Risk Management

Overview

The Group operates in a dynamic and evolving environment in Myanmar. Effective risk management is essential to ensuring resilience, safeguarding stakeholder interests, and supporting sustainable long-term growth.

The Group maintains a robust Enterprise Risk Management (“ERM”) framework that systematically identifies, assesses, and manages risks across all its business segments. This framework is embedded within the Group’s strategic planning and decision-making processes, enabling the Group to balance risk and return, optimise opportunities within defined risk appetite levels, and respond proactively to an increasingly complex and uncertain operating environment.

Risk Governance

The Group’s ERM framework operates within a robust governance structure that ensures clear accountability, effective oversight, and independent assurance.

  • Board of Directors: Provides overall oversight, approves risk appetite, and ensures alignment with strategic
  • Audit & Risk Management Committee (ARMC): Reviews key risk exposures, monitors adherence to risk appetite, and oversees ERM
  • Senior Management: Executes strategy, maintains risk management and internal control systems, and embeds risk ownership within business units.
  • Risk Management and Assurance Department (RMAD): Provides independent oversight, reports significant risk matters to ARMC, and supports risk awareness across the Group.
  • Supporting this governance framework are internal controls, policies, and procedures, including the Code of Conduct and Whistleblowing Policy.

The Three Lines of Defence

The Three Lines of Defence

Risk Culture

The Group promotes a strong risk-aware culture through accountability, ethical conduct, compliance, workplace safety, cybersecurity awareness, and proactive risk management practices. Training programs, whistleblowing channels, incident reporting, leadership engagement, and continuous communication initiatives support transparency, timely escalation, and continuous improvement of internal controls across all business segments.

Risk Appetite

The Board establishes the Group’s risk appetite to support the achievement of its strategic objectives while maintaining appropriate safeguards over people, assets, reputation, and stakeholder interests. Risk appetite is integrated into business planning, investment decisions, operational activities, and risk management processes across the Group.

The Group adopts a balanced approach to risk-taking and is prepared to accept measured levels of risk in pursuit of growth opportunities, business expansion, digital transformation, and operational improvements, provided that such risks are appropriately assessed, managed, and monitored.

The Group maintains a low tolerance for risks that may result in significant harm to employee or customer safety, breaches of laws and regulations, fraud and unethical conduct, cybersecurity incidents, material financial losses, or damage to the Group’s reputation and brand. Risk appetite is supported through established governance processes and policies, internal controls, delegated authorities, and ongoing monitoring by Management, the ARMC, and the Board. Key risk exposures and emerging risks are regularly reviewed to ensure that risk levels remain within acceptable limits and aligned with the Group’s strategic objectives.

Key Risk Categories

Key RisksMitigation
Strategic Risks
Macro
Ongoing uncertainties in the economic, business and regulatory environment in Myanmar, along with the global geopolitical situation may disrupt operations, supply chains, project delivery, workforce availability, and customer demand, resulting in financial and operational impacts.
We manage this risk by:
  • Strengthen enterprise-wide business continuity and crisis management frameworks across all business segments.
  • Enhance macro risk monitoring with defined escalation triggers.
  • Diversify supply chains, logistics routes, and sourcing strategies to improve resilience.
  • Maintain active engagement with government ministries, regulators, and industry associations.
  • Develop segment-specific contingency plans covering workforce safety, operational continuity, liquidity, and customer service.
  • Conduct periodic scenario planning and stress testing for operational disruptions.
Operational Risks
Employee Safety
Natural disasters, workplace incidents, fire hazards, equipment failures, and certain operating conditions may result in injury or loss of life, asset damage, operational disruption, regulatory non-compliance, financial losses, and reputational harm.
We manage this risk by:
  • Incident reporting, investigation, corrective action, safety training, awareness programs, and emergency preparedness exercises are maintained to strengthen safety culture, enhance workforce readiness, and support continuous improvement in operational resilience and risk management effectiveness across all business segments.
  • Regulatory compliance reviews, scheduled safety inspections, and ongoing risk monitoring activities are performed to ensure adherence to applicable standards and requirements.
  • Preventive maintenance programs, monitoring systems, emergency rescue procedures and infrastructure inspections are implemented to enhance operational reliability and safeguard critical facilities and assets, particularly within Yoma Land.
Operational Risks
Recruitment, Selection and Retention
Labour shortages, employee turnover, talent migration, and workforce disruptions may affect the Group's ability to attract and retain skilled employees, resulting in reduced productivity, project delays, increased costs, and operational challenges.
We manage this risk by:
  • Workforce planning, succession management, talent development, and multi-skilling initiatives are implemented to mitigate labour disruptions and enhance workforce resilience across all business segments.
  • Cross-training, career development programs, employee engagement initiatives, and retention measures are maintained to improve workforce stability and reduce employee turnover.
  • Diverse recruitment channels, strategic talent sourcing, and proactive hiring initiatives are utilised to attract qualified candidates and address critical skill gaps across all business segments.
Compliance Risks
Corrupt Practices and Fraud
Fraud, unethical conduct, misappropriation of assets, weak financial controls, or falsification of records may result in financial losses, regulatory breaches, legal liabilities, and reputational damage.
We manage this risk by:
  • Segregation of duties, approval controls, and management oversight processes are maintained to strengthen accountability and reduce fraud risks.
  • Regular training and communication on the Group’s Code of Conduct and Conflict of Interest Policy and Whistleblowing Policy.
  • Digital payment solutions, transaction monitoring mechanisms, and cash management controls are implemented to enhance transparency and minimise cash handling risks.
  • Dual authorisation requirements, invoice verification, reconciliation procedures, supporting documentation reviews, and contract verification controls are enforced to prevent misappropriation of funds and unauthorised claims.
  • Regular internal audits focusing on areas with greater inherent risks combined with adequate internal controls commensurate with each business segment’s operations.
Financial Risks
Market Exposures
Fluctuations in foreign exchange rates, inflation, interest rates, and broader economic conditions may increase operating costs, reduce profitability, impact funding and investment activities, and affect the Group’s financial performance.
We manage this risk by:
  • Economic conditions, inflation trends, interest rates, and foreign exchange exposures are closely monitored to support timely business decisions and effective risk management.
  • Pricing and cost management strategies, including periodic pricing reviews, product mix optimisation, supplier negotiations and foreign exchange monitoring, are implemented to mitigate the impact of inflationary pressures and currency exposure on operations and profitability.
  • Treasury oversight, natural hedging strategies, funding optimisation, and payment planning are maintained to manage market risks, preserve financial stability, and support business continuity.
IT Risks
System Reliability & Continuity
Dependence on critical technology platforms, network infrastructure, and third-party systems may result in service disruptions, transaction failures, operational delays, data loss, cybersecurity incidents, and reduced customer confidence if systems become unavailable or fail to perform as expected.
We manage this risk by:
  • System performance, transaction thresholds, and operational capacity are continuously monitored to maintain service stability and support critical platform operations.
  • Data backups and transaction recovery procedures are maintained to safeguard transactional integrity.
  • Application controls, system enhancements, cybersecurity measures, network resilience, and business continuity arrangements are maintained to ensure accurate transaction processing, protect critical systems and data, and support operational availability.
  • Backup connectivity solutions, system monitoring processes, technology diversification and alternative platform arrangements, and third-party dependency management practices are implemented to minimise operational disruptions and risks across the Group.
Cyber Security
Emerging technologies and behaviours may expose the Group to system disruptions, cybersecurity threats, data breaches, regulatory non-compliance, and operational downtime, potentially affecting business performance and customer confidence.
We manage this risk by:
  • Cybersecurity controls, security awareness programs, technology maintenance practices, and incident response processes are implemented to strengthen resilience against evolving cyber threats and safeguard critical systems and data across all the Group.
  • Access management controls, segregation of duties, user activity monitoring, security governance frameworks, cloud protection measures, and emerging technology risk management practices are maintained to address cybersecurity, data protection, and AI-related risks across the Group.

How We Evaluate Emerging Risks

The Group continuously monitors emerging trends and external developments that may affect its long-term strategy, operations, and resilience. Emerging risks are assessed through environmental scanning, management discussions, stakeholder engagement, and periodic risk reviews. Risks identified as having the potential to significantly impact the Group’s objectives are monitored and incorporated into strategic planning and risk management processes.

The emerging risks identified are:

Key RisksMitigation
AI Risk
The rapid adoption of AI may create risks relating to data privacy, cybersecurity, intellectual property, misinformation, regulatory compliance, and inappropriate use of sensitive information. Failure to establish adequate governance may result in operational, financial, and reputational impacts.
We manage this risk by:
  • AI usage policies, governance frameworks, and guidelines are established to support the responsible and ethical use of AI technologies across the Group.
  • Technical controls, including Data Loss Prevention, web filtering, Cloud Access Security Broker solutions, and monitoring mechanisms, are implemented to manage AI-related technology risks and safeguard sensitive information.
  • Employee awareness initiatives, training programs, and communication activities are conducted to promote the appropriate use of AI and strengthen understanding of associated risks and acceptable practices.
  • Regulatory developments, cybersecurity threats, emerging technologies, and evolving AI-related risks are monitored to support timely risk assessment and response.
  • AI-related risks are incorporated into cybersecurity, information security, and enterprise risk management processes to ensure ongoing oversight and governance across the Group.
Climate Change & Extreme Weather Risk
Climate change and the increasing frequency of extreme weather events may disrupt operations, damage assets, impact employee safety, interrupt supply chains, and increase operating costs.
We manage this risk by:
  • Climate-related risks, regulatory developments, and environmental trends are monitored to assess potential impacts on the Group's operations and business activities.
  • Business continuity arrangements, emergency preparedness measures, and crisis response processes are maintained to support operational resilience during disruptive events.
  • Asset resilience initiatives, infrastructure protection measures, and preventive maintenance programs are implemented to reduce vulnerability to climate-related impacts.
  • Insurance coverage, recovery strategies, and contingency arrangements are regularly reviewed to support financial and operational recovery following adverse events.
  • Climate-related considerations are incorporated into business planning, investment decisions, and risk management processes to support long-term resilience and sustainability objectives.

Monitoring & Reporting

The Group maintains continuous risk monitoring and reporting processes across all its business segments. Key risks, mitigating actions, control effectiveness, and emerging issues are regularly reviewed and reported to Management and the Board. Internal audits, operational reviews, incident escalation procedures, and governance reporting frameworks support timely decision-making, accountability, and proactive risk management.

Internal Control System

FMI’s subsidiaries have their respective internal control system. At Head Office level, the whole financial management system is managed and overseen by the Company’s Financial Controller. To ensure that the strategic vision set out for its subsidiaries are aligned, the Company has delegated its executive directors to serve on the respective Boards. These delegates will regularly update the results of operations of the subsidiaries to the ARMC, which endorses the results to the Board for approval. The ARMC and FMI’s management ensures that management of the subsidiaries maintain a sound risk management framework and internal control system to mitigate material risk exposures identified internally.

Yoma Bank

Yoma Bank (the “Bank”) places great importance on maintaining a sound risk management and internal control framework. The Board of the Bank, via the Audit and Risk Oversight Committees, is tasked with ensuring that appropriate risk management and internal systems are established and working effectively. Among other things, the Board of the Bank (i) approves risk management procedures and ensures compliance with such procedures; (ii) analyzes, evaluates, and improves the effectiveness of the internal risk management and internal control procedures on a regular basis; (iii) develops adequate incentives for executive bodies, departments and employees to apply internal control systems; and (iv) ensures that the Bank complies with legislation and charter provisions. In implementation of the framework, a strong independent internal audit team is in place to directly report to the Audit Committee of YB and to conduct periodic review of key identified areas including changes in relevant policies, internal control system, corporate governance, operations, and security risks. Acting as the main liaison between the External Auditors and the Board of YB, the Audit Committee monitors YB’s internal controls and framework to ensure transparency across the business functions of the Bank, and periodically reviews the integrity of the Bank and makes recommendations for improvement. YB’s Risk Oversight Committee reviews the effectiveness of the Enterprise Risk Management Framework particularly in relation to risk identification, measurement, mitigation, and monitoring. It ensures the risk appetite approved by the Board is properly implemented; and facilitates ongoing dialogue on risk within YB.

Pun Hlaing Hospitals (“PHHs”)

The operating guideline of PHHs is under the governance of its Chief Financial Officer. The shareholders of PHHs namely, the Company and its joint venture partner, OUE Lippo Healthcare Limited (“OUELH”) have appointed their senior management personnel on the boards of PHHs to oversee the financial system and operation of PHHs’ periodically. This is to ensure that 1) strategic objectives set for PHHs are aligned; 2) compulsory steps are taken for the achievement of its strategic goals; and 3) a comprehensive set of oversight controls to put management decisions in check and to prevent it from exposing to various risks that are prone to occur in the healthcare sector.

Risk Response & Mitigation Measures

Environmental, Health & Safety Risks

Risk description

Negative impacts on the Group’s financial performance and productivity.

Drivers

  • 1.1 Fire accidents
  • 1.2 Climate change extreme weather, natural disaster, e.g. earthquakes, floods
  • 1.3 Infectious diseases outbreak such as COVID 19, swine flu, SARS, Ebola

Implications for value creation

  • 1.1 Delayed business expansion and recovery
  • 1.2 Operations suspension
  • 1.3 Loss of lives, reputational damage and interruption in our business operations

Risk response and mitigating measures

  • 1.1 Delivering regular fire drill training to all employees across the Group on a regular basis
  • 1.2 Implemented Health and Safety Policy, HR Policies and Guidelines to practice across the Group
  • In the case of COVID 19, the Group set up a Covid Control Center (CCC) to deliver Covid-19 Emergency Response.
  • 1.3 Provide all employees, medial plans, life insurance plans and special medical coverage to employees who are diagnosed as COVID-19 patients.

Internal & External Risks

Risk description

Risk of loss resulting from inadequate or failed internal organizational practices or driven by external forces.

Drivers

  • 1.4 Financial losses and business instability
  • 1.5 Increase in competition among property developers, healthcare providers, destination management companies, financial services providers

Implications for value creation

  • 1.4 Failures in operational processes, internal policies or support systems in all business activities
  • 1.5 Increased costs to acquire land and raw material, increases in unsold properties, decreases in earning from our core businesses due to lack of competitive advantages

Risk response and mitigating measures

  • 1.4 Apply a risk-based internal audit to help the Group’s businesses accomplish the objectives by bringing a systematic and disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes through the enterprise risk management (ERM) framework. ERM also helps to address operational and finance risks are within the risk appetite monitored by management and are with the Group’s overall business objectives.
  • 1.5 Maintain win-win business relationship with our businesses’ suppliers and business partners
Risk description

Volatility in interest rates, foreign exchange rates could have a material adverse effect on our cash flows and results of operations.

Drivers

  • 2.1 Liquidity Risk
  • 2.2 Capital Risks

Implications for value creation

  • 2.1 A firm’s possible inability to meet its short-term debt obligations, thereby incurring exceptionally large losses
  • 2.2 Inability to make regular dividend payment

Risk response and mitigating measures

  • 2.1 Board of Directors approve an asset liability management (ALM) policies. Liquidity limits are set to address liquidity shocks, whether affecting most financial institutions or the Yoma Bank uniquely, are fully covered and a Contingent Funding Plan is developed. Liquidity levels are being strictly monitored for adherence to the Board specified minimums (as defined in the ALM policy) or the requirements prescribed by the CBM.
  • 2.2 The Group’s objectives when managing capital are to safeguard the Group’s ability to continue as a going concern and to maintain an optimal capital structure so as to maximize shareholder value. In order to maintain or achieve an optimal capital structure, the Group may adjust the amount of dividend payment, return capital to shareholders, issue new shares, obtain new borrowings or sell assets to reduce borrowings.

Human Resources Risks

Risk description

Increase in labor cost and loss of efficiency.

Drivers

  • 3.1 Our dependence on our Management team and skilled personnel
  • 3.2 Our inability to attract and retain such persons
  • 3.3 Lack of Keyman Insurance

Implications for value creation

  • 3.1 Adverse financial impact
  • 3.2 Increase in employee turnover, and costs to hire qualified employees and contractors
  • 3.3 Interruption in business operations and slow down business growth

Risk response and mitigating measures

3.1 Consistently providing training and leadership programs to every level of employees across the Group.
3.2 The Yoma Group’s Human Resources Department is tasked to constantly review and identify high-performing individuals internally and externally to serve as a pipeline for leadership succession planning.

  • Develop innovative talent retention programmes such as leadership training and other development programmes
  • Create safe, fun and flexible working environment
  • Develop effective internal communication system to increase employees’ synergy
  • Provide a variety of welfare benefit plans and Yoma Employees’ Perks so that employees feel that they are taken care of and to increase their sense of belonging
  • Lay out core values to increase employee morale and sense of belong across the Group.
3.3 Limit the number of The Group personnel travelling together, which means transportation or business travel should be arranged such that no single event could create a catastrophic loss of key personal for the Corporation. This means that when possible, no more than five Executive of the Company should travel on the same aircraft (be it a commercial, private, or corporate flight) or other vehicle of transportation. Pre-approval from Human Resources is required if more than half of an organization, group, or entity functional management team will be on the same aircraft.

Societal Risks: Economic and Social Instability

Risk description

Change in customers’ and shareholders’ behavior and taste which results in them investing in other types of investments.

Drivers

  • 3.4 The Company’s inability to pay dividends annually
  • 3.5 Claims or lawsuits derived from medical malpractice claims and accidents due in mismanagement in construction sites
  • 3.6 Credit Risks in the banking services sector

Implications for value creation

  • 3.4 Loss of shareholders’ loyalty and reputational damage
  • 3.5 Loss of customers’ loyalty and reputational damage
  • 3.6 Risk of loss arising from any failure by a borrower or counterparty to meet its financial obligations when such obligation is due

Risk response and mitigating measures

3.4 Shareholder’s complaints are taken seriously and are solved by the Corporate Office Team as soon as they arise. In a financial year when dividend is not paid, the Management will explain the rationale behind such action during media briefings and the Company’s Annual General Meeting.

  • Established a Corporate Office Team (Corporate Office Team) to regularly analyse the market trend and to develop strategies with the Management to ensure FMI’s shares are competitive in value and quality among its fellow listed companies;
  • The Team is also tasked to maintain and build positive relationships with individual shareholders by providing one-on-one meeting at the Company’s Head Office or Annual General Meetings, and via other communication platforms;
  • Group Legal and Group Communication departments are tasked with monitoring all commercial materials to minimize the risk of potential threat of adverse media publicity.
  • The Company’s effort in being transparent and open in communicating the internal movements are evident in the public announcements and annual media briefing.

3.5 Provide channels for stakeholders and customers to report grievances such as a feedback box at each business operation unit and anonymous reporting via a QR code available in the Company’s Stakeholder Engagement Policy

3.6 Board of Directors from banking services approve major policies and limits that govern the monitoring of the credit risk. It structures the levels of credit risk it undertakes by placing limits on the amount of risk acceptable in relation to one borrower, or group of borrowers and industry segments.

Risk description

Risk of loss resulting from inadequate or failed internal processes, people or from external event.

Drivers

  • 4.1 Weaknesses, disruption or failures in overall management and IT systems

Implications for value creation

  • 4.1 Loss of competitive advantage and fragile to external attacks

Risk response and mitigating measures

4.1 Balancing the cost and risk within the constraints of the risk appetite of the Company and the Group’s businesses to ensure that this balance is consistent with the prudent management required of a large Myanmar organization.

  • Implemented a centralized core banking system (CBS) at our subsidiary, Yoma Bank, to provide a common and stable operating platform to develop multi-channel service delivery.
  • Implemented IT security for the overall network system across the Group.
  • Utilized a firewall system to monitor internal traffic, defend against potential external anti-hacking and anti-virus attacks.
  • Planning to integrate the proxy system to monitor and filter contact traffics in the network.
  • Implemented a directory server to authenticate users and passwords.
  • Adopted Advance Threat Prevention (ATP) scanning function to monitor phishing and malware.
  • Adopted SSLVPN to build a secured virtual tunnel for WFH employees.
  • Applied two-factor authentication on for email access.
Risk description

Material adverse effect on the Group’s businesses and its financial condition

Drivers

  • 5.1 Failure or inability of the Group to comply with relevant industry-specific laws, regulations or procedures; Directors Breach of Fiduciary Duties, Corruption and Bribery and Corporate Fraud
  • 5.2 Changes in business environment factors

Implications for value creation

  • 5.1 Revoking of rights by the government without compensation
  • 5.2 Delays encountered in procuring the necessary approvals from the relevant regulatory bodies

Risk response and mitigating measures

5.1 Identifies and manages compliance risk through effective use of its external and internal compliance advisers

  • Monitors its entities’ compliance with relevant international regulatory requirements
  • Ensuring and communicating risk and its control information among the board, auditors and management which is led by Audit and Risk Management Committee and Group’s Risk Management Department

5.2 Build brand loyalty among our businesses’ consumers