Kenanga Sustainability Report 2023

41 MANAGING OUR KEY ESG RISKS GOOD GOVERNANCE SUSTAINABLE ECONOMIC GROWTH ENVIRONMENTAL STEWARDSHIP EMPOWERING PEOPLE AND COMMUNITIES APPENDIX GOOD GOVERNANCE Group Speak Up Policy and Framework • The Group provides a safe and secure environment for employees, customers and third parties to report their concerns about any misconduct or suspected breach of laws, regulations or internal policies and procedures. • In 2023, the Group enhanced its Group Whistleblowing Policy and replaced it with the Group Speak Up Policy for the reporting of any concerns made in good faith about behaviour, conduct, practice, deeds and/ or omissions that might be either unlawful or inconsistent with the policies of the Group. Kenanga ensures confidentiality and assures its stakeholders and the general public that they can make a report in good faith. • The new Group Speak Up Policy introduces a new Speak Up channel where whistleblower may submit a report to the external independent third party appointed by Kenanga Group. Submission may be done by an email, a dedicated internet platform (e-form) or to a postal mail as stated below: External Report Recipient Website : https://secure.deloittehalo.com/kenangaspeakup Email : [email protected] Postal Box: Kenanga Speak Up (External Report Recipient) PO. Box. No. 8097 Kelana Jaya Post Office 46781 Petaling Jaya Selangor, Malaysia Scan here to learn more about our Group Speak Up Policy and Framework For more information on how we manage our Group’s Ethics and Compliance matters, refer to pages 98 to 110 of our Annual Report 2023. Key Policies, Frameworks and Commitment Statements At Kenanga, we monitor and implement all corporate policies and frameworks to incorporate good governance values throughout the organisation. GOOD GOVERNANCE CYBER SECURITY • Group Code of Ethics and Conduct for Employees • Code of Ethics for Dealer Representatives** • Group Code of Conduct for Vendors* • Group Procurement Policy** • Group Sustainability Policy** • E-Procurement Procedure • Business Continuity Management Framework Policy* • Group Conflict Management Policy • Cyber Security Policy • Data Loss Prevention Framework* • Group Confidential Information Policy* • Retention, Archiving and Destruction Policy* • PDPA Data Access and Retention Procedure • Cyber Security Procedure • Technology Risk Management Framework

RkJQdWJsaXNoZXIy MTc1ODMy