
Governance and compliance
How the group is directed and controlled
Parousia Group operates critical infrastructure for public institutions, regulated businesses and network operators.
Governance principles
The principles below are applied in every jurisdiction in which the group operates, by the group and by each of its regional holdings.
- Separation of direction and executionThe board directs and supervises; the executive committee executes. The group statutes require different people in each role.
- Data stays where the law places itCustomer and citizen data stays in the jurisdiction that governs it. The Data Protection Office records each processing operation.
- Every privileged action is recordedAdministrative actions are written to an append-only journal the person who performed them cannot alter. Internal Audit has access.
- Procurement is contestableAwards above the Procurement Department’s threshold go to competitive tender. Single-source awards require written justification and a second signature.
- Concerns reach the board without filtersThe Legal Department runs a written channel that bypasses line management and reaches the board’s ethics committee. Retaliation is prohibited.
Board committees
Four standing committees, each with a written mandate and each reporting to the board.
- Audit committeeReviews financial reporting, internal control and the relationship with the external auditors, and receives the findings of Internal Audit.
- Risk and security committeeOversees operational, cyber and infrastructure risk across the group, on reports from Group Security and Group Operations.
- Remuneration and nominations committeeProposes appointments to the board and to the executive committee and sets their remuneration, with Human Resources.
- Ethics and compliance committeeOversees the code of conduct, anti-corruption controls and the reporting channel, on reports from the Compliance and Legal Departments.
Policies and standards
The documents below carry legal effect. They are issued by the Legal Department and published for each jurisdiction concerned, and the Compliance Department is responsible for keeping them current. The status shown against each document is its status at the date of this page.
- Code of conductIn legal review
- Anti-corruption and anti-bribery policyIn legal review
- Data protection policyIn legal review
- Information security policyIn legal review
- Supplier code of conductIn legal review
- Reporting and whistleblowing procedureIn legal review
Standards the group works to
The group engineers to the standards below and maps its controls to them. The Compliance Department maintains the register of applicable standards and the group’s status against each one; where a certificate is awarded, its number and its issuing body are published on this page.
- ISO/IEC 27001 — information security managementApplied in engineering
- ISO/IEC 27701 — privacy information managementApplied in engineering
- ISO 22301 — business continuityApplied in engineering
- ISO 9001 — quality managementApplied in engineering
- WCAG 2.2 level AA — digital accessibilityApplied in engineering
- GDPR and equivalent regional data protection lawApplied in engineering
Compliance
The group’s regulatory, security and ethical commitments, and the functions accountable for them in every market it operates in.
