IBERSOL Annual Report and Consolidated Accounts 2017

Report on Corporate Governance II. Whistle Blowing Policy 49. Whistle Blowing Policy The values and principles of Ibersol Group, disseminated and rooted in the culture of its collabora- tors, rely in the absolute respect and adoption of good conduct rules in management of conflicts of interests and due diligence duties and confidentiality in relations with third parties. The Company has a policy in place for the receipt of reports, claims or complaints about irregula- rities detected in the Company. As set forth in the Regulations of the Statutory Audit Committee, which are published on the Company’s website, this organ keeps a written record of reports of irregularities that are addressed to it, and, when considered appropriate, takes the necessary steps together with the Board of directors and the auditors, and prepares a report on the irregularities. So, this kind of irregularities may be reported to the Statutory Audit Committee without anony- mity and being reported directly to the Company, by means of its reference to the Statutory Audit Committee. The Company will send the reports received to the Chairman of the Statutory Audit Committee, ensuring confidentiality. During 2017 the Statutory Audit Committee did not receive any reports of irregularities. III. Internal Control and Risk Management 50. Individuals, bodies or committees responsible for internal audit and/ or implementation of internal control systems Ibersol does not have autonomous internal audit and compliance services. Risk management, as part of the company’s culture, is present in all processes and is the responsibility of all managers and employees at the different organization levels. Risk management is undertaken with the goal of creating value by managing and controlling uncertainties and threats that may affect the Group companies, with a view to the continuity of operations, to take advantage of business opportunities. As part of strategic planning are identified and evaluated the risks of the existing businesses portfolio and the development of new businesses and relevant projects and defined those risks management strategies. At the operational level, are identified and evaluated the risks management objectives of each business and planned actions to manage those risks that are included and monitored in the plans of business and functional units. With regard to security risks of tangible assets and people are defined policies and standards, and the self-control of its application is made, being conducted external audits to all units and implemented preventive and corrective actions for the identified risks. In order to ensure compliance of the established procedures is performed regularly assessing of the main in- 164

RkJQdWJsaXNoZXIy NDkzNTY=