Small Hero

Risk management

Our risk-management framework provides a consistent approach to identifying, mitigating, and managing risks, which is essential to achieving our strategic objectives and supports the in its oversight of principal risks and internal controls.

Given the nature of our business and the financial, market and regulatory environments in which we operate, we are naturally exposed to strategic, financial and operational risks. While it is not possible to eliminate all risks, effective risk management ensures they are managed to an acceptable level.

To support the Board in discharging its risk oversight responsibilities, we have an Enterprise Risk Management (“ERM”) Framework in place. This framework aligns risk identification, mitigation and management with our risk appetite and sets out the processes by which risks are identified, assessed, monitored and escalated across the Group. It is regularly reviewed - along with our risk tooling and resources - to ensure it remains effective, in line with market practices and regulatory expectations.

The Board, through its Group Risk Committee, is ultimately responsible for the implementation of an appropriate risk strategy. The Group Risk Committee supports the Board in:

  • Monitoring, reviewing and advising the Board on the Group's overall risk appetite, tolerance and strategy alongside current and prospective risk exposures.
  • Monitoring and reviewing the effectiveness of the Group's risk management framework, including the identification, assessment and mitigation of principal and emerging risks.
  • Monitoring the ability of the Group's risk management framework to identify the risk facing the Group to ensure a robust assessment of the emerging and principal risks has been undertaken.
Board, Executives & Business functions

Board

Executive Committees

Execution of Board's risk strategy including risk appetite.

Risk and control functions

Comprised of compliance, financial crime, financial risk, liquidity risk and operational risk. In addition, legal, finance, data privacy and security functions are also considered as part of the control functions within the Group.

Business functions

Identify, own, assess and manage risks. Design, implement and monitor suitable controls, issue management, KRI and risk appetite reporting.