Risk Management

IT CITY has set up a risk management framework and guidelines in order to systematically, efficiently and effectively manage risks throughout the organization. Additionally, IT CITY has also established a risk management monitoring and performance evaluation system to detect any potential emerging risks, which may arise.

Nevertheless, IT CITY has integrated the risk management in the organization under 3 aspects of Governance, Risk Management and Internal Control and Compliance under one system called GRC. This allows IT CITY to reduce the risks in more comprehensive manner and allows IT CITY to achieve any goals and targets more efficiently.

The risk management process comprises of three steps, which are

1.) Risk Identification & Assessment

IT CITY has leveraged a range of risk management tools to analyze, assess and define a risk management framework, such as appropriate business environment analysis processes based on internal and external factors, risk appetite, risk assessment, and risk prioritization using a risk map.

Risk appetite and risk tolerance levels

2.) Risk Treatment/ Mitigation

IT CITY has appointed a person responsible for risk assessment, established mitigation plan in accordance with the risk appetite, and determined Key Risk Indicators (KRI).

3.) Monitoring & Review

IT CITY has determined that risk management is controlled and tracked through the Risk Management Committee and the Board of Directors. The company requires that risk management performance is monitored and reported regularly at all levels.

rish management process