All Stewardship articles – Page 11
-
Technical guide
Implementing the TCFD recommendations for oil and gas methane disclosure: summary
The mission of the TCFD is to “help companies understand what financial markets want from disclosure in order to measure and respond to climate change risks and encourage firms to align their disclosure with investor needs.”
-
Technical guideImplementing TCFD recommendations for oil and gas methane disclosure
The Task Force on Climate-Related Financial Disclosure (TCFD or the Task Force) published its final recommendations in 2017, and now both companies and investors are moving towards implementation of TCFD’s recommendations.
-
DDQResponsible investment DDQ for infrastructure investors
In order to encourage a globally consistent approach to infrastructure investor due diligence and ESG disclosure by infrastructure managers, the PRI launched the Infrastructure Investor Responsible Investment Due Diligence Questionnaire.
-
Engagement guide
Corporate disclosure on cyber security governance: senior management and board accountability
4. Does the company identify a named person at senior management or executive committee level with overall responsibility for information management and cyber security? 5. Is the board or board committee responsible for cyber security issues?
-
Engagement guideAnalysis of corporate disclosure on cyber security governance: research analysis
This report presents a snapshot and analysis of what 100 companies are currently disclosing about their cyber governance and risk management. It also enables comparisons across regions and sectors to facilitate engagement dialogue.
-
Engagement guideCorporate disclosure on cyber security governance: regional analysis
On average, US and Australian companies performed the strongest on disclosure across all indicators. US companies scored better than those from other regions in terms of disclosing cyber security and/or information security as a key risk in company assessment plans (indicator 14). US companies also scored better on board responsibility ...
-
Engagement guide
Corporate disclosure on cyber security governance: assessment
12. Does the company conduct audits of information/cyber security policies and systems?
-
Engagement guide
Corporate disclosure on cyber security governance: board communication
6. Does the company communicate cyber risks to the board (and how, by whom and how often?) 7. Does the board receive detailed information about the company’s cyber/information security strategy (including what information it receives and how it assesses this information)?
-
Engagement guide
Corporate disclosure on cyber security governance: legal compliance
1. Does the company publicly commit to complying with relevant laws, including those related to cyber and data protection?
-
Engagement guide
Corporate disclosure on cyber security governance: conclusion and next steps
This report analysed data from 100 companies for observations on standards of corporate disclosure relating to cyber security practices. It presented overall findings across the data; results by each specific indicator; and different regional legislative and regulatory standards.
-
Engagement guide
Corporate disclosure on cyber security governance: key takeaways
While companies generally perceived cyber security as a key organisational risk, very few communicated that they have policies, governance structures and processes that were effective at tackling cyber threats.
-
Engagement guide
Corporate disclosure on cyber security governance: policy
2. Does the company publicly disclose a privacy and/or data protection policy? 3. Does the policy explicitly cover its entire operations, including third parties?
-
Engagement guide
Corporate disclosure on cyber security governance: skills and resources
8. Does the company disclose that it has a cyber or information security team and/or dedicated budget? 9. Does the company state that it works with relevant industry initiatives on cyber security and/or has access to internal or external expertise on cyber security? 10. Does the company actively seek cyber ...
-
Engagement guide
Corporate disclosure on cyber security governance: training
11. Does the company provide training on information/cyber security requirements to all employees?
-
Engagement guide
Corporate disclosure on cyber security governance: processes and procedures
13. Has the company established an incident management plan (including disaster recovery and business continuity)? 14. Has the company disclosed information or cyber security as a key part of its risk assessment/business continuity plan?
-
Engagement guide
Corporate disclosure on cyber security governance: overview of regulatory landscape
Standards of legislation relating to data protection and cyber security that companies are expected to adhere to vary widely by region. This section provides an overview of key legislation in force across the regions from which the company sample was drawn.
-
Engagement guideStepping up governance on cyber security
This report presents the research findings on companies’ cyber security disclosures that informed PRI’s collaborative engagement on the topic.
-
Engagement guide
How did companies in the human rights and extractives engagement assess human rights risk?
High-level trends Human rights risk assessment - identifying In 2015, two companies reported on human rights risk identification; this increased to 25 in 2017, making it one of the most improved areas. Almost all target companies have incorporated human rights considerations into their risk management processes and evaluated their ...
-
Engagement guide
How did companies in the human rights and extractives engagement monitor business relationships?
High-level trends Business relationships - selection Over half of the companies now report on the criteria used to select business relationships e.g. suppliers and security providers. While all categories have made progress on this indicator, companies in emerging markets have shown most improvement with almost half of them now ...
-
Engagement guide
How did companies in the human rights and extractives engagement show a commitment to human rights?
High-level trends All 32 companies publicly commit to respecting human rights. However, the level of commitment varies: a third has reached a very sophisticated level of commitment (standalone human rights policy/active participation in multi-stakeholder initiatives, etc.); a third has a clear and well-defined commitment but may not be as ...
