4. RISK, OPPORTUNITY AND FORECAST REPORT
The risk and opportunity policy of the United Internet Group is based on the objective of maintaining and sustainably enhancing the Company’s values by utilizing opportunities while at the same time recognizing and managing risks from an early stage in their development. A risk and opportunity management system which is “lived” ensures that the United Internet Group (“United Internet”) can exercise its business activities in a controlled company environment. The risk and opportunity management system regulates the responsible handling of those uncertainties which are always involved with economic activity.
4.1 Risk report
Risk management
The concept, organization, and task of United Internet’s risk management system are defined by the Management Board and Supervisory Board of United Internet AG, and documented in a risk management strategy and risk management manual which is valid for and available to all members of the Group. These requirements are regularly adapted to changing legal conditions and continuously developed. Corporate Risk Management coordinates the implementation and ongoing development of the risk management system and is responsible for the centrally managed risk management process on behalf of the Management Board. The risk management system covers only the Group’s risks, while responsibility for the early and ongoing identification, evaluation, and management of opportunities lies directly with the Group Management Board and the operating management levels of the respective segments.
Corporate Risk Management is supported by the risk management teams of the respective segments (Company Risk Management). In order to support Company Risk Management, additional local risk managers have been installed in business fields of particular importance for the Company’s business success (such as the areas “Technology & Development”). In order to facilitate the Group-wide exchange and comparison of risk information, regular Risk Manager Meetings are held between the various risk managers and also with the Company-wide, cross-functional managers.
The Corporate Audit department regularly examines the functioning and efficiency of the risk management system. As part of his statutory auditing obligations for the Annual Financial Statements and Consolidated Financial Statements, the external auditor also examines whether the risk early recognition system is generally suitable for the early identification of risks and developments which might endanger the Company so that suitable countermeasures can be swiftly introduced. The system complies with statutory requirements regarding risk early recognition systems, as well as with the version of the German Corporate Governance Code valid at the time of the last Declaration of Conformity of United Internet AG. Its design is based on the specifications of the international ISO standard ISO/IEC 31000:2018. In accordance with the regulations of the German Stock Corporation Act, the Supervisory Board also examines the efficacy of the risk management system.
Methods and objectives of risk management
The risk management system comprises those measures which enable United Internet to identify, classify in terms of money and scenario, steer, and monitor from an early stage all possible risks for the attainment of its corporate objectives with the aid of assessments and early warning systems. The aim of the Group-wide and IT-supported risk management system is to provide maximum transparency for management regarding the actual risk situation, its changes, and the available options for action so that a conscious decision can be taken to accept or avoid such risks. Risks endangering the Company must be avoided as a matter of principle. There is always an established indirect connection to central Group-wide risk management via the regular reporting channels throughout the Group and a direct connection for all major divisions. This ensures the completeness of registered risks in the risk management system.
The current status of the main risks is communicated to the Management Board and Supervisory Board four times per year.
Identified significant risks with an immediate impact and changes in the risk situation trigger an ad-hoc reporting obligation. The respective risk is then communicated immediately to the CFO of United Internet AG, who in turn reports it to the Supervisory Board where necessary. In this way, significant risks can be addressed as quickly as possible.
Risks are assessed with their net impact, i.e., effects from mitigating measures are only considered in the risk assessment after implementation.
Risks for the United Internet Group
The assessment of the overall risk situation is the result of a consolidated examination of all known material risks. Of the total risks identified for the Group, the following sections describe the main risk categories from the Company’s point of view.
The starting point for assessing the materiality of risks is provided by the characteristics “probability of occurrence” and “potential damage”. The potential damage comprises the potential loss of revenue, as well as potential external and internal expenses. Based on the combination of probability of occurrence and potential damage, the risks are assigned as follows to one of three risk categories: “significant”, "moderate", and "low" risks.
Specific assessments of the Company’s Management Board regarding the Group’s risk situation, as well as the probability of occurrence, potential damage, and resulting categorization of the risks described below are provided at the end of this Risk Report.
Strategy
Shareholdings & investments
The acquisition and holding of shares in other companies and the making of strategic investments represent a key success factor for United Internet AG. In addition to improved access to existing and new growth markets, as well as to new technologies and know-how, investments also serve to exploit synergy and growth potential. However, these opportunities involve risks. For example, there is a risk that the targeted potential cannot be exploited as forecast or that acquired shareholdings will not develop as expected (non-scheduled write-downs/impairments, disposal losses, absence of dividend, or reduction of hidden reserves).
All investments are therefore subject to a continuous monitoring process by the Investment Management and are supported promptly if required. This risk is largely without relevance for EBITDA as, in the event of an incident, predominantly non-cash-effective impairments are incurred. The value of investments is continuously monitored by management and the Controlling division.
Business development & innovations
A further important success factor for United Internet is the development of new and constantly improved products and services in order to enhance sales and earnings, attract new customers, and expand existing customer relationships. There is always a risk, however, that new developments might be launched too late on the market or not be accepted by the target group as expected.
United Internet counters such risks by constantly and closely observing market, product, and competition trends, as well as by undertaking product development which constantly responds to customer feedback.
As part of its efforts to diversify the business model or expand its value chain, United Internet occasionally enters new markets, or upstream and downstream markets. For example, the management board of 1&1 AG, a subsidiary of United Internet AG, decided with the approval of its supervisory board to establish and operate a high-performance 5G mobile network on the basis of the spectrum in the 2 GHz and 3.6 GHz bands it acquired in 2019. By establishing and operating its own network, the Company plans to further expand its value added in mobile communications, to tap new business fields, and to reduce its dependence on procuring wholesale services from other network operators.
1&1 has enlisted in particular the services of the Japanese technology group and acclaimed OpenRAN expert Rakuten as general contractor for the rollout of its mobile communications network. Together with Rakuten, 1&1 will build Europe’s first fully virtualized mobile network based on the innovative OpenRAN technology. The use of OpenRAN technology will reduce 1&1’s dependence on network equipment suppliers. Nevertheless, there are still risks that the network rollout will not progress at the expected speed. Supply problems for the necessary hardware or delays in the search for sites are potential risks.
In selecting partners for the rollout of its network, 1&1 placed great importance on minimizing such risks. The general contractor and partner for active network technology Rakuten, for example, was the world’s first and only network equipment supplier to establish a mobile communications network on the basis of the new OpenRAN technology in Japan. As a result, 1&1 can benefit from the experience and learning curve Rakuten gained during this time. The partners for passive technology are established and leading companies in Europe for radio tower infrastructure, enabling 1&1 to benefit from their existing infrastructure.
Nevertheless, initial delays in the construction of antenna locations already occurred in 2022. These delays were due to supply problems of advance service providers. Delays in network rollout may mean that more advance services have to be procured externally than planned in the period up to completion of the mobile network rollout, which would have a negative impact on value added.
In order to counter this risk appropriately, 1&1 has entered into further partnerships for the acquisition of antenna locations and for its own construction of antenna locations.
Cooperation & outsourcing
Some operating divisions of United Internet work together with specialized cooperation and outsourcing partners in certain areas of the Company. The focus here is on objectives such as focusing on the actual core business, reducing costs, or leveraging the expertise of partners. These opportunities also involve risks in the form of dependencies on external service providers, as well as contractual and default risks.
In order to reduce these risks, detailed market analyses and due diligence reviews are carried out before major contracts are concluded with external service providers, and close and cooperative relationships are maintained with the cooperation and outsourcing partners after the contracts have been concluded.
Organizational structure & decision-making
The choice of the appropriate organizational structure is essential for the efficiency and success of the Company. In addition to the organizational structure, business success depends to a large extent on making the right decisions. The basis for such decisions can be negatively influenced by various factors, such as limited flexibility offered by existing business processes and structures, or misunderstandings caused by ambiguities in the definition of key figures. If efficiency is jeopardized by one or several factors, this represents a strategic risk for United Internet which should be avoided wherever it makes economic sense.
Due to the high degree of agility within the organization, United Internet considers itself to be generally well positioned in this respect and undertakes a number of measures to standardize and optimize processes, structures, and key figures.
United Internet is not aware of any significant risks in this field at present.
Personnel development & retention
Highly skilled and well trained employees form the basis for the economic success of United Internet. In addition to the successful recruitment of qualified personnel (see also the “personnel recruitment” risk), personnel development and the long-term retention of top performers within the Company are strategically important. If the Company fails to develop and retain executives and employees with specialist or technological knowledge, there is the danger that United Internet may not be able to effectively conduct its business and achieve its growth targets. The concentrated accumulation of strategic knowledge and skills (so-called head monopoly) can have a considerable impact on the performance of the Company if the corresponding employee is no longer available.
United Internet counteracts this risk by continuously nurturing employee and management skills. For example, it offers targeted measures for professional development, mentoring and coaching programs, as well as special offers for high potentials geared to talent development and retention and leadership skills.
For further information on topics such as “HR Strategy and HR Organization“, “Training and Education”, “Diversity and Equal Opportunities”, as well as “Occupational Health and Safety”, please refer to the chapter “United Internet as an Employer” in the Sustainability Report 2022 of United Internet AG, which will be published in late March 2023 (at https://www.united-internet.de/en/investor-relations/publications/reports.html).
Market
Sales market and competition
The markets in which United Internet operates are characterized by strong and sustained competition. Depending on the strategy of the parties involved in the market, different effects may occur which may lead also involve adjustments to the Company’s own business models or pricing policy. The entry of new competitors might also jeopardize market shares, growth targets, or margins. In addition, United Internet itself occasionally enters new, additional markets with large competitors. Such an entrepreneurial decision is always associated with new risks.
United Internet attempts to minimize these risks by means of detailed planning based on internal experience and external market studies, as well as by constantly monitoring the market and the competition.
Procurement market
A gap in the procurement or delivery of resources required for business operations may also lead to bottlenecks or outages at United Internet. This applies both to the purchase of hardware and the purchase of wholesale services. Increases in the price of purchased products and services represent a risk for the targeted margins. Planned positive effects from contractually fixed price adjustment rounds can become a risk for the achievement of the Company's periodic targets due to time delays.
United Internet counters these risks by cooperating with several long-term service providers and suppliers, contractual obligations, and – where it makes economic sense – by expanding its own value chain. Although significant and unforeseeable developments on the procurement market as a result of events such as the Ukraine war cannot be fully offset, they can be countered by taking preventive measures such as rapidly restocking inventories.
Financial market
United Internet’s activities are fundamentally exposed to risks on the financial market. In particular, these include risks from changes in interest rates and exchange rates.
- Interest
The Company is exposed to interest risks as the major share of its borrowing bears variable interest rates with varying terms. As part of its liquidity planning, the Company constantly monitors the various investment possibilities and debt conditions. Any borrowing requirements are met by using suitable instruments to manage liquidity. Surplus cash is invested on the money market to achieve the best possible return. Due to developments on the global finance markets, i.e., adjustments to central bank interest rates around the world, there was a slight increase in the interest rate risk, but at the same time opportunities from more attractive investment options. Market interest rate changes might have an adverse effect on the interest result and are included in our calculation of sensitive factors affecting earnings. In order to present market risks, United Internet has developed a sensitivity analysis which shows the impact of hypothetical changes to relevant risk variables on pre-tax earnings. The reporting period effects are illustrated by applying these hypothetical changes in risk variables to the stock of financial instruments as of the balance sheet date.
- Currency
The currency risk predominantly results from operations (if revenue and/or expenses are in a currency other than the Group’s functional currency) and its net investments in foreign subsidiaries.
Personnel recruitment market
It is therefore essential that human resources are effectively controlled so that the Company can ensure its short- and long-term needs for staff and the requisite expertise. If United Internet is not able to attract managers and employees with specialist and technological knowledge, it would not be able to effectively conduct its business and achieve its growth targets.
As an attractive employer, the United Internet believes it is well placed to hire highly skilled specialists and managers with the potential to drive its business success in the future. This was confirmed in the past years by the Top Employers Institute, which awarded United Internet the accolade “Top Employer 2022”.
For further information on topics such as “HR Strategy and HR Organization“, “Training and Education”, “Diversity and Equal Opportunities”, as well as “Occupational Health and Safety”, please refer to the chapter “United Internet as an Employer” in the Sustainability Report 2022 of United Internet AG, which will be published in late March 2023 (at https://www.united-internet.de/en/investor-relations/publications/reports.html).
Provision of services
Work processes
In view of the ever-increasing complexity and interoperability of the products offered, there are steadily growing demands placed on the development of internal work processes. This also involves an ever-higher degree of coordination The particular challenge is to ensure quality standards especially in view of fast-changing market events – and on numerous differing domestic and foreign markets.
The Company counters these risks by continuously developing and enhancing its internal processes, pooling and retaining its experts and key personnel, and continuously optimizing its organizational structures.
Information security
United Internet generates its commercial success largely in the telecommunications market and within the environment of the internet. In order to provide products and services, the Company uses information and telecommunication technologies (data centers, transmission systems, connection nodes, etc.) in its business processes which are closely networked with the internet and whose availability may be endangered by threats from the internet.
In order to continue to deal with such risks quickly, the existing monitoring, building access, and alarm system, together with the necessary processes and documentation, is continuously optimized.
There is also the risk of hacker attacks with the aim of stealing or deleting customer data, or using services fraudulently. In the fiscal year 2022, an increasing professionalization of the attackers and their attack methods was observed once again. According to the German Federal Office for Information Security (BSI), the number of new detected malicious program variants increased by around 116.6 million in the period June 1, 2021 to May 31, 2022. According to the BSI, there were no apparent attack campaigns targeting Germany in connection with the war in Ukraine – unlike the situation for NATO as a whole.
United Internet counters this risk with the aid of virus scanners, firewalling concepts, self-initiated tests, and various technical monitoring mechanisms.
The threat potential of the internet is one of the largest threat groups for United Internet with regard to its effects, which are all monitored and reduced by numerous technical and organizational measures. Of particular relevance in this respect are the operation and continuous improvement of the security management system and the steady enhancement of system resilience.
Capacity bottlenecks
Due to temporary or permanent shortages of technical resources, e.g., due to the temporary overloading of systems or a lack of resources to operate data centers, existing capacities might be exceeded and consequently the planned provision of services could be jeopardized, threatening a corresponding loss of sales. Risks from the procurement of resources, such as products or services on the market, are not taken into account here.
In order to counter these risks, several internal stores are maintained which are continuously adapted to delivery times on the global market. In addition, the Company is in close contact with energy suppliers, for example, in order to coordinate emergency concepts regarding the data centers. In the case of outages, these can be compensated for at short notice by implementing the aforementioned measures.
Projects
The classic project objectives of quality, time, and budget are defined before or at the start of a project and are thus the subject of entrepreneurial planning. If potential risks already become apparent in the course of planning or project design or if negative deviations from these plans become apparent in the course of a project’s implementation, these are recorded as risks. Moreover, projects may also involve risks that do not affect the project itself but arise after the project has been completed (e.g., security vulnerabilities in new software code).
Active project management ensures that risk-reducing measures are already implemented during the project. In addition to maintaining the current professional project management, the Company reduces the aforementioned risks by holding regular specialist project management training courses, in order to improve such aspects as security or data privacy requirements. Project objectives are also closely monitored by management and the Controlling division
Technical plant operation
United Internet’s products and related business processes are based on a complex technical infrastructure and a number of success-critical software systems (servers, customer relationship databases, and statistics systems, etc.). Constantly adapting this infrastructure to changing customer needs leads to greater complexity and regular changes. In addition to major events, like the migration of databases, this may lead to various disruptions or defects. Should this affect our business systems or their databases, for example, daily account debiting may be delayed or no longer possible. Should this affect our performance systems, for example, United Internet may not be able to provide its customers with the promised service, on a temporary or longer-term basis.
The Company meets these risks by making targeted adjustments to the architecture, introducing quality assurance measures, and establishing spatially separated (geo-redundant) core functionalities.
For the operation of systems, there is a risk of targeted attacks from inside and outside the Company, e.g., from hackers or manipulation by staff with access rights, which may result in non-availability or a deterioration of services.
In order to counter this risk, the Company takes a wide variety of software- and hardware-based safety precautions to protect the infrastructure and its availability. By dividing responsibilities, the Company has made sure that activities or business transactions involving risks are not carried out by single employees but on the basis of the “double-check principle”. Manual and technical access restrictions also ensure that employees may only operate within their particular area of responsibility. As an additional precautionary measure against data loss, all data are regularly backed up and stored in separate, i.e., geo-redundant, data centers.
Compliance
Data privacy
It can never be fully ruled out that data privacy regulations may be contravened, e.g., by human error or technical weaknesses. In such cases, United Internet faces fines and the loss of customer confidence.
United Internet stores the data of its customers on servers according to international security standards at its own and at rented data centers. The handling of these data is subject to extensive legal regulations.
The Company is aware of this great responsibility and attaches a high degree of importance and care to data privacy. By using state-of-the-art technologies, continuously monitoring all data-privacy and other legal regulations, providing extensive staff training on data protection regulations, and involving data protection aspects and requirements as early as possible in product development, United Internet continuously invests in improving the standard of its data privacy.
The new rules of the EU General Data Protection Regulation (GDPR) came into force in May 2018. Due to increased sanctions for breaches of duty, data protection risks have increased. In addition to higher sanctions, GDPR also includes new regulations regarding consent declarations, as well as new obligations for reporting to authorities and those affected in the case of data loss. With the Telecommunications Telemedia Data Protection Act (“Telekommunikation-Telemedien-Datenschutz-Gesetz” - TTDSG), the data protection regulations of the Telecommunications Act (“Telekommunikationsgesetz” - TKG) and Telemedia Act (“Telemediengesetz” - TMG) have been transferred to a separate law as of December 1, 2021.
Misconduct & irregularities
Non-compliance or non-observance of social norms, trends, and peculiarities can lead to misconduct and wrong decisions and thus to a loss of revenue. As an internationally operating company, United Internet also faces the challenge of countering such negative factors through adequate management in the area of internal processes and procedures. Not every decision or business practice that is unobjectionable from a legal point of view is also acceptable in the respective cultural, ethical, or social context.
United Internet counters the risks arising from misconduct and breaches of rules with its “culture of togetherness”, the provision of a Code of Conduct, country-specific management, and compliance as an integral part of corporate culture.
Legislation & regulation
Changes in existing legislation, the enactment of new laws, and changes in government regulation issues may have unexpected negative effects on the business models pursued by United Internet and their further development. The decisions of the Federal Network Agency and the Federal Cartel Office have an influence on network access and the pricing of internet access tariffs. Price increases of network providers from whom United Internet purchases pre-services for its own customers can have a negative impact on the profitability of tariffs. In the same way, there is also the possibility that a lack of regulation may lead to a deterioration of market circumstances for United Internet.
1&1’s frequency acquisition in 2019 was tied to the fulfillment of certain regulatory requirements. Among other things, 1&1 was obliged to put 1,000 5G base stations into operation by the end of 2022, distributed proportionately across Germany’s federal states. Due to delivery difficulties of the upstream providers commissioned by 1&1 to provide the antenna locations, 1&1 had fallen well short of this target by the end of 2022. Compliance with the frequency requirements is closely monitored by the Federal Network Agency. Non-compliance may result in a fine and, in the worst case, the revocation of frequency usage rights. As a result of the failure to meet the rollout target by the end of 2022, the Federal Network Agency is currently considering a corresponding sanction in the form of a fine. Moreover, there are requirements that the mobile communications network must cover 25 percent of households by 2025 and 50 percent by 2030. Failure to meet these targets could also result in fines or, in the worst case, the withdrawal of frequencies.
In the fiscal year 2022, “fair consumer contracts” came into force with a stronger focus on customer protection for electronic communications. Violations of these regulations may result in fines. As a result, the products and services offered by the United Internet Group were adapted with regard to the new legislation and requested features, such as a “contract termination button”, were added.
United Internet attempts to counter this tendency toward an increasing regulation risk by cooperating with various pre-service providers and by actively participating in the activities of industry associations.
Litigation
United Internet is currently involved in various legal disputes and arbitration proceedings arising from its normal business activities. The outcome is by definition uncertain and thus represents a risk. Insofar as the size of the obligation can be reliably estimated, accruals are formed for such risks from litigation, where permissible.
The United Internet Group is currently involved in various legal disputes and arbitration proceedings arising from its normal business activities. In 2019, an advance service provider filed claims against 1&1 in the low three-digit million range (for the purposes of internal classification, amounts of up to € 333 million are defined as being in the low three-digit million range, and the claims filed do not exceed this amount in total). 1&1 considers the claims of the respective counterparty to be unfounded and regards an outflow of resources as unlikely. The outcome is by definition uncertain and thus represents a risk. Insofar as the size of the obligation can be reliably estimated, accruals are formed for such risks from litigation.
Tax risks
As an internationally operating company, United Internet is subject to the tax laws applicable in the respective countries. Risks may arise from changes in tax laws and double taxation agreements, or case law, as well as from differences in the interpretation of existing regulations.
United Internet counters these risks by continuously expanding its existing tax management system.
Finance
Financing
The main financial liabilities incurred by United Internet AG for the financing of its activities include bank loans, overdraft facilities, and other financial liabilities. United Internet AG holds various financial assets which result directly from its business activities. They consist mainly of shares in affiliated companies and investments, as well as receivables from affiliated companies. As of the balance sheet date, the Company almost exclusively held primary financial instruments.
The aim of financial risk management is to limit risks through ongoing operating and financial activities.
Fraud & credit default
In order to meet the requirements of dynamic customer growth and provide services as quickly as possible in the interests of its customers, United Internet has largely automated its order and provision processes – as have many other companies in such mass market businesses. The nature of such automated processes provides possibilities for attacks from fraudsters. Due to the strong appeal of the products and services offered, not only the number of customers is increasing but also the number of non-payers and fraudsters. Consequently, the amount of credit default has risen.
United Internet attempts to prevent such fraud attacks – or at least to recognize and end them at an early stage – by permanently expanding its fraud management capabilities, working closely with pre-service providers, and taking account of such risks in the design of its products.
Liquidity
The general liquidity risk of United Internet AG consists of the possibility that the Company may not be able to meet its financial obligations, such as the redemption of financial debts. The Company’s objective is to continuously cover its financial needs and secure flexibility, for example by using overdraft facilities and loans.
Group-wide cash requirements and surpluses are managed centrally by the cash management system. By netting these cash requirements and surpluses within the Group, the amount of external bank transactions can be minimized. This is managed, e.g., by using cash pooling processes. The Company has established standardized processes and systems to manage its bank accounts and internal netting accounts, as well as for the execution of automated payment transactions. In addition to operating liquidity, United Internet AG also holds other liquidity reserves, which are available at short notice.
Acts of God
External events such as natural disasters (earthquakes, floods, tsunamis, etc.), personnel crises (pandemics, strikes, etc.), infrastructure crises (power outages, road damage, etc.), or violent incidents (rampage, terrorist attacks, war, etc.) may affect United Internet's operations.
United Internet counters these risks as far as possible with a variety of measures. Examples include the establishment of building access restrictions, the operation of georedundant data centers, or hygiene precautions, location-independent workplaces, the use of modern communication media to avoid travel, and the elaboration of emergency concepts.
The latter has become more important as a result of the Ukraine war. The United Internet Group has taken this as an opportunity to revise its existing security measures and concepts and, if necessary, to adapt them to the higher threat levels.
Additional disclosures on risks, financial instruments, and financial risk management
Further details on risks, financial instruments, and financial risk management are provided in note 43 “Objectives and methods of financial risk management“ in the Notes to the Consolidated Financial Statements.
Management Board’s overall assessment of the Group’s risk position
The assessment of the overall level of risk is based on a consolidated view of all significant risk fields and individual risks, also taking account of their interdependencies.
- From the current perspective, the main challenges are the risk fields “Legislation & regulation”, “Litigation”, “Information security”, and “Technical plant operation”.
- For the risk field “Technical plant operation”, the risk assessment was changed from Moderate to Significant to take account of the increased risks, e.g., from hacker attacks.
- The risk assessment of the risk field “Cooperation & outsourcing” rose from Low to Moderate due to the general development of business.
- There was also an increase in the risk field “Misconduct & irregularities” from Low to Moderate. The reason for this increase is enhanced risk awareness, which has led to an increased identification of risks in this field.
- Otherwise, the risk classifications of the risk fields of United Internet AG as at December 31, 2022 were unchanged from December 31, 2021.
The continuous expansion of its risk management system enables the United Internet Group to limit risks to a minimum, where economically sensible, by implementing specific measures.
There was a slight year-on-year decrease in the overall risk. In the overall risk assessment, decreases in the expected damage extent of individual risks resulted in a lower overall risk. Increased risks in the areas of technical plant operation, cooperation & outsourcing, and misconduct & irregularities were more than offset by the decrease in individual risks in other risk categories. The main drivers are lower individual risks in the risk categories Acts of God (in particular the SARS-CoV-2 virus) as well as litigation and fraud & credit default.
In the assessment of the overall risk situation, the existing opportunities in the United Internet Group were not taken into consideration. There were no risks which directly jeopardized the continued existence of the United Internet Group in the fiscal year 2022, nor as of the preparation date for this Management Report, neither from individual risk positions nor from the overall risk situation.
Probability of occurrence, potential damage, and the classification of risks from the Group's perspective and their relevance for the various segments/divisions :
Risks in the field of “Strategy" | |||||||
Shareholdings & investments | Corporate | Low | Low | Moderate | ➙ | ||
Business development & innovations | Consumer Access | High | High | Moderate | ➙ | ||
Cooperation & outsourcing | Business Applications | Low | Low | Moderate | ➚ | ||
Organizational structure & decision-making | Currently no significant risks | Low | ➙ | ||||
Personnel development & retention | Business Applications | High | Low | Moderate | ➙ | ||
Risks in the field of “Market” | |||||||
Sales market & competition | Business Applications | Low | High | Moderate | ➙ | ||
Procurement market | Business Access | Low | High | Moderate | ➙ | ||
Financial market | Business Applications | Very high | Very low | Low | ➙ | ||
Personnel recruitment | Business Access Business Applications | High | Very low | Low | ➙ | ||
Risks in the field of “Service Provision” | |||||||
Work processes | Business Applications | Low | Low | Moderate | ➙ | ||
Information security | Business Applications | Very low | Extremely high | Significant | ➙ | ||
Capacity bottlenecks | Business Applications | Low | Very low | Low | ➙ | ||
Projects | Consumer Access | Low | High | Moderate | ➙ | ||
Technical plant operation | Business Applications Corporate | Very low | Extremely high | Significant | ➚ | ||
Risks in the field of “Compliance” | |||||||
Data privacy | Consumer Applications | Low | High | Moderate | ➙ | ||
Misconduct & irregularities | Business Applications | Low | Low | Moderate | ➚ | ||
Legislation & regulation | Consumer Access | Low | Extremely high | Significant | ➙ | ||
Litigation | Consumer Access | Low | Extremely high | Significant | ➙ | ||
Tax risks | Business Applications | High | Very low | Low | ➙ | ||
Risks in the field of “Finance" | |||||||
Financing | Business Applications | Very low | Low | Low | ➙ | ||
Fraud & credit default | Consumer Access Business Applications | Very high | Low | Moderate | ➙ | ||
Liquidity | Business Applications | High | Very low | Low | ➙ | ||
Risks in the field of “Acts of God” | |||||||
Acts of God | Business Access Business Applications | Very low | High | Moderate | ➙ | ||
Main segment relevance | Probability of occurrence | Potential damage | Risk classification | Change over previous year |
Legend:➘improved➙unchanged ➚worsened