Approach and Governance
Who we are > Governance
Approach and Governance
Who we are > Governance
Approach and Governance
Risk Philosophy
Yoma Bank’s risk philosophy is based on its commitment to be “Lifelong Banking Partner” in Myanmar. Yoma Bank commits to achieving sustainable risk adjusted returns to support the development of the economy by enabling business growth and expanding access to financial services in target markets.
Risk Governance
Our Board of Directors is ultimately responsible for ensuring that the Bank’s activities are:
- aligned with the Bank’s long-term objectives.
- governed by an effective risk and control framework which enables all material risks to be identified, assessed and managed.
- carried out within the defined risk appetite of the Bank.
Through its Board Committees, the Board ensures that the risk management framework and internal controls are effective:
- the Risk and Compliance Oversight Committee approves risk appetite, risk management policies and oversees their implementation. It delegates responsibility to the Committees led by Management: the Executive Credit Committee (ECC), the Assets and Liabilities Committee (ALCO) and the Non-Performing Loan Committee (NPL Committee).
- the Audit Committee monitors internal controls across the Bank and reviews their effectiveness through the Internal Audit.
- the People, Remuneration and Nomination Committee ensures proper oversight and guidance in relation to the Bank’s people and remuneration related strategies, policies, frameworks, and practices.
The Chief Executive Officer (CEO) and the Chief Risk Officer (CRO) are responsible for ensuring that the risk management policies and procedures approved by the Board of Directors and the Risk and Compliance Oversight Committee are effectively implemented and embedded across the operations and business activities of the Bank.
Executive Credit Committee (ECC)
The ECC is mandated by the Board to provide oversight of the Bank’s credit activities and ensure the effective management of credit risk across the organization. The Committee is responsible for establishing and overseeing appropriate credit risk policies, underwriting standards, risk measurement methodologies, and credit approval authorities to support prudent lending practices.
Credit approval authority is delegated by the Board of Directors to the ECC, which in turn further delegates specific approval authorities to designated executive‑level credit officers in accordance with approved limits and governance requirements. The ECC oversees the consistent implementation of the Bank’s Credit Policy, Guidelines, and Procedures across all business units and ensures compliance with applicable regulatory requirements, internal policies, legal requirements, and portfolio risk appetite limits.
In addition, the ECC reviews the Bank’s credit strategy, monitors portfolio quality trends, and assesses emerging credit risks that may affect the Bank’s asset quality and performance. The Committee also oversees the development of lending and asset growth strategies in response to changing business conditions and external market developments, and reviews proposed credit products and programmes prior to their submission to the Risk and Compliance Oversight Committee for endorsement.
Asset-Liability Committee (ALCO)
The Asset-Liability Committee (ALCO) is responsible for overseeing the implementation of the Bank’s Asset-Liability Management (ALM) Policy and monitoring the key risks covered under the framework, including capital adequacy, liquidity risk, interest rate risk, foreign exchange risk, and other market risks. The Committee plays a critical role in ensuring that the Bank maintains a sound balance between risk and return while supporting its strategic objectives and business growth.
ALCO has a key strategic responsibility in managing the structure of the Bank’s balance sheet, determining pricing strategies for banking products, and ensuring that capital and liquidity levels remain sufficient to support projected business growth. The Committee also ensures compliance with applicable regulatory requirements, industry standards, legal obligations, and contractual covenants.
In addition, ALCO oversees the Bank’s liquidity risk management framework and liquidity crisis management plan. The framework is regularly reviewed and enhanced, taking into consideration the Bank’s strategic business objectives, regulatory requirements, shareholder expectations, internal risk indicators and control environment, as well as prevailing economic conditions. Through the implementation of the Board‑approved liquidity crisis management plan, ALCO helps ensure that the Bank maintains adequate liquidity and operational resilience under both normal and stressed conditions.
Non-Performing Loan Committee (NPL)
The Non‑Performing Loan (NPL) Committee is responsible for overseeing and monitoring the Bank’s non‑performing loan portfolio, including product‑level NPL trends, high‑exposure accounts, and the adequacy of loan loss provisions and provision forecasts. The Committee regularly reviews portfolio performance and emerging credit quality concerns to ensure appropriate management actions are taken in a timely manner.
The NPL Committee plays a strategic role in managing the recovery and resolution of non‑performing assets. It reviews and approves appropriate recovery strategies, including restructuring, settlements, legal actions, and other remedial measures, to maximize recoveries and mitigate credit losses. To support operational efficiency and timely decision‑making, the Committee also delegates specific authorities to management within approved governance and risk management frameworks.
Crisis Management Team
The Crisis Management Team (CMT) is responsible for the operational implementation of the Business Continuity Plan (BCP) of the Bank in accordance with the requirements of the Central Bank of Myanmar. The CMT oversees the Bank’s preparedness and response to crisis situations, ensuring that critical business functions and essential banking services remain operational during periods of disruption.
Risk Management Framework
The Enterprise Risk Management Policy has been established to define the Risk Management System of the Bank and key policy requirements to ensure robust implementation of the system. At Yoma Bank, risk management is core to all banking activities, and we aspire for the Bank’s risk management to be a competitive advantage in our mission to “Build a Better Myanmar for its People”.
Under Yoma Bank’s Risk Management Framework, as shown in the following diagram, the Enterprise Risk Management team together with the business and branch support units identify the respective risks, facilitate risk and control assessments. During the financial year, the Bank further strengthened its risk management capabilities through enhancements to its Fraud Management, Business Continuity Management, and Environmental and Social Governance (ESG) frameworks, reinforcing its operational resilience and commitment to sustainable business practices.

- Yoma Bank has implemented a Fraud Management System, focused on strengthening customer awareness, enhancing employee education, and promoting a culture of integrity across the organization. These initiatives are designed to protect customers, employees, and the Bank from fraud risks. The Bank also maintains a robust incident management framework, supported by a dedicated Customer Care Centre and Social Media Engagement Team, to monitor, record, investigate, and resolve customer complaints in a timely and effective manner.
- Business Continuity Management remains a key priority in ensuring the uninterrupted delivery of products and services to customers. To strengthen operational resilience, the Bank has undertaken a range of initiatives, including the establishment of a Crisis Management Team, enhancement of disaster recovery technology infrastructure, and the regular conduct of emergency drills, tabletop exercises, and employee training programmes. These measures help ensure preparedness and minimize service disruptions during periods of crisis or unexpected events.
- The Bank has also strengthened its Environmental and Social (E&S) Risk Management Framework through the enhancement and implementation of a tailored E&S risk assessment process. This process supports business teams, as the first line, in identifying and assessing environmental and social risks associated with lending activities, particularly for new business opportunities.
Risk Appetite Setting Process
The Bank conducts a robust risk appetite setting considering Strategic Business Objectives, Regulatory Obligations, Shareholders’ Requirements, Bank’s Internal Risk KPIs and Control Environment and External Economic Trends. The review is completed annually and approved by the Board.
Recognizing that the Bank operates in an environment characterized by heightened uncertainty arising from external factors, as well as ongoing political and economic challenges in the country, Yoma Bank proactively identifies, assesses, and monitors key risks on an ongoing basis. Appropriate mitigation and remediation measures are implemented to manage these risks effectively and strengthen the overall resilience of the Bank.
In response to this evolving operating environment, the Bank has adopted a prudent and balanced growth strategy, with a continued focus on maintaining strong capital and liquidity positions. The Bank has established a comprehensive Business Continuity Plan and Board‑approved Risk Appetite Framework, enabling it to continue delivering essential banking services at an optimal level while remaining within its defined risk tolerance. These measures are designed to strengthen the Bank’s resilience, safeguard stakeholder interests, and support sustainable growth over the medium to long term.
Internal Control Procedures
Yoma Bank maintains an integrated Internal Control and Risk Management System based on the Three Lines Model.
- Business units (First Line) are responsible for managing risks and implementing effective controls within their day‑to‑day operations.
- Risk and Compliance functions (Second Line) provide oversight, risk assessment, governance framework enhancement, and monitoring activities to support effective risk management across the Bank.
- Internal Audit (Third Line) provides independent assurance on the effectiveness of governance, risk management, and internal controls through risk‑based audits and the follow‑up of remediation actions.
The Internal Control Team plays a coordinating role by facilitating control activities, monitoring the overall control environment, promoting cross‑functional collaboration, and escalating significant issues to management where appropriate. Findings, emerging risks, and the effectiveness of key controls are regularly reported to management and relevant governance committees, while ongoing training, monitoring, and remediation activities support a culture of continuous improvement.

Three Lines of Defense Model
| First Line Risk Management | Second Line Risk Oversight | Third Line Independent Assurance |
| Takes and manage risk exposure in accordance with the risk appetite, mandate and limits set by the Board | Ensures key risks are escalated to the Board and provides oversight to ensure First Line business is executed in line with the Bank’s risk appetite | Provides the Board with an independent opinion about the effectiveness of Risk Management and Internal Controls |
| Identifies and escalates significant emerging issues related to risk | Develops the Risk Management Framework (policies, systems, processes, tools) | Confirms the level of compliance with regulations, and other limits and requirements as defined in the Bank’s policies |
You may also be interested in

Key risks
Risk of loss arising from any failure by a borrower or counterparty to meet its…
Explore Detail
BizSpace Portal
Payroll Portal
Supply Chain Financing