Enterprise Risk Framework
Strategic, operational and financial risk taxonomy with Board-approved risk appetite, KRIs and three lines of defence.
Scope
The Enterprise Risk Management (ERM) framework applies to VNX Global Ltd.’s digital asset business activities and supporting technology, treasury, compliance and operational functions. The framework is designed to ensure that material risks are identified, assessed, managed and monitored in line with DABA requirements and international risk-management standards.
Principles
Conservative posture — VNX follows a conservative risk policy focused on sustainable growth rather than using maximum regulatory capital tolerance.
Three lines of defence — risk-taking functions, risk-control and compliance functions, and independent internal audit each operate with documented responsibilities and appropriate separation.
Board-approved appetite — risk appetite statements, KRIs and risk assessments are documented in the Enterprise Risk Management Matrix and reviewed by the Board.
Annual review — the ERM Policy and framework are reviewed and approved by the Board at least annually, and upon material changes, audit findings or other trigger events.
Risk taxonomy
The framework categorises risks into three families:
Strategic risks: key person, new product, failed progress, exchange integrity and contagion.
Operational risks: cyber breach, inadequate client disclosures, ineffective control systems, legal/regulatory/conduct risk, people risk, default and substitution risk, business continuity, service provider risk, intellectual property, physical security, financial crime, market manipulation, segregation/financial mismanagement, business change and blockchain network risk.
Financial risks: credit/counterparty, capital, market, liquidity, tax and insurance.
Stablecoin-specific risks are addressed separately under the Stablecoin Risk Management Policy, including reserve adequacy, market, redemption pressure, depegging, operational and reputational risks.
Key controls
Risk appetite statements and KRIs
Documented in the ERM Matrix; reviewed at least annually or upon trigger events
Board / Risk Management Officer
Three lines of defence
Continuous; reviewed through governance and audit processes
All functions
Annual policy review
Board approval at least annually
Board
Risk treatment
Tolerate, treat, transfer or terminate
Risk Management Officer / Risk Owners
Internal monitoring
Ongoing, with escalation when thresholds are exceeded
Risk Owners / Compliance Team
Internal audit
Independent review under audit mandate
Internal Audit
External audit
Statutory and applicable regulatory audit coverage
External Auditor
Reporting and review
The ERM Policy is reviewed and approved by the Board at least annually. Risk owners and employees escalate new, changed or threshold-triggering risks to the Risk Management Officer and Compliance Team for assessment. Where risks exceed defined thresholds or are materially different, they are escalated to the Board and, where applicable, the Audit, Risk and Compliance Committee.
The Senior Representative notifies the BMA in the circumstances required under DABA section 20, including material business changes, cyber reporting events and other prescribed regulatory events. Internal Audit independently assesses the effectiveness of risk management, internal controls and corporate governance; external audit covers statutory audits and applicable regulatory audit requirements.
Related policies and pages
Last updated
