Risk and opportunity management

At Aleatica, our risk management is proactive and agile, enabling us to anticipate threats and leverage opportunities in a volatile global environment.

We maintain our Risk Policies in force and operate under the international ISO 31000 certification, which confirms our commitment to the highest management standards.

Risk management governance

Our governance is structured around the three lines of defence model, reinforcing comprehensive oversight led by the Board of Directors and the Audit and Risk Committee. 

As a key milestone, in 2025, we successfully maintained our ISO 31000 certification.

Continuous improvement of the risk and opportunity management system

2025 was a period of consolidation following the merger of the Audit and Risk areas in 2024:

Risk-audit synergy

The risk unit reviews all audit work programs to ensure the focus is strictly aligned with critical risks.

Regulatory update

We have comprehensively reviewed the risk taxonomy and updated the Business Continuity standard, incorporating a new Business Impact Analysis (BIA) format that includes requirements from the new cybersecurity framework.

Dynamic indicators

We incorporated key performance indicators and key risk indicators into the quarterly report for the boards.

Risk culture

In 2025, we strengthened our Risk Culture by adopting the COSO ERM 2017 framework (Integrating with Strategy and Performance) and implementing awareness initiatives at every level:

During FY2024, at Aleatica we provided risk management training through on-site and online courses, using our corporate training tool. Specifically, the training provided during this exercise has been:

838

Total hours of risk management training in 2025

508

Webinar Participants on Climate Change Risks 2025

5

Articles in the internal magazine

2,854

Total minutes On-screen informational messages.

4

Risk-related Communications in 2025

2

Articles in external magazines

Workshops

on emerging risks

As part of the Executive Committee’s performance evaluation, an employee’s attitude and mindset towards risk management are taken into account, directly influencing their remuneration.

Risk opportunity management process

Through our Comprehensive Risk Management framework, the Company continuously identifies, assesses, controls, monitors, and reports on the full spectrum of strategic, financial, operational, and compliance risks and opportunities to which we are exposed as an organisation:

1. Identification

Risks are identified by the owners in each of the Business Units and functional areas. To aid in identification, we have a risk taxonomy (universe) that is regularly updated and reflects the potential risks the organisation faces. This universe encompasses ESG risks, including environmental, human rights, and occupational safety risks, among others. Climate change risks are also included, aligned with the categorisation suggested by the TCFD (Task Force on Climate-related Financial Disclosure). All risks are classified based on the categories defined in the risk taxonomy. This allows us to analyse their exposure, streamline their aggregation and reporting, and show how they interact with other risks, rather than considering them in isolation.

Risks are assessed based on impact and likelihood criteria. The assessment considers three evaluations: an inherent evaluation, prior to the implementation of risk mitigation controls; a residual evaluation, after the implementation of controls; and an objective evaluation, following the implementation of action/mitigation plans. A software tool supports the entire process.
Regarding risks, the Business Units and Functional Areas define control activities and mitigation plans for each identified risk, documenting and monitoring them on an ongoing basis. It is important to note that while we focus on mitigating risks, some of them are beyond our control, such as changes in regulations, political, economic or social conditions, and exchange rate volatility. However, these risks are identified, assessed, and regularly monitored. Each risk is assigned a responsible party, who must ensure its proper management and the adequate implementation of mitigation plans.
The Risk Department, in collaboration with the Business Units and Corporate Functions, regularly monitors the progress of mitigation plans, as well as the behaviour or evolution of risks.
The most significant risks, as well as material changes, are communicated to and reviewed by Executive Management, including regional directors. The status of risks and mitigation actions is reported at least quarterly to the Committees and/or Boards of each Business Unit, the Group, and the Sustainability Committee. Additionally, individuals in key leadership roles within the organisation and its Business Units certify, on a quarterly basis, their understanding of the risks, controls, and mitigation measures (within their area of responsibility) that help control or reduce their exposure.

Key risks

Our organisation faces a range of risks and uncertainties that could significantly impact our performance and the achievement of our objectives. Below are the most significant risks identified so far.
Risk
Description
Mitigation measures
Changes to and/or rebalancing of concessions

Risk that changes to contractual terms or the economic-financial rebalancing process are not managed properly, affecting the concession’s profitability or viability.

Contract management with rebalancing clauses, rate reviews, and dispute resolution; active management with the grantor; financial control of works; review of financial models; crisis management plan; and a community/social program.
Construction progress
Risk of delays in construction or infrastructure expansion projects due to internal management, contractors, permits, or securing rights of way, which could affect delivery times and commissioning.
Construction plans with milestones and critical paths; change management; contractor evaluation and penalties; right-of-way monitoring; qualified staff; internal audits; and follow-up meetings.
Cost overruns
Risk that actual costs significantly exceed approved budgets due to poor planning, scope changes, price volatility, or contractor claims.
Monitoring of actual versus approved budgets; contract and change management; contractor evaluation with penalty clauses; and contingency provisions.
Business concentration
Risk of being overly dependent on a limited number of concessions, markets, or countries, which increases vulnerability to adverse changes in those segments.
Analysis of opportunities for expansion and partnerships; impact analysis in the event of a drop in traffic, regulatory changes, or defaults.
Infrastructure integrity/maintenance
Risk of deterioration, failure, or collapse of physical assets due to inadequate maintenance, design flaws, end of useful life, or excessive loads, resulting in interruptions, repair costs, or loss of value.
Major and minor maintenance programs; periodic technical inspections; insurance coverage; asset performance indicators; life cycle inventory; load controls.
Business continuity
Risk of critical process disruption and the inability to recover them within established timeframes and service levels.
Business continuity framework (BCP, DRP, crisis management); insurance program; maintenance and monitoring programs.
Estandares
Climate change (physical impacts)
Risk of infrastructure damage and operational disruptions due to acute weather events (floods, hurricanes, fires) or chronic ones (sea level rise, extreme temperatures).
Awareness and training; climate adaptation assessments; emission mitigation; physical and transitional risk manuals; continuity framework; insurance program.
Customer safety
Risk of accidents or incidents on managed infrastructure that result in injury or death to drivers, passengers, or pedestrians.
Road safety strategy with PRA and a Safe System approach; analysis of sections with a high concentration of accidents; signage; tools for monitoring accident rates; and training campaigns.
Cybersecurity
Risk of unauthorised access, data theft, system disruption, or extortion through cyberattacks, affecting the confidentiality, integrity, and continuity of operations.
Firewalls and anti-malware; Active Directory; internal policies for people using the system; penetration tests and audits; disaster recovery plan (DRP); awareness program; technology refresh.
Economic – political – social environment
Risk of a negative impact on results or operations due to adverse changes in the macroeconomic, political, or social environment (recessions, protests, strikes, regulatory changes, etc.).
Monitoring of the fiscal, regulatory, and geopolitical environment; scenario analysis and stress testing; geographic diversification; hedging financial instruments; lobbying; participation in forums; continuity plan and crisis management.

Emerging risks

Aleatica faces emerging risks, which are new or uncertain risks that could become more likely due to changes in the external environment. These scenarios can impact the organisation in the medium and long term, so they require constant monitoring. Among the most significant emerging risks for our business are: 

The use and regulation of artificial intelligence

AI offers opportunities to enhance efficiency and innovation, but it also carries significant risks, such as algorithmic biases, a lack of transparency, job displacement, security and privacy vulnerabilities, as well as ethical and regulatory dilemmas. Responsible AI management requires preventive controls, impact assessments, and ongoing monitoring of new regulations.

Social and environmental challenges have intensified, directly impacting companies’ operations and reputations. Factors like climate change, the scarcity of natural resources, evolving sustainability regulations, and the growing expectations of communities and costumers call for strategies focused on adaptation, compliance, and transparent communication.
The rise and sophistication of cyberattacks, driven by digitalisation and AI, pose a growing risk to business continuity and information protection.
The global regulatory environment is becoming increasingly demanding, especially in terms of data, sustainability, and human rights, forcing companies to continually adapt their processes and reporting.

International tensions and the reconfiguration of supply chains are impacting costs, lead times, and access to key resources for infrastructure projects.

These risks, along with others such as social polarisation, economic volatility, and the challenges associated with the energy transition, require proactive, comprehensive, and dynamic management to anticipate and mitigate their impact on the organisation.