Internal Controls
To further advocate the Company’s commitment in the pursuit of good governance and achieving compliance with applicable laws and Company policies and procedures, the Company ensures to strengthen the Enterprise Governance, Risk Management and Compliance (GRC) Culture and maintain a strong system of internal controls focused on accountability and oversight of operations. With the leadership of the Company’s CFRO, internal control is embedded in the operations of the company and in each Business Unit (BU) and Corporate Center Unit (CCU). To accomplish the established goals and objectives, the BUs and CCUs implement robust and efficient process controls to ensure:
- Compliance with policies, procedures, laws and regulations
- Economic and efficient use of resources
- Check and balance and proper segregation of duties
- Identification and remediation control weaknesses
- Reliability and integrity of information
- Proper safeguarding of company resources and protection of company assets through early detection and prevention of fraud.
The annual Statement of Internal Controls and Compliance System Attestation (“SICCSA”), is signed by the Chief Audit Executive, Chief Finance and Risk Officer, and President and Chief Executive Officer. It attests that the Corporation’s internal controls, risk management and compliance system, and governance practices are adequate, and was reported in AURROC and to the Board. This is in accordance with the Board’s function to annually review the internal control system and risk management framework of the Company.
| SICCSA for 2025 | |
| SICCSA for 2024 | |
| SICCSA for 2023 | |
| View and/or download the Internal Audit Charter here |
ACCOUNTABILITY AND AUDIT
1. Internal Audit
The Board ensures that its shareholders are provided with a balanced and comprehensible assessment of the Company’s performance, position and prospects on a quarterly basis. Interim and other reports that could adversely affect its business, including its submissions and disclosures to the SEC and PSE, are also made available in the Company website. The Board also appointed a Chief Audit Executive upon the recommendation of the AURROC to perform the Internal Audit function, pursuant to the RCGM.
The Chief Audit Executive
The Chief Audit Executive oversees the implementation of the Internal Audit Charter and the annual risk- based Internal Audit Plan, and submits these to Senior Management and the AURROC for review and approval. The CAE ensures effective coordination with other internal and external assurance providers and communicates any significant resource limitations that may affect audit plan delivery. The CAE is responsible for ensuring that internal audit activities adhere to Company policies, applicable internal auditing standards, and leading practices. The CAE provides independent and objective assessments to the AURROC, Management, and external stakeholders on the adequacy and effectiveness of the Company’s governance, risk management, and internal control processes
The Internal Audit Group (“IAG”) is committed to its purpose and mission of serving as a trusted advisor to the Board and Management. It strives to deliver independent, objective, and high-quality assurance and advisory services through agile audit methodologies and modern audit technologies. The IAG is likewise committed to conforming with the Global Internal Audit Standards, and maintaining processes that support the ongoing enhancement of quality, independence, and professionalism.
Further, the IAG operates under an Internal Audit Charter that is periodically reviewed and approved by the AURROC. It applies a risk-based and data-driven audit approach, strengthened by dynamic risk assessments to identify new and emerging risks. The IAG leverages technology-enabled audit techniques, data analytics, and automated testing to enhance coverage, insight, and audit efficiency.
Moreover, the IAG provides independent assurance, consulting, and investigative services over governance, risk management, internal controls, and compliance with applicable laws and regulations. Its audit coverage includes key areas such as Cybersecurity and IT governance, data protection, digital transformation initiatives, artificial intelligence (“AI”)- related risks, and Environmental, Social, and Governance (“ESG”)-related processes and controls.
To promote synergy and scale across the conglomerate, the IAG collaborates closely with the internal audit teams of various business units through benchmarking, best practice sharing, and the use of common GRC tools.
The IAG continues to invest in training, certifications, and professional development to ensure its auditors remain globally competitive and responsive to the organization’s evolving needs and risk landscape.
2. External Audit
The RCGM and AURROC Charter provide that the AURROC shall ensure the integrity and independence of Internal and External Auditors, perform oversight functions over the Company’s Internal and External Auditors to review and monitor their independence and objectivity, and review and monitor compliance with applicable laws and regulations. The AURROC shall likewise review and monitor the External Auditor’s effectiveness on an annual basis. In the event of the removal or change of the External Auditor, the AURROC shall provide justifications and ensure proper disclosure of the reasons for such removal or change.
The Board, after consultations with the AURROC, recommends to the Shareholders a competent External Auditor duly accredited by the SEC (under Group A category) who shall undertake an independent audit of the Corporation. SyCip, Gorres, Velayo & Co., the External Auditor appointed, has the ability to understand complex related party transactions, its counterparties, and valuations of such transactions, adequate quality control procedures, and agrees to be subjected to the SEC Oversight Assurance Review (SOAR) Inspection Program conducted by the SEC’s Office of the General Accountant (OGA).
The AURROC evaluates and approves all non-audit services conducted by the External Auditor. Below is a table of all audit and non-audit related fees in 2025:
| Name of Auditor | Audit and Audit Related Fees | Year 2025 |
|---|---|---|
| SyCip, Gorres, Velayo & Co. | Fees for services that are normally provided by the external auditor in connection with statutory and regulatory filings or engagements | Php 5,830,000.00 |
| All Other Fees | Php 121,300.00 | |
| TOTAL | Php 5,951,300.00 |
No other service was provided by external auditors to the Company for the calendar year 2025.