Al-`Aqar Healthcare REIT Annual Report 2023

STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROLS THE GOVERNANCE STRUCTURE The Governance Structure for the Risk Management and Internal Control is depicted below: The governance structure dictates the segregation of the roles and responsibilities of the Board, BARC, the ERMC and other key personnel; which are summarised as below: Strategic Risks Market Risks Partnership Risks Financial Risks Compliance Risks Operational Risks ESG Risks Enterprise Risk Management Committee (ERMC) CHIEF EXECUTIVE OFFICER (CEO) BUSINESS LINE MANAGEMENT/RISK OWNERS Internal Auditor External Auditor BOARD AUDIT AND RISK COMMITTEE BOARD OF DIRECTORS GOVERNANCE FRAMEWORK CONTENT The Board and the BARC Internal Audit Responsibilities Governing overall risk oversight responsibility including defining the appropriate governance structure and risk appetite. Process • Articulates and provides direction on risk appetite, organisational control environment and risk culture. • Provide an independent view on specific risk and control issues, the state of internal controls, trends and events Responsibilities • Provide independent assurance design and effectiveness on an organisation’s risk management, governance and internal control processes are operating effectively. • Assurance about design and effectiveness Process Perform risk-based internal audit and independent reporting to Management and BARC 132 CORPORATE GOVERNANCE 1 2 3 5 6 AL-`AQAR HEALTHCARE REIT ANNUAL REPORT 2023

RkJQdWJsaXNoZXIy NDgzMzc=