Internal auditing

Internal auditing is responsible for the independent evaluation and assurance function required of a listed company, which systematically examines and verifies the efficiency of risk management, control, management and governance. The Audit Committee of Kojamo’s Board of Directors has confirmed the operating instructions for the internal
audit function.

Kojamo’s internal auditing was outsourced to the audit firm PricewaterhouseCoopers Oy. Kojamo has designated the CFO and Group Controller to be in charge of coordinating the practical activities. Internal auditing operates under the authority of the CEO and the Audit Committee and reports its observations and recommendations to the Audit Committee, the CEO, the Management Team and the auditor. The auditing function covers all companies and functions in the Kojamo Group.

The auditing operations are based on risk analyses and conversations with the Group management related to risk management and control. Regular meetings with the auditor are set up in order to guarantee sufficient
audit coverage and to avoid overlapping operations. Internal auditing annually draws up an auditing plan that is approved by the CEO
and the Audit Committee. The auditing plan is modified based on risks, if necessary.

The internal auditing operations in 2020 were focused on the centralised steering of repair operations, the investment process and ICT and unit inspections.

The main focus areas of internal auditing operations in 2021 will be related to ICT architecture, procurement, sales, data protection and unit inspections.

Internal control

Internal control seeks to ensure that Kojamo’s operations comply with current legislation and regulations and the Company’s operating principles, and that the Company’s financial and business reporting is reliable. Internal control also seeks to safeguard Kojamo’s assets and ensure that its operations are efficient and reliable, thereby enabling its strategic goals to be achieved.

Kojamo’s internal control system is based on the framework published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).

The organisation of internal control is the responsibility of the Board of Directors and the CEO. However, responsibility for carrying out internal control is shared by the entire organisation: each individual Group employee is responsible to his/her supervisor for internal control in his/her area of responsibility.

Read more about Kojamo plc’s internal control from the Corporate Governance Statement 2020.

Page updated 11 March 2021