Maxis Berhad | Annual Report 2012

Maxis Berhad // Annual Report 2012 212 STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL INTRODUCTION The Board affirms its overall responsibility for the Group’s system of internal control and risk management and for reviewing the adequacy and integrity of the system. The Board is pleased to share the key aspects of the Group’s risk management and internal control system in respect of the financial year ended 31 December 2012. In discharging its stewardship responsibilities, the Group has established a sound risk management framework and procedures of internal control. These procedures, which are subject to regular review by the Board, provide an ongoing process for identifying, evaluating and managing significant risks faced by the Group that may affect the achievement of its business objectives. The Group’s risk management framework and internal control procedures, in all material aspects, are consistent with the guidance provided to Directors as set out in the “Statement on Risk Management and Internal Control: Guidelines for Directors of Listed Issuers”. BOARD RESPONSIBILITY The Board of Maxis, in discharging its responsibilities, is fully committed to articulating and maintaining a sound risk management and internal control environment. The Board is responsible for determining the company’s level of risk tolerance and in conjunction with management, to actively identify, assess and monitor key business risks in order to safeguard shareholders’ investments and the Group’s assets. The risk management and internal control systems are designed to identify and manage risks that may impede the achievement of the Group’s business objectives rather than to eliminate these risks. They can only provide reasonable and not absolute assurance against fraud, material misstatement or loss. RISK MANAGEMENT The Board regards risk management as an integral part of the Group’s business operations. There is an established Enterprise Risk Management ("ERM") Framework for systematically identifying, analysing, measuring, monitoring and reporting on the risks that may affect the achievement of its business objectives. The ERM department, alongside the Group’s operational managers, continuously identify, monitor and mitigate the risks and reports the results to Senior Management. The Audit Committee receives a half-yearly report on the risk profile of the Group and the status of progress towards mitigating the risk areas. The Board and Management drive a proactive risk management culture and ensure that the Group’s employees have a good understanding and application of risk management principles towards cultivating a sustainable risk management culture through education. Regular risk awareness and coaching sessions are conducted at the operational level to promote the understanding of risk management principles and practices across different functions within the Group. In addition, a risk-based approach is embedded into existing key processes as well as new key projects, and is compatible with the Group’s internal control systems. This is elaborated in detail under a separate statement called “Risk Management” on pages 217 to 218. CONTROL ENVIRONMENT AND STRUCTURE The Board and Management have established numerous processes for identifying, evaluating and managing the significant risks faced by the Group. These include periodic testing of the effectiveness and efficiency of the internal control procedures and updating the system of internal controls when there are changes to the business environment or regulatory guidelines. These processes have been in place for financial year ended 31 December 2012 and up to the date of approval of this Statement on Risk Management and Internal Control for inclusion in the annual report. The key elements of the Group’s control environment include: 1. Organisation Structure In providing direction and oversight, the Board is supported by a number of established Board committees, namely the Audit, Nomination, Remuneration and ESOS Committees. Each Committee has clearly defined terms of reference and responsibilities. Further, the Board has the power to establish ad-hoc committees comprising Directors or Directors and Management to oversee specific matters within the defined scope and terms of reference. Responsibility for implementing the Group’s strategies and day-to-day businesses, including implementing the system of risk management and internal control, is delegated to Management. The organisation structure sets out a clear segregation of roles and responsibilities, lines of accountability and levels of authority to ensure effective and independent stewardship.

RkJQdWJsaXNoZXIy ODU0MjU5