Yinson Annual Report 2023

156 YINSON HOLDINGS BERHAD | INTEGRATED ANNUAL REPORT 2023 Three Lines of Defence Model The Group adopts a ‘Three Lines of Defence’ approach for its risk management. It provides an overview of the Group’s operations from a risk management perspective while assuring the ongoing success of risk management initiatives. 1st line of defence – Own and manage day-to-day risks inherent in business activities including that of risk taking by having effective internal controls and relevant policies and procedures. 2nd line of defence – Establish, implement, maintain, and review effectiveness of risk management, controls and sustainability process. In addition, they provide overall risk governance and oversight and challenge the assessment of 1st line, where applicable. 3rd line of defence – Provide an independent assurance on the overall integrity, adequacy and effectiveness of the risk management and internal control system noted during the risk evaluation process. This includes the effectiveness of Yinson’s 1st and 2nd lines of defence. RISK MANAGEMENT MODEL & PILLARS The key areas under the GRC’s purview can be portrayed in the following pillars: Management of Risk Automation Solution Responsible to review risk processes within the Group and continuously enhance the risk process through automated solutions. Risk Awareness & Communication Create awareness and seamless communication pertaining to the risk review and assessment process within the Group. Crisis Management Plan Formulate and establish Crisis Management Plan. Risk Assessment, Monitoring, Review & Reporting Conduct quarterly risk assessment reviews on all the business functions within the Group. Conduct ad hoc risk review on new or existing projects and business functions. KEY DEVELOPMENTS IN FYE 2023 Climate risk profile In view of the increasing climate-related risk exposure and in line with Yinson’s sustainability initiatives such as Task Force on Climate-Related Financial Disclosures (“TCFD”) reporting, a climate risk assessment exercise was initiated by GRC during the year to assess Yinson’s exposure to climate-related risks. The exercise was conducted with the respective climate-related risk owners across the Group, and driven by the Risk Management function in collaboration with Corporate Sustainability. The process for this assessment is as per the ERM process established in the ERM Policy Statement and Framework. The climate risk profile is reported to the BRSC and Board on a quarterly basis. STATEMENT ON RISK MANAGEMENT & INTERNAL CONTROL

RkJQdWJsaXNoZXIy NDgzMzc=