GOVERNANCE AND STRATEGIC APPROACH

CMPC has high standards of governance oriented towards sustainable management, rooted in the top-level management of the company. It is based on a corporate culture of ethics and compliance with the Corporate Policies and Regulations. We carry out our operations and business transactions in accordance with the best international practices, strictly complying with the laws and regulations of each country where we are present and always respecting the people, their dignity and rights, as well as the environment.

CMPC’s governance is structured around three  levels: the Shareholders’ Meeting, the Board of Directors, and Executive Management. Each has defined authorities, roles, and responsibilities that ensure the company’s effective functioning, direction, and long-term sustainability. This structure is founded on a governance framework developed and implemented in accordance with the applicable laws and regulations of the countries where CMPC operates, as well as the governance principles outlined in its Corporate Governance Policies and Procedures. 

The governance structure is reflected in CMPC’s bylaws, the amendment of which is subject to Law No. 18,046 on Corporations (Ley de Sociedades Anónimas (LSA)) and requires approval by a qualified quorum of shareholders.

The primary role of CMPC’s Board of Directors is to manage and direct the Company. It is composed of nine members, whose duties must be carried out in strict compliance with applicable regulations. Chilean law, through civil legislation and the Law on Corporations (LSA), establishes the standards of conduct and rules of liability associated with fulfilling directors’ fiduciary duties of care and loyalty. Such liability cannot be waived or mitigated by shareholder’s decision or by the company’s bylaws, nor can it be renounced in advance. In this regard, directors act in the best interests of the company and are subject to the highest standards of conduct.

As part of its governance structure, the Board of Directors has established committees, including the Sustainability and Regulatory Committee. Its primary purpose is to directly oversee the implementation of the company’s sustainability strategy across its economic, social, and environmental dimensions, as well as to verify the effective achievement of the objectives and targets set in this regard. The committee may also review and propose the adoption of best practices to further strengthen CMPC’s long-term commitment to sustainable development.

In order to ensure the continuity of the Company’s operations and strategy, the Company has established a succession plan for the Chief Executive Officer and other senior executives. The plan addresses both planned and unplanned departures, including unforeseen absences, leaves of absence, resignations, or any other circumstances resulting in the temporary or permanent removal of the Chief Executive Officer or one or more senior executives from their duties. The succession plan identifies potential candidates who may replace the Chief Executive Officer and establishes the expected timeframe within which such candidates would be ready to assume the position. In any of these circumstances, the following procedure shall apply:

The Board of Directors shall assess whether there are potential candidates among the Company’s executives to replace the Chief Executive Officer in the event of a removal from duties for any reason whatsoever.

Notwithstanding the foregoing and in any event, it shall be the responsibility of the Chief Executive Officer or the relevant senior executive to ensure that the person who habitually replaces him or her in routine situations, such as vacation or illness, is properly trained and informed regarding his or her duties, provided that, in all cases, the confidentiality obligations inherent in the performance of his or her position are not breached.

CMPC has high standards of governance oriented towards sustainable management, rooted in the top-level management of the company. It is based on a corporate culture of ethics and compliance with the Corporate Policies and Regulations. We carry out our operations and business transactions in accordance with the best international practices, strictly complying with the laws and regulations of each country where we are present and always respecting the people, their dignity and rights, as well as the environment.

CMPC’s governance is structured around three  levels: the Shareholders’ Meeting, the Board of Directors, and Executive Management. Each has defined authorities, roles, and responsibilities that ensure the company’s effective functioning, direction, and long-term sustainability. This structure is founded on a governance framework developed and implemented in accordance with the applicable laws and regulations of the countries where CMPC operates, as well as the governance principles outlined in its Corporate Governance Policies and Procedures. 

The governance structure is reflected in CMPC’s bylaws, the amendment of which is subject to Law No. 18,046 on Corporations (Ley de Sociedades Anónimas (LSA)) and requires approval by a qualified quorum of shareholders.

The primary role of CMPC’s Board of Directors is to manage and direct the Company. It is composed of nine members, whose duties must be carried out in strict compliance with applicable regulations. Chilean law, through civil legislation and the Law on Corporations (LSA), establishes the standards of conduct and rules of liability associated with fulfilling directors’ fiduciary duties of care and loyalty. Such liability cannot be waived or mitigated by shareholder’s decision or by the company’s bylaws, nor can it be renounced in advance. In this regard, directors act in the best interests of the company and are subject to the highest standards of conduct.

As part of its governance structure, the Board of Directors has established committees, including the Sustainability and Regulatory Committee. Its primary purpose is to directly oversee the implementation of the company’s sustainability strategy across its economic, social, and environmental dimensions, as well as to verify the effective achievement of the objectives and targets set in this regard. The committee may also review and propose the adoption of best practices to further strengthen CMPC’s long-term commitment to sustainable development.

In order to ensure the continuity of the Company’s operations and strategy, the Company has established a succession plan for the Chief Executive Officer and other senior executives. The plan addresses both planned and unplanned departures, including unforeseen absences, leaves of absence, resignations, or any other circumstances resulting in the temporary or permanent removal of the Chief Executive Officer or one or more senior executives from their duties. The succession plan identifies potential candidates who may replace the Chief Executive Officer and establishes the expected timeframe within which such candidates would be ready to assume the position. In any of these circumstances, the following procedure shall apply:

The Board of Directors shall assess whether there are potential candidates among the Company’s executives to replace the Chief Executive Officer in the event of a removal from duties for any reason whatsoever.

Notwithstanding the foregoing and in any event, it shall be the responsibility of the Chief Executive Officer or the relevant senior executive to ensure that the person who habitually replaces him or her in routine situations, such as vacation or illness, is properly trained and informed regarding his or her duties, provided that, in all cases, the confidentiality obligations inherent in the performance of his or her position are not breached.

INFORMATION SECURITY AND CYBERSECURITY

For CMPC, information security and cybersecurity are essential to ensuring operational continuity and protecting business value. Given their growing importance for the Company and its stakeholders, CMPC maintains a high level of preparedness to prevent and effectively respond to significant information security and cybersecurity incidents. In this context, CMPC is committed to providing transparent information on the principles and commitments that guide the Company’s approach to these matters. At the same time, given the sensitive nature of information security, the Company seeks to ensure that public disclosure does not compromise the effectiveness of security controls, expose sensitive information, or create additional risks to the security and continuity of its operations. To balance these considerations, CMPC developed a Public Information Security and Cybersecurity Commitment, based on the principles and guidelines established in its internal Information Security Policy. This public commitment provides stakeholders with greater visibility into CMPC’s governance framework, key principles and commitments in this area, while appropriately safeguarding sensitive information, systems and technological infrastructure. The Information Security and Cybersecurity Commitment is publicly available at the following link:

Our management approach is based on high standards and seeks to enhance transparency and the public availability of information in this area. To achieve this, we have established a robust governance structure that ensures comprehensive oversight. At the corporate level, the Board of Directors’ Risk, Audit and Compliance Committee is responsible for overseeing cybersecurity risks. As part of its role in the risk management system, this committee regularly reviews the risk matrix, monitors the execution of internal audit plans, ensures compliance with the Compliance Program, and evaluates actions taken in response to cyber threats, ensuring appropriate controls for prevention, detection, and mitigation.

We consider corporate information to be a strategic asset, and its protection is the responsibility of all employees and third parties. Our Comprehensive Information Security Policy, approved in November 2023, sets out the guidelines for safeguarding information and associated technologies throughout their life cycle, ensuring compliance with quality and security standards. Given that the document includes key procedures and technical controls for threat management, it is distributed internally as a preventive measure to protect its effectiveness. This Policy includes, among others, the following essential elements:

 

  • It actively promotes the continuous improvement of the information security management system by constantly assessing emerging threats and adapting our defense capabilities. This practice aims to reduce risks, optimize costs, and improve the efficiency and effectiveness of information systems.
  • We are committed to protecting information against unauthorized access (confidentiality), intentional or accidental alterations (integrity), and disruptions that prevent its use (availability). Control measures are implemented at every stage of the information life cycle, prioritizing classification and protection to prevent disclosure or manipulation by unauthorized individuals.
  • The Policy defines specialized instances responsible for monitoring and managing information security incidents. These functions follow established procedures that include protocols for detection, response, mitigation, and reporting, ensuring timely and coordinated reactions to potential threats.
  • Information security responsibilities are clearly defined and mandatory for everyone at CMPC, regardless of their role, function, or geographic location. From the Technology, Digitalization, and Cybersecurity Committee to end users, the entire organization must adhere to the Policy’s guidelines. Employees are also expected to promptly report any suspicious behavior or activity that could pose a threat to information security. Key roles such as Corporate and IT Security Officers, along with the Human Resources department, have specific duties to ensure proper implementation, monitoring, and compliance.

 

This Policy also extends to third parties, such as suppliers, contractors, and supply chain actors, who must protect any information accessed during the provision of their services. They are required to comply with CMPC’s defined security standards. The Procurement area ensures that evaluation and contracting processes include security controls as contractual requirements, mitigating risks in external relationships and protecting shared systems and data.

Active Information Security and Cybersecurity Management

CMPC maintains an enterprise-wide Information Security and Cybersecurity program to safeguard business operations, protect critical information assets, and enhance resilience against evolving cyber threats. The program is embedded in the Company’s risk management framework and operates under a governance model that includes executive oversight and periodic reporting to the Board of Directors through the Risk, Audit and Compliance Committee.

The design, implementation, and ongoing enhancement of cybersecurity controls are guided by internationally recognized standards and frameworks, including ISO/IEC 27001, ISO 27002, the NIST Cybersecurity Framework (CSF), CIS Critical Security Controls, ISA/IEC 62443 for industrial cybersecurity, and other applicable sector-specific good practices. These references support the capabilities required to identify, protect, detect, respond to, and recover from cyber risks across the organization.


CMPC’s cybersecurity capabilities are built on a balanced approach across people, processes, and technology. The Company has specialized teams with defined responsibilities in information technology, operational technology, cyber operations, identity protection, risk management, and incident response. These teams are supported by leading cybersecurity technologies, formalized processes, and continuous improvement practices that reinforce prevention, detection, response, and recovery across the organization.

CMPC applies a risk-based cybersecurity approach that includes periodic assessments of technology, information, operational, and third-party risks. These risks are integrated into the corporate risk management process and regularly evaluated to inform decision-making, investment prioritization, and improvement initiatives. The Company complements these activities with internal audits, independent external assessments, control effectiveness reviews, vulnerability evaluations, and remediation programs aimed at strengthening its security posture and operational resilience. During 2024, CMPC conducted both internal and external audits of its information security and technology management systems, verifying compliance with applicable standards and controls. The Corporate Information Technology Department coordinates with business units and subsidiaries to implement contingency plans that ensure operational continuity and information availability in the event of critical incidents. These units are required to maintain and regularly test their Business Continuity Plans (BCP), identifying key processes and resources. In addition, CMPC performs continuous vulnerability monitoring across systems, networks, and applications to anticipate threats and enhance proactive risk management. During fiscal year 2025, CMPC maintained active monitoring and management of information security and cybersecurity risks through its corporate cybersecurity program. The Company did not experience any material information security incidents with a significant impact on business continuity, financial results, customers, employees, or critical operations.

Recognizing the strategic importance of Operational Technology (OT) and Industrial Control Systems (ICS), CMPC maintains a dedicated Industrial Cybersecurity program to protect critical manufacturing, logistics, and production environments. Aligned with ISA/IEC 62443 principles, the program incorporates cybersecurity risk assessments, asset visibility, network segmentation, secure remote access controls, vulnerability management, cybersecurity monitoring, incident response capabilities, and resilience testing. These practices help safeguard the security, reliability, and continuity of industrial operations while reducing exposure to cyber threats affecting critical infrastructure.

Given the growing relevance of identity-based threats, CMPC places particular emphasis on identity protection and digital access management as core components of its cybersecurity strategy. This includes governance over user access, privileged access management, authentication controls, periodic access reviews, and monitoring of identity-related risks to reduce unauthorized access and protect critical systems, data, and operations.
To strengthen preparedness and response, CMPC operates continuous monitoring processes across its technology environments, supporting timely identification and management of vulnerabilities, cyber threats, and security events. Incident management processes, business continuity plans, disaster recovery capabilities, and crisis response procedures are periodically reviewed and tested to reinforce resilience and operational continuity.

CMPC also recognizes cybersecurity as a shared responsibility across the organization and its value chain. Employees receive mandatory cybersecurity awareness training and are expected to promptly report incidents, suspicious activities, or potential security weaknesses. Cybersecurity requirements are also embedded in supplier and third-party management processes through security assessments, contractual controls, and risk-based oversight to help protect information, systems, and interconnected operations. The Internal Audit department contributes to the design, implementation, and evaluation of the system, strengthening the comprehensive management of information security.

Through strong governance, risk management, auditing, training, operational controls, and continuous improvement, CMPC continues to strengthen cyber resilience, protect stakeholder trust, and support the secure and sustainable development of its global operations.

For CMPC, information security and cybersecurity are essential to ensuring operational continuity and protecting business value. Given their growing importance for the Company and its stakeholders, CMPC maintains a high level of preparedness to prevent and effectively respond to significant information security and cybersecurity incidents. In this context, CMPC is committed to providing transparent information on the principles and commitments that guide the Company’s approach to these matters. At the same time, given the sensitive nature of information security, the Company seeks to ensure that public disclosure does not compromise the effectiveness of security controls, expose sensitive information, or create additional risks to the security and continuity of its operations. To balance these considerations, CMPC developed a Public Information Security and Cybersecurity Commitment, based on the principles and guidelines established in its internal Information Security Policy. This public commitment provides stakeholders with greater visibility into CMPC’s governance framework, key principles and commitments in this area, while appropriately safeguarding sensitive information, systems and technological infrastructure. The Information Security and Cybersecurity Commitment is publicly available at the following link:

Our management approach is based on high standards and seeks to enhance transparency and the public availability of information in this area. To achieve this, we have established a robust governance structure that ensures comprehensive oversight. At the corporate level, the Board of Directors’ Risk, Audit and Compliance Committee is responsible for overseeing cybersecurity risks. As part of its role in the risk management system, this committee regularly reviews the risk matrix, monitors the execution of internal audit plans, ensures compliance with the Compliance Program, and evaluates actions taken in response to cyber threats, ensuring appropriate controls for prevention, detection, and mitigation.

We consider corporate information to be a strategic asset, and its protection is the responsibility of all employees and third parties. Our Comprehensive Information Security Policy, approved in November 2023, sets out the guidelines for safeguarding information and associated technologies throughout their life cycle, ensuring compliance with quality and security standards. Given that the document includes key procedures and technical controls for threat management, it is distributed internally as a preventive measure to protect its effectiveness. This Policy includes, among others, the following essential elements:

 

  • It actively promotes the continuous improvement of the information security management system by constantly assessing emerging threats and adapting our defense capabilities. This practice aims to reduce risks, optimize costs, and improve the efficiency and effectiveness of information systems.
  • We are committed to protecting information against unauthorized access (confidentiality), intentional or accidental alterations (integrity), and disruptions that prevent its use (availability). Control measures are implemented at every stage of the information life cycle, prioritizing classification and protection to prevent disclosure or manipulation by unauthorized individuals.
  • The Policy defines specialized instances responsible for monitoring and managing information security incidents. These functions follow established procedures that include protocols for detection, response, mitigation, and reporting, ensuring timely and coordinated reactions to potential threats.
  • Information security responsibilities are clearly defined and mandatory for everyone at CMPC, regardless of their role, function, or geographic location. From the Technology, Digitalization, and Cybersecurity Committee to end users, the entire organization must adhere to the Policy’s guidelines. Employees are also expected to promptly report any suspicious behavior or activity that could pose a threat to information security. Key roles such as Corporate and IT Security Officers, along with the Human Resources department, have specific duties to ensure proper implementation, monitoring, and compliance.

 

This Policy also extends to third parties, such as suppliers, contractors, and supply chain actors, who must protect any information accessed during the provision of their services. They are required to comply with CMPC’s defined security standards. The Procurement area ensures that evaluation and contracting processes include security controls as contractual requirements, mitigating risks in external relationships and protecting shared systems and data.

Active Information Security and Cybersecurity Management

CMPC maintains an enterprise-wide Information Security and Cybersecurity program to safeguard business operations, protect critical information assets, and enhance resilience against evolving cyber threats. The program is embedded in the Company’s risk management framework and operates under a governance model that includes executive oversight and periodic reporting to the Board of Directors through the Risk, Audit and Compliance Committee.

The design, implementation, and ongoing enhancement of cybersecurity controls are guided by internationally recognized standards and frameworks, including ISO/IEC 27001, ISO 27002, the NIST Cybersecurity Framework (CSF), CIS Critical Security Controls, ISA/IEC 62443 for industrial cybersecurity, and other applicable sector-specific good practices. These references support the capabilities required to identify, protect, detect, respond to, and recover from cyber risks across the organization.


CMPC’s cybersecurity capabilities are built on a balanced approach across people, processes, and technology. The Company has specialized teams with defined responsibilities in information technology, operational technology, cyber operations, identity protection, risk management, and incident response. These teams are supported by leading cybersecurity technologies, formalized processes, and continuous improvement practices that reinforce prevention, detection, response, and recovery across the organization.

CMPC applies a risk-based cybersecurity approach that includes periodic assessments of technology, information, operational, and third-party risks. These risks are integrated into the corporate risk management process and regularly evaluated to inform decision-making, investment prioritization, and improvement initiatives. The Company complements these activities with internal audits, independent external assessments, control effectiveness reviews, vulnerability evaluations, and remediation programs aimed at strengthening its security posture and operational resilience. During 2024, CMPC conducted both internal and external audits of its information security and technology management systems, verifying compliance with applicable standards and controls. The Corporate Information Technology Department coordinates with business units and subsidiaries to implement contingency plans that ensure operational continuity and information availability in the event of critical incidents. These units are required to maintain and regularly test their Business Continuity Plans (BCP), identifying key processes and resources. In addition, CMPC performs continuous vulnerability monitoring across systems, networks, and applications to anticipate threats and enhance proactive risk management. During fiscal year 2025, CMPC maintained active monitoring and management of information security and cybersecurity risks through its corporate cybersecurity program. The Company did not experience any material information security incidents with a significant impact on business continuity, financial results, customers, employees, or critical operations.

Recognizing the strategic importance of Operational Technology (OT) and Industrial Control Systems (ICS), CMPC maintains a dedicated Industrial Cybersecurity program to protect critical manufacturing, logistics, and production environments. Aligned with ISA/IEC 62443 principles, the program incorporates cybersecurity risk assessments, asset visibility, network segmentation, secure remote access controls, vulnerability management, cybersecurity monitoring, incident response capabilities, and resilience testing. These practices help safeguard the security, reliability, and continuity of industrial operations while reducing exposure to cyber threats affecting critical infrastructure.

Given the growing relevance of identity-based threats, CMPC places particular emphasis on identity protection and digital access management as core components of its cybersecurity strategy. This includes governance over user access, privileged access management, authentication controls, periodic access reviews, and monitoring of identity-related risks to reduce unauthorized access and protect critical systems, data, and operations.
To strengthen preparedness and response, CMPC operates continuous monitoring processes across its technology environments, supporting timely identification and management of vulnerabilities, cyber threats, and security events. Incident management processes, business continuity plans, disaster recovery capabilities, and crisis response procedures are periodically reviewed and tested to reinforce resilience and operational continuity.

CMPC also recognizes cybersecurity as a shared responsibility across the organization and its value chain. Employees receive mandatory cybersecurity awareness training and are expected to promptly report incidents, suspicious activities, or potential security weaknesses. Cybersecurity requirements are also embedded in supplier and third-party management processes through security assessments, contractual controls, and risk-based oversight to help protect information, systems, and interconnected operations. The Internal Audit department contributes to the design, implementation, and evaluation of the system, strengthening the comprehensive management of information security.

Through strong governance, risk management, auditing, training, operational controls, and continuous improvement, CMPC continues to strengthen cyber resilience, protect stakeholder trust, and support the secure and sustainable development of its global operations.

RESPONSIBLE USE OF ARTIFICIAL INTELLIGENCE


At CMPC, we promote the responsible, safe, and ethical use of Artificial Intelligence (AI) as a tool to drive innovation, efficiency, and value creation. To this end, we have an AI Tools Usage Guide that establishes guidelines for the proper use of AI tools, as well as their scope, restrictions, and associated responsibilities.


Among other aspects, this guide defines the exclusive use of tools authorized by the company, the protection of confidential information, compliance with security and privacy standards, human review and validation of AI-generated results, and the principles of transparency, ethics, and non-discrimination that must guide its application. It also acknowledges that these technologies have limitations and risks; therefore, the content and analyses generated must be critically evaluated before being used in business processes or decision-making.


Through all these processes, CMPC seeks to ensure that the adoption of AI contributes to the company’s sustainable development, safeguarding the trust of its employees, customers, and other stakeholders.

 


At CMPC, we promote the responsible, safe, and ethical use of Artificial Intelligence (AI) as a tool to drive innovation, efficiency, and value creation. To this end, we have an AI Tools Usage Guide that establishes guidelines for the proper use of AI tools, as well as their scope, restrictions, and associated responsibilities.


Among other aspects, this guide defines the exclusive use of tools authorized by the company, the protection of confidential information, compliance with security and privacy standards, human review and validation of AI-generated results, and the principles of transparency, ethics, and non-discrimination that must guide its application. It also acknowledges that these technologies have limitations and risks; therefore, the content and analyses generated must be critically evaluated before being used in business processes or decision-making.


Through all these processes, CMPC seeks to ensure that the adoption of AI contributes to the company’s sustainable development, safeguarding the trust of its employees, customers, and other stakeholders.

 

INVESTMENT AND SOCIAL CONTRIBUTIONS

CMPC is part of different associations and business organizations, universities, think tanks and NGOs with the aim of promoting the forestry industry, its good practices and benefits. Along these lines, during 2025 the most significant contributions were directed towards the Chilean Timber Corporation (CORMA) (USD 384,340), the Pontificia Universidad Católica de Chile (USD 344,532) and the Centro UC de Innovación en Madera (CIM) (USD 219,942), thus contributing to public debate.

Over the year 2025, CMPC did not make any contributions to lobbying, representation of interests or similar, political campaigns, candidates or others.

In addition, CMPC discloses a detailed breakdown of taxes paid in each jurisdiction where it is resident for tax purposes, enhancing transparency and enabling stakeholders to better understand its tax profile and contributions.

 

CMPC is part of different associations and business organizations, universities, think tanks and NGOs with the aim of promoting the forestry industry, its good practices and benefits. Along these lines, during 2025 the most significant contributions were directed towards the Chilean Timber Corporation (CORMA) (USD 384,340), the Pontificia Universidad Católica de Chile (USD 344,532) and the Centro UC de Innovación en Madera (CIM) (USD 219,942), thus contributing to public debate.

Over the year 2025, CMPC did not make any contributions to lobbying, representation of interests or similar, political campaigns, candidates or others.

In addition, CMPC discloses a detailed breakdown of taxes paid in each jurisdiction where it is resident for tax purposes, enhancing transparency and enabling stakeholders to better understand its tax profile and contributions.

 

STRATEGIC APPROACH

According to the CMPC Mission, Values and Corporate Purpose, sustainability is a strategic part of each business unit, its corresponding subsidiaries, a.s well as all operations and geographic area of influence and stakeholders. This strategic focus is based on three fundamental pillars: the risks to which the company and the part it plays in the community is exposed; material issues , related to the positive and negative impact along our entire value chain; Risk Management Program; and our contribution towards global initiatives such as the Sustainable Development Goals to which we subscribe.

According to the CMPC Mission, Values and Corporate Purpose, sustainability is a strategic part of each business unit, its corresponding subsidiaries, a.s well as all operations and geographic area of influence and stakeholders. This strategic focus is based on three fundamental pillars: the risks to which the company and the part it plays in the community is exposed; material issues , related to the positive and negative impact along our entire value chain; Risk Management Program; and our contribution towards global initiatives such as the Sustainable Development Goals to which we subscribe.

VALUE CREATION MODEL

Focusing on key processes, activities, products and by-products of each business unit, and paying close attention to internal circular flows, we have developed our Value Creation Model based on the Corporate Purpose, and through which, we face our Sustainable Development Corporate Goals.

Focusing on key processes, activities, products and by-products of each business unit, and paying close attention to internal circular flows, we have developed our Value Creation Model based on the Corporate Purpose, and through which, we face our Sustainable Development Corporate Goals.

CODE OF ETHIC BREACHES

During 2025, CMPC maintained its historical record of zero fines and convictions related to corruption and bribery, reflecting the Company’s continued commitment to ethical business practices and compliance with applicable laws and regulations. In addition, CMPC systematically monitors and tracks breaches related to a broader range of ethical and compliance matters, including:

Reporting area 2025
Corruption or bribery 3
Discrimination or harassment 9
Customer privacy data 2
Conflicts of interest 23
Money laundering or insider trading 0

During 2025, CMPC maintained its historical record of zero fines and convictions related to corruption and bribery, reflecting the Company’s continued commitment to ethical business practices and compliance with applicable laws and regulations. In addition, CMPC systematically monitors and tracks breaches related to a broader range of ethical and compliance matters, including:

Reporting area 2025
Corruption or bribery 3
Discrimination or harassment 9
Customer privacy data 2
Conflicts of interest 23
Money laundering or insider trading 0

HIGHLIGHTS

LINKS OF INTEREST