Corporate Governance
Risk Management and Internal Audit
Rule V: Apply Sound Systems of Risk Management and Internal Audit
Summary of the Implementation of Requirements for Establishing an Independent Risk Management Department/Office/Unit
An independent Risk Management Department has been established in line with good governance practices, reflecting the Company’s commitment to strengthening an effective and integrated risk management framework. The Department operates with full independence under the supervision of the Chief Risk Officer, supported by the necessary human and technical resources, and maintains direct communication channels with the Board of Directors to ensure integrity, objectivity, and transparency.
The Department is responsible for identifying, analyzing, assessing, and monitoring organizational risks, serving as a key component of the second line of defense within the Company’s three-lines-of-defense framework. It reports directly to the Risk Committee of the Board of Directors, in accordance with the approved organizational structure, ensuring effective oversight, control, and timely escalation of material issues and key matters.
The independent Risk Management Department is fully committed to applicable legal and regulatory requirements, enhancing the Company’s ability to proactively identify and manage risks, protect its assets, and support the achievement of its long-term strategic objectives. This organizational framework reinforces accountability, adherence to recognized best practices and governance standards, and ensures sustainable growth while strengthening stakeholder confidence.
Overview of the Implementation of Requirements for Establishing the Risk Management Committee
The table under Rule II of this report provides full details on the roles and achievements of the Committee, as well as its composition and meetings.
Summary of Internal Control and Oversight Systems
Defining values, principles, and roles is essential to enable informed and sound decision-making. Effective implementation of the Company’s Code of Conduct and internal policies is critical to ensure ethical, efficient, and legally compliant operations.
The Company’s priorities go beyond mere compliance with applicable laws and regulations. They extend to ensuring the design and operation of internal control frameworks that align with internationally recognized best practices and standards. These frameworks serve to protect stakeholder rights and support the achievement of the Company’s strategic objectives and long-term ambitions.
Vision
Our vision is to be the leading provider of innovative ICT technologies and digital lifestyle communications, delivering an exceptional and seamless experience to our customers. We are committed to excellence in customer experience, enhancing operational efficiency, driving business growth, investing in human capital development, and contributing to human progress globally.
Our Values and Corporate Purpose
Heart
Embodying courage at both the individual and organizational levels and adopting an approach that reflects a distinctive corporate philosophy rooted in clear and well-defined values.
Radiance
Elevating performance and exceeding expectations by delivering services that meet global standards.
Belonging
Going beyond geographical boundaries, building sustainable social value, and upholding our cultural and environmental responsibilities.
Internal Control Framework
Responsibilities
Raising Awareness of Policies, Procedures, and the Code of Conduct
Technical Tools, Programs, Trainings, and Courses
Independence of Departments and Employees, and Competence and Integrity of Executives
Commitment to Governance Principles
Risk Assessment
Compliance Risks
Market Risks
Operational Risks
Control Environment
External Factors Shaping the Internal Control Environment:
Policies and Procedures
Effectiveness of Control Programs
Accountability
Compliance
Defense Lines
Internal Audit Department
Risk Management Department
Governance Department
Compliance Department
External Oversight Framework
Zain is subject to an integrated framework of external oversight mechanisms exercised by governmental regulatory and supervisory authorities, in addition to independent auditors and relevant professional bodies. These mechanisms aim to assess the Company’s compliance with applicable legislation, regulatory requirements, and leading corporate governance practices. They constitute a core element of the Company’s overall control environment, focusing on enhancing transparency, safeguarding the integrity of operations, and protecting the rights of shareholders and other stakeholders.
In this context, and beyond mandatory requirements, the Company voluntarily undergoes independent assessments and audits to evaluate the effectiveness of its overall governance structure. Zain is also subject to regular supervision and inspection by several official authorities, including the Capital Markets Authority (CMA), the Ministry of Commerce and Industry, the Anti-Corruption Authority, the Competition Protection Authority, and the Communications and Information Technology Regulatory Authority, in addition to other relevant regulatory and governmental bodies in the jurisdictions where the Company operates.
Role of the Capital Markets Authority in Supervision and Oversight
The Capital Markets Authority carries out its supervisory role through periodic and structured inspection processes, which include a comprehensive review of the Company’s activities, records, and level of compliance with applicable laws and regulations. These inspections result in detailed reports addressing the status of compliance, effectiveness of implementation, and any observations, violations, or required corrective actions. The Company’s records and files are also subject to review under the supervision of the CMA, thereby reinforcing discipline and ensuring ongoing compliance.
Appointment and Independence of the External Auditor
In accordance with the Kuwaiti Companies Law and International Accounting Standards, the Company appoints an external auditor at the Ordinary General Assembly meeting, based on a recommendation from the Board of Directors and the approval of the Audit Committee. The external auditor is required to adhere fully to principles of independence and objectivity. Accordingly, the auditor is prohibited from combining audit responsibilities with any executive or supervisory role within the Company, holding the position of Chairman or Board member, or having any kinship up to the second degree with individuals involved in the Company’s management or oversight of its accounts.
Furthermore, the external auditor is prohibited from owning shares in the Company or in any entity whose accounts are audited by the auditor and must refrain from buying or selling the Company’s shares throughout the audit engagement period or while providing any advisory services. The external auditor is granted full access to the Company’s books, records, and documents, and may request any information deemed necessary to perform audit duties effectively and independently.
The external auditor attends General Assembly meetings and presents the audit report, explaining the fairness of the financial statements in reflecting the Company’s financial position and results of operations, and confirming their compliance with applicable laws and generally accepted accounting standards. The auditor is also required to disclose any obstacles or interference encountered during the performance of audit duties and to report any material violations to the Capital Markets Authority.
Oversight Role of Board Committees
The Risk Committee of the Board of Directors oversees compliance management to ensure adherence to regulatory requirements and approved governance standards. The Compliance function operates independently and conducts periodic internal reviews to provide an additional layer of assurance. Regular reports covering compliance matters, risk assessments, and mitigation strategies are submitted directly to the Committee, thereby enhancing effective oversight, transparency, and accountability.
Internal Control Framework and Risk Management
The Board of Directors is responsible for overseeing the Company’s risk management framework, including operational, financial, and regulatory risks, in addition to risks related to environmental, social, and governance (ESG) matters. In cooperation with executive management, the Board defines the Company’s risk appetite and approves the policies and frameworks through which identified risks are managed, based on an assessment of relevant internal and external factors.
Internal controls create the foundation of this framework, aiming to safeguard the Company’s assets, ensure the reliability of financial reporting, enhance operational efficiency, support legal and regulatory compliance, and achieve strategic objectives, thereby maximizing value for shareholders and stakeholders.
Audit and Assurance Activities at Zain
The Company applies a robust set of audit and assurance practices, including:
- Adoption of the Four Eyes Principle within the organizational structure.
- Independence of the Internal Audit function, which reports to the Board Audit Committee and is responsible for reviewing operations and procedures and ensuring compliance with applicable policies, laws, and standards.
- Appointment of an independent audit firm to conduct an annual review of internal control systems and submit its report to the CMA.
- Conducting an independent assessment of the performance of the Internal Audit function every three years, with results reported to the Audit Committee and the Board of Directors.
- Development of a risk-based annual audit plan focusing on areas with the highest impact, which is updated on an adaptive basis to address emerging risks and regulatory changes.
- Appointment of an independent external auditor (KPMG) to audit the financial statements, ensuring compliance with international standards and strengthening stakeholder confidence.
- Appointment of an independent assurance provider to deliver limited and reasonable assurance on sustainability reports over a period of 15 years, previously conducted by Deloitte and in recent years by Ernst & Young, thereby enhancing the credibility of ESG reporting and alignment with international standards.
Control Environment and Corporate Culture
Zain’s control environment is founded on integrity, ethical conduct, and a clear separation between the roles of the Board of Directors and executive management. It is supported by a well-defined organizational structure, clear reporting lines, and precise delegation of authorities, ensuring effective performance monitoring and achievement of objectives.
As part of promoting a culture of compliance, the Board of Directors has published the Company’s policies, procedures, and codes of conduct on the official website, with the aim of embedding a culture of consistent compliance and ethical standards across all levels of the organization.
Internal Control Review and Continuous Improvement
The Board of Directors approved the appointment of BDO as an independent auditor to conduct the Internal Control Review (ICR). This step reflects the Board’s commitment to continuous improvement, the adoption of leading best practices, and the use of independent and renewed perspectives. The review aims to assess the effectiveness of the internal control systems and their ability to manage day-to-day operational risks.
The Internal Control Review provides stakeholders with a comprehensive view of the effectiveness of the internal control environment and identifies areas for improvement. It includes an evaluation of policies and procedures, risk identification, process assessments, control testing, compliance verification, data analysis, management interviews, and the reporting of findings and recommendations to the Board of Directors and the CMA, thereby supporting transparency, accountability, and sustainable growth.


A brief statement on implementing the requirements for forming an independent department/office/unit for internal audit
In line with the laws and regulations governing corporate governance in Kuwait and the requirements of the CMA, the Company has adopted an integrated framework for an independent Internal Audit function. This framework ensures clarity of scope, the application of effective audit methodologies, the availability of qualified competencies, and full independence from operational activities, with a direct reporting line to the Board Audit Committee.
The Internal Audit function operates independently under the supervision of the Chief Internal Auditor and reports to the Board Audit Committee, which is responsible for overseeing financial reporting, internal control systems, and for submitting recommendations to the Board of Directors regarding the appointment of the external auditor, in accordance with the requirements of the CMA and the Ministry of Commerce and Industry.
Internal audit is an independent assurance and advisory activity designed to add value and improve the Company’s performance through a structured approach to evaluating and enhancing the effectiveness of risk management, internal controls, and governance processes. Internal audit activities cover all Company operations, and relevant reports and recommendations are provided to executive management, the Audit Committee, and the Board of Directors.
Key responsibilities of the Internal Audit function include assessing the adequacy of internal controls, verifying compliance with policies, laws, regulations, and ethical standards, reviewing operational processes and outcomes, and preparing a risk-based annual internal audit plan in coordination with executive management, the Audit Committee, and the Board of Directors, while maintaining full independence.
The Chief Internal Auditor periodically presents internal audit plans and results to the Audit Committee and has direct access to the Board of Directors in the event of material or urgent matters, thereby reinforcing transparency, accountability, and the effectiveness of the governance framework in line with international best practices and the requirements of the Capital Markets Authority.