Understanding and responding to risks is key to building trust, driving safe and stable operations, realising the full potential of our assets, and establishing a platform to invest and grow with confidence.
Governance of risk management
Risk management is integral to our business activity and is integrated into Group-wide policies with our risk strategy part of executive accountability.
Our Board has oversight accountability for establishing risk appetite and tolerance and ensuring effective risk management practices throughout the organisation. The Board carries out this accountability through the Audit and Risk Committee, which is responsible for reviewing and monitoring assurances of AngloGold Ashanti’s system of internal control.
The Audit and Risk Committee reviews the top principal risks quarterly and considers the relevance of each principal risk factor and the Company’s corresponding level of risk exposure.
An Executive Risk Management Committee was established with the approval of the Audit and Risk Committee in 2025. This committee is responsible for driving the implementation of our risk management framework, prioritises risk management focus and resources, and ensures effective and integrated executive ownership of current and emerging principal risks.
Risk management framework
The Board has ultimate oversight accountability for establishing risk appetite and tolerance and ensuring effective deployment of the risk management framework throughout the organisation.
Our established risk management framework supports our strategy for future growth while ensuring that we manage threats appropriately. Based on ISO 31000, the framework calls for the identification and capturing of risks across the Group. Once identified, risk mitigating or improvement actions are applied with actions tracked to completion.
Monitoring emerging risks
Given our extensive portfolio of operations and geographical diversity, AngloGold Ashanti has a multi-faceted, interconnected risk profile that requires rigorous monitoring to identify emerging risks.
This monitoring involves consulting a range of internal and external sources and covers a multitude of variables such as macro-economic trends, geopolitics, local politics, social trends and future technologies, among others.
Also considered is the likely impact, whether positive or negative, of such variables on our business processes, ability to conduct our business, social licence to operate and supply chain. Emerging risks are considered for elevation into our principal risks, or ongoing monitoring via our watch list.
Identifying opportunities
However, not all risks are threats. Recognising that risk management is as much about realising opportunities as it is about controlling threats, we reframed our development and growth, and resource and reserve risks in 2025 to reflect that these uncertainties also include potentially significant upside. Since the controls that enable the capturing of opportunities are often different from threats, it is important that we identify them and monitor their effectiveness.
For details on our principal risks, refer to the 2025 Annual Report: Principal risks, uncertainties and opportunities.
Risk management framework

Responsible and secure supply chain management
Our commitment to responsible sourcing compels us to go beyond the conventional considerations of cost and quality to investigate the labour, ethics, and environmental practices of our direct and indirect suppliers.
A stringent governance policy informs our global procurement activities, and we expect the same ethical standards from both our operations and suppliers. We expect our suppliers to conduct their business with respect for human rights, and we engage in inclusive procurement practices by collaborating with local businesses and communities, and prioritise employing individuals from communities surrounding our operations.
Suppliers are required to commit to our Supplier Code of Conduct, aligning their businesses with our policies and ethical codes related to human rights, labour relations, employment practices, environmental standards, anti-bribery and corruption policies, and safety procedures.
In 2025, we completed 751 vendor evaluations, representing approximately 76% of our 2025 new vendor onboarding requests.
We actively track and report on the top 50 strategic suppliers from a higher risk perspective and in 2025, we introduced an additional market intelligence supplier risk monitoring process to augment this strategic supplier review process. This additional process includes the supplier risk monitoring of around 600 high-risk suppliers.
Learn more about how we use a ratings methodology to determine supplier risk scores 2025 Sustainability Report: Responsible and secure sourcing and local procurement.
Vendor evaluations undertaken
New vendors evaluated (%)
Top 50 vendors – freedom status summary
Top 50 vendors – cyber risk summary
Managing cybersecurity
Integral to AngloGold Ashanti’s business functions and operations, digital technology serves as a critical enabler for operational efficiency and value delivery, ensuring that we remain competitive and sustainable. However, the ungoverned adoption of technology poses significant risks.
We protect the security and value of our assets through the responsible deployment and use of digital technology and through the integration of cyber safety into our overall safety and security processes. Our Cyber Safety governance framework has been reinforced through alignment with industry best practices, including Sarbanes-Oxley Act controls and frameworks such as Cobit, NIST, COSO, ISO 31000, and ISO 27000.
The complexity of the cyber landscape has also meant we need to continually strengthen our and monitoring. Our internal monitoring is augmented by a 24-hour third-party Security Operations Centre, which ensures real-time monitoring. We have also embedded Cyber Safety standards into all third-party relationships by including a cyber clause in new vendor contracts.
Ethical use of artificial intelligence (AI)
The importance of digital technology governance is increasingly evident with the advent of AI, which carries new risks that can require additional diligence. Unlike other technologies, AI solutions present outcomes that individual users may not fully validate.
AI also possesses the ability to learn from, and further disseminate, data, raising concerns about privacy and data-sharing.
AngloGold Ashanti requires the careful management of AI-based tools and users, who are not permitted to input corporate data, are held accountable for the outputs or impacts of those outputs. We also require the use of AI to be disclosed upfront.
Fake domains & social media scams
As a global organisation, we are aware of fake web domain and social media scams specifically targeting AngloGold Ashanti. These potential threats are under constant monitoring, and we urge the public to inspect any email or web link that may be masked as a fake message and report these using our whistle-blowing platform, www.tip-offs.com
