For the complete documentation index, see llms.txt. This page is also available as Markdown.

Enterprise Risk Framework

Strategic, operational and financial risk taxonomy with Board-approved risk appetite, KRIs and three lines of defence.

Scope

The Enterprise Risk Management (ERM) framework applies to VNX Global Ltd.’s digital asset business activities and supporting technology, treasury, compliance and operational functions. The framework is designed to ensure that material risks are identified, assessed, managed and monitored in line with DABA requirements and international risk-management standards.

Principles

  • Conservative posture — VNX follows a conservative risk policy focused on sustainable growth rather than using maximum regulatory capital tolerance.

  • Three lines of defence — risk-taking functions, risk-control and compliance functions, and independent internal audit each operate with documented responsibilities and appropriate separation.

  • Board-approved appetite — risk appetite statements, KRIs and risk assessments are documented in the Enterprise Risk Management Matrix and reviewed by the Board.

  • Annual review — the ERM Policy and framework are reviewed and approved by the Board at least annually, and upon material changes, audit findings or other trigger events.

Risk taxonomy

The framework categorises risks into three families:

Strategic risks: key person, new product, failed progress, exchange integrity and contagion.

Operational risks: cyber breach, inadequate client disclosures, ineffective control systems, legal/regulatory/conduct risk, people risk, default and substitution risk, business continuity, service provider risk, intellectual property, physical security, financial crime, market manipulation, segregation/financial mismanagement, business change and blockchain network risk.

Financial risks: credit/counterparty, capital, market, liquidity, tax and insurance.

Stablecoin-specific risks are addressed separately under the Stablecoin Risk Management Policy, including reserve adequacy, market, redemption pressure, depegging, operational and reputational risks.

Key controls

Control
Threshold / cadence
Owner

Risk appetite statements and KRIs

Documented in the ERM Matrix; reviewed at least annually or upon trigger events

Board / Risk Management Officer

Three lines of defence

Continuous; reviewed through governance and audit processes

All functions

Annual policy review

Board approval at least annually

Board

Risk treatment

Tolerate, treat, transfer or terminate

Risk Management Officer / Risk Owners

Internal monitoring

Ongoing, with escalation when thresholds are exceeded

Risk Owners / Compliance Team

Internal audit

Independent review under audit mandate

Internal Audit

External audit

Statutory and applicable regulatory audit coverage

External Auditor

Reporting and review

The ERM Policy is reviewed and approved by the Board at least annually. Risk owners and employees escalate new, changed or threshold-triggering risks to the Risk Management Officer and Compliance Team for assessment. Where risks exceed defined thresholds or are materially different, they are escalated to the Board and, where applicable, the Audit, Risk and Compliance Committee.

The Senior Representative notifies the BMA in the circumstances required under DABA section 20, including material business changes, cyber reporting events and other prescribed regulatory events. Internal Audit independently assesses the effectiveness of risk management, internal controls and corporate governance; external audit covers statutory audits and applicable regulatory audit requirements.

Last updated