Maxis Berhad | Annual Report 2013
66 Maxis Berhad | Annual Report 2013 14. Systems and Information Security (continued) Apart from the internal security compliance programmes, SIS is also required to maintain and assist in the compliance of the following regulatory and industry security programmes, namely: MS/ISO27001:2005, Payment Card Industry/Data Security Standard, and the Personal Data Protection Act 2010. SIS is governed by a group of Maxis Senior Management team members who meet periodically to direct and approve the corporate security policies and standards set by the department and security projects undertaken by the department. It is also responsible for updating the Audit Committee at least annually on the Group’s security status. MONITORING AND REVIEW The processes that monitor and review the effectiveness of the system of risk management and internal controls include: 1. Management Representations made to the Board by the CEO and CFSO, based on representations made to them by Management on the adequacy and effectiveness of the Group’s risk management and internal control system in their respective areas. Any material exceptions identified are highlighted to the Board. 2. Internal Audit in their quarterly report to the Audit Committee and Senior Management continues to highlight significant issues and exceptions identified during the course of their review on processes and controls compliance. 3. The Defalcation Committee meets and deals regularly on matters pertaining to fraud and unethical practices. All issues arising from work carried out by the investigation team within the Internal Audit department and Management are channelled to this committee for deliberation. Appropriate actions are then taken based on the findings. 4. Enterprise Risk Management department reports to the Board on a half-yearly basis through the Audit Committee on the risk profile of the Group and the progress of action plans to manage and mitigate the risks. Management has taken the necessary actions to remediate weaknesses identified for the period under review. The Board and Management will continue to monitor the effectiveness and take measures to strengthen the risk management and internal control environment. CONCLUSION For the financial year under review and up to the date of issuance of the financial statements, the Board is satisfied with the adequacy and effectiveness of the Group’s system of risk management and internal control to safeguard the interest of shareholders. No material losses, contingencies or uncertainties have arisen from any inadequacy or failure of the Group’s system of internal control that would require separate disclosure in the Group’s Annual Report. The CEO and CFSO have provided assurance to the Board that the Group’s risk management and internal control system, in all material aspects, is operating adequately and effectively. REVIEW OF THE STATEMENT BY EXTERNAL AUDITORS As required by paragraph 15.23 of the Bursa Malaysia Securities BerhadMainMarket Listing Requirement, the external auditors have reviewed this Statement on Risk Management and Internal Control. Their limited assurance review was performed in accordance with Recommended Practice Guide (“RPG”) 5 (Revised): Guidance for Auditors on Engagements to Report on the Statement on Risk Management and Internal Control included in the Annual Report, issued by the Malaysian Institute of Accountants. RPG 5 (Revised) does not require the external auditors to form an opinion on the adequacy and effectiveness of the risk management and internal control systems of the Group. STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL Continued
Made with FlippingBook
RkJQdWJsaXNoZXIy ODU0MjU5