0% found this document useful (0 votes)
49 views6 pages

Operational Risk Management Framework

The Operational Risk Management Policy of The Leonnestar Group establishes a framework for identifying, assessing, mitigating, monitoring, and reporting operational risks to minimize financial losses and ensure compliance. It applies to all departments and employees globally, focusing on non-financial risks from internal processes and external events. The policy emphasizes proactive risk management, accountability, and continuous improvement to enhance operational efficiency and protect the Group's reputation.

Uploaded by

kevin oriku
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
49 views6 pages

Operational Risk Management Framework

The Operational Risk Management Policy of The Leonnestar Group establishes a framework for identifying, assessing, mitigating, monitoring, and reporting operational risks to minimize financial losses and ensure compliance. It applies to all departments and employees globally, focusing on non-financial risks from internal processes and external events. The policy emphasizes proactive risk management, accountability, and continuous improvement to enhance operational efficiency and protect the Group's reputation.

Uploaded by

kevin oriku
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Operational Risk Management Policy

Policy ID: ORM-001


Effective Date: August 14, 2025
Version Number: 1.0
1. Purpose and Scope
1.1 Purpose
The purpose of this Operational Risk Management Policy is to establish a systematic
and comprehensive framework for identifying, assessing, mitigating, monitoring, and
reporting operational risks across The Leonnestar Group. This policy aims to minimize
financial losses, prevent disruptions to business processes, enhance operational
efficiency, ensure compliance with internal procedures and external regulations, and
safeguard the Group's reputation, thereby contributing to the achievement of
strategic objectives and sustainable growth.

1.2 Scope
This policy applies to all departments, subsidiaries, employees, contractors, and all
business processes and systems within The Leonnestar Group globally. It covers all
non-financial risks arising from inadequate or failed internal processes, people, and
systems, or from external events. This includes, but is not limited to, risks related to
process failures, human error, technology breakdowns, security incidents, legal and
compliance breaches (excluding those covered specifically by financial or tax
policies), and external events impacting operations.

2. Policy Statement
The Leonnestar Group acknowledges that operational risks are inherent in all
business activities. We are committed to proactive and systematic management of
these risks to ensure the resilience and effectiveness of our operations. By
embedding robust operational risk management practices into our daily activities, we
aim to protect our assets, maintain business continuity, enhance service delivery, and
support our strategic goals. This policy ensures that risks are identified early,
understood thoroughly, and managed effectively.

2.1 Principles of Operational Risk Management


Our approach to operational risk management will be guided by the following
principles:
● Integration: Operational risk management will be integrated into daily business
processes and decision-making, not treated as a separate activity.
● Proactive Identification: Actively identify potential risks before they materialize,
focusing on root causes.
● Accountability: Clear ownership and accountability for managing operational
risks will be assigned at all levels.
● Transparency: Significant operational risks, mitigation strategies, and incident
outcomes will be communicated transparently within the Group.
● Continuous Improvement: Regularly review and improve operational risk
management processes based on lessons learned from incidents and changes in
the operating environment.
● Value Protection: Prioritize efforts to protect operational stability, human safety,
data integrity, and the Group's reputation.
2.2 Key Areas of Operational Risk Management
2.2.1 Risk Identification and Assessment
● Process Mapping: Map key business processes to identify potential points of
failure, bottlenecks, and control weaknesses.
● Risk Registers: Maintain centralized risk registers at both Group and
departmental/subsidiary levels to document identified operational risks, their
potential impact, likelihood, and existing controls (aligned with Risk Management
& ESG Policy).
● Scenario Analysis: Conduct scenario analysis for high-impact, low-frequency
events to understand potential exposure and test response capabilities (e.g.,
major system outages, supply chain disruptions).
● Incident Data Collection: Systematically collect and analyze data on operational
incidents, near misses, and control failures to inform risk assessments.
2.2.2 Risk Mitigation and Control
● Internal Controls: Implement and maintain robust internal controls (preventative
and detective) within all operational processes to mitigate identified risks (as per
Internal Controls Policy). This includes, but is not limited to:
○ Segregation of Duties: Ensure no single individual has control over an entire
process.
○ Authorization & Approval: Mandate appropriate authorization levels for
transactions and activities.
○ Process Automation: Leverage technology to reduce human error and
increase efficiency.
○ Quality Assurance: Implement checks and balances to ensure accuracy and
quality in outputs.
● Contingency Planning: Develop and regularly update business continuity and
disaster recovery plans for critical operations and systems (as per Crisis
Response & Communication Policy).
● Training & Awareness: Provide ongoing training to employees on operational
procedures, internal controls, and risk awareness to reduce human error.
● Supplier Risk Management: Assess and manage operational risks associated
with third-party suppliers and partners, including service level agreements and
contingency plans (aligned with Logistics & Inventory Management Policy).
2.2.3 Monitoring and Reporting
● Key Risk Indicators (KRIs): Establish and monitor Key Risk Indicators (KRIs) that
provide early warning signals of increasing operational risk exposure.
● Regular Reporting: Provide regular reports on operational risk profiles, incident
summaries, and control effectiveness to relevant management, Executive
Leadership, and the Audit Committee.
● Control Self-Assessment: Encourage departments to conduct periodic self-
assessments of their operational controls.
2.2.4 Incident Management and Learning
● Incident Response: Implement clear protocols for responding to operational
incidents, including immediate containment, escalation, investigation, and
recovery (as per Crisis Response & Communication Policy).
● Root Cause Analysis: Conduct thorough root cause analysis for all significant
operational incidents to prevent recurrence.
● Lessons Learned: Systematically capture and disseminate lessons learned from
operational incidents and control breakdowns across the Group to improve
processes and controls.

3. Roles and Responsibilities


3.1 Board of Directors (Audit Committee)
● Oversight: Provides high-level oversight of the Group's operational risk
management framework, reviewing significant operational risks and
management's mitigation strategies (aligned with Board Oversight Policy).
● Review: Reviews reports on operational risk profile, major incidents, and the
effectiveness of internal controls related to operations.
3.2 Group Chairman, CEO & Managing Director
● Overall Accountability: Bears ultimate accountability for the establishment and
effectiveness of the Group's operational risk management framework.
● Culture: Fosters a culture of proactive risk management and continuous
improvement in operational efficiency.
3.3 Chief Operations Officer (COO)
● Policy Ownership: Serves as the primary Group Executive responsible for the
development, implementation, and enforcement of this policy.
● Framework Implementation: Oversees the day-to-day operational risk
management activities across all departments and subsidiaries.
● Coordination: Ensures effective coordination of operational risk management
efforts across functions (as per Executive Leadership Coordination Policy).
● Reporting: Provides regular reports on the operational risk landscape to the
Executive Leadership Team and the Board.
3.4 Chief Technology Officer (CTO)
● Technology Risk: Responsible for identifying, assessing, and mitigating
operational risks related to IT infrastructure, cybersecurity, data integrity, and
system availability.
● Business Continuity (IT): Oversees disaster recovery and IT business continuity
planning.
3.5 Other Executive Leadership Team Members (CFO, CMO, CSO, HR)
● Functional Risk Management: Responsible for identifying, assessing, and
mitigating operational risks within their respective functional areas.
● Control Implementation: Ensure that appropriate operational controls are
designed and implemented within their departments.
3.6 Internal Audit Department
● Independent Assurance: Provides independent assurance on the effectiveness
of the Group's operational risk management framework and internal controls (as
per Audit & Financial Transparency Policy and Internal Controls Policy).
● Recommendations: Recommends improvements to operational control
processes based on audit findings.
3.7 Departmental Heads and Managers
● Risk Identification: Proactively identify and assess operational risks specific to
their areas of responsibility.
● Control Enforcement: Ensure that operational control procedures are
understood, implemented, and adhered to by their teams.
● Incident Management: Manage operational incidents within their departments,
ensuring proper reporting and initial response.
3.8 All Employees
● Risk Awareness: Understand the operational risks associated with their roles
and responsibilities.
● Adherence: Comply with all operational procedures and internal controls.
● Reporting: Promptly report any operational incidents, control weaknesses, or
potential risks to their manager.

4. Compliance and Enforcement


4.1 Monitoring and Reporting
● Compliance with this policy will be continuously monitored through ongoing
management oversight, regular operational performance reviews, incident
tracking, and periodic internal audits.
● Key operational risk indicators and incident summaries will be regularly reported
to the COO, Executive Leadership, and the Audit Committee.
● Effectiveness of risk mitigation actions and control remediation plans will be
tracked and reported.
4.2 Consequences of Non-Compliance
● Failure to comply with this policy, or a breakdown in operational risk
management, can lead to increased operational failures, service disruptions,
financial losses, regulatory non-compliance, and reputational damage.
● For individuals, non-compliance, particularly regarding adherence to operational
controls or negligence leading to significant incidents, may result in disciplinary
action, up to and including immediate termination of employment or contract.

5. Definitions
● Operational Risk: The risk of loss resulting from inadequate or failed internal
processes, people and systems or from external events (as per Basel II
definition).
● Risk Mitigation: Actions taken to reduce the likelihood or impact of an identified
risk.
● Internal Control: A process designed to provide reasonable assurance regarding
the achievement of objectives related to operations, reporting, and compliance.
● Key Risk Indicator (KRI): A metric that provides an early signal of increasing risk
exposure in a particular area.
● Business Continuity Plan (BCP): A plan that outlines how an organization will
maintain critical business functions during and after a disruption.
● Disaster Recovery Plan (DRP): A plan that focuses on restoring IT systems and
infrastructure after a disaster.
● Root Cause Analysis: A systematic process for identifying the underlying causes
of an operational incident or problem.

6. Related Documents and Appendices


● The Leonnestar Group Corporate Governance Framework Policy
● The Leonnestar Group Risk Management & ESG Policy
● The Leonnestar Group Internal Controls Policy
● The Leonnestar Group Crisis Response & Communication Policy
● The Leonnestar Group Executive Leadership Coordination Policy
● The Leonnestar Group Field Operations Policy
● The Leonnestar Group Logistics & Inventory Management Policy
● The Leonnestar Group Operational Procedures Manual
● Business Continuity Plans (to be developed)
● Disaster Recovery Plans (to be developed)
● Incident Management Procedures (to be developed)

Common questions

Powered by AI

Scenario analysis plays a crucial role in The Leonnestar Group's operational risk management by allowing the organization to prepare for high-impact, low-frequency events such as major system outages or supply chain disruptions. It helps in understanding potential exposures and tests the organization's response capabilities, thereby enhancing preparedness and resilience against unexpected operational disruptions . This process is important because it equips the organization to handle and mitigate severe incidents more effectively, minimizing the potential impact on operations .

The Chief Technology Officer (CTO) at The Leonnestar Group plays a critical role in managing technology-related operational risks by identifying, assessing, and mitigating risks associated with IT infrastructure, cybersecurity, data integrity, and system availability. The CTO oversees disaster recovery and IT business continuity planning, ensuring that the organization's technological resources are resilient and prepared to handle disruptions. This role is vital for maintaining the security and functionality of IT systems, which are essential for supporting business operations and strategic goals .

The Leonnestar Group's approach to supplier risk management is effective in maintaining operational stability by assessing and managing risks associated with third-party suppliers and partners. This includes setting clear service level agreements, having contingency plans in place, and regularly evaluating supplier performance . This proactive management helps to mitigate risks that could arise from supplier failures, thus ensuring that the supply chain and business operations remain stable and reliable, safeguarding against potential disruptions .

Training and awareness programs are fundamental in reducing human error at The Leonnestar Group by equipping employees with the knowledge and skills needed to follow operational procedures and internal controls accurately. Ongoing education ensures that employees are aware of potential risks and understand the importance of adhering to established protocols, thereby minimizing errors due to lack of awareness or misunderstandings . These programs also foster a culture of risk awareness and proactive risk management, contributing to more reliable and efficient operational processes .

Incident management and learning contribute to improving The Leonnestar Group's operational risk management framework by providing structured processes for responding to incidents and extracting valuable insights. Clear protocols for incident response, including immediate containment, escalation, investigation, and recovery, help manage and mitigate the impact of operational disruptions . Conducting thorough root cause analyses of significant incidents allows the organization to identify underlying issues and prevent recurrence. Systematically capturing and sharing lessons learned across the Group enables continuous improvement of processes and controls, enhancing the overall risk management framework .

The Leonnestar Group ensures continuous improvement in its operational risk management practices by regularly reviewing and enhancing processes based on lessons learned from incidents and changes in the operating environment. This includes conducting root cause analyses, capturing and sharing lessons learned across the organization, and updating risk management practices accordingly . These efforts contribute to strategic objectives by enhancing operational efficiency, maintaining business continuity, and supporting sustainable growth through improved risk identification and mitigation practices .

Integrating operational risk management into daily business processes enhances organizational resilience by ensuring that risk assessment and management are embedded into routine operations rather than being treated as isolated activities. This approach allows for the early identification of potential risks and ensures accountability and transparency in managing those risks, leading to improved decision-making and operational stability . By proactively embedding risk management into the organizational culture, the business can adapt more quickly to changes or disruptions, thus maintaining continuity and protecting its assets and reputation .

Key Risk Indicators (KRIs) are pivotal in providing early warning signals of increasing operational risk exposure at The Leonnestar Group. They serve as metrics that alert the organization to potential issues before they become critical, allowing for timely intervention and mitigation strategies . By monitoring KRIs, the organization can proactively manage risks, reduce the likelihood of operational incidents, and ensure that risk management efforts are aligned with changing operational landscapes. This relationship is essential for maintaining operational resilience and preventing service disruptions .

Non-compliance with The Leonnestar Group's Operational Risk Management Policy can lead to increased operational failures, service disruptions, financial losses, regulatory non-compliance, and reputational damage. For individuals, particularly in cases where non-compliance involves failure to adhere to operational controls or negligence leading to significant incidents, consequences may include disciplinary action up to immediate termination of employment or contract . These potential consequences highlight the importance of compliance for maintaining operational integrity and minimizing risk exposure .

Accountability and transparency are fundamental principles guiding operational risk management at The Leonnestar Group. Accountability ensures that there is clear ownership of risk management responsibilities at all organizational levels, reinforcing the importance of effective risk mitigation and control measures . Meanwhile, transparency involves open communication of significant operational risks, mitigation strategies, and incident outcomes within the Group, fostering a culture of trust and shared responsibility. These principles facilitate better coordination, decision-making, and alignment with strategic objectives by ensuring that all stakeholders are informed and engaged in risk management efforts .

You might also like