CMPC’S RISK GOVERNANCE
CMPC ensures that oversight of risk management is entrusted to a dedicated committee of the highest governing body, composed exclusively of independent and non-executive directors, in accordance with best corporate governance practices. The Risk, Audit and Compliance Committee of CMPC is composed of directors Hernán Rodríguez Wilson, Bernardo Larraín Matte, Ximena Corbo Urzúa, and Francisco Ruiz-Tagle Edwards. Its main responsibilities include approving and overseeing the execution of the annual internal audit plan; approving and monitoring the company’s compliance strategy; following up on actions derived from the implementation of CMPC’s prevention model; and monitoring the comprehensive execution of the company’s risk management strategy, which includes, among other areas, cybersecurity.
CMPC’s Risk Management Program is structured according to the three lines of defense model, ensuring a clear allocation of responsibilities for the identification, management, oversight, and independent assurance of risks. This structure enables the company to maintain an integrated and effective approach to risk governance, aligned with international standards such as ISO 31000 and COSO ERM.
The following describes how each line of defense is implemented within CMPC’s risk governance framework:
- First Line of Defense: At CMPC, all administrative, functional, and operational areas are responsible for identifying and managing the risks associated with their activities. This means that risk ownership is clearly assigned at the business unit level, where operational teams actively oversee and manage risks as part of their core responsibilities. These areas are also involved in implementing control measures and reporting to the relevant committees, ensuring an integrated and cross-functional approach to risk management across the organization.
- Second Line of Defense: CMPC has a consolidated governance structure that supports risk management oversight through various specialized functions and committees. The Corporate Risk and Compliance Department is responsible for the implementation, continuous improvement, and supervision of the risk program, including its monitoring, reporting, and alignment with international best practices. In addition, the Risk, Compliance, and Audit Committee and the Sustainability and Regulation Committee support oversight efforts and provide strategic guidance, while the executive owners of each risk category individually oversee their respective risk sources. Together, these structures ensure compliance with risk management objectives and regulatory control throughout the company.
- Third Line of Defense: CMPC’s Internal Audit Department provides independent and objective assurance regarding the quality and level of implementation of internal controls and risk mitigation measures. This department reports directly to the Board of Directors through the Risk, Audit and Compliance Committee, maintaining its independence from operational and oversight functions. Through periodic audits, the Internal Audit Department evaluates the effectiveness of the risk management program, verifies regulatory compliance, and promotes continuous improvement by identifying weaknesses and areas for enhancement.
CMPC ensures that oversight of risk management is entrusted to a dedicated committee of the highest governing body, composed exclusively of independent and non-executive directors, in accordance with best corporate governance practices. The Risk, Audit and Compliance Committee of CMPC is composed of directors Hernán Rodríguez Wilson, Bernardo Larraín Matte, Ximena Corbo Urzúa, and Francisco Ruiz-Tagle Edwards. Its main responsibilities include approving and overseeing the execution of the annual internal audit plan; approving and monitoring the company’s compliance strategy; following up on actions derived from the implementation of CMPC’s prevention model; and monitoring the comprehensive execution of the company’s risk management strategy, which includes, among other areas, cybersecurity.
CMPC’s Risk Management Program is structured according to the three lines of defense model, ensuring a clear allocation of responsibilities for the identification, management, oversight, and independent assurance of risks. This structure enables the company to maintain an integrated and effective approach to risk governance, aligned with international standards such as ISO 31000 and COSO ERM.
The following describes how each line of defense is implemented within CMPC’s risk governance framework:
- First Line of Defense: At CMPC, all administrative, functional, and operational areas are responsible for identifying and managing the risks associated with their activities. This means that risk ownership is clearly assigned at the business unit level, where operational teams actively oversee and manage risks as part of their core responsibilities. These areas are also involved in implementing control measures and reporting to the relevant committees, ensuring an integrated and cross-functional approach to risk management across the organization.
- Second Line of Defense: CMPC has a consolidated governance structure that supports risk management oversight through various specialized functions and committees. The Corporate Risk and Compliance Department is responsible for the implementation, continuous improvement, and supervision of the risk program, including its monitoring, reporting, and alignment with international best practices. In addition, the Risk, Compliance, and Audit Committee and the Sustainability and Regulation Committee support oversight efforts and provide strategic guidance, while the executive owners of each risk category individually oversee their respective risk sources. Together, these structures ensure compliance with risk management objectives and regulatory control throughout the company.
- Third Line of Defense: CMPC’s Internal Audit Department provides independent and objective assurance regarding the quality and level of implementation of internal controls and risk mitigation measures. This department reports directly to the Board of Directors through the Risk, Audit and Compliance Committee, maintaining its independence from operational and oversight functions. Through periodic audits, the Internal Audit Department evaluates the effectiveness of the risk management program, verifies regulatory compliance, and promotes continuous improvement by identifying weaknesses and areas for enhancement.
CMPC’S RISK MANAGEMENT PROGRAM
Empresas CMPC and its subsidiaries are exposed to a series of risks inherent to their businesses. CMPC’s Risk Management Program seeks to identify and manage the main risks that may affect the business strategy and objectives.
CMPC implements a comprehensive methodological process for risk management, consisting of six structured stages: communication and consultation; definition of scope, context, and criteria; risk assessment; treatment; monitoring and review; and recording and reporting. This approach is applied organization-wide, from strategic to operational levels, and covers all types of material risks, regardless of their origin (financial, operational, legal, environmental, among others). Risk identification is carried out through participatory sessions such as workshops, where risks are identified and prioritized. A risk is classified as material when its exposure level in a maximum loss scenario is rated at least “high” according to the established severity scale. From that point, risks are analyzed, assessed, and managed based on their criticality.
The risk assessment process includes a key stage to determine whether an identified risk is acceptable, based on the company’s defined risk appetite. This evaluation is conducted using a matrix that considers severity (or impact) and likelihood criteria, enabling the identification of whether risks fall within the company’s risk tolerance zone. Only those risks whose residual level exceeds the defined “acceptable” thresholds must be addressed with specific treatment plans, following a cost-benefit rationale. This approach aligns the desired level of risk exposure with the company’s strategic objectives and establishes clear limits for each risk category.
Further details on CMPC’s company-specific risk exposure are provided in the Consolidated Financial Statements 2025, which complement the risk assessment methodology described above by presenting the company’s risk profile across different risk categories. The document describes several identified material risks, including their potential impacts and the corresponding management approaches, and provides information that supports the assessment of risk exposure based on likelihood and magnitude considerations. This information contributes to the prioritization, monitoring, and management of risks across the organization. Two examples of identified risks are presented below, while several additional examples can be found throughout the document Consolidated Financial Statements 2025:
- Exchange rate risk: CMPC is continuously exposed to exchange-rate fluctuations due to its international operations and transactions in currencies other than its subsidiaries’ functional currencies. As of December 31, 2025, the Company had a net liability exposure of US$2,942 million, with a 10% currency appreciation or depreciation potentially increasing equity by US$294 million or reducing it by US$243 million, respectively. CMPC mitigates this risk through derivatives, currency matching between debt and cash flows, forward contracts, and limited option transactions authorized by the Board of Directors.
- Credit risk: CMPC is exposed to the risk of financial loss arising from customer insolvency and non-payment of receivables. However, the likelihood and potential magnitude of this risk are limited, as 95% of accounts receivable were covered by credit insurance or letters of credit as of December 31, 2025, and credit losses represented only 0.04% of sales. CMPC mitigates this exposure through regular customer credit assessments, centralized credit limits, insurance policies covering 85% to 90% of each invoice, and counterparty exposure limits for financial institutions.
Risk exposure is continuously monitored by the Corporate Risk and Compliance Management Office and formally evaluated on a quarterly basis during the sessions of the Risk, Audit, and Compliance Committee. During these meetings, updated risk analyses, the effectiveness of implemented controls, the evolution of key indicators, and other initiatives within the risk program are reviewed. The results are recorded within the corporate risk management program, which consolidates the information into reports that support trend analysis, anticipation of critical scenarios, and the strengthening of organizational resilience in a dynamic environment. Both in the processes of product and service development, as well as in the evaluation of projects, risk management topics are considered, mainly to identify those risks that could affect the fulfillment of the established objectives, and thus, determine measures to anticipate such events.
All identified risks are analyzed to determine their material nature. A severity table is used for this purpose, as stated in the methodology. A risk is “material”* when its potential level of risk, in a maximum loss scenario, is at least “high”4 according to the severity scale, which determines the Residual Risk Level, which in turn helps to identify those with greater exposure. This identification procedure considers amended or new regulations, in addition to due diligence procedures regarding human rights. The foregoing means that the detected risk will enter the Risk Management Program, thus continuing the step-by-step scheme of the methodological procedure for risk management, resulting in a higher level of managerial supervision.
*What are material risks? These are risks that, if materialized, would have a significant impact on the Company and its strategic objectives. The Internal Audit Unit assists in this process with an independent opinion on the quality and degree of implementation of critical controls and treatment measures.
One of the main actors in risk governance is the Internal Audit, which provides reasonable and independent assurance on the quality and degree of implementation of critical controls and risk treatment measures frequently. This area reports directly to the Audit Committee of the Board of Directors. The Risk, Audit and Compliance Committee reviews the Audit Program implementation progress on a monthly basis.
The corporate risk management program is audited by various certified and independent external entities at least annually, verifying topics such as governance, methodology, international standards on which the program is based, policy, procedure, and identification and analysis of specific risks, all under the ISO 31000 framework. Over the past two years, the external audits that have been carried out and considered the review of the entire risk management program, are regarding ISO 14001, ISO 45001, ISO 50001, and ISO 9001.
Both in the processes of product and service development, as well as in the evaluation of projects, risk management topics are considered, mainly to identify those risks that could affect the fulfillment of the established objectives, and thus, determine measures to anticipate such events.
CMPC has a policy of compensation, indemnities, and incentives for executives and managers, outlined in the Compendium of Corporate Governance Policies and Procedures. Annually, indicators related to the risk management of critical business activities are determined, aligned with the company’s 2030 strategy.
In addition, the Risk Management program incorporates monitoring of emerging risks, including, for example, the risks caused by cyberattacks on industrial plants, in the most appropriate way, with the aim of minimizing potential adverse effects.
Two examples of emerging risks that CMPC has identified are:
1. Discretionary tariff disruptions
Risk description
A tariff is an additional cost paid by the importer or absorbed by the exporter, affecting a company’s trade flow. While the imposition of tariffs between countries is a common and expected practice, this risk refers to the sudden, unilateral, and arbitrary imposition of tariffs or trade barriers by key economies, lacking predictability and creating uncertainty.
These measures represent a fundamental and structural shift in how international trade is conducted, from a system based on predictable rules to one where political unpredictability and unilateralism become the norm. This generates uncertainties and cascading effects that were previously less prominent or understood, directly impacting CMPC’s operations.
Tariffs not only result in direct costs but can also lead to unexpected additional charges. Companies may be forced to renegotiate contracts, adjust logistics, quickly explore new markets, and sometimes absorb part of the cost in order to retain customers.
CMPC has identified this as an emerging risk for the company, based on the following considerations:
The unilateral, abrupt, and discretionary imposition of tariffs is a growing risk given the current macroeconomic and political context, particularly from the United States and potentially other economies in the long term.
Although the Chilean forestry sector (including wood and pulp) may initially be exempt or subject to lower tariffs, the risk and uncertainty remain. While the impact may not be immediate, it could materialize in the medium to long term.
This is an external risk, driven by the broader macroeconomic context.
- The unilateral, abrupt, and discretionary imposition of tariffs is a growing risk given the current macroeconomic and political context, particularly from the United States and potentially other economies in the long term.
- Although the Chilean forestry sector (including wood and pulp) may initially be exempt or subject to lower tariffs, the risk and uncertainty remain. While the impact may not be immediate, it could materialize in the medium to long term.
- This is an external risk, driven by the broader macroeconomic context.
Potential impact
The potential impacts of this risk include:
- Increase in direct or indirect costs if CMPC’s products are affected by discretionary tariffs, resulting in a direct reduction in profit margins.
- Loss of competitiveness, as CMPC’s products may become more expensive than those from countries not subject to such tariffs, reducing their commercial appeal and potentially leading to a loss of market share.
- Strategic planning uncertainty due to the unpredictability of potential tariff measures, which makes it difficult for CMPC to develop reliable financial forecasts and long-term investment plans. This impact is primarily strategic in nature, creating uncertainty that affects future decision-making rather than causing immediate financial repercussions. It may also require CMPC to fundamentally reassess and adapt its international commercial strategy going forward.
- Supply chain reorganization and increased operating costs, as CMPC may need to seek alternative suppliers or redirect logistics flows to mitigate part of the tariff risk, leading to higher transportation and operational costs.
Risk Management
CMPC continuously monitors macroeconomic risks, including potential tariff measures, and conducts scenario analyses to assess and understand their possible impacts.
2. Phenological Desynchronization Due to Climate Change
Risk Description
Climate change is progressively altering the environmental conditions that regulate the natural cycles of species, including variables such as temperature, precipitation, and seasonality. As a result, key biological events such as flowering, fruiting, sprouting, or seed dispersal may occur at times different from those historically observed.
These changes can create temporal mismatches between forest species and other ecosystem components with which they have significant ecological relationships, such as pollinators, seed dispersers, or other species that contribute to natural regeneration processes. As these effects intensify, various ecological functions that underpin the biodiversity and resilience of forest ecosystems could be affected.
CMPC considers this an emerging risk because, although the effects of climate change on ecosystems are widely known, there is growing evidence of alterations in the phenological patterns of multiple species, and uncertainty still persists regarding the magnitude, speed, and scope that these changes could have on the long-term dynamics of forest ecosystems.
Potential Impact on CMPC
If this risk were to materialize, it could affect the natural processes that contribute to the regeneration and functioning of forest ecosystems, leading to changes in species composition, functional biodiversity, and the forests’ adaptive capacity in the face of environmental disturbances.
Furthermore, disruptions among species that depend on one another to complete their life cycles could reduce the effectiveness of key ecological processes—such as pollination, seed dispersal, or natural regeneration—thereby affecting the stability and resilience of certain ecosystems.
In the long term, these changes could increase the challenges associated with biodiversity conservation, the sustainable management of forest resources, and the maintenance of ecosystem services that sustain the productivity and environmental balance of the regions where the company operates.
Risk Management
CMPC constantly monitors climate variables and changes in the phenological patterns of species relevant to the ecosystems where the company operates, which could lead to adjustments in forest management as well as in the long-term planning and management of forest assets.
Empresas CMPC and its subsidiaries are exposed to a series of risks inherent to their businesses. CMPC’s Risk Management Program seeks to identify and manage the main risks that may affect the business strategy and objectives.
CMPC implements a comprehensive methodological process for risk management, consisting of six structured stages: communication and consultation; definition of scope, context, and criteria; risk assessment; treatment; monitoring and review; and recording and reporting. This approach is applied organization-wide, from strategic to operational levels, and covers all types of material risks, regardless of their origin (financial, operational, legal, environmental, among others). Risk identification is carried out through participatory sessions such as workshops, where risks are identified and prioritized. A risk is classified as material when its exposure level in a maximum loss scenario is rated at least “high” according to the established severity scale. From that point, risks are analyzed, assessed, and managed based on their criticality.
The risk assessment process includes a key stage to determine whether an identified risk is acceptable, based on the company’s defined risk appetite. This evaluation is conducted using a matrix that considers severity (or impact) and likelihood criteria, enabling the identification of whether risks fall within the company’s risk tolerance zone. Only those risks whose residual level exceeds the defined “acceptable” thresholds must be addressed with specific treatment plans, following a cost-benefit rationale. This approach aligns the desired level of risk exposure with the company’s strategic objectives and establishes clear limits for each risk category.
Further details on CMPC’s company-specific risk exposure are provided in the Consolidated Financial Statements 2025, which complement the risk assessment methodology described above by presenting the company’s risk profile across different risk categories. The document describes several identified material risks, including their potential impacts and the corresponding management approaches, and provides information that supports the assessment of risk exposure based on likelihood and magnitude considerations. This information contributes to the prioritization, monitoring, and management of risks across the organization. Two examples of identified risks are presented below, while several additional examples can be found throughout the document Consolidated Financial Statements 2025:
- Exchange rate risk: CMPC is continuously exposed to exchange-rate fluctuations due to its international operations and transactions in currencies other than its subsidiaries’ functional currencies. As of December 31, 2025, the Company had a net liability exposure of US$2,942 million, with a 10% currency appreciation or depreciation potentially increasing equity by US$294 million or reducing it by US$243 million, respectively. CMPC mitigates this risk through derivatives, currency matching between debt and cash flows, forward contracts, and limited option transactions authorized by the Board of Directors.
- Credit risk: CMPC is exposed to the risk of financial loss arising from customer insolvency and non-payment of receivables. However, the likelihood and potential magnitude of this risk are limited, as 95% of accounts receivable were covered by credit insurance or letters of credit as of December 31, 2025, and credit losses represented only 0.04% of sales. CMPC mitigates this exposure through regular customer credit assessments, centralized credit limits, insurance policies covering 85% to 90% of each invoice, and counterparty exposure limits for financial institutions.
Risk exposure is continuously monitored by the Corporate Risk and Compliance Management Office and formally evaluated on a quarterly basis during the sessions of the Risk, Audit, and Compliance Committee. During these meetings, updated risk analyses, the effectiveness of implemented controls, the evolution of key indicators, and other initiatives within the risk program are reviewed. The results are recorded within the corporate risk management program, which consolidates the information into reports that support trend analysis, anticipation of critical scenarios, and the strengthening of organizational resilience in a dynamic environment. Both in the processes of product and service development, as well as in the evaluation of projects, risk management topics are considered, mainly to identify those risks that could affect the fulfillment of the established objectives, and thus, determine measures to anticipate such events.
All identified risks are analyzed to determine their material nature. A severity table is used for this purpose, as stated in the methodology. A risk is “material”* when its potential level of risk, in a maximum loss scenario, is at least “high”4 according to the severity scale, which determines the Residual Risk Level, which in turn helps to identify those with greater exposure. This identification procedure considers amended or new regulations, in addition to due diligence procedures regarding human rights. The foregoing means that the detected risk will enter the Risk Management Program, thus continuing the step-by-step scheme of the methodological procedure for risk management, resulting in a higher level of managerial supervision.
*What are material risks? These are risks that, if materialized, would have a significant impact on the Company and its strategic objectives. The Internal Audit Unit assists in this process with an independent opinion on the quality and degree of implementation of critical controls and treatment measures.
One of the main actors in risk governance is the Internal Audit, which provides reasonable and independent assurance on the quality and degree of implementation of critical controls and risk treatment measures frequently. This area reports directly to the Audit Committee of the Board of Directors. The Risk, Audit and Compliance Committee reviews the Audit Program implementation progress on a monthly basis.
The corporate risk management program is audited by various certified and independent external entities at least annually, verifying topics such as governance, methodology, international standards on which the program is based, policy, procedure, and identification and analysis of specific risks, all under the ISO 31000 framework. Over the past two years, the external audits that have been carried out and considered the review of the entire risk management program, are regarding ISO 14001, ISO 45001, ISO 50001, and ISO 9001.
Both in the processes of product and service development, as well as in the evaluation of projects, risk management topics are considered, mainly to identify those risks that could affect the fulfillment of the established objectives, and thus, determine measures to anticipate such events.
CMPC has a policy of compensation, indemnities, and incentives for executives and managers, outlined in the Compendium of Corporate Governance Policies and Procedures. Annually, indicators related to the risk management of critical business activities are determined, aligned with the company’s 2030 strategy.
In addition, the Risk Management program incorporates monitoring of emerging risks, including, for example, the risks caused by cyberattacks on industrial plants, in the most appropriate way, with the aim of minimizing potential adverse effects.
Two examples of emerging risks that CMPC has identified are:
1. Discretionary tariff disruptions
Risk description
A tariff is an additional cost paid by the importer or absorbed by the exporter, affecting a company’s trade flow. While the imposition of tariffs between countries is a common and expected practice, this risk refers to the sudden, unilateral, and arbitrary imposition of tariffs or trade barriers by key economies, lacking predictability and creating uncertainty.
These measures represent a fundamental and structural shift in how international trade is conducted, from a system based on predictable rules to one where political unpredictability and unilateralism become the norm. This generates uncertainties and cascading effects that were previously less prominent or understood, directly impacting CMPC’s operations.
Tariffs not only result in direct costs but can also lead to unexpected additional charges. Companies may be forced to renegotiate contracts, adjust logistics, quickly explore new markets, and sometimes absorb part of the cost in order to retain customers.
CMPC has identified this as an emerging risk for the company, based on the following considerations:
The unilateral, abrupt, and discretionary imposition of tariffs is a growing risk given the current macroeconomic and political context, particularly from the United States and potentially other economies in the long term.
Although the Chilean forestry sector (including wood and pulp) may initially be exempt or subject to lower tariffs, the risk and uncertainty remain. While the impact may not be immediate, it could materialize in the medium to long term.
This is an external risk, driven by the broader macroeconomic context.
- The unilateral, abrupt, and discretionary imposition of tariffs is a growing risk given the current macroeconomic and political context, particularly from the United States and potentially other economies in the long term.
- Although the Chilean forestry sector (including wood and pulp) may initially be exempt or subject to lower tariffs, the risk and uncertainty remain. While the impact may not be immediate, it could materialize in the medium to long term.
- This is an external risk, driven by the broader macroeconomic context.
Potential impact
The potential impacts of this risk include:
- Increase in direct or indirect costs if CMPC’s products are affected by discretionary tariffs, resulting in a direct reduction in profit margins.
- Loss of competitiveness, as CMPC’s products may become more expensive than those from countries not subject to such tariffs, reducing their commercial appeal and potentially leading to a loss of market share.
- Strategic planning uncertainty due to the unpredictability of potential tariff measures, which makes it difficult for CMPC to develop reliable financial forecasts and long-term investment plans. This impact is primarily strategic in nature, creating uncertainty that affects future decision-making rather than causing immediate financial repercussions. It may also require CMPC to fundamentally reassess and adapt its international commercial strategy going forward.
- Supply chain reorganization and increased operating costs, as CMPC may need to seek alternative suppliers or redirect logistics flows to mitigate part of the tariff risk, leading to higher transportation and operational costs.
Risk Management
CMPC continuously monitors macroeconomic risks, including potential tariff measures, and conducts scenario analyses to assess and understand their possible impacts.
2. Phenological Desynchronization Due to Climate Change
Risk Description
Climate change is progressively altering the environmental conditions that regulate the natural cycles of species, including variables such as temperature, precipitation, and seasonality. As a result, key biological events such as flowering, fruiting, sprouting, or seed dispersal may occur at times different from those historically observed.
These changes can create temporal mismatches between forest species and other ecosystem components with which they have significant ecological relationships, such as pollinators, seed dispersers, or other species that contribute to natural regeneration processes. As these effects intensify, various ecological functions that underpin the biodiversity and resilience of forest ecosystems could be affected.
CMPC considers this an emerging risk because, although the effects of climate change on ecosystems are widely known, there is growing evidence of alterations in the phenological patterns of multiple species, and uncertainty still persists regarding the magnitude, speed, and scope that these changes could have on the long-term dynamics of forest ecosystems.
Potential Impact on CMPC
If this risk were to materialize, it could affect the natural processes that contribute to the regeneration and functioning of forest ecosystems, leading to changes in species composition, functional biodiversity, and the forests’ adaptive capacity in the face of environmental disturbances.
Furthermore, disruptions among species that depend on one another to complete their life cycles could reduce the effectiveness of key ecological processes—such as pollination, seed dispersal, or natural regeneration—thereby affecting the stability and resilience of certain ecosystems.
In the long term, these changes could increase the challenges associated with biodiversity conservation, the sustainable management of forest resources, and the maintenance of ecosystem services that sustain the productivity and environmental balance of the regions where the company operates.
Risk Management
CMPC constantly monitors climate variables and changes in the phenological patterns of species relevant to the ecosystems where the company operates, which could lead to adjustments in forest management as well as in the long-term planning and management of forest assets.