The Enterprise Risk Management Division (ERMD) is responsible for determining the classification of the risks into different categories and levels with the purpose of efficient and effective risk management across the Company. The following section describes Tadawul’s approach for managing different categories of risks:

Operational risks

Risks arising from poor efficiency or failure of internal and external processes, individuals, systems, or external events. These include issuer operations risks, member operations risks, market operations risks, human resources risks and physical asset risks.

Technology risks

Technology failure disrupting the business operations. Technology risks include infrastructure failures, IT system failures or telecommunications risks.

Corporate risks

Risks related with Company’s strategic decisions, compliance and governance framework, projects and communication.

Financial risks

Risks that may affect the Company’s revenues or reduce the efficiency of operating expenses. Financial risks include liquidity risks, credit risks, accounting and financial reporting risks, insurance risks, Fraud.

Information security risks

Risks arising from technical vulnerabilities and threats to information assets owned by the Company that may affect the achievement of business objectives. Information Security Risks include internal threats, external threats, data privacy risks and data integrity risks.

Business continuity risks

Risks that lead to a catastrophic disruptive of The Company’s operation, resulting in significant losses in the technology infrastructure and level of services provided. The ERMD determines the requirements for restoring the service and ensuring the company’s ability to maintain the services provided to ensure the integrity and credibility of the market and investors. The Department also works to establish controls and plans to reduce the risk of disruption of the system or facilities to ensure the continuity of business commensurate with the requirements of raising the efficiency of the market.

Business environment risks

Risks arising from a number of external factors that form the business environment which affect the performance and objective of the Company such as economic, political and environmental conditions, which includes the risks of market members, legal risks, data vendor risks and the risks of vendors and suppliers.

Businesses and contracts to which the Company is a party, or in which a member of the Board of Directors has an interest

Business or contract to which
the Company is a party of and
in which a Director of the Company is or was interested
Nature of the
contract or business
Conditions of the contract or business Amount
Board Member
Mr. Sabti S AlSabti
Saudi Tadawul Group Holding Company’s investment in Riyad SAR Trade Fund of Riyad Capital An open-ended mutual fund available for the public Outstanding investment in the beginning of the year 2022 was SAR 105,962,714. During the year, the Company purchased units of fund amounting to SAR 28,981,923 and sold amounting to SAR 136,500,932 which included the realized gain of SAR 1,556,295 which resulted in the investment of the Company to be Nil as of 31 December 2022.

In addition to the above, the Company entered into transaction with entities having common Directors within the normal course of its business activities as disclosed in Note 30 to the Company’s audited Financial Statements for the year ended 31 December 2022.