68 SECTION 04 : CORPORATE GOVERNANCE Statement On Risk Management And Internal Control (Cont’d) RISK MANAGEMENT (CONT'D) Risk Appetite and Tolerance The Board has established a Risk Appetite and Risk Tolerance Framework to guide the management of risks in achieving the Group’s strategic and operational objectives. The framework defines the nature and level of risks that the Group is willing to accept in pursuit of value creation, while ensuring that material risks remain within acceptable limits. The Group’s risk appetite is established at the enterprise level and is cascaded, where appropriate, to key business units, functions and operational activities. Risk tolerance thresholds are defined for significant risk categories to facilitate consistent risk evaluation, monitoring and escalation across the Group. The Risk Appetite and Risk Tolerance Framework support Management’s decision-making, resource allocation and prioritisation of risk mitigation measures. It also serves as a basis for assessing whether identified and emerging risk exposures remain within the parameters approved by the Board. Emerging Risk Surveillance The Group recognises that the external business environment and risk landscape are dynamic and continuously evolving. Accordingly, the Group has established processes for the identification, assessment and monitoring of emerging risks as an integral part of its enterprise risk management framework. Emerging risks are identified through a combination of environmental scanning, regulatory developments, industry and market analysis, internal audit reviews, management deliberations and periodic risk assessment workshops. Potential emerging risks are evaluated based on their likelihood and potential impact and, where relevant, are incorporated into the Group’s risk register, KRIs and risk mitigation plans. The Group continuously monitors a range of emerging risk areas that may affect the achievement of its strategic and operational objectives, including: • regulatory and policy developments affecting the Group’s business sectors; • environmental, social and governance (“ESG”) matters, including climate-related risks and evolving stakeholder expectations; • cybersecurity, data privacy and technology-related risks; and • supply chain disruptions, geopolitical developments and foreign exchange volatility. To support proactive risk management, the Group has established KRIs and risk tolerance thresholds for its principal risk categories. KRIs are monitored through periodic management reports and operational dashboards, with significant changes or breaches of approved thresholds escalated to the appropriate level of governance in accordance with the Group’s risk escalation framework. Principal Risk Category ERM Risk Theme Risk Appetite Illustrative Key Risk Indicators (KRIs) Escalation Level Strategic Risk Management Business Expansion and Portfolio Diversification Moderate • Strategic plan variance, customer or main contractor disputes, delays in entering targeted markets or business segments MPR / Board Environmental, Health, Safety and Regulatory Compliance ESG, Compliance and Operational Safety Low • Lost Time Injury Frequency Rate (LTIFR), regulatory non-compliance findings, environmental incidents or near misses ARMSC / Board Project Completion and Execution Project Execution and Delivery Low to Moderate • Project cost and schedule variances, subcontractor performance and contractual disputes MPR Transaction Approval and IT General Controls Financial Reporting and Information Technology Controls Low • System overrides, unauthorised or post-period transactions, and IT general control exceptions ARMSC
RkJQdWJsaXNoZXIy NDgzMzc=