01 | ABOUT NEXG 02 | OUR LEADERSHIP 03| OUR PERSPECTIVE 04 | SUSTAINABILITY 05 | GOVERNANCE 06 | FINANCIAL STATEMENTS 07 | OTHER INFORMATION ANNUAL REPORT 2026 Statement on Risk Management AND INTERNAL CONTROL (CONT'D) RISK MANAGEMENT AND INTERNAL CONTROL SYSTEMS RISK MANAGEMENT Risk Management Framework and Activities The Group's risk management and internal control systems are guided by ISO 31000 Risk Management: Principles and Guidelines and the Committee of Sponsoring Organisations of the Treadway Commission (“COSO”) Framework respectively. The key features of the Group's risk management and internal control system are the three lines of defence model with established functional responsibilities and accountabilities for the management of risks and internal controls of the Group, as set out below. In September 2025, the Group appointed Morison LC Advisory Sdn Bhd (“MLCA”) to replace the CAD as its Third Line of Defence. * At the Third Line of Defence, the Outsourced Internal Auditors will perform regular independent reviews of the Group’s operations and system of internal controls, providing assurance on the adequacy and effectiveness of controls implemented by Management. The Group's risk management framework and methodology is guided by ISO 31000 Risk Management: Principles and Guidelines. The framework encompasses a structured and iterative process as summarised below. Line of Defence Role and Responsibilities Provided By First Line of Defence Own, manage and control risks by implementation of internal controls in the business operations and activities. Executive Management Directors, and Heads of Department. Second Line of Defence Coordinate and facilitate risk management activities routinely among the various business units and support and administration functions, including monitoring progress of risk mitigation plans. Risk and Governance Unit (“RGU”) Third Line of Defence Perform regular reviews of the Group's operations and system of internal controls and risk management. Provide independent assurance on the adequacy and effectiveness of the controls processes implemented by business process owners and Management. Corporate Assurance Department (“CAD”) / Outsourced Auditors* Internal 126
RkJQdWJsaXNoZXIy NDgzMzc=