AS Citadele banka

Latvia|Banking|FY2025|Auditor: |View original report →

Sustainability statement, in full

The complete text of AS Citadele banka’s FY2025 sustainability statement is held here – 109 pages, captured from the published report. Every disclosure below also links to its own passage.

ESRS 2 – General Disclosures

GOV-1The role of the administrative, management and supervisory bodies
Reported

Governance roles

Reference: pages 19-20.

ESG governance runs: Supervisory Board and its committees -> Management Board -> ESG Office/ESG Officer, alongside Enterprise Risk Management and the ESG Working Group.

Supervisory Board "is responsible for overseeing the establishment and implementation of the ESG strategy", reviewing ESG targets quarterly and approving ESG policies and the sustainability statement. The Management Board "is responsible for sustainability performance and the implementation of sustainability processes" and for approving the double materiality assessment (DMA). The ESG Officer, reporting to the CEO, "leads the Group's ESG agenda and framework, coordinates the DMA and IRO Register". The ESG Working Group, led by the ESG Officer, "validates DMA results, reviews IROs" before Management Board approval.

Board composition (2025): 8 non-executive Supervisory Board members and 7 executive Management Board members; Supervisory Board gender split 75% male/25% female; Management Board 57% male/43% female. "The group's administrative, management, and supervisory bodies do not include employee representation." In 2025 Board members trained on "CSRD and ESRS implementation... double materiality, IRO management, assurance readiness, and data governance."

GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodies
Reported

Information provided to management and supervisory bodies

Reference: page 20.

"The Supervisory Board and the Risk Committee receive quarterly updates on the implementation of the ESG strategy. In 2025, the Supervisory Board and the Risk Committee received four updates on key developments and achievements in the ESG area, including climate-related and environmental risk disclosures and reporting, results of materiality assessments, potential impacts of climate risks on the Group's assets, and progress toward green lending targets."

Climate-related risk reporting and risk-appetite threshold monitoring are folded into the regular monthly and quarterly internal reporting cycle to the Management Board, alongside green lending target tracking. The Management Board also held "dedicated discussions on other material impacts, risks, and opportunities (IROs) as part of the Double Materiality Assessment and the development of the Transition Plan (Version 1)", with outcomes presented to the Supervisory Board for review and acknowledgement. Updates are prepared by the ESG Officer with the Enterprise Risk Management Division and reviewed by the Management Board before going to the Supervisory Board.

GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemes
Reported

Sustainability in incentive schemes

Reference: page 21.

"Sustainability risks are embedded in Citadele remuneration practices, including performance-based variable remuneration, deferral periods, and ensuring a balance between fixed and variable components." Key Performance Indicators tied to Group sustainability goals, "e.g., financing the green transition, are tracked and evaluated annually", and variable remuneration for employees with sustainability-related responsibilities reflects achievement of these KPIs.

No fixed share is set aside: "While no fixed proportion of variable remuneration is explicitly tied to sustainability-related targets, sustainability KPIs are considered alongside other performance metrics for employees working in relevant areas." Management Board sustainability-KPI progress is overseen by the Supervisory Board and cascaded to top management and relevant functions. Subsidiaries may adopt Group-level sustainability KPIs plus their own business-specific KPIs.

GOV-3(was GOV-4)Statement on due diligence
Reported

Statement on due diligence

Reference: page 21.

Citadele's due diligence is guided by the OECD Guidelines for Multinational Enterprises and "concerns the whole value chain of the Bank including its own operations, its products and services, its business relationships and its supply chain." The statement maps the core elements of due diligence to sections of the sustainability statement:

Core elementMapped sections
Embedding due diligence in governance, strategy and business modelGOV-2; GOV-3; SBM-1; SBM-3
Engaging with affected stakeholdersSBM-2; MDR-P, S1-3; S4-3; G1-3
Identifying and assessing adverse impactsIRO-1; SBM-3
Taking actions to address adverse impactsMDR-A; E1-3; S1-4; S4-4; G1-3
Tracking effectiveness and communicatingMDR-T, MDR-M, E1-4; S1-5; S4-5
GOV-4(was GOV-5)Risk management and internal controls over sustainability reporting
Reported

Risk management and internal controls over sustainability reporting

Reference: page 21.

Citadele has "established a control framework that supports all stages of sustainability reporting - from collecting and checking data to preparing the final disclosures." The main identified risks are "potential omissions, inaccuracies, or misestimations in reported information", surfaced through systematic process reviews, historical error analysis, internal stakeholder feedback and regulatory compliance checks.

The ESG Office maintains a dedicated risk log tracking risks, levels and corrective actions, prioritised by severity and likelihood; high-priority risks trigger immediate mitigation. Mitigation measures include "the 'four-eyes principle,' internal validations, automated control checks (where possible), and targeted cross-departmental reviews", embedded into regular business operations, with significant issues escalated to the Management Board.

SBM-1Strategy, business model and value chain
Reported

Strategy, business model and value chain

Reference: pages 22-24.

Citadele offers "a full range of banking, leasing, investment, pension, and insurance products for retail, SME, and corporate clients across Latvia, Lithuania, and Estonia", serving 412.4 thousand active customers (up 3% year on year), 87% of whom are digital users. Its ESG strategy is organised around Environment, Social and Governance priorities, each with 2025/2026 sustainability targets, e.g. new green financing of EUR 100m (EUR 75m in 2026), eNPS >40%, and close to 100% AML/CTPF training completion.

Value chain: upstream covers goods and services the Group buys to deliver financial products (IT services, financial resources, consultancy); downstream covers the distribution of financial services and products to customers, "including their value chains, via lending, financial services, and asset management". Green products in 2025 included green mortgages, EV/plug-in-hybrid leasing, multi-apartment energy-efficiency loans and EIB/EIF/EBRD-aligned green loans, with EUR 176.2 million disbursed in green financing (EUR 102.4 million in 2024). EBRD is a shareholder holding approximately 25%, and Citadele follows EBRD Environmental and Social Performance Requirements (PR2 labour, PR4 occupational health and safety, PR9 financial intermediaries) and excludes certain industries from financing on environmental/social grounds.

SBM-2Interests and views of stakeholders
Reported

Interests and views of stakeholders

Reference: page 25.

Stakeholder groups: "customers (private individuals, corporate clients, and institutions), employees, shareholders (individual and institutional investors), suppliers, rating agencies, regulatory bodies and public authorities, and civil society organisations." Citadele distinguishes affected stakeholders from users of sustainability statements (investors, lenders, business partners, NGOs, governments, analysts, academics).

Engagement is method- and group-specific: NPS surveys are run by Marketing and Communications, while DMA engagement is directed by the ESG Officer. "Results from the Double Materiality Assessment enable the Bank to confirm that all material impacts, risks, and opportunities (IROs) are captured and to identify any areas requiring further attention." For 2025, "no new DMA-specific stakeholder survey was conducted due to the limited response rate and low added value observed in 2024"; the assessment instead drew on existing stakeholder insight and ongoing engagement channels. The Management Board holds ultimate accountability for integrating stakeholder outcomes into strategy; the Supervisory Board is regularly updated.

SBM-3Material impacts, risks and opportunities and their interaction with strategy and business model
Reported

Material impacts, risks and opportunities

Reference: pages 27-29.

"Through our double materiality assessment (DMA), we have determined our most material sustainability matters" : E1 Climate Change, S1 Own Workforce, S4 Consumers and End Users, and G1 Business Conduct. "Based on the double materiality assessment six out of the ten ESRS topics were not deemed material for this reporting period (Pollution (E2), Water and marine resources (E3), Biodiversity and ecosystems (E4), Resource use and circular economy (E5), Workers in the value chain (S2), Affected communities (S3))."

17 named material IROs span the four material topics: E1 (green & transition financing; GHG emissions from the financed portfolio; transition risk; physical-risk-driven asset devaluation); S1 (safe/fair working conditions; employer-of-choice opportunity; inclusive workplace); S4 (social inclusion via access to financial services; data/cybersecurity/continuity risk and impact); and G1 (corporate culture; whistleblower protection; corruption/bribery; financial crime; execution/process-management risk; data quality). "The result of this year's materiality assessment corresponds with the sustainability areas identified as material in the preceding year, with the exception of Workers in the value chain (S2), which was assessed as not material" in 2025 (previously material in FY2024).

IRO-1Description of the processes to identify and assess material impacts, risks and opportunities
Reported

IRO identification and assessment process

Reference: pages 30-31.

Process initiated in 2021 via Board discussions on sustainability priorities and UN SDG selection, followed by a 2022 company-wide materiality assessment using the UNEP FI Portfolio Impact Analysis Tool covering Retail and Corporate/SME activities (~90% of operating income). For 2024, a long list of topics was built from ESRS 1 AR16, internal risk/GRI topics, SDGs, PRB impact areas and SASB financial-industry topics. "A material change assessment comparing 2024 and 2025 concluded that no material changes have occurred since the 2024 double materiality assessment"; 2025 relies on that structure, refreshed by a targeted IRO review.

Scoring: impact severity uses scale, scope and irremediable character (1-5 scale); potential impacts add likelihood. Financial materiality uses quantitative/qualitative thresholds on likelihood and magnitude, with risk quantification via ICAAP. Time horizons: short-term = the reporting year; medium-term = up to 5 years; long-term = beyond 5 years. "Opportunities are derived from scenario analysis conducted using the Network for Greening the Financial System (NGFS) scenario framework, as well as from the annual business and strategy planning cycle." Topics with no identified IROs received no materiality score; "topics flagged as material by stakeholders but lacking identified IROs (e.g., animal welfare) are considered for review in future DMA cycles."

IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statement
Reported

ESRS content index

Reference: pages 32-33 (IRO-2 disclosure requirements table); pages 33-36 (datapoints derived from other EU legislation).

Citadele prints a full IRO-2 concordance table mapping each disclosure requirement it covers to a page number, covering ESRS 2 (BP-1, BP-2, GOV-1 to GOV-5, SBM-1 to SBM-3, IRO-1, IRO-2), E1 (SBM-3, IRO-1, E1-1 to E1-6 with pages; E1-5, E1-7, E1-8 and E1-9 marked "Not material"), S1 (all of S1-1 to S1-17 with pages), S4 (SBM-2, SBM-3, S4-1 to S4-5 with pages) and G1 (GOV-1, IRO-1, G1-1, G1-3, G1-4 with pages; G1-2, G1-5 and G1-6 marked "Not material"). No rows are printed for E2, E3, E4, E5, S2 or S3, consistent with the DMA finding those six topics not material.

A separate table lists cross-cutting and topical datapoints that derive from other EU legislation (SFDR, Pillar 3, Benchmark Regulation, EU Climate Law), each tagged to its source paragraph and SFDR reference indicator.

E1 – Climate Change

E1-1Transition plan for climate change mitigation
Reported

Transition plan for climate change mitigation

Reference: pages 37-38.

"Citadele's Transition Plan (Version 1), developed in 2025, outlines a phased approach to aligning the Bank's portfolio with climate-neutrality objectives. It focuses on the most material areas - financed emissions arising from the lending portfolio for transition risk-sensitive industries. Emissions from Citadele's own operations are not included in Transition Plan (Version 1), as they are not material in the context of the Bank's overall emissions profile." The plan was "acknowledged by the Supervisory Board and approved for implementation by the Management Board."

Phase 1 (approx. 2026-2027) prioritises "the development of robust processes, data quality, and methodologies to support credible, evidence-based target setting", with GHG monitoring targets to be folded into the Risk Appetite Framework in Q1 2026. The plan foresees "a progression from monitoring targets towards data-driven emission-reduction targets" and "a gradual convergence towards science-based 1.5°C trajectories", conditional on verified customer-level emissions data and credible national transition pathways. "Citadele does not rely on carbon offsets or credits to meet its GHG reduction targets." No capex/opex figures for the plan are disclosed: "the disclosure of detailed financial resources allocated to the Transition Plan... could prejudice the Group's commercial interests" (page 18).

E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysis
Reported

Identification of climate-related risks and scenario analysis

Back-filled from the E1 chapter's transition-plan/IRO-1 climate-risk subsections (pages 38-40). This DR did not exist under the 2023 ESRS the report was prepared against.

Climate risks are classified as physical (acute/chronic) and transition, identified as drivers of credit, market, liquidity, operational and strategic risk (page 39). Physical risk assessment "covers eight climate hazards: riverine flood, coastal flood, water stress, drought, extreme heat, wildfire, earthquake, and landslide", with flood risk "material for all commercial and residential real estate" and drought/water-stress materiality limited to agriculture and forestry (page 40).

Scenarios, NGFS framework (page 38): Orderly - Net Zero 2050 ("global warming is limited to below 1.5°C through stringent climate policies"), Disorderly - Delayed Transition (policies delayed to 2030), Hot house world - NDCs and Current Policies (most adverse, long-term physical risk). Stress-test horizons: Orderly 2025-2027 (short), Delayed Transition 2032-2034 (medium), Current Policies 2048-2050 (long, "the most adverse scenario in terms of projected GDP impact"). "Approximately 89% of the estimated impact is attributable to the Net Zero 2050 scenario", and the combined impact of transition and physical risk was "estimated at 0.2% of assets" (page 39). Scope: the lending portfolio, via ICAAP, latest run Q1 2025 on FY2024 data.

E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate change
Reported

Resilience in relation to climate change

Back-filled from the E1 chapter's "Resilience analysis through scenario analysis and stress tests" subsection (pages 38-39), where this content is disclosed in the FY2025 report. This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

"Citadele has been using climate change scenario analysis to assess the future implications of potential climate change pathways on Citadele's business model and strategy", using the NGFS framework (see E1-2). "Impact assessment on business model - the output of scenario analysis was a qualitative assessment of risks and opportunities in the immediate, middle- and long-term... The analysis shows that Citadele's portfolio is well-positioned for the transition, with material opportunities for business development and limited financial risks." A named area of uncertainty: stranded-asset risk in "agriculture, transportation, utilities, RE & construction" under most scenarios.

Capacity to adjust: the stress test is "integrated into ICAAP" and its results "incorporated into the capital add-on assessment to ensure the Bank's resilience and capital adequacy under evolving climate risk conditions" - resilience is expressed as a capital buffer rather than asset redeployment. Refreshed annually (latest: Q1 2025 on FY2024 data); the report does not say whether the scenario selection itself was updated in 2025.

E1-4(was E1-2)Policies related to climate change mitigation and adaptation
Reported

Policies related to climate change mitigation and adaptation

Reference: page 41 (E1-2 and ESRS 2 MDR-P).

Policies apply "across its own operations as well as its upstream and downstream value chains", with "management focus[ed] primarily on downstream impacts due to their higher significance, while upstream impacts are identified and managed proportionately."

Main policy documents: ESG Policy, ESG Risk Policy, Risk Strategy and Risk Appetite Framework, Credit Risk Management Policy, Operational and Reputational Risk Management Policy, and the Green Lending Framework (aligned with the Paris Agreement, UN SDGs and the EU Taxonomy, covering green mortgages, vehicle leasing, renewable energy projects and energy-efficiency improvements). The ESG Risk Policy sets "zero tolerance for greenwashing" and a three-lines-of-defence governance structure. The Credit Risk Management Policy "mandates the inclusion of climate-related factors in the client annual review process." CBL Asset Management applies a separate Sustainability and Engagement Policy to managed funds and pension products. "Policy-level documents are adopted by the Management Board and approved by the Supervisory Board" and are available to employees via Confluence.

E1-5(was E1-3)Actions and resources in relation to climate change policies
Reported

Actions and resources in relation to climate change policies

Reference: page 42 (E1-3 and ESRS 2 MDR-A).

"The Bank developed its Transition Plan (Version 1), setting the foundation for long-term alignment with net-zero financed emissions by 2050." 2025 actions: launch of "a new unsecured green consumer loan to support household investments in energy-efficient home improvements"; client-engagement activities "aimed at raising awareness of transition and physical climate risks, improving the quality of client-level ESG data, and supporting customers in their own decarbonisation efforts."

Ongoing actions: "enhancing climate-risk assessment methodologies, integrating ESG considerations into the Group's risk and governance frameworks, and expanding green lending in line with the EU Taxonomy and the Green Lending Framework." Resources are described qualitatively only - "dedicated human and financial resources are allocated" - since specific capex/opex amounts for the Transition Plan are withheld as commercially sensitive (page 18).

E1-6(was E1-4)Targets related to climate change mitigation and adaptation
Reported

Targets related to climate change mitigation and adaptation

Reference: page 43.

"In 2025, Citadele established its initial climate-related monitoring targets as part of the Transition Plan (Version 1), aimed at aligning the Bank's financed emissions with national and EU climate objectives." Phase 1 (2026-2027) tracks portfolio performance against "national policy-based GHG reduction pathways, EU and SBTi reference trajectories" across mortgage, commercial real estate, energy, transport and agriculture financed sectors, via semi-annual monitoring indicators of emission intensity and portfolio composition.

These are monitoring targets, not yet quantitative emission-reduction targets: "As methodological capacity and data maturity improve, Citadele plans to establish quantitative, science-based targets consistent with a 1.5°C pathway, in line with SBTi principles. The long-term objective is to achieve net-zero financed emissions by 2050." Quantitative, activity-based targets already in place cover the downstream value chain: the annual new green-lending target (EUR 100m for 2026, versus EUR 75m for 2025) and an Article 8 funds target. "Citadele does not rely on carbon offsets or credits to meet its GHG reduction targets." No changes were made to target definitions or methodologies within the 2025 cycle.

E1-7(was E1-5)Energy consumption and mix
Not Material
E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissions
Reported

Gross Scope 1, 2, 3 and total GHG emissions

Reference: pages 43-44 (E1-6 tables); page 18 (restatement note).

Own operations (tCO2eq): gross Scope 1 fell from 79.2 (2024) to 75.1 (2025), a 5% decrease. Scope 3 categories 1-14 are excluded as "non-significant"; only Scope 3 Category 15 (investments/financed emissions) is disclosed as significant.

Financed emissions (PCAF method), tCO2e: total rose from 1,449,653.4 (2024, restated) to 1,626,501.5 (2025), up 12%. By category (2025): Business loans 727,940; AuM 490,808; Motor vehicle loans 248,853; Securities 103,812; Mortgages 29,232; Commercial RE 25,857. "63% of financed emissions originated from the loan portfolio, 6% from securities and 30% from AuM." Loan-portfolio emissions alone were broadly stable (-0.2%); AuM emissions rose 48%.

Restatement: "Citadele restated financed-emissions (scope 3, category 15) figures reported in sustainability statement for year 2024 as a result of (i) excluding emissions from sovereign debt from its financed-emissions reporting scope and (ii) following data quality improvements and refinements to GHG emissions calculation" (page 18) - 2024 total financed emissions fell 11% on a like-for-like basis versus the figure originally reported.

E1-9(was E1-7)GHG removals and GHG mitigation projects financed through carbon credits
Not Material
E1-10(was E1-8)Internal carbon pricing
Not Material
E1-11(was E1-9)Anticipated financial effects from material physical and transition risks and potential climate-related opportunities
Not Material

S1 – Own Workforce

S1-1Policies related to own workforce
Reported

Policies related to own workforce

Reference: pages 90-91.

Main documents: the employment policy framework, Code of Ethics (professional conduct, anti-discrimination on "nationality, race, gender, religion, age, sexual orientation, appearance, social status, or political affiliation"), the Whistleblowing Policy, the Human Resources Policy, the Diversity and Inclusion Policy, a Succession Planning Policy, and the Remuneration Policy.

The Diversity and Inclusion Policy "has set a 40/60% gender balance target for the Supervisory and Management Boards by 2027" and "ensures gender-neutral policies in recruitment, remuneration, and career growth." The Remuneration Policy "applies a gender-neutral approach in all remuneration and performance management decisions, with no differentiation based on gender or other personal attributes", and incorporates sustainability risk via deferral periods and claw-back provisions. "These standards inherently prohibit forced labour, human trafficking, and child labour." Policy-level documents are Management-Board-adopted and Supervisory-Board-approved, and are available to all employees on Confluence.

S1-2Processes for engaging with own workforce and workers' representatives about impacts
Reported

Engaging with own workforce about impacts

Reference: page 91.

"Employees participate in quarterly engagement surveys, providing both anonymous and open feedback on their experiences at Citadele. The bank engages directly with employees without the involvement of workers' representatives" for most matters. Managers receive detailed survey reports and are expected to discuss findings with teams. In 2025, 89.9 thousand feedback items were shared via the Peero recognition app (68.8 thousand in 2024).

Lithuania has a Labour Council - "a five-member employee representation body that protects employees' professional, labour, economic, and social rights", reachable by e-mail or a common mailbox. Quarterly Live@Citadele sessions hosted by the Management Board give employees direct Q&A access to leadership on strategy and performance.

S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concerns
Reported

Remediation channels for own workforce

Reference: page 91.

Channels: direct communication with managers, anonymous engagement surveys, "a formal grievance mechanism... to address any employment-related issues", and a dedicated whistleblowing system (see also G1-1). Processing follows internal instruction and "typically includes investigation of reported issues, mediation or dialogue between parties, and, where appropriate, disciplinary actions." Material cases are reported to senior management. "The effectiveness of these processes is monitored through participation rates and engagement scores, with results being reported to the Management Board and the Supervisory Board."

S1-3(was S1-4)Taking action on material impacts on own workforce
Reported

Taking action on material workforce impacts

Reference: pages 91-92.

"There are no material negative impacts identified on its own workforce for year 2025, accordingly there are no actions to prevent or mitigate these impacts. No workplace incidents were registered that would have required remediation." Actions instead target the two positive-impact/opportunity IROs: the Wellbeing@Citadele programme (health insurance, flexible working, the Little Champions Co-Working Space), personalised growth plans and leadership development, a summer internship programme, and Employee Volunteering Days (142 days used in 2025 versus 219 in 2024). Metrics tied to these actions include eNPS (target >40%), employee turnover rate and the Mood Barometer, all reported via the Business Plan/People Strategy.

S1-4(was S1-5)Targets related to own workforce
Reported

Targets related to own workforce

Reference: page 93.

Targets apply to the Group's own workforce only - "do not extend to upstream and downstream value chain." eNPS: target >40% (and >40% for 2026); actual 50% in 2025, down from 53% in 2024. Gender balance at Board level: target 40/60% (underrepresented gender) by 2027; actual 44% in 2025, down from 50% in 2024. "There are no interim targets for Underrepresented gender in the Boards. eNPS target is reviewed on annual basis as part of the strategy planning and budgeting cycle." Targets were set with the Management and Supervisory Boards and the Head of HR, informed by stakeholder feedback and past performance; no changes to targets or methodology in 2025.

S1-5(was S1-6)Characteristics of the undertaking's employees
Reported

Characteristics of the undertaking's employees

Reference: pages 93-94.

Headcount: 1,288 employees at 31 December 2025, down from 1,321 in 2024 (2024 restated from FTE to headcount). By country: Latvia 71.6%, Lithuania 19.8%, Estonia 8.6%. By gender (2025 headcount): 423 male, 865 female. Contract type: 1,270 full-time, 18 part-time; no non-guaranteed-hours employees. "Temporary employees are not separately tracked... as they arise mainly from short-term maternity leave replacements and represent an immaterial share of the workforce." Turnover: 243 leavers in 2025, an 18.7% turnover rate (16.9% in 2024).

S1-6(was S1-7)Characteristics of non-employee workers
Reported

"Citadele does not employ non-employees in its own workforce" (page 94). The workforce "primarily consists of full-time employees, with no substantial reliance on self-employed individuals" (page 89); outsourcing of services supporting core activities is assessed and approved under internal risk-management procedures and subject to regulatory confirmation. This nil return is treated as the complete S1-7 disclosure: there is no population of agency workers, self-employed people or value-chain-supplied non-employees to characterise.

S1-7(was S1-8)Collective bargaining coverage and social dialogue
Reported

Collective bargaining coverage and social dialogue

Reference: page 94.

"Citadele has not entered into any collective bargaining agreements and in social dialogue in the European Economic Area (EEA)." The exception is the Lithuanian branch's Labour Council, "an employee representation institution that protects the professional, labour, economic, and social rights of the Bank's employees and represents their interests", consisting of 5 employee members reachable by e-mail or the Labour Council's common mailbox on working-condition matters.

S1-8(was S1-9)Diversity metrics
Reported

Diversity metrics

Reference: page 94.

Top management gender split (headcount, 2025): 49% female (22), 51% male (23) - versus 50%/50% in 2024. "Top management includes all managers who report directly to a Management Board member, as well as all members of the Management Boards of Citadele Group subsidiaries, excluding the Management Board of Citadele Group."

Age distribution (headcount, 2025): under 30: 211 (16.4%); 30-50: 861 (66.9%); over 50: 216 (16.8%). 2024 (restated): under 30 190 (14.4%); 30-50 900 (68.1%); over 50 231 (17.5%).

S1-9(was S1-10)Adequate wages
Reported

Adequate wages

Reference: page 95.

"Our compensation practices comply with local minimum wage requirements in every country where we operate." Pay is benchmarked "against the Finance and IT sectors, targeting the median market level", reviewed annually against comparable labour-market roles, and set with reference to education, experience, job complexity, mental effort, collaboration, leadership and accountability, plus seniority, skills and performance.

"From 2024 to 2027, we are conducting a comprehensive review and update of our job architecture" to enable precise equal-value pay comparisons and sharper gender-pay-gap monitoring by role; the company frames this as enhancing consistency rather than introducing a new wage-adequacy benchmark.

S1-10(was S1-11)Social protection
Reported

Social protection

Reference: page 95.

"Citadele ensures that its employees are covered by social protection against loss of income due to major life events", in line with applicable national regulation in each country of operation, "through public state programs or benefits offered by the bank". Coverage spans "sickness, unemployment, employment injury and acquired disability, parental leave, and retirement."

S1-11(was S1-12)Persons with disabilities
Reported

Persons with disabilities

Reference: page 95.

"In 2025, Citadele employed nine persons with disabilities, representing 0.7% of the total workforce (compared to seven employees, or 0.5%, in 2024)." Data is self-disclosed at different stages of employment; "as employees have the right to withhold this information, the data might be incomplete."

S1-12(was S1-13)Training and skills development metrics
Reported

Training and skills development metrics

Reference: page 96.

Channels: internal e-learning, the VIVA learning platform, leadership-development programmes, individual career plans, and "Digital Friday" for digital-literacy training; annual performance reviews assess "skills, goals, achievements, growth potential, and development needs."

2025 metrics: 100% of employees participated in performance/career-development reviews (67.6% female, 32.4% male participants). Average training hours per person fell to 20.5 in 2025 (22.7 female, 15.9 male) from 28.6 in 2024 (32.8 female, 19.6 male).

S1-13(was S1-14)Health and safety metrics
Reported

Health and safety metrics

Reference: page 96.

"100% of its workforce was covered by its health and safety management system" in both 2025 and 2024. 2025 vs 2024: fatalities 0 / 0; recordable work-related accidents 1 / 0; recordable work-related ill health 0 / 1; days lost to ill health 0 / 5; days lost to injuries 0 / 0.

S1-14(was S1-15)Work-life balance metrics
Reported

Work-life balance metrics

Reference: page 96.

"All employees (100%) are entitled to take family-related leave" (maternity, paternity, parental and carers' leave, per AR 96 of Regulation (EU) 2023/2772). Employees on family-related leave (headcount, 2025): 6.9% female, 0% male, 0% other/not stated; 2024: 7.5% female, 0.2% male.

S1-15(was S1-16)Compensation metrics (pay gap and total compensation)
Reported

Remuneration metrics

Reference: page 96.

Gender pay gap (2025): Supervisory Board -6.8%, Management Board -6.5%, all staff 34.6% (versus 0.0%, 1.2% and 33.5% respectively in 2024, restated). "Gender pay gaps are calculated as the difference between the average gross hourly pay level of male employees and the average gross hourly pay level of female employees... divided by the average gross hourly pay level of male employees." The 2024 figures were restated because the originally reported numbers used wages rather than the full ESRS pay-level definition.

Annual total remuneration ratio: 24.99 in 2025, down from 27.77 (restated) / 27.85 (as previously reported) in 2024 - "the annual total remuneration of the highest paid individual in relation to the median for the annual total remuneration of all employees."

S1-16(was S1-17)Incidents, complaints and severe human rights impacts
Reported

Incidents, complaints and severe human rights impacts

Reference: page 97.

"In 2025, Citadele recorded no work-related incidents of discrimination on grounds such as gender, racial or ethnic origin, nationality, religion or belief, disability, age, sexual orientation, or other protected characteristics" (consistent with 2024). No serious harassment incidents reported in either year. "Channels for own workers to raise concerns received 3 complaints (2024: 1), which were investigated in accordance with internal procedures and were not substantiated as discrimination, harassment, or severe human rights incidents." No National Contact Point complaints, no identified severe human-rights incidents (forced labour, trafficking, child labour), and no related fines or penalties in either year.

S4 – Consumers and End-users

S4-1Policies related to consumers and end-users
Reported

Policies related to consumers and end-users

Reference: page 99.

Core documents: the Data Protection Policy (GDPR-aligned; customers hold "the rights to erase, rectify, complete, or amend the information stored by the Bank"), the Code of Ethics (requires "clear, accurate, explicit, and non-misleading information about the Bank's products and services"), the Consumer Rights Protection Law, the Advertising Law, and the Good Practice Guidelines of the Finance Latvia Association. "We have no information on severe human rights issues and incidents connected to our customers that have been reported in 2025." Key policies, including the Code of Ethics and Privacy Protection Rules, are published externally on the Bank's website.

S4-2Processes for engaging with consumers and end-users about impacts
Reported

Engaging with consumers and end-users about impacts

Reference: pages 99-100.

Engagement channels: regular satisfaction, MobileApp, Brand Personality and Brand Awareness surveys; NPS and MobileApp NPS tracked quarterly, assessed separately for Latvia and Lithuania (Estonia excluded from the survey for methodological/sample-size reasons). NPS tracking is "complemented by post-interaction ratings after calls and branch visits, analysis of negative CSAT scores, quarterly mystery-shopper evaluations by an external partner, and regular call-listening reviews by managers." The Baltic Marketing Unit, reporting to the CEO, runs NPS monitoring; results feed the annual Group scorecard reviewed quarterly by the Management and Supervisory Boards.

S4-2(was S4-3)Processes to remediate negative impacts and channels for consumers and end-users to raise concerns
Reported

Remediation channels for consumers and end-users

Reference: page 100.

Customers raise concerns via an external whistleblowing system (electronic or in person at service centres) with confidentiality and anonymity guaranteed. Complaints follow "a dedicated procedure that aligns with external and internal regulations, as well as industry association recommendations", with country-specific legal deadlines for review and response. Dedicated country representatives oversee retail/corporate feedback. "In cases where a complaint involves financial loss, damage, or matters related to the Bank's commission, remedial actions are taken... [which] may include compensation for losses, a reduction or waiver of commission, or reimbursement of previously applied fees."

S4-3(was S4-4)Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actions
Reported

Taking action on consumer-related impacts and risks

Reference: pages 100-102.

Positive impact (access/affordability): a Group-wide Customer Servicing Standard, responsible-lending checks, an exclusion list for high-impact sectors, plain-language product information, and accessibility measures under the EU Accessibility Directive, including C Cards with 95% recycled plastic carrying braille code and a blind notch. "In Latvia, Citadele achieved the highest overall customer-service score and maintained its leading position for the 11th consecutive year."

Risk/negative impact (data, cybersecurity, continuity): role-based access control, encryption in transit and at rest, DLP and user-activity monitoring; two geographically separate data centres with continuous backup; regular penetration testing, a SIEM solution, and mandatory phishing-awareness training. "Prime-time system availability (≥99.9%)" and phishing-test participation are tracked as effectiveness indicators, alongside complaint trends and post-incident resolution times. "No material adverse impacts requiring corrective or remedial action were identified during the reporting period."

S4-4(was S4-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Targets for consumers and end-users

Reference: page 104.

Customer complaints ratio: 0.01% in 2025, below the <0.04% monitoring threshold. NPS: target >35%; actual 39% (Latvia) and 38% (Lithuania) in 2025. MobileApp NPS: 57% (Latvia), 48% (Lithuania); target >50%. I-bank/MobileApp prime-time system availability target: ≥99.9%. Estonia is excluded from the NPS survey scope "due to methodological and sample size considerations", with inclusion in future periods under assessment.

G1 – Business Conduct

G1-1Business conduct policies and corporate culture
Reported

Business conduct policies and corporate culture

Reference: pages 105-106.

Main documents: Corporate Governance Policy, Code of Ethics, Anti-Corruption Policy, AML/CTPF Policy, Data Governance Policy, Conflict of Interest Policy, extended to suppliers via the Supplier Code of Conduct. "Citadele defines its corporate culture through core values - Aspire, Personalize, Innovate, Act", reinforced through onboarding, Peero feedback, quarterly eNPS and Peero analytics, reported to both Boards.

Whistleblowing: an internal channel for employees plus an external channel "for customers, suppliers and other third parties", with confidentiality and anonymity guaranteed and retaliation protection under the Code of Ethics. "Citadele's principle [is] that all functions are treated as equally exposed to corruption and bribery risk, and therefore subject to the same controls." In 2025 key actions included near-100% completion of ethics/AML training and continued whistleblower-handling procedures; "no material adverse impacts requiring corrective or remedial action were identified during the reporting period."

G1-2Management of relationships with suppliers
Not Material
G1-2(was G1-3)Prevention and detection of corruption and bribery
Reported

Prevention and detection of corruption and bribery

Reference: pages 108-109.

Whistleblowing reports on corruption/bribery are assessed by the Head of the Compliance Division, with the Legal Division and Information Analysis and Due Diligence Unit involved as needed; cases implicating the Management Board go to Internal Audit for independent review. "If an investigation confirms misconduct, law enforcement agencies are promptly informed." Findings go to the Management and Supervisory Boards quarterly.

"Mandatory ethics and anti-corruption training is conducted annually for all employees, including Management and Supervisory Board members and during the first month of employment for new hires", covering anti-corruption principles, whistleblowing, gift policy and conflict-of-interest management, with knowledge testing. "Citadele does not classify any specific business functions as being at higher risk for corruption or bribery" - all employees are treated as equally exposed and covered by the training programme, targeting close to 100% annual completion.

G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conduct
Reported

Targets related to business conduct

(part of MDR-T/GDR-T disclosures)

Reference: page 107.

"Performance effectiveness is monitored for all material IROs through measurable outbound targets, internal assessments, key risk indicators, or other tracking mechanisms, as described in the Business Conduct (G1) section." Where a numeric target exists it is reported in the relevant sub-section - e.g. close to 100% completion rate of anti-corruption and AML/CTPF training (G1-3, G1-4) and the sanctions/financial-crime key risk indicators.

Where none exists, the company relies on monitoring rather than a stated target: "In cases where no specific targets are published (e.g., whistleblower protection), Citadele relies on internal processes to ensure oversight and follow-up." "Performance during the reporting period remained broadly in line with established targets, with no material deviations or significant adverse trends identified." This was prepared under the 2023 ESRS, which had no standalone G1 targets DR; business-conduct targets were covered under the cross-cutting MDR-T requirement referenced above.

G1-4Incidents of corruption or bribery
Reported

Incidents of corruption or bribery

Reference: pages 109-110.

"There were no confirmed incidents of corruption or bribery in 2025 (compared to 0 in 2024). Accordingly, no employees were dismissed or disciplined in relation to corruption or bribery during the reporting period, and no contracts with business partners were terminated or not renewed due to such violations." "No fines, penalties, or convictions for violations of anti-corruption or anti-bribery laws were imposed on Citadele or its employees during 2025" and "no public legal cases concerning corruption or bribery were brought against Citadele or its employees in 2025", including no unresolved cases carried over from prior years. "No incidents involving actors in the value chain were identified where Citadele or its employees were directly involved."

G1-5Political influence and lobbying activities
Not Material
G1-6Payment practices
Not Material