Risk Management
Overview
The Group operates in a dynamic and evolving environment in Myanmar. Effective risk management is essential to ensuring resilience, safeguarding stakeholder interests, and supporting sustainable long-term growth.
The Group maintains a robust Enterprise Risk Management (“ERM”) framework that systematically identifies, assesses, and manages risks across all its business segments. This framework is embedded within the Group’s strategic planning and decision-making processes, enabling the Group to balance risk and return, optimise opportunities within defined risk appetite levels, and respond proactively to an increasingly complex and uncertain operating environment.
Risk Governance
The Group’s ERM framework operates within a robust governance structure that ensures clear accountability, effective oversight, and independent assurance.
- Board of Directors: Provides overall oversight, approves risk appetite, and ensures alignment with strategic
- Audit & Risk Management Committee (ARMC): Reviews key risk exposures, monitors adherence to risk appetite, and oversees ERM
- Senior Management: Executes strategy, maintains risk management and internal control systems, and embeds risk ownership within business units.
- Risk Management and Assurance Department (RMAD): Provides independent oversight, reports significant risk matters to ARMC, and supports risk awareness across the Group.
- Supporting this governance framework are internal controls, policies, and procedures, including the Code of Conduct and Whistleblowing Policy.
The Three Lines of Defence
Risk Culture
The Group promotes a strong risk-aware culture through accountability, ethical conduct, compliance, workplace safety, cybersecurity awareness, and proactive risk management practices. Training programs, whistleblowing channels, incident reporting, leadership engagement, and continuous communication initiatives support transparency, timely escalation, and continuous improvement of internal controls across all business segments.
Risk Appetite
The Board establishes the Group’s risk appetite to support the achievement of its strategic objectives while maintaining appropriate safeguards over people, assets, reputation, and stakeholder interests. Risk appetite is integrated into business planning, investment decisions, operational activities, and risk management processes across the Group.
The Group adopts a balanced approach to risk-taking and is prepared to accept measured levels of risk in pursuit of growth opportunities, business expansion, digital transformation, and operational improvements, provided that such risks are appropriately assessed, managed, and monitored.
The Group maintains a low tolerance for risks that may result in significant harm to employee or customer safety, breaches of laws and regulations, fraud and unethical conduct, cybersecurity incidents, material financial losses, or damage to the Group’s reputation and brand. Risk appetite is supported through established governance processes and policies, internal controls, delegated authorities, and ongoing monitoring by Management, the ARMC, and the Board. Key risk exposures and emerging risks are regularly reviewed to ensure that risk levels remain within acceptable limits and aligned with the Group’s strategic objectives.
Key Risk Categories
| Key Risks | Mitigation |
|---|---|
Strategic Risks |
|
| Macro Ongoing uncertainties in the economic, business and regulatory environment in Myanmar, along with the global geopolitical situation may disrupt operations, supply chains, project delivery, workforce availability, and customer demand, resulting in financial and operational impacts. | We manage this risk by:
|
Operational Risks |
|
| Employee Safety Natural disasters, workplace incidents, fire hazards, equipment failures, and certain operating conditions may result in injury or loss of life, asset damage, operational disruption, regulatory non-compliance, financial losses, and reputational harm. | We manage this risk by:
|
Operational Risks |
|
| Recruitment, Selection and Retention Labour shortages, employee turnover, talent migration, and workforce disruptions may affect the Group's ability to attract and retain skilled employees, resulting in reduced productivity, project delays, increased costs, and operational challenges. | We manage this risk by:
|
Compliance Risks |
|
| Corrupt Practices and Fraud Fraud, unethical conduct, misappropriation of assets, weak financial controls, or falsification of records may result in financial losses, regulatory breaches, legal liabilities, and reputational damage. | We manage this risk by:
|
Financial Risks |
|
| Market Exposures Fluctuations in foreign exchange rates, inflation, interest rates, and broader economic conditions may increase operating costs, reduce profitability, impact funding and investment activities, and affect the Group’s financial performance. | We manage this risk by:
|
IT Risks |
|
| System Reliability & Continuity Dependence on critical technology platforms, network infrastructure, and third-party systems may result in service disruptions, transaction failures, operational delays, data loss, cybersecurity incidents, and reduced customer confidence if systems become unavailable or fail to perform as expected. | We manage this risk by:
|
| Cyber Security Emerging technologies and behaviours may expose the Group to system disruptions, cybersecurity threats, data breaches, regulatory non-compliance, and operational downtime, potentially affecting business performance and customer confidence. | We manage this risk by:
|
How We Evaluate Emerging Risks
The Group continuously monitors emerging trends and external developments that may affect its long-term strategy, operations, and resilience. Emerging risks are assessed through environmental scanning, management discussions, stakeholder engagement, and periodic risk reviews. Risks identified as having the potential to significantly impact the Group’s objectives are monitored and incorporated into strategic planning and risk management processes.
The emerging risks identified are:
| Key Risks | Mitigation |
|---|---|
| AI Risk The rapid adoption of AI may create risks relating to data privacy, cybersecurity, intellectual property, misinformation, regulatory compliance, and inappropriate use of sensitive information. Failure to establish adequate governance may result in operational, financial, and reputational impacts. | We manage this risk by:
|
| Climate Change & Extreme Weather Risk Climate change and the increasing frequency of extreme weather events may disrupt operations, damage assets, impact employee safety, interrupt supply chains, and increase operating costs. | We manage this risk by:
|
Monitoring & Reporting
The Group maintains continuous risk monitoring and reporting processes across all its business segments. Key risks, mitigating actions, control effectiveness, and emerging issues are regularly reviewed and reported to Management and the Board. Internal audits, operational reviews, incident escalation procedures, and governance reporting frameworks support timely decision-making, accountability, and proactive risk management.
Internal Control System
FMI’s subsidiaries have their respective internal control system. At Head Office level, the whole financial management system is managed and overseen by the Company’s Financial Controller. To ensure that the strategic vision set out for its subsidiaries are aligned, the Company has delegated its executive directors to serve on the respective Boards. These delegates will regularly update the results of operations of the subsidiaries to the ARMC, which endorses the results to the Board for approval. The ARMC and FMI’s management ensures that management of the subsidiaries maintain a sound risk management framework and internal control system to mitigate material risk exposures identified internally.
Yoma Bank
Yoma Bank (the “Bank”) places great importance on maintaining a sound risk management and internal control framework. The Board of the Bank, via the Audit and Risk Oversight Committees, is tasked with ensuring that appropriate risk management and internal systems are established and working effectively. Among other things, the Board of the Bank (i) approves risk management procedures and ensures compliance with such procedures; (ii) analyzes, evaluates, and improves the effectiveness of the internal risk management and internal control procedures on a regular basis; (iii) develops adequate incentives for executive bodies, departments and employees to apply internal control systems; and (iv) ensures that the Bank complies with legislation and charter provisions. In implementation of the framework, a strong independent internal audit team is in place to directly report to the Audit Committee of YB and to conduct periodic review of key identified areas including changes in relevant policies, internal control system, corporate governance, operations, and security risks. Acting as the main liaison between the External Auditors and the Board of YB, the Audit Committee monitors YB’s internal controls and framework to ensure transparency across the business functions of the Bank, and periodically reviews the integrity of the Bank and makes recommendations for improvement. YB’s Risk Oversight Committee reviews the effectiveness of the Enterprise Risk Management Framework particularly in relation to risk identification, measurement, mitigation, and monitoring. It ensures the risk appetite approved by the Board is properly implemented; and facilitates ongoing dialogue on risk within YB.
Pun Hlaing Hospitals (“PHHs”)
The operating guideline of PHHs is under the governance of its Chief Financial Officer. The shareholders of PHHs namely, the Company and its joint venture partner, OUE Lippo Healthcare Limited (“OUELH”) have appointed their senior management personnel on the boards of PHHs to oversee the financial system and operation of PHHs’ periodically. This is to ensure that 1) strategic objectives set for PHHs are aligned; 2) compulsory steps are taken for the achievement of its strategic goals; and 3) a comprehensive set of oversight controls to put management decisions in check and to prevent it from exposing to various risks that are prone to occur in the healthcare sector.
Risk Response & Mitigation Measures
Operational Risks
Environmental, Health & Safety Risks
Risk description
Negative impacts on the Group’s financial performance and productivity.
Drivers
- 1.1 Fire accidents
- 1.2 Climate change extreme weather, natural disaster, e.g. earthquakes, floods
- 1.3 Infectious diseases outbreak such as COVID 19, swine flu, SARS, Ebola
Implications for value creation
- 1.1 Delayed business expansion and recovery
- 1.2 Operations suspension
- 1.3 Loss of lives, reputational damage and interruption in our business operations
Risk response and mitigating measures
- 1.1 Delivering regular fire drill training to all employees across the Group on a regular basis
- 1.2 Implemented Health and Safety Policy, HR Policies and Guidelines to practice across the Group
- In the case of COVID 19, the Group set up a Covid Control Center (CCC) to deliver Covid-19 Emergency Response.
- 1.3 Provide all employees, medial plans, life insurance plans and special medical coverage to employees who are diagnosed as COVID-19 patients.
Internal & External Risks
Risk description
Risk of loss resulting from inadequate or failed internal organizational practices or driven by external forces.
Drivers
- 1.4 Financial losses and business instability
- 1.5 Increase in competition among property developers, healthcare providers, destination management companies, financial services providers
Implications for value creation
- 1.4 Failures in operational processes, internal policies or support systems in all business activities
- 1.5 Increased costs to acquire land and raw material, increases in unsold properties, decreases in earning from our core businesses due to lack of competitive advantages
Risk response and mitigating measures
- 1.4 Apply a risk-based internal audit to help the Group’s businesses accomplish the objectives by bringing a systematic and disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes through the enterprise risk management (ERM) framework. ERM also helps to address operational and finance risks are within the risk appetite monitored by management and are with the Group’s overall business objectives.
- 1.5 Maintain win-win business relationship with our businesses’ suppliers and business partners
Financial Risks
Risk description
Volatility in interest rates, foreign exchange rates could have a material adverse effect on our cash flows and results of operations.
Drivers
- 2.1 Liquidity Risk
- 2.2 Capital Risks
Implications for value creation
- 2.1 A firm’s possible inability to meet its short-term debt obligations, thereby incurring exceptionally large losses
- 2.2 Inability to make regular dividend payment
Risk response and mitigating measures
- 2.1 Board of Directors approve an asset liability management (ALM) policies. Liquidity limits are set to address liquidity shocks, whether affecting most financial institutions or the Yoma Bank uniquely, are fully covered and a Contingent Funding Plan is developed. Liquidity levels are being strictly monitored for adherence to the Board specified minimums (as defined in the ALM policy) or the requirements prescribed by the CBM.
- 2.2 The Group’s objectives when managing capital are to safeguard the Group’s ability to continue as a going concern and to maintain an optimal capital structure so as to maximize shareholder value. In order to maintain or achieve an optimal capital structure, the Group may adjust the amount of dividend payment, return capital to shareholders, issue new shares, obtain new borrowings or sell assets to reduce borrowings.
Strategic Risks
Human Resources Risks
Risk description
Increase in labor cost and loss of efficiency.
Drivers
- 3.1 Our dependence on our Management team and skilled personnel
- 3.2 Our inability to attract and retain such persons
- 3.3 Lack of Keyman Insurance
Implications for value creation
- 3.1 Adverse financial impact
- 3.2 Increase in employee turnover, and costs to hire qualified employees and contractors
- 3.3 Interruption in business operations and slow down business growth
Risk response and mitigating measures
3.1 Consistently providing training and leadership programs to every level of employees across the Group.
3.2 The Yoma Group’s Human Resources Department is tasked to constantly review and identify high-performing individuals internally and externally to serve as a pipeline for leadership succession planning.
- Develop innovative talent retention programmes such as leadership training and other development programmes
- Create safe, fun and flexible working environment
- Develop effective internal communication system to increase employees’ synergy
- Provide a variety of welfare benefit plans and Yoma Employees’ Perks so that employees feel that they are taken care of and to increase their sense of belonging
- Lay out core values to increase employee morale and sense of belong across the Group.
Societal Risks: Economic and Social Instability
Risk description
Change in customers’ and shareholders’ behavior and taste which results in them investing in other types of investments.
Drivers
- 3.4 The Company’s inability to pay dividends annually
- 3.5 Claims or lawsuits derived from medical malpractice claims and accidents due in mismanagement in construction sites
- 3.6 Credit Risks in the banking services sector
Implications for value creation
- 3.4 Loss of shareholders’ loyalty and reputational damage
- 3.5 Loss of customers’ loyalty and reputational damage
- 3.6 Risk of loss arising from any failure by a borrower or counterparty to meet its financial obligations when such obligation is due
Risk response and mitigating measures
3.4 Shareholder’s complaints are taken seriously and are solved by the Corporate Office Team as soon as they arise. In a financial year when dividend is not paid, the Management will explain the rationale behind such action during media briefings and the Company’s Annual General Meeting.
- Established a Corporate Office Team (Corporate Office Team) to regularly analyse the market trend and to develop strategies with the Management to ensure FMI’s shares are competitive in value and quality among its fellow listed companies;
- The Team is also tasked to maintain and build positive relationships with individual shareholders by providing one-on-one meeting at the Company’s Head Office or Annual General Meetings, and via other communication platforms;
- Group Legal and Group Communication departments are tasked with monitoring all commercial materials to minimize the risk of potential threat of adverse media publicity.
- The Company’s effort in being transparent and open in communicating the internal movements are evident in the public announcements and annual media briefing.
3.5 Provide channels for stakeholders and customers to report grievances such as a feedback box at each business operation unit and anonymous reporting via a QR code available in the Company’s Stakeholder Engagement Policy
3.6 Board of Directors from banking services approve major policies and limits that govern the monitoring of the credit risk. It structures the levels of credit risk it undertakes by placing limits on the amount of risk acceptable in relation to one borrower, or group of borrowers and industry segments.
Information Technology Risks
Risk description
Risk of loss resulting from inadequate or failed internal processes, people or from external event.
Drivers
- 4.1 Weaknesses, disruption or failures in overall management and IT systems
Implications for value creation
- 4.1 Loss of competitive advantage and fragile to external attacks
Risk response and mitigating measures
4.1 Balancing the cost and risk within the constraints of the risk appetite of the Company and the Group’s businesses to ensure that this balance is consistent with the prudent management required of a large Myanmar organization.
- Implemented a centralized core banking system (CBS) at our subsidiary, Yoma Bank, to provide a common and stable operating platform to develop multi-channel service delivery.
- Implemented IT security for the overall network system across the Group.
- Utilized a firewall system to monitor internal traffic, defend against potential external anti-hacking and anti-virus attacks.
- Planning to integrate the proxy system to monitor and filter contact traffics in the network.
- Implemented a directory server to authenticate users and passwords.
- Adopted Advance Threat Prevention (ATP) scanning function to monitor phishing and malware.
- Adopted SSLVPN to build a secured virtual tunnel for WFH employees.
- Applied two-factor authentication on for email access.
Compliance Risks
Risk description
Material adverse effect on the Group’s businesses and its financial condition
Drivers
- 5.1 Failure or inability of the Group to comply with relevant industry-specific laws, regulations or procedures; Directors Breach of Fiduciary Duties, Corruption and Bribery and Corporate Fraud
- 5.2 Changes in business environment factors
Implications for value creation
- 5.1 Revoking of rights by the government without compensation
- 5.2 Delays encountered in procuring the necessary approvals from the relevant regulatory bodies
Risk response and mitigating measures
5.1 Identifies and manages compliance risk through effective use of its external and internal compliance advisers
- Monitors its entities’ compliance with relevant international regulatory requirements
- Ensuring and communicating risk and its control information among the board, auditors and management which is led by Audit and Risk Management Committee and Group’s Risk Management Department
5.2 Build brand loyalty among our businesses’ consumers