CSL Annual Report 2026

Material Risks (alphabetical order) Risk Description and Potential Impacts Managing the Risk 1. Cybersecurity, Privacy & Artificial Intelligence (AI) • A failure or breach of information technology systems arising from human error, malicious activity or unauthorised access that could result in the compromise, loss or misuse of sensitive information. Such events may lead to operational disruption, regulatory exposure, reputational damage and financial loss. • T he adoption of artificial intelligence (AI) technologies introduces additional and emerging risks, including those related to data governance, model integrity, ethical use, regulatory compliance and cyber vulnerability. • C SL maintains a proactive approach to cybersecurity, continuously monitoring the threat landscape and aligning CSL’s controls to industry practices. • S ecurity safeguards are embedded across CSL’s infrastructure, IT systems and data environments, based on threat intelligence and risk-based prioritisation. • C SL invests in employee awareness and preparedness, performing ongoing training, crisis response simulations and business continuity exercises to reduce cyber and privacy risks across the organisation. • A I risks are managed through CSL’s AI governance and Global AI Policy, which embed privacy, cybersecurity, risk assessment, monitoring and escalation controls into the design, deployment and ongoing use of AI solutions. • C yber, Privacy and AI risks and measurement against risk appetite are overseen by the Audit and Risk Management Committee (ARMC). Also refer to page 50 (Privacy) of this Annual Report. 2. Employee Health, Safety and Wellbeing • A failure to effectively manage workplace health, safety and wellbeing risks that could result in physical or psychological harm to employees, contractors or visitors. • A dditional consequences may include operational disruption, regulatory action, legal liability, reputational damage and financial loss. • E mployee Health and Safety-related risks, measurement against risk appetite, compliance with the Environment, Health & Safety (EHS) Management System, including leading and lagging KPIs, and regulatory compliance are overseen by the ARMC. Also refer to pages 38–39 (Additional Material Topics) of this Annual Report. 3. Environment and Climate • A failure to effectively manage CSL’s environmental impacts across its operations, including emissions, resource use and waste management, which could result in environmental harm and resource depletion. • A failure to comply with regulatory or customer sustainability requirements such as packaging, net-zero targets, or product lifecycle analysis. • S uch failures may also lead to regulatory non-compliance, operational disruption, reputational damage and financial loss. • C limate-related risks and opportunities impact CSL operations and value chain: e.g. extreme weather events, exacerbated by climate change, damage CSL assets and supply chains. • E nvironment-related risks, measurement against risk appetite, and compliance with the EHS Management System, including regulatory compliance, are overseen by the ARMC. Also refer to the Healthier Environment section on page 34 of this Annual Report and the new climate-related financial disclosures sections of CSL’s Annual Report. Also refer to Sustainability Risks in section 5.7 of the Corporate Governance Statement. 19 CSL Limited Annual Report 2025/26

RkJQdWJsaXNoZXIy MjE2NDg3