Risk Management Policy

1. Introduction

1.1 Background

Risk recognition and management are viewed by the Company as integral to its objectives of creating and maintaining shareholder value, and to the successful execution of the Company's strategies.

1.2 Purpose

The purpose of the Risk Management Policy (the Policy) is to ensure that:

(a) appropriate systems are in place to identify to the extent reasonably practicable all material risks that may impact on the Company's business;

(b) the financial and non-financial impact of identified risks is understood, and appropriate internal control systems are in place to limit the Company's exposure to such risks;

(c) appropriate responsibilities are delegated to control the identified risks effectively; and

(d) any material changes to the Company's risk profile are disclosed in accordance with the Company's Continuous Disclosure Policy.

For the purpose of this Policy, "risk" is defined as possible outcomes that could materially adversely impact on the Company's financial performance, assets, reputation, people or the environment.

1.3 Board responsibility

The Board is responsible for risk oversight and the management and internal control of the processes by which risk is considered for both ongoing operations and prospective actions.

As a minimum, the Board is required to:

(a) establish the acceptable levels of risk within which the Board expects the management of the Company to operate and analysing whether the Company is operating with due regard to the risk appetite set by the Board; and

(b) oversee the establishment and implementation of the risk management system; and

(c) review the effectiveness of the Company's risk management system at least once each reporting period in relation to the processes, structures and culture established to identify, assess, treat and monitor risk to support the achievement of the Company's objectives.

2. Key principles and concepts

2.1 Identified Business Risks

There are a number of risks which are inherent to the business activities which the Company undertakes. These risks may change over time as the external environment changes and as the Company expands its operations. The risk management process requires the Board to conduct regular reviews of the Company's existing risks and the identification of any new and emerging risks facing the Company, including financial and non-financial matters. It also requires the management, including mitigation where appropriate, of these risks.

2.2 Business Risk Management Policies and Practices

In order to properly identify and develop strategies and actions to manage business risks, the Company has put in place a business risk management framework based on the following key elements:

(a) an assessment of the potential impact of identified business risks and the likelihood of occurrence; (b) a ranking of the business risk in accordance with the likely impact on the Company; (c) an assessment of the acceptability of each identified risk; (d) a consideration and decision on the proposed actions to eliminate, reduce or manage each material risk; and (e) an assignment of the responsibilities for the management of each risk.

The Board reviews the Company's risk management at every Board meeting and where required, makes improvements to its risk management and internal compliance and control systems.

2.3 Additional Risk Management Policies and Practices

In addition to the specific risk management process described in this Policy, the Company has the following procedures and practices which are designed to manage specific business risks:

(a) regular budgeting and financial reporting; (b) the Company's business plan; (c) corporate strategy guidelines and procedures to review and approve the Company’s strategic plans; (d) legally binding commitments and expenditure exceeding certain levels must be submitted to the Board for approval; (e) procedures/controls to manage financial exposures and operational risks; (f) procedures/controls/policies and management standards to ensure that the Company complies with its obligations and responsibilities in relation to environmental issues, occupational health and safety matters, and the communities in which it operates; (g) oversight of the Company's financial affairs; (h) regular performance reporting enabling the identification of performance against targets and evaluation of trends; and (i) management standards to ensure that the Company complies with its obligations and responsibilities in relation to health and safety, environmental issues and the communities in which it operates.

3. Other matters

3.1 Amendment of policy

The Board must review and reassess this Policy at least once each reporting period to enable the Board to satisfy itself that this Risk Management Policy continues to be sound and that the Company is operating with due regard to the risk appetite set by the Board. Any amendments to this Policy must be approved by the Board. The Company Secretary will communicate any amendments to employees as appropriate.

This Policy can only be amended with the approval of the Board.

This Policy has been approved by the Board and takes effect from 26 February 2026 and replaces any previous policy in this regard.

3.2 Adoption of Policy and Board review