TRUSTED AND RESILIENT MARKET INFRASTRUCTURE

103-1 103-2 103-3 102-15 102-30

Risk management

Moscow Exchange Group has successfully established an integrated risk management system that complies with Russian regulatory requirements, as well as with leading international standards and best practices.

Key documents:

Responsible bodies:
  • Risk Management Committee of the Supervisory Board
  • Risk Management Unit
  • Internal Audit Service
  • Internal Control Service

Role of management bodies in risk management

103-2 102-30

ESG risk management is handled by the Supervisory Board and other management bodies, such as participants in the Group’s integrated risk management system. They perform monitoring and control procedures.

The Supervisory Board of Moscow Exchange is responsible for establishing principles and approaches of the risk management system, including approving the risk management strategy, internal documents, and policies that stipulate actions to prevent the materialization of risks and minimize their consequences.

The Risk Management Committee of the Supervisory Board reviews risk management reports and develops recommendations for managing individual risk profiles, analyzes internal procedures and proposes measures for improving them, and monitors reports submitted. Similar structures have been established within the Group’s companies, including the Risk Committee of NCC Supervisory Board and the Risk Committee of NSD Executive Board. Moscow Exchange has also created a separate business unit that is responsible for managing the risks of the market operator.

ESG risks and their potential impact on the Group’s operations are identified annually within the Group’s integrated risk management system. Risk acceptance and pre-approval of risk management issues are submitted for discussion at Supervisory Board meetings. The Executive Board is responsible for defining an acceptable level of risk.

The Group has been conducting regular training sessions for its employees to improve their risk identification skills. The sessions are part of the Risk Management System Development Strategy. Risk-management-related KPIs are included in the criteria used by management for assessing employee performance.

Key risk profile

102-15

Each of the Group’s companies faces different types of risk, depending on the specific nature of their activities. As the parent company of the Group, Moscow Exchange faces risks associated with the organization of trading, as well as with transactions involving its own assets. NSD, as a core element of Russia’s financial market infrastructure, faces risks in its depository activities. The key risk bearer in the Group is NCC, which acts as a clearing house and central counterparty for all major markets of the Group, and as a commodity delivery facility for the commodities market.

The Group’s financial and non-financial risk map is updated annually following the results of the risk identification procedure. Non-financial risks are classed into several categories, as described in the table below Detailed information on risk management is presented in the 2021 Annual Report. .

Key:

 High

 Medium

Risk

Description

Risk management activities

Strategic risk

Significance

Risk of expenses (losses) resulting from (1) erroneous assumptions made by management in preparing, approving and executing strategic plans; (2) inadequate execution of decisions made by management; (3) the impact of changes caused by external factors and that affect or could affect the Group’s performance

  • Developing transformation projects in organized trading or related activities, including providing additional services and access to organized trading for new financial instruments, foreign currency, goods, and other organizational or technology changes in a uniform and structured manner;
  • Conducting feasibility studies for transformation projects, including analyzing the following variables: investment feasibility, potential economic benefits, mitigation of identified risks, and potential operational improvements;
  • Analyzing the effectiveness of implemented transformation projects, including post-project (post-investment) monitoring;
  • Planning the development of strategic activities (e.g., by designing strategic plans). As part of this process, Moscow Exchange designs a five-year strategic plan, prepares a Roadmap to guide strategy execution, assesses the resources needed to successfully execute the strategic plan, and receives final approval of the strategic plan from the Supervisory Board, which may decide to amend certain aspects;
  • Evaluating the strategic plan in terms of feasibility and amending it, if needed. This process may also involve assessing the related risks, as well as evaluating whether the strategic plan is consistent, aligned with market conditions, acceptable for stakeholders and likely to generate a competitive advantage for Moscow Exchange Group.

Compliance risk

Significance

Risk of losses due to failure to comply with legislation, internal regulations and standards issued by self-regulatory organizations (if such standards and rules are obligatory) or as a result of sanctions and other enforcement measures taken by oversight agencies

  • Monitoring legislative developments;
  • Coordinating with regulatory authorities on the development of new regulations;
  • Identifying regulatory risk in existing and proposed internal procedures;
  • Analyzing best practices in internal control;
  • Obtaining preliminary approval and performing background checks when onboarding clients, signing contracts with counterparties, admitting securities to trade, launching new products or services, etc.;
  • Setting up automated controls, including controls to run parties (stakeholders) through compliance checklists;
  • Ensuring that the necessary policies and procedures are in place;
  • Conducting mandatory training.

The Internal Control and Compliance Department is responsible for managing compliance risk.

Information security Risk

Significance

Risk of the security (confidentiality, integrity, accessibility) of information assets being compromised as a result of the materialization of information security threats.

  • Ensuring the accessibility, integrity and efficient use of information assets;
  • Ensuring information confidentiality and preventing harm from the disclosure of confidential information, including personal data;
  • Building an effective system for monitoring and protecting the Group’s information infrastructure;
  • Increasing protection and optimizing the cost of ensuring information security via a risk-based approach;
  • Raising awareness of information security risks among Group employees;

Reputational risk

Significance

Risk of expenses (losses) or any other adverse effects resulting from a negative perception of Moscow Exchange Group by its counterparties, traders and their clients, shareholders, the Central Bank of Russia, and others, which may adversely impact the Group’s ability to maintain its existing relationships and/or to establish new ones and provide access to sources of financing on an ongoing basis.

  • Collecting and analyzing coverage of Moscow Exchange Group in the media;
  • Regular analysis of information that may pose a reputational risk which has been obtained from media and other sources, including analysis of the impact of reputational factors on Moscow Exchange’s financial position, the impact of the reputation of other Group companies on the Group’s reputation, and the impact of Moscow Exchange Group’s corporate charitable and marketing activities on its business reputation;
  • Performing ongoing assessments and monitoring of PR through regular assessment of Moscow Exchange’s performance, and monitoring the number of complaints and claims from clients and counterparties, and positive and negative coverage of shareholders and related parties in the media;
  • Regularly monitoring the business reputation of shareholders, related parties, and management;
  • Overseeing the fair presentation of information in the financial statements and any other published information provided to shareholders, clients and counterparties, regulatory and oversight bodies, and other stakeholders, including for advertising or promotional purposes;
  • Preventing persons with access to certain information from using that information for their personal benefit;
  • Providing management and employees with data on negative and positive coverage about Moscow Exchange Group in the media and other sources, and considering and analyzing the completeness, credibility and objectivity of such information in a timely manner;
  • • Taking disciplinary action against employees whose misconduct may have created a risk of damaging Moscow Exchange Group’s reputation.

HR risk

Significance

Risk of expenses (losses) incurred by MOEX Group as a result of the lack of alignment between HR policy and business objectives, as well as the significant loss of key personnel or expertise.

  • Review of the parameters of the long-term incentive program for key management of the Group;
  • Management of the performance evaluation system and review of the compensation structure;
  • Revision of the ratio between remuneration components.
  • Employee engagement surveys;
  • Annual planned training program for mid-level managers;
  • Succession planning;
  • Cross-functional internship program;
  • Internal coaching program;
  • Talent management program to identify high-potential employees and facilitate their individual development.

Climate risks

TCFD

Risks of financial losses as a result of reduced demand for listing services and investment prospects of issuers in a number of industries; physical damage or loss of property, as well as malfunctions in equipment and in the availability of services to clients; additional expenditures due to regulatory changes and the need to introduce new technologies, which may adversely affect the Group companies’ revenue and reputation

  • Technological, information and organizational solutions for the protection of equipment and data;
  • Diversification of financial risk hedging instruments;
  • Introduction of ESG requirements in listing rules for issuers;
  • Development and implementation of a greenhouse gas emissions accounting system by the Group’s organizations.

For more information on climate-related risk management, see the Climate Agenda subsection.

Internal audit and internal control

Moscow Exchange’s risk management system is based on the COSO principles COSO — Committee of Sponsoring Organizations of the Treadway Commission. and structured on the ‘three lines of defense’ model, which stipulates that risk management and internal control responsibilities be distributed among management bodies, business units responsible for control and coordination, and the internal audit function. The Group continues to improve its internal control system to maintain a high level of performance.

COSO Internal Control System

Line of defense

Responsibility

Units

First line of defense

Identifying, assessing and managing risks, and developing and implementing policies and procedures governing business processes

  • All business function staff and employees of the operating units of Moscow Exchange

Second line of defense

Ongoing risk monitoring and risk management by units as part of their functions.

Infrastructure resilience issues include:
  • Information security
  • Compliance with legislation and internal documents
  • Prevention of corruption and unlawful and fraudulent activities
  • Prevention of improper use of inside information and/or market manipulation
  • Prevention of conflicts of interest
  • Operational Risk, Informational Security, and Business Continuity Department
  • Internal Control and Compliance Department
  • Internal Control Service
  • Security Department
  • Legal Department
  • Designated employees and departments of the Finance Unit

Third line of defense

Overseeing the efficiency of business activities, the management of assets and liabilities, and the effectiveness of the risk management system

  • Internal Audit Service
  • Management bodies of Moscow Exchange

Compliance with international standards

103-3

The Group conducts an annual audit of its compliance with the CPMI-IOSCO Principles for Financial Market Infrastructures, the COSO Enterprise Risk Management Framework, and the Basel Committee on Banking Supervision risk management guidelines.

In 2020, NCC successfully underwent an operational audit by PwC (an international audit and consulting company) to check compliance with the requirements of the Central Bank of Russia Central Bank of Russia Regulation No. 556-P, dated 11 November 2016, On the Procedure Whereby the Central Counterparty Conducts an Operational Audit. . The audit covered the following components: management of risks of the central counterparty, assessment of the accuracy of the central counterparty model, stress-testing of risks of the central counterparty, determination of the allocated capital of the central counterparty, and recovery of financial stability of the central counterparty. The operational audit is conducted every two years, and the most recent was conducted in March 2022.

NCC also undergoes a certification audit every three years in accordance with ISO 9001 Quality management systems (the most recent audit was conducted in 2019).

Distribution of risk management responsibilities

Management bodies

  • Approval of core risk management principles and approaches
  • Control and oversight of the risk management system
  • Key decisions to manage the most significant risks

Risk management and internal control services

  • Monitoring of risk management processes and reporting to management bodies
  • Compliance with standards and requirements
  • Improvement of the internal control and risk management systems
  • Risk assessment
  • Development and implementation of risk management measures
  • Development and improvement of internal policies and procedures

Business and operational units

  • Risk identification
  • Risk assessment

The Group’s companies have developed risk and capital management strategies. As part of its risk management strategy, Moscow Exchange Group reviews its risk appetite and risk tolerance annually in the context of the Group’s strategic objectives.

Disclosure

Information Policy

103-2

As a market operator, Moscow Exchange applies a transparent investor- and bidder-oriented information policy regarding its activities. This ensures that stakeholders can exercise their rights to reliable information to the fullest possible extent. As per the information policy, the purpose of disclosing information about Moscow Exchange as an issuer of securities is to reach all stakeholders so that they can make balanced decisions on holding Moscow Exchange equity or performing other actions.

Moscow Exchange complies with the following principles of disclosure regarding its activities:
  • regularity and promptness of reporting;
  • availability for stakeholders, reliability and completeness of disclosures;
  • neutrality, namely the avoidance of prioritizing certain groups of recipients over others;
  • accountability for information disclosure.

Moscow Exchange does not evade disclosure of adverse information if such information is material for shareholders and other stakeholders.

Disclosure at the request of government agencies

Moscow Exchange Group is obliged under Russian law to disclose information on market participants (issuers and bidders By virtue of Federal Law No. 325-FZ. ) to competent government agencies, including law enforcement agencies, for the prevention or investigation of potentially unlawful activities. Such disclosures may cover insider trading, market manipulation (Federal Law No. 224), and anti-money laundering (Federal Law No. 115).

Information security

103-2 FN-EX-550a.3

Information security (IS) means the protection of information and the equipment used to process it from accidental or deliberate interference, whether natural or artificial.

The main goal of ensuring IS is to appropriately protect the company’s business processes, as well as to minimize IS risks when organizing trading and clearing services, and when providing services on the Equity, Derivatives, FX, and Money Markets. This goal is achieved by ensuring and continuously maintaining the confidentiality, integrity and accessibility of the company’s protected information assets.

Key documents:

Responsible bodies:
  • Operating Risk, Information Security, and Business Continuity Department
  • Technical Policy Committee

Moscow Exchange has implemented an information security management system that meets the requirements of Russian law and complies with ISO 27001. Organizational and technical activities are continuously conducted to ensure information security and manage IT infrastructure and information security incidents. The Security Operations Center is responsible for monitoring and responding to information security incidents. The Group regularly conducts information security audits, intrusion tests, and anti-phishing tests to manage risks. To protect against malicious attacks, Moscow Exchange uses its own equipment or a provider’s.

103-3

In October 2021, following an independent audit, the Group underwent recertification for compliance with ISO 27001:2013 (Information technologies. Security techniques. Information security management systems. Requirements) and ISO 22301:2012 (Societal security. Business continuity management systems. Requirements). This certification is voluntary and covers 100 measures aimed at ensuring information security and business continuity.

Employees are required to comply with information security measures and are provided with training and information, including the following activities:
  • including employees’ compliance with information security requirements in KPIs;
  • online training on information security, and introductory briefings during onboarding;
  • regular newsletters on information security and protection of confidential information;
  • workshops on preventing phishing attacks.

Technology development

103-2

The implementation of technology development processes at Moscow Exchange Group is regulated under the Group’s Information Technology Development Strategy. IT systems are regularly updated with new products and services, and new platform solutions are developed and implemented. The Development Strategy focuses on:
  • implementing business and technology initiatives;
  • accelerating the incorporation of new technologies while maintaining reliability;
  • creating an innovative IT environment;
  • boosting synergy within the Group;
  • implementing an IT management model;
  • controlling cost-effectiveness.
Key documents:
  • Information Technology Development Strategy

Responsible bodies:
  • IT User Committee
  • Managing Director for Information Technologies

Uninterrupted and fault-tolerant systems are supported by “hot” and “warm” back-up technology that facilitates rapid restoration of the trading and clearing systems in case of failure. Server equipment that performs critical trading and clearing operations is no more than three years old, while network equipment is no more than five years old and is regularly upgraded by installing the most up-to-date models. With due consideration for targets for reduced energy consumption, older and less energy-efficient servers are taken out of service.

Privacy of personal data

103-2 FN-EX-550a.3

The principles, terms and measures that ensure the security of personal data processing are set out in the Personal Data Processing Policy of Moscow Exchange.

103-3

Moscow Exchange Group conducts regular human rights risk assessments associated with data privacy. To assess this risk, the Group uses its own risk appetite methodology for assessing risk appetite. In accordance with the Methodology for Determining Risk Appetite Benchmarks of Moscow Exchange. Moscow Exchange discloses the process for evaluating and responding to law enforcement or government data requests in accordance with Russian law.

All employees can express their concerns regarding the handling of personal data via the Speak Up! hotline. The Group companies consider the concerns raised and take appropriate action.

Market access and customer experience

FN-EX-550a.3

Moscow Exchange offers its clients information and technology services that provide real-time market data, as well as information on trading results and indices.

It works to increase the appeal of its services on organizing trade on the commodity and financial markets for investors and issuers.

Key documents:

Responsible departments:
  • Customer Service Department
  • Customer Support Department
  • Technical Access Department
Moscow Exchange’s technology infrastructure provides market participants with a safe and reliable environment that supports uninterrupted trading, clearing, and settlement operations. Reliability is ensured by the following factors:
  • high-quality risk management;
  • capitalized central counterparty and settlement infrastructure;
  • high standards of listing and information disclosure by issuers.
Moscow Exchange spares no efforts to ensure convenience for its customers:
  • develops new products, services, and ways of trading;
  • extends trading hours;
  • implements new technologies for access to trading and market data;
  • strengthens cooperation with other markets and exchanges.

To continue developing Moscow Exchange as a trusted market participant, the Group has set the following objectives:

Category

Key objectives

Providing additional world-class exchange services beyond traditional exchange products

  • Offer a wider range of exchange products and services beyond those currently available on traditional exchange markets (stocks, bonds and derivatives).

Creation of uniform infrastructure for the entire Russian market, including traditional over-the-counter segments, based on a single set of post-trading services with integrated settlement, collateral and risk management systems.

  • Continue to enhance access for market participants and their customers to global OTC markets, offer better prices thanks to the exchange infrastructure, and further expand new tailored mechanisms for liquidity takers/makers that are recognized globally among OTC FX platforms.

Development of central counterparty and central depository institutions

  • Ensure the operational reliability of depositary and clearing services.
  • Modernize equity accounting infrastructure: consolidation of records, collateral management and segregated record keeping.
  • Maintain the high share of central counterparty repo transactions in the total volume of inter-dealer repo.
  • Develop a market for standardized derivative financial instruments with centralized clearing, and make it easier for market participants to sign long-term derivatives contracts.

Process reliability and efficiency

  • Ensure the uninterrupted operation of trading and information systems as well as prompt response to any potential disruption.
  • Implement measures to mitigate dependence on services provided by foreign vendors to better manage sanctions-related technological risk and account for macro-political factors.

Creation of new services for individuals and corporate clients

  • Develop the Finuslugi.ru personal finance platform for retail investors, a one-stop shop for all financial products and services offered on the market (for more details, see “2021 Sustainability Performance Highlights: Responsible investing and sustainable growth”).
  • Develop a single marketplace interface for corporate clients, including a wide range of treasury services (asset and liability management) and division of services by trading, clearing and settlement.