YWO (MU) Ltd · Legal
Risk Disclosure & Management Policy
Last Updated: May 2026
1. Purpose of Risk Disclosure and Management Policy
The Company is incorporated under the laws of Mauritius and is licensed by the Financial Services Commission, Mauritius (FSC).
The activity for which it is licensed by the FSC and undertaken by the Company carry an element of risk.
This Risk Disclosure and Management Policy (“Policy”) sets forth a comprehensive framework for identifying, assessing, managing, and mitigating risks that the Company may encounter in the course of its operations. It establishes clear roles and responsibilities for the Board of Directors, the Compliance Officer, the Directors, and senior management, ensuring that risk management is integrated into all aspects of the Company’s decision-making processes. The Policy underscores the Company’s commitment to maintaining a robust risk-aware culture that prioritizes both operational integrity and regulatory compliance.
The primary objective of this Policy is to proactively identify potential risks, evaluate their possible impact on the Company, and implement strategies to minimize the likelihood and severity of adverse events. This includes operational risks such as process failures, system disruptions, or human errors, as well as compliance risks arising from breaches of laws, regulations, or internal policies. By adopting structured risk management practices, the Company aims to protect its assets, reputation, and stakeholders’ interests while ensuring sustainable business continuity.
The Company is committed to implementing appropriate mechanisms, including risk assessment procedures, monitoring systems, and reporting protocols, to effectively manage and mitigate identified risks. Risk management processes are designed to be dynamic, with regular reviews and updates to reflect changes in the business environment, regulatory requirements, or emerging risks. This proactive approach helps in timely detection and mitigation of potential threats, thereby reducing financial, operational, and reputational losses.
All directors, officers, designated employees, and third-party service providers engaged with the Company are required to adhere to this Policy. Each party is expected to actively participate in risk management practices, report potential risk events, and comply with established procedures and controls. The Company emphasizes accountability at every level, ensuring that risk management is not only a centralized function but an integral part of daily operations across all departments.
Ultimately, this Risk Management Policy serves as a cornerstone for the Company’s governance framework, promoting transparency, resilience, and informed decision-making. By fostering a culture of vigilance and preparedness, the Company aims to safeguard its operations, maintain regulatory compliance, and deliver consistent value to its clients and stakeholders.
2. Scope of Risk Disclosure/Management Policy
This Policy applies to all the activities of the Company. It forms part of the Company’s governance framework and it applies to all employees and contractors and third-party service providers.
3. Understanding Risk Management
Risk is the probability of an event occurring that may adversely affect the Company’s objectives. Risk management refers to the structured approach used to identify events that could impact the Company and to implement processes to manage or mitigate their potential adverse effects.
The Company’s risk management system is designed to identify the risks it faces and implement measures to reduce those risks to an acceptable level. Risks may present both threats and opportunities, and the Company aims to balance these effectively.
As noted in point 1 above, risk owners have been assigned responsibility for each identified risk. In doing so, the Company considers the nature, scale, and complexity of its business operations.
The risk management process consists of the following main elements:
Identify: identify a risk (threats or opportunities) and document the risks captured by the risk register owner. Assess: the primary goal is to document the net effect of all identified threats and opportunities, by assessing:
- Likelihood of threats and opportunities (risks);
- Impact of each risk;
- Proximity of threats; and
- Prioritisation based on scales.
Communicate: provide regular reports to Board of Directors or senior management team on an annual basis Plan: preparation of management responses to mitigate threats and maximise opportunities. Implement: risk responses are actioned based on any findings or recommendations Monitor and review: monitor and review the performance of the risk management system based on the Business Risk Assessment and risk profiles of clients.
4. Risk Governance The Company has a well-established risk governance structure that facilitates the identification and escalation of risks while providing assurance to its Board of Directors (the “Board”). This structure is reinforced by an active and engaged Board.
The Company’s risk management governance framework begins with oversight by the Board, ensuring that all decision-making aligns with the Board’s approved risk appetite. Competent staff are responsible for translating the Board’s high-level guidance into operational practices, monitoring their implementation, and reporting periodically back to the Board.
The aggregate enterprise-wide risk profile and portfolio risk appetite are reviewed and discussed at the relevant risk management forums on an annual basis.
5. Risk Governance Structure
The Company adopts the ‘three-lines-of-defense’ model, a widely recognized framework for risk management that ensures comprehensive oversight and accountability at all organizational levels. Under this model, the first line of defense consists of operational management and staff, who are directly responsible for identifying, assessing, and managing risks within their day-to-day activities. This ensures that risk ownership is embedded throughout the operational processes of the Company, promoting a proactive approach to risk mitigation.
The second line of defense is formed by the risk management and compliance functions, which provide guidance, oversight, and support to the first line. These functions develop risk management policies, monitor adherence to regulatory requirements, and ensure that appropriate controls are in place to manage risks effectively. They act as a check on operational activities, facilitating early detection of potential issues and advising on risk response strategies.
The third line of defense is the internal audit function, which provides independent assurance to the Board of Directors and senior management. Internal audit evaluates the effectiveness of the first and second lines of defense, examines the adequacy of governance structures, and assesses whether systems and controls are operating as intended. This independent oversight ensures that risks are not only identified and managed but also continuously monitored and improved upon.
By implementing the three-lines-of-defense model, the Company aligns its risk management framework with regulatory expectations and industry best practices. This structured approach strengthens corporate governance, enhances the effectiveness of systems and controls, and ensures that risk awareness and accountability are ingrained at every level of the organization, supporting sustainable decision-making and long-term resilience.
Table 1: Risk Governance Structure
| Details | Key Responsibilities | |
|---|---|---|
| (i) Board of Directors | Executive and independent/non-executive directors | - Approves the risk management framework and policies - Oversees overall risk governance - Ensures alignment with ethical and sound business practices |
| (ii) Compliance Functions | Compliance Officer, internal team, and relevant staff | - Ensures adherence to legal and regulatory requirements (e.g., AML/CFT) - Provides compliance training and guidance - Monitors day-to-day legal obligations |
| (iii) Independent Audit | Internal or external audit providers (outsourced where applicable) | - Provides independent assessment of risk controls - Recommends improvements to risk management processes and internal controls |
6. Risk Management Framework
The risk management framework is supported by a variety of risk management tools, which are regularly reviewed and updated to ensure consistency with risk-taking activities and relevance to the business strategies of the Company:
Policies and Limits
Policies related to specific types of risk or activities are used to manage risk exposure. Policy developments incorporate recommendations of risk management, internal audit, business units and senior executive management, industry best practices and regulatory requirements.
Prudential limits and tolerances are set as a prudent approach to manage risks. Limit setting establish accountability for key activities within the risk-taking activities and establish the conditions under which transactions may be approved or executed. The Board approves all the risk management policies, each of which defines clear accountability and ownership. The Compliance Officer and designated staff are responsible and accountable for the effective implementation of these policies, ongoing-monitoring and adherence to the Company’s defined risk appetite. The Board retains ultimate oversight of the risk management policies even though the daily responsibilities are delegated to the Compliance Officer and relevant staff.
The risk management policies are designed based on the following principles -
(i) Accountability and ownership (ii) Effective management (iii) Clarity on purpose (iv) Alignment with risk appetite
7. Risk Management Organisation
Risk Management Objectives
The Board of the Company places great emphasis on risk management. The Company constantly enhances i ts risk management practice as a way to strengthen its competitive advantage. The objectives of its risk management are not only to passively control the expected and unexpected losses of the business but also to actively increase the risk-adjusted return on capital. To utilize the capital more efficiently, the Company allocates capital in line with its defined risk appetite, taking into account the availability of liquid capital and the financial goals and market volatility.
Risk Management Organization
The Board is responsible for the Company’s overall risk management strategies and for approving the risk management framework and policies. The Board oversees all risk management matters. The Compliance department is responsible for providing guidance and training, as well as timely update of relevant laws and regulations. It is also responsible for supervising the periodic self-assessment of legal compliance among all units of the Company. Ultimately it is the responsibility of the Board to ensure adequate policies and processes are in place to manage and mitigate any risk.
Employees should abide by risk management related policies and procedures, and promptly report any exceptional case and the potential impact thereof on the Company to the Board or Senior Management.
8. Risk Categories
Table 2: Risk Categories
| Key Risk | Arising From | Measurement, monitoring and management of risk |
|---|---|---|
| Operational Risk | ||
| Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events. | Operational risk arises from human error, inappropriate conduct, failures in systems, processes, or controls, as well as from natural and man-made disasters. It is inherent in all products, activities, processes, and systems, and can occur in all business and support areas. | Operational risk is: (i) Measured using the risk and control assessment process, which enables the identification and evaluation of risks as well as the effectiveness of controls; (ii) Monitored through regular risk assessment procedures, key risk indicators, and the internal loss database; and (iii) Managed through a strong control environment, supported by robust operational risk policies, processes, and systems, as well as an appropriate risk culture within the organisation, all of which contribute to maintaining a low operational loss experience over the years. |
| Liquidity Risk | ||
| Liquidity risk is the inability to meet contractual and contingent financial obligations, on‐ and offbalance sheet as they may come due. Our primary liquidity objective is to provide adequate funding for our business throughout market cycles, including periods of financial stress. | Liquidity risk arises from mismatches in the timing of cash flows. Funding risk arises when the liquidity needed to fund illiquid asset positions cannot be obtained at the expected terms and when required. | Liquidity and funding risk is: (i) Measured using internal metrics, including stressed cash flow projections, coverage ratios, and advances-to-core-funding ratios; and (ii) Monitored in accordance with the Company’s liquidity and funding risk framework, with oversight provided by the Asset and Liability Committees of the respective entities and the Board. |
| Business Risk Assessment | ||
| The Company must, under Section 17(1) of the FIAMLA identify, assess, understand and monitor that person’s AML/CFT risks | During business operations, Management, Compliance, and Risk Management should collaborate closely to conduct the Business Risk Assessment | (i) take appropriate steps to identify, assess, and understand the money laundering and terrorism financing risks associated with customers, countries or geographic areas, and products, services, transactions, or delivery channels; and (ii) consider all relevant risk factors when determining the overall level of risk and the corresponding level and type of mitigation measures to be applied. |
9. Risk Reporting
Risks shall be monitored and controlled on an ongoing basis as an integral part of the risk management process. Ultimate responsibility for this lies with the Compliance Officer and competent staff, who shall ensure monitoring at appropriate levels and report to the Board annually, or sooner if triggered by specific factors, through the Compliance Report. At each level, risk criteria shall be regularly reviewed and assessed in light of changes affecting the risk, updates to risk scores, or progress in implementing mitigating actions. These elements are revisited continuously to ensure effective control.
Reporting arrangements provide an additional layer of oversight. The Board may receive high-level risk updates periodically, summarizing the status of risks and highlighting any significant changes. Risks will also be monitored and controlled through the Company’s planning processes, with each functional unit tracking relevant risk criteria as part of its established management procedures.
10. Statement on Risk Appetite
Risk appetite is the expression and allocation of the level of risk the Company is willing to accept in pursuit of its strategic objectives. Risk bearing capacity reflects the Company’s ability to assume risk, considering available capital, the capacity to raise additional capital, the robustness of operational processes, and the strength of its organizational culture.
The Company maintains a comprehensive Risk Appetite Framework, which provides a structured foundation for setting and managing risk appetite across all business areas. This framework supports the identification, measurement, and control of risk through a suite of policies, processes, controls, and systems. It ensures that the level of risk the Company is willing to assume aligns with its overall risk profile.
By providing a common framework and a consistent set of risk appetite measures, supported by management-level limits and controls, the framework enables the Board to clearly articulate and monitor the Company’s acceptable risk levels.
The framework is guided by the following strategic risk objectives:
(i) early identification and control of all types of possible risks; (ii) maintaining adequate Company-side capital under stressed conditions to absorb losses, if any; and (iii) promoting stability of earnings to avoid unexpected losses.
11. Risk in CFDs trading
The Risk Disclosure and Warning Notice also provides, on a fair and non-misleading basis, a general description of the risks associated with trading Contracts for Difference (“CFDs”).
Clients should not engage in CFD trading unless they fully understand the nature of the risks involved. It should be noted that this Risk Disclosure Document cannot set out all potential risks or factors relevant to CFD trading, nor can it explain how such risks may apply to the personal circumstances of each individual client. Clients must therefore ensure that any decision to trade is made on an informed basis. Independent professional advice should be sought where necessary before commencing trading.
This document is provided solely for informational purposes and does not constitute marketing material or a solicitation to engage in any investment activity.
The Risk Disclosure Document should be read together with the Client Agreement and the General Business Terms, which are available on the Company’s website.
12. Risk Acknowledgement for Trading
The Client understands and acknowledges that investments in leveraged foreign exchange transactions and financial instruments are speculative, involve a high degree of risk and are appropriate only for Client’s who can assume the risk of loss of their margin deposit and/or all funds invested. The Client understands that price changes in foreign exchange contracts trading may result in the loss of all or part of funds. The Client warrants that Client is willing and able, financially and/or otherwise to assume the risk of trading, and in consideration of the Company carrying the Client’s account(s), the Client agrees not to hold the Company responsible for losses incurred through the Client’s trading or through Client following any sort of trading recommendation or suggestion of Company’s employees, agents or representatives.
The Client acknowledges that Client has received no guarantees from the Company or from any of its employees, directors, officers, representatives or any introducer or entity with whom Client is conducting the account and has not entered into this Agreement in consideration of or in reliance upon any such guarantees or similar representations.
13. Main risks associated with transactions in CFDs
Leverage in CFD transaction enables clients to gain exposure to an underlying asset with a smaller initial investment, known as margin.
While leverage can be a powerful tool, it is often described as a double-edged sword. This is because even small market movements can significantly magnify both profits and losses. If the market moves against a client’s position, substantial losses may occur. However, retail clients cannot lose more than the balance of their trading account(s), as the Company provides negative balance protection.
Before engaging in margin trading, clients should carefully consider their financial situation and ensure that they only invest funds they can afford to lose.
14. Trading Platforms
All client instructions are transmitted to our server and executed sequentially. Accordingly, a client cannot place a new order until the previous one has been executed. Any second order submitted before the first has been processed will be automatically rejected. Clients are solely responsible for any unintended trading activity that may result from resubmitting an order before receiving confirmation of the outcome of the initial order.
Clients should note that closing the order or position window does not cancel an order that has already been submitted.
Furthermore, clients acknowledge that only the quotes provided by our server are deemed valid. In the event of a connection issue between the client terminal and our server, clients may retrieve any undelivered quote data from the terminal’s quote database.
15. Force Majeure Events
The Company shall not be held liable for any financial losses arising from force majeure events. Force majeure refers to extraordinary and unavoidable circumstances beyond the control of the parties to this Policy, which cannot be reasonably foreseen, prevented, or mitigated. Such events include, but are not limited to: natural disasters, fires, industrial or man-made accidents, utility failures or emergencies, distributed denial-of-service (DDoS) attacks, riots, military actions, terrorist attacks, uprisings, civil unrest, strikes, and regulatory acts or decisions of state or local governmental authorities.
16. Slippage
Slippage is the difference between the expected price of a trade and the actual price at which the trade is executed. It occurs when the requested price has shifted, meaning the order is opened at a different price than originally intended.
Slippage can occur at any time, but it is most common during periods of high market volatility. It does not inherently represent a negative or positive outcome—any variation between the intended execution price and the final execution price qualifies as slippage.
Slippage can be categorized as:
- Positive slippage – the trade is executed at a better price than requested.
- No slippage – the trade is executed at the requested price.
- Negative slippage – the trade is executed at a worse price than requested.
For example, a market order may be filled at a more or less favourable price than initially intended when slippage occurs.
17. Risks associated with the laws of individual governments
Clients assume responsibility for trading and non-trading operations performed within countries where they are restricted or prohibited by law.
18. No Investment Advice
The Company provides services strictly on an execution-only basis. We do not provide investment, financial, tax, legal or regulatory advice. Any information provided by the Company (including market news, research, commentary or analysis) is general information only and does not consider your financial situation, objectives or risk profile. You are solely responsible for your trading decisions. If you require advice, you must seek independent professional assistance.
19. Final Warning and Acknowledgment
By applying for a trading account with the Company and by entering into any transaction, you expressly acknowledge, confirm, and agree that:
- you have carefully read, understood, and accepted the entirety of this Risk Disclosure Statement;
- you fully understand the nature, characteristics, and risks of CFDs, FX contracts, leveraged products, and any other instruments offered by the Company;
- you understand that trading leveraged products involves a high level of risk and may result in losses exceeding your initial deposit;
- you have independently assessed and evaluated the risks involved, without relying on any representation, recommendation, or advice from the Company;
- you have the necessary knowledge, experience, financial resources, and risk appetite to trade such products; you are solely responsible for monitoring your positions, maintaining adequate margin at all times, and managing your trading activity;
- you assume full responsibility for all trading decisions, outcomes, and losses, whether arising from market movements, platform performance, execution speed, or any other factor;
- you will seek independent professional advice where you do not fully understand any aspect of the risks involved or the functioning of the financial instruments.
If you are uncertain about any part of this Risk Disclosure or the risks associated with trading CFDs or FX, you must not trade until you have obtained independent financial, legal, tax, or investment advice.
20. Review and approval
This Policy is approved by the Board of Directors and reviewed whenever there are changes to legislation or guidelines issued by the FSC.
