Maxis Berhad | Annual Report 2012

Maxis Berhad // Annual Report 2012 217 RISK MANAGEMENT FINANCIAL STATEMENTS CORPORATE GOVERNANCE ANALYSIS OF SHAREHOLDINGS OTHER INFORMATION ANNUAL GENERAL MEETING ENTERPRISE RISK MANAGEMENT The Board of Directors ("Board") is ultimately responsible for the management of risk. The oversight of this critical area is carried out through the Audit Committee and reported to the Board at half-yearly meetings. The Board is pleased to share the activities of Maxis Enterprise Risk Management ("ERM") in relation to the Group in respect of the financial year ended 31 December 2012. The Group operates in a highly competitive and technology-based environment. The ability to effectively identify and manage risk reduces the uncertainties surrounding the Group’s internal and external environment, thus allowing it to maximise opportunities that may arise as well as minimise the effects on the Group from adverse incidences. The major risks to which the Group is exposed to are strategic, operational, regulatory, legal, financial, market, technological, product and reputational risks. These risks are proactively identified, evaluated, monitored and reported to Senior Management, Audit Committee and the Board through the ERM process. Maxis ERM adopts a structured and integrated approach in managing key business risks in line with the risk management framework and best practices. This approach is consistent with the ERM framework of the Committee of Sponsoring Organisation (“COSO”) and involves the systematic identification and analysis of risks which impact the Group’s objectives, formulation of response strategies and monitoring and reporting of the risk management progress on a regular basis. The implementation of the ERM framework ensures that major areas of risks are identified, managed and controlled or mitigated effectively. MAXIS’ ENTERPRISE RISK MANAGEMENT FRAMEWORK The ERM process is based on the following principles: • Consider and manage risks enterprise-wide; • Integrate risk management into business activities; • Manage risks in accordance with the Risk Management framework; • Tailor responses to business circumstances; and • Communicate risks and responses to Management. Risk management is firmly embedded within the business units through the annual strategic and budgeting processes. The business units, being the first line of defense against risks, are responsible for identifying, mitigating and managing risks within their respective areas. These units are to ensure that their day-to-day business activities are carried out within the established risk policies, procedures and limits. All risks identified are assessed to determine the risk ranking and displayed on a 5 by 5 risk matrix. With this visual representation, the risk owners and Senior Management can prioritise their efforts and manage the different classes of risks appropriately. The Audit Committee, supported by the Internal Audit Department, provides an independent assessment of the adequacy and reliability of the ERM processes. RISKS OBJECTIVE CONTROL AL I G N M EN T IDENTIFY & ANALYSE RESPOND MONITOR & REPORT

RkJQdWJsaXNoZXIy ODU0MjU5