The FMI Group instils and promotes a risk management culture to allow prudent risk-based decision-making by embedding core values, principles, compliance and dynamic internal control systems in its day-to-day operations. Ongoing communication, education, monitoring and mitigation are an integral part of the FMI Group’s dynamic risk management culture and is adopted across all its businesses.

Investment assessments and due diligence exercises are carried out on prospective business opportunities to ensure that potential financial, operational and strategic risks are identified and mitigated prior to commitment. In addition, Fraud Risk Assessment is conducted across the group as part of the Annual Internal Audit Programme to ensure consistency with anti-corruption commitment. Half yearly and annual enterprise risk assessments are carried out to validate the existence and effectiveness of the controls in place, review the changes in risk profile, and update the existing controls if required.

Risk Management Framework provides a sound system of risk management and internal control, and is underpinned by a strong foundation of the FMI Group’s strong corporate governance culture, supported by five pillars of management control system being: Policies Procedures Internal External Audits Due Diligence Reviews Compliance Monitoring Reporting and Enterprise Risk Assessments, all of which are overseen by the Audit Committee and the Board.

Risk-Based Internal Audit

Risk-based internal audit is one of the main functions carried out by Group Risk Management to help the businesses to accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes through:

  1. Identification of potential risks inherent within the FMI Group and external risks which the FMI Group faces in the pursuit of its corporate objectives
  2. Assessing and rating all the identified risks in a meaningful way in order for the FMI Group to determine the extent of risks that it faces
  3. Treating all identified risks, as far as possible, through established controls or pending control plans
  4. Monitoring and updating any changes to the severity of the identified risks and any new risks that have emerged and
  5. Reporting key risks and the established controls (or pending controls plans) to the Audit Committee and the Board regularly.

EVOLUTION OF RISK

Over the years, FMI assessed various risks it is exposed to. The diagram below indicates a snapshot of FMI’s evolving risks.
Five major risks identified are affecting FMI’s ability to create value over the short, medium and long term.

FY 2016 - 17

FY 2018 - 19

5 major risks have been identified to
provide a more integrated approach.

FINANCIAL SERVICES

  • Interest Rate Risk
  • Exchange Rate Risk
  • Maturity Risk
  • Cyber Security Risk
  • Collateral Risk

HEALTHCARE

  • Common Healthcare Sector Risk
  • Pandemic Risk

Operational Risk
Financial Risk

REAL ESTATE

  • Demand Risk
  • Cost Risk
  • Liquidity Risk

GENERAL

  • Market Competition Risk
  • IT Risk
  • HR Risk
  • Regulatory Risk
  • Profitability Risk
  • Technology Risk

Strategic Risk
IT Risk
Compliance Risk

5 MAJOR RISK CATEGORIES

INFORMATION TECHNOLOGY RISK

  • Inadequate IT Governance
  • Cyber Security Risk

STRATEGIC RISK

  • Political, Economic and Social Instability
  • Regulatory Risk

5-MAJOR-RISKS

OPERATIONAL RISK

  • Lack of Efficiency
  • Environmental and Social / Health and Safety Risk

FINANCIAL RISK

  • Long Term Profitability and Net Margin
  • Cash Flow and Funding Risk
  • Cash Management Risk

COMPLIANCE RISK

  • Changes in Legislation and Policies
  • Legal and Regulatory Compliance Risk