Our risk management process
| Combined assurance methodology |
The MTN board understands and takes accountability for all risks that potentially affect the achievement of its strategic
priorities and has delegated the responsibility for overseeing the adequacy and effectiveness of risk management to
the audit and risk committees.
With the objective of ensuring a more integrated approach to managing risks that threaten the organisation, our business
risk management division follows a combined assurance methodology in line with the requirements of King III.
The overview of our combined assurance methodology is set out below:

MTN’s objectives are to instil greater risk awareness throughout the organisation, standardise the approach to risk
management and to embed the process into day-to-day running of the business.
Derived from our combined assurance methodology, MTN has adopted robust risk management frameworks which consist
of proactively identifying and understanding the factors and events that may impact the achievement of our strategic
and business priorities, then managing them through effective mitigating plans, internal controls and monitoring and
reporting processes. This is known as enterprise risk management.
The Group business risk management function is responsible for ensuring the existence of an effective policy and framework
for risk management and driving the implementation of these throughout the Group.
Business risk management is a support function responsible for the disciplines of enterprise risk management, internal
audit and fraud risk management and co-ordination of combined assurance across the Group. The business risk
management function has a staff complement of more than 230, comprising risk, internal audit, fraud risk and forensic
specialists across the 22 operating countries. Of the total, more than two-thirds are internal audit specialists. The internal
audit discipline within business risk management is independent of the risk management discipline.
The activities of the business risk management function are guided by a set of policies, frameworks and methodologies
which have been approved by the Group audit committee and Group risk management, compliance and corporate
governance committee.

|