Al-`Aqar Healthcare REIT Annual Report 2021

STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL 15. The Manager undertakes adequate insurance coverage on both its employees and assets to ensure both are sufficiently insured against any losses arising from various perils faced in the Manager’s/ Fund’s operations. 16. TheManager has, inplace theKPI reporting todrive awareness of sharedmanagement responsibility on their contribution towards enhancing the operating performance in achieving the business objectives. 17. Internal audit is outsourced to ensure independence in audit function, which include performing regular reviews of business processes to assess the effectiveness of the internal control system and to highlight significant risks impacting the Company with recommendations for improvement. The internal audit team reports directly to the BARC. 18. Evaluations of outsourced service providers on critical business functions are carried out on a yearly basis and presented to the Board. 19. Senior management team conducts regular discussions with property, maintenance, and service managers to discuss issues for improvement and to promote better understanding to facilitate cognizance in decision-making capability. During the year under review, three (3) meetings with the Maintenance Manager were carried out on 5 April, 11 August and 22 December 2021. 20. The Manager launched its Anti-Bribery & Corruption Framework and the Whistleblowing Policy effective 1 June 2020, which is guided by the Guidelines on Adequate Procedures issued under section 17A(5) of the MACC Act to mitigate corruption and integrity risks. 21. On 7 September 2021, the Personal Data Protection (“PDP”) Policy was tabled and approved by the Board to provide assurance to its data owners – tenants, directors and employees that their personal data will be safeguarded and protected by the Fund. 22. The Board, on 2 December 2021 has also approved the Anti-Money Laundering and Anti-Terrorism Financing Policy and undertakes the following approach: (a) Compliance with laws: Service is not provided where there is good reason to suppose that transactions are associatedwithmoney laundering (“ML”) or terrorist financing (“TF”) activities. (b) Co-operation with law enforcement agencies: The Management and the Board must co-operate fully with relevant law enforcement agencies. This includes taking appropriate measures such as timely disclosure of information to relevant law enforcement agencies. (c) Establishing internal controls: Issue and adopt policies and procedures which are consistent with the principles set out under the AMLA and these Guidelines, which include ongoing training programmes to keep its board of directors, the management and employees abreast on matters under the AMLA and SC AMLA Guidelines. (d) Risk-based approach: Ensure that the depth and breadth of its policies and procedures to identify, assess, monitor, manage and mitigate risks commensurate with the nature, scale and complexity of its activities. (e) Customer Due Diligence: Have an effective procedure to identify its customers and to obtain satisfactory evidence to verify its customers’ identity. 23. The Group has established processes and procedures to ensure the quarterly and annual reports, which cover the Group’s performance, are submitted to Bursa Malaysia for release to shareholders and stakeholders on a timely basis. All quarterly results are reviewed by the Board prior to their announcements. The Annual Report of the Group is issued to the shareholders within the stipulated time as prescribed under the MMLR of Bursa Securities. GOVERNANCE STRUCTURE 123 STRATEGIC PERFORMANCE FINANCIAL REPORTS CORPORATE OVERVIEW THE DRIVING FORCES SUSTAINABILITY STATEMENT

RkJQdWJsaXNoZXIy NDgzMzc=