Compliance at Vossloh

Vossloh defines Compliance as behavior in line with all applicable laws and internal company guidelines. As a global player with a tradition of over 130 years in business, Vossloh bears a responsibility towards its customers, partners, employees, investors and the public. It is part of this social responsibility that Vossloh and all its employees comply, always and anywhere, with applicable law, respect ethical principles, and act as a role model when we act on behalf of the company.

The Management Board of Vossloh AG has explicitly expressed these principles in its Compliance Commitment, including: “Compliance with the law has absolute priority over closing a deal or achieving internal targets. We would rather forgo a business opportunity than violate the law. We will not tolerate any violation of the law or of our internal guidelines and policies and will sanction any such behavior (zero tolerance policy).”

The Management Board of Vossloh AG has established a Compliance Management System for the Vossloh Group. The Vossloh Compliance Management System is designed to identify risks of events of non-compliance and minimizing these risks by taking the appropriate steps to prevent damage and liability risks for Vossloh and its employees. Prevention of corruption and the strict observance of antitrust regulations play a particularly important role.

Since 2007, the Vossloh Compliance Management System has been based on the Vossloh Code of Conduct, which clearly defines and sets out the values of integrity and honest and ethical business conduct and is binding for the entire Group and all employees. Together with the Compliance guidelines, which apply across the Group, all employees have a framework to be used as a guideline for their daily work and which helps them make good and lawful decisions. The Compliance framework is available in all major Group languages and was distributed to all employees of the Vossloh Group worldwide. All employees are regularly provided with focused training on Compliance issues on the basis of the Compliance Training Concept. Vossloh has also established a Compliance eLearning program for all employees with a computer workstation.

The Management Board has established a Compliance Organization to implement and monitor Compliance, of which the structure, responsibilities and tasks of individual Compliance functions as well as reporting channels are set out in the Rules of Procedure of the Compliance Organization. The Vossloh Compliance Organization comprises of the Chief Compliance Officer (supported by a Compliance Office) and the Group Compliance Committee at Vossloh AG level, of Compliance Officers and Compliance Committees in the Business Units and of Local Compliance Officers in the operating companies. The Chief Compliance Officer regularly reports to the Management and Supervisory Boards in addition to the Audit Committee of the Supervisory Board, which is in charge of Compliance.

Together with an international law firm, Vossloh has established a whistleblower hotline to uncover potential Compliance violations. The whistleblower hotline gives employees and external whistleblowers an independent external contact (the ombudsperson) to report suspicions of potential misconduct. The whistleblower hotline is currently available for 20 countries, covering the most important regions and languages of the Vossloh Group. The Chief Compliance Officer follows up all reports and introduces appropriate measures, where necessary.

The Chief Compliance Officer and the Group Compliance Committee regularly review the effectiveness of the Compliance Management System throughout the Group. This also involves regular reviews by external Compliance experts. In the financial year 2017, KPMG AG Wirtschaftsprüfungsgesellschaft comprehensively audited the Compliance Management System of the Vossloh Group according to the Auditing Standard 980 of the Institut der Wirtschaftsprüfer in Deutschland e.V. (Institute of Public Auditors in Germany), IDW PS 980, referring to the sections antitrust and anti-corruption. The audit was performed as an efficiency review and finalized in February 2018. KPMG confirmed in their audit report (only available in German) that the Compliance Management System of the Vossloh Group was adequately implemented and effective in the period under review. Observations or recommendations for the future Compliance procedures have already been and are still being implemented in the course of the continuous further development and improvement of the Vossloh Compliance Management System.

The Group Compliance Committee also carries out regular audits, generally with the support of external auditors, in order to review the effectiveness of the Compliance Management System in the Group companies and to identify new or changed risks as well as potential opportunities for improvement.

If you have questions, suggestions or would like to make a notification with regard to the Vossloh Compliance Management System, please contact the Compliance Office of Vossloh AG:

Phone: +49 (0)2392 /52-723
E-Mail: compliance@vossloh.com