ENRA Group Berhad Annual Report 2026

70 SECTION 04 : CORPORATE GOVERNANCE Statement On Risk Management And Internal Control (Cont’d) INTERNAL AUDIT FUNCTION (CONT'D) In FYE 2026, the Internal Audit Function completed a holistic Corporate Governance Review of ENRA Group Berhad with reference to the MCCG 2021, MMLR of Bursa Securities and relevant ESG reporting developments. In addition, one routine audit covering the Property Development division and three follow-up reviews relating to the MRO division, ITGC and Hexagon Alpha were carried out. The Internal Audit Function also undertook ESG data monitoring and assessments of compliance with the Group’s Code of Business Conduct, in accordance with the ARMSC-approved Annual Audit Plan. The scope of internal audit coverage was aligned with the Group’s enterprise risk management framework and included, where relevant, reviews of Finance, Human Resources, Operations, Procurement, Inventory Management, Information Technology General Controls, Sales and Marketing, Fraud Risk Management, Project Management and ESG practices. Weakness And Remedial Actions The Board, through the ARMSC, reviews significant internal audit findings and monitors the implementation of Management’s action plans to address identified control gaps and opportunities for improvement. During the financial year under review, the Internal Audit Function identified several areas where internal controls and administrative processes could be further strengthened. Management has initiated or implemented appropriate remedial actions, including the following: Observation Management's Remedial Action The enforcement of Liquidated Ascertained Damages (“LAD”) remains subject to a contractual dispute with the contractor. Management is actively engaging with the contractor to resolve the matter, taking into consideration the contractual rights and responsibilities of both parties. The matter continues to be monitored by Management. The use of external Google email accounts for work-related communications within a joint venture subsidiary was observed. The Group’s Information Technology (“IT”) function is supporting the phased migration of subsidiaries to the Group’s centrally managed and approved email platform to enhance governance, security and standardisation. Certain fixed assets and specialised tools deployed for operational and maintenance activities had yet to be tagged and updated in the Fixed Asset Register. Asset tagging and reconciliation activities are being progressively completed as the assets are returned from operational deployment, with periodic verification by the responsible departments. Vendor registration and supporting records require further enhancement and updating. Management is in the process of consolidating and updating information for both existing and new suppliers to strengthen vendor management and record-keeping processes. The ARMSC receives periodic updates from Management on the implementation status of agreed corrective actions and is satisfied that appropriate measures have been undertaken to address the observations raised by the Internal Audit Function. The Board is of the view that the control weaknesses identified during the financial year were not material, either individually or in aggregate, and did not result in any material loss or have a significant impact on the Group’s operations. Accordingly, the Board is satisfied that the Group’s system of risk management and internal control remained adequate and effective in safeguarding shareholders’ investments, the Group’s assets and stakeholders’ interests during the financial year under review.

RkJQdWJsaXNoZXIy NDgzMzc=