ENRA Group Berhad Annual Report 2026

72 SECTION 04 : CORPORATE GOVERNANCE CONTROL ENVIRONMENT AND INTERNAL CONTROL ACTIVITIES (CONT'D) Information, Communication and Monitoring • Timely and reliable management information systems that support decision-making, performance monitoring and risk reporting across the Group. • Regular reporting by Management, the Internal Audit Function and other assurance providers to the ARMSC and the Board on governance, risk management and internal control matters. • Ongoing monitoring of the effectiveness of internal controls through Management reviews, risk management activities and independent assessments performed by the Internal Audit Function, with corrective actions tracked until satisfactory resolution. Management Visits The Board and Senior Management undertake regular visits to project sites, operational facilities, overseas locations, and the offices of key clients and business partners to gain first-hand insights into the Group’s operations and support informed decision-making. These visits complement the Group’s formal reporting and monitoring processes by facilitating direct engagement with employees, assessing operational and project performance, reinforcing governance and health, safety and environmental (“HSE”) practices, and identifying matters requiring follow-up or improvement. Business Continuity and Resilience The Group has established a Business Continuity Plan (“BCP”), Information Technology Disaster Recovery Plan (“ITDRP”) and Emergency Response Plan (“ERP”) to enhance its resilience against potential business disruptions and minimise the impact on critical operations. These plans are reviewed periodically and supported by drills and testing exercises to promote preparedness, operational continuity and continuous improvement. Code of Business Conduct and Ethics The Group communicates the Code of Business Conduct to its employees upon their employment. The Code of Business Conduct reinforces the Group’s core value on integrity by providing guidance on moral and ethical behaviour that is expected from all employees in following applicable laws, policies, standards and procedures. Every six months, the employees and EXCO of the Group confirm compliance via the Code of Business Conduct Questionnaire for disclosure of any irregularities or breach of the Code of Business Conduct. The feedback from the Code of Business Conduct Questionnaire is considered by the EXCO and further deliberated by the ARMSC. There were no irregularities or breaches in this financial year. Vendor Code of Conduct The Group has established a Vendor Code of Conduct, which sets out the minimum standards of ethical business practices and expected conduct for all vendors and business partners. The Code covers key areas including compliance with applicable laws and regulations, business ethics, anti-corruption and anti-competitive practices, human rights and labour standards, conflict of interest, health, safety and environmental responsibilities, and the protection of confidential information and records. All vendors are required to acknowledge and comply with the Vendor Code of Conduct as part of the Group’s procurement and contracting processes. Acceptance of a purchase order, letter of award, contract or other agreement with the Group constitutes the vendor’s commitment to adhere to the principles and requirements set out in the Code. Whistleblowing Policy A Whistleblowing Policy is established to provide appropriate communication and feedback channels which facilitate whistleblowing in a transparent and confidential manner to enable employees and stakeholders and where applicable, members of the public, to raise genuine concerns about possible improprieties, improper conduct or other malpractices within the Group in an appropriate way. Statement On Risk Management And Internal Control (Cont’d)

RkJQdWJsaXNoZXIy NDgzMzc=