Risk Management Policy

Version 1.0 · Last Updated:

1. Purpose

This policy establishes Murzo Group’s approach to identifying, assessing, managing, and monitoring risk across its operations, projects, and strategic activities.

The purpose of this policy is to support informed decision-making, protect Murzo Group’s legal, financial, operational, and reputational interests, embed risk awareness into governance and management practices, and promote consistency in how risks are considered and addressed.

This policy is aligned with the principles of ISO 31000 – Risk Management, but does not claim certification.

2. Scope

This policy applies to all Murzo Group operations and activities, strategic, operational, financial, legal, and reputational risks, projects, partnerships, research, and international engagements, digital, physical, and hybrid operations, and employees, contractors, and authorised representatives.

It applies globally and irrespective of jurisdiction.

3. Risk Management Principles

Murzo Group’s approach to risk management is guided by the following principles, consistent with ISO 31000:

3.1 Integrated

Risk management is integrated into governance, strategy, and operational decision-making.

3.2 Structured & Comprehensive

Risks are considered in a consistent and methodical manner, proportionate to their nature and potential impact.

3.3 Customised

Risk management practices are tailored to Murzo Group’s activities, scale, and risk profile.

3.4 Inclusive

Relevant stakeholders may be consulted where appropriate to improve awareness and decision quality.

3.5 Dynamic

Risk considerations evolve in response to internal and external change.

3.6 Best Available Information

Risk decisions are informed by available information, recognising uncertainty and limitations.

3.7 Continuous Improvement

Risk management practices are reviewed and refined over time.

4. Risk Categories

Murzo Group recognises that risks may arise across multiple categories, including but not limited to:

  • Strategic Risks: market conditions, partnerships, growth decisions
  • Operational Risks: process failures, resource constraints, supply chain issues
  • Legal & Regulatory Risks: compliance, contractual obligations, enforcement
  • Financial Risks: cash flow, credit, pricing, currency exposure
  • Information & Cyber Risks: data security, system resilience, IP protection
  • Health, Safety & Environmental Risks: physical operations, fieldwork, sustainability
  • Reputational Risks: public perception, partner conduct, communications
  • Geopolitical & International Risks: cross-border operations, sanctions, trade controls

Risk categories may overlap and are assessed holistically.

5. Risk Identification

Murzo Group identifies risks through strategic planning and review, project initiation and change management, partner and supplier assessment, incident analysis and lessons learned, and monitoring of legal, regulatory, and market developments.

Risk identification is ongoing and context-specific.

6. Risk Assessment

Identified risks may be assessed based on likelihood of occurrence, potential impact (financial, legal, operational, reputational), velocity (speed at which impact may materialise), and existing controls and mitigations.

Assessment is qualitative and proportionate; Murzo Group does not guarantee completeness or accuracy.

7. Risk Treatment

Murzo Group may choose to manage risks through one or more of the following approaches:

  • Avoidance: deciding not to proceed with certain activities
  • Reduction: implementing controls to reduce likelihood or impact
  • Transfer: allocating risk through contracts or insurance
  • Acceptance: accepting residual risk where appropriate

The chosen approach reflects Murzo Group’s risk appetite, legal obligations, and strategic objectives.

8. Risk Appetite & Decision-Making

Murzo Group maintains a risk appetite appropriate to its business objectives, legal and regulatory environment, ethical standards, and financial capacity.

Final decisions regarding risk acceptance or treatment rest with Murzo Group management.

9. Roles & Responsibilities

  • Senior Management: Oversight of risk governance and strategic risk decisions
  • Operational Leads: Identification and management of risks within their areas
  • Employees & Contractors: Awareness of risks and reporting concerns

Risk management is a shared responsibility.

10. Integration with Other Policies

This policy operates alongside and is supported by Murzo Group’s International Operations & Cross-Border Governance Policy, Conflict of Interest Policy, Information Classification & Handling Policies, Cybersecurity & Security Assurance Framework, Business Continuity & Disaster Recovery Policy, and Health, Safety & Wellbeing Policy.

Where conflicts arise, contractual terms and applicable law prevail.

11. Monitoring & Review

Murzo Group may monitor key risks periodically, review the effectiveness of controls, adjust risk treatment strategies, and respond to incidents or near-misses.

Murzo Group does not commit to maintaining formal risk registers or public reporting unless required.

12. Incident Escalation

Significant risks or incidents may be escalated internally for review and action.

Murzo Group reserves discretion over escalation thresholds, response measures, and disclosure decisions.

13. Limitations & Legal Position

This policy does not eliminate risk, does not guarantee prevention of loss or harm, does not create contractual or statutory obligations, and does not constitute legal or financial advice.

Nothing in this policy excludes liability that cannot be lawfully excluded.

14. Review & Updates

This policy is reviewed periodically and may be updated to reflect changes in operations or strategy, legal or regulatory developments, and emerging risks.

Updated versions will be published where appropriate.

Murzo Group signature