Enterprise risk management framework 2026 #
Document control #
Document Type: Enterprise Risk Matrix and Governance Framework
Department: Risk and Compliance Division
Version: 1.2
Approval Status: Board Approved
Effective Date: March 2026
Classification: Internal Use
Executive summary #
This Enterprise Risk Management Framework establishes the principles, governance structures, mitigation strategies, and monitoring mechanisms used by NAM-MIC Holdings to identify, assess, manage, and report organizational risks.
The framework supports sustainable growth, operational resilience, regulatory compliance, and long-term stakeholder value creation across all portfolio entities and business operations.
Risk governance structure #
| Governance Body | Responsibility |
|---|---|
| Board of Directors | Overall risk oversight and strategic risk approval |
| Audit and Risk Committee | Monitoring enterprise risk exposure and compliance |
| Executive Management | Implementation of risk controls and mitigation plans |
| Internal Audit | Independent assessment of control effectiveness |
| Risk and Compliance Division | Risk monitoring, reporting, and framework management |
Enterprise risk matrix #
| Risk Category | Risk Description | Impact Level | Likelihood | Mitigation Strategy |
|---|---|---|---|---|
| Financial Risk | Decline in investment returns and cash flow instability | High | Medium | Diversified investment portfolio and quarterly financial reviews |
| Operational Risk | Failure of internal systems or business processes | High | Medium | Process automation, system redundancy, and staff training |
| Cybersecurity Risk | Unauthorized access to digital systems and sensitive information | High | High | Multi-factor authentication, endpoint protection, regular audits |
| Regulatory Risk | Non-compliance with statutory and governance obligations | High | Medium | Compliance monitoring and annual policy reviews |
| Reputational Risk | Negative public perception or media exposure | Medium | Medium | Stakeholder communication strategy and media protocols |
| Procurement Risk | Fraud, corruption, or supplier misconduct | High | Medium | Segregation of duties and transparent procurement procedures |
| Strategic Risk | Failure to achieve long-term investment objectives | High | Low | Annual strategic planning and investment performance reviews |
| Human Capital Risk | Loss of key personnel and critical skills shortages | Medium | Medium | Succession planning and employee development programmes |
Risk assessment methodology #
Risks are assessed using the following criteria:
Impact levels #
- Low
- Medium
- High
- Critical
Likelihood levels #
- Rare
- Unlikely
- Possible
- Likely
- Almost Certain
Each identified risk is assigned a residual risk score after mitigation controls are applied.
Governance controls #
The following governance controls are implemented across the organization:
- Quarterly risk reporting to the Board
- Annual internal and external audits
- Procurement approval workflows
- Policy compliance monitoring
- Business continuity planning
- Information security controls
- Delegation of authority frameworks
- Whistleblower and ethics reporting mechanisms
Monitoring and reporting #
Risk registers are reviewed quarterly by management and reported to the Audit and Risk Committee. Critical risks requiring escalation are communicated immediately to executive leadership and the Board of Directors.
Key risk indicators are monitored continuously to ensure proactive response measures and organizational resilience.
Conclusion #
NAM-MIC Holdings recognizes enterprise risk management as a strategic function essential to sustainable growth and responsible governance. This framework provides a structured approach to identifying uncertainties, strengthening controls, and supporting informed decision-making across all operations.
Prepared by:
Risk and Compliance Division
NAM-MIC Holdings Ltd.