POL00027716 - Deloitte Project Zebra Supporting Your Assurance Needs - Post Office Limited.

Evidence on official site

POL00027716
POL00027716

Deloitte.

Project Zebra

7 June 2012

POL00027716

POL00027716
Simon Baker, A
Post Office Ltd. owe ne 5
148 Old Street, Ponies reet Square
ECIV 8HQ EC4A 3BZ
: United Kingdom

Dear Simon,

June 2012

As per our recent conversations, I am delighteditovide some further information summarising tha@e possible options which we see as availabledst Pffice Ltd
(POL) which would provide you with differing “leyeand “types” of comfort over the integrity of pressing within your Horizon system.

Based on our conversations to date, my personaW\iethat Option B appears to best suit POL’s nedésist a number of comparisons are outlined iisttocument,
my primary reason for suggesting this is that sanhapproach is more flexible in its delivery foamd outputs. Such an approach has less reportimgtcaints (eg:
agreed upon procedures only enables us to repottcfal findings, not conclusions) and fewer forrasborting protocols (eg: in a positive assurancerash, based on
ISAE3000, we would be required to adhere to a pied reporting format and prescriptive wording anod our conclusions, aBctated by the standard).¥ a review
such as this, avoiding such reporting constraims protocols enables us to scope our forensic testvork in more pragmatic, risk focussed and timasiderate way
and enables us to shape our end deliverable momaptively with you, to ensure our findings and clusions are most suitabhgported. I strongly betive that this,
combined with your current level of understandingdetailed system data flows, architectural mattensd activities to manage key processing riskd,se@ POL
achieving best value from our work through this apach.

I would be very comfortable delivering such workytau under legal privilege, should you require tHisom our team bios and credentials previouslyeHawe have
demonstrated that our team has the right experieraed capabilities to give you confidence that Dibtotan deliver such a high profile and complexgief assurance
work for you, what-ever form this may take. I aracatonfident that our background of working with IP@ver the past 4 years oth IT and Financial axe (with your
teams in Chesterfield) will help improve our effieiness through all stages of the review and rdiiggner quality improvement suggestions with you.

My team and I are genuinely excited by the oppoitymf working with POL in this area, so please’tibesitate to call me on my mobile number belowthwany further
queries should these be raised in your discusswitis Paula, Alice, Susan or Lesley.

Gareth James
Partner

© 2012 Deloitte LLP. Private and confidential
POL00027716
POL00027716

Three Potential Options

There are three key approaches that could be adopted by P OL to provide varying degrees of assurance around the proce ssing integrity of your Horizon
system. These approaches have different characteristics, which r evolve around complexity, flexibility and cost.

Our recommendation, based on our conversations to date, i s that option B would most likely best suit POLs current ne eds. This offers the greatest degree of
flexibility to define the scope to meet your requirement s and has a much less “prescriptive” reporting output.

Option B
Conclusions & Recommendations

Option C

‘eed Upon Procedures (AUP) Positive Assurance

© 2012 Deloitte LLP. Private and confidential.
POL00027716
POL00027716

Key Features and Estimated Costs

Option A Option B Option C
Agreed Upon Procedures Conclusion and Recommendation Positive Assurance

Cl
2
:
s

* Estimated costs for Stage 2 work under each Option are based on a number of assumptions which, through our experience of the various delivery models, we have suggested likely fee
outcomes to POL for consideration. Our actual costs would be charged on a time and materials basis, in line with the Advisory rate card within our framework agreement with POL, and
would depend on exact scoping requirements of the performance and reporting phase. All fees exclude VAT and out of pocket expenses, which would be charged as incurred.

© 2012 Deloitte LLP. Private and confidential.
Important notice

This document has been prepared by Deloitte LLP (as defined below) for the sole purpose of providing aproposal to the parties to whom it is addressed inorder that
they may evaluate the capabilities of Deloitte LLP to supply the proposed services.

‘The information contained in this document has been compiled by Deloitte LLP and includes material whh may have been obtained from information provided by
various sources and discussions with management buthas not been verified or audited. This document abo contains confidential material proprietary to Ddoitte LLP.
Except in the general context of evaluating our carabilities, no reliance may be placed for any purposes whatsoever on the contents of this document or an its
completeness. No representation or warranty, express or implied, is given and no responsibility or lability is or will be accepted by or on behalf of Deloitte LLP or by any
of its partners, members, employees, agents or any other person as to the accuracy, completeness or carrectness of the information contained in this docunent or any

other oral information made available and any suchliability is expressly disclaimed,

This document and its contents are confidential and may not be reproduced, redistributed or passed on, directly or indirectly, to any other person in whde or in part
without our prior written consent

This document is not an offer and is not intended b be contractually binding. Should this proposal beacceptable to you, and following the conclusion of our internat
acceptance procedures, we would be pleased to discuss terms and conditions with you prior to our appontment,

In this document references to Deloitte are references to Deloitte LLP. Deloitte LLP is the United Kingdom member firm of Deloitte Touche Tohmatsu Limital (“DTTL"), a
UK private company limited by guarantee, whose memier firms are legally separate and independent entites. Please see www.deloitte.co.uk/about for a detaled
description of the legal structure of DTTL and its member firms

© 2012 Deloitte LLP. All rights reserved

Deloitte LLP is a limited fiability partnership regstered in England and Wales with registered number 0C303675 and its registered office at 2 New Street Square, London
EC4A 3BZ, United Kingdom

Member of Deloitte Touche Tohmatsu Limited

POL00027716
POL00027716

© 2012 Deloitte LLP. Private and confidential.