doValue S.p.A.

Italy|Credit Servicing (NPL Management)|FY2025|Auditor: KPMG S.p.A.|View original report →

Sustainability statement, in full

The complete text of doValue S.p.A.’s FY2025 sustainability statement is held here – 126 pages, captured from the published report. Every disclosure below also links to its own passage.

ESRS 2 – General Disclosures

GOV-1The role of the administrative, management and supervisory bodies
Reported

Role of the administrative, management and control bodies

Reference: pages 69-72; 179 (cross-reference under G1).

doValue has a traditional model: a Board of Directors of 11-13 members and a Board of Statutory Auditors of three members plus two alternates, both appointed by the Shareholders' Meeting on 26 April 2024 for a term running to the 2027 AGM (p.69). Two board committees support it: the Appointments and Remuneration Committee (five non-executive directors, three independent) and the Risk, Related Party Transactions and Sustainability Committee (three independent non-executive directors), which "supports the Board of Directors with adequate investigative activities" on internal control, risk management and "issues relating to Sustainability" (p.69).

The Board is 54% men / 46% women, with 46% of members independent under art. 148 TUF (p.70). There is no employee representation on the Board (p.70). For business conduct, the Board approves the Code of Ethics and the Model 231, and pursuant to ESRS G1 GOV-1 "the Board of Directors is responsible for approving the Code of Ethics and the Organisation, Management and Control Model" (p.70).

GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodies
Reported

Information provided to and Sustainability matters addressed by the administrative, management and supervisory bodies

Reference: pages 75-76.

The results of the double materiality analysis are shared by Group Communication & Sustainability with the Financial Reporting Officer, who in turn informs the Risk, Related Party Transactions and Sustainability Committee, the Board of Statutory Auditors and the Board of Directors, which "approves the double relevance analysis" (p.75). "In developing the Group's strategies, the Board of Directors takes Sustainability objectives into account to integrate ESG factors into business decisions" (p.76), and the Committee weighs both materiality outcomes and regulatory change when defining strategy and ESG objectives.

GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemes
Reported

Integration of Sustainability performance into incentive systems

Reference: pages 76-78.

The doValue 2025-2026 Remuneration Policy, approved by shareholders on 29 April 2025, ties variable pay to ESG targets. The CEO's 2025 MBO includes a 10% ESG weighting tied to the Group's Sustainability Index; Key Management Personnel's MBO carries a 10% ESG target split 5%/5% between the Employee Engagement (Trust Index) survey and the Sustainability Index, and the 2025-2027 LTI also carries a 10% ESG-weighted KPI on the Sustainability Index, paid on a 1-5 rating scale (p.77). "There are no objectives explicitly linked to climate change", but the environmental Sustainability objective covers resource management, energy efficiency and monitors Scope 2/3 emissions and % renewable electricity as indicators (p.77). Under ESRS E1 GOV-3 the report confirms explicitly: "The variable remuneration of the Chief Executive Officer and Key Management Personnel does not envisage targets explicitly linked to climate change" (p.116).

GOV-3(was GOV-4)Statement on due diligence
Reported

Statement on due diligence

Reference: pages 81-82.

doValue maps the ESRS due-diligence core elements to its own sections: embedding in governance/strategy (GOV-2, GOV-3, SBM-3 and its topical SBM-3 sub-sections); stakeholder engagement (GOV-2, SBM-2, IRO-1, IRO-2, MDR-P, S1-2/S2-2/S4-2); identifying and assessing negative impacts (IRO-1, SBM-3 and its topical sub-sections); adoption of measures to address negative impacts (MDR-A, E1-1, E1-3, S1-4, S2-4, S4-4); and monitoring effectiveness (MDR-T, MDR-M, E1-6, S1-6, S1-8, S1-10, S1-11, S1-14, S1-16, S1-17) (pp.81-82, tabular mapping).

GOV-4(was GOV-5)Risk management and internal controls over sustainability reporting
Reported

Risk management and internal controls over Sustainability reporting

Reference: pages 78-81.

Since 2024, doValue runs an Internal Control System on Sustainability Reporting (ICSSR), fully integrated with the financial-reporting control system and structured on the CoSO Framework's 5 pillars / 17 principles, via an Entity Level Control (ELC) catalogue mapped to ESRS 2 principles (p.80). The Financial Reporting Officer's Control Function rates supervision per control, identifies the most material Sustainability indicators and the entities contributing most to them ("Scoping"), and rates any shortcomings on a 5-level severity scale combined with a 3-level likelihood scale, assessed in financial, reputational and regulatory terms (p.80). Separately, the Group-wide Enterprise Risk Management (ERM) function runs a four-stage risk process (identification, measurement, response, monitoring) reported through a "Tableau de Bord" shared with the CEO, Committees and Board (pp.78-79).

SBM-1Strategy, business model and value chain
Reported

Strategy, business model and value chain

Reference: pages 83-85.

doValue is "the leading operator in southern Europe in the management of credit portfolios and real estate assets deriving from non-performing loans", with more than 20 years' experience and approximately €136 billion in assets under management (p.83). Services span NPL/UTP/performing-loan servicing, real estate (REO) management, Master Legal, Alternative Asset Management, due diligence and mortgage brokerage. As of 2025 the Group employs 3,072 people across Italy (1,219), Spain (471), Greece (986) and Cyprus (396) (p.84). Value chain: upstream are suppliers of ICT, consulting and utilities plus the External Network (loan-recovery companies, external professionals and lawyers); downstream are institutional customers (banks, investors) and end-users (debtors) (p.84). The Group holds an MSCI ESG "AAA" rating for the third consecutive year and a Sustainalytics "low risk" rating (p.84).

SBM-2Interests and views of stakeholders
Reported

Interests and views of stakeholders

Reference: pages 86-88.

Key stakeholder groups are shareholders/investors, customers, employees, the External Network, suppliers, debtors/community and trade unions (pp.86-88). Mechanisms include Investor Relations engagement governed by a 2021 Engagement Policy; customer Key Quality Indicators (KQI) written into servicing contracts; an annual People Engagement Survey (run since 2020) and Great Place to Work® certification obtained in 2025 across all four countries; External Network monitoring via debtor questionnaires; and a Top-Vendor supplier performance campaign (pp.86-87). On shareholder dialogue, three items shaped strategy in the period: the December 2024 share capital increase, an updated 50-70% dividend-payout policy, and the July 2025 binding agreement to acquire coeo (p.88).

SBM-3Material impacts, risks and opportunities and their interaction with strategy and business model
Reported

Material impacts, risks and opportunities and their interaction with strategy and business model

Reference: pages 89-93, 97-98.

The 2025 DMA identified 35 material impacts, risks and opportunities concentrated in E1 (climate), S1 (own workforce), S2 (value chain workers), S4 (consumers/end-users) and G1 (business conduct) (p.89); two new material sub-topics versus 2024: S4 personal security of consumers/debtors, and G1 whistleblowing (p.89). "On the basis of the audits carried out, no events or conditions emerged that have generated significant financial effects on the Group's financial position, economic result or cash flows" (p.97). On resilience, the Group states the DMA's longer time horizon than the Annual Financial Report means climate and transition risks "can generate indirect effects on the business" even though the sector has "limited direct environmental impacts" (p.98).

IRO-1Description of the processes to identify and assess material impacts, risks and opportunities
Reported

Description of the processes to identify and assess material impacts, risks and opportunities

Reference: pages 94-97.

The DMA follows ESRS 1 Chapter 3 / ESRS 2 IRO-1, using the EFRAG IG 1 Materiality Assessment Implementation Guidelines, and is doValue's second iteration, refining the 2024 list (p.94). Context analysis excluded E2 (pollution), E4 (biodiversity) and S3 (affected communities): "the analysis... did not lead to the identification of impacts, risks and opportunities in terms of water, air and soil pollution... the Group's business activities concern the management of credit portfolios and properties... that do not have a significant impact on the environment" (p.95). IROs were scored 1-5 on severity/benefit and probability (impact materiality) and magnitude/probability (financial materiality) against a Group-defined threshold, with internal functions and ESG Ambassadors surveyed alongside shareholders, suppliers and customers (pp.95-97). Results went to the Financial Reporting Officer, the Risk/RPT/Sustainability Committee and the Board, which approved the analysis in November 2025 (p.97).

IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statement
Reported

Disclosure requirements in ESRS covered by the undertaking's Sustainability statement

Reference: pages 98-101 (content index table).

doValue publishes a full ESRS content index mapping each disclosure requirement it covers to a page reference, spanning ESRS 2 (BP-1, BP-2, GOV-1 to GOV-5, SBM-1 to SBM-3, IRO-1, IRO-2, MDR-P/A/M/T) and the topical standards E1, S1, S2, S4 and G1 only — E2, E3, E4, E5 and S3 disclosure requirements are absent from the table. The index states: "With regard to the list of disclosure requirements set out in the cross cutting and topical principles deriving from other EU legislative acts, presented in Appendix B of ESRS 2, it is specified that these are not relevant for doValue and are therefore not included in the Consolidated Sustainability Reporting" (p.101). Separately, on transitional reliefs: "The doValue Group has made use of some transitional provisions set forth in Appendix C: List of gradually introduced disclosure obligations applicable to it, including SBM-3, par. 48 (e)... and E1-9 relating to the expected financial effects of material physical and transition risks and potential climate-related opportunities" (p.69).

E1 – Climate Change

E1-1Transition plan for climate change mitigation
Reported

Transition plan for climate change mitigation

Reference: page 115.

doValue reports plainly that it has none yet: "At present, the doValue Group has not adopted a climate transition plan. However, it monitors the evolution of the European regulatory framework and progressively assesses the opportunity to develop and formalise a climate transition plan consistent with the Group's Sustainability strategy" (p.115). The remuneration cross-reference confirms no climate-linked incentive target exists (ESRS E1 GOV-3, p.116). Decarbonisation levers and 2025 actions are nonetheless described under E1-3, and targets (including Spain's local quantitative goals) under E1-4.

E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysis
Reported

Identification of climate-related risks and scenario analysis

Back-filled from the E1-specific SBM-3 section (ESRS E1, ESRS 2 SBM-3), disclosed in the FY2025 report (page 115). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

doValue classifies its material climate risk as physical and transition in nature, but states: "a climate risk analysis has not yet been conducted with a level of granularity such as to fully meet all the information requirements envisaged by the ESRS E1 SBM-3 standard" (p.115). Exposure assessment: "Direct exposure to physical risks is currently limited, as the properties associated with the assets under management do not represent the Group's operating assets, but guarantees associated with credit exposures" (p.115). Climate risk is monitored inside the Group's general ERM system rather than a dedicated climate process. On scenarios, the report is explicit that none were used: "In identifying and assessing risks as well as climate-related opportunities, the Group did not use climate scenarios" (p.116, under ESRS 2 IRO-1 for climate). Per ESRS E1-2 paragraph 17, the scenario-analysis items therefore do not apply; this is not a gap.

E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate change
Reported

Resilience in relation to climate change

Back-filled from the E1-specific SBM-3 section (ESRS E1, ESRS 2 SBM-3), disclosed in the FY2025 report (page 115). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

doValue states plainly that no ESRS-defined resilience analysis has been carried out for climate: "a climate risk analysis has not yet been conducted with a level of granularity such as to fully meet all the information requirements envisaged by the ESRS E1 SBM-3 standard, without prejudice to the gradual integration of climate assessments into the Group's risk management processes" (p.115). The Group commits only to continued, progressive development: "The Group will continue to progressively develop its analyses on climate risks... in order to strengthen alignment with the requirements of the ESRS standards over time" (p.115).

E1-4(was E1-2)Policies related to climate change mitigation and adaptation
Reported

Policies related to climate change mitigation and adaptation

Reference: pages 116-117.

doValue has no standalone climate policy; climate sits inside the Group's Sustainability Policy and its attached "Guidelines on environmental issues", which cover reduction of energy consumption and emissions from buildings/transport/equipment, environmental criteria in procurement, and employee/collaborator awareness training (pp.116-117). The Policy's recipients are "corporate bodies, employees, collaborators and all those who operate in the name and on behalf of the Group companies" (p.116); the Gardant perimeter has progressively adopted the same Policy following the 2025 merger (p.117).

E1-5(was E1-3)Actions and resources in relation to climate change policies
Reported

Actions and resources in relation to climate change mitigation

Reference: pages 117-119.

Main decarbonisation levers: energy efficiency, renewable energy (exploring solar, purchasing certified green power), sustainable mobility (hybrid/electric fleet, smart working) and offsetting via reforestation — the Group states it "does not have a CapEx plan dedicated to mitigation actions" (p.117). Concrete 2025 measures: renewed 100%-renewable electricity supply contract with Repower S.r.l. for the Italian real estate portfolio (GO-certified); LED relamping and presence detectors at several Italian sites; heat-pump replacement of obsolete refrigeration at Rome Lungotevere Flaminio; EV charging stations installed in Cyprus; ~95% of energy at the main Gardant offices came from renewable sources in 2025 (p.118); Spain's Madrid site runs on 100%-certified renewable electricity (p.119).

E1-6(was E1-4)Targets related to climate change mitigation and adaptation
Reported

Targets related to climate change mitigation and adaptation

Reference: pages 119-120.

At Group level doValue states: "the doValue Group has not identified specific quantitative targets relating to climate change mitigation or the reduction of greenhouse gas (GHG) emissions" (p.119), only the 24 qualitative 2024-2026 Business Plan objectives (sustainable mobility awareness, public-transport/hybrid-fleet uptake, GHG-management improvement, office energy-efficiency maintenance). doValue Spain alone sets quantitative local targets: fossil-fuel fleet consumption -15% by 2030, office electricity consumption -10% by 2026, business-travel emissions -10% by 2030, and paper consumption -10% by 2026 (p.119).

E1-7(was E1-5)Energy consumption and mix
Reported

Energy consumption and energy mix

Reference: page 120.

Total energy consumption rose from 8,555.05 MWh (2024) to 9,455.35 MWh (2025) following a reporting-scope extension to the corporate fleet; fossil consumption grew from 7,192.39 to 7,400.60 MWh while its share of the mix fell from 84.07% to 78.27%. Renewable consumption roughly doubled, from 1,199.16 to 2,052.88 MWh (14.02% to 21.71% of the mix); nuclear-sourced consumption fell from 163.50 to 1.87 MWh. Energy intensity is stated as not applicable, since consumption does not relate to real-estate activities classed as high climate impact under EU/2020/1818 (p.120).

E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissions
Reported

Gross Scopes 1, 2, 3 and Total GHG emissions

Reference: pages 121-123.

Scope 1: 508.55 → 619.67 tCO2e. Scope 2 location-based: 2,143.72 → 2,170.94 tCO2e; market-based: 2,637.31 → 2,003.38 tCO2e. Scope 3 is tracked for Category 1 (purchased services, 9,179.67 tCO2e in 2025, not previously reported), Category 6 (business travel, 30.00 → 267.24 tCO2e) and Category 7 (employee commuting, 7,268.00 → 8,361.21 tCO2e) (p.121). "The increase compared with 2024 is primarily attributable to methodological refinements in the calculation and to an extension of the reporting boundary" (p.122). The Group applies GHG Protocol methodology with DEFRA 2025 and UNFCCC/European Residual Mixes emission factors by country (pp.122-123), and separately offsets a small volume tied to website visits: "Emissions attributable to 2025 amount to 864 kg of CO2 and have been offset through carbon credits generated by the contribution to the conservation and protection of 643 m² of growing forests within the Madagascar project" via a LifeGate partnership (p.123) — a minor voluntary initiative, not a reported E1-7 metric (see E1-7).

E1-9(was E1-7)GHG removals and GHG mitigation projects financed through carbon credits
Not Material
E1-10(was E1-8)Internal carbon pricing
Not Material
E1-11(was E1-9)Anticipated financial effects from material physical and transition risks and potential climate-related opportunities
Omitted

S1 – Own Workforce

S1-1Policies related to own workforce
Reported

Policies related to own workforce

Reference: pages 127-131.

doValue's Code of Ethics "expressly prohibits any type of activity that may involve the exploitation or enslavement of any individual, as well as any form of exploitation of child labour" (p.129), and the Group joined the UN Global Compact. Country-level trade-union dialogue runs through dedicated intranet sections (Italy), Works/Health-and-Safety/Equality Committees (Spain), periodic meetings (Cyprus) and recognised collective bargaining (Greece) (pp.127-128). Health and safety is governed locally (Italian Legislative Decree 81/2008; Spain's Occupational Risk Plan; Cyprus's ISO-45001-aligned OHS system; Greece's externally managed OHSMS) (pp.128-129). A Group D&I Policy, approved by the Board in September 2023, targets discrimination on gender, age, ethnicity, religion, orientation and more; a 2024 Anti-Harassment Policy and a Spanish Equality Committee/Equal Opportunity Plan reinforce it (pp.129-131).

S1-2Processes for engaging with own workforce and workers' representatives about impacts
Reported

Processes of involvement of own workforce and of workers' representatives with regard to impacts

Reference: pages 131-132.

Engagement with employees is channelled through the same mechanisms described under SBM-2 (Town Halls, Quarterly People Meetings, performance-review dialogue, People Partner meetings, intranet/email communication, Breakfast with Management, Buddy Program) plus structured trade-union consultation on strategic, structural and human-resources matters, formalised country by country (see S1-1, pp.127-128).

S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concerns
Reported

Processes to remedy negative impacts and channels that allow own workers to raise concerns

Reference: pages 136-137.

"Although the double materiality analysis did not identify negative impacts relating to its own workforce", doValue maintains reporting channels in each country — Italy's intranet-based reports, Cyprus's staff meetings/focus groups/HR booths, Greece's formalised negative-impact process compliant with EU Directive 2019/1937, and Spain's dedicated mailboxes plus satisfaction-survey follow-up (p.136). Group-wide, the Whistleblowing Policy, Code of Ethics and Anti-Harassment Policy set the escalation framework, with local managers (Health & Safety in Italy, HR in Greece, joint committees in Spain) assigned ownership of cases (p.137).

S1-3(was S1-4)Taking action on material impacts on own workforce
Reported

Interventions on relevant impacts for own workforce

Reference: pages 137-140.

Work-life balance: welfare spend rose from >€7.34 million (2024) to €12.154 million (2025), driven mainly by the Gardant integration, and a new smart-working union agreement was signed at end-2025 (p.137). Country benefits include mixed-use company cars, housing support, supplementary pension contributions, health/accident insurance and flexible-benefit platforms in Italy; healthcare, EAP counselling and an 18-week parental-leave extension in Spain; gym/health benefits and stress-management programmes in Cyprus; and flexible/hybrid schedules plus EAP support in Greece (pp.137-139). Training: a Training Committee (established 2022) runs an annual needs survey feeding a Training Programme reviewed by the Executive Committee (pp.139-140).

S1-4(was S1-5)Targets related to own workforce
Reported

Targets related to own workforce

Reference: page 146.

"As of the reporting date, the doValue Group has not identified specific quantitative targets relating to its own workforce and has not established a date by which to adopt them" (p.146). Instead, the 2024-2026 Business Plan's "For people" pillar sets nine qualitative commitments: D&I programmes, UN Global Compact membership, a 70%-participation Great Place to Work survey, Bloomberg gender-parity certification, university partnerships, ESG Ambassadors, annual training plans, a Group philanthropic plan and ESG training for new hires (p.146).

S1-5(was S1-6)Characteristics of the undertaking's employees
Reported

Characteristics of the undertaking's employees

Reference: page 146.

Headcount by country (2025 vs 2024): Italy 1,219 (905), Spain 471 (503), Greece 986 (951), Cyprus 396 (395). Group total 3,072 employees, up 11.5% year on year; women are 56.1% of the Group (p.146).

S1-6(was S1-7)Characteristics of non-employee workers
Reported

Characteristics of non-employee workers in the undertaking's own workforce

Reference: page 148.

"The organisation also employs 314 external collaborators, who are not employees" — mainly consultancy, external maintenance, temporary interim and intern roles. By country (2025 vs 2024): Italy 6 (8), Spain 7 (13), Greece 295 (234), Cyprus 6 (6), counted on a headcount basis at period end (p.148).

S1-7(was S1-8)Collective bargaining coverage and social dialogue
Reported

Collective bargaining coverage and social dialogue

Reference: pages 149-150.

Italy, Spain and Greece: 100% collective-bargaining coverage in 2025 (Greece up from 99.20% in 2024); Cyprus: 38.64% (down from 43.04%) (p.150). Italy's notice period for significant organisational change is 45 days, Greece's 2-4 weeks, and the minimum elsewhere one week per local trade-union agreement (p.150). Only Spain reports workers'-representative coverage, at 100%; data is unavailable for Italy, Cyprus and Greece (p.150). The Group has no European Works Council or SE/SCE works council agreement (p.150).

S1-8(was S1-9)Diversity metrics
Reported

Diversity metrics

Reference: page 149.

Top-management gender split, 2025 (2024): Italy 20 (13) — 75.00% men / 25.00% women; Spain 8 (8) — 75.00% men / 25.00% women; Greece 18 (16) — 61.11% men / 38.89% women; Cyprus 7 (8) — 71.43% men / 28.57% women (p.149). Age-band distribution by country (under 30 / 30-50 / over 50) is also tabulated (p.149).

S1-9(was S1-10)Adequate wages
Reported

Adequate wages

Reference: page 151.

"All employees of the doValue Group receive an adequate salary, in line with national collective agreements" (p.151); no shortfall against minimum-wage or collective-bargaining floors is reported.

S1-10(was S1-11)Social protection
Reported

Social protection

Reference: page 150.

"All employees of the doValue Group are covered by social protection against loss of income due to illness; unemployment, work-related injuries and acquired disabilities; parental leave and retirement, in all countries in which the Group operates, regulated by current local regulations" (p.150).

S1-11(was S1-12)Persons with disabilities
Reported

Persons with disabilities

Reference: page 149.

"In 2025, 83 people (48 women and 35 men) employed by the Group belong to protected or vulnerable categories, equal to 2.72% of the total company population" (p.149), up from smaller shares in 2024 across Italy, Spain, Greece and Cyprus (country table, p.149).

S1-12(was S1-13)Training and skills development metrics
Reported

Training and skills development metrics

Reference: pages 152-153.

Evaluation coverage in 2025: 57 top managers (18 women, 39 men), 779 middle managers (358 women, 421 men) and 2,105 staff (1,302 women, 803 men) received performance reviews (p.152). Total training hours rose from 65,497 (2024) to 81,042 (2025); average hours per person were 27.59 for men and 25.43 for women (p.153).

S1-13(was S1-14)Health and safety metrics
Reported

Health and safety metrics

Reference: pages 154-155.

Work-related injuries rose from 8 to 11 among employees and 2 to 4 among non-employees, with five of the 2025 incidents being commuting accidents (p.154). No occupational diseases were recorded among employees or non-employees in 2025, down from 4 and 2 respectively in 2024 (p.154). Days lost to work-related injury or illness rose from 244 to 427 for employees and held at 24 for non-employees (p.155).

S1-14(was S1-15)Work-life balance metrics
Reported

Work-life balance metrics

Reference: page 155.

"All employees of the doValue Group have the right to take leave for family reasons." Uptake by gender and country, 2025 (2024): Italy 14 men/67 women (51/141); Spain 22 men/13 women (36/71); Greece 68 men/249 women (86/280); Cyprus 6 men/24 women (5/29) (p.155).

S1-15(was S1-16)Compensation metrics (pay gap and total compensation)
Reported

Compensation metrics (pay gap and total compensation)

Reference: pages 151-152.

Group gender pay gap: 26.66% (gross hourly pay, men vs women). By country: Italy 23.20%, Spain 24.68%, Greece 33.55%, Cyprus 25.21% (p.152). CEO pay ratio (highest-paid individual to median employee total annual remuneration): 57.44 in 2025, down from 59.48 in 2024 (p.152).

S1-16(was S1-17)Incidents, complaints and severe human rights impacts
Reported

Incidents, complaints and severe human rights impacts

Reference: page 156.

"During the year 2025, an incident of human rights violation was recorded in Spain, for which the Group sustained the payment of a fine" of €35,317.84, after a ruling recognised the employment nature of a relationship with an external professional; doValue Spain regularised social-security contributions and paid the reduced penalty under a facilitated procedure (p.156). The Group remedied 1 of 1 such cases in 2025 (zero in 2024). "In 2025, through the Whistleblowing Channel, no complaints were submitted by employees concerning human rights related issues", and no OECD National Contact Point reports were filed (p.156).

S2 – Workers in the Value Chain

S2-1Policies related to value chain workers
Reported

Policies related to value chain workers

Reference: pages 159-160.

The Group Code of Ethics extends to external parties — self-employed workers, suppliers, professionals and consultants — and "expressly prohibits any form of child or forced labour, as well as practices that might involve exploitation, enslavement, or degrading working conditions" (p.159). Supplier management runs on the Group Procurement Policy plus local vendor guidelines; Gardant applies its own Ciclo Passivo Policy requiring adherence to Model 231 and the Code of Ethics, with an ESG Questionnaire for higher-value supplies (p.159). doValue Spain additionally extends its Occupational Risk Prevention Plan and Sexual Protocol to supplier workers via its Supplier Approval Procedure (p.160).

S2-2Processes for engaging with value chain workers about impacts
Reported

Processes for engaging with value chain workers about impacts

Reference: pages 160-161.

Engagement is mainly indirect, through vendor qualification (Code of Ethics acceptance, legal/social/environmental compliance) and ongoing SLA-based performance monitoring (p.160). Spain's Equality Committee examines requests from workers employed by suppliers, including individual interviews for people with disabilities employed by third-party suppliers, supported by the ECDI and Acoge specialist networks (p.160-161). "The Group does not implement global framework agreements with international trade unions" on value-chain workers' rights (p.160).

S2-2(was S2-3)Processes to remediate negative impacts and channels for value chain workers to raise concerns
Reported

Processes to remediate negative impacts and channels for value chain workers to raise concerns

Reference: page 161.

"Although the double materiality analysis did not identify negative impacts relating to value chain workers", the Whistleblowing channel is open to them via the Group website and they are informed of it during onboarding; "once a concern or request is communicated to doValue, it is treated as if it had been raised directly by an internal staff member" (p.161). Spain additionally runs social dialogue with service coordinators and workers' representatives for remediation (p.161).

S2-3(was S2-4)Taking action on material impacts on value chain workers
Reported

Taking action on material impacts on value chain workers

Reference: pages 161-163.

Supplier vetting requires compliance with collective agreements, contribution regularity and standards such as SA8000 and ISO 14001 (p.161). In 2025 Spain took the most concrete action: outsourced service teams stopped operating from company offices to reduce unlawful-assignment risk and travel-related accident exposure, and a supplier addendum now incorporates Spain's own Equality Plan commitments plus new health/well-being requirements (pp.162-163). "Italy, Greece, and Cyprus did not implement any further actions regarding significant impacts on workers in the value chain" in 2025 (p.162). "The Group has not recorded any serious human rights issues or incidents in the supply chain" (p.163).

S2-4(was S2-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Targets related to value chain workers

Reference: page 163.

"The doValue Group has not currently defined objectives related to value chain workers aligned with the characteristics envisaged by the regulations" (p.163).

S4 – Consumers and End-users

S4-1Policies related to consumers and end-users
Reported

Policies related to consumers and end-users

Reference: pages 166-168.

Consumer protection runs through the Code of Ethics, local Codes of Conduct (Greece's CoC, Cyprus's Code of Conduct under the Arrears Management Directive and Consumer Protection Law) and dedicated whistleblowing channels for Code-of-Ethics or human-rights violations (p.166). Data protection follows GDPR under a Data Protection Policy governed by the Global DPO, covering identity verification, statutory response timeframes and full deletion including backups on request; "the Global DPO reports periodically to the Board of Directors on monitoring activities carried out, any data breaches, complaints received" (p.168). Spain operates Privacy by Default/by Design and Information Security policies with multi-channel complaint handling (p.167).

S4-2Processes for engaging with consumers and end-users about impacts
Reported

Processes for involving consumers and end-users with regard to impacts

Reference: pages 168-169.

"Although it does not currently have a formalised and homogeneous process at the Group level" for involving all consumer categories, doValue gathers feedback via surveys, a toll-free number, call centres and online platforms, mainly post-service and during recovery activity, with effectiveness judged on satisfaction rates and complaints analysis (p.168). A structured debtor-counterpart questionnaire also monitors External Network professionalism and consistency, feeding corrective action (p.169).

S4-2(was S4-3)Processes to remediate negative impacts and channels for consumers and end-users to raise concerns
Reported

Processes to remedy negative impacts and channels for consumers and end-users to express concerns

Reference: pages 169-171.

Complaints received rose from 8,334 (2024) to 11,049 (2025): Italy 1,058→1,420; Spain 1,101→1,962 (NPL-portfolio driven); Greece 6,087→7,571 (portfolio growth); Cyprus 88→96 (p.170). Channels include a toll-free number, dedicated Asset Manager email, written/web complaint forms and the Whistleblowing Portal (p.170). Unresolved complaints can escalate to the Banking and Financial Ombudsman (ABF) within 60 days, with doValue's Litigation Office responding to the ABF Technical Secretary within 30 days (pp.170-171).

S4-3(was S4-4)Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actions
Reported

Taking action on material impacts on consumers and end-users

Reference: pages 172-176.

Flagship actions: the Re-performing Loan programme restructures NPL terms (repayment extensions up to 40 years) to return debtors to good standing (p.173); Italy's Ready to Restart programme supports temporarily distressed debtors with tailored repayment paths and a public debt-settlement guide (pp.173-174); Greece's My e-servicing Portal and doResponsible Financial Centre (University-of-Piraeus-backed e-learning) extend digital self-service and financial education (pp.174-175); doValue joined the European Commission's NPL Advisory Panel (DG FISMA) in 2026 (p.175). On security, doValue Spain Servicing S.A. obtained ISO/IEC 27001:2022 certification in 2025 for its core servicing activities, with rollout continuing Group-wide (p.175).

S4-4(was S4-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities (consumers and end-users)

Reference: page 176.

"As of the reporting date, the Group has not formalised specific public quantitative targets related to consumers and end-users." Instead it monitors operational indicators — complaint volumes and average handling time, External Network quality/compliance KPIs, and IT-security/data-protection indicators such as data breaches and training completion (p.176).

G1 – Business Conduct

G1-1Business conduct policies and corporate culture
Reported

Business conduct policies and corporate culture

Reference: pages 178-181.

The framework rests on the Code of Ethics and Model 231 (updated September 2024), the AML Policy and Whistleblowing policies/procedures, applied to employees, corporate bodies, suppliers and commercial partners (pp.178-179). In 2025 the audit plan ran 10 Model-231-relevant audits across Italy (ex-Gardant), plus 3 more after doNext's merger into Master Gardant; overall internal control in Italy was assessed "adequate to address the underlying risks" (p.179). "The Group has not adopted a specific training policy on business conduct", but runs mandatory, risk-differentiated training on the Code of Ethics, Model 231 and Whistleblowing coordinated by People/Compliance (p.181). Corruption-sensitive-area mapping varies by country: 18 medium-low-risk functions in Italy; 6 company-wide risk areas in Spain; multiple functions in Greece and Cyprus (p.181).

G1-2Management of relationships with suppliers
Reported

Management of relationships with suppliers

Reference: pages 182-184.

No dedicated payment-terms procedure exists, but practice is 60 days from invoice date, end of month (p.182). Supplier selection runs pre-qualification (Code of Ethics, Model 231, Anti-Corruption Policy, DURC contribution regularity, DVR, SA8000/ISO 14001) → qualification (technical/commercial scoring) → vendor rating → continuous monitoring, with an ISO 37001 anti-corruption check that can trigger suspension or escalation to Top Management or the Governing Body for moderate/high risk (pp.182-183). Contracts carry an anti-corruption clause (p.183). Gardant applies its separate Ciclo Passivo Policy given its decentralised procurement (p.183); Spain's Supplier Approval and Engagement procedure screens for AML red flags and tax/social compliance (p.184).

G1-2(was G1-3)Prevention and detection of corruption and bribery
Reported

Prevention and detection of corruption and bribery

Reference: pages 185-186.

doValue runs a Group Anti-Corruption Policy certified to UNI ISO 37001:2016, with 2025 certification maintenance confirmed for the 2026-2028 cycle (p.185). An independent Supervisory Body oversees model effectiveness; the Board reviews the Anti-Corruption Management System annually (p.185). Training coverage of at-risk departments, 2025 vs 2024: Italy 30/30 (100%, unchanged); Spain 15/15 (100%, up from 8/8); Cyprus 12/12 (100%, up from 0/0 in 2024); Greece 0/14 (0%, unchanged from 0/7) (p.186). 2,349 hours of mandatory anti-corruption/AML training delivered in 2025 (1,262 doValue, 1,087 Gardant), covering 71% of the doValue population and 90% of Gardant's (p.186).

G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conduct
Reported

Targets related to business conduct

This FY2025 statement is prepared under the 2023 ESRS, where a standalone business-conduct targets requirement did not exist; the ground is instead covered by MDR-T and the 2024-2026 Business Plan metrics table.

The Plan's "Sustainable Governance" objectives explicitly tagged ESRS G1 (p.106) include "Maintain ISO 37001 certification" (tracked via the 2025-2028 recertification, see G1-3), "Provide continuous cyber security training to 100% of employees", "Provide privacy training to 85% of employees" (achieved, S4-1), "Implement AI in the e-procurement system" and "Integrate ESG ratings into the e-procurement system", each with a named monitoring metric (% employees trained, number of suppliers ESG-assessed) (p.106). The report carries the standard MDR-T caveat: "It is specified that the targets illustrated below do not fully comply with the requirements of the regulations (MDR-T)" (p.104). Effectiveness on the corruption-prevention sub-topic is also tracked year over year via training-coverage percentages and a zero-confirmed-corruption-cases outcome in both 2024 and 2025 (G1-3, G1-4, pp.186-187).

G1-4Incidents of corruption or bribery
Reported

Incidents of corruption or bribery

Reference: page 187.

"During 2025, similar to the previous year, there were no cases of corruption or legal disputes involving Group employees or commercial partners. As a result, no convictions or fines were imposed for violating the laws against active and passive corruption" (p.187).

G1-5Political influence and lobbying activities
Not Material
G1-6Payment practices
Reported

Payment practices

Reference: page 187.

Average days to pay an invoice, 2025 (2024): Italy 28 (34), Spain 60 (64), Greece 45 (60), Cyprus 7 (7, paid on receipt) (p.187). Payments aligned with standard terms, 2025 (2024): Italy 28.16% (31.05%), Spain 56.46% (62.64%), Greece 81.8% (47.69%), Cyprus 100% (100%) (p.187). Standard contractual terms are 60 days from invoice date at month-end (p.187).