PUBLIC SCOPE NOTEDetailed risk registers, scores, named dependencies, security controls, recovery procedures and client-specific continuity plans remain controlled internal or client-confidential records. Their exclusion protects operations and does not reduce accountability.
01Governance and risk appetite
The Managing Director owns the enterprise framework. Operational leaders own risks within their services and sites. Fiesta has no appetite for deliberate illegality, bribery, forced or child labour, knowingly unsafe food, concealed serious incidents or retaliation. Other risks are accepted only when understood, controlled and proportionate to service commitments.
- Material risks and overdue actions are reviewed by leadership at least quarterly.
- Tender, mobilisation and change decisions include proportionate risk review.
- Owners receive authority, resources and deadlines appropriate to the exposure.
02Risk identification and assessment
Teams consider hazards, threats, opportunities, causes, controls, consequences and affected stakeholders. Internal registers assess likelihood and impact using defined scales and record both existing and planned controls. Ratings support prioritisation but do not replace professional judgement or mandatory action.
- Categories include food safety, people, supply continuity, utilities, site access, security, finance, contract, integrity, environment, information and reputation.
- Emerging risks are added when operations, evidence or external conditions change.
- Interdependencies and single points of failure are considered explicitly.
03Treatment, escalation and assurance
Treatment may avoid, reduce, share, transfer or consciously accept risk. Controls are specific, owned and measurable. Immediate threats are escalated without waiting for a scheduled review, while significant decisions and residual acceptance are recorded at the proper authority level.
- First-line owners operate controls; independent or cross-functional checks provide additional challenge where practical.
- Incidents, near misses, complaints, audit findings and supplier failures inform the risk profile.
- Corrective actions are verified for completion and effectiveness.
04Continuity planning and response
Priority services identify minimum safe operating conditions, critical people and suppliers, communications, alternative arrangements and recovery objectives appropriate to the contract. Response structures protect life and food safety first, establish command, communicate verified facts and preserve essential records.
- Plans consider loss of utilities, access, supply, equipment, workforce, information and transport.
- No continuity workaround may bypass an essential food-safety or legal control.
- Clients and authorities are notified according to agreed and legal requirements.
05Exercises, recovery and learning
Continuity arrangements are reviewed and exercised at a frequency proportionate to risk. After a disruption or exercise, teams record what occurred, restore safe service, reconcile records and stock, confirm stakeholder needs and assign improvements.
- Lessons are shared without publishing confidential vulnerabilities.
- Material changes trigger plan and contact-list updates.
- Leadership confirms closure of significant recovery and preventive actions.