CFSL Integrated Report 2023

Communication with shareholders and stakeholders is mainly done through the Annual Report, Investors’ Briefings, the published unaudited results, the Annual Meeting of Shareholders (‘AMS’), dividends declarations, press communiqués and the website. An “Investors’ Corner” section is available on CFSL’s website and such section provides shareholders and stakeholders with information in a timely manner on audited financial statements, interim and final dividends, share price information, communiqués on activities of the Company amongst others, and also includes the digital version of the annual reports of the Company. The Group interacts with its internal stakeholders namely its employees via Workplace, a collaborative platform run by Facebook which offers social networks features in a corporate environment. Through the platform, employees can communicate with one another via groups. The external stakeholders of the Group namely its customers, suppliers, shareholders, the Government/Regulators and the public are reached via social media platforms such as Facebook and LinkedIn, as well as via advertisements. As and when required, focus groups are held with clients to assess their expectations from the Group. Regular channels of communication are also maintained with the regulators and the Government. In addition, shareholders are invited to the AMS on an annual basis to approve the financial statements and vote on the reappointment/appointment of Directors and the external auditor. The AMS for the year 2023 was held in March 2023. The next AMS of the Company is scheduled in February 2024, and shareholders will receive the notice of the AMS at least 21 days prior to the meeting in accordance with the law. The Annual Report, which also includes the notice of annual meeting, is published in full on the Company’s website. Shareholders also have the option to request a hard copy of the Annual Report. 4. Risk Management The Group is subject to a number of risks and uncertainties in carrying out its activities. The activities related to Risk Management, the material risks and steps taken to address known weaknesses in internal controls are set out in the Risk Management Report on pages 58 to 75. 5. Internal Audit Function Governance and structure During the year under review, the Internal Audit Function performed audit, advisory and investigation engagements for CIM Financial Services Ltd (‘CFSL’) as per the Risk-Based Internal Audit Plan approved by the Audit and Compliance Committee (‘ACC’) of CFSL. There are no significant areas which have not been covered. The main role of the function is to provide independent, objective assurance and consulting activity designed to add value and improve the company’s operations. The Internal Audit Function is independent of Executive Management and functionally reports to the ACC on a quarterly basis. The Head of Internal Audit presents audit reports to the ACC, and discusses key issues contained therein. The Head of Internal Audit has a direct reporting line to the Chair of the ACC, and has regular meetings with the Chair, thereby further establishing Internal Audit’s independence. The ACC approves the Risk-Based Internal Audit plan, ensures adequate resources are available to deliver on the plan and evaluates the effectiveness of the Internal Audit Function. In addition, the ACC monitors the progress in achieving the Risk-Based Internal Audit plan on a quarterly basis. Moreover, in the performance of their duties, the Internal Audit Function has unrestricted access to all documents, key personnel, and Management staff. There was no limitation of scope placed on the internal auditors in conducting the audits. Internal audits are carried out in accordance with the Standards for the Professional Practice of Internal Auditing issued by the Institute of Internal Auditors (IIA). Internal audit staff also abide by the Code of Ethics established by the IIA and by CFSL. The Internal Audit Function was restructured and segregated into two units, namely Risk-Based unit and IT unit. The Risk-Based unit performed assurance engagements in line with the definition of the IIA as well as investigations, independent reviews, etc. The IT unit, for its part, performed engagements where a high reliance on Information Systems and Technology was required. Both units use a risk-based approach when building up the Internal Audit Plan for the year. The structure, organisation and qualifications of the key members of the Internal Audit team are listed on the Company’s website. During the year under review, the Internal Audit team carried out 21 internal audit assignments for CFSL consisting of risk-based, IT, advisory and investigation engagements. In addition, follow-up audits (review of the implementation status of recommendations) along with fraud monitoring using data analytics were also carried out throughout the year. 85 OUR YEAR AT A GLANCE OUR PEOPLE GOVERNANCE FINANCIAL STATEMENTS

RkJQdWJsaXNoZXIy MzQ3MjQ5