RISK MANAGEMENT STRATEGY

Risk management is integrated into every aspect of SAGT’s business, forming a core element of the Company’s strategies and processes. It is central to shaping the Company’s sustainability initiatives, operational framework, and governance practices. SAGT has developed a robust risk management system aimed at proactively identifying and addressing potential risks, ensuring the continued resilience and success of the business.

SAGT’s risk management framework supports the management of the Company’s material sustainability topics identified through its materiality assessment process. These include occupational health and safety, climate change and environmental stewardship, operational resilience, regulatory compliance, data security, and responsible supply chain management. The Enterprise Risk Management (ERM) framework enables SAGT to identify, assess, and manage risks and opportunities that may impact the economy, environment, and people, including employees, customers, contractors, and surrounding communities.

THE INTERNAL AUDIT, RISK, AND COMPLIANCE DIVISION

The responsibility for ensuring that SAGT adheres to its risk policies, procedures, and regulatory compliance requirements rests with the Internal Audit and Risk and Compliance Division. The Risk and Compliance Division is tasked with providing regular reports to the Audit Committee on the adequacy and effectiveness of the Company's internal control systems.

The Head of the Risk and Compliance Division presents updates and followup actions regarding significant matters to the Audit Committee at each quarter. Additionally, the Head of the Audit Committee oversees all risk management activities, collaborating with the Company’s

management to identify, assess, and address potential and significant risks. The Head of the Risk and Compliance Division is also responsible for obtaining formal assurances from the Senior Management Team quarterly regarding the effectiveness and status of internal controls and risk management systems and confirming the Company's compliance with relevant laws and regulations.

The effectiveness and resource requirements of the Audit and Risk and Compliance Division are reviewed regularly by the Audit Committee, while the Company’s audit functions are primarily outsourced to leading external professional firms.

Oversight of risk management ultimately rests with the Board of Directors through the Audit Committee, which reviews key risk exposures, internal control effectiveness, and compliance matters on a quarterly basis. Material sustainability and ESGrelated risks such as Sustainability Related Risks and Opportunities (SRROs) and Climate Related Risks and Opportunities (CRROs) identified through the ERM process and Sustainability Management Framework are escalated to the Board as required to support strategic decision-making and longterm value creation.

Enterprise Risk Management (ERM) Process:

The Enterprise Risk Management (ERM) process at SAGT follows a bottom-up approach, starting at the departmental level. The Company adheres to process flow for risk management activities and reporting, as illustrated in the diagram below.

Company risks are identified, documented, and recorded through departmental Risk Control Self-Assessment (RCSA) documents, which are then consolidated into a Company-wide RCSA. These risks are assessed and managed in the following manner:

Identification of all risks that the Company may face in striving for its business objectives and the assessment of existing processes to mitigate these risks.

Determination of the level of each risk via a net risk rating

Identification of further appropriate control improvement mitigation strategies

Allocation of a risk owner for each risk

Regular audits across all departmental RCSA’s

RISK IDENTIFICATION:

Risk events are occurrences that could significantly hinder SAGT’s ability to achieve its predetermined objectives if they take place. SAGT classifies risk events into three levels:

  1. Common Risks: These are risks commonly identified across departments during their respective RCSAs. These risks are then incorporated into the Company’s consolidated risk grid and assigned an appropriate rating. These risks would also include prioritized SRROs and CRROs where relevant
  2. Departmental-specific Risks: These are risks that apply specifically to individual departments, reflecting unique challenges or circumstances within those areas.
  3. Core Risks: These are risks that could have a catastrophic impact on the Company, both internally and externally. Though likelihood is low, their occurrence would pose a significant threat to the sustainability or long-term viability of the business.

Each identified risk is evaluated in relation to SAGT’s material topics to ensure alignment between operational risk management and sustainability impact management. Risks are assessed not only based on operational consequences but also on their potential economic, environmental, and social impacts.

The key risks are summarized below along with their corresponding ratings:

No Key Risk Material Topic Impact Rating
1 Health and Safety Occupational Health & Safety (Social)
2 Natural Disasters & Climate Change Impacts Climate Resilience & Environmental Stewardship
3 Global Competition Economic Performance & Business Continuity
4 Macroeconomic & Political Environment Economic Stability & Stakeholder Value
5 Cyber Security Data Privacy & Customer Trust
6 Fires & Explosions Workplace Safety & Operational Continuity
7 Regulatory Compliance Ethical Business Conduct & Compliance
8 Supplier Governance Responsible Supply Chain Management
9 Breakdown of Internal Controls Corporate Governance & Transparency
ULTRA-HIGH
HIGH
MEDIUM
LOW
INSIGNIFICANT
RISK RATING:

SAGT applies the rating system outlined below to determine each risk event’s level of risk.

Identified risks are evaluated using a matrix that considers both "Impact to the Company" and "Likelihood of Occurrence." Each risk is then assigned a score based on this assessment and documented in the Risk Control Self-Assessment (RCSA). Risks are categorized on a scale ranging from “Insignificant” to “Ultra-high” to ensure effective risk management and mitigation.

The Company’s residual risk is defined as the overall risk level assigned, upon considering existing risk control and mitigation measures.

RISK MITIGATION, MONITORING AND REPORTING:

Each risk event is assigned a corresponding mitigation action within the risk management framework, classified as either preventive, detective, or corrective. The designated Risk Owner is responsible for managing the specific risk and overseeing the development and implementation of plans to mitigate it.

The Company’s departmental-level RCSAs undergo quarterly reviews, which are managed by individual departments. These departments are responsible for conducting the reviews and communicating their findings to the Management Committee for appropriate action. This process ensures that individual risk ratings are continuously updated and consolidated within the Company’s overall RCSA for the quarter.

The Head of Internal Audit and Compliance monitors and analyses any variations and changes within the SAGT risk rating system. This involves risk profiling, tracking and incident reporting. The Senior Management Team (SMT) and the Executive Committee (ExCom) analyse and review both Company-specific risks and risks common to the sector and industry, involving the Audit Committee as needed for further insights and decisions. The below table summarises the risk description, ratings and mitigatory actions for the organisation’s key risks.

Risk Description and Rating Mitigatory Actions

Health and Safety

  • Safety incidents may cause serious injuries or fatalities, leading to service disruptions
  • Damage to property or equipment can impact operational continuity
High Risk
  • Mandatory Safety Induction Program for employees, contractors, and visitors.
  • Contractor Management Program comprising weekly meetings and discussions with three of the critical contractor groups employed within the terminal.
  • Regular safety drills and trainings for employees and contractors to bolster incident readiness.
  • Safety procedures and procedures are reviewed and updated periodically.
  • Safety trainings carried out for relevant staff and contractors as and when required.
  • Regular Audits and inspections on health and safety procedures.
  • Mandatory safety refresher for employees and contractors annually
  • Management safety walks are conducted by cross functional teams to identify and rectify potential health and safety risks.
  • Insurance covers is in place for key terminal assets
  • Risk assessments are mandatory for all work taken up within the terminal
  • Periodic review of standard operating procedures and risk assessments
  • Technology adaptation to minimise human-machine interaction

Natural Disasters and Climate Change Impacts

  • Restricted access to work and information
  • Operational disruptions due to extreme weather events
  • Potential damage to critical machinery and infrastructure
  • Risk of injury or loss of life to employees and contractors
  • Increased operational costs arising from energy stability and higher recovery costs
High Risk
  • Business continuity plan along with a comprehensive disaster recovery plan, health and safety processes and port infrastructure in place.
  • Weather conditions are actively monitored.
  • Key equipment is fitted with tie-down mechanisms to prevent catastrophic damage.
  • Employees and contractors receive regular training and drills. Relevant insurance policies are in place.
  • Transition to low-carbon operations is guided by financial and non-financial evaluation criteria, with the Finance Division assessing payback periods and ROI before implementing transition strategies.

Global Competition

  • Loss of transshipment business to other terminals in the region leading to negative impacts in profitability
High Risk
  • Maintaining strong relationships with key stakeholders to the business
  • Maintaining long term business agreements with customers
  • Developing and promoting the Port of Colombo's feeder vessel links
  • Enhance the Company's and Port of Colombo's sustainable business practices

Cyber Security Risk

  • Compromise of critical business and customer data may lead to service disruptions and reputational loss
  • Potential exposure to legal action
High Risk
  • IT Policy, data security process and data backup procedures are in place
  • Implementation of a Security Operation Center to monitor cyber activities 24/7.
  • Policy and security controls undergo continuous assessment.
  • Cyber security assessments are done on an annual basis. The recommendations provided during the assessments are implemented to improve risk mitigation processes.

Macroeconomic and Political Environment

  • Geopolitical tension and economic instability disrupting shipping services and cargo volumes leading to vessel bypasses and reduced throughput.
  • Rising fuel prices and increasing operating costs despite operational continuity as an essential service.
High Risk
  • Continuous monitoring of geopolitical and macroeconomic developments with scenario planning and periodic risk reassessment.
  • Proactive collaboration with shipping lines and Port stakeholders to manage capacity, avoid yard congestion and optimize operations.
  • Strengthening volumes from key Southeast Asian markets and implementing cost efficiency measures to offset volatility and rising fuel costs.

Fire/ Explosion

  • Serious lost time injuries/ fatalities to employees and contractors resulting in service disruption.
  • Property/ equipment damage leading to service disruptions.
  • Increased costs
Medium Risk
  • Business Continuity Plan, Disaster Recovery Plan and evacuation plans in place.
  • Pre-planned fire drills are conducted with employees and contractors on a periodic basis.
  • The Emergency Response Team is trained for handling emergencies.
  • Fire alarm system is in place in the building, yard and on key equipment.
  • Fire inspections are conducted on an annual basis by an external party.
  • Hazardous cargo within the terminal premises is monitored daily.
  • Insurance covers are in place for key terminal assets

Regulatory Compliance

  • Regulatory violations may lead to legal, financial, and reputational consequences
  • Breach of concession terms could result in a complete halt of operations
Medium Risk
  • Adhere to procedures and continuously review and update standards
  • Benchmark to international standards
  • Maintain critical activity calendar for renewal of license and certification

Supplier Governance Risk

  • Negative impact to Company reputation due to legal, regulatory compliance and privacy issues
Medium Risk
  • A supplier code of conduct is in place. The supplier code of conduct is included on all supplier contracts
  • All significant suppliers are registered on SAGT's vendor management portal
  • Periodic review on supplier performance and enforcement of supplier contracts
  • Bi-annual leadership meetings with key suppliers

Breakdown of Internal Controls

  • Disruptions to internal processes may affect operations and profitability
  • Potential reputational damage to the Company
Low Risk
  • Key processes are analysed with segregation of duties, approval limits, decision rights and committee structures.
  • Monitoring control processes and internal and external audit processes
  • Action internal and external audit findings and reviews
SAGT’s readiness to meet risks associated with Climate Change:

Climate change risks highlight the potential negative impacts of climate change on both human and ecological systems. Whilst these risks are integrated into SAGT’s Enterprise Risk Management (ERM) framework, they can be divided into two categories: physical risks and transition risks

Physical risks stem from natural disasters such as floods, high winds and other unfavourable weather conditions. SAGT has in place a Business Continuity Plan along with a comprehensive Disaster Recovery plan, health and safety processes and port infrastructure to avoid damage to the terminal due to natural disasters. The Company also has business interruption and workers’ compensation insurance as a precaution in the event of physical risk.

Transition risks relate to the changes in policy, law, technology, and markets that result from the transition to a low-carbon economy. The decision to transition to low-carbon operations is driven by both financial and nonfinancial evaluation criteria. The Finance Division plays a key role in assessing payback periods and return on investment (ROI) before moving forward with any transition strategies. While over 30% of Sri Lanka’s electricity generation comes from renewable sources, there are currently no regulations regarding a transition to a low-carbon economy, no carbon pricing, nor limits on emissions or effluent discharge in Sri Lanka.

Since 2019, SAGT has invested in transitioning to low-carbon alternatives, including adopting energy-efficient technology, investing in solar energy, replacing fossil fuel-driven equipment with hybrid technology, and forming strategic partnerships. These investments undergo rigorous financial and nonfinancial evaluations to ensure that risks related to transitioning to a low-carbon operation are mitigated effectively. Details of these investments can be found in the Environmental Stewardship section from pages 46 to 57 of this report.

SAGT believes that these investments in low-carbon operations, as well as its commitment to Environmental, Social, and Governance (ESG) performance, enhance the Company’s social license to operate and positions it as a market leader in efficient port operations, all within the broader context of Corporate Responsibility.

INTERNAL COMPLIANCE

SAGT ensures compliance with statutory and other regulatory procedures through a quarterly self-certification process which is verified and confirmed by the CFO and CEO. They are also responsible for identifying any significant deviations from expected conditions and taking necessary actions to address any discrepancies. This process helps maintain the Company’s adherence to legal and regulatory requirements, ensuring transparency and accountability across its operations.

During the reporting period, SAGT monitored compliance with all applicable laws and regulations through its internal compliance framework. No significant fines or non-monetary sanctions for noncompliance with environmental, social, or economic laws and regulations were recorded during the reporting period.

SYSTEM OF INTERNAL CONTROL

The Senior Management Team and Executive Committee, in collaboration with the Head of Internal Audit and the Risk and Compliance Division, are responsible for obtaining assurances regarding the presence and effectiveness of systems designed to safeguard the Company’s assets. This includes ensuring that these systems are functioning properly and provide adequate protection for the Company's resources. Their efforts are crucial in maintaining operational integrity, security, and risk mitigation throughout the organization.

All risks identified in the ERM risk register are discussed at Audit Committee (AC) meetings, which are held every four months. Sustainabilityrelated risks are also discussed alongside the risk register. Further, sustainability-related risks are evaluated by the Executive Committee of the Company at its quarterly meetings.

SAGT’s system of internal controls comprises the following activities

  1. Clearing all transactional entries in a timely manner and ensuring complete reconciliation to maintain the accuracy and integrity of financial records.
  2. Subjecting unreconciled and open entries to scrutiny and formally flagging them for the attention of the Audit Committee and ensuring necessary corrective actions are taken promptly
  3. Ensuring cash and cheque deposits are efficiently managed and tracked in adherence to best practices to ensure transparency and security in financial transactions.
  4. Continuously streamlining the Internal Audit function by optimising focus areas, enhancing efficiency, and ensuring thorough oversight across key business operations.
Segregation of Duties (SOD) under Sarbanes-Oxley (SOX) Guidelines

SAGT takes every precaution to ensure that no individual has unrestricted access to execute transactions across the organization. To mitigate risks such as fraud, material misstatements, and manipulation of financial statements, the Company has implemented critical approval linkages and a clear segregation of duties. This helps prevent any leakage of sensitive information and ensures that operational processes remain secure.

The impacts of SAGT’s material topics, including the risks posed by climate change, are assessed on a quarterly basis from an ESG risk management perspective. This assessment is conducted using Key Sustainability Performance Indicators (KSPI) and Key Risk Indicators (KRI), which align with GRI Standards. In addition to these standards, SAGT tracks more detailed information to enable management to make data-backed decisions. The KSPIs and KRIs are reported internally to the Management Committee every quarter, allowing the Company to take corrective actions based on its ESG performance in a timely manner.

Key Sustainability Performance Indicators (KSPIs) and Key Risk Indicators (KRIs) are derived from SAGT’s materiality assessment and aligned with applicable GRI Standards. Indicators are reviewed periodically to ensure relevance to evolving ESG risks and stakeholder expectations. Performance thresholds are monitored quarterly, enabling management to identify trends, evaluate risk exposure, and implement corrective actions where necessary.

Further details regarding the implementation of SAGT’s ESG Management Strategy can be found in the “Sustainability Integration” section, along with disclosures related to Environmental Stewardship and Social Responsibility within this report.