> For the complete documentation index, see [llms.txt](https://vnx.gitbook.io/vnx-global/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vnx.gitbook.io/vnx-global/institutional/risk/enterprise-risk-framework.md).

# Enterprise Risk Framework

Strategic, operational and financial risk taxonomy with Board-approved risk appetite, KRIs and three lines of defence.

## Scope

The Enterprise Risk Management (ERM) framework applies to VNX Global Ltd.’s digital asset business activities and supporting technology, treasury, compliance and operational functions. The framework is designed to ensure that material risks are identified, assessed, managed and monitored in line with DABA requirements and international risk-management standards.

## Principles

* **Conservative posture** — VNX follows a conservative risk policy focused on sustainable growth rather than using maximum regulatory capital tolerance.
* **Three lines of defence** — risk-taking functions, risk-control and compliance functions, and independent internal audit each operate with documented responsibilities and appropriate separation.
* **Board-approved appetite** — risk appetite statements, KRIs and risk assessments are documented in the Enterprise Risk Management Matrix and reviewed by the Board.
* **Annual review** — the ERM Policy and framework are reviewed and approved by the Board at least annually, and upon material changes, audit findings or other trigger events.

## Risk taxonomy

The framework categorises risks into three families:

**Strategic risks:** key person, new product, failed progress, exchange integrity and contagion.

**Operational risks:** cyber breach, inadequate client disclosures, ineffective control systems, legal/regulatory/conduct risk, people risk, default and substitution risk, business continuity, service provider risk, intellectual property, physical security, financial crime, market manipulation, segregation/financial mismanagement, business change and blockchain network risk.

**Financial risks:** credit/counterparty, capital, market, liquidity, tax and insurance.

Stablecoin-specific risks are addressed separately under the Stablecoin Risk Management Policy, including reserve adequacy, market, redemption pressure, depegging, operational and reputational risks.

## Key controls

| Control                           | Threshold / cadence                                                             | Owner                                 |
| --------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------- |
| Risk appetite statements and KRIs | Documented in the ERM Matrix; reviewed at least annually or upon trigger events | Board / Risk Management Officer       |
| Three lines of defence            | Continuous; reviewed through governance and audit processes                     | All functions                         |
| Annual policy review              | Board approval at least annually                                                | Board                                 |
| Risk treatment                    | Tolerate, treat, transfer or terminate                                          | Risk Management Officer / Risk Owners |
| Internal monitoring               | Ongoing, with escalation when thresholds are exceeded                           | Risk Owners / Compliance Team         |
| Internal audit                    | Independent review under audit mandate                                          | Internal Audit                        |
| External audit                    | Statutory and applicable regulatory audit coverage                              | External Auditor                      |

## Reporting and review

The ERM Policy is reviewed and approved by the Board at least annually. Risk owners and employees escalate new, changed or threshold-triggering risks to the Risk Management Officer and Compliance Team for assessment. Where risks exceed defined thresholds or are materially different, they are escalated to the Board and, where applicable, the Audit, Risk and Compliance Committee.

The Senior Representative notifies the BMA in the circumstances required under DABA section 20, including material business changes, cyber reporting events and other prescribed regulatory events. Internal Audit independently assesses the effectiveness of risk management, internal controls and corporate governance; external audit covers statutory audits and applicable regulatory audit requirements.

## Related policies and pages

* [Stablecoin Specific Risks](/vnx-global/institutional/risk/stablecoin-specific-risks.md)
* [Business Continuity](/vnx-global/institutional/risk/business-continuity.md)
* [Investment Policy](/vnx-global/institutional/reserve/investment-policy.md)
* [Liquidity Buffers](/vnx-global/institutional/reserve/liquidity-buffers.md)
