Governance, Risk, Compliance and Assurance
An overview of frameworks and arrangements in place to protect our business foundations.

The Aster Group (Aster) exists to be a registered provider of social housing with a vision that everyone has a home.
Our Corporate Strategy ensures that we continue to prioritise the right things and work together to achieve that. The purpose of this document is to guide you through the arrangements in place to ensure that we maintain our strong business foundations in everything we do while we are achieving our strategy. By business foundations we mean the fundamental elements, principles, and core components upon which a business is built and operates; the basic building blocks providing structure, direction, and stability such as planning, finances, management and decision making.
This document sets out some of the key principles, how they connect and provides context as to why they are in place. There is signposting to the more detailed frameworks.
The purpose of this document Group frameworks
We have a set of frameworks in place to maintain the strength of our business foundations.
These frameworks provide some overarching principles and guidance that apply to protect and enable our whole business, allowing for freedom to experiment and adapt in a way that doesn’t introduce unnecessary risk that may harm our business foundations. Frameworks and arrangements include, but are not limited to:
• Scheme of Delegation (The Delegations Matrix)
• Governance Framework
• Business Planning approach
• Risk Framework
• Compliance Framework
• Policy Methodology
• Corporate Performance Framework
• Internal Audit Plan
• Assurance Principles.
Governance Framework
What is it?
A Governance Framework is a structured system that defines how an organisation is directed, controlled and held accountable.
It encompasses processes, policies and corporate legal practices to help align the organisation’s activities with its goals. Additionally, it ensures compliance with regulatory and legal requirements.
The Corporate Structure is often included within the Governance Framework. This refers to the arrangement of different roles and responsibilities within the organisation, the Governing Body structure and the arrangement of its corporate entities under the parent company, often referred to as subsidiaries. Collectively with the parent company, this is known as a Group.
How does this apply to the Aster Group?
Our Governance Framework provides key information to help us manage our complex Group and defines the relationship between Aster Group Limited, as the parent company sitting at the top, and all its subsidiaries.
These include companies, charities, community benefit societies and joint ventures. Our Boards, Committees and Panels constitute our Governing Body structure and are the ‘decision- making’ and ‘scrutiny’ groups, whilst our Executive Structure shows the hierarchy of leadership roles designed to manage and oversee Aster Group’s activities.
What does Aster Group’s Corporate Structure look like?
Our Governing Body structure comprises various Boards, Committees and Panels. Each body operates under specific Terms of Reference (the ‘ToR’), which outline their membership, purpose, responsibilities and delegated decision-making authority from the Aster Group Limited Board. Our Governing Bodies include:
• Overlap Boards: Responsibility for the delivery of strategy through strong assurance provided by the performance and compliance frameworks
• Committees: Support work of the Boards by providing oversight and assurance
• Executive Board: Supports the Overlap Boards to deliver the strategy through effective operations
• Executive Board Panels: Operational oversight and scrutiny.
Governance Framework (continued)
The ‘Four Cornerstones’ of Aster Group
At Aster Group, our four cornerstones form the foundation of our operations and strategic initiatives. These cornerstones ensure that we maintain the highest standards of excellence, integrity and innovation in everything we do.
What does this mean for you?
Every action, decision and initiative should reflect our commitment to these cornerstones. Whether you are drafting a report, entering into a contractual agreement, requesting information or proposing a new initiative, it is essential to align with our established guidelines and procedures. This alignment not only ensures compliance but also reinforces our collective dedication to upholding the values that define the Aster Group.
• Report Submission: When required to draft or contribute to a report for one of our Governing Bodies, please consult the report templates and guidelines to ensure compliance with the established requirements
• Contractual Agreements: As Aster Group is a brand name and not a legal entity, it is imperative that any contract entered into on behalf of Aster is with a legal entity within the Aster Group, such as Aster Property Limited. This ensures the transaction is legally binding
• Information Requests: For legal information pertaining to any entity within the Aster Group, including company numbers, please refer to our legal group structure
• New Initiatives: When proposing a new initiative that requires scrutiny and decisions by our Governing Bodies, the Head of Governance will provide the necessary guidance to navigate the approval process.
Risk Appetite
What is it?
Risk appetite is how much risk Aster is willing to take to achieve its goals. It’s a crucial part of our framework for managing risks. The board of Aster Group Ltd decides the appropriate level of risk appetite for different parts of the business and different objectives.
Actively seeking opportunities with higher potential reward. We are willing to take significant risks, but only where we fullyunderstand them, can manage them, and they strongly support our strategic goals.
Comfortable taking a balanced level of risk. We look for opportunities that improve value for money, efficiency or outcomes, as long as the potential benefits outweigh the risks.
Prepared to take some risk when it is necessary to deliver key outcomes. We will try new things, but only when the risks are manageable and well-controlled.
Sticking to tried-and-tested approaches. We only take very small risks and prefer activities that are stable, predictable and well-understood.
Avoiding risk wherever possible. Safety, compliance and control come first.
What is the purpose?
The purpose is to determine the right level of risk that Aster is willing to accept. If the Board is too cautious about risk, it can limit performance, stifle innovation, and hinder strategic goals. In addition to this, being overly risk-averse can lead to complex and expensive risk mitigation efforts. On the other hand, being too risk hungry can have severe consequences, including financial threats or endangering lives and homes.
Aster’s risk appetite may differ from that of individual risk owners, so decisions should align with Aster’s overall risk tolerance. The Board has identified risks they are willing to take in pursuit of strategic priorities and key outcomes, as well as risks they absolutely won’t tolerate—such as safety threats that undermine well-being. Safety always comes first.
What does this mean for you?
Everyone at Aster has a responsibility to manage risks related to the services and outcomes they are accountable for. This includes providing appropriate onward assurance. A positive risk culture involves acceptable behaviours, attitudes, discussions, and decisions related to risk management.
It emphasises transparent, timely, and honest communication, learning, and continuous improvement. By adhering to “The Aster Way,” we can share a mature risk culture.
The Delegation Matrix
What is it?
Aster’s Governance Framework includes a Delegation Matrix (the ‘DM’), which outlines the specific responsibilities and decision-making authority at various levels of the organisation. The DM ensures clarity in roles and accountability, helping to maintain an efficient and effective governance structure. It also which decisions are reserved for the Boards, and which can be delegated to our Committees, the Executive Board or Panels. The latest version of our DM can be found within AsterNet.
What is the purpose?
The DM’s primary role is to map how decisions are made in Aster by individuals and / or by a Governing Body, including the scrutiny and the assurance provided ahead of a final approval.
Within the governance structure of Aster Group Limited and its subsidiaries, certain decisions are explicitly reserved for the Boards and cannot be delegated. This stipulation is outlined in the Rules or Articles of Aster Group Limited. Other decisions are delegated to various Committees, the Executive Board or our Panels. This delegation is designed to streamline operations and leverage specialisedexpertise within the organisation.
What does this mean for you?
You will regularly make decisions as part of your role at Aster. However, some decisions will require approval by somebody more senior than you and / or by a Governing Body as set out in the DM. The Head of Governance provides advice about what action needs to be taken and provides guidance in how to navigate through the DM.
Ownership Approval
Business Planning Framework
What is it?
Aster’s The Business Planning Framework provides the structure for us to decide on our priorities and the projects to deliver them in the short, medium and longer term and encompasses:
• Clearly defined projects / activities
• Clarity of purpose
• Strategic Priority or business health?
• Discretionary VS non-discretionary
• Identification of enabling requirements
• Resource and workforce planning
• Budget / financial implications - focusing on both cost and direct financial benefits
• Clear articulation of any wider, non-financial benefits.
What is the purpose?
The framework enables us to:
• Prioritise finite resources
• Drive greater focus on benefits realisation and budget control
• Ensure dependencies and cross-business impacts are surfaced and understood
• Support budget setting and financial planning.
What does this mean for you?
Everything we do should support our underlying business foundations, delivery of our Strategic Priorities or the delivery of our Strategy Enablers. Any projects you initiate must follow the process below:
Risk Framework
What is it?
Risk management involves successfully managing Aster’s business in all situations. The process includes several steps: identifying, assessing, planning, and implementing measures to mitigate threats and maximise opportunities. Aster’s risk management policy, risk framework, and guidance serve as tools to help us do that effectively.
What is the purpose?
The Risk Framework outlines how we identify, assess, and manage risk. It also covers reporting and scrutiny of risk management actions. Effective monitoring of risk management is crucial for our governance and this framework should be read alongside the Governance, Compliance, and Corporate Performance Frameworks.
The purpose of the Risk Framework is to ensure a structured and consistent approach. It enables effective monitoring of our risk profile and exposure, providing insight to support decision-making and understand our likely future performance. Risks identified through the risk management process should be considered in conjunction with our key performance measures and within the context of the sector’s challenging operating environment.
It is supported by a Risk Management Policy and Risk Management Guidance.
What does this mean for you?
All colleagues are responsible for accepting and implementing the risk management process. This includes understanding Aster’s risk appetite.
You should make decisions that respond to risk in your day-to-day work, sharing the commitment to risk management. You must take responsibility for your actions and be accountable for the outcomes. If you encounter inefficient, unnecessary, or unworkable controls, you should raise concerns with your leader.
It is also your responsibility to report risk issues and near-miss incidents to your leader. If you are designated as owner of any specific operational or strategic risks, or owner of controls within a risk management plan, you must follow the risk framework to assess and review these, seeking and providing assurance over the management of the risk.
Riskmanagementcan:
Compliance Framework
What is it?
The Compliance Framework defines how we identify, assess, and manage legal, regulatory, and contract obligations. It also outlines our approach for gaining assurance, reporting on compliance, and scrutinising compliance management actions. It is supported by a Compliance Management Guidance.
What is the purpose?
The Compliance Framework and its associated arrangements serve the following purposes:
Assurance
Coordinated programmes
Identifying weaknesses
Role clarity Clear improvement plans
Proportionate resources
Reliable system Harmonisation
It ensures timely, credible, evidence-based compliance with our obligations. This is balanced across the assurance model.
It coordinates assurance activities, ensuring alignment with business needs and support.
The framework helps identify areas of weakness, providing clarity for creating improvement plans.
Improvement plans have clear actions, ownership, and oversight.
Everyone understands their role under the Compliance Framework, which aims to protect customers, colleagues, homes, and business health.
Resources and assurance activities are proportionate to risks and consequences related to non-compliance or internal control breakdowns.
We maintain a reliable, systemic, group-wide internal control system with confidence in its effectiveness.
Activities align with related frameworks under the ‘Governance, Risk, Compliance, and Assurance Framework’ (GRCA) umbrella.
What does this mean for you?
You must:
• Understand, accept, and implement the compliance management process
• Make appropriate decisions, sharing a commitment to proactive compliance management
• Take responsibility for your actions and be accountable for the outcomes
• Raise concerns about inefficient, unnecessary, or unworkable controls with your leader
• Report non-compliance events and near-miss incidents to your leader.
Compliance Incident Management
In the event of a compliance incident, we will reassure enforcement bodies that we understand how it occurred through responsive and robust investigation. We’ll also outline the improvements we’ll make. Any incident or situation that might indicate Aster isn’t meeting a compliance obligation must be managed according to the Regulatory Notification Policy and Arrangements.
Sometimes, we’ll need to communicate with regulators beyond our internal reporting. The policy clarifies designated leads and broader considerations. The Regulator of Social Housing expects us to identify compliance issues ourselves and take effective action to resolve them. Transparency is crucial.
Failing to address compliance issues can impact our relationship with the regulator, governance rating, and long-term strategy. For concerns related to potentially illegal, corrupt, improper, unsafe, or unethical conduct, refer to the Probity & Integrity Policy and Speak Up Procedure for reporting.
Policy Framework
What is it?
The Policy Methodology outlines the principles and processes for developing and reviewing policies at Aster. It ensures successful policy implementation, including through effective operating procedures. A policy is a formal statement that describes Aster’s approach on a specific topic. It provides guidance to colleagues on how to handle situations, sets boundaries, and may offer alternative options. Policies serve as guide rails, enabling Aster colleagues to align with the shared vision and values, ensuring consistent and desirable outcomes.
Policies set out principles that:
• Ensure compliance with legal and regulatory requirements
• Manage identified risks effectively
• Translate complex specialisms into accessible instructions
• Help with decision making.
A policy is not a procedure! Procedures are operating manuals which contain the practical information and steps that are taken to implement a policy. They describe how and why things are done and should contain enough detail to enable a good understanding of the end-to-end process.
What is the purpose?
Using a standardised approach to policy development will ensure Aster’s policies are reviewed, developed, approved, implemented and monitored consistently across the organisation.
The methodology also helps underpin Aster’s four cornerstones of good governance and assurance. Aster’s policies play a crucial role in achieving the second cornerstone. They help manage risks, ensure compliance, and support our strategic goals. Policies developed using the methodology will:
• Align with Aster’s strategy and priorities while safeguarding long-term business health
• Adhere to relevant regulations and best practices
• Have been informed by customer voice
• Be flexible to address diverse needs
• Be clear, accessible, and easy to understand
• Involve effective consultation with stakeholders
• Be monitored for effective implementation and ongoing suitability
• Typically follow standardised review cycles, unless exceptions apply.
What does this mean for you?
If you are involved in policy work, then you need to follow the guidance in the Policy Methodology This involves a seven-stage process taking approximately eight weeks:
Stage 1 Plan
Stage 2 Research and analysis
Stage 3 Design and draft
Stage 4 Consult
Stage 5 Approve
Stage 6 Implement
Stage 7 Monitoring
The Policy team can provide help and guidance at policy@aster.co.uk.
Corporate Performance Framework
What is it?
The Corporate Performance Framework outlines Aster’s approach to reporting and scrutinising business performance, focusing on areas that are considered business critical, and therefore posing the greatest risk, to the business. The effective monitoring of our corporate performance is an integral part of our governance, and this should be read in conjunction with both the Risk and Compliance Frameworks.
What is the purpose?
The purpose of the Corporate Performance Framework, and the measures contained within it, is to enable timely monitoring and scrutiny as to how we are performing as a business. The measures set out within this framework were developed alongside the identification of our key risks and consideration of the wider operating environment. Key principles:
• Focus on business-critical performance: Measures contained within this framework are intended to monitor our performance against things that could critically impact our business and/or financial health, particularly recognising our financial, compliance and regulatory requirements and recognised risks
• Visibility of wider performance environment: Other performance reporting elements that sit within the framework include Operational Performance Indicators (OPIs), Strategic Priority measures and Tenant Satisfaction Measures (TSMs).
• Targets and tolerances: All measures have risk-based targets and tolerances set by leadership teams, which enables escalation and the identification of appropriate mitigations
• Clearly defined roles and responsibilities: The framework captures the performance reporting structure, the direction of assurance and escalation, and the roles and responsibilities linked to data quality, integrity, assurance and controls.
What does this mean for you?
Data teams and Business intelligence, insight and reporting specialists are spread across the business, supporting the performance reporting process in some way. Specialist knowledge and in-depth understanding of data and processes allows for detailed scrutiny and timely management information to help the business identify changing risks.
It is your, and everyone’s role to enable accurate, robust, and reliable performance reporting. It is everyone’s responsibility to critically evaluate the performance information they receive and provide appropriate onwards assurance (including escalation, where appropriate).
Escalation and assurance
Business critical KPIs and narrative reports
OBs (and committees) and EB
Operational performance indicators and entity specific performance
Management information
Leadership teams
Internal Control Key Principles
What is it and what is the purpose?
Internal control refers to the mechanisms, rules, and processes used to ensure the achievement of organisational objectives, compliance with law and regulations relevant to the nature of the business and to ensure the integrity of financial and accounting information. In doing so, a well-designed control framework will in turn promote accountability and efficiency where the need for control is understood.
Our internal controls include the frameworks summarised in this document but also include:
• Review and approval authorisations, with clearly defined roles to ensure accountability
• Accurate and complete records of financial transactions and other relevant information through routine reconciliation’s
• IT system change management processes and audit logs
• Segregation of duties including separate stages related to purchase order request, authorisation and payment
• Automated or manual approaches and work flows, recognising well thought through technology-based controls enhance accuracy and efficiency
• Management oversight of the activity and quality assurance processes.
Control frameworks feature inter-related components of these elements, with an overarching need to consider the attitudes, integrity and competence of colleagues in adhering to the requirements of the control framework.
What does this mean for you?
Everyone’s role is to comply with the internal controls in place around any process or activity they are engaged with. When designing new processes or altering existing, it’s important to consider the controls and safeguards that should be in place and to thoroughly test their operation.
You should raise a concern if you feel an internal control has been compromised, including where this provides an opportunity for fraud.
Fraud Triangle Opportunity
Rationalisation
Incentive
The fraud triangle is commonly used to explain the reason behind an individual’s decision to commit fraud. The fraud triangle outlines three components that contribute to increasing the risk of fraud: (1) opportunity, (2) incentive, and (3) rationalisation.
Independent Assurance
What is it and what is the purpose?
The benefits of identifying and managing strategic and operational risks, within the boundaries of the organisation’s risk appetite, are widely recognised. When sound risk management practices are in place a key question is for all organisations is: How do we get assurance regarding the effectiveness of these controls and mitigations?
Provision of assurance is an objective examination of evidence for the purpose of providing an independent assessment on governance, risk management and control processes for the organisation. When properly commissioned and scoped, use of an independent organisation can enable access to skillsets that can be used to gain assurance on risk mitigations, and with no connection to the operational management of the function, can provide a strong signal that reports are trustworthy
The role of internal audit
Internal audits play a critical role in assessing our internal controls. The approach taken is one of ensuring that the control is adequately designed to ensure compliance with the requirement and to mitigate any risk exposure. Testing is undertaken to ensure that control activities are operating as intended and that there is no movement away from determined processes.
At Aster, the internal audit team is in house, in that Internal Audit colleagues are employed by Aster, but are independent from any operational activities with the Director of Audit having a direct reporting line to the chair of the Group Risk and Assurance Committee. These colleagues work to internationally recognised professional standards.
An internal audit plan provides a forward plan of assurances against key risks on the Group’s risk register. This is reviewed routinely with management to adjust to changing assurance needs and priorities.
Other sources of independent assurance
There are many different sources of independent assurance available to the Group in addition to or instead of internal audit. In some cases, there are mandated requirements such as external audit, Homes England audits, Health and Safety Executive or regulatory inspections. There will be occasions such as these where the scope will be determined by the third-party, rather than Aster.
Commissioning independent assurance
Delegations IA14 and IA15 guide on the authorities and process for commissioning independent assurance from third-party providers. This includes for the Director of Audit to approve the scope and receive the resulting report. This ensures the activity is co-ordinated and complements wider sources of assurance and ensures the quality meets expected practices.
What does this mean for you?
When there is an internal audit relevant to your business area, you may need to provide records and information to the audit team. You may be asked to meet with the auditor so they can gain an understanding of your work and the processes you follow. You must always be transparent, open and honest during any audit or independent assurance process.
Aster’s Assurance Model
What is it and what is the purpose?
Aster’s approach to assurance has its roots in a model called the ‘3 Lines of assurance’ (Institute of Internal Audit 2020). This model helps us to understand different sources of assurance. While you may hear reference to the ‘1st , 2nd and 3rd Line’, within Aster we think of these different sources as:
Independent assurance
Internal audit
External audit
Regulatory grading
Provides objective and independent challenge to the levels of assurance provided by operational management and oversight functions. Assesses internal controls to enable business improvement.
Independent reviews
Corporate oversight
Oversight functions
Functions who also set direction, define policy and/or monitor business wIde, providing an overview and oversight of business processes. Governing bodies who receive and scrutinise assurance from management and oversight functions
Governing body scrutiny
Management reporting and oversight
Day to day management oversight of processes and business activities, implementation of controls and reporting on performance and outcomes.
Management oversight
Team processes and reporting
Independent assurance
This comes from functions or bodies that are independent from business operations or the Group itself and provide independent challenge and objectivity. Internal audit provide a significant proportion of this assurance and have a role in the commissioning of independent reviews and the consideration of the resultant assurance reports. Other sources of Independent Assurance include External Audit, Regulatory inspections and gradings, or assessments leading to accreditation.
Corporate oversight
This is provided by the functions that oversee, set policy and internal control arrangements and/or monitor in some way, and therefore providing an overview and oversight of business processes and risks. These roles would have expertise to support, monitor and challenge. Corporate Oversight also comes from the scrutiny of governing bodies and their consideration of management information presented to them.
Management reporting and oversight
Day to day, assurance comes from management oversight of processes and business activities, the implementation and monitoring of management controls and reporting through the management structure on performance and outcomes.
Aster’s Assurance Principles
Assurance with:
Assurance provides an objective view that cannot be influenced
Reduced duplication of effort. A proportionate approach which maximises the effective use of resources.
Using an integrated approach to obtaining assurance where stakeholders understand their role.
Assurance is given due regard with senior level commitment; governance and reporting systems, trust, transparency and visibility.
A view discussed and agreed between stakeholders and assurance providers.
Share findings, agree actions, escalate concerns where appropriate, implement required actions and measure effectiveness.
Assurance or reassurance?
Assurance happens when someone tells you what is happening and provides evidence of how it was done. Reassurance happens when someone tells you all is well, and you believe there’s no need for further checks..
Example:
Are we keeping a record of these data inputting errors?
Reassurance answer: Yes, we are.
Assurance answer: Yes, here is the detailed record, along with analysis and reporting to the data owner.
What does this mean for you?
Assurance processes happen every day. Teams and leadership will use assurance and reassurance differentially and in context. In some matters, being reassured is enough, while in others a greater level of assurance is required.
Any information you present as assurance must be credible, unfiltered and based in evidence and fact. When you receive information presented as assurance, ask yourself the ‘How do I know?’ question, including:
• Do we really know what we think we know?
• Where does the assurance come from?
• How reliable is this assurance?
• What is this assurance telling me?
• Is the assurance proportionate to the level of risk?
You should engage openly and transparently with any corporate oversight or independent assurance activity.
