POL00423153 - Post Office Limited Compliance Framework - Legislative and Regulatory Obligations.

Evidence on official site

POL00423153
POL00423153

POST OFFICE LIMITED

COMPLIANCE FRAMEWORK

INDEX

POL-BSFF-0237968
POL00423153

POL00423153

1. [HYPERLINK \1l "P1"]

[HYPERLINK \1l "P1"]

2. [HYPERLINK \1l "P4"] [HYPERLINK \1 "P4"]
3a. [ HYPERLINK \1 "P5" J] C
HYPERLINK \1l "P5" J
3b. [ HYPERLINK \1l "P6" ] [
HYPERLINK \1 "P6" J]
3c. [ HYPERLINK \1l "P7" ] [HYPERLINK \1
"pI"]
3d. [ HYPERLINK \1l "P8" ] [
HYPERLINK \1 "P8" ]

4. [ HYPERLINK \1 "P9" ]

[HYPERLINK \1l "P9"]

5. [ HYPERLINK \1 "P10" ] [ HYPERLINK

\l "P10" ]j

6. [HYPERLINK \1l "P11"]

[ HYPERLINK \1l "P11" J

APPENDIX [ HYPERLINK \1l "P12" ] if
HYPERLINK \l "P12" ]

1. Introduction
[HYPERLINK \1l "P3"]

Compliance with Post Office Limited’s legislative and
regulatory obligations is vital and something that everyone
must do wherever they work in this Business. In an environment
of greater transparency, mobilised customer scrutiny and

POL-BSFF-0237968_0001
POL00423153
POL00423153

increasingly proactive regulators, any failure to comply with
our legal and regulatory requirements could have a significant
impact, both in terms of financial implications and
reputational damage.

The Post Office is enormously proud of the trust our customers
have in our brand and in order to retain that trust, we must
adhere to robust policies and procedures that demonstrate our
commitment to fulfill the following obligations:

Conduct its business with integrity

Operate with due skill, care and diligence

Observe proper standards

Be transparent in all business dealings

Treat our customers fairly

Provide adequate protection to customers

Deal with all regulators in an open and honest way

It is therefore important that we all understand the
implications of these legislative and regulatory obligations as
we go about our day-to-day work. Everybody has a duty to comply
with these as they apply to their job or area of
responsibility.

This document has been designed as a source of reference for
all the areas of legislation and regulation that Post Office
Limited is governed by, especially those relating to our higher
profile regulators such as Ofcom, Postcomm, Financial Services
Authority (FSA) and Her Majesty’s Revenue & Customs (HMRC). The
primary purpose of this document is to clearly state the
allocation of ownership between Post Office Limited's directors
and each of the regulatory and legislative obligations that
Post Office Limited is subject to.

For further information on any of the sections in this
document, or on how we manage compliance within the Post
Office, please contact Keith Woollard in the first instance on
: GRO Por f GRO

Managing Director

POL-BSFF-0237968_0002
2. Compliance Framework Controls &
Responsibilities [HYPERLINK \1 "P3"]

The Compliance Framework lays out all areas of the Post
Office’s legislative and regulatory responsibilities.

It is important that each identified owner is aware of
their responsibilities for ensuring appropriate controls
are in place (as detailed below), to ensure that
compliance with Post Office’s legislative and regulatory
requirements is possible:-

Integrity and ethics

= Post Office brand is not compromised including the
People’s Post Office advertising campaign

" Fairer, Easier, Better principles are fully deployed
and supported throughout Post Office

Management philosophy and attitude:

" Monitoring systems are in place to assess compliance
and remedial actions are taken where necessary

= Legal Services are used for advice on non-compliance

= Implications of new or emerging legislation and
regulation are identified, evaluated and responded to
in a timely manner.

Organisational structure:
*" All relevant managers and non-managers are kept
informed of changes to compliance requirements

Authority and responsibility:

=" Legal Services are fully consulted in the development
of new products, business processes and projects

=" Business change process is fully utilised as a tool to
drive and manage compliance

= Suppliers and clients understand their role in meeting
legislative and regulatory requirements.

HR and competence of personnel:

= Employees understand their role in meeting legislative
and regulatory requirements

=" There is sufficient resource to manage and monitor
compliance requirements.

Operating policies and procedures:

*" Operating procedures are designed to meet the
requirements of legislation and regulation together
with the appropriate Post Office Ltd or Group policies

™ Supporting policies in place (Royal Mail Group & Post
Office Ltd) are accessible, communicated and applied
across all areas of the Business.

POL00423153
POL00423153

POL-BSFF-0237968_0003
POL00423153

POL00423153
3a. Map of Accountabilities - How we sell products & services (by Director)
[HYPERLINK \1 "P3"]
ET Regulator Legislative I Sub Area (if Supporting statutes / regulations I RM Group Policy Post
Responsibilit / applicable) Office
y Regulatory Limited
Area Policy
Peter Corbett {[ HYPERLINK Product: Financial Services & Markets Act Rl Regulation Money
Finance "http: //www.o I Sales Proceeds of Crime Act F22 Taxation Laundering
Director fcom.org.uk/" Consumer Credit Act S2 Criminal Policy
] VAT Act Investigation &
Communications Act Prosecution Policy
[ HYPERLINK
“http: //www.h
mrc.gov.uk/ml
Be ae I
[ HYPERLINK
“http: //www.f
sa.gov.uk/" ]
Paula [ HYPERLINK I Relating to Mails I [ HYPERLINK G19 Management of [
Vennells [ HYPERLINK "ftp://ftp.r Integrity "ftp://ftp.royalmail.com/Download I the relationship HYPERLINK
Network "http: //www.p I oyalmail.com s/public/ct£/rmg/Royal Mail _Licen I with Postcomm "http://ip
Director /Downloads/p

ostcom
k/" ]

1.gov.u

ublic/ct£/rm
g/Royal_Mail
_Licence_25
May__2006.pd
"J

ce_25 May _2006.pd£”
Mails Integrity - Postcomm
Postal Services Act

{ HYPERLINK

"http: //iplatform-
sp.intranet.point/si
tes/Compliance-
library/Published
Documents/Shared
Documents/4447 RM
Comp bk A5_6.pd£" ]
( HYPERLINK
"http://www. royalmai
lgroup.com/portal/zm
g/jump1?catId=232005
29&mediaId=23200532"
]

latform.in
tranet.poi
nt/zmg/pol
/Informati
on/Policie
s+and+Guid
elines/Mai
ls+Integri
ty+Policy+
Documents.
htm" ]

POL-BSFF-0237968_0004
POL00423153

POL00423153
Relating to { HYPERLINK (HYPERLINK
protection of 374 "ftp://ftp.royalmail.com/Download I "http://iplatform.in
party interests s/public/ct£/rmg/Royal_Mail_Licen I tranet.point/rmg/Ser
ce_25 May __2006.pdf" ] vices/Compliance/Con
dition+10/"]
( HYPERLINK
"http://iplatform.in
tranet.point/rmg/Ser
vices/Compliance/"
[ HYPERLINK Competition I Promotion of Enterprise Act (Subpostmaster { HYPERLINK [
“http: //www.c Competition Relationships) "http://iplatform.in I HYPERLINK
ompetition- tranet.point/rmg/Ser I "http://ip
Gomis sion. ox vices/Compliance/" latform.in
a tranet.poi
g-uk/" J nt/rmg/pol
/Informati
on/Policie
stand+Guid
elines/Res
trictions+
Policy.htm
Gary Hockey [ HYPERLINK
Morley [ HYPERLINK "“ftp://ftp.r I Relating to { HYPERLINK { HYPERLINK
Marketing "http: //www.p I °valmail.com I Access "£tp://ftp.royalmail.com/Download I "http://iplatform.in
Director ostcomm.gov.u /Downloads/p s/public/ctf£/rmg/Royal_Mail Licen I tranet.point/rmg/Ser
ublic/ct£/rm ce 25 May 2006.pdf" ] vices/Compliance/Pol

k/" ]

g/Royal_Mail
_Licence_25

icies/" ]

May __2006.pda
£" J
{ HYPERLINK Competition Promotion of Competition Act / Law (Post G2 Benchmarking &

"http: //www.c
ompetition-
commission.or
g-uk/" ]

Competition

Office Limited Products)

Exchanging
information with
outside
organisations

G4 Competition Law
Compliance

Intellectual
Property

Copyrights @ Related Rights
Databases Act
Trademarks Act

IP1 Intellectual
Property

G29 Observing
copyright when using
external sources of
information

POL-BSFF-0237968_0005

POL00423153

POL00423153
ET Regulator Legislative I Sub Area (if Supporting statutes / regulations I RM Group Policy Post
Responsibilit / applicable) Office
y Regulatory Limited
Area Policy
Gary Hockey Product Fairness in Unfair Contract Terms Act (client IG4 Competition Law
Morley [ HYPERLINK Sales Trading and customer contracts) Compliance
Marketing "http: //www.t Unfair Terms in Consumer Contract I (including G4a &
Director radingstandar Regulations G4b)
ds.govuk/" ] Disability Discrimination Act G5 Conflicts of
(products) Interest
Sale and Supply of Goods Act G16 Insider Dealing
{ HYPERLINK Supply of Goods (implied terms) G18 Mergers &
“http: //www.o Act Associations
ft.gov.uk/" J Trade Description Act G21 Corporate

Consumer Protection Act
Control of Misleading
Advertisements Act

Governance of
Subsidiary,
Associate & Joint
Venture Companies
(including G2la «&
G21b)

G23 Creation of new
subsidiaries « Joint
Venture Companies

{ HYPERLINK
"http://iplatform.in
tranet.point/rmg/Ser
vices/Compliance/Car
tel+News+Story.htm"
]

POL-BSFF-0237968_0006
POL00423153
POL00423153

3b. Map of Accountabilities - How we operate (by Director)
[HYPERLINK \1 "P3"]
ET Regulator Legislative / Sub Area (if Supporting statutes / regulations I RM Group Policy Post Office
Responsibilit Regulatory applicable) Limited
y Area Policy
Debbie Moore Data & { HYPERLINK G30 Freedom of { HYPERLINK

HR Director

Information

"http: //iplatform.intranet.point/r
mg/pol/I rmation/Policies+and+Gu
idelines/Freedom+of+InformationtAc
tehtm" ]

Document Retention Act

Computer Misuse Act

Official Secrets Act

Welsh Language Act

Public Interest Disclosure Act

Information

G6 Document
Retention (including
G6a & Géb)

G12 Welsh Language
P6 Use of
Information &
Information Systems
G7 Employee
Disclosure
(Whistleblowing)

http://ipl
atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0ffice+
Ltd/Policy/
Employee _Di
sclosure_ Po
licy.htm" ]
[ HYPERLINK
http://ipl
atform.intr
anet.point/
rmg/pol/Int
ormation/Po
liciestand+
Guidelines/
Welsh+Langu
age+Guideli
nes.htm" ]

POL-BSFF-0237968_0007
POL00423153
POL00423153

[

Health &
Safety

Procedural
aspects

Health & Safety at Work Act
Employers Liability Act
Offices, shops & Premises Act
RIDDOR regulations
Occupiers Liability Act
H&S Information for Employees
regulations
Working Time Directive
Six Pack Regulations
" Management of H&S at work
* Display Screen Equipment

P4 Health & Safety

HYPERLINK
https: //ww
w.postoffic
eintranet.c
o.uk/teams/
usemanual.a
sp" )

[ HYPERLINK
"http://ipl

HYPERLINK " Provision & use of work atform.intr
"http: //ww related equipment anet.point/
w.hse.gov. "= Workplace health, safety « xmg/pol/Inft
uk/index.h welfare oritaélen/ Fo
‘ei? "Personal protective Liciestandt
equipment at work Guidelines/
" Manual handling HostagetPol
icy.htm" J
Premises aspects e Precautions Act P4 Health & Safety
H&S First Aid regulations F8 Fire Safety I HYPERLINK
Electricity at Work regulations G14 Disabled "https: //ww
Control of Substances hazardous to I Customers w.postoffic
health regulations eintranet.c
Control of Asbestos at work o.uk/teams/
regulations usemanual.a
Health Act 2006 sp" ]
Disability Discrimination Act
(access to premises) [ HYPERLINK
Noise at Work regulations "http://ipl
atform.intr
anet.point/
rmg/pol/Inf
ormation/Po
licies+and+
Guidelines/
Suspect+pac
kages+intro
-htm" ]
ET Regulator Legislative / I Sub Area (if Supporting statutes / regulations I RM Group Policy Post Office
Responsibility Regulatory applicable) Limited
Area Policy

POL-BSFF-0237968_0008
POL00423153
POL00423153

Debbie Moore
HR Director

Employment

Terms &
Conditions

Unfair Contract Terms Act
(employment contracts)

Fixed Term Workers Directive
Employment Act

G3 Code of Business
Standards

[ HYPERLINK
"http://ipl
atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Recruitment
_Policy.htm

I HYPERLINK
"http://ipl
atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Flexible Wo
rking_Polic
y-htm" ]

Relations

Employment Relations Act
Trade Union & Labour Relations Act
TUPE Regulations

[ HYPERLINK
"http://ipl
atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet+
Ltd/Industr
ial_Relatio
ns.htm" ]

POL-BSFF-0237968_0009
POL00423153

POL00423153
Discrimination Equality Act P5 Equal [ HYPERLINK
Race Relations Act Opportunities - "http://ipl
[ HYPERLINK Diversity & atform.intr
"http: //iplatform.intranet.point/r I Inclusion anet.point/

mg/pol/Information/Policiestand+Gu
idelines/Disability+Discrimination
+Act.htm" ]

Human Rights Act

Protection from Harassment Act

Sex Discrimination Act

Equal Pay Act

Valuing Diversity
Policy v1.1

rmg/Service
s/HR+Help/P
ost+Office+
Ltd/Policy/
Harassment _
and_Bullyin
g_Policy.ht

Employment Equality (Age) n" ]
Regulations
National Minimum Wage Act 1998
(National Minimum Wage Regulations
1999)
Gary Hockey Data & Client Contracts I Public Records Act CS9 Acceptable
Morley Information Partnerships with
Marketing Trusted Third
Director Parties
Mike Young Data & Purchasing Public Records Act Fé Liability in
Operations Information Contracts Purchasing Contracts
Director
Data & Information Security $1 Information I HYPERLINK
Information Security "http: //ipl
S10 Clear Desk atform.intr
Policy anet.point/

$16 Third Party
Access Policy

73 Royal Mail Anti
Virus

rmg/pol/Inf
ormation/Po
licies+and+
Guidelines/
Clear+Desk+
policy.htm"

I HYPERLINK
http://ipl
atform.intr
anet.point/
rmg/pol/Inft
ormation/Po
licies+and+
Guidelines/
Information
+Security+P
olicy.htm"

POL-BSFF-0237968_0010
POL00423153
POL00423153

Employment

Private Security Act

Procurement

Public Procurement Regulations

Fl Authority to

Unfair Contract Terms Act (re: Requisition, Procure
procurement contracts) & Pay
VAT Act (purchasing) F2 Procurement
Sale & Supply of Goods Act (re: Policy
purchasing) ( HYPERLINK
Public Records Act (re: "http://iplatform.in
purchasing) tranet.point/rmg/Ser
vices/How2Buy/3Buy"
]
ET Regulator Legislative / I Sub Area (if Supporting statutes / regulations I RM Group Policy Post Office
Responsibility Regulatory applicable) Limited
Area Policy
David Glynn Data & Sales & Direct Data Protection Act G13 Data Protection HYPERLINK
Sales Director Information Channels Act "http://ipl
T15 Intranet atform.intr
Exploitation anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Data_Protec
tion_Act.ht
m"]
Royal Mail Other Highways Act G17 Royal Mail

Company
Secretary’s
Office

Environment Protection Act

Environmental Policy
( HYPERLINK
"http://iplatform.in
tranet.point/rmg/Ser
vices/CSR+Environmen
t/CSR+Environment.ht
nm]

Property related
legislation
(Managed at
Group Level)

Town & Country Planning Act
Property Act

Land Registration Act
Landlord & Tenants Act
Occupiers Liability Act

Vehicle related
legislation
(Managed at
Group Level)

Road Safety Act
Goods Vehicle (licensing of
operators) Act

POL-BSFF-0237968_0011
POL00423153
POL00423153

Managed at Group
Level

Pensions Act

Occupational Pensions Regulations
Companies Act

Income & Corporation Taxes Act
Employers Liability (compulsory
insurance) Act

F21 Pensions Policy
(Finance)

3c.

Map of Accountabilities
regulatory area)

- How we sell products & services

[HYPERLINK \1l "P3"]

(by legislative &

Legislative / I Regulator Responsibil I Sub Area (if Supporting statutes / regulations I RM Group Policy Post Office
Regulatory ity applicable) Limited
Area Policy
Product Sales I [ HYPERLINK I Peter Financial Services & Markets Act IR1 Regulation Money
"http://www I Corbett Proceeds of Crime Act F22 Taxation Laundering
.ofcom.org. Finance Consumer Credit Act $2 Criminal Policy
Director VAT Act Investigation &

uk/" ]

[ HYPERLINK

Communications Act

Prosecution Policy

POL-BSFF-0237968_0012
POL00423153

POL00423153
“http://www I Gary Hockey I Fairness in Unfair Contract Terms Act (client IG4 Competition Law
shmre.gov.u I Morley Trading and customer contracts) Compliance
k/mlr/" ] Marketing Unfair Terms in Consumer Contract I (including G4a &
Director Regulations G4b)
[ HYPERLINK Disability Discrimination Act GS Conflicts of
"http://www (products) Interest ;
Sale and Supply of Goods Act G16 Insider Dealing
-fsa.gov.uk Supply of Goods (implied terms) G18 Mergers &
uy Act Associations
Trade Description Act G21 Corporate
[ HYPERLINK Consumer Protection Act Governance of
“http://www Control of Misleading Subsidiary,
.tradingsta Advertisements Act Associate & Joint
ndards.gov. Venture Companies
uk/" ] (including G2la &
G21b)
G23 Creation of new
{ RYPRRL INK subsidiaries & Joint
“http://www Venture Companies
.oft.gov.uk
vf" 9 { HYPERLINK
"http://iplatform.in
tranet.point/rmg/Ser
vices/Compliance/Car
tel+News+Story.htm"
]

Competition [ HYPERLINK I Paula Promotion of Enterprise Act (Subpostmaster ( HYPERLINK [ HYPERLINK
“http://www I Vennells Competition Relationships) "http://iplatform.in I "http://ipl
.competitio I Network tranet.point/rmg/Ser I atform.intr
n= Director vices/Compliance/" ] I anet.point/

Sood rmg/pol/Inft
commission.
1 ormation/Po
org.uk/™ J liciestand+
Guidelines/
Restriction
s+Policy.ht
nm")
Gary Hockey Competition Act / Law (Post Office IG2 Benchmarking &
Morley Limited Products) Exchanging
Marketing information with
Director outside
organisations
G4 Competition Law
Compliance

POL-BSFF-0237968_0013
POL00423153
POL00423153

Intellectual

Gary Hockey

Copyrights & Related Rights

IPl Intellectual

Property Morley Databases Act Property
Marketing Trademarks Act G29 Observing
Director copyright when using
external sources of
information
Legislative / I Regulator Responsibil I Sub Area (if Supporting statutes / regulations I RM Group Policy Post Office
Regulatory ity applicable) Limited
Area Policy
{ HYPERLINK Paula Relating to { HYPERLINK G19 Management of { HYPERLINK
/ftp.roy I [ HYPERLINK I Vennells Mails Integrity I "ftp://ftp.royalmail.com/Downloads I the relationship http: //ipl
almail.com/Dow I "nttp://www I Network /public/ct£/rmg/Royal Mail Licence I with Postcomm atform.intr
nloads/public/ I postcomm.g I Dizector _25 May __2006.pd£" ] [ HYPERLINK anet.point/
ct£/rmg/Royal ov.uk/" J Mails Integrity - Postcomm "http: //iplatform- ymg/pol/Inf

Mail Licence 2
5
May__2006.pdé"

Postal Services Act

sp.intranet.point/si
tes/Compliance-
library/Published
Documents/Shared
Documents/4447 RM
Comp bk AS _6.pd£" ]
( HYPERLINK
"http://www. royalmai
lgroup.com/portal/zm
g/jump1?catId=232005
29&mediaId=23200532"
]

ormation/Po
liciestand+
Guidelines/
Mails+Integ
rity+Policy
+Documents.
htm" ]

Relating to
protection of
34 party
interests

[ HYPERLINK
ftp://£tp.royalmail.com/Downloads
/public/ctf£/rmg/Royal_Mail_Licence
_25 May__2006.pd£" ]

(HYPERLINK
"http://iplatform.in
tranet.point/rmg/Ser
vices/Compliance/Con
dition+10/"]

( HYPERLINK

"http://iplatform.in
tranet.point/rmg/Ser
vices/Compliance/" ]

Gary Hockey
Morley
Marketing
Director

Relating to
Access

[ HYPERLINK
tp://f£tp.royalmail.com/Downloads
/public/ct£/rmg/Royal_Mail_Licence
_25 May__2006.pd£" ]

( HYPERLINK
"http://iplatform.in
tranet.point/rmg/Ser
vices/Compliance/Pol
icies/" ]

POL-BSFF-0237968_0014
3d.

Map of Accountabilities - How we operate (by legislative & regulatory area)

[HYPERLINK \1l "P3"]

POL00423153
POL00423153

Legislative /
Regulatory
Area

Regulator

ET
Responsibili
ty

Sub Area (GE
applicable)

Supporting statutes / regulations

RM Group Policy

Post Office
Limited
Policy

POL-BSFF-0237968_0015
POL00423153

POL00423153
Health & Debbie Moore I Procedural Health & Safety at Work Act P4 Health & Safety

Safety HR Director I aspects Employers Liability Act I HYPERLINK
Offices, shops & Premises Act "https: //ww
RIDDOR regulations w.postoffic
Occupiers Liability Act eintranet.c
H&S Information for Employees o.uk/teams/
regulations usemanual.a

Working Time Directive sp" ]

Six Pack Regulations
" Management of H&S at work [ HYPERLINK
[ HYPERLINK =" Display Screen Equipment. "http://ipl
“http://www * Provision & use of work atform.intr
-hse.gov.uk related equipment anet.point/
/index.htm" " Workplace health, safety « rmg/pol/Inft
] welfare ormation/Po
= Personal protective equipment iiciest+and+
ak work Guidelines/
" Manual handling HostagetPol
icy.htm" J
Premises Fire Precautions Act P4 Health & Safety

aspects H&S First Aid regulations F8 Fire Safety I HYPERLINK
Electricity at Work regulations G14 Disabled "https: //ww

Control of Substances hazardous to
health regulations

Control of Asbestos at work
regulations

Health Act 2006

Disability Discrimination Act
(access to premises)

Noise at Work regulations

Customers

w.postoffic
eintranet.c
o.uk/teams/
usemanual.a
sp" ]

[ HYPERLINK
"http://ipl
atform.intr
anet.point/
rmg/pol/Inft
ormation/Po
licies+and+
Guidelines/
Suspect+pac
kages+intro
shtm" J

POL-BSFF-0237968_0016
POL00423153

POL00423153
Data & [ HYPERLINK G30 Freedom of [ HYPERLINK
Information “"http://iplatform.intranet.point/rm I Information "http://ipl

g/pol/Information/Policies+and+Guid I G6 Document
elines/Freedom+of+Information+Act.h Retention

tm" J

Document Retention Act

Computer Misuse Act
Official Secrets Act
Welsh Language Act

Public Interest Disclosure Act

(including Géa &
G6b)

G12 Welsh Language
P6 Use of
Information &
Information Systems
G7 Employee
Disclosure
(Whistleblowing)

atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Employee _Di
sclosure_Po
licy.htm™ ]
I HYPERLINK
"http://ipl
atform.intr
anet.point/
xmg/pol/Inf
ormation/Po
liciestand+
Guidelines/
Welsh+Langu
age+Guideli
nes.htm" ]

Legislative /] Regulato I ET Sub Area (if Supporting statutes / RM Group Policy Post Office
Regulatory x Responsibility I applicable) regulations Limited
Area Policy
Data & Gary Hockey Client Contracts Public Records Act CS9 Acceptable
Information Morley Partnerships with

Marketing Trusted Third Parties

Director

David Glynn Sales & Direct Data Protection Act G13 Data Protection HYPERLINK
Sales Director I Channels Act http://ipl
T15 Intranet atform.intr
Exploitation anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet+
Ltd/Policy/
Data_Protec
tion_Act.ht
nm" ]
Mike Young Purchasing Public Records Act Fé Liability in
Operations Contracts Purchasing Contracts

POL-BSFF-0237968_0017
POL00423153

POL00423153
Director Information Security Sl Information [ HYPERLINK
Security "http://ipl

$10 Clear Desk Policy
$16 Third Party Access
Policy

73 Royal Mail Anti
Virus

atform.intr
anet.point/
rmg/pol/Int
ormation/Po
licies+and+
Guidelines/
Clear+Desk+
policy.htm"

HYPERLINK
"http://ipl
atform.intr
anet.point/
xmg/pol/Inf
ormation/Po
licies+and+
Guidelines/
Information
+Security+P
olicy.htm"

Private Security Act

Public Procurement Regulations
Unfair Contract Terms Act (re:
procurement contracts)

VAT Act (purchasing)

Sale & Supply of Goods Act (re:
purchasing)

Public Records Act (re:
purchasing)

Fl Authority to
Requisition, Procure &
Pay

F2 Procurement Policy
[I HYPERLINK

“http: //iplatform.intr
anet.point/rmg/Service
s/How2Buy/3Buy" ]

POL-BSFF-0237968_0018
POL00423153

POL00423153
Employment Debbie Moore Terms & Cond Unfair Contract Terms Act G3 Code of Business [ HYPERLINK
HR Director (employment contracts) Standards "http://ipl

Fixed Term Workers Directive
Employment Act

atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Recruitment
cy-htm

I HYPERLINK
"http://ipl
atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Flexible Wo
rking_Polic

y-htm" ]
Relations Employment Relations Act [ HYPERLINK
Trade Union & Labour Relations "http://ipl

Act
TUPE Regulations

atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet+
Ltd/Industr
ial_Relatio
ns.htm" ]

POL-BSFF-0237968_0019
POL00423153
POL00423153

Discrimination

Equality Act

Race Relations Act

[ HYPERLINK

“http: //iplatform.intranet.point
/rmg/pol/Information/Policies+an
d+Guidelines/Disability+Discrimi
nation+Act.htm" ]

Human Rights Act

Protection from Harassment Act
Sex Discrimination Act

Equal Pay Act
Employment Equality
Regulations
National Minimum Wage Act 1998
(National Minimum Wage
Regulations 1999)

(Age)

P5 Equal Opportunities
- Diversity &
Inclusion

Valuing Diversity
Policy v1.1

[ HYPERLINK
"http://ipl
atform.intr
anet.point/
rmg/Service
s/HR+Help/P
ost+0fficet
Ltd/Policy/
Harassment _
and_Bullyin
g_Policy.ht
m" J

Legislative /

Regulatory
Area

Regulato

ET
Responsibility

Sub Area (if
applicable)

Supporting statutes /
regulations

RM Group Policy

Post Office
Limited
Policy

Other
(Managed at
Group Level)

Royal Mail
Company
Secretary's
Office

Highways Act
Environment Protection Act

G17 Royal Mail
Environmental Policy

[I HYPERLINK
"http://iplatform.intr
anet.point/rmg/Service
s/CSR+Environment/CSR+
Environment htm" ]

Property related
legislation
(Managed at Group
Level)

Town & Country Planning Act
Property Act

Land Registration Act
Landlord & Tenants Act
Occupiers Liability Act

Vehicle related
legislation
(Managed at Group
Level)

Road Safety Act
Goods Vehicle (licensing of
operators) Act

Managed at Group
Level

Pensions Act

Occupational Pensions
Regulations

Companies Act

Income & Corporation Taxes Act
Employers Liability (compulsory
insurance) Act

F21 Pensions Policy
(Finance)

Note 1:

This list should not be taken as definitive or exhaustive,

an annual basis to moderate any changes to legislative and regulatory requirements.

and will need to be reviewed on

POL-BSFF-0237968_0020
POL00423153
POL00423153

Note 2: The Royal Mail Group Policies can be located using the following link - [ HYPERLINK
"http: //domino.point/POLICYLI.nsf/pgFrameTickerNone?openpage &docid=BB982DF613AEF68D802571CA00299D6
E" ]

POL-BSFF-0237968_0021
4. Assurance
[HYPERLINK \1l "P3"]

This compliance framework forms part of the Post Office’s
Governance processes.

The Board and other stakeholders will gain assurance in
respect of the extent of compliance across the business
and the appropriateness of controls through: -

* Periodic self assessment activities performed by
identified owners

* Independent validation work, performed by Royal Mail
Internal Audit & Risk Management (IARM). IARM manage
the validation of critical business processes across
the Royal Mail Group and Post Office's identified
critical business processes include a key sub
process of Regulation and Legislation.

* Activities performed by the Compliance Team (as set
out in the Annual Assurance Plan)

* Monitoring by the Risk & Compliance Committee (a sub
committee of the Board) as set out in the terms of
reference for the committee

The self-assessment and independent validation processes
referred to will be signed off by the Managing Director
and reported to the Corporate Risk Management Committee.
This will enable the Post Office to provide its statutory
declaration on risk and control in its annual report

5. Disciplinary Statement
[HYPERLINK \l "P3"]

Compliance with legal and regulatory requirements is not
optional and disciplinary measures will be applied in
cases of wilful, persistent or negligent non-compliance.
The Royal Mail Group Employee Disclosure (Whistleblowing)
Policy (G7) and Post Office Limited Employee Disclosure
Policy that allows for anyone in the Business to raise
any suspected non-compliance without fear of detriment or
reprisal

6. Contact
(HYPERLINK \1l "P3"]

Initial contact or any questions regarding the content of
the Compliance Framework should be directed to Keith
Woollard (Head of Compliance).

@

_
{

Bxeith.woollard

POL00423153
POL00423153

POL-BSFF-0237968_0022
POL00423153

POL00423153
Appendi Seep £ fram k [HYPERLINK
\l "P3"]
Appendix - Scope of framework [HYPERLINK
\1 "P3"]
Note 8 Bundle of
2 — Bundle of OTHER: MANAGED AT GROUP LEVEL Sbaiites /regiaians
7regulations ° = . -Town & Country Planning Act
@ Safety at Work Act Pensions Act / Occupational Pension -Property Act
-Employers Liability (Defective Regs -Land Registration Act
Equipment) Act @ companies act -Landlord & Tenants Act
-Offices, Shops and Premises A Income & Corporation Taxes Act -Occupiers’ Liability Act
Ox ane cl ener
-RIDDOR regulations Peete a tdaniite {eoapelaaey
-Occupiers’ Liability Act fe) “ Note 9 - Bundle of
-H&S Information for Employees Property Related Legislation (bundle ‘statutes/reguiations 3- Bundle _of
regulations -Road Safety Act regulatio
-Working Time Directive -Goods Vehicles (Licensing of -Unfair Contract Terms Act
-"six Pack” regulations HEALTH & SAFETY >) (re: employment contracts)
-Management of Health & [ ) -Fixed Term Workers
safety at work Bega cin, Aspects Teal Directive
-Display Screen Equipment ry semi Ne / enepnevemier \
-Provision & use of work Building Aspe: (bundle r) .
see Note 2) Temis @ Condleieos Note 4- Bundle of
D (bundle - see Note 3) statutes/regulations
Note 2 ~ Bundle of Employment Relations =Employment Relations
stat’ (bundle — see Note 4) -Trade Union & Labour

-Fire Precautions Act
-Health & Safety (First Aid)
Regulations

“Electricity at Work Regulations
Control of Substances Hazardous
to Health Regulations
-Control of Asbestos a’
Regulations

-Health Act 2006
-Disability Discrimination Act

Work

INTELLECTUAL

ROPERTY

Copyrights & Related Rights
Databases Act

PROCUREMENT

@ vutic Procurement
Regulations

KEY

@ potentially Very High Impact

£ Breached

@ potentially High Impact if
Breached

Potentially Medium Impact if

Breached

~\

DATA & INFORMATTO
@ data Protection act
@ public Records Act

@ Freedom of Information
Act

@ document Retention
(act)

@ computer Misuse Act
Official Secrets Act

LEGISLATI
VE
AND
REGULATOR
YX
OBLIGATIO
NS

procuremen’

Sale & Supply of Goods Act

purchasing)

(x

(ret

@ Financial services «

@ vroceeds of Crime Act

Consumer Credit Act
Communications Act
Fairness
(bundle ~ see Note 7)
VAT Act

© discrimination (bundle -
see Note 5

5)

ROYAL MAIL LICENCE CONDITIONS

Freedom of Information Act

® document Retention (Act)

@ private security Act

XY

Relations Act

Note 5- Bundle
statutes/regulations

-Equality Act

-Race Relations Act

Disability Discrimination

Act (re: employment)

-Human Rights Act

COMPETITION
@ Promotion of Competition
(bundle — see Note 6)

Note 6 - Bundle of
tatutes/regulatiot

Competition Act

-Enterprise Act

PRODUCT SALES

in Trading

Note 7 ~ Bundle of
-Unfair Contract Terms Act (re:
ient & customer contracts

-Unfair Terms in Consumer Cor
Regulations
-Disability Discrimination Act
(re: Products)

-Sale & Supply of Goods Act

“" BOL-BSFF-0237968" 0023

Document Control

POL00423153
POL00423153

Version 1

18/03/2009

Rob Bolton

Final version produced

following input from Risk &
Assurance Manager, Head of
Compliance & Communications

POL-BSFF-0237968_0024