Risk Management Policy
Effective Date: 1
st
July 2026
Finesse Capital ("the Firm", "we", "us", or "our") maintains a risk management framework designed to identify, assess, manage, and monitor the risks arising from its business, in order to protect clients, the Firm, and its stakeholders, and to comply with applicable law and the requirements of the Securities and Exchange Commission (SEC) and the Central Bank of Nigeria (CBN), where relevant. This Risk Management Policy (the "Policy") describes our approach at a general level; the detailed procedures supporting this Policy are maintained internally.
Our Commitment
We are committed to embedding a strong risk management culture across the Firm, in which risk is everyone's responsibility, not solely that of the Compliance Officer or senior management. We aim to take a proportionate, forward-looking approach to risk, balancing the pursuit of our business objectives with the protection of our clients, our people, and the integrity of the markets in which we operate.
Purpose and Scope
This Policy applies to all risks arising from the Firm's business activities, including those relating to client portfolios, the Firm's own operations, and its people, systems, and third-party relationships. It sets out the categories of risk we consider, and the general framework through which those risks are governed.
Risk Governance
Responsibility for risk management is set within a clear governance structure. Ultimate oversight of the Firm's risk management framework rests with senior management, who are responsible for setting the Firm's risk appetite and ensuring that adequate resources and controls are in place.
The Compliance Officer is responsible for monitoring compliance-related risk, including regulatory and financial crime risk, and for escalating material risk issues to senior management.
All employees are responsible for identifying and escalating risks arising in the course of their day-to-day work.
Regulatory Compliance
Regulatory compliance risk is treated as a standing priority within our risk management framework, not merely one category among others. We monitor changes in applicable law and regulatory guidance, including that issued by the SEC, the CBN, and the Nigeria Data Protection Commission (NDPC), and assess their impact on our business. We maintain policies, procedures, and training designed to support compliance with our regulatory obligations, and we engage openly with our regulators, including through timely and accurate regulatory reporting where required.
Categories of Risk
We consider the following broad categories of risk as part of our risk management framework:
- Market risk: the risk of loss arising from movements in market prices, interest rates, or exchange rates affecting client portfolios or the Firm's own positions.
- Credit and counterparty risk: the risk that a counterparty, custodian, or other third party fails to meet its obligations.
- Liquidity risk: the risk that assets cannot be realized, or obligations met, in a timely manner without adverse impact.
- Operational risk: the risk of loss resulting from inadequate or failed internal processes, people, or systems, or from external events.
- Compliance and regulatory risk: the risk of loss, sanction, or reputational harm arising from a failure to comply with applicable law or regulatory requirements.
- Financial crime risk: the risk that the Firm's products or services are used to facilitate money laundering, terrorist financing, fraud, bribery, or corruption, as further addressed in our Anti-Money Laundering Policy.
- Technology and cyber risk: the risk of loss or disruption arising from a failure, compromise, or misuse of information systems, including cyberattacks and data breaches.
- Concentration risk: the risk arising from insufficient diversification, whether in a client portfolio, a counterparty relationship, or the Firm's own revenue base.
- Reputational risk: the risk of damage to the Firm's reputation arising from any of the above, or from the conduct of the Firm, its staff, or its associates.
- Other risk: the risk not specifically identified above but which may impact the company’s business.
Risk Identification and Assessment
Risks are identified through a combination of ongoing business-as-usual monitoring, periodic risk assessments, client and transaction due diligence, internal reporting, and lessons learned from incidents or near-misses. Identified risks are assessed by reference to their likelihood and potential impact, in order to prioritize the Firm's response and allocate resources appropriately.
Continuous Monitoring, Reporting and Escalation
Risk exposures and the effectiveness of controls are monitored on a continuous, ongoing basis, rather than solely at fixed review points, so that emerging risks can be identified and addressed promptly. Material risk issues, control failures, or incidents are escalated to the Compliance Officer or senior management without delay, in accordance with our internal escalation procedures, and, where required, reported to the relevant regulatory authority.
Risk Mitigation and Controls
Where a risk is identified, we implement controls designed to reduce it to a level consistent with our risk appetite, which may include policies and procedures, staff training, segregation of duties, technology controls, insurance, and third-party due diligence. Controls are reviewed periodically to confirm that they remain effective and proportionate to the risk they are designed to address.
Information Security
We maintain technical and organizational measures designed to protect the confidentiality, integrity, and availability of client and Firm information, including access controls, encryption, staff training, and regular review of our security practices, consistent with our Privacy Policy. We maintain arrangements to detect, respond to, and recover from information security incidents, and to notify affected individuals and, where required, the relevant regulatory authority, in accordance with applicable law.
Business Continuity
As part of our operational risk management, we maintain arrangements designed to enable the Firm to continue, or promptly resume, critical business functions in the event of a significant disruption, and to protect client interests during any such disruption.
Client Risk Disclosure
Risks specific to a client's investments or strategy are disclosed to the client directly, as further described in our Transparency, Disclosure and Client Commitment Statement and the applicable Client Agreement. This Policy addresses the Firm's internal risk management framework and does not replace those client-specific disclosures.
Review of This Policy
This Policy is reviewed periodically, and updated as necessary, to reflect changes in our business, the risk environment, or applicable law. We may update this Policy from time to time; the updated version will be posted on our website with a revised effective date.