ReShopMe Limited — Risk Policy and Standard
Version 2.0 · Effective 28 July 2026
Preamble
This document sets out ReShopMe's approach to risk analysis and management, referred to as the Risk standard. It provides the framework by which the company complies with its Risk policy.
ReShopMe operates an online marketplace for preloved goods. Our business depends on the trust of the people who buy and sell through it, and on our ability to keep their money, their goods and their personal information safe as they pass through our hands. We recognise that uncertainty creates opportunity as well as threat, and that the threats which matter most to us are those that would harm a customer, breach a legal obligation, or lose the confidence of the market we are building.
Every person in the company has a part to play in managing risk.
Risk policy
ReShopMe recognises that risk is an integral and unavoidable component of our business, and is characterised by both threat and opportunity.
The Company fosters a risk-aware culture in all decision making. Through consistent, good-quality risk analysis and management, we exploit risk to enhance opportunities and reduce threats.
We are committed to managing risk proactively. That requires analysis good enough to inform the decisions taken at every level of the company.
Risk analysis is applied to all parts of the business, following the principles set out in this Risk standard.
Risk standard
Introduction
Risk analysis and management is undertaken as a source of sustainable business benefit. It also serves our compliance obligations. As a New Zealand company operating a marketplace that holds customer funds, the obligations that bear on our risk analysis are:
- the Companies Act 1993, and the duties it places on directors;
- the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, under which we are a reporting entity supervised by the Department of Internal Affairs, and which requires a written risk assessment under section 58;
- the Privacy Act 2020 and its Information Privacy Principles;
- the Fair Trading Act 1986 and the Consumer Guarantees Act 1993;
- Australian consumer law, so far as it applies to our Australian customers;
- our contractual obligations to payment providers and carriers, including the security and compliance conditions on which those services are supplied.
A common approach must be applied across the business. This Standard sets the minimum framework; specific areas may build on it where that produces a better result. Where an existing practice does not conform, it must be brought into conformity within a reasonable period.
The process
Risk analysis and management follows six steps:
- Risk process initiation
- Risk identification
- Risk evaluation
- Risk management
- Risk reporting
- Risk updates
1. Risk process initiation
A suitably competent person must be nominated to lead each analysis. That person must:
- define the scope and context, stating explicitly what is in and out of scope;
- determine which objectives are at risk;
- define the methodology, tools and techniques;
- identify who participates, with roles and responsibilities;
- define the likelihood and consequence scales, and the risk acceptance thresholds;
- describe the reporting and update cycles.
These outputs must be documented in a risk analysis plan.
Risk acceptance thresholds determine the level of risk that can be tolerated. Risks are classified against them into one of four Risk Management Classes:
- Class I — below the acceptance threshold; no active management required.
- Class II — on the threshold; requires active monitoring.
- Class III — exceeds the threshold; requires proactive management.
- Class IV — significantly exceeds the threshold; requires urgent and immediate attention.
These apply equally to threats and to opportunities. Every risk identified must be mapped to one of them.
2. Risk identification
The aim is to expose and document all currently knowable risks affecting the objectives, both threats and opportunities.
As a minimum, a facilitated identification session must be held with the people who know the area. Care must be taken to separate risks from their causes and their effects.
After initial identification, the possibility of risk aggregation must be considered — risks that are individually tolerable but which, taken together or arising from a common cause, are not. Aggregated risks are recorded for special attention and evaluated urgently.
Risks must be recorded in a Risk register. Evaluation must not be performed during identification, so that it does not bias what gets recorded.
3. Risk evaluation
The likelihood and consequences of each risk must be assessed using the predefined scales, and each risk classified and prioritised against the acceptance thresholds. A 4×4 matrix is preferred; 3×3 and 5×5 are permitted where justified. Asymmetric matrices are not permitted.
Economic consequences must be scaled to the size of what is at stake. Every analysis must consider at least:
- Revenue and commission — lost sales, lost take rate, customers who leave;
- Direct loss — refunds, upheld claims, chargebacks and fees borne by us;
- Working capital — funds tied up in escrow, reserves and holds;
- Remediation cost — engineering, professional advice, or a forced change of provider;
- Cost of capital and runway — the effect on a pre-revenue or early-revenue balance sheet, where a loss that a larger company would absorb may not be absorbable here.
Non-economic consequences cannot be scaled. Every analysis must consider at least:
- Customer harm — financial loss to a buyer or seller, or goods lost;
- Personal safety and wellbeing — harassment, threats or abuse through messaging, calls or livestreams, and the safety of our own people;
- Privacy and data — exposure or misuse of personal information;
- Regulatory and compliance — breach of a statutory obligation, or the loss of a supervisor's or provider's confidence;
- Trust and reputation — the marketplace's standing with buyers, sellers, providers and investors;
- Service availability — the platform, payments or delivery not working.
Evaluation must be undertaken by people with relevant knowledge of the area, and consensus should be sought. External expertise must be obtained where the subject matter requires it — including legal, tax and AML/CFT advice.
Special attention must be paid to risks of very high consequence and very low likelihood. For ReShopMe these include: a breach exposing customer personal or identity information; a sustained failure of payment acceptance or of payouts; a systemic seller-fraud event; the loss of a payment provider or acquirer relationship; and regulatory intervention. They also include aggregation risks arising from several related causes. Such risks must be recorded in the Risk register as special cases and treated immediately.
Quantitative methods may be used where appropriate.
4. Risk management
Appropriate responses must be determined and implemented for each risk. Threats must be avoided, transferred or minimised; opportunities must be exploited, shared or enhanced. Where no active response is possible, the residual risk must be accepted with a suitable level of contingency.
The cost effectiveness of each response must be assessed before it is agreed. Each agreed response is allocated to a single risk owner, with the resources needed to implement it. Secondary risks arising from a response must be considered. Progress must be monitored, and where a response is not achieving its intended result, further responses must be developed.
Agreed responses are recorded in the Risk register with their status.
5. Risk reporting
Results must be documented and reported to the board. Every analysis must produce a Risk register containing, for each risk:
- unique reference number
- date of last update
- brief title
- description
- likelihood
- assessment of all consequence types
- risk level, from the likelihood and the highest consequence
- risk responses, candidate and agreed, with status
- control status — built, in build, or not started
- risk owner
The register must retain closed risks, to provide an audit trail and to inform future analyses.
6. Risk updates
Every analysis must be updated in light of progress and developments. Updates must reflect the results of responses implemented, and identify risks that have emerged since the last update. All risks must be re-examined to confirm that previous Class I and Class II risks have not developed a higher profile.
Analyses must be reviewed at least annually, and whenever there is a material change to the business, its products, its providers or its regulatory position.
Definitions
Consequence — the outcome of a risk if it occurs. Threats have unfavourable consequences, opportunities favourable ones. Consequences are economic or non-economic.
Inherent risk — the risk as originally identified, before controls.
Likelihood — the chance that a risk will occur, as a probability for a single event or a frequency for repeat events.
Opportunity — a positive risk; an uncertain beneficial event or condition which, if it occurs, results in favourable outcomes such as saved cost, improved customer trust or enhanced reputation.
Residual risk — the risk remaining after agreed controls are implemented.
Risk — an uncertain event or condition which, if it occurs, will affect achievement of one or more objectives.
Risk acceptance threshold — the level of exposure above which action must be taken, and below which risk may be accepted.
Risk aggregation — the combination of individually tolerable risks into an intolerable one, through interdependence or common cause.
Risk analysis — the overall process of identification and evaluation.
Risk evaluation — estimating likelihood and consequences, and comparing against the acceptance threshold.
Risk identification — a structured process to identify threats and opportunities.
Risk management — taking decisions and implementing actions in response to known risks.
Risk register — the record of identified risks, their evaluation, their agreed responses and their owners.
Threat — a negative risk; an uncertain adverse event or condition which, if it occurs, results in unfavourable outcomes such as customer loss, harm to a person, breach of a legal obligation, damage to reputation, or economic loss.