1. Purpose
This policy establishes Murzo Group’s approach to identifying, assessing, managing, and monitoring risk across its operations, projects, and strategic activities.
The purpose of this policy is to support informed decision-making, protect Murzo Group’s legal, financial, operational, and reputational interests, embed risk awareness into governance and management practices, and promote consistency in how risks are considered and addressed.
This policy is aligned with the principles of ISO 31000 – Risk Management, but does not claim certification.
2. Scope
This policy applies to all Murzo Group operations and activities, strategic, operational, financial, legal, and reputational risks, projects, partnerships, research, and international engagements, digital, physical, and hybrid operations, and employees, contractors, and authorised representatives.
It applies globally and irrespective of jurisdiction.
3. Risk Management Principles
Murzo Group’s approach to risk management is guided by the following principles, consistent with ISO 31000:
3.1 Integrated
Risk management is integrated into governance, strategy, and operational decision-making.
3.2 Structured & Comprehensive
Risks are considered in a consistent and methodical manner, proportionate to their nature and potential impact.
3.3 Customised
Risk management practices are tailored to Murzo Group’s activities, scale, and risk profile.
3.4 Inclusive
Relevant stakeholders may be consulted where appropriate to improve awareness and decision quality.
3.5 Dynamic
Risk considerations evolve in response to internal and external change.
3.6 Best Available Information
Risk decisions are informed by available information, recognising uncertainty and limitations.
3.7 Continuous Improvement
Risk management practices are reviewed and refined over time.
4. Risk Categories
Murzo Group recognises that risks may arise across multiple categories, including but not limited to:
- Strategic Risks: market conditions, partnerships, growth decisions
- Operational Risks: process failures, resource constraints, supply chain issues
- Legal & Regulatory Risks: compliance, contractual obligations, enforcement
- Financial Risks: cash flow, credit, pricing, currency exposure
- Information & Cyber Risks: data security, system resilience, IP protection
- Health, Safety & Environmental Risks: physical operations, fieldwork, sustainability
- Reputational Risks: public perception, partner conduct, communications
- Geopolitical & International Risks: cross-border operations, sanctions, trade controls
Risk categories may overlap and are assessed holistically.
5. Risk Identification
Murzo Group identifies risks through strategic planning and review, project initiation and change management, partner and supplier assessment, incident analysis and lessons learned, and monitoring of legal, regulatory, and market developments.
Risk identification is ongoing and context-specific.
6. Risk Assessment
Identified risks may be assessed based on likelihood of occurrence, potential impact (financial, legal, operational, reputational), velocity (speed at which impact may materialise), and existing controls and mitigations.
Assessment is qualitative and proportionate; Murzo Group does not guarantee completeness or accuracy.
7. Risk Treatment
Murzo Group may choose to manage risks through one or more of the following approaches:
- Avoidance: deciding not to proceed with certain activities
- Reduction: implementing controls to reduce likelihood or impact
- Transfer: allocating risk through contracts or insurance
- Acceptance: accepting residual risk where appropriate
The chosen approach reflects Murzo Group’s risk appetite, legal obligations, and strategic objectives.
8. Risk Appetite & Decision-Making
Murzo Group maintains a risk appetite appropriate to its business objectives, legal and regulatory environment, ethical standards, and financial capacity.
Final decisions regarding risk acceptance or treatment rest with Murzo Group management.
9. Roles & Responsibilities
- Senior Management: Oversight of risk governance and strategic risk decisions
- Operational Leads: Identification and management of risks within their areas
- Employees & Contractors: Awareness of risks and reporting concerns
Risk management is a shared responsibility.
10. Integration with Other Policies
This policy operates alongside and is supported by Murzo Group’s International Operations & Cross-Border Governance Policy, Conflict of Interest Policy, Information Classification & Handling Policies, Cybersecurity & Security Assurance Framework, Business Continuity & Disaster Recovery Policy, and Health, Safety & Wellbeing Policy.
Where conflicts arise, contractual terms and applicable law prevail.
11. Monitoring & Review
Murzo Group may monitor key risks periodically, review the effectiveness of controls, adjust risk treatment strategies, and respond to incidents or near-misses.
Murzo Group does not commit to maintaining formal risk registers or public reporting unless required.
12. Incident Escalation
Significant risks or incidents may be escalated internally for review and action.
Murzo Group reserves discretion over escalation thresholds, response measures, and disclosure decisions.
13. Limitations & Legal Position
This policy does not eliminate risk, does not guarantee prevention of loss or harm, does not create contractual or statutory obligations, and does not constitute legal or financial advice.
Nothing in this policy excludes liability that cannot be lawfully excluded.
14. Review & Updates
This policy is reviewed periodically and may be updated to reflect changes in operations or strategy, legal or regulatory developments, and emerging risks.
Updated versions will be published where appropriate.