Skip to main content
Parousia Group

Governance and compliance

How the group is directed and controlled

A holding operating critical infrastructure for states and regulated institutions is judged first on its controls.

Governance principles

The principles the group applies in every jurisdiction it operates in.

  • Separation of direction and execution

    The board directs and supervises; the executive committee executes. The two roles are held by different people, and the distinction is written into the group statutes.

  • Data stays where the law places it

    Customer and citizen data is hosted in the jurisdiction that governs it. Where a client is a public institution, that institution holds the encryption keys.

  • Every privileged action is recorded

    Administrative actions on group systems are written to an append-only audit journal. A record that can be edited is not a record.

  • Procurement is contestable

    Awards above a defined threshold require competitive tender and a documented decision. The threshold and the process are the same in every country.

  • Concerns reach the board without filters

    A reporting channel exists that does not pass through line management, and using it carries no consequence for the person who does.

Board committees

Standing committees, each with a written mandate.

  • Audit committee

    Reviews financial reporting, internal control and the relationship with external auditors.

  • Risk and security committee

    Oversees operational, cyber and infrastructure risk across the group and its regional holdings.

  • Remuneration and nominations committee

    Proposes appointments to the board and the executive committee, and sets their remuneration.

  • Ethics and compliance committee

    Oversees the code of conduct, anti-corruption controls and the reporting channel.

Policies and standards

The documents below carry legal effect. Each is issued by group counsel and published per jurisdiction; a document is listed here only once its final text has been approved.

  • Code of conductIn legal review
  • Anti-corruption and anti-bribery policyIn legal review
  • Data protection policyIn legal review
  • Information security policyIn legal review
  • Supplier code of conductIn legal review
  • Reporting and whistleblowing procedureIn legal review

Standards the group works to

The group engineers to the standards below. Where a certification has been awarded, the certificate number and issuing body are published; where certification is in progress, that is stated rather than implied.

  • ISO/IEC 27001 — information security managementApplied in engineering
  • ISO/IEC 27701 — privacy information managementApplied in engineering
  • ISO 22301 — business continuityApplied in engineering
  • ISO 9001 — quality managementApplied in engineering
  • WCAG 2.2 level AA — digital accessibilityApplied in engineering
  • GDPR and equivalent regional data protection lawApplied in engineering

Leadership

Who directs the group

Parousia Group is directed by a board and run by an executive committee accountable to it.

Learn more