OCU Group - Annual Report 2026

Strategic report

Governance

Financial statements

72 OCU Group Annual report and financial statements 2026

Governance continued Driving sustainable growth through strong oversight and accountability

Robust compliance regime

Effective risk management

OCU One: Expanded digital workflows, risk assessments and compliance processes support transparent and consistent governance. Gifts & Hospitality Register: A digital register improved central reporting and oversight. Information security: ISO 27001 certification was extended to six additional locations, strengthening governance of information across the Group. Third-party risk: Dun & Bradstreet Risk & Finance Analytics strengthened due diligence, supplier monitoring and procurement decisions. Environmental governance: ANZ incident processes were enhanced to cover environmental and cultural-heritage considerations. Priorities for FY27 • Achieve certification to ISO 27701, the international standard for privacy information management, further strengthening data protection and privacy governance capabilities. • Roll out emissions monitoring tools across our Australia and New Zealand platform to improve environmental performance measurement, reporting capability and decarbonisation planning. • Continue enhancing governance, compliance and assurance frameworks to support sustainable growth, operational resilience and stakeholder trust across all regions.

Business continuity: OCU strengthened its Business Continuity Management framework, with scenario testing planned for FY27. National Operations Centre: The 24/7 Leeds NOC supports incident response, service co‑ordination and operational resilience. Priorities for FY27 • refresh and relaunch the Group Code of Conduct to reflect evolving stakeholder expectations, regulatory requirements and organisational values; • implement a new third-party onboarding and ongoing monitoring platform to strengthen due diligence, supplier oversight and supply chain risk management; • continue the rollout of a new digitally enabled internal financial control attestation and testing regime leveraging the capabilities of the Optro platform to improve assurance, accountability and governance; • establish an internal audit function to provide independent assessment of governance, risk management and control effectiveness across the Group; and • continue investing in risk management systems, governance structures and specialist

Overview Compliance protects OCU’s people, clients, reputation and licence to operate. The Group maintains a proportionate framework to support responsible international growth. Clear conduct standards, reporting channels, supply chain governance, monitoring and continuous improvement reinforce accountability and resilience. In FY26, OCU continued to develop its compliance systems, governance, assurance and digital oversight in response to regulatory change and a broader footprint. The Group Supplier Code of Conduct sets expectations for ethics, human rights, environmental responsibility and regulatory compliance. Key achievements in FY26 Integrated Management System (IMS): Continued integration improved consistent ways of working, accountability and operational control across the Group. Commercial Conduct refresh: Updated guidance applies consistent ethical and commercial standards across OCU’s international operations. Audit and assurance: Stronger controls, monitoring and digital reporting improve visibility of findings and timely close-out of actions.

Overview Effective risk management protects stakeholder value and supports informed decisions as OCU expands across geographies and capabilities. The Group framework combines governance, digital tools, monitoring and ownership across strategic, operational, financial, regulatory and emerging risks. A two-tier structure led by the Head of Risk and Compliance comprises Board-level Audit & Risk Committee oversight and a monthly cross‑functional Regulatory & Compliance Working Group. Key achievements in FY26 Dedicated risk capability: Further investment through a dedicated Head of Risk and Compliance strengthened specialist oversight. Enterprise risk management: Optro provides a Group-wide platform for risk identification, assessment, monitoring and Board visibility. Conflicts of interest: NAVEX disclosures improved transparency and oversight across the Group. Facilities risk: The expansion of the dedicated Facilities Management function strengthened property oversight and risk control. Cyber security awareness: Simulated phishing campaigns identify training needs and reinforce secure behaviours.

resources to support sustainable growth, organisational resilience and long-term stakeholder value creation.

Powered by