Overview
A robust and agile Risk Management Framework enables the achievement of Zain’s strategic objectives by identifying, analyzing, mitigating, monitoring and governing risks or potential threats to strategic objectives.
Accordingly, Zain Group’s Risk Management function plays a vital role within the company, reporting to the Board Risk Committee (BRC), which meets quarterly to discuss the risk profile of Zain Group. The BRC oversees the implementation of a strategic top-down risk assessment exercise covering all of Zain’s operations, while also reviewing and approving the risk management framework and plan on an annual basis.
In addition, the BRC oversees compliance with risk management policies and procedures, and reviews adequacy of the risk management framework in relation to the risks faced by the organization
Framework
Zain’s Risk Management Framework has been benchmarked with leading global risk management standards and guidance such as ISO 31000 and the Committee of Sponsoring Organization (COSO) framework
ERM POLICY, PROCEDURES AND ROLES & RESPONSIBILTIES
- Establish the context
- Identify risks
- Analyze risk
- Evaluate risks
- Treat risks
Figure 1:Zain Risk Management Framework (alignment to ISO 31000)
Zain’s Risk Management framework continues to use an Impact-Likelihood matrix to determine the risk rating of events facing the company across its operations. The impacts are assessed across multiple parameters that include financial, reputational, climate change, markets, customers, and employees among others. The rating also takes into consideration the pre- and post-mitigated status of the risks, providing information on both the status of inherent and residual risk status to the organization.
The Risk Management function uses Key Risk Indicators (KRIs) that are monitored and analyzed by Zain Group and Its operating companies to ensure that risk profiles are within the acceptable risk appetite set by the Board of Directors. The table below illustrates some of the key risks across Zain Group and how they are being mitigated through the various mitigation options:
Table 1: Key Risks for Zain
| Description | Impact | Mitigation | |
|
Regulatory Changes & Management of External Stakeholders |
As our business is undergoing a digital transformation, the regulatory implications bring new challenges. |
Increased cost of operations (license fees, cost of regulatory compliance) leading to lower profits; Delay or rejection in launching new businesses and services to create new revenue streams. |
Collaborate with market regulatory authorities and other stakeholders, engaging on market issues, with a clear focus on common benefit. Innovation on new products and services to enhance revenues and overcome increased regulatory costs |
|
Cybersecurity Risks |
As technologies advance rapidly, cybersecurity threats are also evolving and need continuous monitoring. |
Customer data breach, financial, reputational or regulatory consequences |
Continuous enhancement of our Cybersecurity capabilities by updating:
|
|
Over the Top (OTT) applications |
Disruptive technologies are being adopted at an extremely fast rate, where competitors are infringing into traditional voice and SMS revenue streams. |
These OTT players continue to impact revenue for all mobile network operators without having to conform to regulatory implications. |
Transform our business from a pure telecommunications model to a digital lifestyle provider by creating innovative products and services and reinventing business models. |
|
Geopolitical & Macro-economic situation |
Zain operates in multiple markets, and changes to macro-economic indicators impact operations enormously. |
Reduced customer spending ability leads to reduced revenues impacting the execution of the company’s strategy. Weakening currencies impact the profitability of Zain’s operations and asset valuation. Geopolitical hindrances lead to reduced access to capital and technology. |
Ensure cost optimization initiatives and access to long and short-term capital options through varied sources of funding. Employ various hedging instruments to prevent value erosion of assets. Continuous improvement of our business continuity capabilities across our operations |
|
Price Wars & Irrational Competition |
Unrestrained competitors or irresponsible operators with low value and market share could perpetrate market erosion through price pressures |
Impacts revenue, profitability and customer experience metrics. |
Observe the competitor landscape in all markets, and counter suitably. Ensure the market is fair and competitive, while trying to create value propositions to maintain customer loyalty. |
Highlights for the year
Implementation of an enhanced Risk Management Reporting Process within the Group and its operating companies
Commencement of Group-wide Cybersecurity Program Maturity Benchmark exercise to operationalize Zain’s Cybersecurity Strategy 2019-2021. The scope includes a full-spectrum review of Telecom & IT security environments across Zain’s operations.
ISO Certifications
- Maintenance of existing ISO 27001 Information Security Management System at Zain operations
- Zain Kuwait achieved the ISO 22301 Business Continuity Management System certification, becoming the first operation in the Group to achieve the milestone.
Risk Synergy Forum
- After the successful undertaking of the first Risk Synergy Forum in 2018, Group Risk organized the second gathering in Bahrain in October 2019. The two-day conference was inaugurated by Board Risk Committee Chairperson Dr. Saud Al Nahari and the Group Chief Risk Officer, Mr. Abdul Ghaffar Setareh. Risk Management professionals from across Zain’s operations shared their best practices across enterprise risk management, business continuity, and cybersecurity management. New trends in cybersecurity and risk management were presented to ensure all operations are aligned, work to enhance synergy possibilities, and establish a strategic direction for Risk Management.
Cybersecurity
- Overseen by Group Risk Management, Zain operations continue to invest in automated detection and prevention solutions to address evolving cybersecurity threats. Rigorous security reviews and testing across operations are performed by Group Risk Management to validate effectiveness of security controls.
Business Continuity Management
- Group Risk Management conducted resilience reviews in 2019 for mission critical services within operations where resilience and continuity risks were identified and assigned mitigation plans. All Zain operations’ Risk Management teams performed controlled testing and exercising of business continuity plans to assess the robustness and reliability of the plans.