ENRA Group Berhad Annual Report 2026

67 ANNUAL REPORT 2026 ENRA GROUP BERHAD Statement On Risk Management And Internal Control (Cont’d) RISK MANAGEMENT (CONT'D) The Group’s risk management framework is guided by its Risk Management Policy and Manual, which sets out the principles, governance structure and processes for managing risks across the organisation. In support of this framework, RMUs have been established at the subsidiary and operational levels to facilitate the identification, assessment, monitoring and reporting of risks to the ERMC on a quarterly basis. The Group adopts an Enterprise Risk Management (“ERM”) framework based on recognised risk management principles, including ISO 31000 and the COSO Enterprise Risk Management Framework. The ERM framework incorporates the Three Lines Model, under which: • the first line of defence comprises process owners and heads of business units and support functions, who are responsible for identifying and managing risks within their respective areas of accountability; • the second line of defence comprises the RMUs and the ERMC, which provide oversight, coordination and challenge over risk management activities, monitor the effectiveness of controls and mitigation measures, and review the progress of action plans; and • the third line of defence is provided by the Internal Audit Function, which reports directly to the ARMSC and provides independent assurance on the adequacy and effectiveness of the Group’s risk management and internal control systems. The Group applies a structured and continuous risk management process that is aligned with the principles and guidelines of ISO 31000. The process encompasses the identification, assessment, analysis, evaluation, treatment, monitoring and reporting of risks, supported by ongoing communication and consultation across the organisation. The key stages of the Group’s risk management process are illustrated in the diagram below. PRINCIPLES FRAMEWORK PROCESS A. Creates and protects value B. Intergral part of organisational processes C. Part of decision making D. Explicity addresses uncertainty E. Systematic, structured and timely F. Based on the best available information G. Tailored H. Take human and cultural factors into account I. Transparent and inclusive J. Dynamic, interactive and responsive to change K. Facilitates continual improvement and enchancement of the organisation Mandate and commitment Design of framework for managing risk Monitoring and review of the framework Continual improvement of the framework Implementing risk management Risk assessment Establishing the context Risk analysis Risk identi cation Risk ovaluation Risk treatment Monitoring and review Communication and consultation Risk Management based on ISO 31000

RkJQdWJsaXNoZXIy NDgzMzc=