We strive to ensure compliance with our values and commitments by implementing a company-wide compliance programme through our compliance system. The compliance system is embedded in our governance model and is designed to bolster company performance and a culture of integrity at all levels. We follow how this culture is developing with the help of the Integrity Index, which is an average calcu- lated on the basis of favourable responses to integrity-related questions in our annual Employee Engagement Survey (EES). These questions are: 1. I understand the UPMCode of Conduct and ethical standards. 2. If I had to report unethical behaviour or misconduct, I am confident that it would be handled effectively by UPM. 3. UPM operates in an ethical manner and in accordance with the UPMCode of Conduct. Our integrity index figure in 2020 was 87% (86%). Our compliance system places emphasis primarily on preventive actions, which are drawn from the annual risk management cycle and risk assessments conducted for all businesses and operations. Our compliance system and actions within this system are demonstrated in the illustration below.
Risk assessment With the support of our compliance team, each business area, function and unit is responsible for identifying, measuring and managing compliance risks related to its own operations. The results of annual risk assessments and discussions are used to guide compliance activities and mitigation actions. Risk assessments and mitigation actions are updated throughout the year so as to respond to changes in the risk environ- ment. The progress of mitigation actions is reported to the Audit Committee of the Board of Directors and businesses on a quar- terly basis. Policies and procedures Updating our Code of Conduct and cer- tain other focal corporate policies, such as Supplier and Third-Party Code, Anti-Cor- ruption Rules and Confidentiality Rules in 2019, meant that 2020 was a year of renewed training and communication. Training and communication To complement the Code of Conduct e-learning launched in 2019, in 2020 we launched renewed Anti-Corruption, Confi- dentiality and Competition law e-learning and made some updates to our Insider policy e-learning. We also introduced a completely new Supplier and Third-Party Code e-learning for our employees.
% Code of Conduct training
100% coverage of participation in UPM Code of Conduct training (continuous)
99% of active employees completed the UPM Code of Conduct training since September 2019
SIGNIFICANCE • Compliance is an integral part of responsibility, which is one of our strategic focus areas • Compliance helps us to create sustainable business in the long term • Compliance is an important asset in our decision making, management and operations TARGETS • Compliant operations and behaviour • Engaging work environment where employees feel safe to voice their concerns • Responsible value creation OUR WAY • We are all responsible for building a culture of integrity, with everything we do and every choice we make • We do not compromise our standards of integrity under any circumstances • Accountability for compliance extends down from the Board of Directors and senior management to all employees
COMPLIANCE UNDERPINS PERFORMANCE
UPM COMPLIANCE SYSTEM
Company performance Corporate reputation, financial performance, operational excellence
Risk assessment Policies and procedures Preventive controls
Communication Training Proactive advice
Regardless of the location, circumstances or people involved, we are committed to complying with applicable laws and regulations, as well as our Code of Conduct. Our Code of Conduct and our values help us make the right choices and guide our work in a changing business environment. This lays the foundations for long-term success.
Auditing, monitoring and surveys Notification/ reporting channels