ENRA Group Berhad Annual Report 2026

69 ANNUAL REPORT 2026 ENRA GROUP BERHAD Statement On Risk Management And Internal Control (Cont’d) RISK MANAGEMENT (CONT'D) Emerging Risk Surveillance Risks that remain within approved tolerance levels are managed by the respective business units through routine monitoring and established control activities. Risks approaching approved thresholds are subject to enhanced management oversight and corrective actions, while material risks or breaches of the Group’s approved risk appetite are escalated to the ERMC and, where appropriate, to the ARMSC and the Board for deliberation and direction. The Group has established a systematic process for the identification, assessment, communication, monitoring and periodic review of risks and the effectiveness of corresponding mitigation measures and controls. Risks are evaluated using a risk impact and likelihood matrix, taking into account the approved risk appetite and tolerance thresholds. These parameters provide a consistent basis for the evaluation, prioritisation and treatment of identified risks, and support the timely escalation of significant risk matters to the ERMC and the Board. The Group’s activities are exposed to a broad range of risks, including operational, financial, strategic, human capital, information technology, procurement, regulatory, political, sales and marketing, and health, safety and environmental risks. Relevant policies, procedures and reporting mechanisms are in place to support the effective management and disclosure of these risks across the Group. Risk management is an ongoing and iterative process. The Group continually reviews and enhances its risk management practices to ensure that the framework remains effective and responsive to changes in the operating environment, emerging risks and evolving stakeholder expectations. INTERNAL AUDIT FUNCTION The Group maintains an in-house Internal Audit Function that provides the ARMSC and the Board with independent and objective assurance on the adequacy and effectiveness of the Group’s governance, risk management and internal control processes. The Internal Audit Function operates in accordance with the Global Internal Audit Standards issued by the Institute of Internal Auditors (“IIA”) and is guided by its Internal Audit Charter, which is approved by the ARMSC. In carrying out its responsibilities, the Internal Audit Function adopts a risk-based audit approach and utilises the COSO Internal Control – Integrated Framework as a guide in evaluating the effectiveness of the Group’s internal control system. The Internal Audit Function assesses the adequacy and effectiveness of the Group’s internal controls based on the following five interrelated components of the COSO Framework: • Control Environment • Risk Assessment • Control Activities • Information & Communication • Monitoring Activities The Internal Audit Function is headed by Mr. Melvinder Singh Harminder Singh, Group Head of Compliance & Governance, who is a Chartered Member of the Institute of Internal Auditors Malaysia with more than 20 years of experience in internal auditing. The Internal Audit Function reports functionally to the ARMSC and administratively to the President & Group Chief Executive Officer, thereby preserving its independence and objectivity. Internal audit reports, together with recommendations for improvement and Management’s action plans, are presented to the ARMSC on a quarterly basis. The ARMSC reviews the significant audit findings and monitors the timely implementation of agreed corrective actions by Management. During the FYE 2026, the Internal Audit Function developed a risk-based Annual Audit Plan, which was reviewed and approved by the ARMSC. The audit plan was formulated after taking into consideration the Group’s risk profile, strategic priorities and emerging risks, and covered the Group’s key governance, operational, financial and compliance processes.

RkJQdWJsaXNoZXIy NDgzMzc=