Suits The C-Suite

SGV thought leadership on pressing issues faced by chief executives in today’s economic landscape. Articles are published every Monday in the Economy section of the BusinessWorld newspaper.
18 November 2024 Joseph Ian M. Canlas and Christiane Joymiel C. Say-Mendoza

Harnessing the human element in cybersecurity

IN BRIEF: Recognizing employees as the cornerstone of cybersecurity, organizations must shift from tech-centric defenses to fostering a vigilant, security-aware culture.Comprehensive education and behavioral change strategies are essential to mitigate human-related security risks and reinforce a collective approach to cybersecurity.A balanced strategy that combines technological tools with human oversight and continuous cultural development is key to maintaining a resilient cybersecurity posture. PULL QUOTE: "Empowering employees with knowledge and vigilance is as crucial as technology in building a resilient cybersecurity defense.” In today’s rapidly evolving digital landscape, cybersecurity threats are more sophisticated and pervasive than ever. While companies invest heavily in advanced technologies and security protocols, the most critical line of defense consists of their own employees. Despite having robust security measures in place, organizations frequently find themselves vulnerable due to human error, negligence, or a lack of awareness. This reality underscores the urgent need for a shift in focus—from solely relying on technology to cultivating a culture where every employee actively contributes to cybersecurity.The critical role of human behavior in information securityThe prevalence of cyber threats in our interconnected world is undeniable, and the assumption that technology alone can safeguard information security and privacy is a misconception. A security-conscious culture within an organization is essential to effectively complement and enhance the technical safeguards already in place. IT risk management, therefore, must be a holistic practice that not only includes technological solutions but also addresses the human factors that significantly influence the security landscape.The impact of human error on security breachesHuman error continues to be a significant contributor to security breaches, with recent statistics from the 2024 Verizon Data Breach Investigations Report indicating that 68% of breaches involve some form of non-malicious human element. According to IBM, the financial repercussions are staggering, with the global average cost of each data breach in 2024 reaching USD 4.88M — the highest total ever recorded. This figure reflects direct financial losses and encompasses the long-term reputational damage that organizations suffer following a breach. Case studies from various industries have shown that breaches often stem from a lack of awareness or negligence, underscoring the importance of addressing human error as a critical component of cybersecurity strategies.Understanding human behavior in cybersecurityDelving into the psychological and behavioral aspects of cybersecurity reveals that human actions are often the weakest link in security chains. Common risky behaviors such as password reuse, oversharing on social media, and susceptibility to phishing and social engineering attacks can significantly compromise an organization's security. To effectively mitigate these risks, it is imperative to understand the underlying motivations and cognitive biases that drive such behaviors and to develop targeted strategies that promote secure practices.To combat the risks associated with human behavior, organizations must implement comprehensive and continuous education programs that raise awareness about the dangers of insecure practices and actively engage employees in adopting and maintaining secure habits. These programs should be dynamic, incorporating real-life scenarios and practical exercises that resonate with employees and foster a sense of personal responsibility for cybersecurity.Building and sustaining a security-conscious cultureCreating a security-conscious culture within an organization begins with the development of engaging and effective training programs. These programs should be designed to capture the attention of employees, providing them with the knowledge and skills necessary to recognize and respond to cybersecurity threats. Leadership commitment is crucial in reinforcing the importance of these programs, ensuring that security awareness is not just a one-time event but an ongoing priority.A human-centered approach to designing security processes and IT risk management is essential. By considering the user experience and incorporating principles of secure-by-design and human-centered design, organizations can create systems and processes that naturally encourage secure behaviors. The promotion of security champions within teams can also further embed security awareness into the fabric of business operations.The responsibility for maintaining a secure environment extends beyond the cybersecurity function or the Chief Information Security Officer (CISO). It is a collective responsibility that requires the engagement and participation of every employee. By instilling a culture where security is viewed as a shared obligation, organizations can create a more resilient and vigilant workforce capable of defending against cyber threats.Technology and human oversight: a balanced approachWhile technology plays a vital role in supporting good security habits through tools such as two-factor authentication and password managers, human oversight remains indispensable. Employees must be trained to understand the limitations of these tools and to remain vigilant in their daily activities, ensuring that security practices are consistently applied.The balance between automating security processes and maintaining human oversight is particularly important in the context of Zero Trust models. These models, which integrate privacy, security, and cyber resilience, rely on a combination of technology and human insight to verify trustworthiness and manage access to sensitive resources.Evaluating the effectiveness of security awareness programs is critical to ensuring that they are meeting their objectives. Organizations should employ strategies for continuous improvement, staying abreast of emerging threats and adapting their programs to address the evolving cybersecurity landscape.Securing the futureFostering a culture of security and privacy awareness is a collective endeavor that requires the active participation of every individual within an organization. By integrating the human element into IT risk management strategies, organizations can build a resilient defense against cyber threats. Continuous education and cultural evolution are imperative in promoting this balanced approach in risk management, ensuring that organizations remain vigilant and prepared to face the rapidly evolving cybersecurity challenges of the digital age.  Joseph Ian M. Canlas is a Risk Consulting Partner and ASEAN Core Consulting Quality Leader, and Christiane Joymiel C. Say-Mendoza is a Risk Consulting Partner, both of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the authors and do not necessarily represent the views of SGV & Co.

Read More
11 November 2024 Joseph Ian M. Canlas and Christiane Joymiel C. Say-Mendoza

Managing third-party risk

IN BRIEF: Shifting from traditional Third-Party Risk Management (TPRM) to agile, real-time methodologies is crucial due to the intricate interdependencies and evolving cyber threats in IT operations.Proactive TPRM, powered by AI, enables organizations to predict and respond to third-party risks swiftly, ensuring continuous IT security.Embracing transparency and strategic collaboration with vendors fortifies TPRM, equipping organizations to handle emerging challenges and maintain robust IT systems.PULL QUOTE: " Proactive and AI-powered TPRM is vital for navigating the complexities of today's IT ecosystems and effectively managing third-party risks. In an era where technology is deeply integrated into business operations, managing third-party risk has become a critical concern for organizations worldwide. The traditional methods of Third-Party Risk Management (TPRM) are being challenged by the fast-paced and complex nature of modern IT environments, where external vendors play a pivotal role in day-to-day operations. As the reliance on third parties grows, so does the potential for risk, making it imperative for TPRM strategies to keep pace with the dynamic landscape of IT risks. This article seeks to explore the transformative approaches necessary for managing third-party risks effectively, ensuring that organizations can maintain robust IT operations amid the ever-present threat of external vulnerabilities.The evolving landscape of TPRM in IT operations The complexity and interconnectivity of modern IT operations demand a more agile and continuous approach to managing third-party risks. This necessity is underscored by the escalating frequency and sophistication of cyber threats, which can significantly impact IT operations. As businesses become more reliant on third-party vendors for essential services, the potential for risk exposure grows, highlighting the need for TPRM strategies that can adapt to new threats as they emerge. The evolving landscape of TPRM in IT operations requires a strategic shift from static, periodic assessments to a dynamic, real-time risk management model that is capable of identifying and mitigating risks promptly.From static to dynamic TPRM: adapting to real-time threats The transition from a traditionally reactive TPRM approach, characterized by annual assessments, to a more proactive and dynamic model marks a significant shift in risk management practices. This shift necessitates the continuous monitoring of third-party activities to swiftly identify and address potential risks.As an example, a global organization implemented continuous real-time monitoring tools to proactively assess third-party risks. By leveraging advanced analytics and real-time data, they were able to swiftly detect and mitigate potential vulnerabilities introduced by external vendors, enhancing their overall security posture. Continuous threat intelligence and monitoring solutions allowed the organization to detect and respond to third-party risks in real time, minimizing the window of exposure to potential threats.Integrating cyber threat intelligence (CTI) into this proactive TPRM framework offers a strategic advantage, transforming reactive security measures into a forward-thinking, intelligence-driven approach. By enabling real-time monitoring of potential vulnerabilities and emerging threats, CTI enhances the ability to share tactical intelligence with industry peers and conduct comprehensive risk assessments, thus strengthening the overall security posture of the extended enterprise. The importance of this approach was starkly highlighted by incidents such as the CrowdStrike incident, which exposed vulnerabilities in third-party risk management and had profound implications for critical IT infrastructure. Incidents such as these serve as wake-up calls, prompting organizations to reevaluate their TPRM practices. The evolution of TPRM practices post-incident, focusing on lessons learned and the implementation of strategies to prevent similar issues, is essential for safeguarding IT operations against the ubiquitous risk of third-party threats.Interdependencies between TPRM and IT operations The interdependencies between TPRM and IT operations are becoming increasingly apparent as third-party failures, such as cybersecurity breaches or service outages, directly impact IT operations. These incidents can have cascading effects across an organization, affecting everything from data security to business continuity. For example, an organization that experienced a service disruption due to issues with a third-party provider strengthened its incident response and disaster recovery plans by implementing redundancy measures and conducting regular recovery drills. This integration of TPRM and IT operations ensured that the organization could swiftly recover and maintain operational stability during future vendor-related disruptions.The integration of TPRM with IT disaster recovery and incident response planning is crucial for building resilience. Organizations must employ redundancy, backup systems, and other measures to mitigate the impact of third-party risks on IT operations. Understanding these interdependencies is vital for developing robust TPRM strategies that can withstand the ripple effects of third-party issues and maintain operational stability.Navigating unforeseen changes and unvetted updates from vendors The challenge of navigating unforeseen changes and unvetted updates from vendors is becoming increasingly relevant in today's IT landscape. Vendors' software or service updates are often released without comprehensive testing, and these can introduce significant vulnerabilities or compatibility issues. Organizations must develop adaptive response mechanisms to quickly adjust to these changes.For instance, one organization faced unexpected compatibility issues when a vendor released a critical software update without thorough testing. In response, they established an automated testing environment to assess vendor updates before deployment, allowing for seamless integration with existing systems and minimizing operational disruptions.This includes maintaining robust patch management processes, utilizing automated testing environments, and employing rapid deployment frameworks to ensure the continuity and security of IT operations. By adopting such strategies, organizations can better manage the risks associated with unpredictable vendor changes and maintain the integrity of their IT infrastructure.Future-proofing TPRM Future-proofing TPRM strategies with advanced technologies and collaboration is essential for staying ahead of potential third-party risks. Leveraging AI and machine learning can provide predictive insights into third-party risks based on patterns and trends, enabling organizations to anticipate IT disruptions before they occur. For example, a logistics company used AI-driven predictive analytics to identify potential disruptions from third-party providers, such as delays due to external factors. This allowed them to adjust operations proactively, minimizing risks and maintaining service continuity.Enhancing vendor collaboration and transparency ensures that all parties are aligned on updates, vulnerabilities, and risks. Additionally, the continuous integration of feedback from IT incidents, risk assessments and cyber threat intelligence into the TPRM framework drives ongoing improvements, ensuring that TPRM strategies remain effective and aligned with the evolving IT landscape, providing organizations with actionable intelligence, facilitating informed decision-making, and fostering a proactive security posture.Evolving together – the future of TPRM in IT-driven environments As IT operations continue to evolve at a rapid pace, the need for an evolving, dynamic approach to TPRM becomes increasingly apparent. Organizations must view TPRM as an integral component of their IT strategy and resilience planning, rather than as a mere compliance requirement. Managing third-party risk in an IT-centric world requires a forward-thinking approach that embraces advanced technologies, collaboration, and continuous improvement. By adopting dynamic TPRM strategies and viewing them as integral to IT strategy, organizations can confidently and effectively navigate the challenges of an IT-driven environment and secure their operations for the future.  Joseph Ian M. Canlas is a Risk Consulting Partner and ASEAN Core Consulting Quality Leader, and Christiane Joymiel C. Say-Mendoza is a Risk Consulting Partner, both of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the authors and do not necessarily represent the views of SGV & Co.

Read More
04 November 2024 Christiane Joymiel C. Say-Mendoza and Joseph Ian M. Canlas

Key components for strategic risk management

IN BRIEF: Board surveys reveal a pressing need for more effective risk management, with several boards recognizing room for improvement.The strategic empowerment of CROs is essential to navigate the complex risk landscape and capitalize on emerging opportunities.Implementing a connected risk approach and embracing technology are key steps to advancing risk management practices and driving organizational value.PULL QUOTE: " As organizations strive for resilience amid escalating risks, empowering CROs is essential. They must break down silos, foster collaborative interactions, adopt a connected risk approach, and harness technology to modernize risk management strategies." In an era where risk landscapes are rapidly evolving, the role of Chief Risk Officers (CROs) has never been more crucial. The 2023 EY Global Board Risk Survey revealed a stark reality: 60% of boards agree that emerging risks are insufficiently addressed in risk management. Looking ahead, the survey suggests that boards need to strengthen their governance structures, processes and knowledge to improve oversight of both risks and opportunities.The survey further echoes the urgency for robust risk management, identifying various risks poised to severely impact organizations in the upcoming year. From geopolitical events and supply chain disruptions to cyberattacks and changing customer demands, the array of threats is diverse and daunting. Notably, while certain risks such as changing customer demands have decreased in perceived importance since 2021, others like misaligned culture and increased remote working have surged in significance.Empowering the risk steward/Chief Risk Officer (CRO)Successful risk management lies in the empowerment of the CRO. In many non-regulated sectors, this role is not formally recognized within the C-suite, despite the intense demands on risk leaders. As the complexity of the risk environment evolves, the need for CROs to collaborate closely with executive management and the board becomes paramount.Boards now expect executive management to identify risks and uncover the opportunities they may present. For example, a competitor's new joint venture could be seen as a threat, but from a strategic standpoint, it might also represent an acquisition target or potential partnership. Additionally, boards are calling for a deeper understanding of interconnected risks and their second-order impacts, such as the multifaceted challenges posed by climate change.CROs must be fully integrated into the business strategy and kept abreast of emerging megatrends that could affect the organization. Their insights are invaluable for mitigating downside risks and seizing "upside" opportunities. To be effective, CROs need clear and open communication channels with other senior executives and should be involved in regular management reporting, including strategies, business plans, and investment proposals.Successful risk stewards are characterized by their ability to break down organizational silos and work across all lines of defense. They understand the cultural risk appetite and can motivate leaders to adopt a common risk definition. Their experience in prioritizing risk outcomes is crucial for organizational performance.Connected risk approachA connected risk approach leverages improved data access to risk taxonomy, implement dynamic risk assessment methods that adapt to the changing business environment and coordinate risk response and reporting across all Three Lines (e.g., management, risk and compliance teams and internal audit). This approach unifies data on a common platform, offering continuous refresh capabilities and creating value through analytics and dashboards for better risk management planning.To execute a connected risk approach, an integrated risk taxonomy is essential. It provides a single view of risk by connecting data from traditionally siloed functions across the Three Lines. This enables rapid identification and assessment of risks that matter. Building a dynamic risk assessment is a collaborative effort that must be comprehensive and flexible, incorporating new data and market changes for agility.The dynamic risk assessment process includes orienting the mandate to manage risk, identifying risks through data-driven inputs, prioritizing current risks, and responding in a manner that fits the organization's risk posture. It incorporates qualitative assessments, quantitative metrics, risk performance leveraging a common taxonomy, and external data to challenge internal risk assessments.Technology-enabled risk managementThe 2023 EY Global Board Risk Survey indicates that only 31% of boards say their oversight of risks related to digital transformations is very effective, while 19% say it is slightly or less effective. Traditional risk management, which relied on professional judgment and manual processes, must evolve to take advantage of automation and data analysis capabilities.Integrated Risk Management treats risk and compliance activities as an enterprise-wide responsibility, promoting transparency and better decision-making. Automation technology can process low-value manual tasks and free up management time to enable them to focus on emerging risks, while data collection and monitoring can be automated to occur in real time to flag issues earlier. Cloud and AI technologies can execute complex scenario analyses and reveal insights into risk interdependencies.An integrated risk platform is foundational for connected risk capabilities, storing and modeling relationships between various data sources. This unified technology solution provides better insights, enabling a common risk ecosystem, consolidating risk management activities, and managing customer expectations through informed risk-taking.Fostering resilient risk leadershipTo be risk resilient, the boards need to understand the full spectrum of current and emerging risks that could impact the organization.  CROs can swiftly generate value by aggregating risk registers to form a comprehensive risk landscape and conducting collaborative sessions to unify risk definitions across the organization. This establishes a centralized framework and common taxonomy, essential for integrating risk management with strategic and operational planning. By embedding risk considerations into decision-making and employing technology for automation, CROs enhance the organization's proactive risk posture, turning risk management into a strategic asset for resilience and success.As organizations strive for resilience amid escalating risks, empowering CROs is essential. They must break down silos, foster collaborative interactions, adopt a connected risk approach, and harness technology to modernize risk management strategies. The strategic empowerment of CROs is not just beneficial—it is imperative for safeguarding and driving value. Christiane Joymiel C. Say-Mendoza and Joseph Ian M. Canlas are Business Consulting Partners of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the authors and do not necessarily represent the views of SGV & Co.

Read More
28 October 2024 Victor C. De Dios

The far-reaching effects of VAT on digital services

IN BRIEF: As more countries legislate on the imposition of consumption tax on digital services, the Philippines joins the list with the recent enactment of Republic Act No. 12023, commonly known as the VAT on digital services law. The law defines digital service providers (DSPs) as the suppliers of digital services consumed in the Philippines, and sets certain VAT obligations upon them, both resident and non-resident.The far-reaching effects of the new law are to be felt more by non-resident DSPs who are assigned unprecedented VAT responsibilities.PULL QUOTE: “For the very first time, a Philippine law calls the attention of non-resident businesses, DSPs in particular, to comply with local VAT requirements such as registration, invoicing, and more importantly, VAT payment.” The digital economy significantly changed the landscape of doing business worldwide, and with this change comes the obvious need for governments to regulate, as well as the opportunity to conceptualize measures for raising revenue. As more countries legislate on the imposition of consumption tax on digital services, the Philippines joins the list with the recent enactment of Republic Act No. 12023, commonly known as the VAT on digital services law. This new law took effect last 18 October 2024. According to the Department of Finance, the initiative is set to generate an estimated Php16 billion VAT collection annually, and somehow level the playing field between traditional and digital businesses. It introduces amendments to the general VAT provisions of the Tax Code, putting emphasis on ‘digital service’ as among the services subject to VAT. It defines digital service as any service supplied over the internet or other electronic network with the use of information technology, describing the supply as essentially automated. Included in the definition of digital service are online search engines, online marketplace or e-market places, cloud services, online media and advertising, online platforms, and digital goods. Defining digital service providers The law defines digital service providers (DSPs) as the suppliers of digital services consumed in the Philippines, and sets certain VAT obligations upon them, both resident and non-resident.Resident DSPs, being local service providers, are presumed to have been operating within the purview of the old VAT provisions. Thus, for them, the new law would serve as a reaffirmation of the obligation to report and remit VAT. The far-reaching effects of the new law are to be felt more by non-resident DSPs who are assigned unprecedented VAT responsibilities. These responsibilities are anchored on the core of the law, which treats digital services by non-resident DSPs as performed or rendered in the Philippines, provided that they are consumed in the country, thus subjecting them to VAT.VAT implications The following are VAT implications of the new law as far as non-resident DSP transactions are concerned, highlighting what transacting parties should be on the lookout for:VAT registration. The law requires non-resident DSPs to register with the BIR for VAT purposes if their gross sales for the past three months exceed Php3 million or if there are reasonable grounds to believe that their gross sales for the next 12 months will exceed the same threshold. The actual requirements and process for VAT registration are not yet clearly set out. In any case, non-resident DSPs are advised to watch out for the ‘simplified automated registration system’ that the BIR is mandated to establish. Invoicing and accounting. The law requires non-resident DSPs to issue VAT invoices for digital services consumed in the Philippines. In any case, the law ensures that a non-resident DSP’s invoice is simplified in terms of contents as compared to mandatory contents of a regular local invoice. A non-resident DSP invoice only needs to reflect the date, transaction reference number, consumer identification, brief description of the transaction, amount, and breakdown of sale price by component if subject to VAT at 12%, VAT zero-rated, or VAT exempt, if necessary. Non-resident DSPs are advised to be on standby for announcements on when the government will operationalize the invoicing requirement. For accounting purposes, non-resident DSPs are not required to maintain subsidiary sales and purchase journals.VAT payment. The law mandates the manner of VAT remittance, which depends on whether the non-resident DSP transacts with a non-VAT consumer or VAT-registered consumer in the Philippines. For transactions with non-VAT registered consumers, the non-resident DSPs are the ones required to directly remit the VAT to the BIR. For transactions with VAT-registered consumers, the said consumers are the ones supposed to withhold VAT and remit the same to the BIR. This process is referred to as the ‘reverse charge mechanism,’ a similar mechanism to our existing withholding VAT. The BIR will likely soon release mechanics for VAT payment, whether via direct remittance or reverse charge. In either case, transacting parties are advised to assess whether the imposition of VAT on the digital services would have an effect on agreed pricing between them.Special rule for online marketplaces or e-marketplaces. Online marketplaces may also be required under the law to remit the VAT on behalf of its non-resident sellers, if the online marketplaces are involved in setting the terms and conditions of supply, or are involved in the ordering or delivery of goods. Recognizing the far-reaching effects of VAT on digital servicesFor the very first time, a Philippine law calls the attention of non-resident businesses, DSPs in particular, to comply with local VAT requirements such as registration, invoicing, and more importantly, VAT payment. The law even goes on to say that, in case of failure to register and non-compliance, the BIR, through the Department of Information and Communications Technology, can suspend business operations by blocking access to their digital services in the Philippines.At the same time, the law subtly calls the attention of Philippine customers transacting with DSPs. With a local tax ecosystem that encourages taxpayers to comply, Philippine customers, especially businesses placed on the receiving end of tax audits, should assess its implications from various angles. Questions around the consequences of transacting with unregistered non-resident DSPs, transacting with DSPs that issue non-compliant VAT invoices, and the applicability and proper implementation of the reverse charge mechanism are just some of the valid concerns consumers should recognize in view of the recent VAT law development.The effects of the VAT on digital services law are far-reaching. For now, taxpayers can expect further clarifications to come from the tax authority as it designs the rules and regulations for effective implementation. Atty. Victor C. de Dios is a Tax Principal of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinion expressed above are those of the authors and do not necessarily represent the views of SGV & Co.

Read More
21 October 2024 Henry M. Tan

Why entrepreneurs are critical to the Philippine economy

IN BRIEF:While entrepreneurs represent 10% of the adult population, their ventures account for 70% of employment, making them the most important drivers of job creationEntrepreneurs solve the most complex challenges in today's world and boost the overall economyPhilippines ranks as the world’s 18th most entrepreneurial country, besting developed nations like Denmark, Switzerland, Taiwan, Japan, Singapore, Italy, and New ZealandPULL QUOTE: “When you solve problems, you also attract capital and investments. The Philippines has already produced three unicorns—privately-held startups valued at USD 1 billion or more—with each finding its niche.”  There are 594 million entrepreneurs worldwide, according to the Global Entrepreneurship Monitor, representing 7.5% of the global population, or about 10% of the adult population. This makes entrepreneurs a minority, but their impact on the world is unmistakably massive, as ventures by entrepreneurs account for 70% of total employment—making them significant drivers of job creation and critical for economic development.In this article, we run down the reasons why we should celebrate the successes of entrepreneurs and why we should enable more of them to succeed and flourish.Solving the most complex challengesWe recognize the importance of entrepreneurs because they solve the most complex challenges in today's world by bringing new ideas, products, and services to the market. The essence of entrepreneurship is finding innovative ways to solve seemingly impossible problems—from driving healthcare revolutions to enabling financial inclusion and advancing education technology. The pandemic showcased how entrepreneurial agility in startups can respond to global health crises, giving rise to telemedicine, AI-driven diagnostics, personalized medicine, and vaccine development at unprecedented speeds.Entrepreneurs have created platforms that provide financial services to underserved populations, making it easier for people to access banking services, thus enabling economic growth and helping reduce poverty. Through EdTech, free or affordable education has bridged the gap between formal education and those who need it most, at a time and place they prefer.Entrepreneurs are also bringing the world closer to solving the toughest challenges, such as climate change and the destruction of natural ecosystems. The World Economic Forum points out certain grim realities—10% of the global population still live in extreme poverty, 8 million tons of plastic are deposited into the ocean each year, and an area the size of a football pitch is deforested every second. However, the new generation of entrepreneurs is using technology such as drones and satellites to monitor and heal our planet.Being able to solve problems can also potentially attract capital and investments. The Philippines has already produced three “unicorns”—privately-held startups valued at USD 1 billion or more—with each finding its niche. Two of these unicorns notably emerged during the pandemic. Specifically, a developer of prefabricated properties became the nation's first unicorn in October 2017. A digital wallet and lending platform followed in November 2021, and a payment gateway solutions provider joined the ranks in April 2022.Creating jobs and boosting the overall economyWe celebrate entrepreneurs because they excel at creating jobs and boosting economic growth by introducing innovative technologies, products, and services. In the Philippines, MSMEs make up 99.59% of businesses, providing 65.1% of national employment.Filipinos are very entrepreneurial. Data compiled by the business publication and news site CEOWORLD Magazine ranks the Philippines as the world’s 18th most entrepreneurial country, besting developed nations like Denmark, Switzerland, Taiwan, Japan, Singapore, Italy, and New Zealand.This buoyant entrepreneurial environment is likely to inspire more entrepreneurs to join the ranks. A recent research survey by polling firm OCTA found that four out of five Filipinos would prefer to own their own business. Conducted among 1,200 Filipinos aged 18 and above, the survey revealed that 31% of respondents were motivated by the desire to manage their own time and explore horizons that offer limitless opportunities.By offering something better or new, entrepreneurs create competition within the ecosystem, challenging existing firms to become more competitive. This, in turn, creates more jobs and investments in a wide range of industries.All of this results in increased productivity–which Ray Dalio, founder of the world's largest hedge fund firm, Bridgewater Associates, and author of Principles for Dealing with the Changing World Order: Why Nations Succeed and Fail—argues is the most important force in causing the world's total wealth, power, and living standards to rise over time.“Without innovation, productivity growth would grind to a halt,” he said. “In a market-based system, the most powerful way to drive innovation is to bring new ideas to market and to commercialize and profit from them. The marketplace is incredibly efficient at weeding out bad ideas and pricing good ones. In this way, the concepts of innovation and commercialism go hand in hand.”By encouraging a culture of innovation, entrepreneurs enable countries to produce more relative to the rest of the world, making them more attractive places to do business. By doing what they do best, entrepreneurs also create a platform with the potential to lift people out of poverty and improve the overall quality of life. Many international and local studies have shown that entrepreneurship has a positive and significant impact on poverty reduction. There is evidence proving that entrepreneurship increases the probability of individuals moving out of poverty and remaining above the poverty threshold in the Philippines.Empowering entrepreneurs to shape opportunitiesTo empower more entrepreneurs to shape the future of their businesses with confidence, we are pleased to have once again launched a search for entrepreneurs who are shaping opportunities through the EY Entrepreneur Of The Year Philippines 2024.Formed in 1986, the EY Entrepreneur Of The Year program seeks to honor entrepreneurs whose ingenuity and perseverance have created and sustained successful ventures. In 2003, the SGV Foundation first launched the program in the Philippines and has since been recognizing impactful business who can mold and reshape the country’s economic landscape to build a better Philippines and a better working world.This year’s theme, “Shaping Opportunities,” honors individuals who are turning possibilities into realities and making a profound impact on both the country and the world. The current theme recognizes the transformative ability of Filipino entrepreneurs in reimagining and advancing economic and national development with vision, passion, and innovation, according to the SGV Foundation.Inspired by their dreams and propelled by their unwavering resolve, these Filipino business leaders have played a pivotal role in elevating the country. Over the recent weeks, their narratives have been featured in BusinessWorld, sharing their stories of challenges and triumphs to hopefully encourage current and aspiring entrepreneurs.   Henry M. Tan is a Partner and the Entrepreneur Of The Year Philippines Program Director of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinion expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
14 October 2024 Carlo Kristle G. Dimarucut

Bridging the cybersecurity and business strategy gap

IN BRIEF: Today’s cyber risks go beyond technical vulnerabilities, where a breach can disrupt supply chains, damage brand reputation, and lead to significant financial losses. To mitigate cyber risks and protect business interests, cybersecurity must be integrated into the highest levels of decision-making, aligning security measures with the business’s overall objectives to enhance both security and performance.By embedding cybersecurity into the organization’s DNA, C-suite leaders can protect their assets, enhance innovation, and strengthen customer trust.PULL QUOTE: “To effectively safeguard intellectual property, business continuity, and customer trust, companies must bridge the gap between cybersecurity and business objectives for maximum protection. In the digital era, cybersecurity is no longer just a technical concern—it is a strategic imperative. As organizations embrace new technologies to drive growth, the urgency for robust cybersecurity has escalated. However, many businesses still see cybersecurity as a separate function rather than a critical component of their overarching strategy. This disconnect can be costly, as cyber incidents have far-reaching consequences that threaten every facet of the enterprise. For C-suite executives, integrating cybersecurity into the core business strategy is essential. Cyber threats are increasingly sophisticated, targeting intellectual property, business continuity, and customer trust. To effectively safeguard these assets, companies must bridge the gap between cybersecurity and business objectives, aligning them for maximum protection.Cybersecurity: more than an IT issueTraditionally, cybersecurity was relegated to IT departments as a defensive measure against data breaches, malware, and other threats. However, today’s cyber risks go beyond technical vulnerabilities. A breach can disrupt supply chains, damage brand reputation, and lead to significant financial losses. The average cost of a data breach in 2023 reached $4.45 million, underscoring the financial impact of cyber incidents.High-profile ransomware attacks on global companies demonstrate that cyber threats are not just IT issues—they are business risks that demand executive attention. For businesses to thrive, cybersecurity must be viewed as a strategic priority that permeates all levels of the organization.The cost of misalignment The misalignment between cybersecurity and business strategy stems from how risk is perceived at the executive level. While financial, market, and operational risks are often discussed in boardrooms, cybersecurity remains the domain of technical experts. As a result, cybersecurity measures frequently lag behind business initiatives like mergers, acquisitions, or digital transformation projects, leaving companies vulnerable.This reactive approach can lead to crisis management scenarios rather than proactive risk mitigation. For example, adopting cloud solutions without fully assessing security implications exposes sensitive data to potential attacks. When cybersecurity is treated as an afterthought, companies are forced to respond to breaches rather than preventing them, resulting in increased costs and lost opportunities.To mitigate cyber risks and protect business interests, cybersecurity must be integrated into the highest levels of decision-making. The goal is not just to prevent breaches but to align security measures with the business’s overall objectives, enhancing both security and performance.Embedding cybersecurity in digital transformationDigital transformation initiatives aim to enhance customer experience, optimize operations, and streamline processes. However, these efforts can introduce new vulnerabilities if security is not embedded from the outset. For example, integrating internet of things (IoT) technologies or migrating data to the cloud can open up new attack vectors.Cybersecurity should not be seen as a barrier to innovation but as an enabler. By incorporating security considerations into digital transformation, businesses can mitigate risks while maximizing the benefits of new technologies.Cybersecurity as a value propositionIn industries such as financial services, healthcare, and e-commerce, where data breaches can have severe consequences, demonstrating robust cybersecurity practices can differentiate a business in the market. Customers are increasingly aware of how their data is handled, and a strong cybersecurity framework can foster trust and loyalty and create a competitive advantage.By communicating the company’s commitment to data security, executives can build trust and position their brand as a leader in privacy protection.Integrating cybersecurity into risk managementCybersecurity is not just a technical challenge; it is a critical component of enterprise risk management. A cyber incident can affect a company’s finances, operations, and reputation, making it essential to integrate security into the broader risk framework.C-suite leaders and board members should regularly review cybersecurity performance metrics, monitor emerging threats, and ensure that security investments align with the company’s risk profile. This proactive approach enables companies to anticipate and address cyber risks before they escalate, protecting both the business and its stakeholders.Effective cybersecurity requires collaboration across all business functions. From HR to finance and operations, each department plays a role in maintaining security. For example, HR can drive a security-first culture through regular training, while finance can ensure that security investments align with business goals.The C-suite must foster cross-functional collaboration to create a unified approach to cybersecurity. Breaking down silos ensures that security considerations are embedded into every aspect of the business, enhancing resilience and maximizing ROI.The role of leadership in cybersecurity integrationSuccessful integration of cybersecurity into business strategy requires strong leadership from the top. Executives must champion cybersecurity as a core business priority, actively participating in shaping security strategies and ensuring alignment with business objectives.This begins with a shift in mindset: understanding that cybersecurity is not just about preventing breaches but enabling secure, long-term business growth. Regular communication between cybersecurity teams and the board ensures that the organization remains agile and prepared for emerging threats.In an era of escalating cyber risks, companies that fail to align cybersecurity with their business strategy do so at their own peril. By embedding cybersecurity into the organization’s DNA, C-suite leaders can protect their assets, enhance innovation, and strengthen customer trust. Those that bridge the gap between cybersecurity and business strategy will be better positioned to navigate the complexities of the digital age, turning security from a defensive measure into a strategic advantage.To thrive in the digital age, executives must integrate cybersecurity into their business strategies, emphasizing the importance of aligning security with organizational goals for a holistic, proactive approach.  Carlo Kristle G. Dimarucut is a Technology Consulting Partner of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
07 October 2024 Rossana A. Fajardo

Realizing transformation success through the human element

IN BRIEF: Companies are engaging in transformational activities at an accelerated rate, making the ability to transform successfully and continuously in response to disruption essential for an organization’s survival.Human factors were commonly identified as a primary reason for the result of transformations.To take their transformation efforts to a higher level, organizations must focus on placing humans at the heart of their strategies.PULL QUOTE: “The complex factors that determine whether a transformation succeeds or fails are deeply connected to the human element.” Transformation is important for the enduring success of any organization. However, there has recently been a noticeable shift in its frequency and pace. The EY Global Board Risk Survey revealed that 82% of board members and CEOs believe market disruptions are happening more frequently, and with greater impact. As a result, companies are engaging in transformational activities at an accelerated rate – making the ability to transform successfully and continuously in response to disruption, essential for an organization’s survival.EY and the University of Oxford’s Saïd Business School collaborated to look into more modern and effective methods for driving organizational change. The approach placed a greater emphasis on human factors, which was commonly identified as a primary reason for the failure of transformations. It was observed that not only is the rate of transformation failure excessively high, but it also imposes a human toll that organizations can no longer tolerate.The research indicates that 85% of senior leaders have participated in at least two major transformations in the past five years. Furthermore, 67% of those surveyed acknowledged that they have been part of at least one transformation that did not perform well during this period. While not surprising, it was astonishing that companies continue to accept this high rate of failure as the cost of change. By any other measure or in any other scenario, such a level of performance would be unacceptable.This research underscores that the complex factors determining whether a transformation succeeds or fails are deeply connected to the human element, a pattern that holds true across various industries and geographies. Adequate support can transform the increased stress associated with transformation into a catalyst for enhanced performance and drive progress. To optimize their chances of success, organizations must become proficient in these key areas.Cultivate essential leadership skillsIn the study, employees identified leadership as the primary factor influencing transformation outcomes, regardless of whether it was successful or not. Leaders themselves considered leadership to be the most critical element in successful transformations, but deemed it insignificant when the transformation did not meet expectations.It's essential for leaders to confront their own fears, worries, and uncertainties about the path that lies ahead. For instance, 47% of participants from highly successful transformations reported that leaders were open to ideas from junior staff members, compared to 29% from less successful transformations.Inspire through a shared and compelling visionThe vision is the cornerstone of any transformation. Leaders should extend their search for an inspiring vision beyond their personal scope, their organization, and even their industry. They should cast a broad net to employ future-oriented planning to uncover bold new possibilities, shaping a vision that garners widespread support and resonates emotionally with everyone involved. Close to half (47%) of participants from highly successful transformations acknowledged that the vision was clear and persuasive, in contrast to just 26% from transformations that did not perform well.For the vision to take hold, leaders must effectively convey the reasons behind the need for transformation, rather than merely dictating the actions required. Nearly half (48%) of employees from successful transformations reported that leaders successfully communicated the reasons for organizational change, as opposed to 25% from unsuccessful transformations.Foster a culture that encourages inputIn the qualitative analysis of the research, employees involved in unsuccessful transformations expressed feelings of being ignored, unsupported, and stressed both during and after the process. Subsequent discussions found leaders surprised at these findings and their lack of awareness regarding the significant emotional impact an unsuccessful transformation has on employees.Leaders must channel the appropriate emotions to keep employees committed and driven, while also offering sufficient emotional support to stave off worry and exhaustion. According to the predictive model used in the study, increasing emotional support raised the average probability of a successful transformation by 17%. By being attuned to the emotional state of employees throughout the transformation, leaders can detect early signs of trouble and implement changes to steer the transformation back on course.Empower through clear responsibilitiesThere will be unexpected developments, and intermittent pauses in any transformation journey. Leaders must strike a balance between providing structure and discipline while allowing space for creativity and innovation. Over half (52%) of participants from successful transformations reported that employees had well-defined roles and responsibilities, and 49% indicated that decision-making powers were distributed clearly and suitably throughout the organization.Leaders should promote a culture of trial and error by shifting from a mindset of avoiding failure at all costs to one that embraces rapid learning from failures. Minor setbacks can pave the way for significant achievements, while a fear of failure often results in lost opportunities. Forty-six percent of respondents from successful transformations said they established a process that fosters innovative experimentation without the risk of such experimentation adversely affecting careers or compensation.Leverage technology and skills to drive actionTechnology is not the end goal, but it is instrumental in bringing the vision to fruition. Selecting the appropriate technology is essential to achieving the vision and streamlining the transformation process. Leaders identified the effective deployment of technology as the second most important factor for a successful transformation and its ineffective use as the second leading cause of poor performance. Nearly half (48%) of those from successful transformations reported that their organizations had made the right technological investments to support their transformation goals, as opposed to 33% from less successful transformations. It's vital to consider the emotional reactions that come with the introduction of new technology. Employees from underperforming transformations are 25% more likely to associate transformation with concerns about job stability (49% compared to 39%). Others might view technology as a substitute for human interaction, which is crucial for the emotional health of employees and the smooth functioning of the organization.Leaders should focus on demonstrating progress rather than striving for perfection. By combining recruitment, upskilling or reskilling, partnerships, and outsourcing, leaders can foster the appropriate digital mindset and skills to actualize the potential benefits of technology. Forty-nine percent of participants from successful transformations indicated that their organizations possessed the necessary digital skills and mindset for the transformation, compared to 35% from less successful transformations.Collaborate to connect and createIn contrast to traditional corporate cultures that favored a directive, top-down hierarchy with employees carrying out a vision dictated by their leaders, the current continuous state of transformation demands mutual reliance and teamwork. Leaders must cultivate a culture that promotes connectedness and inventiveness, creating an environment where employees feel secure to explore new methodologies — both digital and agile — that foster innovation, engagement, and rewarding work experiences. Forty-four percent of those from successful transformations reported that their organization's culture supported the adoption of new work practices, as opposed to 28% from less successful transformations. For new work practices to thrive, leaders and employees must work together to recalibrate the dynamics of delegation, ownership, and empowerment. Forty-two percent of participants from successful transformations noted that a new organizational culture was intentionally defined and put into practice as part of the transformation initiative.Harness the human element to achieve transformation successLeaders are aware that their organizations must undergo change, yet the challenge of transformation can leave many feeling inundated. In a time characterized by relentless change, complacency is not a viable option. By tapping into the collective strength of their employees and by applying best practices in relation to each of the factors mentioned, leaders can steer their organizations towards a successful transformation. To take their transformation efforts to a higher level, organizations must focus on placing humans at the heart of their strategies. Rossana A. Fajardo is the Consulting Leader of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinion expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
30 September 2024 Rajiv Kakar

Navigating the software landscape in the GenAI era

IN BRIEF: Traditionally, the choice between custom and packaged software was straightforward – each option presented clear pros and cons aligned with specific business needs. However, the rise of Generative AI (GenAI) has blurred these lines, altering the decision-making process for business leaders.GenAI, with its unprecedented capabilities in generating code, creating unique content and personalized user experiences, has added to the dilemma for enterprises on whether customized solutions continue to create a unique competitive advantage.Businesses must continue to evaluate the need for customization against the benefits of AI-enhanced packaged solutions. PULL QUOTE: “GenAI is redefining software implementation strategy, compelling businesses to choose between the innovations of custom solutions and the broad appeal of AI-powered packaged software.” The rise of GenAI is reshaping the software industry, enabling new ways to create content, automate tasks, and tailor user experiences. Businesses now face a critical decision: should they invest in custom software that is specifically designed for their needs, or should they choose off-the-shelf solutions that are enhanced by GenAI add-ons like customized content and task automation? This choice has significant implications for how software is selected and implemented across enterprises.For example, the insurance and finance sectors, traditionally reliant on custom-built software for their complex operations, are now moving towards standard, packaged solutions driven by GenAI. Given the need for agility, cost-effectiveness, and digital service demands, this shift showcases the challenges and opportunities in modernizing software systems. Their experiences offer valuable lessons for other industries contemplating similar transitions.As leaders navigate this decision, they must consider the long-term impact on their business strategy and operations. This article explores the considerations and implications of choosing between bespoke and off-the-shelf software solutions in the age of GenAI.The evolving decision matrixCustom software is tailored to meet the specific needs of a business, offering a high degree of personalization and flexibility. On the other hand, packaged software provides a ready-made solution that is generally more cost-effective and quicker to deploy but may not cater to every unique requirement.Traditionally, the choice between custom and packaged software was straightforward – each option presented clear pros and cons aligned with specific business needs. However, the rise of GenAI has blurred these lines, altering the decision-making process for business leaders. The integration of GenAI into software development and deployment processes introduces a new complexity, requiring a more strategic approach to software selection. Like the late 1990s shift in production and manufacturing companies, which moved from proprietary systems to standardized ERP (Enterprise Resource Planning) and CRM (Customer Relationship Management) systems, today's businesses must consider the automation and cost advantages that such a transition could bring.Custom software in the GenAI eraCustom software development, once a time-consuming and costly endeavor, is being transformed by GenAI. AI-driven development tools can now assist programmers in generating code snippets, produce functional and test specifications, and reduce the overall development life cycle. Empirical evidence shows that the appropriate use of GenAI in coding tasks can double the gain in developer productivity. This mirrors the automation of important business functions seen in other industries, such as one-touch customer billing or automated supply-chain planning, which have reaped significant cost advantages from shared services.However, the challenges of integrating GenAI into custom software cannot be overlooked. It requires a depth of technical expertise and raises ethical questions about data usage and AI-generated content. Additionally, custom solutions demand a focused approach, often necessitating the hiring of specialized developers and heavy investment in IT infrastructure and licenses. This is akin to the banking and insurance sectors, where upgrades to core systems are lengthy and risky due to complex, heterogeneous products and decades-old IT systems.Packaged software and GenAIOn the other side of the spectrum, packaged software providers are also incorporating generative AI into their products, offering advanced features that were once only possible with custom development. This democratizes access to powerful AI tools, making them available to a wider audience.This change also makes advanced AI tools more accessible to a wider range of businesses. With these enhanced off-the-shelf products, companies can quickly implement sophisticated solutions and tap into the knowledge of a large user base. However, the generic nature of packaged software may not suit all business requirements. Depending on vendors for updates and new AI features could also lead to potential risks and limitations.Navigating the new software landscapeThe age of GenAI is reshaping the software industry, blurring the lines between custom and packaged solutions. Custom software, now more accessible with AI assistance, offers unparalleled customization and competitive advantage. Packaged software, enhanced by AI, provides a cost-effective and quick-to-deploy alternative with a wealth of community support. Businesses must carefully assess their needs, considering factors such as the level of customization required, budget constraints, and the strategic importance of AI in their operations. Whether opting for a custom-built AI-driven platform or an AI-enhanced packaged solution, the goal remains the same: leveraging the transformative power of GenAI to drive innovation and success in the digital age.As the software industry evolves with the integration of GenAI, businesses are faced with choices that mirror those made by banks and insurance companies. The move towards standard software, driven by the need for new digital services and customer demand for online products, suggests a similar path for businesses across all sectors. By examining the success factors identified in the transition from proprietary to standard systems, such as technology selection, transformation leadership, team composition, timing, and transparency, companies can navigate this new era effectively. The lessons learned from other industries serve as a guide for businesses to make informed decisions in adopting new software solutions that harness the power of GenAI. Rajiv Kakar is a Technology Consulting Principal of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
23 September 2024 Bonar A. Laureto

Navigating Change: 10 Key Shifts Shaping Sustainability in the Philippines (Second Part)

IN BRIEF: The SEC's new sustainability reporting form aligns Philippine companies with global standards, enhancing climate risk transparency.Adoption of IFRS S1 and S2 by 2027 will improve the Philippines' attractiveness to investors seeking reliable ESG data.Innovations in insurance, electric vehicles, green steel, renewable energy and battery storage, and aviation fuel are creating new sustainable investment opportunities. PULL QUOTE: “Strategic sustainability shifts are creating new investment frontiers in the Philippines, bolstering the nation's economic and environmental resilience.”The Philippines is rapidly embracing a future where sustainability is not just a buzzword but a core aspect of business and economic strategy. Building on the regulatory reforms and market dynamics discussed in the first part of this series, the country is laying the groundwork for a transformative shift towards a more sustainable and resilient economy. The first part of this article discussed the first five key shifts that are shaping the sustainability landscape in the Philippines, focusing on the implications for businesses and the opportunities for investors in this emerging low-carbon economy. This second article examines the key shifts that are influencing this green transition. It will discuss the roadmap for IFRS S1 and S2 adoption, the severity of rising climate-related loss and damage, rising growth in electric vehicle (EV) adoption, emergence of green steel in construction, decarbonization of the aviation industry, and the innovative approaches and opportunities that are emerging for businesses ready to adapt and thrive in this new landscape.The Philippine Sustainability Reporting Committee’s roadmap for IFRS S1 and S2 adoptionThe Philippine Sustainability Reporting Committee has proposed a roadmap for the full adoption of IFRS S1 and S2 by 2027, which was approved by the Philippine Financial and Sustainability Reporting Standards Council (FSRSC) and for approval by the Board of Accountancy. This phased approach allows companies to gradually align their reporting processes with international standards, improving transparency and comparability across the market. As more companies adopt these standards, the Philippines is set to become increasingly attractive to global investors seeking consistent and reliable ESG data, which is crucial for sustainable investment portfolios.Rising climate-related loss and damageThe increasing severity of climate-related loss and damage in the Philippines has led the insurance sector to re-evaluate its risk models. Consequently, premiums for natural catastrophe insurance products are expected to rise, potentially widening the insurance coverage gap. However, businesses that proactively assess facility-level climate risks can better manage these costs. Additionally, this scenario presents an opportunity for insurance companies to develop innovative products that address the unique risks posed by climate change in the Philippines, thereby safeguarding businesses and communities.Growth in electric vehicle (EV) adoptionEV adoption in the Philippines is gaining significant momentum, driven by investments in charging infrastructure and partnerships with global EV manufacturers. This trend creates investment opportunities in EV technology, infrastructure, and related services, catering to the growing demand for green mobility solutions in the region.Emergence of green steel in constructionThe construction sector in the Philippines is increasingly turning to green steel to reduce scope 3 emissions. This shift is driven by the need to meet sustainability-linked bond requirements and access capital tied to ESG performance. Green steel, which is produced with significantly lower carbon emissions, is becoming a preferred material in real estate and infrastructure projects. This trend opens new avenues for steel manufacturers and suppliers who can meet the rising demand for sustainable construction materials, aligning with global efforts to reduce the carbon footprint of the construction industry.The expansion of the electric vehicle (EV) and green steel industries is set to drive increased demand for renewable energy and battery storage. This surge presents significant opportunities for the renewable energy sector, supporting the Philippines' goal of 50% renewable energy generation by 2040.  Decarbonization of the aviation industryThe Philippine aviation industry is actively pursuing decarbonization strategies, including the production of Sustainable Aviation Fuel (SAF) from biomass feedstocks and the implementation of carbon offset initiatives. Government is considering policies that would set clear directions for the use of SAF by local airlines, creating a significant investment opportunity in SAF production. Moreover, private sector companies that rely on aviation services can contribute to this decarbonization effort by purchasing SAF certificates. This approach not only supports the aviation industry's sustainability goals but also enables these companies to reduce their scope 3 emissions related to air travel and freight, thereby enhancing their overall sustainability profiles.How businesses can adapt and thriveAs the sustainability landscape in the Philippines rapidly evolves, businesses must adapt to remain competitive and resilient. The following strategic priorities are essential for navigating this transition:Transforming management systems and analytical approachesTraditional impact reporting, which often focuses on broad, enterprise-wide metrics, is no longer sufficient. The adoption of IFRS S1 and S2 entails a more detailed, data-driven analysis. Companies need to move beyond basic environmental metrics, employing advanced financial modeling to understand how climate and sustainability risks impact specific business segments. This granular analysis—tailored to the organization’s different business models—enables targeted risk mitigation and strategic planning, ensuring resilience against unique challenges.For instance, a retail mall and an office building within the same company might face vastly different climate risks, requiring tailored risk management strategies. By embracing this level of detail, businesses can better identify vulnerabilities, develop targeted mitigation plans, and ultimately enhance their resilience to climate-related disruptions.Integrating climate considerations into strategic planning and innovationIncorporating climate-adjusted financials into strategic planning not only helps businesses anticipate disruptions but also allows them to understand the broader shifts in their business ecosystem, driven by sustainability and climate imperatives. For example, as the finance community increasingly values sustainable investments, real estate companies are under pressure to adopt green building practices. This shift creates opportunities for manufacturers of construction materials to innovate and supply eco-friendly products, such as green steel or recycled materials. By aligning their strategies with these market dynamics, companies can meet the evolving needs of key customers and capitalize on the growing demand for low-carbon solutions across various sectors. This ecosystem viewpoint ensures that businesses remain competitive and relevant in a market increasingly shaped by sustainability considerations.Elevating corporate governance and oversightThe transition to IFRS S1 and S2 significantly broadens the responsibilities of corporate boards, requiring a deep integration of climate and sustainability considerations into governance practices. Boards must ensure that climate-related risks are systematically managed, utilizing advanced tools like scenario analysis and stress testing to evaluate the resilience of the company’s strategies under various environmental scenarios.Effective governance is also about recognizing and seizing new opportunities. Boards should actively engage in pursuing opportunities identified through strategic planning, such as expanding into emerging markets for sustainable products and technologies. By focusing on both risk management and opportunity capitalization, boards can ensure that the company is not only protected from potential disruptions but also well-positioned to thrive in a changing market.To reinforce this strategic focus, it’s crucial that executive incentives are aligned with sustainability goals. Linking leadership compensation to the achievement of these objectives ensures that sustainability is embedded in the company’s core strategies and decision-making processes. This governance approach ensures compliance, strengthens the company's reputation among stakeholders, and positions the business to capitalize on opportunities in the evolving sustainability landscape.By focusing on these areas, businesses in the Philippines can navigate the evolving sustainability landscape and lead in building a resilient, sustainable future. Bonar A. Laureto is an Assurance Principal and leads Climate Solutions under the Sustainability Services team of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
16 September 2024 Bonar A. Laureto

Navigating Change: 10 Key Shifts Shaping Sustainability in the Philippines (First Part)

IN BRIEF: As a signatory to the Paris Agreement, the Philippines is advancing towards a low-carbon economy with the proposed Low Carbon Economy Investment Act, incentivizing decarbonization plans and carbon pricing.New legislation, including the Carbon Rights Act and BSP Circulars on Environmental and Social Risk Management Systems, is set to redefine sustainable investment and risk management in the financial sector.The SEC's upcoming sustainability reporting form aligns with global standards, enhancing transparency and aiding investors in assessing climate-related risks and opportunities. PULL QUOTE: “Philippine regulatory reforms are catalyzing a sustainable transformation, positioning businesses for resilience and investors for informed decision-making.”  The Philippines is at a pivotal moment in its sustainability journey, driven by a blend of regulatory reforms, market dynamics, and heightened climate awareness. These developments create both risks and opportunities for businesses operating in the country and global investors interested in sustainable investments. As the nation confronts the realities of climate change and its potential impacts, there is a growing consensus among policymakers, business leaders, and civil society on the need for a strategic and coordinated approach to sustainability. This collective push towards environmental stewardship is shaping new business models and investment strategies that prioritize long-term resilience and ethical practices. The Philippines' commitment to this transition is reflected in a series of progressive policies and initiatives that aim to align economic development with sustainable outcomes.This first part of the article explores the first five key shifts that are shaping the sustainability landscape in the Philippines, focusing on the implications for businesses and the opportunities for investors in this emerging low-carbon economy. It explores the upcoming Low Carbon Economy Investment Act, the proposed carbon rights legislation, BSP Circulars 1128 and 2022-042, BSP Circular 1187, and the upcoming Philippine SEC sustainability reporting form. Upcoming carbon pricing policy – Low Carbon Economy Investment Act (HB 7705)The proposed Low Carbon Economy Investment Act, or House Bill 7705, is poised to be a transformative force in the Philippines' shift towards a low-carbon economy. This bill mandates that covered enterprises with substantial contributions to the country’s greenhouse gas (GHG) emissions develop decarbonization plans aligned with a pathway to limit global temperature rise to below 2°C. Additionally, it introduces a carbon pricing mechanism for emissions that exceed established milestones, creating a decarbonization fund. This fund will be reinvested into viable low-carbon projects, presenting significant opportunities for enterprises and investors committed to sustainable development.Proposed carbon rights legislationThe Philippine Congress has introduced the Carbon Rights Act (HB 10635), which aims to address the barriers to investing in carbon forestry and other carbon projects. This legislation seeks to define ownership of carbon rights and establishes mechanisms for their transfer. By clarifying these ownership rights and enabling corresponding adjustments, the bill facilitates the Philippines’ participation in global carbon markets under Article 6 of the Paris Agreement. For investors, particularly those focused on nature-based solutions, this bill presents new opportunities to invest in carbon projects that are critical to achieving global emission reduction targets.BSP Circulars 1128 and 2022-042 on Environmental and Social Risk ManagementThe Bangko Sentral ng Pilipinas (BSP) has implemented Circulars 1128 and 2022-042, which mandate financial institutions to integrate Environmental and Social Risk Management Systems (ESRMS) into their credit risk assessments. These regulations compel banks to conduct climate risk assessments, including stress testing, as part of their underwriting processes. Companies with strong sustainability and climate risk management practices are likely to benefit from easier access to finance, while those slower to adapt may face higher borrowing costs. These circulars also ensure that climate risks are systematically integrated into the financial sector, promoting long-term resilience and stability.BSP Circular 1187 – Sustainable Finance TaxonomyBSP Circular 1187 introduces the Philippine Sustainable Finance Taxonomy Guidelines (SFTG), a framework that classifies economic activities based on their environmental and social sustainability. The taxonomy uses a "traffic light" system—green for aligned activities, amber for transitional activities, and red for non-aligned activities. This classification is crucial for guiding banks and investors in directing capital toward projects that support climate change mitigation and adaptation. By preventing greenwashing, the SFTG ensures that sustainable finance practices in the Philippines are both transparent and credible.Upcoming Philippine SEC sustainability reporting formThe Philippine Securities and Exchange Commission (SEC) is set to introduce a mandatory sustainability reporting form for publicly listed companies, requiring disclosures aligned with International Financial Reporting Standards (IFRS) S1 and S2. These standards emphasize the identification and management of climate-related risks and opportunities, encouraging companies to integrate sustainability into their core business strategies. For investors, these reporting requirements will provide critical insights into the sustainability practices of Philippine companies, facilitating more informed and responsible investment decisions.Charting a sustainable pathThe Philippines stands at a crossroads in its sustainability journey, with recent regulatory reforms and evolving market dynamics steering the nation towards a greener future. As climate change becomes an increasingly pressing global issue, the country is responding with innovative and comprehensive legislative measures and initiatives that aim to reduce carbon emissions and promote sustainable practices, while fostering economic growth, enhancing community resilience, and ensuring environmental justice.The impending introduction of the Philippine SEC's mandatory sustainability reporting form marks a significant step towards greater transparency and accountability in corporate environmental practices. By aligning with international standards, this move propels Philippine companies toward more sustainable operations and equips investors with the requisite information to make responsible decisions. As the nation forges ahead with these regulatory changes, businesses can play a pivotal role in the transition to a sustainable economy, with the potential to set a precedent for other emerging markets in the region.The second part of this article will discuss the roadmap for IFRS S1 and S2 adoption, the severity of rising climate-related loss and damage, rising growth in electric vehicle (EV) adoption, emergence of green steel in construction, decarbonization of the aviation industry, and the innovative approaches and opportunities that are emerging for businesses ready to adapt and thrive in this new landscape. Bonar A. Laureto is an Assurance Principal and leads Climate Solutions under the Sustainability Services team of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
Leading the way in business

Other SGV News and Publications