ENRA Group Berhad Annual Report 2026

66 SECTION 04 : CORPORATE GOVERNANCE Statement On Risk Management And Internal Control (Cont’d) GOVERNANCE STRUCTURE (CONT'D) Management Management is responsible for the design, implementation and day-to-day operation of the Group’s risk management and internal control systems. This includes maintaining the risk register, monitoring key risk indicators, evaluating control effectiveness, and implementing corrective actions. Management also provides periodic assurance to the Chief Executive Officer on the effectiveness of controls within their respective areas of responsibility. RISK MANAGEMENT The Group adopts an integrated and organisation-wide approach to risk management, where the ownership and management of risks are embedded across all levels of the organisation. The framework combines both topdown and bottom-up approaches to ensure that strategic, operational, financial and emerging risks are identified, assessed, monitored and managed in a holistic and timely manner, thereby supporting the achievement of the Group’s business objectives. The Group’s risk management framework is supported by a clearly defined governance structure involving the Board, the ARMSC, the Executive Risk Management Committee (“ERMC”), the Internal Audit Function and the Risk Management Units (“RMUs”), each with distinct roles and responsibilities in overseeing and managing risks across the Group. The respective reporting lines and responsibilities are illustrated in the Risk Management Responsibilities diagram below. Risk Management Structure Risk Management Responsibilities BOARD OF DIRECTORS STAKEHOLDERS BOARD MANAGEMENT EMPLOYEES AUDIT, RISK MANAGEMENT AND SUSTAINABILITY COMMITTEE EXECUTIVE RISK MANAGEMENT COMMITTEE RMU RMU RMU Risk Oversight (2nd Line of Defence) Internal Audit (3rd Line of Defense) DAY-TO-DAY RISK MANAGEMENT (1st Line of Defense) RMU • Risk management - policy - Philosopy • Establish structured risk management system • Ensure accountability • Risk aware culture • Risk pro le • Issues to emerge • Current risk pro le • Action plans The Board oversees the Group’s risk management framework with the assistance of the ERMC and the Internal Audit Function. The Board reviews the effectiveness of the framework periodically to ensure that key risks are identified, assessed, monitored and managed in a systematic and consistent manner. The ERMC, which is chaired by the President & Group Chief Executive Officer and comprising members of management, with the Head of Internal Audit serving as the Risk Coordinator, meets on a quarterly basis to review the Group’s risk profile, key risk exposures and the adequacy of risk mitigation measures. The ERMC is responsible for identifying and communicating significant risks and changes in risk exposures to the Board, together with Management’s action plans to manage such risks.

RkJQdWJsaXNoZXIy NDgzMzc=