Risk Management
Effective Risk and Crisis Management
We regard Enterprise Risk Management as an integral part of the responsibilities of all our employees and aim to make it one of the fundamental elements of our decisionmaking mechanisms by integrating it into all our activities and processes.
Our Board of Directors is ultimately responsible for the effectiveness of our Enterprise Risk Management. Under the supervision of our Board of Directors, we evaluate and monitor the risks and opportunities faced by our Group in alignment with our Group strategies. We support the Board of Directors in fulfilling its oversight responsibilities through the Early Identification and Management of Risks Committee.
Our Early Identification and Management of Risks Committee ensures the necessary coordination among Affiliates, the Enterprise Risk Presidency, executive units and the Internal Audit Presidency in order to ensure the effective management of potential risks and opportunities. The Committee carries out the duties of establishing, maintaining and, where necessary, improving our Enterprise Risk Management System in order to identify all potential risks that may endanger the existence, growth and continuity of our Company and to eliminate the risks identified. During the year, our Committee held two meetings to ensure the regular review of identified risks and to inform our Board of Directors about significant risks. Our Enterprise Risk Presidency operates directly under our Chief Executive Officer and conducts coordinated activities with our Early Identification and Management of Risks Committee operating under the Board of Directors. It undertakes the duties of determining and improving the standards related to our Enterprise Risk Management System, coordinating risk management processes across the Group, and reporting the status and developments regarding identified risks to the relevant management levels.
While our business units assume ownership of their own risks and take the necessary measures, our understanding of risk management ensures that it becomes a natural part of the business processes of all our employees. All our employees are responsible for complying with the risk management policy, effectively managing the risks within their areas of responsibility and taking the necessary measures to ensure compliance with legal regulations. The risk management processes of our Group Companies are also conducted in parallel with the risk management standards we have established for Türk Telekom as the parent company.
We actively contribute to our Enterprise Risk Management and Internal Control practices across all organisational levels of our Group, particularly senior management and risk owners. Through our Internal Control Policy, we define our internal control objectives within our Group, structure our corporate control environment and establish the foundation of our control culture. Our Internal Control Standards, which complement the policy, are used as a guideline in order to define our internal control practices, determine the standards required to achieve the objectives set out in the policy and ensure consistency of practice through a common internal control language among our employees.

Internal Control Structure
As Türk Telekom, while achieving our strategic objectives, we adopt as a fundamental principle: enhancing the effectiveness and efficiency of operational processes, ensuring the accuracy and reliability of our financial data, protecting the personal data of our customers with high security standards and managing our corporate assets in a sustainable manner. In this context, we aim to conduct our activities in a secure, transparent and sustainable manner by establishing a holistic internal control structure based on legal regulations and internal policies and procedures.
We adopt a risk-focused approach at every stage of our business processes, from design to implementation. Through the control mechanisms integrated into our processes, we ensure that potential risks are foreseeable, and in cases where their occurrence is possible, we activate our action plans in order to minimise their impacts. Within this scope, we regularly review existing controls together with relevant stakeholders and monitor their effectiveness through control owners.
Our Internal Control Vice Presidency contributes to strengthening corporate control points and ensuring the effective operation of processes by coordinating relevant control activities holistically.
Our integrated Governance, Risk & Compliance (GRC) platform, to which we transfer all control records and findings related to previous periods, enables us to carry out the monitoring of existing controls, findings and actions in a more systematic and traceable structure. In the coming period, we aim to plan, manage, report and track actions for all our internal control activities through this platform. Through this approach, we plan to increase standardisation in control processes and to make our monitoring and improvement activities more efficient, therefore strengthening operational efficiency. Our processes developed within the scope of four fundamental risk management options are as follows:
• Identification, Assessment and Monitoring of Risks
• Accept the Risk
• Mitigate the Risk
• Transfer (Share) the Risk
• Avoid the Risk
Identification, Assessment and Monitoring of Risks
We continue our efforts with diligence to ensure the effective and holistic management of our potential risks. Within this scope, we identify the risks faced by our Group through Risk Identification and Assessment meetings. We classify the risks we identify under three main categories: Financial, Strategic and Operational Risks, and analyse in detail the potential short-, medium- and long-term consequences of these risks. At the table, the financial and operational impacts related to the potential occurrence of risks are classified in alignment with the Company’s strategy and business plans.
We measure current risk levels by assessing the likelihood of risks occurring and their potential impact should they occur. During the risk analysis process, we conduct a comprehensive assessment by considering that a risk may have impacts in more than one area.
We evaluate the risks that we identify and analyse through the relevant units and prioritise them with the participation of our senior management. As a result of this process, we determine risk owners for each risk and develop action plans aimed at managing or completely eliminating the risks. While developing our action plans, we conduct detailed root cause analyses in cooperation with the relevant units and our Enterprise Risk Presidency.
When deciding to manage a risk, risk owners conduct cost–benefit analyses and consider the expectations of all stakeholders. With this approach, we aim to develop strategies aligned with our risk appetite by maintaining the balance between risks and returns in order to achieve our objectives. In addition, we also evaluate whether specialised expertise outside our business units is required for the management of such risks. We regularly review the effectiveness of the controls and action plans we implement and continuously monitor the current status of risks. The results of the monitoring and reporting of risks are regularly presented to senior management and the Board of Directors through the relevant management levels.
Strategic Risks at Türk Telekom
We operate in a sector where technological transformations, intense competition and changes in regulations occur continuously. In this context, we closely monitor the dynamics of the sector and carefully follow technological developments in the market and changing customer expectations.
In order to increase our company revenues and ensure customer satisfaction, we implement proactive risk management practices in line with our strategic priorities. By utilising information and communication technologies, we offer innovative solutions for individuals and the public sector. By bringing the newest and most advanced communication technologies to Türkiye, we assume a pioneering role in many areas within the sector.
We address our strategic risk assessment process in a holistic manner across areas such as Sustainability Risk, Fraud Risk, Reputational Risk and Sectorial Regulatory Compliance Risk. Within the scope of Programme/Project Management Risk, we systematically assess risks related to human rights, including employee rights, before initiating new projects. In addition, through the human rights due diligence processes we conduct within the framework of Sustainability Risk, we regularly monitor and implement labour standards such as occupational health and safety, working hours and non-discrimination in our existing operations.
We do not limit the human rights assessments we conduct in direct connection with Reputational Risk to our employees alone, but address them in a way that also covers broader stakeholder groups such as our suppliers and local communities. We include fundamental labour rights such as harassment, discrimination, forced labour, child labour and occupational health and safety within our assessments. In particular, we evaluate issues such as forced labour and workplace harassment within the scope of Fraud Risk and take the necessary measures against these risks.
In order to achieve our future strategic objectives, we adopt risk management tools and models that will protect our brand value. Furthermore, these tools turn our competitive advantages into opportunities by establishing the infrastructure required for high-performance products and technologies. At the same time, thanks to the structure we have strengthened through our affiliates, we compensate for potential losses in market share arising from regulatory changes or fundamental transformations in the market with new products and services. This structure helps us continue to evaluate opportunities both domestically and internationally.
Sustainability-Related Risks
We aim to integrate sustainability principles into our business model, strategies and corporate decisions with the goal of leaving a liveable world for future generations. The communications and telecommunications sector directly contributes to the Global Sustainable Development Goals by providing fundamental solution tools in many areas such as the economy, innovation, health, education, social equality, environmental protection and the fight against the climate crisis and we consider sustainability not only as a risk management element but also as an opportunity for value creation. In line with our Sustainability Policy, we address sustainability-related risks and opportunities in a holistic manner. By conducting root cause analyses for sustainability risks, we aim to manage risks focused on Climate Change and Environment, Contribution to Society and Value for People more effectively. In addition, in line with TSRS requirements, we analyse climate-related risks and opportunities that may arise within our value chain. Within this scope, we regularly evaluate environmental impacts arising from the supply chain.
We consider climate change as both a commercial risk and an opportunity area for our operations and business model. Within the scope of the analyses, we conduct in line with the TCFD approach, we evaluate the potential impacts of extreme weather events, regulatory changes in market expectations on our operations and financial performance, and integrate the outputs obtained into our business strategies. In this context, while managing the risks created by climate change, we aim to create new commercial opportunities by developing innovative products and services aimed at energy efficiency, digital infrastructure optimisation and reducing resource use. Within the scope of our TSRS-compliant climate-related risk management approach, we regularly evaluate our assets and operations that may be exposed to transition and physical climate risks. Through scenario analyses conducted on our base stations, network infrastructure, data centres and operational facilities, we analyse the financial impacts of the relevant risks and integrate the results obtained into our investment plans and risk management processes.

Operational Risks at Türk Telekom
The effective management of our operational risks is of great importance due to the fact that we provide services based on technology infrastructure. We define operational risks as risks that may affect our communication infrastructure and critical systems and, consequently, the continuity of the services we provide to our subscribers. Accordingly, operational risks include risks arising from our business processes, employees and systems, as well as those resulting from natural disasters, power outages and other external events. In line with our Business Continuity Management, we aim to protect our Company’s internal and external stakeholders, reputation and brand value by identifying potential risks and the impacts of these risks on our operations. Through the Business Continuity Plans, General Disaster Management Plan and Crisis Management Plan that we have established, we ensure rapid and effective response in possible disaster and crisis situations. We subject critical products and services to our Business Impact Analysis and Risk Assessment processes and carry out the necessary improvements by monitoring performance in line with our continuity objectives. We organise training programmes in order to increase the knowledge and awareness of our employees regarding operational risks. In 2025, the online Business Continuity e-learning training assigned to 17,288 employees were completed by 14,473 employees and the completion rate was 84%.
We manage potential threats and security vulnerabilities that may arise within our digital infrastructures through a holistic approach within the scope of cybersecurity risks. By considering the impacts of increasing cyber threats driven by advancing technology on the confidentiality, integrity and availability of information, we implement detective and preventive control mechanisms to ensure that these risks do not prevent us from achieving our strategic objectives.
Considering the potential of cyber-attacks to lead to service interruptions, financial losses, data breaches and reputational damage, we conduct our activities within the framework of our security policies. Through early warning systems, we continuously analyse potential threats and aim to minimise the impacts of possible incidents on our operations, customer experience and legal obligations. In order to protect our Company and our subscribers against service disruptions and security breaches, we implement international best practices, standards and policies. We ensure the effective management of all our Information Technologies and Network operations through certifications obtained within the scope of ISO 27001 Information Security Management System, ISO 22301 Business Continuity Management System and PCI DSS (Payment Card Industry Data Security Standard).
Due to the nature of our sector, we work with a limited number of suppliers that produce high technology. For this reason, we conduct our procurement processes by also considering risks arising from our suppliers and subcontractors. By considering potential risks related to product and service quality, customer satisfaction, security or business continuity within the supply chain, we evaluate factors such as Total Cost of Ownership (TCO), supply chain risks and sustainability.
We carry out various studies in order to make potential risks and opportunities more visible and measurable, develop appropriate risk mitigation strategies and increase the overall efficiency and resilience of our business processes. Within this scope, we quantitatively calculate the potential financial impacts of risks under the headings of “Supply Chain Risk” and “Information Security and Cyber Risk”. In the coming years, we aim to calculate the financial equivalents of other risk headings as well.
We conduct all our Information Technologies and Network operations within the framework of our security policies and keep them under control through early warning systems that we have established by continuously analysing potential threats. In order to protect ourselves and our subscribers against service interruptions and security breaches, we implement best practices, standards and policies.
Fraud Risk Assessment
Within the scope of Enterprise Risk Management, we regularly assess “Misconduct and Fraud Risks”, which include risks related to corruption, irregularities and conflicts of interest. In our Risk Identification and Assessment studies, we address misconduct and fraud risks under the category of operational risks. During this process, we determine risk owners and develop action plans aimed at managing and mitigating these risks. Our Internal Audit and Ethics and Compliance units support this process through audit, reporting and whistleblowing mechanisms.
Risk Assessment Regarding Labour Standards
We implement human rights risk assessments covering the labour rights of our employees in our existing operations and new projects in line with our Human Rights Policy. In our assessment, we address working hours, discrimination, workplace harassment, forced labour, child labour and occupational health and safety as priority risk areas.
This approach directly corresponds with the risk categories of Sustainability, Reputational, Misconduct, Talent Retention and Programme/ Project Management. We believe that establishing fair, safe and respectful working conditions in the workplace strengthens employee engagement, increases corporate credibility and contributes to the responsible implementation of new projects. In this context, we aim to develop an employee-focused risk management culture.
Business Continuity Management
As a company providing Information and Communication Technologies (ICT) services to more than 56 million customers, we are aware of the importance of the continuity of the services we provide for society, the public sector, the economy and individuals. With this awareness, we implement end-to-end Business Continuity Management in line with the roles and responsibilities defined within the scope of our Business Continuity Policy, which we have established by taking international standards and best practices as reference.
Our Business Continuity Management activities are addressed in a holistic manner, covering human-related risks, natural disasters and all other threats, and including operational interventions following interruptions and actions aimed at reducing potential risks. At the highest level of this structure is the Business Continuity Committee, which is responsible for strategically directing and supervising Business Continuity processes. Through our Business Continuity approach shaped in line with the risk appetite and risk tolerance levels determined by our Board of Directors, we ensure the continuity of communication, which carries the nature of a public service.
The main activities we carry out within the scope of Business Continuity Management are as follows:
• Business interruption risk analyses
• Scenario analyses and scenario-based action planning
• Business Impact Analyses
• Improvement of risk mitigation and control environments
• Studies conducted with universities, public institutions, municipalities and companies that provide solutions for risk identification
• Service continuity resource planning, management and monitoring
• Establishment of Business Continuity Policies, Procedures and Plans
• Preparation of region-based Disaster Management Plans
• Testing and exercise activities
• Training and awareness activities
• Incident and Crisis Management processes
• Post-incident improvement activities
By adopting international best practices in Business Continuity Management, we successfully completed the compliance and assessment processes in 2021 within the scope of the Resilient Enterprise Assessment Program (REAP) developed by DRII. In line with our existing practices and competencies, we have been accredited as a Resilient Organisation by DRII and hold the distinction of being the first and only telecommunications company in the world to receive this accreditation.
In addition, within the scope of the ISO 22301 Business Continuity Management System certificates we hold for Türk Telekomünikasyon A.Ş. and TT Mobil A.Ş., we effectively operate all our management system processes.
Financial Risk Management
We are aware that maintaining our financial stability and ensuring sustainable growth are of critical importance not only for our Company but also for the trust of all our stakeholders. We demonstrate a strong stance against external factors such as global economic fluctuations, foreign exchange movements and changes in interest rates through our proactive, comprehensive and dynamic financial risk management strategies. By managing financial risks such as liquidity, foreign exchange, interest rate and counterparty risks in the most effective manner, we strengthen our financial health and continue to create long-term value. Türk Telekom may be exposed to financial risks such as liquidity risk, foreign exchange risk, interest rate risk and counterparty risk.
Within the framework of the strategy to minimise liquidity risk, financial borrowings are obtained on a long-term basis from different geographies (America, Canada, Europe, the Gulf, Japan, China, Türkiye) and different creditor groups (commercial banks, international financial institutions, officially supported export financing institutions and bond markets). This strategy enables the Group to access long-term financing under competitive conditions without being dependent on a limited number of funding sources. With respect to the international bonds issued by Türk Telekom, the Group actively monitors the price and yield dynamics of these bonds, which can be traded in the secondary market, in order to ensure an optimum cash management strategy based on total return and cost.
The procurement of a portion of capital expenditure-related supply from foreign companies, and the need to finance such expenditures through long-term and diversified funding sources, arise from Türk Telekom’s foreign currency-denominated liabilities. Accordingly, when hedging transactions are not taken into consideration, Türk Telekom carries net liabilities denominated in foreign currency and may be exposed to foreign exchange rate risks due to fluctuating exchange rates, which may have an impact on the financial statements.
Türk Telekom aims to minimise the impact of interest rate and foreign exchange risks on the financial statements through foreign exchange and interest rate risk management transactions. Within this framework, Türk Telekom holds a total hedging position equivalent to 2,938* million USD, the details of which are included in the notes to the financial statements. Including foreign currency cash held for the purpose of providing a natural hedge against foreign exchange risk, the total hedging position corresponds to 3,043 million USD.
Türk Telekom aims to minimise counterparty risk with respect to its financial assets within the framework of the limits applied to counterparties and diversification policies, and conducts hedging transactions related to its financial risks within the framework of the guidance and authorisations of the Board of Directors.
Counterparty Risk: Strong Financial Safeguard Mechanisms
In order to safeguard our financial assets and minimise counterparty risk, we implement a strong risk management and diversification policy. By determining applicable limits for the financial institutions with which we work, we ensure that risk remains within defined boundaries and reinforce our financial stability.
Our financial risk management is conducted with diligence within the framework of the guidance and authorisations of the Board of Directors. Through our effective and proactive risk management strategies, we establish a strong financial structure against market fluctuations and build our long-term growth objectives on solid foundations.
This comprehensive and strategic approach supports not only our short-term financial performance but also our objective of enhancing our long-term corporate sustainability and the value we provide to our stakeholders.
* Hedged amount includes hedging of FX financial debt, currency protected time deposit, hedging of FX net trade payables and net investment hedge.