Risk and opportunity management
At Aleatica, our risk management is proactive and agile, enabling us to anticipate threats and leverage opportunities in a volatile global environment.
We maintain our Risk Policies in force and operate under the international ISO 31000 certification, which confirms our commitment to the highest management standards.
Risk management governance
Our governance is structured around the three lines of defence model, reinforcing comprehensive oversight led by the Board of Directors and the Audit and Risk Committee.
Continuous improvement of the risk and opportunity management system
2025 was a period of consolidation following the merger of the Audit and Risk areas in 2024:
Risk-audit synergy
Regulatory update
Dynamic indicators
Risk culture
In 2025, we strengthened our Risk Culture by adopting the COSO ERM 2017 framework (Integrating with Strategy and Performance) and implementing awareness initiatives at every level:
During FY2024, at Aleatica we provided risk management training through on-site and online courses, using our corporate training tool. Specifically, the training provided during this exercise has been:
838
Total hours of risk management training in 2025
508
5
2,854
4
2
Workshops
As part of the Executive Committee’s performance evaluation, an employee’s attitude and mindset towards risk management are taken into account, directly influencing their remuneration.
Risk opportunity management process
Through our Comprehensive Risk Management framework, the Company continuously identifies, assesses, controls, monitors, and reports on the full spectrum of strategic, financial, operational, and compliance risks and opportunities to which we are exposed as an organisation:
1. Identification
Risks are identified by the owners in each of the Business Units and functional areas. To aid in identification, we have a risk taxonomy (universe) that is regularly updated and reflects the potential risks the organisation faces. This universe encompasses ESG risks, including environmental, human rights, and occupational safety risks, among others. Climate change risks are also included, aligned with the categorisation suggested by the TCFD (Task Force on Climate-related Financial Disclosure). All risks are classified based on the categories defined in the risk taxonomy. This allows us to analyse their exposure, streamline their aggregation and reporting, and show how they interact with other risks, rather than considering them in isolation.
2. Assessment
3. Response
4. Review and monitoring
5. Information, communication, and reporting
Key risks
Risk that changes to contractual terms or the economic-financial rebalancing process are not managed properly, affecting the concession’s profitability or viability.
Emerging risks
Aleatica faces emerging risks, which are new or uncertain risks that could become more likely due to changes in the external environment. These scenarios can impact the organisation in the medium and long term, so they require constant monitoring. Among the most significant emerging risks for our business are:
The use and regulation of artificial intelligence
AI offers opportunities to enhance efficiency and innovation, but it also carries significant risks, such as algorithmic biases, a lack of transparency, job displacement, security and privacy vulnerabilities, as well as ethical and regulatory dilemmas. Responsible AI management requires preventive controls, impact assessments, and ongoing monitoring of new regulations.
Sustainability and climate change
Cybersecurity
Regulatory pressure and compliance
Geopolitics and supply chains
International tensions and the reconfiguration of supply chains are impacting costs, lead times, and access to key resources for infrastructure projects.
These risks, along with others such as social polarisation, economic volatility, and the challenges associated with the energy transition, require proactive, comprehensive, and dynamic management to anticipate and mitigate their impact on the organisation.