NexG Berhad Annual Report 2026

01 | ABOUT NEXG 02 | OUR LEADERSHIP 03| OUR PERSPECTIVE 04 | SUSTAINABILITY 05 | GOVERNANCE 06 | FINANCIAL STATEMENTS 07 | OTHER INFORMATION ANNUAL REPORT 2026 Statement on Risk Management AND INTERNAL CONTROL (CONT'D) Annual budgets are reviewed by the Executive Director and the Executive Deputy Chairman / Chief Executive Officer prior to tabling to the Board for approval. Actual performance is reviewed against the approved budget by the Executive Directors and Executive Deputy Chairman / Chief Executive Officer, allowing timely responses and corrective actions to be taken. Project-level budgeting is implemented as part of the Group's cost optimisation efforts to monitor and control expenditures incurred for each project. Heads of project are responsible for ensuring that project expenses remain within approved budgets, and any significant variances against approved budgets are reported to Management for attention and the formulation of necessary action plans The Group undertook continuous development and improvement of its information technology systems and platforms to support operational efficiency across various activities and to facilitate effective decision-making by providing decision makers with timely and accurate information. The Group's disaster recovery and business continuity plan (“BCP”) has been developed, and its implementation continued during the financial year. The plan is designed to minimise downtime and data loss and to ensure continuity of business operations in the event of a management systems breakdown or other potential hazards such as fire and flood. Key information and data are backed up systematically on a periodic basis. The ARMC reviewed the adequacy and effectiveness of the internal control systems with respect to operational issues reported by the Internal and External Auditors, and the actions taken by Management in response to findings, to provide assurance that control procedures are in place and are being followed as intended. The ARMC reviewed the adequacy and effectiveness of the risk management system and the mitigation controls applied to manage key risk areas as reported by the risk management function, to provide assurance that the systems are operating as intended to manage the overall risk exposure of the Group. Internal control and key risk-related matters requiring the Board's attention were conveyed to the Board by the ARMC. The Corporate Assurance Department performs regular reviews of the Group's operations and system of internal controls and evaluates the adequacy and effectiveness of the controls processes implemented by process owners and Management. In September 2025, the Group appointed Morison LC Advisory Sdn Bhd (“MLCA”) to replace the CAD as its internal audit service provider. MLCA reports principally to the ARMC. During the financial year ended 31 March 2026, the adequacy and effectiveness of internal controls were reviewed by the ARMC based on reports from audits conducted by the Corporate Assurance Department and MLCA in accordance with the approved audit plan. Audit issues and Management's responses were deliberated and accepted at ARMC meetings. There were two (2) Internal Audit Reports issued and reviewed by the ARMC throughout the financial year, in which the CAD and MLCA provided recommendations to Management to improve the design and effectiveness of controls where applicable. The ARMC also reviewed the implementation progress of corrective action plans committed by Management for all key findings and recommendations in previous Internal Audit Reports, to ensure that corrective actions were implemented appropriately. From the Internal Audit Reports issued, weaknesses and gaps in internal controls were identified, and remedial actions and corrective measures including monitoring have been, and are being, taken to address such weaknesses. A description of the Corporate Assurance Department's and MLCA’s activities for the financial year ended 31 March 2026 is available in the ARMC Report included in this Annual Report. 11. Financial Budgeting and Project-Level Budgeting 12. Continuous Improvement of IT Systems 13. Group Disaster Recovery Plan 14. Review by the Audit and Risk Management Committee (“ARMC”) 15. Independent Review by the Corporate Assurance Department and Outsourced Internal Auditor KEY ELEMENTS OF THE INTERNAL CONTROL SYSTEMS OF THE GROUP (CONT'D) 130

RkJQdWJsaXNoZXIy NDgzMzc=