Corporate governance Throughout FY2026, CSL’s governance arrangements were consistent with the ASX Corporate Governance Council’s Corporate Governance Principles and Recommendations (4th edition). This year, CSL was again unable to fully comply with the ASX Corporate Governance Council’s Corporate Governance Principles and Recommendation 1.5 (Lay solid foundations for management and oversight; Diversity) due to legal and contractual requirements introduced in the United States. Instead, CSL has provided a summary of its approach to inclusion and belonging in the FY2026 Corporate Governance Statement. CSL’s FY2026 Corporate Governance Statement has been approved by the Board and is available on CSL.com. + R EAD MORE AT CSL.COM/WE-ARE-CSL/ CORPORATE-GOVERNANCE The Board continually reviews governance at CSL so that the governance framework remains appropriate in light of changing expectations and general developments in good corporate governance. Risk management CSL has adopted and follows a detailed and structured Enterprise Risk Management Framework (ERMF) to identify, evaluate, monitor and manage risks. This ERMF sets out the risk management processes, internal compliance and monitoring requirements, governance processes and structures including roles and responsibilities for different levels of management, the matrix of risk impact and likelihood for assessing risk, the three lines of accountability for risk, and risk management reporting requirements. The ERMF has been established to provide reasonable assurance that: • any material exposure to risk can be identified and adequately monitored and managed; and • significant strategic, emerging, financial, managerial and operating risk-related information is accurate, relevant, timely and reliable. Further details of CSL’s risk management framework are contained in CSL’s Corporate Governance Statement. Governance Data protection and cybersecurity CSL’s cybersecurity program is a core component of its broader enterprise risk management strategy. Governance and oversight are provided by CSL’s Global Leadership Team and Board of Directors, including through the Audit and Risk Management Committee, to support the effective management of cybersecurity risk and alignment with applicable legal and regulatory requirements across the regions in which CSL operates. CSL’s Chief Information Security Officer provides regular updates to the Audit and Risk Management Committee, supporting strategic alignment and Board-level visibility into the evolving cyber threat landscape. CSL takes a risk-based approach to cybersecurity and data protection, structuring its program around industry-recognised frameworks that support resilience against a constantly evolving threat environment. The program includes cybersecurity policies, standards, processes and practices embedded across CSL’s operations to help prevent, detect, contain, respond to and recover from cybersecurity threats and incidents. The overarching goals are to minimise business disruption, protect CSL’s systems and data, and safeguard the confidentiality, integrity and availability of information, including personal information. The program also includes ongoing monitoring, identification, assessment and management of cybersecurity risks, supported by clear communication and escalation protocols that keep the Global Leadership Team informed as the cyber threat landscape evolves. Key components of CSL’s cybersecurity program include: • perimeter and system safeguards • incident response capabilities • awareness and training initiatives • threat intelligence integration • risk assessments and security testing • identity governance • vulnerability analysis and management. A description of CSL’s material risks and key risk management activities for each risk can be found in the Material Risks section on page 18 of this Annual Report. Tax transparency While CSL’s roots are proudly Australian, it operates as a global organisation, with more than 90% of revenue generated outside Australia. Transparency is a core element of CSL’s tax governance framework. CSL reports on its global tax profile through its annual Tax Transparency Report and other regulatory disclosures. These provide stakeholders with a clear view of CSL’s approach to tax, governance and global footprint. Tax Transparency Reports are available on CSL’s website. CSL operates across multiple jurisdictions and complies with applicable tax laws and reporting obligations in each. This includes the Organisation for Economic Co-operation and Development (OECD) Country-by-Country Reporting (CbCR) and emerging public CbCR requirements, including in the EU and Australia. CSL is committed to meeting these obligations in a timely and transparent manner. CSL has a low appetite for tax risk and does not engage in aggressive tax planning. This reflects CSL’s Values, with integrity at its core. CSL supports the principle that income earned in a country should be reflective of economic activities undertaken there, and taxed accordingly. CSL supports initiatives that enhance transparency and strengthen confidence in global tax systems, including OECD-led reforms such as Pillar Two. CSL monitors implementation closely to ensure compliance, and encourages governments to continue to work together to adopt coordinated, practical approaches that balance transparency with operational complexity for global businesses. 50 Governance
RkJQdWJsaXNoZXIy MjE2NDg3