Risk Management

Risk Management Process

The Línea Directa Group is exposed to various risks inherent to the activities and businesses it carries out, as well as to those arising from external factors, which may prevent it from achieving its objectives and successfully executing its strategies. To ensure that the most relevant risks are properly identified, measured, managed and controlled, the following principles of action are established:

  • Integration. Risk management is part of management responsibilities and an integral part of all organisational processes. A risk management culture must be maintained in every decision taken at all levels.
  • Independence. At operational level, appropriate segregation of duties must be ensured, as well as coordination mechanisms between business units and risk monitoring and control units.
  • Comprehensive management. The entities of the Línea Directa Group must identify, measure, manage and control all their significant risks, establishing the appropriate policies, procedures, structure and resources for each of them. The Risk Map is the tool that provides a global view of the most significant risks to which the entity is exposed.
  • Transparency. Appropriate channels must be maintained to facilitate the communication of internal information, so that any threat can be detected as early as possible in order to avoid or reduce its impact.
  • Review and continuous improvement of risk management. The adequacy, suitability and efficiency of risk management will be reviewed and assessed periodically. Improvement opportunities that may arise internally from lessons learned from reported incidents, or externally from the availability of new tools and knowledge that can improve risk management, will be analysed.
  • Compliance with internal regulations. At all times, action must be taken in accordance with the values and standards of conduct reflected in the Code of Ethics, especially the commitment to legality, and under the principle of “zero tolerance” towards the commission of unlawful acts and situations of fraud set out in the Integrity and Compliance Policies.

Review of Risk Exposure

Línea Directa has defined a risk map with associated indicators (KRIs) and internal controls, through which the company’s risk exposure is reviewed monthly, quarterly, semi-annually or, in specific cases, annually, whenever the type of control does not allow it to be performed more frequently.

Audit of Risk Management Processes

In 2025, the Internal Audit area carried out a series of reviews focused on assurance risk management and ICT risk control due to a regulatory change concerning the Digital Operational Resilience Act (DORA):

  • Assurance Map: The objective of this audit carried out during 2025 consisted, among other functions, of creating a permanent assurance map at Línea Directa and gaining knowledge of the level of assurance over risks. The assurance functions (certifying their degree of confidence) of each of the company’s areas were assessed, as they are the first line of defence performing assurance work in their operations. The procedures established and processes implemented by the Risk Area will provide an integrated and updated view of the assurance level of the risks managed by the Areas. Likewise, the impact of assurance work on the assessment of risks in the corporate map and the degree of assurance of the entity’s relevant risks were evaluated (high and very high risks included in the “TOP TEN” risk category). In addition, the information flow and the deadline for updating the assurance map were defined, as well as the controls to guarantee the quality of assurance work and its alignment with the corporate methodology.
  • Implementation of the Digital Operational Resilience Act (DORA). The main objective of the Digital Operational Resilience Act (DORA) is to strengthen cybersecurity and the resilience of information and communication technology (ICT) systems against cyberattacks and other technological incidents. For the proper management of related ICT risks, Línea Directa has implemented an ICT risk governance system, which includes its providers, an incident reporting and management system (internal and external), and a testing-based strategy that enables the resilience of LDA’s systems to be assessed periodically. The objective of the audit was to verify Línea Directa’s performance regarding certain aspects related to ICT risk management, incidents and Operational Resilience testing. The degree of compliance with the identified gaps regarding said resilience was also reviewed, and the maturity level of Digital Operational Resilience at Línea Directa was assessed.

Risk Culture

Línea Directa has developed a risk management culture since its inception. Each year, a high proportion of the workforce has financial incentives linked to objectives related to risk management, from Senior Management to middle managers and back-office employees. In 2025, these objectives were linked to employee training and awareness in Sustainability. In 2025, training sessions were held with the aim of embedding the risk culture in the company’s processes, understanding risk and its control environment, and applying the internal control methodology. Cross-functional departments across the company participated in these training sessions.