Luberef’s approach to risk management is built on foresight, governance, and resilience. The Company proactively identifies, assesses, and mitigates risks across strategic, operational, and financial dimensions, ensuring that decisions balance opportunity with risk exposure.

Governance Structure for Risk Oversight

Luberef’s governance model ensures that risk oversight is embedded across all organizational levels.

Risk oversight

Risk oversight
FunctionRole
Board of DirectorsProvides strategic risk oversight, defines risk appetite, and ensures that risk management supports the Company’s long-term objectives.
Board Audit CommitteeOversees the risk management framework, reviews risk registers, monitors compliance, and ensures effective internal controls and assurance processes.
Management TeamImplements the risk management framework, executes mitigation strategies, and monitors operational risks.

Risk oversight

Risk oversight
FunctionRole
Board of DirectorsProvides strategic risk oversight, defines risk appetite, and ensures that risk management supports the Company’s long-term objectives.
Board Audit CommitteeOversees the risk management framework, reviews risk registers, monitors compliance, and ensures effective internal controls and assurance processes.
Management TeamImplements the risk management framework, executes mitigation strategies, and monitors operational risks.

Three Lines of Defense

Luberef’s Enterprise Risk Management (ERM) framework is structured around the internationally recognized Three Lines of Defense model, ensuring accountability, transparency, and continuous improvement.

Three Lines of Defense

Three Lines of Defense
LineFunctionRole
First LineBusiness and Support UnitsResponsible for identifying and managing risks within their areas and implementing appropriate controls.
Second LineRisk Management FunctionMonitors and reports on enterprise-level risks, oversees mitigation plans, and aligns ERM practices with business strategy.
Third LineInternal AuditProvides independent assurance on the effectiveness of controls, governance systems, and the overall risk management process.

Three Lines of Defense

Three Lines of Defense
LineFunctionRole
First LineBusiness and Support UnitsResponsible for identifying and managing risks within their areas and implementing appropriate controls.
Second LineRisk Management FunctionMonitors and reports on enterprise-level risks, oversees mitigation plans, and aligns ERM practices with business strategy.
Third LineInternal AuditProvides independent assurance on the effectiveness of controls, governance systems, and the overall risk management process.

Process and Risk Management Framework

Luberef maintains an Enterprise Risk Management (ERM) Framework aligned with ISO 31000:2018 and COSO ERM 2017 principles, through which the Company continuously enhances its risk management capabilities. The framework supports comprehensive risk identification and mitigation across the enterprise, strengthens integration between ERM and Insurance Management, while also reinforcing financial and operational resilience.

Luberef also undertakes periodic third-party ERM maturity assessments to benchmark its practices against industry peers, identify key strengths, and define targeted areas for continuous improvement. The Company also promotes a strong risk-aware culture by empowering employees to take ownership of risk management and adapt to evolving market and operational conditions.

Luberef’s risk management framework identifies, evaluates, and mitigates risks across all operations. Policies are regularly reviewed to ensure alignment with market dynamics and business objectives.

Expanding Risk Domains

Luberef applies a comprehensive and proactive approach to managing both internal and external risks, ensuring resilience across all aspects of its operations. Its risk management system covers a broad range of risk domains to ensure business continuity and strategic agility.

Process and Risk Management Framework

Process and Risk Management Framework
StepActionDescription
1Define ScopeEstablish the scope and context of risk assessment in alignment with the Board’s strategic direction.
2Identify RisksIdentify and assess risks using internal and external frameworks with input from leadership.
3Independent AssuranceEngage external assurance providers to evaluate the effectiveness of internal controls when required.
4Assess and MonitorApply transparent, consistent methodologies to assess and monitor risks objectively.
5Report and ReviewReport risks, guide teams, and review processes to ensure effectiveness and accountability.
6Track TrendsMonitor market and macroeconomic trends to adjust frameworks and strengthen resilience.
7Continuous ImprovementMaintain ongoing discussions on emerging risks and continuously enhance risk management systems.

Process and Risk Management Framework

Process and Risk Management Framework
StepActionDescription
1Define ScopeEstablish the scope and context of risk assessment in alignment with the Board’s strategic direction.
2Identify RisksIdentify and assess risks using internal and external frameworks with input from leadership.
3Independent AssuranceEngage external assurance providers to evaluate the effectiveness of internal controls when required.
4Assess and MonitorApply transparent, consistent methodologies to assess and monitor risks objectively.
5Report and ReviewReport risks, guide teams, and review processes to ensure effectiveness and accountability.
6Track TrendsMonitor market and macroeconomic trends to adjust frameworks and strengthen resilience.
7Continuous ImprovementMaintain ongoing discussions on emerging risks and continuously enhance risk management systems.

Business Continuity and Operational Resilience

Luberef’s Business Continuity Framework ensures the uninterrupted continuation of critical operations during potential disruptions. It focuses on

  • Identifying critical processes and assessing potential impacts.
  • Developing and testing recovery and contingency plans.
  • Aligning continuity plans with ERM and cybersecurity systems to manage both digital and physical disruptions.
  • Conducting scenario-based simulations and improvement exercises.

Cybersecurity and Digital Resilience

During 2025, Luberef elevated cybersecurity governance to a new level of maturity. Operating as a strategic governance enabler, the Cybersecurity function ensures that risks across IT and Operational Technology (OT) environments are proactively managed.

Key achievements included

  • Integrated IT/OT Governance Model: Clearly defined roles, escalation pathways, and decision rights across all business units.
  • Cyber Risk Register: Implemented a unified, business-aligned risk register to assess and prioritize risks consistently.
  • Maturity Advancements: Completed structured maturity evaluations with Aramco, identifying capability gaps and targeted improvements across people, process, and technology.
  • Incident Readiness: Conducted executive- level tabletop exercises and improved coordination with internal and external stakeholders.
  • Cultural Awareness: Launched Luberef’s first company-wide Cybersecurity Awareness Campaign, achieving 89% engagement, embedding security awareness across all functions.
  • Strong Results: Recorded zero critical or high-severity cybersecurity incidents during 2025, reflecting effective governance, monitoring, and preventive controls.