⬅️PROCEDURES

CP2: Corporate Governance

This procedure describes how Breheny Civil Engineering Ltd manages IMS governance, corporate risk and opportunity management, energy management, audits and management system reviews.

18
Sections
54
Key points

In this procedure

  1. 1Corporate Governance3 parts

    1.1–1.2 Purpose and Scope — What CP2 covers

    This procedure sets out the corporate governance framework Breheny Civil Engineering (BCE) uses to plan, run, monitor and improve its Integrated Management System (IMS). It consolidates risk management, audits, management review and energy management into a single, ISO-aligned (and ISO 31000-informed) structure. CP2: Corporate Governance applies across all activities, locations and projects and to everyone from the Board down to employees and contractors whose activities affect IMS performance.

    Key points

    • Pulls risk, audits, management review and energy management into one governance procedure aligned to the IMS standards and ISO 31000.
    • Applies to all BCE activities, locations and projects, and to Board, Directors, Managers, Risk Owners, SHEQ/ESG and contractors who affect IMS performance.
    • Provides the corporate governance control through which top management directs and reviews the IMS.
    From the source document(9 clauses)

    1Corporate Governance

    No text in source for this clause.

    1.1Purpose and Scope

    No text in source for this clause.

    1.1.1Purpose

    This procedure establishes the governance framework used by Breheny Civil Engineering Ltd (BCE) to plan, implement, monitor, review, and continually improve the Company’s Integrated Management System (IMS).

    It consolidates corporate requirements for:

    • Risk management
    • Management system audits
    • Management reviews
    • Energy management

    within a unified structure. This ensures governance activities are consistent, aligned, and riskbased, enabling top management to exercise effective oversight of organisational performance, compliance, objectives, and improvement opportunities.

    This procedure is the corporate governance control through which top management directs and reviews these arrangements.

    1.1.2Standards Alignment

    This procedure supports compliance with the Management System Standards identified in CP1 Cl.1.3

    Additionally, this procedure also adopts the principles and framework of ISO 31000 for risk management.

    Together these arrangements provide assurance that the IMS remains:

    • Suitable
    • Adequate
    • Effective

    and aligned with the company’s strategic direction, business plan, decarbonisation objectives, and stakeholder expectations

    1.1.3Relationship to the IMS Manual

    The structure, scope and core requirements of the IMS are defined in CP1 – Integrated Management System Manual.

    This procedure defines the corporate governance arrangements through which the IMS is directed, monitored, reviewed and continually improved.

    1.2Scope

    No text in source for this clause.

    1.2.1Organisational Scope

    This procedure applies to all activities, functions, locations, projects, and organisational levels under the control of the Company.

    1.2.2Governance Coverage

    This procedure covers the corporate governance arrangements for:

    • Identification, assessment, treatment, monitoring, and review of risks and opportunities at corporate and project level
    • Establishment and application of the risk appetite framework including escalation of risks exceeding defined risk criteria and appetite thresholds
    • Planning, delivery, reporting and followup of internal and external IMS audits
    • Conduct and outputs of formal Management Reviews, including performance evaluation, compliance status, objectives, resource adequacy, and continual improvement
    • Governance and oversight of the Energy Management System (EnMS), including energy performance, objectives, targets, reviews, and audits

    1.2.3This procedure applies to:

    • Board of Directors
    • Directors, Managers, Supervisors, and designated Risk Owners
    • SHEQ and ESG functions
    • Employees, contractors, and relevant interested parties where their activities influence IMS performance

    1.3 IMS Governance Framework — How oversight works

    BCE runs the IMS as a single coordinated framework covering quality, health & safety, environment and energy. The Board and Senior Management set strategic direction and retain oversight; Directors implement governance and monitor performance; the Head of ESG coordinates implementation, monitoring and reporting. IMS objectives () are aligned with the business plan, risk appetite and decarbonisation commitments, and performance is monitored through indicators, audits, inspections, reviews and reporting — with corporate and project risk, audits, management review and the EnMS operating as one integrated system.

    Key points

    • IMS is one coordinated system across quality, H&S, environment and energy — not separate silos.
    • Board and Top Management hold ultimate accountability; the Head of ESG coordinates day-to-day implementation and reporting.
    • Objectives, risk, compliance and performance are monitored through linked indicators, audits, reviews and reporting ().
    From the source document(1 clause)

    1.3Integrated Management System (IMS) Governance Framework

    The Company operates an IMS governed through a structured framework that provides clear leadership, accountability, assurance, and continual improvement across quality, health and safety, environmental, and energy management.

    The IMS governance framework ensures that:

    • IMS objectives (recorded on CP2-F12) are aligned with the company’s strategic direction, business plan, risk appetite and decarbonisation commitments
    • Risks and opportunities are systematically identified, assessed, controlled, monitored and reviewed at both corporate and project levels
    • Legal, regulatory, contractual and other compliance obligations are identified, evaluated and managed through the IMS
    • Performance is monitored and evaluated through defined indicators, audits, inspections, reviews and reporting mechanisms
    • Top management retains effective oversight of IMS performance, resource adequacy and improvement priorities

    Governance of the IMS is achieved through the integration of:

    • Corporate and project risk management
    • Internal and external audit programmes
    • Management review processes
    • Energy management system (EnMS) planning, performance evaluation and review

    These elements operate as a single, coordinated system rather than standalone disciplines, enabling consistent decisionmaking, proportionate control, and efficient use of resources.

    Roles, responsibilities and authorities for IMS governance are defined within this procedure and supporting documents, ensuring accountability at all levels of the organisation. The Board of Directors and Senior Management provide strategic direction and oversight of the IMS, while Directors and management are responsible for implementing governance arrangements and monitoring performance.

    The Company’s Directors acting as Top Management retain overall accountability for the effectiveness of the Integrated Management System (IMS). The Head of ESG is responsible for coordinating implementation, monitoring, and reporting activities.

    The IMS governance framework supports continual improvement through the review of audit results, performance data, risk reviews and management review outputs, including evaluation of energy performance, Significant Energy Uses (SEUs), Energy Performance Indicators (EnPIs) and progress against energy objectives.

    Documents you'll need

    1.4 Relationship to Other Documents

    CP2: Corporate Governance sits above operational and discipline procedures — it does not replace them. CP1: IMSM (IMS Manual) defines IMS structure and core requirements; supporting procedures define operational controls and discipline-specific processes; CP2: Corporate Governance provides the corporate governance layer that ensures alignment, consistency and top-management oversight across all of them.

    Key points

    From the source document(1 clause)

    1.4Relationship to Other IMS Documents

    This procedure defines the overarching governance framework for the IMS. It establishes how risk management, audit, management review, and energy management are directed, coordinated, monitored, and reviewed at a corporate level.

    CP2 does not replace operational or disciplinespecific procedures. Instead, it provides the governance structure within which those procedures operate, ensuring alignment, consistency, and effective topmanagement oversight of the IMS.

    The structure and requirements of the IMS are defined within CP1 – Integrated Management System Manual, while operational controls and discipline-specific processes are defined within supporting procedures.

  2. 2Corporate Risk and Opportunity Management10 parts

    2.1–2.3 Risk Management — Why and how we do it

    BCE treats risk management as a core business tool supporting strategy, resilience and informed decision-making. The Risk Management Strategy sets the method for identifying, assessing and managing risks and opportunities and applies the Company''s Risk Appetite Framework. The process is deliberately efficient: identify, assess, manage and review. Day-to-day risk is managed through the Corporate Risk Register () and project ROMPs (), overseen by the Board with support from the Head of ESG. Benefits include proportionate response, clearer decisions, organisational resilience and supported compliance and financial disclosure.

    Key points

    • Risk management is a core governance tool aligned to ISO principles and the BCE Risk Appetite Framework.
    • Five principal risk types are managed through the Corporate Risk Register () and project ROMPs ().
    • Benefits: proportionate response, clearer decisions, resilience, and support for compliance and financial reporting.
    From the source document(5 clauses)

    2Corporate Risk and Opportunity Management

    No text in source for this clause.

    2.1Introduction

    The Company recognises its obligation to address both internal and external risks as an integral aspect of sound corporate governance. The Company is committed to integrating robust risk management practices that support the achievement of its strategic and operational objectives.

    The Company’s Risk Management Strategy establishes our methodology for identifying, assessing and managing risks and opportunities and defines the application of the Company’s Risk Appetite Framework. Through this approach, risks are systematically identified and managed so that they are either mitigated or reduced to acceptable levels.

    This structured approach safeguards the organisation and promotes effective informed decision-making. It also recognises that proactive risk management plays a vital role in the successful execution of the Company’s Business Plan. To sustain attention on valuable, high-quality outcomes, our risk management process is intentionally designed to be efficient and straightforward.

    Effective organisational risk management strengthens resilience, enabling the Company to respond effectively to uncertainty, absorb disruption, and continue operating in challenging conditions.

    2.2Objectives of the strategy

    The key objectives of this strategy are to:

    • Integrate risk management as a core business tool for identifying both risks and opportunities
    • Build organisational resilience to operate successfully in uncertain or changing conditions
    • Promote understanding of risk management and encourage staff engagement in risk identification and control
    • Support compliance with governance standards and enable accurate disclosure within the Company’s financial reporting

    2.3Risk Management

    No text in source for this clause.

    2.3.1BCE Risk Management Process

    BCE has established a structured risk management framework supported by a defined Risk Appetite Framework.

    Five principal risk types have been identified, each supported by a Risk Statement and associated tolerance metrics. These are detailed within the table in Section 2.6.

    The Company’s Risk Appetite underpins all business activities and must be considered when reviewing new business opportunities, projects, or strategic decisions.

    Risk is managed on a day-to-day basis through active monitoring and review of the Corporate Risk Register (CP2-F01), together with the project Risk and Opportunity Management Plans (ROMPs) (CP4-F01), where appropriate.

    Corporate Risk is overseen by the Board of Directors, supported by the Head of ESG.

    The detailed processes supporting the Company’s Risk Management framework are set out in the following sections**.**

    Documents you'll need

    2.4–2.5 Risk Appetite — what the company will accept

    Risk appetite is the amount and type of risk BCE is prepared to accept to achieve its objectives (per ISO 31100). The framework guides decisions for both threats (tolerable exposure) and opportunities (acceptable risk to realise benefits), informed by potential financial, reputational, operational and strategic consequences. BCE maintains minimal appetite for anything that would adversely impact strategic objectives. Five appetite levels are used — Averse, Cautious, Moderate, Open, Seeking — with risk statements describing attitude per risk type and tolerance metrics setting measurable limits. Exposure exceeding appetite must be escalated.

    Key points

    • Five appetite levels: Averse, Cautious, Moderate, Open, Seeking — applied per risk type.
    • Appetite balances financial, reputational, operational and strategic consequences against opportunity value.
    • Any exposure beyond the defined appetite triggers escalation under this procedure.
    From the source document(3 clauses)

    2.4Risk Appetite

    No text in source for this clause.

    2.4.1Definition

    Risk appetite is defined in ISO 31100 Risk Management – Code of Practice as:

    “The amount or type of risk that an organisation is prepared to tolerate in order to achieve its strategic aims and objectives”

    • A Risk Appetite Framework provides direction regarding the level and type of risk that the Company is prepared to accept, supporting informed decisionmaking and prioritisation.
    • In relation to threats, risk appetite defines the level of exposure that the Company considers tolerable should a risk materialise.
    • In relation to opportunities, it defines how much risk the Company is prepared to accept in order to realise the potential benefits.
    • Risk appetite is informed by an assessment of the potential financial, reputational, operational, and strategic consequences of risk events, balanced against the benefits or opportunities that may arise.
    • As a guiding principle, the Company maintains minimal appetite for risks in relation to any activity which could adversely impact the achievement of its strategic objectives.
    • Risk Statements describe the Company’s attitude towards each risk type, while tolerance metrics provide measurable indicators to determine whether risks remain within acceptable limits.

    2.5Benefits

    Defining an organisation’s risk appetite provides several benefits:

    • Ensures the Company only undertakes risks that are consistent with its strategic objectives and tolerance levels
    • Ensures the risks accepted are proportionate to the opportunity or reward available
    • Provides a structured framework for decision-making on significant business matters
    • Assists employees in determining which risks are acceptable and which require mitigation or escalation
    • Ensures that the response to risk is proportionate, and helps to avoid both excessive caution and uncontrolled exposure
    • Establishes clear triggers for reporting and escalation when the Company’s risk exposure exceeds defined appetite levels.

    2.6 Risk Types and Appetite Statements

    Five principal risk types are defined — Strategic, Operational, Project, Legal & Regulatory Compliance, and Financial — each with a written appetite statement and tolerance metrics. Strategic and Operational risks are managed with a Cautious approach; Project risks Open (controlled risk-taking is needed to win and deliver work); Legal & Regulatory Compliance is Averse (non-compliance is unacceptable); Financial is Moderate (protecting cash flow, stability and client/partner confidence). A visual matrix summarises appetite by risk type, and the colour key shows relative position only — it is not a risk severity rating.

    Key points

    • Five risk types, each with a written appetite statement and tolerance metrics.
    • Stance by type: Strategic Cautious, Operational Cautious, Project Open, Legal & Reg Averse, Financial Moderate.
    • The appetite matrix and colour key show appetite position, not risk severity.
    From the source document(6 clauses)

    2.6Risk Types & Appetite

    No text in source for this clause.

    2.6.1Risk Types

    Five principal risk types have been identified, each with an associated risk appetite as defined in the table below.

    | Risk Type | | | --- | --- | | Strategic | Risks that may impact the achievement of the Company’s strategic objectives and long-term business aspirations | | Operational | Risks arising in failures in people, processes, systems, or external events that may affect the Company’s ability to deliver its operations. | | Project | Risks associated with the successful delivery of project objectives, including programme, cost, quality, and commercial outcomes | | Legal and Regulatory Compliance | Risks relating to failure to meet legal, statutory, regulatory, or contractual obligations | | Financial | Risk affecting the Company’s financial performance, including funding, cash flow, profitability, and income streams |

    2.6.2Risk Appetite Scale

    The Company defines its risk appetite using the following categories:

    | Risk Appetite | Descriptions | | --- | --- | | Averse | The Company prioritises risk avoidance and seeks to eliminate or minimise uncertainty wherever practicable, even at the expense of potential opportunities. Only the safest, most predictable options are considered. | | Cautious | The Company has a low tolerance for risk and favours safe, low-risk options that support stable outcomes. While some risks may be accepted, decisions shall focus on minimising exposure and ensuring compliance. | | Moderate | The Company is willing to accept a controlled level of risk in pursuit of its objectives but remains risk aware. It balances risk with reward, selecting options that provide reasonable benefits while ensuring that exposure remains within defined tolerance levels. | | Open | The Company is comfortable with uncertainty and evaluates all available options to determine the most effective path forward. Risk-taking is permitted when it aligns with strategic objectives and delivers measurable value or competitive advantage. | | Seeking | The Company actively pursues innovation and high-reward opportunities, even where there is significant inherent risk. Higher risks are accepted in pursuit of long-term value, transformation, or industry leadership. |

    2.6.3Risk Appetite Matrix

    Where risk exposure exceeds the defined appetite, escalation in accordance with this procedure is required.

    2.6.3.1Risk and Opportunity Appetite by Risk Type

    | Risk Type | Risk or Opportunity | Visual Indicator | | --- | --- | --- | | Strategic | Threat | | | Strategic | Opportunity | | | Operational | Threat | | | Project | Threat | | | Legal & Regulatory Compliance | Threat | | | Financial | Threat | |

    This table provides a visual summary of the Company’s risk appetite as defined in CP2 clause 4.3.1

    | Key | | | | --- | --- | --- | | Colour | Risk Appetite | Summary | | | Averse | Avoidance of risk wherever practicable | | | Cautious | Preference for low-risk, controlled approaches | | | Moderate | Balanced approach between risk and reward | | | Open | Willingness to consider a wide range of options | | | Seeking | Active pursuit of high-risk, high-reward opportunities |

    Note: Colours indicate relative risk appetite position only and do not represent risk ratings or risk severity.

    2.6.4Risk Appetite Statements

    | Risk Appetite Statement | | | --- | --- | | Strategic | The Company adopts a cautious approach, seeking to manage and reduce risk by diversifying our work types, client base, and market sectors while supporting sustainable growth. | | Operational | The Company adopts a cautious approach, aiming to avoid loss-making activities through robust planning, controls and assurance processes. | | Project | The Company adopts an open approach, recognising that controlled risk-taking is necessary to remain competitive and deliver successful outcomes. Risks are actively managed, and opportunities are maximised in line with commercial and delivery objectives. | | Legal & Regulatory Compliance | The Company adopts an averse approach. Non-compliance is not acceptable, and robust systems are in place to ensure obligations are identified, understood, and met. Residual risk is managed through monitoring, assurance, and continual improvement. | | Financial | The Company adopts a moderate approach, recognising the importance of maintaining strong cash flow, financial stability, and confidence among clients, supply chain partners, and funders. |

    2.10 Risk Management Process — step-by-step

    BCE follows a structured ISO-aligned cycle: 1) Identify risks and opportunities; 2) Analyse using appropriate methodologies and existing controls; 3) Evaluate against the 5x5 matrix; 4) Manage using one of the 4Ts — Tolerate, Treat, Transfer or Terminate; 5) Monitor and review through the lifecycle. Each risk has an owner responsible for monitoring, coordinating treatment, keeping it within limits and escalating when needed. Oversight sits with Delivery Managers, Project Delivery Teams and Directors.

    Key points

    • Five-stage cycle: Identify → Analyse → Evaluate → Manage (4Ts) → Monitor & Review.
    • Treatment options are Tolerate, Treat, Transfer, Terminate.
    • Every risk has a named owner accountable for monitoring, treatment and escalation.
    From the source document(1 clause)

    2.10Risk Management Process

    The Company applies a structured risk management process comprising the following stages:

    • Identification of risks and opportunities
    • Evaluation using appropriate methodologies
    • Managing risks through defined strategies (Tolerate, Treat, Transfer, Terminate)
    • Ongoing monitoring and review

    Oversight is provided by Delivery Managers, Project Delivery Teams, and Directors.

    2.7–2.9 Corporate vs Project Risk — who handles what

    Risk is managed at two levels. Corporate risk (strategic, business-wide) is overseen by the Board, with the Corporate Risk Register () maintained and reviewed annually by the JMDs and Head of ESG; risks exceeding appetite are escalated to the Board, and a formal review feeds the IMS Management Review. Project risk runs through ROMPs () — identified pre-contract under CP4: Pre-Contracts and maintained during delivery under CP5: Contract by the Delivery Team. High and Very High project risks are escalated to the JMDs and reviewed for corporate impact, with further escalation to the Board where required.

    Key points

    • Corporate Risk Register () is reviewed annually by JMDs and Head of ESG; escalation to Board above appetite.
    • Project risk is managed via ROMPs () — CP4: Pre-Contracts pre-contract, CP5: Contract during delivery.
    • High and Very High project risks are escalated to JMDs and, where needed, to the Board.
    From the source document(3 clauses)

    2.7Corporate and Project Risk Management

    Risk is managed at both corporate and project levels to ensure the Company can effectively identify, assess, and respond to risks and opportunities across all areas of its operations.

    This dual approach reflects the different scope and nature of risks:

    • Corporate Level: Focuses on strategic risks that may impact the overall business.
    • Project Level: Focuses on risks and opportunities associated with the delivery of individual projects.

    Corporate risk is overseen by the Board of Directors.

    Project risks and opportunities are managed by the estimating, planning, commercial and project delivery teams throughout the project lifecycle, from pre-construction through to practical completion. This is led by the Directors.

    2.8Corporate Risk Management

    Corporate risk is managed through a structured governance framework led by the Board of Directors.

    The Corporate Risk Register (CP2-F01) is maintained and reviewed annually by the Joint Managing Directors (JMDs), and the Head of ESG.

    Risks exceeding the Company’s defined risk appetite or agreed escalation threshold are escalated to the Board for review and decision.

    A formal review of corporate risk is undertaken as part of the IMS Management Review process, supporting continual improvement and ensuring alignment with the Company’s strategic objectives.

    2.9Project Risk Management

    Project-level risk management includes:

    • Development and maintenance of ROMPs, completed using form CP4-F01
    • Identification of risks and opportunities during pre-contract and planning stages
    • Evaluation and treatment of risks using structured, risk-based approaches
    • Escalation of significant risks to corporate level where appropriate

    Each project maintains a ROMP, with risks and opportunities identified, evaluated, and managed throughout the project lifecycle.

    The pre-contract ROMP is developed in accordance with CP4 (Pre-contracts). During delivery, the ROMP is maintained by the Delivery Team in accordance with CP5 (Contract).

    High and Very High risks are escalated to the JMDs and reviewed for potential corporate impact, with further escalation to the Board where required.

    Documents you'll need

    2.11 Identifying Risks and Opportunities

    Risk identification is the first stage and starts from a clear understanding of objectives. Risks are considered across financial, strategic, operational, reputational, technological and stakeholder categories, with opportunities considered alongside threats. Identification uses SWOT analysis, risk workshops, historical data, scenario planning, incident reviews and project ROMPs (covering financial, operational, reputational, legal, safety and environmental risks).

    Key points

    • Start from a clear view of objectives, then consider all risk categories — including opportunities.
    • Methods include SWOT, workshops, historical data, scenario planning and incident reviews.
    • Project ROMPs cover financial, operational, reputational, legal, safety and environmental risks.
    From the source document(1 clause)

    2.11Risk and Opportunity Identification

    The identification of risks and opportunities is the first stage of the process and focusses on determining factors that may affect the achievement of strategic and operational objectives.

    This activity is undertaken by the relevant management teams responsible for delivering the objectives outlined in the business plan.

    Before identifying risks, the group must have a clear understanding of their objectives. Risks come in many forms, and consideration shall be given to a wide range of risk types, including:

    • Financial
    • Strategic
    • Operational
    • Reputational
    • Technological
    • Stakeholder risks.

    Opportunities associated with identified risks are also considered to support informed evaluation and decision-making.

    The Company identifies risks and opportunities through a range of methods, including:

    • Strength Weakness Opportunity and Threat (SWOT) analysis
    • Risk workshops
    • Historical data
    • Scenario planning
    • Incident reviews
    • Project ROMPs (covering financial, operational, reputational, legal, safety and environmental risks)

    2.13–2.16 Evaluation — the 5x5 matrix and scoring

    Risks are evaluated on a 5x5 matrix of Likelihood (Rare → Almost Certain, 1–5) and Impact (Negligible → Critical, 1–5). The product gives the score and rating band: 15–25 Very High, 8–12 High, 5–6 Moderate, 3–4 Low, 1–2 Very Low. Very High, High and Moderate risks must be Terminated, Transferred or Treated; Low and Very Low are Tolerated. At project level, ROMPs apply the same risk-based approach, weighing organisational context, interested-party expectations, legal and compliance obligations and potential impact on quality, environmental, energy and OH&S performance. Evaluation focuses on credible impact and the effectiveness of existing controls.

    Key points

    • 5x5 matrix: Likelihood × Impact (1–5 each) gives the score and rating.
    • Score bands: 15–25 Very High, 8–12 High, 5–6 Moderate, 3–4 Low, 1–2 Very Low.
    • Very High/High/Moderate need Terminate/Transfer/Treat; Low/Very Low can be Tolerated.
    From the source document(4 clauses)

    2.13Risk and Opportunity Evaluation

    After risks and opportunities are identified, they shall be assessed. Risks and opportunities vary in magnitude and significance for the Company, and it is not feasible to address each one equally. The evaluation stage aims to distinguish which risks and opportunities require management and which only need monitoring.

    At corporate level, risks are evaluated using a 5x5 evaluation matrix (as the table below).

    • At project level, the ROMPs apply a structured, risk-based approach that considers;
    • Organisational context
    • Needs and expectations of interested parties
    • Legal and compliance obligations
    • Potential impact on quality, environmental performance, energy performance and occupational health and safety.

    Evaluation focuses on credible impact and the effectiveness of existing controls, ensuring that responses are proportionate to the level of risk.

    Risks are managed through appropriate treatment strategies, while opportunities are pursued where they support improved performance, compliance, or commercial outcomes.

    Risks and opportunities are reviewed throughout the lifecycle of activities and following change, ensuring continued suitability, effectiveness and continual improvement of the IMS.

    The outcome of evaluation determines whether risks are:

    • Accepted
    • Monitored
    • Escalated

    in accordance with the Company’s risk appetite.

    Both corporate and project-level approaches are approved within the IMS governance framework and are applied based on the scale, context and purpose of the risk.

    2.14Risk Rating

    Risk ratings determine the level of management attention, required actions, and escalation in accordance with the Company’s risk appetite framework.

    2.155x5 Matrix

    | | | Impact | | | | | | --- | --- | --- | --- | --- | --- | --- | | Likelihood | | Negligible | Minor | Moderate | Major | Critical | | | | 1 | 2 | 3 | 4 | 5 | | Almost Certain | 5 | Moderate (5) | High (10) | Very High (15) | Very High (20) | Very High (25) | | Likely | 4 | Low (4) | High (8) | High (12) | Very High (16) | Very High (20) | | Possible | 3 | Low (3) | Moderate (6) | High (9) | High (12) | Very High (15) | | Unlikely | 2 | Very Low (2) | Low | Moderate (6) | High (8) | High (10) | | Rare | 1 | Very Low (1) | Very Low (2) | Low (3) | Low (4) | Medium (5) |

    2.16Scoring

    | Risk Scores | Overall Risk Rating | Approach Options | | --- | --- | --- | | 15-25 | Very High Risk | Terminate, Transfer, Treat | | 8-12 | High Risk | Terminate, Transfer, Treat | | 5-6 | Moderate Risk | Terminate, Transfer, Treat | | 3-4 | Low Risk | Tolerate | | 1-2 | Very Low Risk | Tolerate |

    2.17–2.19 Risk Rating Definitions and Criteria

    Ratings define expected management action. Very High exceeds tolerance and requires immediate, comprehensive action and senior escalation. High requires prompt action and a comprehensive action plan, with escalation considered. Moderate requires action, an action plan and active monitoring. Low needs proportionate controls and periodic monitoring; Very Low is accepted with occasional review. Likelihood criteria range from Rare (<4% / less than once in 25 years) to Almost Certain (>95% / multiple times per year). Impact is rated across nine dimensions — Financial, OH&S, Environmental, Asset Loss, Business Continuity, Reputation, Corporate Objectives and Legal & Compliance — with defined thresholds at each level.

    Key points

    • Very High demands immediate senior-escalated action; Low/Very Low only need monitoring.
    • Likelihood is anchored by frequency and probability bands (Rare <4% → Almost Certain >95%).
    • Impact is rated across financial, OH&S, environmental, asset, continuity, reputation, objectives and legal dimensions.
    From the source document(3 clauses)

    2.17Risk Rating Definitions

    | Risk Rating | Description | | --- | --- | | Very High | This level exceeds the Company’s defined risk tolerance. The consequences of the risk materialising would have a critical impact on business continuity, reputation, or operational capability. Immediate and comprehensive action is required to eliminate or significantly reduce the risk.<br/>Escalation to senior management is required. | | High | The consequences of the risk materialising would be severe. Prompt action is required to reduce the risk, plus the development of a comprehensive action plan.<br/>Escalation shall be considered where appropriate. | | Moderate | The consequences of the risk materialising would have a noticeable impact on operations or delivery. Appropriate actions shall be implemented to reduce the risk, plus the development of an action plan and the risk must be actively monitored. | | Low | The consequences of the risk materialising would have a minor impact. No immediate action is required, however, proportionate controls shall be maintained and an action plan shall be actively considered. The risk shall be monitored periodically. | | Very Low | The Company accepts this risk and the impact would be insignificant. The status of the risk shall be reviewed occasionally. |

    2.18Risk Criteria - Likelihood

    | Likelihood<br/>Rating | Likelihood | Frequency | Indicative Probability Range | | --- | --- | --- | --- | | 5 | Almost Certain | Risk is expected to materialise multiple times over a 1-year period | >95% | | 4 | Likely | Risk is expected to materialise once in a 1-year period | 75-95% | | 3 | Possible | Risk is expected to materialise once in a 5-year period | 25-75% | | 2 | Unlikely | Risk is expected to materialise once in a 25-year period | 4-25% | | 1 | Rare | Risk is expected to materialise less often than once in a 25-year period | <4% |

    2.19Risk Criteria - Impact

    | Overall Impact Rating | Description | Financial Impact | Occupational Health & Safety | Environmental | Asset Loss | Business Continuity | Reputation and image | Corporate Objectives/Performance | Legal & Compliance | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | 1 | Very Low | £50k - £750K | No or only minor personal injury. First Aid needed, but no days lost | No impact | Little or no impact on assets | Interruption negligible; less than ½ day. Critical systems unavailable for less than one hour | Minor effects on external relations | Workaround required, within Company resources, to deliver objective. Up to 5% variation in achievement of targets. | No litigation, claims covered by workers compensation and less than deductible for property damage, no fine imposed on company or individuals | | 2 | Low | £750k -£1.5m | Minor injury, requiring medical treatment, limited lost time | Localised, short-term issue | Minor loss or damage to assets | Interruption inconvenient; ½ -1 day. Critical systems unavailable for several hours | Adverse media coverage with short term damage to reputation | Additional resources required or delay in achieving part of objective. Minor shortfall in several categories or major shortfall in one category 5 – 10 % variation in achievement of targets | Minor regulatory action possible, fine imposed on Company possible but unlikely, no fine imposed on individuals | | 3 | Moderate | £1.5m - £5m | Serious medical treatment, hospitalisation and multiple days lost | Moderate impact, requiring remediation | Major damage to assets | Interruption 1 day – 1 week Client dissatisfaction; Critical systems unavailable for up to 1 day | Local or community concern involving political involvement (e.g. formal ministerial correspondence),or stakeholder escalation | Major compromise in objectives. Major shortfall in several categories 10 – 25% variation in achievement of targets | Regulatory investigation, small fine imposed on company possible, no fine imposed on individuals | | 4 | High<br/>Will have a significant impact on the operations of the Company; will likely require market disclosure | >£5m | Single death, extensive injuries or long-term illness / injury. | Large-scale damage, regulatory intervention | Significant loss of assets | 1 week – 1-month Critical systems unavailable for 1 day or a series of prolonged outages. | Damage to reputation causing delays or interruptions to existing or planned projects | Elements of objective abandoned fail to meet needs of Client 25 – 50% variation in achievement of targets | Significant enforcement action, medium fine imposed on the Company, small fine imposed on individuals possible. | | 5 | Very High<br/>Severely impairs the ability of the Company to operate as a going concern | >£10m | Multiple deaths or permanent disabilities | Severe, irreversible environmental damage, major penalties | Complete loss of assets | Interruption more than 1 month. Critical systems unavailable for more than a day (at a crucial time) | Widespread negative community sentiment; withdrawal of public and/or political support for continued operations | Unable to deliver objective Widespread failure to meet Client needs more than 50% variation in achievement of targets | Major litigation, no settlement, maximum fine imposed on the Company, large fine imposed on individuals and potential imprisonment |

    2.20, 2.22 Roles & Responsibilities — who does what

    The Board approves the Risk Management Strategy, embeds risk in strategic decision-making, reviews effectiveness at least annually, ensures internal control and stress-tests the Business Plan. Directors (Contracts, Regional Commercial, Estimating) allocate resources, embed risk into planning and operations, maintain controls, monitor the corporate risk profile, apply appetite, report to the Board and escalate emerging risks. Managers and Supervisors handle risks in their area, communicate and escalate, and support controls. Risk Owners manage assigned risks over time, implement controls, update records, escalate breaches and consult stakeholders. All staff identify and report risks, comply with controls and build risk awareness day-to-day.

    Key points

    • Board: approve strategy, review effectiveness annually, ensure internal control, stress-test the Business Plan.
    • Directors resource, embed and report risk; Managers/Supervisors handle local risks and escalate.
    • Risk Owners are accountable for keeping their risks within appetite; all staff identify, report and control.
    From the source document(2 clauses)

    2.20Accountabilities, Roles & Responsibilities

    The Company operates a structured approach to risk management, with defined roles and responsibilities to ensure effective governance and control.

    | Board of Directors<br/>(strategic oversight) | The Board of Directors is responsible for:<br/>Approving the Company’s Risk Management Strategy<br/>Ensuring risk is considered as part of all strategic decision-making<br/>Reviewing the effectiveness of arrangements for risk management at least annually<br/>Ensuring that appropriate systems of risk management and internal control are in place<br/>Challenging and reviewing the robustness of the Business Plan, including stress testing against key risk scenarios<br/>Ensuring that stakeholder perspectives are considered in significant risk-related decisions | | --- | --- | | Directors<br/>(Contracts Director, Regional Commercial Directors & Estimating Director)<br/>(implementation & governance) | Directors are responsible for:<br/>Ensuring that sufficient financial, technological, and human resources are allocated to support effective risk management<br/>Embedding risk management into planning, decision-making, and operational activities.<br/>Maintaining effective risk management and internal control arrangements<br/>Identifying, assessing, and prioritising strategic and operational risks<br/>Implementing proportionate and effective risk mitigation measures<br/>Monitoring and maintaining the corporate risk profile<br/>Defining and applying the Company’s risk appetite and tolerance<br/>Providing regular risk reporting to the Board<br/>Escalating significant or emerging risks in a timely manner<br/>Reviewing the effectiveness of risk controls and implementing improvements.<br/>Directors shall also ensure that appropriate processes are in place for consultation with internal and external stakeholders to inform risk identification and management. | | Managers and Supervisors<br/>(operational control) | Managers and Supervisors are responsible for:<br/>Identifying, assessing, and managing risks within their sphere of responsibility<br/>Ensuring that relevant risks are communicated and, where appropriate, escalated to the corporate level<br/>Maintaining effective communication with stakeholders to identify emerging risks and opportunities<br/>Supporting the implementation of risk controls and mitigation measures within projects and operations | | Risk Owners<br/>(operational control) | Risk owners are responsible for:<br/>Managing and monitoring assigned risks over time<br/>Ensuring that appropriate controls and mitigation actions are implemented<br/>Reviewing risk status and updating risk records as required<br/>Escalating risks that exceed defined tolerance or appetite levels<br/>Consulting with relevant stakeholders in the management of risks<br/>Providing updates to stakeholders on risk status and effectiveness of controls<br/>Risk owners are accountable for ensuring risks remain within the Company’s defined risk appetite. | | All staff | All employees have a role in effective risk management. This includes:<br/>Supporting the identification and reporting of risks and opportunities<br/>Complying with risk control measures and procedures<br/>Contributing to risk awareness through day-to-day activities<br/>Risk management is embedded within normal working practices and is supported through communication, training, team briefings, and management engagement. |

    2.22Responsibilities:

    The Company shall:

    • Engage internal and external stakeholders at all relevant levels
    • Use appropriate communication methods, including workshops, interviews, and team meetings
    • Ensure stakeholder feedback is captured and used to improve the risk management process
    • Maintain mechanisms for ongoing feedback on risk controls, mitigation actions, and the effectiveness of the risk management framework.
    • Promote transparency and a shared understanding of risk across the Company.

    2.21, 2.23–2.26 Communication, Monitoring and Escalation

    Risk communication runs through ROMP reviews, performance dashboards, incident debriefs, project/management meetings and staff briefings, with external stakeholders engaged where useful. Monitoring is continuous via Delivery Manager Quarterly Reviews (DMQRs), Top Management Quarterly Review meetings and the annual Management Review, with risks tracked in the Corporate Risk Register and ROMPs and considered as part of normal director-level decisions. Periodic review: Corporate Risk Register at least annually (plus on significant change), project risks regularly, and an annual Audit and Risk Review by the JMDs and Head of ESG. Escalation timescales: Extreme/Intolerable within 24 hours; High within 5 working days; Medium within 20 working days; Low through routine reporting. Records are kept in the EDMS; business-disruption risks feed Business Continuity Management (BIA, BCPs) so critical activities can be restored within acceptable timeframes.

    Key points

    • Continuous monitoring via DMQR, Quarterly Reviews and the annual Management Review; tracked in the Corporate Risk Register and ROMPs.
    • Escalation timescales: Extreme/Intolerable ≤24h, High ≤5 days, Medium ≤20 days, Low via routine reporting.
    • Disruption-grade risks flow into the BCM process (BIA + BCPs); all records are retained in the EDMS.
    From the source document(5 clauses)

    2.21Communication and Consultation

    The Company recognises that effective communication and consultation with internal and external stakeholders are essential to successful risk management.

    Stakeholders are identified and engaged throughout the risk management process to:

    • Support transparency
    • Enable informed decision-making
    • Promote a proactive risk management culture across the organisation.

    Communication and consultation are facilitated through a range of mechanisms, including:

    • ROMP reviews
    • Performance dashboards
    • Incident debriefs
    • Project and management meetings
    • Staff briefings and forums

    External stakeholders may be consulted where appropriate to support joint risk evaluation, coordination, or treatment planning.

    2.23Monitoring and Review

    Monitoring and review are essential components of an effective risk management framework. In accordance with ISO 31000, Breheny Civil Engineering Limited is committed to ongoing monitoring and periodic review of its risk management processes to ensure they remain effective, relevant, and aligned with organisational objectives.

    2.24Continuous Monitoring

    • Risk management activities are monitored on an ongoing basis through routine business performance reviews (including review of risks/opportunities and the effectiveness of risk treatment actions), such as the project-level Delivery Manager’s Quarterly Review (DMQR), Top Management’s Quarterly Review Meetings, and the annual Management Review.
    • Key risks, controls, and mitigation actions are tracked using the Corporate Risk Register and Project ROMPs
    • Risk management is integrated into Director level management meetings, with risks and opportunities considered as part of strategic, operational and performance discussions and decision making, rather than through a separate formal agenda item.
    • Delivery Managers, Project Delivery Teams, and Directors are responsible for ensuring that risk information remains current, accurate, and appropriately managed.

    2.25Periodic Review

    • The Corporate Risk Register is formally reviewed at least annually, with additional reviews triggered by significant changes in the internal or external environment.
    • Project risks are reviewed regularly by Directors, Delivery Managers and Delivery Teams.
    • An annual Audit and Risk Review is undertaken by the JMDs and Head of ESG to update the Corporate Risk Register and support continuous improvement.
    • The effectiveness of risk controls and mitigation actions is evaluated during these reviews, with lessons learned incorporated into future risk management activities

    2.26Escalation and Reporting

    • Risks that exceed the Company’s defined risk appetite or tolerance shall be escalated to the Board for review and decision.
    • Escalation shall be undertaken in a timely, structured and documented manner, in accordance with defined reporting and governance arrangements, with timescales proportionate to the severity and urgency of the risk, as defined below:
    • Extreme / Intolerable risks (immediate or imminent realisation) – escalated immediately and no later than 24 hours
    • High risks (credible short-term potential for realisation) - escalated within 5 working days
    • Medium risks shall be escalated through normal management reporting arrangements within 20 working days of identification
    • Low risks - managed at the appropriate operational level and escalated through routine reporting where trends or changes increase exposure
    • Significant project-level risks identified at project level shall be escalated to the JMDs for review and assessment of potential corporate impact
    • Where review identifies potential exceedance of corporate risk appetite, dependency impacts, or material financial, legal, safety, environmental or reputational exposure, further escalation shall be undertaken in accordance with the timescales above.
    • The Board of Directors and Directors are responsible for monitoring and tracking key risk metrics to evaluate the effectiveness of the risk management framework, including risk trends, the number and status of mitigated risks, audit findings, significant incidents, and lessons learned.
  3. 3Energy Management3 parts

    3.1–3.9 Energy Management — ISO 50001 EnMS essentials

    BCE runs an ISO 50001-certified Energy Management System (EnMS), embedded across operations, procurement and design (see the EnMS Manual). Governance is layered: the Board sets strategy, approves objectives/targets and reviews annual performance; Directors lead, resource and integrate the EnMS; the Head of ESG runs the EnMS, manages ISO 50001 compliance and the audit programme, and conducts Energy Reviews; SHEQ Advisors promote energy management on-site; Heads of Department/Managers implement practices and report inefficiencies; Delivery Teams run site-specific energy plans and record consumption; the Plant Department procures and maintains efficient plant and equipment.

    Key points

    • ISO 50001-certified EnMS embedded across operations, procurement and design.
    • Clear roles top to bottom — Board approves objectives; Head of ESG runs the EnMS and audits; Delivery Teams run site plans.
    • Plant Department keeps the equipment fleet energy-efficient; SHEQ Advisors promote on-site.
    From the source document(11 clauses)

    3Energy Management

    No text in source for this clause.

    3.1Energy Management Framework

    The Company operates an ISO 50001 certified Energy Management System (EnMS), which provides a structured approach to the planning, implementation, monitoring, and continual improvement of energy performance. The framework ensures energy efficiency is embedded across operations, procurement, and design, as detailed in the EnMS Manual

    3.2Roles and Responsibilities

    | Board of Directors | Ensuring energy management is integrated into the organisation’s strategic direction<br/>Approving energy objectives and targets.<br/>Reviewing annual energy performance reports<br/>Ensuring continued effectiveness of the EnMS | | --- | --- | | Directors | Demonstrating leadership and commitment to improving energy performance<br/>Ensuring the EnMS is implemented, maintained, and integrated into business operations<br/>Allocating sufficient resources (personnel, technology, and financial) to implement, maintain and improve the EnMS. | | Head of ESG | Overseeing the implementation and performance of the EnMS<br/>Managing compliance with ISO 50001 and relevant obligations<br/>Establishing and maintaining the energy audit programme<br/>Undertaking Energy Reviews and developing energy management plans for regional offices and the Company. | | SHEQ Advisors | Promoting energy management and identifying energy-saving opportunities during site audits.<br/>Supporting the implementation and monitoring of energy-related controls on projects | | Heads of Departments/Managers: | Implementing energy management practices within their areas of responsibility.<br/>Identifying and reporting energy inefficiencies or wastage<br/>Supporting delivery of energy objectives and targets | | Delivery Teams: | Implementing and maintaining site-specific energy management plans.<br/>Ensuring efficient use of site accommodation, plant, equipment and fuels<br/>Recording energy consumption data where required. | | Plant Department | Procuring and maintaining energy-efficient plant and equipment<br/>Identifying and adopting alternative fuels and emerging technologies to reduce energy consumption. | | Procurement | Procuring energy services and products through appropriate commercial processes, ensuring value for money<br/>Considering energy performance and renewable energy options where economically viable<br/>Incorporating energy efficiency, carbon impact, and life-cycle cost considerations into procurement decisions | | All Employees | Adopting energy-efficient working practices<br/>Supporting energy conservation efforts<br/>Complying with energy management procedures and controls |

    3.3Procedure

    No text in source for this clause.

    3.3.1Energy Conservation and Efficiency

    The Company shall implement measures to promote energy conservation and improve energy efficiency across all operations.

    All employees are expected to take reasonable steps to minimise energy consumption and associated emissions.

    Energy efficiency measures shall be applied to minimise energy consumption and emissions to atmosphere where practicable and proportionate, including:

    • Use of automatic controls for heating, lighting, air conditioning, and equipment
    • Good housekeeping practices, such as switching off unnecessary lighting and equipment
    • Selection, operation, and maintenance of plant and equipment to optimise energy efficiency
    • Use of energy-saving modes of operation where available

    Fuel usage associated with site activities and business travel is recognised as a significant contributor to the overall energy consumption and carbon emissions and shall be managed accordingly.

    Project-specific energy-saving measures, are defined within Site Energy Management Plans (CP2-F06), to ensure consistent implementation across all relevant projects.

    Delivery Team Managers, with support from the Delivery Teams and the Plant Department, are responsible for implementing these measures. SHEQ Advisors are responsible for monitoring compliance.

    3.4Site Energy Management Measures

    The following energy saving measures are identified within the energy plan:

    | Site Based Energy Saving Measures | | | --- | --- | | Site accommodation | Use of temporary site accommodation with EPC ratings A–C and high insulation.<br/>Hybrid solar power generators supported by battery systems.<br/>PIR LED lighting for reduced electricity consumption.<br/>Energy-efficient water boilers in canteen facilities.<br/>Door closers on welfare facilities to retain heat.<br/>Eco-type hand dryers in toilets.<br/>Appropriate notices, posters shall be displayed throughout buildings to remind all users to conserve energy. | | Site-based Energy Saving Measures | Correct sizing and selection of energy-efficient plant and machinery.<br/>No idling policy: engine shutdown during inactivity.<br/>Proactive maintenance to ensure optimal plant performance.<br/>Operator training to promote efficient plant use.<br/>Installation of photosensitive and manual override switches for site lighting. | | Lighting | Lighting design to minimise intrusion on adjacent buildings, wildlife, and residents.<br/>Use of solar-hybrid LED tower lights or battery equivalents.<br/>Strategic placement and screening of generators to reduce noise and light pollution. | | Electricity Supply | Grid connection as early as practicable to reduce generator use<br/>Use of renewable or low-carbon electricity tariffs where commercially viable. |

    3.5Design

    The Company shall incorporate sustainability and energy efficiency considerations into the design of new projects, modifications and refurbishments where practicable and shall invest in energy-efficient plant and equipment as opportunities become available.

    3.6Procurement of energy services, products, equipment, and energy

    Energy services, products, and equipment shall be procured through a competitive tendering process ensuring value for money while considering energy performance and carbon impact.

    Where economically viable, renewable energy sources and energy efficient technologies shall be considered.

    Life-cycle cost and energy performance shall be considered in procurement decisions for projects, goods, and services.

    3.7Training and Awareness

    The Company shall ensure that individuals whose activities can influence energy performance, including those affecting Significant Energy Uses (SEUs), are competent on the basis of appropriate education, training or experience.

    Training shall be provided through the Company’s training and induction programmes, supplemented by additional or specialist sessions tailored to the specific requirements of individual employees or departments.

    3.8Essential equipment

    The Company shall identify and maintain, where appropriate, a schedule of essential equipment required to support operations. This schedule shall be reviewed periodically and updated as necessary.

    All non-essential equipment shall be switched off at or by the end of the working day.

    3.9Energy Management

    The Company shall monitor, measure, and analyse energy performance to:

    • Evaluate energy performance improvement
    • Ensure operational control is maintained
    • Support data-driven decision-making

    Monitoring and measurement shall apply to:

    • Significant Energy Uses (SEUs)
    • Relevant variables affecting energy consumption
    • Energy Performance Indicators (EnPIs)
    • Energy objectives and action plans

    As part of the energy planning process, office specific and generic site energy management plans shall be developed for the purposes of managing energy performance. Site energy plans shall be produced for sites exceeding 30 days duration.

    Energy Management Plans shall be recorded on form CP2-F06 for site plans and on form CP2-F07 for office plans.

    | The Energy Measurement Plan should describe the following: | What is measured and monitored | | --- | --- | | | The purpose of measurement | | | Methods of measurement | | | Expected performance levels | | | Thresholds for significant deviation | | | The action to be taken for a significant deviation | | | Personnel responsible for data collection and measurement | | | Data storage and record location | | | Any critical measurement parameters | | | Future measurement requirements. |

    Internal EnMS audits shall:

    • Verify compliance with ISO 50001, legal requirements, and Company Procedures
    • Review operations and gather user feedback.
    • Identify opportunities for improvement

    The Head of ESG determines audit frequency, with a minimum one audit annually. EnMS IMS audits are recorded on form CP2-F08.

    Audits of the IMS also address energy usage.

    The need for remedial actions shall be assessed and reported.

    Incidences or identified practices that cause energy wastage shall be reported to the Facilities Responsible Person as soon as possible.

    Full energy audits shall be conducted every three to five years at each main site to identify, quantity and prioritise opportunities for improving energy efficiency.

    Heating, ventilation and air conditioning systems shall be controlled, preferably automatically, to maintain comfortable working conditions, while complying with legislative requirements and energy efficiency good practice.

    Settings for all automatic timers shall be maintained and documented. The settings shall be reviewed on a regular basis, at least bi-annually, and any changes recorded.

    3.10, 3.12–3.18 Energy Baseline, EnPIs and Reporting

    The Energy Review is coordinated by the Head of ESG and run at least annually (and on significant change), analysing consumption, identifying Significant Energy Uses (SEUs) via Pareto analysis, defining variables and updating the Energy Baseline (EnB) and EnPIs. The baseline was originally 2010–15 (2012 reference year) and has been reset to 2023 following the Finance Act 2021 fuel-policy change to full-duty diesel. The 2023 EnB totals 25,639,267.61 kWh and 6,297.26 tonnes CO₂, broken down by fuel (electricity, gas, diesel, biomass, HVO, petrol, EV charging). The primary organisational EnPI is MWh per £million turnover (reflecting project-based delivery), with EnPIs applied to each SEU. Energy Reviews are recorded on ; deviations are managed under non-conforming output and improvement processes.

    Key points

    • Energy Review () runs at least annually, identifies SEUs by Pareto and updates EnB and EnPIs.
    • 2023 EnB: 25.6M kWh and 6,297 tCO₂ — reset from 2012 after the 2021/2022 rebated-diesel change.
    • Primary EnPI is MWh per £million turnover, with EnPIs for each SEU (diesel, petrol, gas, electricity, biomass).
    From the source document(8 clauses)

    3.10Energy review

    The company shall undertake an annual energy review, in accordance with the following:

    • Analyse energy consumption and usage trends
    • Identify Significant Energy Uses (SEUs)
    • Determine variables affecting energy performance
    • Establish and review the Energy Baseline (EnB)
    • Define and update Energy Performance Indicators (EnPIs)
    • Identify and prioritise opportunities for improvement

    Outputs of the Energy Review shall include:

    • Updated EnB and EnPIs
    • Energy performance trends
    • Prioritised improvement actions
    • Investment considerations and implementation plans

    3.12Responsibility and Review Frequency

    The Energy Review is coordinated by the Head of ESG, who is responsible for ensuring that:

    • Energy use and consumption are identified and analysed
    • SEUs are determined and maintained
    • Opportunities for improving energy performance are identified, evaluated, and documented

    The Energy Review shall be undertaken at least annually and additionally where significant changes occur that may affect energy performance, including:

    • Changes in operations, equipment, or processes
    • Changes in energy supply or usage patterns
    • Abnormal energy consumption trends
    • Significant incidents impacting energy use.

    Outputs of the Energy Review shall be reported to Senior Management and form part of the Management Review process.

    3.13Energy baseline (EnB)

    The Company has established an Energy Baseline (EnB), based on data from its Energy Review process.

    The original baseline was established using data from 2010 to 2015, with 2012 selected as the reference year.

    Following legislative changes introduced by the Finance Act 2021 and subsequent secondary legislation, which restricted entitlement to use rebated diesel in the construction industry from April 2022, a transition to full duty diesel became necessary.

    As a result of this change, the 2012 baseline is no longer comparable due to the significant shift in fuel usage.

    In accordance with ISO 50001 requirements, the energy baseline has therefore been revised to 2023, representing the first full year of operation under the new fuel regime.

    This ensures that the baseline remains relevant, comparable, and suitable for measuring energy performance.

    The Energy Baseline shall be reviewed periodically and updated where significant changes affect its validity or comparability.

    3.14Energy Baseline (EnB) Data

    The Energy Baseline (EnB) is based on a 12-month data period to ensure that seasonal variations in energy consumption and relevant variables are appropriately accounted for.

    The current baseline (2023) is summarised below:

    | BCE EnB 2023 | kWh & CO2 Emissions | | | | --- | --- | --- | --- | | Fuel | kWh | Conversion factor | Tonnes/year | | Electricity (Office/Yard) | 340,303.00 | 0.2071 | 70.47 | | Electricity (Site) | 135,544.66 | 0.2071 | 32.82 | | Natural Gas (Office/Yard) | 31,965.00 | 0.1829 | 5.84 | | Natural Gas (Site) | 25,886.00 | 0.1829 | 4.73 | | Fuel Oil | 0.00 | 0.2681 | 0.00 | | Biomass | 273,151.80 | 0.0113 | 2.93 | | Diesel | 22,977,886.70 | 0.2390 | 5,717.13 | | HVO | 0.00 | 0.0356 | 0.00 | | Petrol | 0.00 | 0.2201 | 0.00 | | Diesel (fuel card) | 1,680,791.99 | 0.2390 | 432.13 | | Petrol (fuel card) | 89,105.09 | 0.2201 | 22.43 | | EV Charging (Home & card) | 51,671.37 | 0.2620 | 13.54 | | Annual total | 25,639,267.61 | | 6,297.26 |

    3.15Application of the Energy Baseline

    Changes in energy performance shall be measured against the EnB. The EnB shall be reviewed and adjusted where necessary, including where:

    • Energy Performance Indicators (EnPIs) no longer accurately reflect energy use and consumption
    • Significant changes occur in operations, processes, or energy sources
    • Structural or organisational changes affect energy consumption patterns
    • A defined periodic review identifies the need for recalibration

    The Energy Baseline is used as the reference point for evaluating energy performance improvement and supporting the achievement of energy objectives and targets.

    3.16Energy Performance Indicators (EnPIs)

    Energy Performance Indicators (EnPIs) are established to monitor and evaluate the energy performance of the Company’s facilities, systems, processes, and equipment.

    The following EnPIs are applied to Significant Energy Uses (SEUs):

    | SEU | EnPI | | --- | --- | | Diesel | MWH / £Million turnover | | Petrol | MWH / £Million turnover | | Natural Gas | MWH / £Million turnover | | Electricity | MWH / £Million turnover | | Biomass | MWH / £Million turnover |

    3.17EnPI Methodology

    The Company has adopted megawatt hours (MWh) per £million turnover as its primary organisational EnPI for the purposes of monitoring, measuring and evaluating energy performance in accordance with ISO 50001.

    The selection of this EnPI reflects the nature of the Company’s operations as a projectbased civil engineering contractor, where energy consumption is directly influenced by the scale, value and intensity of work delivered, rather than by a fixed unit of output.

    Turnover data is derived from verified financial records, ensuring that the EnPI is accurate, consistent and auditable.

    The EnPIs shall be determined for current year and used to assess current energy performance against the EnB.

    3.18Monitoring and Evaluation

    Formal evaluation of EnPI performance, including comparison against the energy baseline and objectives, shall be undertaken at least annually as part of the Energy Review and Management Review process.

    Where significant deviations from expected energy performance are identified, these shall be investigated and managed in accordance with the Company’s procedures for nonconforming outputs and improvement.

    Documents you'll need

    3.19–3.22, 3.24 Energy Actions, Audits and Continuous Improvement

    Energy objectives and targets are set by the Board from the Energy Review and tracked through Energy Management Action Plans (), monitored via EnPIs and updated at review intervals. Objectives include delivering the Decarbonisation Policy, maintaining ISO 50001, legal compliance, awareness and competence, targeted consumption reduction, energy-aware procurement and design integration. Site Energy Management Plans () are produced for any site over 30 days; office plans use ; monthly consumption data is captured from verified sources within the financial system and maintained in the EDMS, with deviations investigated and energy reports submitted to the Board. Internal EnMS audits () verify ISO 50001 compliance and effectiveness; non-conformances are managed under CP3: Operational Control Section 6 (Form ); energy performance is reviewed annually as part of Management Review, and improvement is driven through CP1: IMSM and CP3: Operational Control.

    Key points

    • Action plans () track objectives; site plans () required for any site >30 days, offices on .
    • Internal EnMS audits () check ISO 50001; non-conformances are managed under CP3: Operational Control (Form ).
    • Annual Management Review covers energy performance; improvement runs through CP1: IMSM and CP3: Operational Control processes.
    From the source document(7 clauses)

    3.19Energy Objectives, Targets and Action Plans

    No text in source for this clause.

    3.19.1Objective Setting

    The Board of Directors shall use the data analysis and outputs from the energy review to establish energy objectives and targets.

    Objectives and targets shall:

    • Align with the Company’s decarbonisation strategy
    • focus on improving the performance of SEUs
    • Address identified opportunities for improvement

    Energy objectives shall be documented on (Form CP2-F12), published on the SHEQ Homepage and reviewed periodically by the Directors and the Head of ESG.

    3.19.2Strategic Objectives

    The Company’s energy objectives and targets include:

    • Delivery of the Decarbonisation Policy
    • Maintenance of ISO 50001 certification
    • Compliance with applicable legal and other requirements
    • Improvement of energy awareness, competence and good practice
    • Reduction of energy consumption through targeted initiatives
    • Monitoring and analysis of energy usage in all areas of the business to identify inefficiencies
    • Consideration of energy performance into procurement decisions and fully integrate energy lifecycle information
    • Incorporation of energy efficiency into design and operational processes.

    The Company’s Decarbonisation Policy incorporates the Energy Policy and fulfils the requirements of ISO 50001 Clause 5.2.

    3.20Energy Management Action Plans

    The Company shall develop and maintain Energy Management Action Plans to support the achievement of energy objectives and targets.

    These plans shall:

    • Be monitored using Energy Performance Indicators (EnPIs)
    • Be reviewed at defined intervals and as part of the Management Review process
    • Be updated to reflect performance, changing conditions, and improvement opportunities

    Energy Management Action Plans shall be recorded on Form (CP2-F10).

    3.21Monitoring

    The Company shall monitor and analyse energy performance data:

    • Track performance improvement
    • Maintain operational control
    • Support decision-making

    The following monitoring arrangements shall apply:

    • Energy Management Plans shall be developed by the SHEQ Department for all projects exceeding 30 days
    • Energy Management Plans shall be established annually for each regional office by the Head of ESG
    • Monthly energy consumption data shall be recorded using verified sources (e.g. meter readings, invoices) within the Company’s financial systems
    • Energy data shall be maintained within the Company’s EDMS
    • Significant deviations from expected performance shall be investigated, explained, and reported.
    • Energy performance reports shall be submitted to the Board of Directors as part of governance reporting.

    The Head of ESG shall be responsible for coordinating energy performance monitoring and reporting.

    3.22Audits, Non-conformance and Improvement

    Internal EnMS audits shall be undertaken to:

    • Verify compliance with ISO 50001 and Company procedures
    • Assess effectiveness of energy management controls
    • Identify opportunities for improvement

    Corrective actions shall be implemented where required.

    Non-conformances shall be managed in accordance with CP3 Section 6 - Management of Non-Conforming Outputs & Improvement.

    Non-conforming outputs shall be recorded on Non-Conformance / Complaint Record (Form CP3-F01), retained within the EDMS and sent to sheqadmin@breheny.co.uk.

    3.24Improvement

    Energy performance improvement shall be managed in accordance with CP1 IMS Manual and as defined in CP3 Operational Control Section 6 - Management of Non-Conforming Outputs and Improvement.

    Opportunities for improvement identified through monitoring, audits, and reviews shall be evaluated and implemented where appropriate.

    Documents you'll need

  4. 4Management System Audits1 part

    4.1–4.11 Audits — governance check points

    Audits give independent assurance the IMS is implemented, compliant with ISO/legal/contractual requirements, supports risk management and delivers intended outcomes — feeding risk, performance evaluation, improvement and Management Review. The Head of ESG owns the risk-based programme (frequency, scope, resources), the SHEQ Team plans/runs/reports audits with competent independent auditors, Delivery Teams run site inspections and close actions, and Top Management retains accountability. Programme inputs: project risk and complexity, operations, prior results, stakeholder concerns and business changes; project audits typically every six weeks (more often where risk demands), most unannounced. Audit types: Initial Site Assessments (CP3: Operational Control-05), routine SHEQ project audits (), internal system audits (), external audits (annual independent + certification/client) and targeted/reactive audits. Findings are reported, action-tracked and escalated on overrun; external findings get the same control as internal ones (managed via CP3: Operational Control). The framework also covers customer satisfaction, IMS and project performance evaluation, lessons learnt and formal project performance reviews (DMQRs on ).

    Key points

    • Head of ESG owns a risk-based programme; SHEQ Team runs audits; Top Management is accountable.
    • Audit types: ISAs (CP3: Operational Control-05), SHEQ project audits (), internal system audits (), annual external + reactive audits.
    • Findings are tracked and escalated; outputs feed risk, performance evaluation, improvement and Management Review.
    From the source document(12 clauses)

    4Management System Audits

    No text in source for this clause.

    4.1Purpose

    Management System Audits form a key component of the Company’s corporate governance framework and provide independent assurance that the Integrated Management System (IMS):

    • Is effectively implemented and maintained
    • Complies with applicable ISO standards, legal, and contractual requirements
    • Supports the management of risks and opportunities
    • Delivers intended performance outcomes

    Audits are used to evaluate the effectiveness of controls, identify non-conformances and improvement opportunities, and provide objective evidence to support decision-making.

    Audit outputs contribute directly to:

    • Risk management processes
    • Performance evaluation
    • Continual improvement activities
    • Management review

    4.2Audit Roles and Responsibilities

    The Head of ESG shall have overall responsibility for establishing, maintaining, reviewing and updating the Management System Audit Programme, including determining audit frequency, scope and resources.

    Responsibility for monitoring and analysing energy performance, including EnPIs and energy objectives, shall be assigned to the Head of ESG or nominated competent person.

    The SHEQ Team shall be responsible for planning, conducting and reporting audits in accordance with this procedure, ensuring auditor competence and independence is maintained.

    Delivery Team Members shall be responsible for undertaking site inspections and implementing corrective actions within their area of control.

    Top Management shall retain accountability for the effectiveness of the IMS, including the monitoring, analysis and evaluation of SHEQ and energy performance, and the review of audit results as part of Management Review.

    4.3Audit Programme and Frequency

    The audit programme shall be risk-based and determined by the Head of ESG, taking into account:

    • Project risk and complexity
    • Nature of operations
    • Previous audit results
    • Stakeholder concerns
    • Changes to business activities

    Project audits shall typically be undertaken at intervals no longer than six weeks, with increased frequency applied where performance concerns or elevated risks are identified.

    Wherever possible, Initial Site Assessments (ISAs) shall be undertaken for new projects and those exceeding defined durations at intervals determined by the Head of ESG.

    Typically, the date and time of a SHEQ Audit is not announced in advance to enable a more typical “snapshot” of the project to be obtained during the audit.

    Wherever practicable, all new projects with a duration of over 30 days will be visited by a member of the SHEQ Team to conduct an Initial Site Assessment. Projects lasting less than 30 days may also be visited, at the discretion of the Head of ESG, or where requested by the Client or Contracts Manager.

    4.4Audit Types

    The audit programme shall include:

    • Initial Site Assessments (ISAs)
    • Routine SHEQ project audits
    • Internal system audits
    • External audits (certification and client audits)
    • Targeted or reactive audits based on incidents or performance concerns

    4.5Audit Programme Objectives

    The objectives of the audit programme are to:

    • Evaluate compliance with the requirements of ISO 9001, ISO 14001, ISO 45001, and ISO 50001.
    • Verify compliance with applicable legal, regulatory, contractual and Company requirements
    • Assess the effectiveness of the Integrated Management System (IMS) in achieving its intended outcomes
    • Identify non-conformances, risks, and opportunities for improvement across operational and corporate activities
    • Promote the identification and sharing of best practice across the organisation
    • Provide assurance that Company policies, commitments, and governance arrangements are consistently implemented

    Audit outcomes shall support:

    • Risk management processes
    • Performance evaluation
    • Continual improvement
    • Management Review

    4.6Initial Site Assessments

    Initial Site Assessments (ISAs) shall be undertaken using Form (CP3-05) for new projects to:

    • Establish early assurance of compliance with Company procedures
    • Identify initial risks and control requirements
    • Support effective project mobilisation

    ISAs shall be undertaken by the SHEQ Team within defined timeframes and findings shall be:

    • Documented
    • Communicated to relevant project personnel
    • Tracked through to close-out

    Outstanding actions shall be verified during subsequent audits.

    4.7SHEQ Project Audits

    Routine SHEQ audits shall be undertaken using Form (CP2-F04) on projects to:

    • Verify compliance with legal requirements and Company procedures
    • Assess implementation of the Integrated Management System (IMS)
    • Identify risks, non-conformances, and opportunities for improvement

    Additional or targeted audits may be undertaken in response to:

    • Incidents or complaints
    • Poor performance or previous audit findings
    • Client or stakeholder requirements

    Audit findings shall be:

    • Formally reported
    • Assigned with actions and timescales
    • Monitored to completion

    Failure to close actions within agreed timescales shall result in escalation in accordance with Company procedures.

    4.8Internal System Audits

    Internal system audits shall be undertaken in accordance with an audit programme (CP2-F02) to:

    • Verify compliance with ISO standards and Company procedures
    • Assess the effectiveness of the IMS
    • Support continual improvement

    Audits shall:

    • Be conducted by competent and independent personnel
    • Be risk-based in frequency and scope
    • Include defined criteria and documented outputs

    Non-conformances shall:

    • Be recorded and managed in accordance with CP3
    • Include root cause analysis and corrective actions
    • Be verified for effectiveness

    Audit results and trends shall be reported to management and form part of Management Review inputs.

    4.9External Audits

    Audits of the Company systems, projects and procedures shall be undertaken annually by an external independent auditing organisation. These shall be overseen by the Head of ESG or nominated representative.

    Audits of the company systems and procedures shall also be subject to audit by other external organisations such as:

    • Certification and assessment bodies
    • Clients or Principal Contractors
    • Other relevant third-party organisations

    4.10Management of External Audit Findings

    Findings arising from external audits shall be:

    • Reviewed and evaluated by the Company
    • Managed in accordance with internal audit and non-conformance processes (CP3)
    • Assigned appropriate corrective actions and timescales

    External audit findings shall be treated with the same level of control, investigation, and follow-up as internal audit findings.

    Outcomes from external audits shall:

    • Contribute to performance evaluation
    • Inform risk management activities
    • Be included as inputs to Management Review

    4.11Site Inspections

    Site inspections are undertaken by the appropriate Delivery Team Member in accordance with CP6 and form part of the overall assurance framework supporting audit activities.

    Documents you'll need

  5. 5Management System Review1 part

    5.1–5.5 Management Review

    Management Review is held at least annually, led by Top Management with the Head of ESG, and attended by the Company Chairman, JMDs, Contracts/Commercial/Pre-Contracts Directors, SHEQ Team and others as required. Inputs cover follow-up actions, internal and external issues, audit results, legal compliance, non-conformances and incidents, energy performance (EnB and EnPIs), progress against SHEQ and energy objectives, customer satisfaction, environmental/H&S/quality/energy performance, resource adequacy, effectiveness of risk and worker-participation actions, communication, and IMS changes. Outputs are documented decisions and actions covering IMS improvements, confirmation that the QHSE and Decarbonisation policies remain suitable, policy/objective/strategy changes, performance and customer-satisfaction improvements, resource needs and assigned responsibilities and timescales. A formal Management Review Report () is produced and retained in the EDMS along with agendas, minutes and decision records.

    Key points

    • Held at least annually; led by Top Management with the Head of ESG; attended by Chairman, JMDs, Directors and SHEQ Team.
    • Inputs span audits, legal compliance, non-conformances, energy performance (EnB/EnPIs), objectives, satisfaction and resources.
    • Outputs are decisions and actions captured in the Management Review Report () and held in the EDMS.
    From the source document(6 clauses)

    5Management System Review

    No text in source for this clause.

    5.1Purpose

    Management Review is a key element of the Company’s corporate governance framework and is undertaken to ensure that the IMS:

    • Remains suitable, adequate, and effective
    • Is aligned with the Company’s strategic direction
    • Continues to deliver intended performance outcomes

    Management Review provides Top Management with a structured process to evaluate performance, review risks and opportunities, and make informed decisions regarding improvement and resource allocation.

    5.2Frequency and Attendance

    Management Reviews shall be undertaken at least annually.

    The review shall be led by Top Management, with support from the Head of ESG, and shall include:

    • Company Chairman
    • Joint Managing Directors
    • Contracts, Commercial and Pre-Contracts Directors
    • Members of the SHEQ Team
    • Other relevant personnel as required

    5.3Management Review Inputs

    The Management Review shall include, as a minimum:

    • Follow-up actions from previous reviews
    • Changes in internal and external issues
    • Audit results (internal and external)
    • Legal and compliance performance
    • Non-conformances, incidents, and corrective actions
    • Energy performance, including EnB and EnPIs
    • Progress against SHEQ and energy objectives
    • Customer satisfaction and stakeholder feedback
    • Environmental, health & safety, quality, and energy performance
    • Adequacy of resources
    • Effectiveness of actions addressing risks and opportunities
    • Effectiveness of worker participation and consultation arrangements relating to occupational health and safety
    • Communication and awareness
    • Changes affecting the IMS
    • Other relevant issues raised by management

    5.4Outputs from Management Review

    • The meeting shall result in documented outputs including:
    • Decisions and actions relating to improvement of the IMS
    • Confirmation of the continued suitability, adequacy, and effectiveness of the Quality, Environmental, OH&S, and Decarbonisation Policies
    • Changes to policies, objectives, and strategic direction
    • Improvements to environmental, energy, and health & safety performance
    • Actions to enhance customer satisfaction
    • Identification of resource needs
    • Assignment of responsibilities and timescales

    Outputs from Management Review shall be used as formal inputs to the planning and improvement processes of the Integrated Management System.

    5.5Records and Documentation

    A formal Management Review Report (CP2-F13) shall be produced and shall include:

    • Agenda items
    • Discussions and conclusions
    • Decisions and actions
    • Assigned responsibilities and deadlines

    Directorlevel and Boardlevel review of risk, performance and IMS effectiveness is evidenced through documented meeting agendas, minutes and reports retained within the EDMS. Records shall be:

    • Retained in accordance with the Company’s document control procedures
    • Available for internal and external audit

    Evidence of implementation and effectiveness of actions shall be monitored and reviewed.

    Documents you'll need

Tables & figures

All tables, charts and diagrams extracted from the source PDF.