Risk management is integrated into every aspect of SAGT’s business, forming a core element of the Company’s
strategies
and processes. It is central to shaping the Company’s sustainability initiatives, operational framework, and
governance
practices. SAGT has developed a robust risk management system aimed at proactively identifying and
addressing potential
risks, ensuring the continued resilience and success of the business.
SAGT’s risk management framework supports the management of the Company’s material sustainability topics
identified
through its materiality assessment process. These include occupational health and safety, climate change and
environmental
stewardship, operational resilience, regulatory compliance, data security, and responsible supply chain
management. The
Enterprise Risk Management (ERM) framework enables SAGT to identify, assess, and manage risks and
opportunities
that may impact the economy, environment, and people, including employees, customers, contractors, and
surrounding
communities.
THE INTERNAL AUDIT, RISK, AND COMPLIANCE DIVISION
The responsibility for ensuring
that SAGT adheres to its risk
policies, procedures, and regulatory
compliance requirements rests with
the Internal Audit and Risk and
Compliance Division. The Risk and
Compliance Division is tasked with
providing regular reports to the
Audit Committee on the adequacy
and effectiveness of the Company's
internal control systems.
The Head of the Risk and Compliance
Division presents updates and followup actions regarding significant
matters to the Audit Committee at
each quarter. Additionally, the Head
of the Audit Committee oversees
all risk management activities,
collaborating with the Company’s
management to identify, assess, and
address potential and significant risks.
The Head of the Risk and Compliance
Division is also responsible for
obtaining formal assurances from the
Senior Management Team quarterly
regarding the effectiveness and
status of internal controls and risk
management systems and confirming
the Company's compliance with
relevant laws and regulations.
The effectiveness and resource
requirements of the Audit and Risk
and Compliance Division are reviewed
regularly by the Audit Committee,
while the Company’s audit functions
are primarily outsourced to leading
external professional firms.
Oversight of risk management
ultimately rests with the Board
of Directors through the Audit
Committee, which reviews key
risk exposures, internal control
effectiveness, and compliance
matters on a quarterly basis.
Material sustainability and ESGrelated risks such as Sustainability
Related Risks and Opportunities
(SRROs) and Climate Related
Risks and Opportunities (CRROs)
identified through the ERM process
and Sustainability Management
Framework are escalated to the
Board as required to support
strategic decision-making and longterm value creation.
Enterprise Risk Management (ERM) Process:
The Enterprise Risk Management (ERM) process at SAGT follows a bottom-up approach, starting at the
departmental level.
The Company adheres to process flow for risk management activities and reporting, as illustrated in the
diagram below.
Company risks are identified, documented, and recorded through departmental Risk Control Self-Assessment
(RCSA)
documents, which are then consolidated into a Company-wide RCSA. These risks are assessed and managed in the
following manner:
Identification of
all risks that the
Company may face
in striving for its
business objectives
and the assessment
of existing processes
to mitigate these
risks.
Determination of
the level of each
risk via a net risk
rating
Identification
of further
appropriate control
improvement
mitigation
strategies
Allocation of a risk
owner for each risk
Regular audits
across all
departmental
RCSA’s
RISK IDENTIFICATION:
Risk events are occurrences that could significantly hinder SAGT’s ability to achieve its predetermined
objectives if they
take place. SAGT classifies risk events into three levels:
- Common Risks: These are risks commonly identified across departments during their respective RCSAs.
These risks are
then incorporated into the Company’s consolidated risk grid and assigned an appropriate rating. These
risks would also
include prioritized SRROs and CRROs where relevant
-
Departmental-specific Risks: These are risks that apply specifically to individual departments,
reflecting unique
challenges or circumstances within those areas.
-
Core Risks: These are risks that could have a catastrophic impact on the Company, both internally and
externally.
Though likelihood is low, their occurrence would pose a significant threat to the sustainability or
long-term viability of
the business.
Each identified risk is evaluated in relation to SAGT’s material topics to ensure alignment between
operational risk
management and sustainability impact management. Risks are assessed not only based on operational
consequences but
also on their potential economic, environmental, and social impacts.
The key risks are summarized below along with their corresponding ratings:
| No |
Key Risk |
Material Topic Impact |
Rating |
| 1 |
Health and Safety |
Occupational Health & Safety (Social) |
|
| 2 |
Natural Disasters & Climate Change Impacts |
Climate Resilience & Environmental Stewardship |
|
| 3 |
Global Competition |
Economic Performance & Business Continuity |
|
| 4 |
Macroeconomic & Political Environment |
Economic Stability & Stakeholder Value |
|
| 5 |
Cyber Security |
Data Privacy & Customer Trust |
|
| 6 |
Fires & Explosions |
Workplace Safety & Operational Continuity |
|
| 7 |
Regulatory Compliance |
Ethical Business Conduct & Compliance |
|
| 8 |
Supplier Governance |
Responsible Supply Chain Management |
|
| 9 |
Breakdown of Internal Controls |
Corporate Governance & Transparency |
|
RISK RATING:
SAGT applies the rating system outlined below to determine each risk event’s level of risk.
-
Likelihood of occurrence: the probability of occurrence is rated
from 1 to 5
-
The severity of impact: the impact to business is rated from 1 to 5
-
The velocity of risk the speed at which the impact of the risk would
hit the organization
Identified risks are evaluated using a
matrix that considers both "Impact
to the Company" and "Likelihood of
Occurrence." Each risk is then assigned
a score based on this assessment
and documented in the Risk Control
Self-Assessment (RCSA). Risks are
categorized on a scale ranging from
“Insignificant” to “Ultra-high” to
ensure effective risk management and
mitigation.
The Company’s residual risk is defined
as the overall risk level assigned, upon
considering existing risk control and
mitigation measures.
RISK MITIGATION, MONITORING AND REPORTING:
Each risk event is assigned a corresponding mitigation action within the risk management framework,
classified as either
preventive, detective, or corrective. The designated Risk Owner is responsible for managing the specific
risk and overseeing
the development and implementation of plans to mitigate it.
The Company’s departmental-level RCSAs undergo quarterly reviews, which are managed by individual
departments. These
departments are responsible for conducting the reviews and communicating their findings to the Management
Committee
for appropriate action. This process ensures that individual risk ratings are continuously updated and
consolidated within
the Company’s overall RCSA for the quarter.
The Head of Internal Audit and Compliance monitors and analyses any variations and changes within the SAGT
risk
rating system. This involves risk profiling, tracking and incident reporting. The Senior Management Team
(SMT) and the
Executive Committee (ExCom) analyse and review both Company-specific risks and risks common to the sector
and
industry, involving the Audit Committee as needed for further insights and decisions. The below table
summarises the risk
description, ratings and mitigatory actions for the organisation’s key risks.
| Risk Description and Rating |
Mitigatory Actions |
|
Health and Safety
- Safety incidents may cause serious injuries or fatalities, leading to service
disruptions
- Damage to property or equipment can impact operational continuity
High Risk
|
- Mandatory Safety Induction Program for employees, contractors, and visitors.
- Contractor Management Program comprising weekly meetings and discussions with three
of
the critical contractor groups employed within the terminal.
- Regular safety drills and trainings for employees and contractors to bolster
incident
readiness.
- Safety procedures and procedures are reviewed and updated periodically.
- Safety trainings carried out for relevant staff and contractors as and when
required.
- Regular Audits and inspections on health and safety procedures.
- Mandatory safety refresher for employees and contractors annually
- Management safety walks are conducted by cross functional teams to identify and
rectify
potential health and safety risks.
- Insurance covers is in place for key terminal assets
- Risk assessments are mandatory for all work taken up within the terminal
- Periodic review of standard operating procedures and risk assessments
- Technology adaptation to minimise human-machine interaction
|
|
Natural Disasters and Climate Change Impacts
- Restricted access to work and information
- Operational disruptions due to extreme weather events
- Potential damage to critical machinery and infrastructure
- Risk of injury or loss of life to employees and contractors
- Increased operational costs arising from energy stability and higher recovery costs
High Risk
|
- Business continuity plan along with a comprehensive disaster recovery plan, health
and
safety processes and port infrastructure in place.
- Weather conditions are actively monitored.
- Key equipment is fitted with tie-down mechanisms to prevent catastrophic damage.
- Employees and contractors receive regular training and drills. Relevant insurance
policies are in place.
- Transition to low-carbon operations is guided by financial and non-financial
evaluation
criteria, with the Finance Division assessing payback periods and ROI before
implementing transition strategies.
|
|
Global Competition
- Loss of transshipment business to other terminals in the region leading to negative
impacts in profitability
High Risk
|
- Maintaining strong relationships with key stakeholders to the business
- Maintaining long term business agreements with customers
- Developing and promoting the Port of Colombo's feeder vessel links
- Enhance the Company's and Port of Colombo's sustainable business practices
|
|
Cyber Security Risk
- Compromise of critical business and customer data may lead to service disruptions
and reputational loss
- Potential exposure to legal action
High Risk
|
- IT Policy, data security process and data backup procedures are in place
- Implementation of a Security Operation Center to monitor cyber activities 24/7.
- Policy and security controls undergo continuous assessment.
- Cyber security assessments are done on an annual basis. The recommendations provided
during the assessments are implemented to improve risk mitigation processes.
|
|
Macroeconomic and Political Environment
- Geopolitical tension and economic instability disrupting shipping services and cargo
volumes leading to vessel bypasses and reduced throughput.
- Rising fuel prices and increasing operating costs despite operational continuity as
an essential service.
High Risk
|
- Continuous monitoring of geopolitical and macroeconomic developments with scenario
planning and periodic risk reassessment.
- Proactive collaboration with shipping lines and Port stakeholders to manage
capacity, avoid yard congestion and optimize operations.
- Strengthening volumes from key Southeast Asian markets and implementing cost
efficiency measures to offset volatility and rising fuel costs.
|
|
Fire/ Explosion
- Serious lost time injuries/ fatalities to employees and contractors resulting in
service disruption.
- Property/ equipment damage leading to service disruptions.
- Increased costs
Medium Risk
|
- Business Continuity Plan, Disaster Recovery Plan and evacuation plans in place.
- Pre-planned fire drills are conducted with employees and contractors on a periodic
basis.
- The Emergency Response Team is trained for handling emergencies.
- Fire alarm system is in place in the building, yard and on key equipment.
- Fire inspections are conducted on an annual basis by an external party.
- Hazardous cargo within the terminal premises is monitored daily.
- Insurance covers are in place for key terminal assets
|
|
Regulatory Compliance
- Regulatory violations may lead to legal, financial, and reputational consequences
- Breach of concession terms could result in a complete halt of operations
Medium Risk
|
- Adhere to procedures and continuously review and update standards
- Benchmark to international standards
- Maintain critical activity calendar for renewal of license and certification
|
|
Supplier Governance Risk
- Negative impact to Company reputation due to legal, regulatory compliance and
privacy issues
Medium Risk
|
- A supplier code of conduct is in place. The supplier code of conduct is included on
all supplier contracts
- All significant suppliers are registered on SAGT's vendor management portal
- Periodic review on supplier performance and enforcement of supplier contracts
- Bi-annual leadership meetings with key suppliers
|
|
Breakdown of Internal Controls
- Disruptions to internal processes may affect operations and profitability
- Potential reputational damage to the Company
Low Risk
|
- Key processes are analysed with segregation of duties, approval limits, decision
rights and committee structures.
- Monitoring control processes and internal and external audit processes
- Action internal and external audit findings and reviews
|
SAGT’s readiness to meet risks
associated with Climate Change:
Climate change risks highlight the
potential negative impacts of climate
change on both human and ecological
systems. Whilst these risks are
integrated into SAGT’s Enterprise Risk
Management (ERM) framework, they
can be divided into two categories:
physical risks and transition risks
Physical risks stem from natural
disasters such as floods, high winds
and other unfavourable weather
conditions. SAGT has in place a
Business Continuity Plan along
with a comprehensive Disaster
Recovery plan, health and safety
processes and port infrastructure to
avoid damage to the terminal due
to natural disasters. The Company
also has business interruption and
workers’ compensation insurance as a
precaution in the event of physical risk.
Transition risks relate to the changes
in policy, law, technology, and markets
that result from the transition to a
low-carbon economy. The decision to
transition to low-carbon operations
is driven by both financial and nonfinancial evaluation criteria. The
Finance Division plays a key role in
assessing payback periods and return
on investment (ROI) before moving
forward with any transition strategies.
While over 30% of Sri Lanka’s
electricity generation comes from
renewable sources, there are currently
no regulations regarding a transition
to a low-carbon economy, no carbon
pricing, nor limits on emissions or
effluent discharge in Sri Lanka.
Since 2019, SAGT has invested
in transitioning to low-carbon
alternatives, including adopting
energy-efficient technology, investing
in solar energy, replacing fossil
fuel-driven equipment with hybrid
technology, and forming strategic
partnerships. These investments
undergo rigorous financial and nonfinancial evaluations to ensure that
risks related to transitioning to a
low-carbon operation are mitigated
effectively. Details of these investments
can be found in the Environmental
Stewardship section from pages 46 to
57 of this report.
SAGT believes that these investments
in low-carbon operations, as well as its
commitment to Environmental, Social,
and Governance (ESG) performance,
enhance the Company’s social license
to operate and positions it as a market
leader in efficient port operations,
all within the broader context of
Corporate Responsibility.
INTERNAL COMPLIANCE
SAGT ensures compliance with
statutory and other regulatory
procedures through a quarterly
self-certification process which is
verified and confirmed by the CFO
and CEO. They are also responsible for
identifying any significant deviations
from expected conditions and taking
necessary actions to address any
discrepancies. This process helps
maintain the Company’s adherence
to legal and regulatory requirements,
ensuring transparency and
accountability across its operations.
During the reporting period, SAGT
monitored compliance with all
applicable laws and regulations
through its internal compliance
framework. No significant fines or
non-monetary sanctions for noncompliance with environmental, social,
or economic laws and regulations were
recorded during the reporting period.
SYSTEM OF INTERNAL CONTROL
The Senior Management Team and
Executive Committee, in collaboration
with the Head of Internal Audit and
the Risk and Compliance Division,
are responsible for obtaining
assurances regarding the presence
and effectiveness of systems designed
to safeguard the Company’s assets.
This includes ensuring that these
systems are functioning properly and
provide adequate protection for the
Company's resources. Their efforts
are crucial in maintaining operational
integrity, security, and risk mitigation
throughout the organization.
All risks identified in the ERM risk
register are discussed at Audit
Committee (AC) meetings, which are
held every four months. Sustainabilityrelated risks are also discussed
alongside the risk register. Further, sustainability-related risks are
evaluated by the Executive Committee
of the Company at its quarterly
meetings.
SAGT’s system of internal controls
comprises the following activities
- Clearing all transactional entries
in a timely manner and ensuring
complete reconciliation to maintain
the accuracy and integrity of
financial records.
-
Subjecting unreconciled and open
entries to scrutiny and formally
flagging them for the attention of
the Audit Committee and ensuring
necessary corrective actions are
taken promptly
-
Ensuring cash and cheque
deposits are efficiently managed
and tracked in adherence to best
practices to ensure transparency
and security in financial
transactions.
-
Continuously streamlining
the Internal Audit function by
optimising focus areas, enhancing
efficiency, and ensuring thorough
oversight across key business
operations.
Segregation of Duties (SOD) under
Sarbanes-Oxley (SOX) Guidelines
SAGT takes every precaution to ensure
that no individual has unrestricted
access to execute transactions across
the organization. To mitigate risks such
as fraud, material misstatements, and
manipulation of financial statements,
the Company has implemented
critical approval linkages and a clear
segregation of duties. This helps
prevent any leakage of sensitive
information and ensures that
operational processes remain secure.
The impacts of SAGT’s material topics,
including the risks posed by climate
change, are assessed on a quarterly
basis from an ESG risk management
perspective. This assessment is
conducted using Key Sustainability
Performance Indicators (KSPI) and Key
Risk Indicators (KRI), which align with
GRI Standards. In addition to these
standards, SAGT tracks more detailed
information to enable management to make data-backed decisions. The
KSPIs and KRIs are reported internally
to the Management Committee every
quarter, allowing the Company to take
corrective actions based on its ESG
performance in a timely manner.
Key Sustainability Performance
Indicators (KSPIs) and Key Risk
Indicators (KRIs) are derived from
SAGT’s materiality assessment and
aligned with applicable GRI Standards.
Indicators are reviewed periodically
to ensure relevance to evolving ESG
risks and stakeholder expectations.
Performance thresholds are monitored
quarterly, enabling management to
identify trends, evaluate risk exposure,
and implement corrective actions
where necessary.
Further details regarding the
implementation of SAGT’s ESG
Management Strategy can be found in
the “Sustainability Integration” section,
along with disclosures related to
Environmental Stewardship and Social
Responsibility within this report.