
A review of the process is provided to the
Audit Committee each year. The Internal
Auditteam also manages the confidential
independent whistleblowing reporting
channel, Speak Up (see page 110 of the Audit
Committee Report). The Chief Executive has
Board responsibility for our responsible
business approach, including climate-related
issues.
Information security
As with all organisations, the scale and
complexity of cyber attacks on the business
isincreasing, and we continue to identify,
monitor and mitigate the risk this presents (see
pages 77 and 78). Despite repeated attempted
attacks (including several serious attempts
in2021), the business has not had a material
breach in the last three years. In 2021, we
invested in the security tools and services
weneed to support the longer-term move to
hybrid and home working, as well as managing
the rising threat from malware (especially
ransomware), and increased the protection for
our online web presence and digital services.
Rentokil Initial holds the ISO 27001 Certificate
for Information Security Management, audited
by the British Standards Institution (BSI), for
the design, development and hosting of digital
pest control services for remote monitoring,
analysis and reporting for our global
customers.
We maintain our investment in IT security to
ensure the cyber resilience of systems and
services stays at an appropriate level, and
thatwe continually monitor and improve our
cyber resilience. We run penetration testing
exercises to test our detection and response
capability and an information security
awareness programme is helping reduce
security incidents. In 2021, this included
phishing simulation exercises over nine
separate campaigns to an audience of
approximately 13,500 colleagues per
simulation, as well as workshops and online
training packages. Improvements to our email
security capability were also extended to
enable our core user populations to identify
high-risk emails and improve technical
resilience to phishing attacks. Information
security training programmes run at least
annually for critical roles.
The IT security team briefs the Board directly
at least annually and whenever operations
security risk requires escalation, aswell as
reporting via the Group Risk Committee
quarterly. We also monitor external ratings
using the Assessment of Business Cyber Risk
framework provided by the US Chamber of
Commerce, and benchmark our cyber security
wherever possible. We want to ensure we are
doing the right things for our business and
customers to be able to operate securely and
safely. The Group has a cyber risk insurance
policy in place.
Data privacy
We have a global data protection compliance
programme based on the requirements of
theEU General Data Protection Regulation
(GDPR) and equivalent regulations globally.
We require all our businesses to sign and
abide by the terms of an inter-company data
Governance and policies
We ensure our responsible business
prioritiesare part of our overall governance
arrangements, the cornerstone of which is
theCode of Conduct (available in 16 local
languages and supported by training
programmes). The Code of Conduct sets
outafundamental commitment to comply
withall legal requirements that apply, and to
operate with high ethical standards. It outlines
responsibilities to colleagues, customers and
the business, and highlights our determination
to establish our values of service, relationships
and teamwork, and a culture of integrity,
everywhere within the business.
We have a rigorous policy framework for each
of our key sustainability priority areas. We
review policies periodically to ensure they
meet current best practice and legislative
needs and our technical and safety standards
and practices often exceed local regulatory
requirements. By establishing clear policies
and procedures in areas such as ethical
conduct, human rights, data security and
suppliers, and by reporting openly on our
progress, we can reduce risks to our business
and our customers.
Our Supplier Code is designed to ensure our
suppliers’ standards align with our Code of
Conduct. Available on our website in 18
languages, it outlines the standards and
controls we expect within their operations.
Since March 2019, we have required all
criticalsuppliers and major local suppliers
toacknowledge receipt of, and compliance
with,the Supplier Code. In 2021, it was
updated and re-issued to expand the remit of
the environmental section and include new
sections on quality of products or services,
zero tolerance on tax evasion and protecting
personal data. We inspect tangible aspects of
the Supplier Code, such as safety standards,
during periodic audits of critical and major
suppliers.
During the year we also launched a supplier
Speak Up service and encourage all supplier
employees or other stakeholders to report
genuine concerns over malpractice, illegal
acts or failures to comply with recognised
standards of ethical behaviour that they
observe at any point within our global supply
chain.
A full list of our key policies is available on our
website. We monitor our impact using the
performance metrics summarised overleaf and
shown in this Responsible Business section.
Management and compliance
Adherence to corporate policies and the Code
of Conduct is reinforced by an annual Letter of
Assurance, signed by senior management to
confirm that they personally, and those they
are responsible for, are aware of and
understand what is required of them, and have
complied with it. They must provide details of
any areas of non-compliance or uncertainty.
Monitored by the Company’s Group General
Counsel and Internal Audit team, adherence
issupported by mandatory training on the
U+learning platform.
transfer agreement that incorporates EU
standard model clauses. This demonstrates all
businesses take privacy seriously. Our Group
Data Protection Officer has established a
global privacy network and all countries have
assigned local privacy officers and/or privacy
champions to support the programme. We
provide them with support and guidance
through regular newsletters, meetings, training
and access to updated data protection
compliance resources. In addition, all local
privacy officers have been issued a
comprehensive Data Protection Handbook
touse in day-to-day compliance activities.
The main operational controls and compliance
framework are underpinned by tools, systems,
policies and processes. We implement privacy
and data-management considerations in
project and contract governance mechanisms.
A privacy notice is available in 19 languages
and over 50% of colleagues have completed
basic data protection training, made available
in 43 different languages. Since
implementation, wehave also provided
functional training for teams such as
marketing, HR, sales and IT, supplemented
bysupport and guidance from the network
ofc.60 local privacy officers and over 200
privacy champions.
The Group Data Protection Officer reports any
identified data protection risks, gaps and
requirements via the Group General Counsel
to the Group Risk Committee and the Audit
Committee as well as periodic update to the
Executive Leadership Team. We have created
measures to assess the compliance status
ofcountries and regions, based on data
protection programme activities and risk levels
associated with local regulatory requirements,
enforcement action and breaches.
Tax
Our tax strategy is aligned with our wider
business strategy, which we believe creates
aresponsible and sustainable tax strategy
thatwill enhance long-term shareholder value.
We will consider tax as part of every significant
business transaction. When considering tax
issues, we will always try to protect the
Group’s reputation and adhere to its Code
ofConduct. We aim to meet all our legal
obligations, filing all required tax returns
accurately and on time, and paying the correct
amount of tax when due. We aim to deal with
HMRC and other tax authorities in an open
and collaborative manner, aimed at reaching
agreement on tax issues in good time, and
minimising the risk of disputes arising. We will
not undertake transactions where the sole
purpose is to create a greater tax benefit than
that intended by the relevant legislation. We
aim to comply with both the spirit and letter of
the law on tax matters, and will not establish
companies in tax havens if there is no
substantive economic reason to do so.
We operate appropriate tax risk governance
processes, overseen by the Audit Committee
and the Board. Our tax strategy applies to all
Group business, sets out our approach to tax,
and can be found on our website. Our Board
reviews our tax strategy annually.
Governance, trust and transparency
Responsible Business
continued
70
Rentokil Initial plc
Annual Report 2021