“We needed a better standard for entity-level and management controls,” Bendermacher says. “We
used the COSO framework, and added Sarbanes-Oxley and Basel II controls, as well as corporate gov-
ernance compliance policies, business continuity planning and corporate security. From all this came
the Robeco Management Control Framework that we use to assess the management controls of all
entities in Robeco.”