Market Turnover
-






-
-
|
|
|
|
|
|
-
-
-
Risk management

  • An issuer’s risk management closely interacts with the operational, reporting and compliance objectives of the issuer and the issuer’s framework of internal controls. To understand its exposure to risks, an issuer should first define clear objectives:
    • Operational Objectives – Objectives which facilitate effective and efficient operations by enabling the issuer to achieve strategic, operational and financial performance goals and safeguard such goals against business, operational, financial, compliance and other risks (including fraud).
    • Reporting Objectives – Objectives which safeguard the quality of the issuer’s internal and external reporting, including through the maintenance of proper records and processes that generate timely, relevant and reliable information.
    • Compliance Objectives – Objectives which focus on the issuer achieving regulatory compliance (and compliance with applicable laws) and adherence to internal policies with respect to the operation of the issuer’s business.
  • After defining its objectives, an issuer can identify the risks that may impact or prevent it from achieving these objectives. The risks that each issuer encounters will be different, depending (among other things) on the scale, complexity and geographical locations of its business operations. An issuer should undertake the following steps:
    • Analyse the source of potential risks – The scope of the issuer’s analysis should be broad and cover risks that can develop from internal processes and infrastructure (for example IT infrastructure, issuer’s resources, assets, organisation and operational infrastructure), as well as from external interactions, developments and threats (for example political or economic environment, business developments, and interaction with outside parties). Without limitation, the scope for analysing potential risks should be wide enough to cover material ESG risks, cyber security risks, and fraud risk.
    • Evaluate and prioritise the identified risks – To formulate its risk management strategy, the issuer will have to evaluate identified risks and develop procedures to prioritise addressing significant risks and allocate relevant resources accordingly. This evaluation should be conducted by the board with the support of the issuer’s management.
    • Monitor existing risks (and the emergence of new risks) – The issuer should constantly monitor the development of current and emerging risks.   For the purpose of tracking risks and logging risk responses, an issuer may consider creating a risk register of all identified risks with a particular focus on significant risks.  This risk register should be updated regularly and, in any event, at least annually.