model — business partners embedded in the business for high-value advisory
work, with transactional processes in a shared service centre or outsourced. The key risk in all models is
maintaining appropriate control and quality.

G2 – Financial Analysis and Decision-Making Techniques


G2a – Overall Investment Requirements
Determine the overall investment requirements of the organisation. [2]
Determining investment requirements involves identifying what capital the organisation needs to fund its
strategic objectives. This covers both long-term capital investment and short-term working capital needs.
Capital Investment (Long-term)

● Fixed asset investment — property, plant, equipment, technology infrastructure


● Acquisitions and joint ventures — buying other businesses or stakes in them
● Research and development — investing in future products and capabilities
● Strategic projects — major change programmes, system implementations, expansion into new markets
Working Capital (Short-term)
Working capital = current assets minus current liabilities. The organisation must hold enough working capital
to fund day-to-day operations without holding excess cash that earns no return.

● Inventory — stock must be held to meet demand but excess ties up cash
● Receivables — credit extended to customers creates a funding gap
● Payables — extending payment terms to suppliers reduces the funding gap
● Cash — a minimum cash buffer must be maintained for operational needs
The working capital cycle (cash conversion cycle) measures the time between paying for inputs and receiving
cash from customers. A shorter cycle reduces the funding requirement.
G2b – Sources of Finance
Assess and advise on alternative sources of short and long-term finance available to the organisation to
support strategy and operations. [3]
Long-Term Finance

Source Description Advantages Disadvantages

Raising capital by
No obligation to repay; no Dilutes existing
Equity (share issuing new shares to
interest cost; strengthens shareholders; costly to
issue) existing or new
balance sheet issue; dividend expectations
shareholders

no mandatory repayment dividends are not tax


Preference shares:
shares that usually of capital; less control deductible; fixed dividend
No ownership- fixed
carry a fixed dividend dilution than ordinary expectation increases
return, meaning set
but limited or no shares; fixed dividend financial pressure; may be
dividend.
voting rights. may be attractive to more expensive than debt.
investors.

Limited by profitability;
Using accumulated
opportunity cost of not
profits rather than No issuance costs; no
Retained earnings paying dividends; may signal
distributing them as dilution; flexible
lack of investment
dividends
opportunities

Increases financial risk;


Borrowing over a Interest is tax deductible; interest must be paid
Long-term debt
period typically no dilution of ownership; regardless of performance;
(bonds/loans)
greater than one year cheaper than equity covenants restrict
management freedom

Using assets without


purchasing them Preserves cash; off-
Higher total cost than
Leasing outright — either balance sheet (operating
purchase; asset not owned
operating or finance lease); flexible
lease

Investment by a PE
Large sums available; PE Loss of control; PE typically
firm in exchange for a
Private equity brings strategic expertise requires exit within 3-7
significant equity
and networks years; intensive monitoring
stake

Early-stage equity Patient capital; brings Significant equity stake


Venture capital investment in high- expertise; no repayment given up; loss of control;
growth businesses obligation difficult to obtain

Short-Term Finance

Source Description Best suited to

Flexible borrowing up to an agreed


Day-to-day cash flow management;
Bank overdraft limit; interest charged only on amount
unexpected short-term needs
used

Extended payment terms from suppliers Managing working capital; smoothing


Trade credit
— effectively interest-free finance cash flow
Invoice financing Advancing cash against outstanding Businesses with long receivables cycles;
/ factoring invoices before customers pay rapid growth requiring working capital

Commercial Short-term unsecured debt instruments Large, creditworthy organisations


paper issued by large companies needing short-term funds at low cost

Revolving credit A pre-agreed borrowing facility that can Businesses needing flexible access to
facility be drawn down and repaid repeatedly funds for operational purposes

Exam tip: when advising on sources of finance, always consider the organisation's existing capital structure
(gearing level), the purpose of the finance (short vs long-term need), the cost of each option and the impact
on control and financial risk. There is no universally correct answer — it depends on the organisation's
circumstances.

G2c – Investment Appraisal


Review and justify decisions to select or abandon competing investments, applying suitable investment
appraisal techniques. [3]
Technique How it works Advantages Disadvantages

Simple to calculate and Ignores time value of money;


Time taken to recover the
Payback understand; focuses on ignores cash flows after
initial investment from net
Period liquidity; useful for high- payback; does not measure
cash inflows
risk projects profitability

Average annual
Accounting Uses accounting data Uses profit not cash flow;
accounting profit as a %
Rate of that is readily available; ignores time value of money;
of initial or average
Return (ARR) easy to understand affected by depreciation policy
investment

Present value of all future Accounts for time value Requires reliable cash flow
Net Present cash inflows minus initial of money; directly forecasts; sensitive to discount
Value (NPV) investment, discounted at measures value created; rate chosen; complex to
the cost of capital theoretically superior communicate

Can give misleading results


Internal Rate Discount rate at which Easy to compare against
with non-conventional cash
of Return NPV = 0 — the return the cost of capital; intuitive
flows; ignores project scale;
(IRR) project generates percentage return
multiple IRRs possible

Selecting or Abandoning Investments


When selecting between competing investments:

● NPV is the theoretically preferred method — accept projects with positive NPV; select the highest
NPV when mutually exclusive
● IRR should exceed the cost of capital (hurdle rate) — but use NPV as the primary decision rule when
IRR conflicts
● Payback provides a useful secondary filter — particularly relevant in high-risk or rapidly changing
environments
● Qualitative factors must also be considered — strategic fit, risk profile, stakeholder impact
When considering abandonment:

● Sunk costs are irrelevant — only future incremental cash flows matter
● Compare the NPV of continuing with the net realisable value of immediate disposal
● Consider strategic implications — abandoning a project may have reputational or stakeholder
consequences beyond the financial calculation
Investment appraisal techniques provide a framework for decision-making but are only as reliable as the
assumptions underpinning them.
Optimism bias: the tendency to overestimate benefits and underestimate costs is a common failure in
investment appraisal. Sensitivity analysis and scenario planning should be used to test the robustness of the
decision.

G2d – Decisions Under Risk and Uncertainty


Justify strategic and operational decisions taking into account risk and uncertainty. [3]

Risk: the probability distribution of outcomes is known or Both must be accounted for in
can be estimated. strategic and operational
Uncertainty: the probability distribution is unknown. decisions.

Sensitivity analysis - Tests how the decision changes if one variable changes (e.g. how much can costs
increase before NPV becomes negative). Identifies the key variables the decision is most sensitive to
Scenario analysis - Constructs best case, worst case and base case scenarios. Tests the decision under
different combinations of assumptions simultaneously
Expected value (EV) - Weights possible outcomes by their probability to produce a single expected outcome.
EV = Σ (probability × outcome). Useful for repeated decisions but can mislead for one-off decisions
Decision trees - Visual tool mapping out sequential decisions and chance events with associated
probabilities. Useful for complex multi-stage decisions
Simulation (Monte Carlo) - Runs thousands of scenarios using random values for key variables to produce
a probability distribution of outcomes. Provides the most comprehensive risk picture but complex to build
MAXIMIN - Conservative strategy: choose the option with the best worst-case outcome. Appropriate when
the downside is catastrophic
MAXIMAX - Optimistic strategy: choose the option with the best best-case outcome. Appropriate when the
upside is transformational and downside is acceptable
Minimax regret: Minimises the maximum regret (opportunity cost) from making the wrong decision
No technique eliminates uncertainty — they simply make it more visible and manageable. The choice of
technique should reflect the nature of the decision, the quality of available data and the organisation's risk
appetite. Quantitative analysis should always be combined with qualitative judgement.

G2e – Financial Reporting and Tax Implications


Assess the broad financial reporting and tax implications of taking alternative strategic or investment
decisions.[2]
Financial Reporting Implications

● Acquiring another business: Goodwill recognised on the balance sheet; annual impairment test
required; consolidation of subsidiary financials
● Organic growth investment: Capital expenditure recognised as assets and depreciated; affects
gearing and return on capital ratios
● Outsourcing: Reduction in assets and headcount; operating lease commitments now on balance
sheet under IFRS 16
● Issuing equity: Increases share capital and equity on balance sheet; dilutes EPS
● Taking on debt: Increases liabilities and gearing; interest charges reduce reported profit; debt
covenants may restrict future decisions
● Restructuring / closure: Provisions for redundancy and closure costs; impairment of assets;
potentially significant one-off charge to P&L
Tax Implications

● Capital allowances — tax relief is available on capital expenditure, but the timing differs from
accounting depreciation; affects the after-tax NPV of investments
● Interest tax shield — interest on debt is tax deductible, reducing the effective cost of debt finance
● Transfer pricing — multinational organisations must price transactions between group entities at
arm's length to comply with tax regulations
● Tax losses — losses can often be carried forward to offset future profits, affecting the timing of tax
payments
● Structuring decisions — the legal structure of an acquisition (asset purchase vs share purchase)
has different tax consequences for both buyer and seller

G2f – Organisational Performance Assessment


Assess organisational performance and position using appropriate performance management techniques,
KPIs and ratios. [3]
Profitability Ratios

Gross profit Gross profit / Revenue × 100 Efficiency of production — what % of revenue is left
margin after direct costs

Operating profit Operating profit / Revenue × Efficiency of operations — what % of revenue is left
margin 100 after all operating costs

Return on Profit before interest and tax Overall return generated on long-term capital. ROCE
Capital (PBIT) / (Shareholders’ equity = Profit margin × Asset turnover — use this
Employed + debt) × 100 decomposition to explain what is driving a change in
(ROCE) ROCE

Liquidity Ratios

Current Current assets / Current Ability to meet short-term obligations — above 1 means
ratio liabilities current assets exceed current liabilities

Quick Current assets – Inventory) / More stringent liquidity test — excludes inventory which
ratio Current liabilities may not be quickly converted to cash

Gearing Ratios

Gearing Debt / Equity × 100 Financial risk — proportion of funding from debt vs equity

Interest Operating profit / Interest Ability to service debt — how many times interest is covered
cover expense by operating profit

Investor Ratios

Earnings Per Share Profit after tax / Profit attributable to each share — key measure of
(EPS) Number of shares shareholder value creation
Price/Earnings (P/E) Share price / EPS Market's valuation multiple — how many years'
ratio earnings investors are willing to pay

Efficiency Ratios

Receivables Receivables /
Average time taken to collect payment from customers
days Revenue × 365

Payables / Cost of
Payables days Average time taken to pay suppliers
sales × 365

Inventory / Cost of
Inventory days Average time inventory is held before being sold
sales × 365

How efficiently assets are used to generate revenue.


Revenue / (Total Improves when revenue rises or asset base shrinks (e.g.
Asset turnover assets − current asset disposal, sale and leaseback). Deteriorates after
liabilities) asset acquisition until the asset generates a full year’s
return

Beyond Financial Ratios


Balanced Scorecard: assesses performance across four perspectives, recognising that financial
measures alone are insufficient:

Perspective Focus Example KPIs

Financial Has the organisation created value Revenue growth; ROCE; EPS; profit margin
for shareholders?

Customer How do customers perceive the Customer satisfaction score; market share;
organisation? retention rate; Net Promoter Score

Internal What must the organisation do well Process cycle time; defect rate; on-time
processes internally? delivery; cost per unit

Learning and Can the organisation sustain Employee engagement; staff turnover; training
growth improvement and change? hours; innovation pipeline

Balanced Scorecard is a more comprehensive performance framework than financial ratios alone, but it is
only as useful as the KPIs chosen. KPIs must be genuinely linked to strategic objectives - organisations
that measure everything effectively measure nothing. The board should ensure KPIs are reviewed regularly
and updated as strategy evolves.
Exam Technique: How to Discuss Financial Results (Significance → Reasons → Implications)
It is never enough to restate calculations or simply state that a ratio has increased or decreased. Every
figure must be discussed using a three-stage framework:
1. Significance: Why does this result matter strategically or operationally? Link the figure to objectives,
competitive position, stakeholder expectations. Do not just say “revenue has increased”
2. Reasons: Why has the figure changed? Use information from the scenario exhibits — do not just list
generic possibilities. Link to KPIs and other ratios to confirm or explain the movement. Consider whether
more than one factor may have contributed
3. Implications / Recommendations: What will happen if performance continues on this trajectory? What
action should management take? Implications often cascade e.g. falling visitor numbers may reduce
income from other revenue streams. Recommendations should be specific to the scenario
Effect of One-Off Items on Ratios
One-off events distort ratios and must be identified and adjusted for when making meaningful year-on-year
comparisons. Always consider whether the change is structural or a one-off before drawing conclusions.

One-off event Effect on ratios and what to say

Profit or loss on disposal hits P&L (distorts operating margin); asset base shrinks
(improves ROCE and asset turnover); cash inflow aids liquidity. This is a one-off —
Asset disposal
recalculate ROCE/margin excluding disposal to show underlying performance.
Consider: what would liquidity look like without the cash received?

Capital employed base grows — ROCE and asset turnover deteriorate without any
Asset
real change in operating capacity or profitability. Explain this distortion explicitly; it
revaluation
does not reflect underlying performance deterioration

Capital employed increases immediately but the asset has not contributed a full year’s
Mid-year asset profit — ROCE and asset turnover temporarily deteriorate. This is not a sign of poor
purchase performance; in future years the return should improve as the asset generates
revenue across a full period

Customer Revenue improves (higher volume) but gross profit margin falls (lower price per unit).
rebates / A favourable volume variance and adverse price variance occurring simultaneously —
discounts the net effect depends on whether the volume increase offsets the margin sacrifice

Industry Context and Benchmarking


Ratio benchmarks vary significantly by industry — never apply generic norms without considering the
sector context. A current ratio below 1 is typical in service businesses (little inventory, fast cash
conversion). A current ratio of 2 may signal inefficiency in fast-moving consumer goods. Payables days that
seem high may be normal in an industry where extended supplier credit is standard. Always compare ratios
to prior periods and industry averages rather than applying textbook ideals rigidly.

G3 – Cost and Management Accounting


G3a – Cost Management and Control Systems
Discuss, from a strategic perspective, the continuing need for effective cost management and control
systems within organisations. [3]
Effective cost management is not just an operational concern — it is a strategic necessity. The ability to
manage costs effectively determines the organisation's competitiveness, profitability and financial
resilience.
Why Cost Management Remains Strategically Important
Competitive pressure: In competitive markets, the ability to reduce costs while maintaining quality is a
source of sustainable competitive advantage — particularly for cost leadership strategies
Margin protection: Revenue growth alone is insufficient if costs grow faster. Cost management protects
margins and profitability
Resource allocation: Understanding costs helps the board allocate resources to their highest-value uses
— investing in profitable activities and exiting loss-making ones
Pricing decisions: Accurate cost information is essential for setting prices that are both competitive and
profitable
Strategic flexibility: A lean cost base gives the organisation more financial flexibility to invest in
opportunities or absorb economic shocks
Shareholder value: In the long run, sustainable cost management underpins the cash generation that
drives shareholder value
Modern Cost Management Approaches

Allocates overhead costs to products/services based on the activities that drive


Activity-Based
them, rather than simple volume-based absorption. Gives a more accurate
Costing (ABC)
picture of true product profitability

Sets a target cost based on the market price the customer will pay and the
Target costing required profit margin. Design and production must then achieve that cost —
cost is managed from the outside in

Considers the total cost of a product over its entire life — development,
Life cycle
production, use and disposal. Prevents short-term cost decisions that create
costing
higher long-term costs

Continuous improvement — sets incremental cost reduction targets for existing


Kaizen costing
products and processes rather than accepting current costs as fixed

Throughput Focuses on maximising the rate at which the organisation generates profit
accounting through its bottleneck constraint. Based on the Theory of Constraints

cost management systems must evolve alongside strategy. A standard costing system designed for mass
production may be entirely inappropriate for a service organisation or a business pursuing differentiation. The
board should periodically assess whether cost management systems reflect the current cost drivers and
strategic priorities.

G3b – Forecasting, Budgeting, Standard Costing and Variance Analysis


Evaluate methods of forecasting, budgeting, standard costing and variance analysis in support of strategic
planning and decision making. [3]
Forecasting: provides the financial projections that underpin strategic planning. Methods include;

Extrapolates historical trends into the future. Simple and data-driven but assumes
Time series
the future will resemble the past — inappropriate in volatile or rapidly changing
analysis
environments

Identifies statistical relationships between variables (e.g. sales and marketing


Regression
spend) to forecast outcomes. More sophisticated but requires reliable historical
analysis
data

Continuously updated forecasts (e.g. 12-month forward-looking) that replace


Rolling
static annual budgets. More responsive to changing conditions but resource-
forecasts
intensive

Scenario Develops multiple plausible futures rather than a single point forecast. More
planning honest about uncertainty; supports strategic flexibility

Budgeting: A budget is a quantified plan for a defined period, used to allocate resources, set performance
targets and control costs. Types of budgeting;

Method Description Advantages Disadvantages

Incremental Previous year's Simple and quick to prepare; Perpetuates


budgeting budget adjusted stable and predictable inefficiency: existing
by a percentage spend is rarely
for inflation or challenged; no
growth
incentive to reduce
costs

Zero-based Every line of Eliminates wasteful spending; Very time-consuming;


budgeting (ZBB) expenditure forces prioritisation; aligns requires significant
must be justified spend with strategy management effort;
from scratch can create short-
each period termism if applied
annually

Rolling budgets Budget is More responsive to change; Resource-intensive;


continuously reduces the gap between plan may reduce
updated — as and reality commitment if targets
one period are constantly revised
ends, a new
period is added

Activity-based Budget based More accurate resource Complex to


budgeting on the cost of allocation; links spend to value- implement; requires
activities creating activities ABC cost data
required to
deliver the plan

Beyond Replaces fixed Eliminates budget gaming Requires significant


Budgeting annual budgets (managers manipulating targets cultural change;
with flexible, or spending to hit budget figures harder to maintain
adaptive targets rather than making genuinely financial control
and good decisions, e.g. spending
decentralised remaining budget at year-end to
decision-making avoid cuts next year); more
responsive to change;
empowers managers

Standard Costing: sets predetermined costs for inputs (materials, labour, overheads) against which actual
costs are compared. It provides the benchmark for variance analysis.

● Standard costs are set based on expected efficiency levels, current prices and planned production
volumes
● They provide a basis for pricing, budgeting and performance measurement
● Most applicable in manufacturing environments with repetitive, standardised production processes
● Less applicable in service industries, project-based work or rapidly changing environments where
standards quickly become outdated
Variance Analysis: compares actual performance against standard or budgeted performance to identify
where and why performance deviated. Key variances:

Variance Favourable if... Adverse if... Strategic significance

Sales price Actual price > Actual price < May indicate pricing power or competitive
variance standard price standard price pressure on margins

Actual volume >


Sales volume Actual volume < Indicates market share gains or losses;
budgeted
variance budgeted volume demand forecasting accuracy
volume
Purchasing efficiency; supply chain
Material price Actual price < Actual price >
management; commodity price
variance standard price standard price
movements

Less material
Material usage More material used Production efficiency; waste management;
used than
variance than standard quality of materials
standard

Labour rate Actual rate < Actual rate > Workforce mix; pay rate changes; use of
variance standard rate standard rate overtime

Labour
Less hours than More hours than Workforce productivity; training
efficiency
standard standard effectiveness; quality of supervision
variance

Fixed overhead Actual overhead Actual overhead >


Cost control; capacity utilisation
variance < budgeted budgeted

Variances should be interpreted in context — a favourable variance is not always positive and an adverse
variance is not always negative. For example, a favourable material price variance achieved by buying
cheaper materials that cause quality problems creates adverse downstream consequences.
SBL Section H - Enabling Success, Managing Change and
Project Management
H1 – Enabling Success: Organising
H1a – Organisational Structure and Strategy
Advise on how organisational structure and internal relationships can be reorganised to deliver a selected
strategy. [3]

Structure Description Best suited to


Organised by business function (finance, Stable environments; single-product
Functional marketing, operations). Clear lines of businesses; where efficiency matters
authority and specialisation more than flexibility
Organised by product, geography or Diverse product ranges; multinational
Divisional customer segment. Each division operates organisations; where responsiveness
semi-independently to local markets matters
Combines functional and divisional Complex organisations needing both
Matrix structures. Employees report to both a specialist expertise and cross-
functional and a project/divisional manager functional collaboration
Flat / Few layers of management; wide spans of Small, innovative organisations;
Entrepreneurial control; fast decision-making start-ups; creative environments
Many layers of management; narrow spans Large, established organisations;
Tall /
of control; formal rules and procedures; public sector bodies; regulated
Bureaucratic
slower but more controlled decision-making environments
Network / Core organisation surrounded by a network Organisations pursuing outsourcing
Virtual of external partners and suppliers strategies; digital businesses

The recommended structure should depend on the organisation’s strategy, size, environment, product range
and need for control versus flexibility.
Internal relationships may also need to change so the new structure supports the selected strategy. This may
involve reorganising:

● Reporting lines - Clarifying who reports to whom, especially in divisional or matrix structures.
● Authority and decision-making - Delegating more authority to divisions, project teams or local
managers where faster responses are needed.
● Communication & Coordination between teams - Improving cross-functional communication so
departments do not work in silos. Creating project teams, steering groups or cross-functional
committees to support strategic priorities.
● Accountability - Assigning clear responsibility for strategic objectives, performance targets and
outcomes.

H1b – Collaborative Working and Partnering


Advise on the implications of collaborative working and partnering, including franchising, process
outsourcing, shared services and global business services. [3]
collaborative arrangements can help organisations access new markets, specialist skills, technology,
efficiency savings and shared risk without making permanent structural changes.
However, collaboration reduces direct control and creates governance risks. The organisation may remain
accountable for quality, compliance, reputation and overall performance, even where another party is
involved in delivery.
Key risks include dependency on partners, loss of control, confidentiality issues, intellectual property
concerns and strategic misalignment. Therefore, collaborative arrangements require strong governance,
including due diligence, clear contracts, defined roles and responsibilities, service level agreements,
performance monitoring, escalation routes and exit plans.
Franchising

● franchisor allows a franchisee to operate under its brand in return for fees or royalties.
● can support rapid geographic expansion without the franchisor needing to invest heavily in new branches
or operations (doesn’t have to own or manage every location)
Risk: franchisor does not directly control the franchisee’s day-to-day behaviour. If service standards fall, the
franchisor’s brand and reputation may still be damaged. Requires clear operating standards, training,
monitoring and contractual controls.
Licensing

● licensor gives another party the right to manufacture, distribute or sell a product, technology or intellectual
property in exchange for a fee or royalty.
● usually narrower than franchising because it focuses on a product, technology or intellectual property
rather than a whole business model.
● often lower cost for both parties and can help the licensor earn income from intellectual property while
helping the licensee access an established product or technology.
Risk: dependency. If the agreement is not renewed, the licensee may lose access even after investing in the
licensed product. The licensor may also face quality or brand risk if the licensee does not maintain acceptable
standards.
Process Outsourcing / BPO

● organisation transfers an entire business process to an external provider e.g. payroll, IT support, finance
processing or customer service.
● allows the organisation to focus on its core activities while the external provider delivers the process more
efficiently or with specialist expertise.
● can reduce costs, improve service quality and provide access to skills the organisation does not have
internally.
Risk: dependency on the provider and may lose internal capability over time. Can also be difficult to bring
the process back in-house if the contract fails. Requires strong service level agreements, performance
monitoring and exit arrangements.
Shared Services

● consolidating support functions, such as HR, finance or IT, into one internal service unit that supports the
whole organisation.
● can create economies of scale, reduce duplication, standardise processes and improve efficiency. Often
used by larger organisations with multiple divisions or locations.
Risk: centralised service may become too standardised and may not meet the specific needs of every
division or business unit. Good governance is needed to balance efficiency with responsiveness to local or
divisional needs.
Global Business Services / GBS

● Advanced form of shared services operating across international boundaries.


● may combine internal shared services with outsourcing and usually involves standardised global
processes.
● can provide significant cost savings, access to global talent and more consistent processes across
countries. Can help multinational organisations operate more efficiently.
Risk: complexity. The organisation must manage differences in culture, regulation, time zones, language,
service expectations and accountability. Clear governance, reporting and performance measures are needed
to maintain control.
Strategic Alliances

● legally binding agreement between independent organisations to cooperate without creating a new legal
entity.
● allows organisations to share resources, knowledge, risk, research and development costs, or access to
markets while remaining separate businesses.
● useful where organisations want flexibility and do not want to commit to a merger or permanent structural
change.
Risk: partners may not contribute equally, fail to meet commitments, or have conflicting objectives. Alliance
may also break down if one partner lacks the required competence or if trust is damaged.
Joint Ventures

● Two or more organisations create a separate legal entity in which each partner has a share.
● Allows partners to combine resources, skills, capital, technology or market access while sharing both risk
and reward.
● Usually more formal than strategic alliances because a new organisation is created.
o project-based joint venture: created for a specific project and usually ends when the project is
complete (clear purpose and exit point).
o functional joint venture: partners combine different capabilities for mutual benefit. E.g. food
producer with food distributer.
Risk: partners may have different cultures, priorities or levels of commitment.
In an exam, discuss the benefit, risk and control needed for each collaborative option.

H2 – Enabling Success: Disruptive Technology


H2a – Disruptive Technologies including Fintech
Identify and assess the potential impact of disruptive technologies such as Fintech, including
cryptocurrencies. [3]
Disruptive technologies such as fintech, blockchain and cryptocurrencies can transform industries by
reducing costs, removing intermediaries, improving transparency and creating new business models.
However, they also create major risks, including loss of control for traditional firms, increased competition,
regulatory uncertainty, cybersecurity concerns, financial volatility, fraud, money laundering and reputational
damage.
Therefore, organisations should identify disruptive technologies early, assess their strategic impact, monitor
regulation, manage risks carefully and decide whether to adopt, partner with, invest in or defend against the
technology.
Fintech - application of technology to financial services. Any technology that makes banking, payments,
lending, investing, insurance, or money management faster, more digital, or more automated is usually
fintech. This has disrupted traditional banking, insurance and investment models.
E.g. Business Finance Tools (Xero, QuickBooks), Money transfer (Wise, Remitly), Lending Platforms/Buy
now Pay later (Clearpay, Klarna), Budgeting/Personal Finance apps, Cryptocurrency/blockchain platforms,
Digital banking (Monzo, Wise), Payments (PayPal, GooglePay)
Blockchain - decentralised digital ledger that records transactions across a network of computers. No single
person or organisation owns the whole system, and data is stored across multiple nodes. This makes
tampering very difficult and creates a transparent audit trail.
The key features of blockchain are:

● Single source: all participants use one shared ledger to verify transactions or asset ownership.
● Consensus: participants must agree that a transaction is valid before it is recorded.
● Origin: users can trace where an asset came from and how ownership has changed over time.
● Integrity: recorded transactions cannot be altered. If an error occurs, a new correcting entry must
be made, leaving both entries visible.
Blockchain can improve efficiency by reducing duplication and lowering the need for intermediaries. It may
be useful where a scenario involves hacked systems, data manipulation, weak audit trails or lack of
transparency. It also has legitimate business uses, such as smart contracts, transparent supply chains and
secure audit trails.
Cryptocurrencies - digital currencies that use blockchain technology and operate without central bank
control.
They can be used as a medium of exchange, allowing faster and potentially cheaper transactions because
fewer intermediaries are involved. However, they are not widely accepted by retailers and are highly volatile,
making them unreliable as a store of value.
They are also used as an investment asset. Publicity around Bitcoin and other cryptocurrencies has
attracted investors, but the risks are significant because of volatility, limited regulation, anonymity and
potential use in financial crime.
The main impacts of cryptocurrencies include:

● alternative to traditional currency and payment systems, reducing dependence on banks.


● create financial risk because their value can rise or fall sharply.
● create regulatory uncertainty because governments may regulate, restrict or ban their use.
● create compliance and reputational risks because they may be linked to fraud, tax evasion or
money laundering.
Initial Coin Offering (ICO) - fundraising method used by cryptocurrency and blockchain startups. Similar to
an Initial Public Offering (IPO) in traditional finance, companies sell new digital tokens in exchange for
established cryptocurrencies or fiat money to fund their project development.
Unlike buying stocks in an IPO, participating in an ICO does not grant you an equity stake in the company.
Instead, investors purchase tokens for their utility (the right to use the project's future product/service) or as
a speculative asset hoping the token gains value.

H2b – New Products, Processes and Innovation


Assess the impact of new products, processes, service developments and innovation in supporting
organisation strategy. [2]
Innovation supports strategy by helping organisations differentiate themselves, reduce costs, enter new
markets, improve customer satisfaction and respond to changing customer needs. It should be embedded
into the organisation’s culture and properly resourced, rather than treated as an occasional project.
Types of Innovation

⮚ Product innovation - creating new or significantly improved products. Can support strategy by driving
revenue growth, building competitive advantage and extending the product life cycle.
⮚ Process innovation - improving the way products or services are delivered. Can reduce costs,
improve quality, increase efficiency and support a cost leadership strategy. E.g. automation may allow
an organisation to produce goods faster and with fewer errors.
⮚ Service development - creating new or improved services for customers. Can improve customer
experience, increase loyalty and help the organisation differentiate itself from competitors. E.g.
offering faster delivery, online support or personalised services may strengthen the organisation’s
market position.
⮚ Business model innovation - changing how the organisation creates and captures value. Can
redefine industries and create major competitive advantage. E.g. Netflix disrupted the traditional DVD
rental market by moving towards streaming and subscription-based services.
⮚ Incremental innovation - making small, continuous improvements to existing products, processes
or services. usually, lower risk and easier to manage. helps organisations sustain competitiveness
and keep improving performance over time.
⮚ Radical innovation - breakthrough changes that create new markets or significantly disrupt existing
ones. Can produce high rewards but is also high risk, as it usually requires significant investment,
uncertainty and tolerance of failure.
Overall, innovation can strongly support organisational strategy, but it must be aligned with strategic
objectives. Poorly managed innovation may waste resources, distract management or expose the
organisation to unnecessary risk. Therefore, the board should ensure innovation is linked to strategy, properly
funded and supported by a culture that encourages improvement and creativity.

H3 – Enabling Success: Talent Management


H3a – Talent Management and Organisational Strategy
Discuss how talent management can contribute to supporting organisational strategy. [3]
Talent management — the strategic approach to attracting, developing, retaining and deploying people with
the skills and potential the organisation needs to achieve its strategic objectives. People are a source of
sustainable competitive advantage as skills, knowledge and culture are difficult for competitors to replicate.
Components of Talent Management

⮚ Attraction: employer branding, competitive remuneration and a clear career proposition to attract the
right talent.
⮚ Selection: using rigorous recruitment processes that are aligned to the skills, behaviours and values
required by the strategy.
⮚ Development: training, mentoring, coaching and stretch assignments to build employee capability.
⮚ Retention: keeping high performers through engagement, recognition, career development and a
positive organisational culture.
⮚ Succession planning: identifying and developing future leaders to ensure continuity, especially
important for senior management and board-level roles.
⮚ Performance management: setting clear objectives, giving regular feedback and linking
accountability to strategic goals.
Talent management fails when it operates in isolation from strategy. If the strategy requires digital capabilities
but talent management continues to recruit for traditional skills, the strategy cannot be delivered. HR and the
board must align talent decisions explicitly with strategic direction.

H3b – The POPIT Model


Analyse opportunities for organisational improvement using the four view POPIT (people, organisation,
processes and information technology) model. [3]
POPIT is a useful model for assessing organisational improvement because it recognises that sustainable
change requires four elements to be aligned: People, Organisation, Processes and Information Technology.

● People covers skills, competencies, culture, motivation, leadership and readiness for change. Key
questions include whether employees have the skills required by the strategy, whether the culture
supports the change, and whether people are motivated to deliver it.

● Organisation covers structure, roles, governance, accountability and reporting lines. This involves
asking whether the organisational structure supports the strategy and whether responsibilities are
clear.

● Processes cover workflows, controls and how work actually gets done. The organisation should
assess whether processes are efficient, whether they support the strategy, and where bottlenecks or
duplication exist.

● Information Technology covers systems, data, technology infrastructure and digital capability. The
key issue is whether technology supports the required processes and whether data is reliable,
accessible and useful for decision-making.
Changing one area without considering the others can create problems elsewhere. E.g. Introducing new
technology without redesigning processes may simply automate existing inefficiencies. Similarly, improving
a process without training staff may fail because people do not have the skills or confidence to operate it
effectively.
When advising on organisational improvement, POPIT helps ensure recommendations are balanced across
all four dimensions. A successful change should consider not only what needs to change, but also whether
the people, structure, processes and technology are aligned to support it.

H4 – Enabling Success: Performance Excellence


H4a – The Baldrige Model
Apply the Baldrige model for world class organisations to achieve and maintain business performance
excellence. [3]
The Baldrige Excellence Framework provides criteria against which organisations can assess themselves
and identify improvement priorities. For a organization, assess;

Criteria What it covers / exam application


Organisational The current situation, external environment, strategic position and key
Profile challenges. E.g. organisation’s context, using SWOT or PESTEL.
How senior leadership guides the organization (set values, ensure governance
Leadership and address societal responsibilities). E.g. is leadership is providing clear
direction and effective control?
How strategic objectives are developed, communicated and deployed. E.g. are
Strategy
objectives clear, realistic and aligned with the organisation’s environment.?
How relationships with customers are built, their needs are met and their
Customers satisfaction managed. E.g. are customer expectations managed and their needs
responded to?
Measurement,
How data, information and knowledge is used in decision-making and
analysis &
performance. E.g. are the right measures and information being used to drive
knowledge
improvement?
management
How people are developed, engaged and managed to achieve high
Workforce performance. E.g. are the skills, motivation and culture there needed to deliver
excellence?
How key processes are designed, managed and improved. E.g. process
Operations
efficiency, quality, operational issues and opportunities for improvement.
Performance outcomes across key areas, including financial, customer,
Results workforce and operational results. E.g. is performance improving? Is strategy
being delivered?

Exam use: Baldrige can be used as a diagnostic framework - identify which element is weak, explain how it
is damaging performance excellence, and recommend improvements under the relevant headings.

H4b – Critical Success Factors (CSFs)


Assess and advise on how an organisation can be empowered to reach its strategic goals, improve its results
and be more competitive, focusing on its critical success factors (CSF). [3]
Critical Success Factors (CSFs) are the limited number of areas where satisfactory performance is
essential for strategic success. They are the things the organisation must get right to achieve its goals.
Organisation must identify its critical success factors and measure performance against them. KPIs (Key
Performance Indicators) are the measurable indicators used to track performance against each CSF;

Examples of CSF Examples of KPI


Customer satisfaction Net Promoter Score; customer retention rate; complaint levels
Operational efficiency Cost per unit; process cycle time; productivity levels
Financial performance Revenue growth; profit margin; return on capital employed

For each KPI, define its title, purpose, link to strategy/CSF, responsible owner, source data, calculation
method, target, reporting frequency, who investigates variances, and what action will be taken. This prevents
KPIs becoming “hit and run” measures that are set but not managed.
CSFs are only useful if they are genuinely critical and limited in number. If an organisation identifies too many
CSFs, management attention becomes diluted and the organisation loses focus on what truly matters.
Objectives underpin KPIs and should be SMART:

● Specific: clear and focused, rather than vague.


● Measurable: capable of being measured and monitored.
● Achievable / Agreed: realistic and accepted by the people responsible.
● Relevant: linked to strategy and within the individual’s influence.
● Time-limited: given a clear deadline.
SMART objectives help ensure that performance measures are clear, fair and linked to strategic goals.
Pitfalls in Performance Measurement Design
- Too few measures: important areas are ignored. What gets measured tends to get managed, so
unmeasured areas may receive little attention.
- Too many measures: dilute attention and effort. Staff may focus on easier or less important targets
rather than the measures that really drive strategic success.
- Wrong measures: encourage behaviour that conflicts with strategy. E.g. strict cost targets may
damage quality in a differentiation strategy.
- Targets that are too tight or too loose: reduce motivation. Unachievable targets may encourage
gaming or misreporting, while loose targets can create complacency. Benchmarking against
competitors can help set realistic but challenging targets.
- “Hit and run” measures: KPIs are set but not followed up. KPIs need a management framework,
including responsibility, reporting frequency, investigation of variances and corrective action.
Fitzgerald and Moon’s Building Blocks Model
Used to design a performance management system, especially for service businesses.
1. Dimensions — What to measure
o Determinants: Quality (reliability, service standards), Flexibility (ability to respond to
change/customer needs), Resource utilisation (efficient use of staff, time, assets) and Innovation (new
ideas, improved services/processes)
o Results: Financial performance (profit, revenue, costs) and Competitiveness (market share,
customer satisfaction, reputation)

2. Standards — Targets. Should be clear (easy to understand), Fair (achievable and realistic) and
Challenging (encourage improvement)

3. Rewards — incentives. Rewards should be: Motivating, Fair, linked to controllable performance and
aligned with business objectives
Simple memory line: Measure the right things, set fair targets, reward the right behaviour.
Exam Technique: To answer this type of question (1) identify the organisation’s strategic goals (2) determine
the few CSFs that are essential to achieving them (3) For each CSF, recommend appropriate KPIs and
SMART targets. (4) Assess whether the performance measurement system is balanced, fair and linked to
reward.
The key point is that performance measurement should empower the organisation by focusing management
attention on the areas that drive strategic success, competitiveness and improved results.

H5 – Managing Strategic Change


H5a – Evaluating Current Organisational Processes
Evaluate the effectiveness of current organisational processes. [3]
Before redesigning processes, the current state must be understood and evaluated. A process that was fit
for purpose under a previous strategy may be entirely inappropriate under a new one.

− Process mapping: documenting how work currently flows through the organisation
− Identifying bottlenecks, duplication, waste and failure points
− Benchmarking against best practice or competitor performance
− Assessing whether current processes support or undermine the strategy

H5b – Types of Strategic Change


Evaluate different types of strategic change and assess their implications. [2]

Type Description Implications


Lower risk and easier to manage, but may be
Incremental Small, continuous adjustments
too slow or insufficient if the external
change to existing ways of working.
environment changes rapidly.
High risk and disruptive; requires strong
Transformational A fundamental shift in strategy,
leadership, communication, resources and
change structure, culture or processes.
stakeholder management.
More predictable and controllable, but can be
A deliberately designed and
Planned change slow and may assume the environment is stable
managed change programme.
enough to plan ahead.
Unplanned change that
Flexible and responsive, but harder to control;
develops in response to
Emergent change requires organisational agility and empowered
environmental shifts or internal
staff.
learning.
Rapid, organisation-wide
Often used in turnaround situations,
change that does not
Reconstruction restructuring or cost-cutting; can deliver quick
fundamentally alter the
results but may damage morale.
organisation’s culture.
Rapid and fundamental change Usually required in crisis, merger or major
Revolution affecting both strategy and disruption; very high risk and needs decisive
culture. leadership and strong communication.

Strategic change can vary by scale, speed and how deliberately it is managed. The greater the scale and
speed of change, the greater the risk, disruption and need for leadership, communication and stakeholder
management. Incremental or planned change is easier to manage, but transformational, reconstruction or
revolutionary change may be necessary where the organisation faces crisis or major strategic misalignment.

H5c – Harmon's Process-Strategy Matrix


Establish an appropriate scope and focus for organisational process change using Harmon's process-
strategy matrix. [3]
Harmon’s Process-Strategy Matrix helps determine the appropriate scope and focus for organisational
process change by assessing processes against two dimensions:
1. Strategic importance: how important the process is to competitive advantage and strategic success.
2. Process complexity: how difficult, specialised or resource-intensive the process is to manage.

Streamline and improve Invest heavily


High strategic
importance keep the process in-house but make Redesign/re-engineer the process as its
it more efficient. core to competitive advantage and affects it
Automate or outsource Outsource to a specialist
Low strategic
importance standardise the process and reduce avoid heavy internal investment where the
cost. process is not strategically important.
Low complexity High complexity

Overall, Harmon’s matrix helps managers decide whether a process should be redesigned internally,
improved, automated or outsourced, depending on its strategic value and complexity.

H5d – Process Redesign Options


Assess and advise on possible redesign options for improving the current processes of an organisation. [3]
Process improvement: Incremental improvements to existing processes. Process is fundamentally sound
but has specific inefficiencies.
Process redesign: Significant restructuring of an existing process. Process is outdated but the overall
approach remains valid.
Business Process Reengineering (BPR): Radical, clean-sheet redesign; start from scratch. Process is
fundamentally broken; incremental improvement will not be sufficient
Automation: Using technology to replace manual process steps. High-volume, repetitive, rule-based
processes.
Outsourcing: Transferring the process to an external provider. Process is non-core and can be delivered
more efficiently externally

H5e – Process Redesign Methodology


Recommend a process redesign methodology for an organisation. [2]
1. Define scope: Identify which processes are in scope using Harmon's matrix
2. Map the current state: Document existing processes to understand how they actually work
3. Identify improvement opportunities: Bottlenecks, waste, duplication and failure points
4. Design the future state: Redesign the process to eliminate identified problems
5. Pilot and test: Test the redesigned process on a small scale before full rollout
6. Implement: Roll out the new process with appropriate training and communication
7. Monitor and review: Track performance against KPIs and refine as needed

H5f – Lewin's Three Stage Model


Manage change in the organisation using models such as Lewin's three stage model. [2]

− Unfreeze - Preparing the organisation for change by breaking down the existing mindset and creating
motivation to change; communicating why change is necessary, creating a sense of urgency and
addressing resistance before it takes hold.
− Change - Implementing the actual change. People learn new behaviours, processes and ways of
working; characterised by uncertainty and requires strong leadership, clear communication and
support for those affected.
− Refreeze - Embedding the change so it becomes the new normal; reinforcing new behaviours through
reward structures, updated processes and revised governance. Without refreezing, organisations
often revert to old ways of working.
Lewin's model is simple and intuitive but assumes change is a linear, planned process with a clear beginning
and end. In practice, change is often messy and continuous, particularly in rapidly changing environments
where refreezing may be inappropriate because further change is immediately required.

H5g – Balogun and Hope Hailey's Contextual Features


Assess implications of change in an organisation using Balogun and Hope Hailey's contextual features. [3]
This framework identifies eight contextual features that determine how change should be managed.

● Time: how urgently change is needed. If the organisation is in crisis, rapid change may be required.
If the environment is stable, a slower and more planned approach may be more appropriate.
● Scope: how much of the organisation is affected. A narrow change may only require limited
communication and training, while a wide organisational change will need more extensive stakeholder
management.
● Preservation: what existing strengths must be retained. Change should not simply remove everything
from the current organisation; it should protect what already works well.
● Diversity: different values, cultures and attitudes that are across the organisation. Greater diversity
may require different approaches for different teams, divisions or locations.
● Capability: does the organisation have the skills and experience to manage change. If change
capability is low, the organisation may need external support, training or a slower implementation
pace.
● Capacity: does the organisation have enough resources, time and management attention to carry
out the change. Limited capacity may restrict the pace or scale of change.
● Readiness: how willing staff are to accept the change. If readiness is low, more communication,
involvement and “unfreezing” may be needed before implementation.
● Power: where power sits in the organisation. In a hierarchical organisation, change may need to be
driven from the top. In a flatter organisation, a more collaborative approach may be more effective.
Mnemonic to remember: Tall Students Prefer Different Crisps, Chips, Rolls & Pizza
H6 – Leading and Managing Projects
H6a – Distinguishing Features of Projects
Determine the distinguishing features of projects and the constraints they operate in. [2]
A project is a temporary, unique endeavour undertaken to achieve a specific objective within defined
constraints. It differs from ongoing operations because projects have a defined start and end point, produce
a unique output, and involve greater uncertainty.

Area Project Operations


Duration Temporary - defined start and end Ongoing - continuous and repetitive
Standardised - produces the same output
Output Unique - produces something new
repeatedly
Team Temporary - assembled for the project Permanent - stable workforce
Lower - processes are established and
Risk Higher - uncertainty is inherent
known
Managemen
Project manager - specific methodology Line management - operational processes
t

Projects also operate within key constraints which are linked:

● Time — the project must be completed within an agreed deadline.


● Cost — the project must be delivered within the approved budget.
● Scope — the project must deliver the agreed objectives, outputs and requirements.
● Quality — the project output must meet the required standard and be fit for purpose.

H6b – The Triple Constraints


Discuss the implications of the triple constraints of scope, time and cost. [2]
Every project operates within three interdependent constraints. Changing one affects the others:

● Scope - What the project will deliver; the features, functions and outcomes
● Time - The schedule; when deliverables will be completed and when the project will end
● Cost - The budget; the financial resources available to deliver the project

The triple constraint trade-off: if scope increases, either time must extend or cost must increase. If time is
compressed, either cost must increase or scope must reduce. A project manager asked to deliver more,
faster and cheaper simultaneously is being set up to fail, at least one constraint must give.

H6c – Business Case and Project Initiation Document


Prepare a business case document and project initiation document. [2]
Business Case - justifies the investment in a proposed project and seeks approval before the project begins.
It answers the question: Should we do this project? It covers;

Internal and external analysis, with clear identification of the problem or


Current situation
opportunity requiring a project solution.
Options
The alternative solutions considered, plus justification for the selected option in
considered and
terms of fit, feasibility and acceptability.
chosen
Whether the project can realistically be delivered, including availability of physical
Feasibility
resources, human resources, skills, and whether the timeline is achievable.
The impact on key stakeholders, such as the workforce and customers, as well as
financial acceptability to shareholders. This requires high-level investment
Acceptability
appraisal of costs and benefits. Benefits often materialise after completion, so
accurate projections are important.
The main constraints of time, cost and scope, and which one is the priority. E.g. A
Project constraints time-critical project may require extra resources and higher cost, while a cost-
critical project may require reduced scope.
The key risks that could prevent the project from achieving its objectives. At
High-level risk business case stage, this is high-level only, assessing probability and potential
assessment impact on time, cost and scope. Detailed risk analysis follows in the planning
phase after approval.

Project Initiation Document (PID) - sets out how the project will be managed once it has been approved
(How will we do it?).

What the project is intended to achieve and what is included or excluded from
Objectives and scope
the project.
The specific outputs the project must produce for its objectives to be
Deliverables
achieved.
Milestones and Key dates, review points and formal sign-off stages where the project cannot
gateways proceed without approval from the sponsor or project board.
Budget The approved financial resources available for the project.
Risk register The identified project risks and how they will be monitored or managed.
Governance How the project will be controlled, reported and escalated, including the role
arrangements of the sponsor or project board.
Roles and Who is responsible for managing, approving and delivering different parts of
responsibilities the project.
Whether project team members are working full-time on the project or
Time allocation
alongside their normal duties.

H6d – Costs and Benefits of Project Investment


Analyse, assess and classify the costs and benefits of a project investment. [3]

⮚ Tangible benefits - Revenue increase; cost savings; efficiency gains — measurable in financial terms
⮚ Intangible benefits - Improved customer satisfaction; enhanced reputation; staff morale — harder to
quantify
⮚ Capital costs - One-off investment costs e.g. equipment, system development, construction
⮚ Revenue costs - Ongoing operational costs e.g. staffing, maintenance, licences
⮚ Opportunity costs - Value of the next best alternative foregone by committing resources to this project
⮚ Sunk costs - Costs already incurred that cannot be recovered — should not influence future decisions
Investment Appraisal Techniques
Payback period — how long until the project recoups its initial investment. Simple but ignores time value of
money. E.g. If initial investment is £100,000

Year Cash Flow Balance Workings

1 20,000 1. create a running total to see which year investment is recuperated.

2 25,000 45,000 2. Recovery happens in Yr 4.


3. Amount still needed after Year 3: 100,000 − 75,000 = 25,000
3 30,000 75,000
4. Cash flow in Year 4 = 40,000
5. Payback Period Formula
𝐴𝑚𝑜𝑢𝑛𝑡 𝑠𝑡𝑖𝑙𝑙 𝑛𝑒𝑒𝑑𝑒𝑑
𝑃𝑎𝑦𝑏𝑎𝑐𝑘 𝑃𝑒𝑟𝑖𝑜𝑑 = 𝐹𝑢𝑙𝑙 𝑦𝑒𝑎𝑟𝑠 𝑏𝑒𝑓𝑜𝑟𝑒 𝑟𝑒𝑐𝑜𝑣𝑒𝑟𝑦 +
𝐶𝑎𝑠ℎ 𝑓𝑙𝑜𝑤 𝑖𝑛 𝑟𝑒𝑐𝑜𝑣𝑒𝑟𝑦 𝑦𝑒𝑎𝑟
4 40,000 115,000 25,000
=3+ = 3.625 𝑦𝑒𝑎𝑟𝑠
40,000

6. Convert decimal into months: 0.625 × 12 = 7.5


Final Answer: 3 𝑦𝑒𝑎𝑟𝑠 𝑎𝑛𝑑 8 𝑚𝑜𝑛𝑡ℎ𝑠 (𝑎𝑝𝑝𝑟𝑜𝑥)

Net Present Value (NPV) — present value of all future cash flows minus initial investment. Preferred method
as it adjusts future money for the time value of money. E.g. If initial investment is £10,000 and Discount rate
is 10%
Yea Cash Discoun Presen
Workings
r Flow t Factor t value

1 4,000 0.909 3,636 1. Discount each cash flow and get the total PV
2 3,000 0.826 2,478 2. Minus initial investment = NPV = 9,869 - 10,000 = -131
3 5,000 0.751 3,755 3. If Positive NPV → ACCEPT, if Negative NPV → REJECT
4. This project would be rejected.
Total Prevent Value (PV) 9,869

Internal Rate of Return (IRR) — the discount rate at which NPV = 0. Used to compare projects. ACCA
usually gives you two NPVs and asks you to estimate.
Discount
NPV Workings
Rate
+£50
10% 𝑁𝑃𝑉(𝐿) 500
0 𝐼𝑅𝑅 = 𝐿 + × (𝐻 − 𝐿) = 10 + × 5 = 10 + 3.57 = 13.57%
𝑁𝑃𝑉(𝐿) − 𝑁𝑃𝑉(𝐻) 700
15% -£200

Remember:

● Payback → “How fast do I get my money back?” For Liquidity / risk

● NPV → “Does this project create value?” Best method

● IRR → “What return rate does this project earn?” Compare to cost of capital
Financial appraisal must be combined with qualitative assessment. A project with a strong NPV but significant
reputational or ethical risks may not be the right choice. The board should consider the full impact, not just
the financial return.

H6e – Project Manager and Project Sponsor


Establish the role and responsibilities of the project manager and the project sponsor. [2]

Area Project Manager Project Sponsor Project Board


Day-to-day manager of the Senior owner accountable Top-level authority and
Role
project for project success decision-making body
Strategic ownership,
Delivery, planning and Strategic approval,
resources and escalation.
operational control. governance and oversight.
Link between the project
Main focus Ensures the project is Ensures the project
and strategic leadership.
delivered effectively day to remains justified, aligned
gives it organisational
day and properly governed
backing
Plans, schedules and
Secures resources; Approves business case;
budgets; manages risks;
resolves escalated issues; checks alignment to
leads the team; reports
champions the project at corporate goals; signs off
Responsibilities progress
board level; approves major gateways; makes
Maintains project
major decisions within decisions outside
documentation and
agreed limits sponsor/PM authority
version control
Strategic authority across
Operational authority
Authority the organisation, within Highest project authority
within the project
limits set by the board
Accountable to the
Accountable to the Project Accountable to the Project
Accountability organisation/board/steerin
Sponsor Board
g structure

Hierarchy: Project Board → Project Sponsor → Project Manager → Project Team


Project team — responsible for completing assigned project tasks to the required standard, within the agreed
timeframe, and reporting progress/issues to the project manager.

H6f – Project Plan and Key Elements


Assess the importance of developing a project plan and its key elements. [3]
Developing a project plan is important because it sets out objectives of the project, timeline, resources
required and the responsible people for overseeing and completing the project; helps ensure project is
realistic, organised and aligned with the organisation’s objectives.
It supports control and monitoring; progress can be compared against planned deadlines, costs and
deliverables. Without a project plan, delays, overspending, duplicated work and unclear responsibilities are
more likely.
It also helps identify risks, dependencies and resource constraints early, so they can be managed before
they affect delivery; especially important where a project is complex, involves multiple stakeholders, or has
strict deadlines.
Key elements of the project plan

⮚ Work breakdown structure (WBS) - Decomposing the project into manageable tasks and work
packages

⮚ Requirements - should be identified early because they influence scope, resources, quality criteria
and stakeholder satisfaction. Some requirements may be aspirational rather than direct deliverables,
so the project manager must distinguish between what the project must deliver and what stakeholders
hope it will achieve.

⮚ Schedule - Project schedules are communicated using Gantt charts, horizontal bar charts that identify
each task in sequential order so the overall completion date can be determined. Tasks are classified
as:
o Consecutive (must be completed before the next can begin) or
o Concurrent (can run simultaneously with other tasks).
o Identifying which tasks are consecutive and which are concurrent allows the project manager
to determine the critical path and the minimum project duration. Any delay on the critical path
delays the entire project; delays on non-critical tasks have float and do not necessarily delay
completion.

⮚ Resource plan - Who is responsible for each task and what resources are required
⮚ Budget - Cost estimates for each element of the plan

⮚ Risk register - Identified risks, probability, impact and mitigation actions

⮚ Quality Criteria - what quality standards the outputs must meet and the methods and processes that
will ensure those standards are achieved.

⮚ Procurement Plan - what goods, materials and services need to be purchased externally, together
with the strategy for procurement. In larger organisations or public sector projects, formal procurement
procedures may apply (e.g. competitive tendering requirements) to ensure public funds are not
misappropriated.

⮚ Communications Plan - what each stakeholder group needs to receive, when and in what format.
There are three audiences:
o Project sponsor — needs to know about issues, concerns and how they are being resolved;
schedule and budget status
o Project team — needs technical and quality information specific to their roles;
o External stakeholders — need to know how their explicit concerns and demands are being
addressed by the project manager.
A project plan is only as good as the assumptions underpinning it. Plans should be treated as living
documents, updated regularly as the project progresses. A plan created at the start and never revisited
provides false assurance rather than genuine control.

H6g – Monitoring, Controlling Risk and Slippage


Monitor and control project risks and slippages, recommending improvements. [2]
Slippage: when a project falls behind schedule, exceeds budget or fails to deliver agreed scope. Early
identification is critical, the longer slippage goes unaddressed, the harder it is to recover.
Monitoring and Control Mechanisms

● Regular progress reporting against plan (milestones, budget, scope)


● Earned value analysis: comparing planned progress with actual progress and actual cost
● Risk register review: regularly reassessing probability and impact of identified risks
● Change control: formal process for assessing and approving any changes to scope, time or cost;
prevents scope creep

Options When Slippage is Identified


Serious slippage should be escalated to the sponsor or project board where it affects time, cost, scope or
benefits. The project manager should identify the cause of slippage before choosing a recovery action.

⮚ Crashing: Adding more resources to accelerate delivery; increases cost


⮚ Fast tracking: Running tasks in parallel that were originally planned sequentially; increases risk
⮚ Reducing scope: Delivering less than originally planned; requires sponsor approval
⮚ Extending timeline: Accepting a later completion date; requires stakeholder agreement

H6h – Post-Implementation and Post-Project Review


Discuss the benefits of a post-implementation and a post-project review. [2]
Post-implementation review (PIR) - Carried out shortly after the project output has gone live. Assesses
whether the solution is working as intended and identifies any immediate issues requiring correction.
Post-project review (PPR) - Carried out after the project is fully closed. Assesses the project process itself;
what went well, what went wrong, and what should be done differently next time
Benefits of Both Reviews

● Confirms whether the benefits set out in the business case have been realised. Some benefits may only
be measurable months after implementation, so benefits tracking may need to continue beyond project
closure.
● Identifies lessons learned that can improve future project management
● Holds the project team and sponsor accountable for delivery
● Provides evidence for future investment decisions — did similar projects deliver as promised?
● Supports organisational learning and continuous improvement

Without post-project reviews, organisations repeat the same mistakes across successive projects and never
develop genuine project management capability.

You might also like