Our risk management framework is built on a strong strategic
foundation, guided by our Risk Management Policy and
seamlessly integrated into day-to-day operations. Risks are
proactively identified through diverse sources, including risk
forecast reports, industry insights, insurance assessments,
and internal audits, and captured in a central risk register.
Each identified risk is assigned to a management owner
responsible for developing and periodically reviewing
mitigation plans. Risks are prioritised based on impact and
likelihood and quantified as inherent risk values. Residual risk
is the value post mitigation. Mitigation actions are assigned to
ensure timely execution, thereby lowering residual risk.
Scenario analysis is undertaken to evaluate options for
significant risks, while sensitivity analysis assesses the impact
of changes in external and operational variables, enabling
more agile and resilient decision-making.
A formal Risk Appetite Statement defines threshold
limits on critical parameters such as debt exposure and
business value creation. These limits are continuously
monitored and reviewed to ensure risk levels remain within
acceptable bounds while optimising performance in a
dynamic environment.
By aligning risk management with core strategy and business
planning, we ensure a forward-looking, integrated approach
focused on protecting value across existing operations and
new projects. We also promote a strong risk culture across
the organisation through:
- Periodic awareness sessions for Non-Executive Directors
on cybersecurity, regulatory, and sustainability topics
- Monthly training for employees on risk management
principles and business continuity
- Integration of risk analysis and mitigation review into
Board approval notes for new business lines and projects
- Cascading risk mitigation goals into measurable
individual KPIs, linked to performance appraisal to ensure
accountability and achievement of risk targets