Approach to Risk Management
The risk management framework enables early identification and mitigation of risks through a structured hierarchy of controls. It is designed to surface emerging risks, assess interdependencies, and align risk considerations with business objectives, including during product and service development. Streamlined operational processes and optimised resource allocation support efficiency and regulatory compliance. Sustainability is embedded across the framework, with ESG-linked metrics integrated into performance reviews of executives, ESG mentors, and champions.
Monitoring and Review
Governance is reinforced through regular reviews by the Management Risk Committee (MRC), with oversight from the Risk Management Committee (RMC) and the Board of Directors. The Business Risk Team (BRT) and Functional Risk Committees (FRCs) coordinate risk identification, benchmarking, and reporting across business units. Written updates are submitted to the MRC on a monthly basis. Key risk matters are reviewed from a strategic perspective, with meeting outcomes formally reported to the Board.
Assurance of Risk Controls
The framework incorporates periodic internal audits conducted by the Management Audit and Assurance Services (MAAS) team, which reports directly to the Chairman’s office, ensuring independent validation of risk controls. In addition, the Company engages an external third party to review the risk management framework and integrates their recommendations to strengthen processes. Internal audits are conducted annually on a rotational basis across functions to maintain consistent assurance coverage.
Building Risk Culture
Developing Skills and Competencies in Executive Leadership, Operational Team, HoDs, BRT, and FRT
Executive leadership, operational teams, Heads of Departments, the Business Risk Team (BRT), and Functional Risk Teams (FRTs) undergo regular risk management training to strengthen enterprise-wide risk awareness and decision-making. Non-executive directors, drawing on extensive industry experience, remain closely engaged through quarterly briefings on strategic, tactical, operational, and emerging risks, supported by the Board familiarisation programme.
Developing Skills and Competencies in Corporate Responsibility Committee
The Company assesses and develops Corporate Responsibility Committee (CRC) competencies through a structured skill matrix to strengthen sustainability oversight. Internal evaluations, including anonymous member feedback, help identify capability gaps critical to committee effectiveness. Targeted training is then provided on climate-related financial disclosures, evolving regulations, and emerging ESG risks. The CRC also engages with internal and external ESG experts to deepen technical understanding and support informed decision-making. This assessment is conducted biannually.
Developing Skills and Competencies in Employees
All employees receive structured training on the Company’s internal risk framework and risk management system, aligned with ISO 31000. Practical case examples from across functions reinforce how risk principles are embedded into daily operations, supporting consistent application at the operational level.