Responsible business
Responsible business
At MMS, we’re focused on corporate governance, risk management and a culture that supports responsible business conduct. This is crucial to being a trusted partner to our customers, clients and stakeholders and to delivering our strategy.
Responsible business at MMS
Governing and conducting business responsibly
Ethical business practices
Our Code of Conduct provides clear guidelines on ethical conduct and the standards of behaviour expected from our employees, contractors and directors. The Code is supported by policies that guide our approach to responsible business conduct.
Compliance training is provided to all MMS employees and contractors to build their awareness and understanding of our policies and their obligations.
Regular reviews of our policies are carried out to assess their effectiveness, uphold ethical standards and compliance obligations and are up to date with evolving stakeholder and regulatory expectations.
MMS’ Whistleblower Policy outlines how employees and stakeholders can raise grievances and do so without fear of reprisal. The Board receives regular summary reports about whistleblower disclosures where they are received by MMS. These reports are provided in a way to address confidentiality of any Whistleblower. One grievance was reported during FY25.
Policies that support our Code of Conduct:
- Acceptable Use of IT Systems Policy
- Anti-Bribery and Anti-Corruption Policy
- Conflicts of Interest Policy
- Equal Opportunity and Diversity Policy
- Privacy Policy
- Responsible Artificial Intelligence (AI) Policy
- Securities Trading Policy
- Supplier Code of Conduct
- Whistleblower Policy
- Work, Health and Safety Policy.
Risk culture
The MMS Board recognises that sound risk management is a continual process which is an integral component of good corporate governance and fundamental to the Group fulfilling its purpose, achieving its strategic objectives and maintaining its social license to operate. MMS maintains a Risk Management Framework (Framework) that is based on the guidelines set out in ISO 31000:2018 which provides for a structured and comprehensive approach to identify, analyse, evaluate, treat, record and report material risks to the Group’s strategic and operational objectives.
MMS strives to promote and foster an organisational culture that is risk aware and which is supported by high standards of accountability where employees understand and adhere to their responsibilities for managing risks within the parameters of the Board’s risk appetite and internal policies.
Advocating for better outcomes
We proactively participate in and advocate for public policy reforms that have the potential to impact our business, industry and customers, primarily through the industry organisations that MMS is a member of.
The Group’s public policy advocacy work throughout FY25 related to matters concerning:
- Australia’s transition to zero emission vehicles and decarbonisation of land transport and associated taxation and policy arrangements.
- The Fringe Benefits Tax (FBT) regime as it relates to electric vehicles and chargers.
- Regulatory requirements pertaining to products and services provided by the Group.
- Through our association with AFIA, we submitted feedback on the Anti-Money Laundering and Counter Terrorism Financing Amendment legislative review and the Proposals paper for introducing mandatory guardrails for AI in high-risk settings.
- Senate Select Committee on the Cost of Living specifically regarding novated leasing and salary packaging measures.
- Climate Change, Energy, Environment and Water enquiry into the transition to electric vehicles.
- NDIS reforms and NDIS pricing changes via engagement with the Agency and Government.
Responsible supply chain
MMS is committed to working with our suppliers fairly, transparently and with the highest level of integrity. We are committed to building a diverse supplier portfolio that shares our commitment to sustainability, climate action, diversity and inclusion and making a positive impact on the communities in which we operate.
Our Supplier Code of Conduct outlines our expectation that our suppliers conduct business in an ethical manner and abide by all legislative requirements, including anti-modern slavery, anti-bribery, corruption and money laundering laws as well as having governing policies in place including but not limited to an anti-corruption policy. Our expectations extend to minimising environmental impact, abiding by legislated labour and human-rights requirements and workplace health and safety policies and processes.
As outlined in MMS’ Modern Slavery Statement (PDF), the likelihood of our operations contributing to or being directly linked to modern slavery is considered low. MMS recognises the importance of these issues and as outlined in our Human Rights Position Statement (PDF), our approach to respecting and upholding human rights is informed by the United Nations Guiding Principles on Business and Human Rights.
Safeguarding our information
Managing and protecting the data we hold on behalf of our customers and employees and the integrity of our information systems is critical to maintaining the trust of our stakeholders and meeting our contractual and lawful requirements.
The MMS Privacy Policy governs how we collect and manage personal and sensitive information. This policy applies to the Group’s Australian entities. Our New Zealand entity has its own privacy policies that comply with relevant privacy requirements.
Oversight of privacy and cyber security matters are provided by both Board and Executive-level committees established through our corporate risk management framework and supported by internal and external audits as appropriate. The Chief Information Officer (CIO) leads our cyber security program and continuously reviews and improves security controls. We take a risk-based approach and have a dedicated cyber security team who are supported by threat intelligence providers, external partners, our membership in the Australian Computer Emergency Response Team (AusCERT) and our network partnership with the Australian Cyber Security Centre (ACSC).
Our Group Remuneration Services (GRS) business undergoes annual ASAE 3402 audits, which include testing of IT general controls including logical access, system development and IT change management, physical security, data backup and recovery. Since FY23, Plan and Support Services (PSS) has achieved and maintained ISO 27001 accreditation. During the first half of FY25 our GRS business achieved Systems and Organisation Controls 2 (SOC 2) and ISO 27001 accreditation. All our people are responsible for managing cyber security risks.