Supplier governance

Supplier Code of Conduct

The Raeburn Group and its operating businesses expect suppliers, contractors, consultants and material subprocessors to conduct business lawfully, ethically and securely. Expectations apply proportionately to the nature, risk and access associated with the relationship.

Confidentiality

Suppliers must protect Raeburn, customer and third-party confidential information; use it only for authorised purposes; restrict disclosure to personnel with a legitimate need to know; and return, delete or securely dispose of information when required, subject to lawful retention obligations.

Privacy & data protection

Suppliers processing personal data must comply with applicable privacy law and contractual requirements, minimise processing, protect data and support appropriate rights, audit and compliance obligations.

Information security

Suppliers must maintain security measures appropriate to risk, including secure configuration, vulnerability and patch management, encryption where appropriate, secure development where software is supplied, backup/recovery and proportionate monitoring.

Access control

Access to Raeburn/customer systems or information must be authorised, attributable, limited by least privilege and promptly removed when no longer required. Appropriate MFA must be used for privileged/administrative access where supported and applicable.

Incident reporting

Suppliers must notify the designated Raeburn contact without undue delay after becoming aware of an actual or reasonably suspected incident materially affecting Raeburn/customer information, systems or services, preserve relevant evidence and cooperate with remediation.

Ethical conduct & anti-bribery

Suppliers must act honestly, avoid deceptive practices and material conflicts, keep accurate records, and comply with applicable anti-bribery/anti-corruption law. Bribery, facilitation payments, kickbacks and improper inducements are prohibited.

Modern slavery & human rights

Forced labour, servitude, human trafficking and unlawful child labour are prohibited. Suppliers must comply with applicable employment, human-rights and modern-slavery law and take proportionate steps to address relevant supply-chain risks.

Subcontracting & subprocessors

Material subcontractors/subprocessors must be appropriately assessed and bound by obligations materially consistent with the supplier's commitments to Raeburn. Required notification, authorisation and data-processing provisions apply before relevant subcontracting.

This Code supplements applicable contracts, DPAs, security schedules and law. Where a contract imposes a stronger requirement, the stronger contractual requirement applies. Security vulnerabilities: security@theraeburngroup.com · Privacy: dpo@theraeburngroup.com.