NexG Berhad Annual Report 2026

01 | ABOUT NEXG 02 | OUR LEADERSHIP 03| OUR PERSPECTIVE 04 | SUSTAINABILITY 05 | GOVERNANCE 06 | FINANCIAL STATEMENTS 07 | OTHER INFORMATION Governance Statement on Risk Management AND INTERNAL CONTROL (CONT'D) KEY ELEMENTS OF THE INTERNAL CONTROL SYSTEMS OF THE GROUP Risk Management Framework and Activities (Cont'd) The Group's internal control systems during the financial year ended 31 March 2026 were embedded within the operating activities. Up to the date of approval of this Statement for inclusion in the Annual Report, the key elements of the internal control systems encompassed, among others, the following: Standard Operating Procedures (“SOP”) governing risk management processes and reporting procedures are in place to support and outline the policies and procedures for the implementation of the Enterprise Risk Management Framework. The efforts to implement formal risk management reviews and reporting as outlined in the Framework continued to improve on a progressive basis during the financial year. Even though formal risk management activities and reporting within the Group are continuously being improved, the Executive Directors and Key Senior Management affirm that risk management processes have been ongoing throughout the financial year, and that key risks were reviewed by the Executive Directors and Management in the course of managing business activities. Significant risk management activities and progress, including those initiated by the Executive Directors and Management, were reported to the ARMC for review and recommendation to the Board for approval. The anticipated or known key risks to which the Group is exposed, together with related mitigating strategies as reported by the risk management function for the financial year ended 31 March 2026, are presented in the Management Discussion and Analysis included in this Annual Report. Stage Description Establish Context Define the internal and external context within which risk management takes place, including the Group's objectives, strategies and stakeholder expectations. Risk Identification Systematically identify risks that may affect the achievement of the Group's objectives, drawing on inputs from business unit heads, historical data and environmental scans. Risk Analysis Assess the likelihood and consequence of each identified risk using the Group's risk matrix to determine risk levels. Risk Evaluation Compare assessed risk levels against the Group's risk appetite and tolerance thresholds to prioritise risks for treatment. Risk Treatment Formulate and implement appropriate risk response strategies, which may include risk avoidance, reduction, sharing or acceptance, with corresponding action plans and ownership assigned. The Board has delegated certain responsibilities to the Board Committees established within the Group, namely: • The Audit and Risk Management Committee; • The Nomination and Remuneration Committee; • The Employees' Share Option Scheme Committee; and • The Sustainability Committee. These Board Committees have oversight authority to examine and consider all matters within their respective scope of responsibilities as defined in their formalised terms of reference, and to report to the Board with appropriate recommendations. The terms of reference of all Board Committees are published on the Group's website at www.nexg.com.my. 1. Board Committees 127

RkJQdWJsaXNoZXIy NDgzMzc=