135 ANNUAL REPORT 2025 Corporate Governance ACCOUNTABILITY AND AUDIT Principle 9: The Board is responsible for the governance of risk and ensures that Management maintains a sound system of risk management and internal controls, to safeguard the interests of the company and its shareholders. The Board acknowledges that it is responsible for the risk management and internal control system in UHREIT which includes the establishment of an appropriate control environment and framework as well as reviewing its adequacy and integrity to safeguard Unitholders’ interest and UHREIT’s assets. ROLES OF THE BOARD AND ARC IN ENSURING EFFECTIVE RISK MANAGEMENT AND INTERNAL CONTROLS The Board is responsible for UHREIT’s risk management framework and system of internal controls and for reviewing the adequacy and integrity of the risk management framework and system of internal controls. Accordingly, the Board is required to ensure that the Manager has in place an effective system of internal controls, which provides reasonable assessment of effective and efficient operations, internal financial controls and compliance with laws and regulations. The Board has delegated the responsibility of undertaking periodic reviews of the internal controls to the ARC, with an established ToR to assist in discharging this responsibility. A summary of the ARC’s key responsibilities under its ToR is disclosed on page 141 of this Annual Report. The ARC also assesses the materiality of specific developments or risks that might have an impact on UHREIT. However, the Board remains ultimately responsible for the effectiveness, adequacy and integrity of the system of risk management and internal controls. ENTERPRISE RISK MANAGEMENT FRAMEWORK RISK MANAGEMENT The Manager strives to employ a strategy which balances the level of risk with UHREIT’s business growth and profitability goals, so as to achieve consistent and sustainable performance over the long-term. The Manager has put in place an Enterprise Risk Management (the “ERM”) framework which aims to identify and manage the risks from all aspects of the business, and which evolves in tandem with the changes to the business environment and operations. 4-STEP RISK MANAGEMENT PROCESS The Manager adopts a four-step risk management process comprising risk identification, assessment, management as well as risk monitoring and reporting. Step 1. Identify – Identify risks to the organisation based on business context and strategy; Step 2. Assess – Assess each identified risk according to its impact on UHREIT both financially and non-financially and the likelihood of occurrence; Step 3. Manage – Develop mitigating measures and action plans to manage risks; and Step 4. Monitor and report – Identify the key risks for monitoring and reporting on a quarterly basis.
RkJQdWJsaXNoZXIy NTM2MDQ5