ENRA Group Berhad Annual Report 2026

71 ANNUAL REPORT 2026 ENRA GROUP BERHAD CONTROL ENVIRONMENT AND INTERNAL CONTROL ACTIVITIES The Group has established a comprehensive system of internal controls that is embedded within its governance, risk management and business processes. The system is designed to support the achievement of the Group’s strategic and operational objectives, safeguard assets, promote accountability and facilitate compliance with applicable laws, regulations, policies and procedures. The key elements of the Group’s internal control system include the following: CONTROL ACTIVITIES AUTHORITY ETHICS & COMPLIANCE MONITORING Governance, Policies and Delegation of Authority • Clearly defined organisational structures, reporting lines and responsibilities to support effective governance and accountability across the Group. • Formalised Board Committees with approved Terms of Reference setting out their respective roles and responsibilities. • Documented policies, standard operating procedures and guidelines that are periodically reviewed and updated to reflect changes in business operations, regulatory requirements and industry practices. • A formal delegation of authority framework that defines approval limits and decision-making responsibilities for the Board, Board Committees and Management. • Significant instances of non-compliance with established policies and procedures, where any, are reported to the ARMSC together with the corresponding remedial actions. Strategic Planning, Performance Monitoring and Financial Controls • A structured strategic planning and business planning process that aligns the Group’s objectives with operational and financial priorities. • Regular Executive Committee (“EXCO”) and performance review meetings, where Management monitors and evaluates business performance against approved plans and key financial and operational indicators. • An annual budgeting process, with periodic reviews by business units and Management, followed by approval by the President & Group Chief Executive Officer and the Board. • Quarterly financial reporting by the Group Chief Financial Officer to the Board, including analysis of significant variances against approved budgets and business plans. Material variances are reviewed by Management and reported to the Board for deliberation and appropriate action. Risk Assessment and Compliance • An ongoing process for identifying, assessing and monitoring principal risks that may affect the achievement of the Group’s strategic and operational objectives. • Periodic reviews by the President & Group Chief Executive Officer, with input from the ERMC, of significant changes in the internal and external operating environment that may affect the Group’s risk profile, with the outcomes reported to the ARMSC. • A Code of Business Conduct and Ethics and related governance policies that promote integrity, accountability and ethical business practices across the Group. • Established mechanisms to monitor compliance with applicable laws, regulations, internal policies and governance requirements, with significant matters reported to the ARMSC and the Board, where appropriate. Statement On Risk Management And Internal Control (Cont’d)

RkJQdWJsaXNoZXIy NDgzMzc=