Tietoevry

Finland|Software & IT Services|Reporting year:FY2025FY2024|Auditor: Deloitte Oy|View original report →

Sustainability statement, in full

The complete text of Tietoevry’s FY2025 sustainability statement is held here – 198 pages, captured from the published report. Every disclosure below also links to its own passage.

Value chain diagram – from the 2024 report (click to enlarge)

Tietoevry's value chain showing upstream suppliers, own operations (people, assets, processes), and downstream customers and societySource: Tietoevry 2024 annual report, p.82. View original →

ESRS 2 – General Disclosures

GOV-1The role of the administrative, management and supervisory bodies
Reported

The role of the administrative, management and supervisory bodies

Reference: page 69

Listed in the ESRS content index at page 69 (page 127).

The Board "is also responsible for guiding the company's sustainability strategy, overseeing sustainability target setting and the Sustainability Statement", for "assessing the effectiveness of Tieto's sustainability due diligence" and for "approving material IROs" (p.69). It draws sustainability expertise from Group Sustainability, which "regularly provides training to the Board on sustainability matters", and business-conduct expertise from Group Legal and Compliance, Corporate Risk Management and Internal Audit (p.69).

Composition (p.69). Two executive and eight non-executive members; 30% female and 70% male; gender diversity ratio 43%; 80% independent; two members and two deputy members elected by personnel. The 2024 diversity ratio was restated from 40% to 43% after a change in calculation methodology.

Committees (p.70). The Audit and Risk Committee (ARC) "oversees the sustainability reporting process" and receives regular reports from the General Counsel, the Whistleblowing Unit and Internal Audit. The Remuneration Committee prepares compensation proposals "including applicable ESG targets".

Management (p.70). Group Sustainability is led by the Chief Sustainability Officer, who reports to the CFO. The Sustainability Steering Group, chaired by the CSO, meets every two months and approves long-term sustainability plans and targets; major initiatives require CEO approval. Of the Group Executive Team, 18% are female and 82% male.

GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodies
Reported

Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodies

Reference: page 70

Listed in the ESRS content index at page 70 (page 127).

"Group Sustainability reports regularly to the Board on Tieto's due diligence, including its effectiveness and performance against targets linked to the company's material impacts, risks, and opportunities (IROs)." From 2025 "regular sustainability updates have also been added as a standing agenda item in the CEO's monthly review to the Board" (p.70).

Board updates in 2025 (two occasions, besides the monthly CEO reviews, p.70):

  • implications of the Tech Services divestment on the sustainability plan, reporting and organizational setup;
  • the revision of the double materiality assessment and its result, "including Board approval of the process and outcome";
  • review of due diligence activities on material IROs, covering process effectiveness and performance against targets;
  • the target development process and new targets for collective bargaining, freedom of association and social dialogue, corporate culture and protection of whistleblowers, and training and skills development.

ARC updates (four during 2025, p.70): review of the FY2024 Sustainability Statement, the DMA revision and outcome, internal quality control and risk management over the reporting process, and review of the FY2025 Statement. Whistleblowing reports reach the ARC twice a year, "with urgent or critical matters escalated on an ad hoc basis".

GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemes
Reported

Integration of sustainability-related performance in incentive schemes

Reference: page 70

Listed in the ESRS content index at page 70, and cross-referenced from the E1 chapter at page 94 (pages 127-128).

ESG metrics sit in the long-term incentive (LTI) plan for the CEO and Group Executive Team, not the short-term plan. "Tieto introduced ESG metrics in the LTI plan in 2022, and has continued this practice since then while also increasing the weighting of aggregated measures from 10% to 20% in 2023, maintaining a consistent split equally between two key metrics: SBTi-approved scope 1 and 2 GHG emission reduction target and increasing the share of female recruits" (p.70).

Target recalibration after the divestment (pp.70-71). The original SBTi-validated scope 1 and 2 target ran to 2026, so the trajectory was extended by one year to cover 2027 and rebased on 2024. Applying the extended trajectory initially produced a 40% reduction target for 2027, which "was subsequently revised to a 25% reduction from the 2024 baseline" after the Tech Services divestment and a move "from a highly ambitious to a more moderate trajectory".

First payout (p.71). "In 2025, the first ESG-linked reward was delivered based on the LTI 2022-2024 plan. Performance against the ESG metrics was as follows: the GHG reduction metric reached 147% of the set target, while the gender diversity metric achieved 72% of its target."

The 2026-2028 LTI plan retains a 10% weighting and extends the climate metric to cover scope 3 (p.94).

GOV-3(was GOV-4)Statement on due diligence
Reported

Statement on due diligence

Reference: page 71

Listed in the ESRS content index as "Statement of due diligence" at page 71 (page 127).

"Tieto conducts ongoing sustainability due diligence to assess IROs, aiming to mitigate harm and drive business opportunities. The company tracks progress continuously and addresses any significant negative impacts directly or collaboratively. Tieto prioritizes engagement with affected stakeholders, including vulnerable groups, as a vital part of evaluating its due diligence efforts." (p.71)

The required mapping of the core due diligence elements to paragraphs of the Statement is given as a table (p.71):

Core elementParagraphs in the Sustainability Statement
Embedding due diligence in governance, strategy and business modelGOV-1, GOV-2, GOV-3, SBM-3
Engaging with affected stakeholders in all key stepsGOV-2, SBM-2, IRO-1, MDR-P, MDR-T
Identifying and assessing adverse impactsIRO-1, SBM-3, MDR-A
Taking actions to address those adverse impactsMDR-A
Tracking the effectiveness of these efforts and communicationMDR-T

The datapoint is also flagged in Appendix B as deriving from SFDR indicator 13 of Table #1 (p.129).

GOV-4(was GOV-5)Risk management and internal controls over sustainability reporting
Reported

Risk management and internal controls over sustainability reporting

Reference: page 71

Listed in the ESRS content index at page 71 (page 127).

"Sustainability reporting is centrally managed by Group Sustainability within the CFO office in close collaboration with the financial reporting team and other relevant support functions, as well as the businesses." (p.71)

Risk approach. "In sustainability reporting, internal control is based on risk identification, analysis and a focus on the material risks identified. This approach is consistent with Tieto's internal controls framework. The main risks in Tieto's sustainability reporting process are data completeness and accuracy." (p.71) A governance model "clearly defines roles and responsibilities, ensuring accountability in data collection and reporting", and the capabilities needed to produce the disclosed information are embedded in the Group's common business processes.

Second-cycle improvements. "Internal and auditor insights from the first reporting cycle according to CSRD/ESRS have guided targeted improvements, ensuring a stronger control environment and supporting the continuous enhancement of reporting processes." (p.71)

Findings from the risk assessment and controls are fed back through regular reviews; Group Sustainability informs the Sustainability Steering Group about reporting risks and controls and reports to the ARC (p.71). The company does not quantify control deficiencies or state a maturity rating.

SBM-1Strategy, business model and value chain
Reported

Strategy, business model and value chain

Reference: page 72

Listed in the ESRS content index at page 72 (page 127).

Business model (p.72). Four businesses hold full operational responsibility: Tieto Tech Consulting, Tieto Banktech, Tieto Caretech and Tieto Indtech, supported by Group functions. Revenue by segment for 2025 was Tech Consulting EUR 789.2 million, Banktech EUR 585.7 million, Caretech EUR 232.7 million and Indtech EUR 270.1 million, with eliminations of EUR -25.5 million and a Group total of EUR 1,852.3 million (2024 restated: EUR 1,879.5 million; 2024 as reported: EUR 2,802.6 million including Tech Services of EUR 1,000.7 million).

Headcount by geography: Nordic countries 6,755, Europe other 4,699, Asia 3,320, North and South America 192, total 14,966 (p.72). Customers span around 90 countries, "with approximately 80% of its revenue coming from Finland, Sweden and Norway" (p.72).

Excluded sectors (p.72). "Tieto's strategy does not include products or services that would be banned in certain markets. Additionally, the company is not active, as defined by ESRS 2, in sectors associated with fossil fuels, such as coal, oil, gas, chemicals production, controversial weapons, or tobacco cultivation or production."

Value chain (p.73). Upstream covers third-party software providers, cloud, SaaS and AI technology providers, subcontractors and staffing agencies; own operations cover employees, software, leased facilities, intellectual property, tools and systems; downstream covers customers and society. Inputs, outputs and outcomes are described at pages 74-75.

Gap acknowledged (p.75). "Goals related to key products and service groups, customer categories, geographical areas and stakeholder relationships have not been assessed, as such goals have not been established at the Group level."

SBM-2Interests and views of stakeholders
Reported

Interests and views of stakeholders

Reference: page 76

Listed in the ESRS content index at page 76, and cross-referenced from S1, S2 and S4 (pages 127-128).

Five stakeholder groups are tabulated with purpose, channels and value created (p.76): employees and other personnel; customers and end-users; suppliers and business partners; investors, shareholders and analysts; and potential employees and students.

Channels (p.76). Annual engagement and pulse surveys, leadership dialogues, performance and development discussions and DEI initiatives for employees, plus "Collaborations with work councils and unions (European Work Council and other local collaborations)". Customers are reached through satisfaction surveys, joint planning and co-innovation. Suppliers through the Supplier Code of Conduct, sustainability assessments and audits. Investors through reporting, meetings and the AGM, and "a Capital Markets Day was arranged in 2025".

Outcomes fed back (p.76). "Dialogue with stakeholders informs Tieto's action plans for managing impacts, risks and opportunities." Customer feedback "has driven a renewed emphasis on the quality of service delivery"; "In 2025 the company conducted an investor survey, using the feedback to further improve transparency in communications."

Oversight rests with the Board, with Group Sustainability coordinating engagement (p.76). The disclosure does not report a separate Board-level summary of stakeholder views beyond the GOV-2 update cycle.

SBM-3Material impacts, risks and opportunities and their interaction with strategy and business model
Reported

Material impacts, risks and opportunities and their interaction with strategy and business model

Reference: page 77

Listed in the ESRS content index at page 77 and repeated under E1 (p.93), S1 (p.104), S2 (p.111), S4 (p.114), G1 (p.118) and the entity-specific topics (pp.122, 124).

Position (p.77). "The material risks and opportunities are predominantly rooted in its own operational activities, while the material impacts exert influence throughout its value chain. Negative impacts are typically found upstream or within Tieto's own operations, while positive impacts tend to occur downstream and in own operations." The company states plainly that "The company's material impacts, risks, and opportunities do not currently influence its strategy."

Changes from the 2023 assessment (p.77). "Circular economy and Collective bargaining and Freedom of association for workers in the value chain are no longer material to Tieto, while Training and skills development and Privacy for its own workforce were concluded to be material in the last assessment." Diversity for value chain workers was material in 2023 but was omitted from that year's published table; the company notes the omission was immaterial (p.79).

Material topics (p.77). Energy; climate change mitigation; climate change adaptation (risk only); gender equality and equal pay, diversity, training and skills development, secure employment, working time and work-life balance, collective bargaining and freedom of association, and privacy for own workforce; diversity and gender equality for value chain workers; privacy for consumers and end-users; corporate culture, protection of whistleblowers, prevention and detection of corruption and bribery, and corruption and bribery incidents; and the entity-specific topics cybersecurity and AI.

Not material (p.77): pollution (7 subtopics), water and marine resources (5 sub-subtopics), biodiversity and ecosystems (3 subtopics), affected communities (11 sub-subtopics), and further sub-subtopics under own workforce (7), value chain workers (16), consumers and end-users (8) and business conduct (3).

Full impact and financial materiality tables, with value chain position and time horizon per IRO, run to pages 78-80. "During the reporting period, Tieto's material risks and opportunities did not have a material effect on the company's financial position, financial performance, or cash flows" (p.81).

IRO-1Description of the processes to identify and assess material impacts, risks and opportunities
Reported

Description of the processes to identify and assess material impacts, risks and opportunities

Reference: page 82

Listed in the ESRS content index at page 82, with topic-specific IRO-1 descriptions at pages 83 (E1, E2, E3) and 84 (E4) (page 127).

History and 2025 revision (p.82). The first DMA was conducted in 2023 and defined the FY2024 reporting scope. "It was updated in spring 2025, primarily following the announced divestment of the Tech Services business on 23 March, which was concluded on 2 September 2025."

Method (p.82). Value chain mapping, contextual analysis of industry trends, frameworks, legislation and peer benchmarking, plus inputs from the TCFD and TNFD analyses, performance data, human rights risk assessments, diversity metrics, employee survey results and ESG risks from the GRC platform. Assessment was at Group level "with input gathered separately from each of Tieto's four businesses", each of which "assessed every ESRS sub-subtopic from both an impact and financial materiality perspective".

Thresholds and scoring (p.82). "In 2025, Tieto conducted a comprehensive review of its scoring system... No changes were made to the scoring parameters." Quantitative financial thresholds were developed with Group Risk Management. Thresholds set in 2023 were tested by sensitivity analysis and kept. The company discloses that judgement overrode the thresholds in both directions: "certain topics that did not meet the thresholds... were still included", while "some topics that exceeded the thresholds were excluded following the same dialogue".

Granularity change (p.82). "In contrast to 2023, this year's assessment involved a more granular evaluation of both impact and financial materiality at the sub-subtopic level", and the ESRS 1 short, medium and long-term horizons replaced the single 0-5 year horizon used in 2023.

Approval (p.83). "The result of the company's double materiality assessment was reviewed by the ARC and formally approved by the Board in September 2025", with the next evaluation scheduled for Q2 2026.

IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statement
Reported

Disclosure Requirements in ESRS covered by the undertaking's sustainability statement

Reference: page 84

The concordance itself is printed as "Disclosure of list of ESRS Disclosure Requirements complied with in preparing Sustainability Statement following outcome of materiality assessment (ESRS 2 IRO-2)" at pages 127-128, with the Appendix B datapoint table at pages 129-132.

"The material impacts, risks and opportunities disclosed are the outcome of Tieto's double materiality assessment conducted during 2025. The assessment covered all sustainability matters included in the topical ESRS (ESRS 1 AR16) and entity-specific topics, of which cybersecurity and AI were confirmed to remain material for Tieto." (p.84)

"For Tieto's entity-specific topics SBM-3, MDR-P, MDR-A, MDR-T and MDR-M have been disclosed in the statement." (p.84)

What the index covers. ESRS 2 (BP-1, BP-2, GOV-1 to GOV-5, SBM-1 to SBM-3, IRO-1, IRO-2) plus EU Taxonomy; E1-1 to E1-8; E2, E3 and E4 by IRO-1 only; S1-1 to S1-6, S1-8, S1-9, S1-16 and S1-17; S2-1 to S2-5; S4-1 to S4-5; G1-1, G1-3, G1-4 and the MDR-T and MDR-A business conduct rows; and the entity-specific cybersecurity and AI blocks under SBM-3, MDR-P, MDR-A and MDR-T (pp.127-128).

Not covered. E1-9 is marked "Phase-in, not reported" in Appendix B (p.130). E2-4, E3, E4-2, E5-5, S1-14 and S3 datapoints are marked "Not material" (pp.129-132). Neither E5 topical disclosures nor S3 disclosures appear in the index.

E1 – Climate Change

E1-1Transition plan for climate change mitigation
Reported

Transition plan for climate change mitigation

Reference: page 92

Listed in the ESRS content index at page 92 (page 127).

"Tieto's climate transition plan (CTP) sets out the company's strategic roadmap for reducing its greenhouse gas emissions and aligning its operations with a low-carbon and climate-resilient economy. The plan presents the company's ambition to achieve net zero in its own operations and throughout its value chain by 2040." It "aligns with the Paris Agreement objectives, the EU Green Deal, and the requirements of the Corporate Sustainability Reporting Directive (CSRD)" and follows SBTi methodologies (p.92).

Targets (p.92). After the Tech Services divestment the company applied for and obtained new SBTi-validated near-term, long-term and net-zero targets covering scopes 1, 2 and 3. "The target year for near-term targets is 2034, and the long-term and net-zero target year is 2040. The baseline for the scope 1 and 2 targets is 2022 and for the scope 3 target it is 2024. All reduction targets have been validated and approved by the Science Based Targets initiative (SBTi) and are aligned with limiting global warming to 1.5°C."

Levers (p.92). Transition "to 100% renewable energy sources across its operations" via renewable heating and cooling and certified electricity (RECs/GoOs); building energy-efficiency measures; energy-efficient devices and IT optimization; electrification of the vehicle fleet; business travel mitigation; and supplier engagement, with "supplier selection includes criteria to prioritize partners that demonstrate clear commitments to reducing their CO2 footprint" since 2024.

Locked-in emissions (p.92). "A significant share of locked-in emissions relates to third-party data centres and cloud service providers, which typically have long asset lifespans and high electricity demand", together with diesel backup generation, refrigerants, facility infrastructure in fossil-dependent grids, and ICT equipment production.

Stated limitation (p.93). "While the current transition plan addresses key decarbonization levers and governance, it does not yet include a detailed breakdown of financial investments or funding mechanisms." Approval sits with the Sustainability Steering Group and the CEO (p.92). "Tieto is included in EU Paris-aligned benchmarks" (p.93).

E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysis
Reported

Identification of climate-related risks and scenario analysis

Back-filled from ESRS 2 IRO-1, where this content is disclosed in the FY2025 report (page 83), and from the E1 chapter's SBM-3 section (page 93). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

Reference: page 83

Risk classification (p.93). Risks are split explicitly: "Identified physical risks include potential electricity supply interruptions or operational disruptions caused by extreme weather events. Transition risks primarily relate to increasing renewable energy costs, as demand is expected to outpace supply in the medium term. These transition risks were evaluated in accordance with the TCFD classification of climate-related transition categories."

Scenarios used (p.83). Three, drawn from the TCFD analysis carried out during 2022-2023:

  • IEA Net Zero Emissions (NZE) 2050 - "advanced economies reach net-zero emissions by 2035, with 90% of electricity coming from renewable sources by 2050. The key risk identified for Tieto in this scenario is related to carbon pricing, renewable energy cost and alignment with evolving regulations."
  • RCP 8.5 - "high levels of carbon emissions leading to over 4°C global temperature rise by the end of the century", presenting "substantial physical risks to facilities and disruptions in its supply chain."
  • RCP 4.5 - "a peak of emissions around 2040, with global warming stabilizing between 2°C and 3°C."

So a high-emission physical scenario and a 1.5°C-aligned transition scenario are both named, and a temperature projection is given for each.

Methodology and exposure (p.83). Physical risks in operating countries "were assessed using the INFORM Risk Assessment model. It uses RCPs and Shared Socioeconomic Pathways (SSPs) projections to evaluate hazards, vulnerability and a country's ability to cope with crises. Exposure to physical hazards was identified on a country-by-country scale in countries where Tieto has operations. Each location was assigned a risk value that corresponds to a hazard risk class, ranging from very low to very high." Projections "forecast climate risks up to 2050 and 2080".

Timing (p.83). The TCFD analysis dates from 2022-2023 and was not refreshed this year: "TCFD analysis will be conducted during 2026." Horizons applied are short-term 0-2 years, medium-term 2-7 years and long-term 7-30 years (pp.68, 93).

E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate change
Reported

Resilience in relation to climate change

Back-filled from ESRS 2 SBM-3, where this content is disclosed in the FY2025 report (pages 80 and 93). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.

Reference: page 93

The analysis and what it covered (p.93). "The climate resilience analysis, based on the TCFD-aligned scenarios conducted in 2023, integrated planned mitigation actions and assessed the financial, technological, and organizational resources required for their implementation. Measures such as renewable energy sourcing, energy-efficiency improvements, and Scope 1 and 2 transition pathways were evaluated for their ability to reduce exposure to climate-related risks."

Scope is stated with an explicit exclusion: "In its resilience analysis, Tieto screened its activities to identify potential future GHG emission sources, excluding only a full value-chain evaluation for Avega, Bekk, Evry India and Evry USA." (p.93)

Result (p.93). "While core operations remain resilient across scenarios, uncertainties related to regulatory changes, technological development, and supplier-level data have been considered in strategic planning."

Areas of uncertainty (p.93). Regulatory change, technological development and supplier-level data, all of which "will be reassessed as more granular data becomes available". Emerging technology is named as a live uncertainty: AI "may increase energy demand and thus pose a potential risk to energy efficiency and emission reduction performance."

Capacity to adjust (pp.80, 93). "The outcomes of these assessments are integrated into Tieto's strategic planning and investment decision-making processes. Climate-related risks and opportunities are regularly reviewed as part of enterprise risk management and inform capital allocation, particularly in relation to energy procurement, infrastructure investments, and technology development." At page 80 the company adds that after the divestment "Although Tieto no longer operates its own data centres, the company addresses indirect impacts and dependencies across digital infrastructure."

Caveat. The underlying scenario work dates from 2022-2023 and the report states the TCFD analysis "will be conducted during 2026" (p.83), so the resilience conclusion was not refreshed in the reporting year. Under the adopted ESRS AR 9 a resilience analysis need not be annual, so this is disclosed timing rather than a gap.

E1-4(was E1-2)Policies related to climate change mitigation and adaptation
Reported

Policies related to climate change mitigation and adaptation

Reference: page 94

Listed in the ESRS content index at page 94 (page 127).

"The fundamental principles regarding climate change mitigation and adaptation are set out in Tieto's Supplier Code of Conduct and its Code of Conduct. The company further defines its commitment and sets the foundation for its environmental and climate-related work in its publicly available Environmental Policy." (p.94)

Scope and alignment (p.94). "The policy confirms Tieto's alignment with key global frameworks, including the United Nations (UN) Global Compact, UN Sustainable Development Goals, the ISO 14001 EMS and SBT." Objectives include "compliance with applicable environmental laws and regulations, pollution prevention, promoting environmental awareness and contributing to the development of sustainable societies and businesses in collaboration with relevant stakeholders."

The policy "sets out principles addressing the topics of Energy, Climate change mitigation and Climate change adaptation. These include leadership commitment, enhanced process approach, environmental protection, active engagement and striving for continuous improvement." (p.94)

Review in the reporting year (p.94). "The Environmental Policy is reviewed annually. The review process considers stakeholder interest consideration through benchmarking, stakeholder interviews, and active dialogue with experts. In 2025, the review focused particularly on the implications of the Tech Services business divestment. This resulted in minor adjustments to the policy; the core principles underpinning the company's climate actions remain unchanged."

Accountability and reach (p.94). The policy "applies to all Tieto companies and employees globally, as well as to companies under Tieto's control". Content is made available "through a mandatory e-learning module in Tieto Essentials", and "The responsibility for implementing the Environmental Policy lies with the Chief Sustainability Officer."

E1-5(was E1-3)Actions and resources in relation to climate change policies
Reported

Actions and resources in relation to climate change policies

Reference: page 94

Listed in the ESRS content index at page 94 (page 127).

Quantified expected effects of the levers (p.94). "Renewable energy procurement is expected to reduce scope 2 emissions by 379 t CO2e from the 2024 level by 2034. Supplier engagement and selection of low-emission suppliers aim to cut upstream scope 3 emissions by 50 634 t CO2e by 2034. Shifting employee commuting and business travel to electric vehicles and public transportation is projected to reduce scope 1 and 3 emissions by 642 t CO2e and 124 t CO2e, respectively. Finally, leasing only electric vehicles for operations is expected to lower upstream scope 3 emissions by 1 297 t CO2e."

What was actually done in 2025 (p.94). Renewable energy purchasing and office consolidation delivered "a greenhouse gas (GHG) emission reduction of 143 tCO2e in own operations (scope 1 and 2)", with the renewable electricity share at 95%. Energy-efficiency work covered workspace optimization, energy inspections, electrical equipment upgrades, building automation and lighting. "Additional progress included upgrading the LEED certification of Tieto's head office to platinum level and relocating the Oslo office to more modern and energy-efficient facilities."

Business travel emissions "were reduced by 504 tCO2e, as a result of continued promotion of hybrid working practices and reinforcement of Tieto's Travel Rule" (p.94).

Management system (p.94). Major offices operate under an ISO 14001 certified global Environmental Management System, "externally audited annually". "During 2025, four additional sites were brought under Tieto's global certification following successful scope extension audits, and 43 internal EMS audits were conducted."

Forward actions (p.95). Carbon compensation from Gold Standard projects for Norway operations; preparation to use carbon removal credits toward carbon neutrality in own operations by 2026; targets for climate change adaptation to be set during 2026; and investigation of an internal carbon pricing scheme in 2026.

Resources (p.95). "Tieto's action plan for the material impacts, risks and opportunities did not require any significant operational expenditure (Opex) or capital expenditure (Capex) for the financial year 2025."

E1-6(was E1-4)Targets related to climate change mitigation and adaptation
Reported

Targets related to climate change mitigation and adaptation

Reference: page 95

Listed in the ESRS content index at page 95 (page 127). Two target tables are printed at page 96.

Current SBTi-validated targets, approved 2025 (pp.95-96). Absolute reduction targets across all scopes: scope 1 and 2 (market-based) down 69% by 2034 and 90% by 2040 from a 2022 base of 2,179 tCO2e; scope 3 down 59% by 2034 and 90% by 2040 from a 2024 base of 98,393 tCO2e; and a net-zero target across the value chain by 2040 against a combined 100,572 tCO2e baseline. "All reduction targets have been validated and approved by the Science Based Targets initiative (SBTi) and are aligned with limiting global warming to 1.5°C."

Progress against them (p.95). "Within scopes 1 and 2, the company achieved an 60% reduction in GHG emissions (market-based) compared with the 2022 base year. For scope 3, the company reported a 6% reduction compared with the 2024 base year." Total value chain emissions were 92,986 tCO2e in 2025 against a 2024 base of 99,399 tCO2e.

Previous SBTi targets, approved 2022, still reported for comparability (pp.95-96). 90% absolute scope 1 and 2 reduction by 2026 from a 2020 base of 10,042 t: 88% in 2025 (2024 restated 86%). 100% renewable electricity by 2026: 95% (96%). 47% reduction in business travel emissions per FTE by 2030: 54% (55%). 70% of suppliers with SBTs by 2026: 41% (40%).

Deterioration explained (p.95). "The share of renewable electricity decreased from 99% to 95%, primarily due to the exclusion of data centre operations previously powered by 100% renewable electricity related to the divestment of the Tech Services business." "The supplier engagement SBT result declined to 41% (46%) as the divestment... led to the removal of suppliers with higher SBT adoption rates from the reporting scope."

Additional target (p.96). 100% annual completion of the environmental e-learning, excluding the subsidiary Bekk; the 2025 result was 97%. "Measurements of the environmental training target are not validated by any external body other than through external assurance."

Adaptation is not yet covered by a target: the company "is preparing to set targets for this area during 2026" (p.95).

E1-7(was E1-5)Energy consumption and mix
Reported

Energy consumption and mix

Reference: page 98

Listed in the ESRS content index at page 98 (page 127). Appendix B maps paragraph 37 to SFDR indicator 5 of Table #1 (p.129) and marks the high-climate-impact-sector datapoints (paragraphs 38 and 40-43) "Not material" (p.129).

2025 result (p.98). "In 2025, energy consumption in Tieto's own operations (Scope 1 and 2) decreased by 11% from 2024 to 23,953 MWh (2024: 27,056 MWh). The key drivers behind these changes include factors such as reduced and optimized office floor area, operational energy-efficiency measures and improved building management, optimization of ventilation and heating schedules, and targeted equipment upgrades."

Metric (MWh unless shown)20252024 restated2024
Crude oil and petroleum products268340608
Natural gas6300
Purchased electricity, heat, steam, cooling from fossil sources3,2714,5108,076
Total fossil energy3,6024,8508,684
Share of fossil sources15%18%10%
Nuclear24515010,930
Total renewable energy20,10622,05663,932
Share of renewable sources84%82%77%
Total energy consumption23,95327,05683,546

Effect of the divestment (p.98). "When comparing figures for 2024 before and after the divestment, total energy consumption in own operations (scope 1 and 2) decreased by 68%. This reduction is primarily attributed to the removal of data centre energy use." "Nuclear energy consumption was 99% lower following the removal of the data centre cooling agreement from the scope."

The fossil share rose against the unrestated 2024 figure "mainly because the excluded data centre operations were powered by 100% renewable electricity and therefore no longer contribute to the energy mix", with office heating still partly fossil (p.98). No energy intensity per net revenue is given, consistent with the "Not material" flag on the high-climate-impact-sector datapoints.

E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissions
Reported

Gross Scopes 1, 2, 3 and Total GHG emissions

Reference: page 99

Listed in the ESRS content index at page 99 (page 127).

tCO2e20252024 restatedChange2024 as reported
Gross scope 18487-3%158
Gross market-based scope 1 and 28631,006-14%8,094
Gross location-based scope 24,0764,258-4%6,937
Gross market-based scope 2779919-15%1,157
Total scope 392,12398,393-6%163,204
Total (market-based)92,98699,399-6%164,519
Total (location-based)96,283102,738-6%170,299

Scope 3 is 99% of the market-based total. The largest categories in 2025 were purchased goods and services 73,979 tCO2e (-8%), business travel 6,096 (-8%), employee commuting 4,238 (+5%), upstream transportation and distribution 4,312 (-1%), capital goods 1,671 (+17%) and fuel and energy-related activities 1,181 (-5%) (p.99). "Percentage of scope 1 GHG emissions from regulated emission trading schemes" is 0 (p.99).

Intensity (p.100). Location-based 52 tCO2e/MEUR (2024 restated 55) and market-based 50 (53).

Method and data quality (p.100). GHG Protocol, operational control approach, IPCC AR6 100-year GWPs. "The share of value chain emissions calculated using primary data obtained from suppliers or other value chain partners is 11% (<5%), while the remaining share is based on estimates." The purchased goods and services factor set moved from EPA to "EXIOBASE database version 3.10.1", which "provides a more comprehensive representation of emissions associated with Tieto's global procurement activities". Scope 2 market-based rests on GoOs and RECs: "During 2025 Tieto purchased bundled (16%) and unbundled (55%) Energy Attribute Certificates (EACs)... which in total covered 71% of scope 2."

Categories 9, 10, 11, 13, 14 and 15 are stated not material, each with a reason (p.101).

E1-9(was E1-7)GHG removals and GHG mitigation projects financed through carbon credits
Reported

GHG removals and GHG mitigation projects financed through carbon credits

Reference: page 102

Listed in the ESRS content index at page 102 (page 127).

"In 2025, Tieto cancelled carbon credits corresponding to 1 159 metric tCO2e of voluntary reduction credits to offset emissions related to operations in Norway. 100% of these carbon reduction credits were purchased from two Gold Standard programme projects in India. The projects generate electricity through sustainable means, using solar power and wind power resources, and are annually monitored and third-party verified." (p.102)

The two projects are "Renewable energy project (wind power generation) with distribution within the Indian power grid" and "Renewable energy (solar power generation) projects in selected Indian states" (p.102).

Integrity controls (p.102). "All credits are issued following an annual monitoring and verification process, and 10% of all credits are pooled into a buffer account. If any reversals occur in the projects, the carbon losses are covered through the cancellation of an equivalent number of buffer credits from the buffer pool. The carbon credits have been issued in accordance with the relevant standard's protocols and are recorded in the registry to prevent double counting or double selling. The serial number of the credits cancelled is available. No adjustments have been issued for these carbon credits."

Removals (p.102). These are reduction credits, not removals: "In 2025, the company did not purchase any carbon removal credits. Tieto aims to prioritize direct emission reductions and, for the remaining residual emissions (targeted less than 10%), to use high-quality carbon removal solutions consistent with the requirements of ESRS E1." The company is "preparing to compensate emissions related to its own operations with carbon removal credits as a part of its commitment to achieving carbon neutrality in own operations by 2026" (p.95). No own GHG removals or storage projects are reported.

E1-10(was E1-8)Internal carbon pricing
Reported

Internal carbon pricing

Reference: page 102

Listed in the ESRS content index at page 102 (page 127).

This is a nil return, and a complete one. "Tieto does not currently apply internal carbon pricing. However, in 2026 Tieto will explore options for the introduction of an internal carbon pricing mechanism to guide operational decision-making towards lower greenhouse gas emissions as well as to support emission reduction initiatives across all businesses." (p.102)

The intention is repeated in the E1-3 forward-looking actions: "Tieto is also investigating the introduction of an internal carbon pricing scheme for the company during 2026 to support internal GHG emission reduction efforts within the company." (p.95)

Because no scheme exists, no carbon price, type of scheme, scope of application or share of emissions covered is disclosed, and none is required.

E1-11(was E1-9)Anticipated financial effects from material physical and transition risks and potential climate-related opportunities
Omitted

S1 – Own Workforce

S1-1Policies related to own workforce
Reported

Policies related to own workforce

Reference: page 105

Listed in the ESRS content index at page 105 (page 128).

Four policies are described: the Human Rights Policy, the Code of Conduct, the Human Resources Policy and the Health and Safety Policy (p.105).

Human Rights Policy (p.105). Aligned with the UN Guiding Principles, the OECD Guidelines and the UN Global Compact, "to which Tieto is a signatory". Core components are "accountability for human rights across the value chain, regular human rights due diligence, performance tracking and transparent communication of progress". "The policy is approved by the CEO, while the Chief Financial Officer is responsible for its implementation."

Code of Conduct (p.105). Reinforces commitments "on topics such as freedom of association, health and safety, and fair employment", enforces "a robust non-discrimination policy which prohibits discrimination based on gender, identity, nationality, religion, race, age, disability, marital status, sexual orientation, political views, or union membership", establishes "zero tolerance for bullying, harassment, or violence, and strictly prohibits forced, compulsory, and child labour, including human trafficking". It applies to "all employees, Board members, subcontractors, and representatives globally", with mandatory annual training.

Human Resources Policy (p.105). Covers fair recruitment, equal treatment, well-being and compliance with labour laws; approved by the CEO, with the Group Executive Team accountable for implementation.

Health and Safety Policy (p.105). Promotes physical and mental health, includes hazard identification, training and emergency preparedness. "The Head of HR is responsible for implementing the policy, while the Head of Facility ensures that all company premises remain safe and compliant."

"All policies undergo annual updates, and significant revisions informed by benchmarking, stakeholder consultation, and engagement with employee unions." (p.105) Appendix B maps the S1-1 human rights, ILO due diligence, human trafficking and workplace accident prevention datapoints to S1-1 (p.131).

S1-2Processes for engaging with own workforce and workers' representatives about impacts
Reported

Processes for engaging with own workforce and workers' representatives about impacts

Reference: page 105

Listed in the ESRS content index at page 105 (page 128).

"Tieto engages both directly with its own workforce and through workers' representatives including through unions, employee representation committees, and work councils both locally and internationally (through the European Works Council)." (p.105)

Direct engagement (p.105). "Employee surveys are conducted multiple times a year to ensure a continuous dialogue within the company. Quantitative results are openly shared with all employees." Outcomes "are analyzed to assess employee satisfaction, work-life balance, and overall well-being. Based on these findings, policies and programmes are continuously adjusted."

Through representatives (p.105). "Regular local meetings with unions are held, in addition to specific meetings based on formal negotiation meetings set by local laws. Monthly meetings with the European Works Council (EWC) are conducted, including two in-person meetings per year."

Agreements with workers' representatives "facilitate regular communication and dialogue on human rights and labour rights, including working conditions and collective bargaining. By ensuring that employee representatives can perform their functions unhindered and without fear of retaliation, Tieto gains valuable insights into employee perspectives." A limit is stated plainly: "The company does not have a Global Framework Agreement in place." (p.105)

Accountability (p.105). "Responsibility for ensuring effective engagement lies with Human Resources (HR). The Head of HR, as the most senior accountable role, oversees the implementation of engagement initiatives and ensures that the insights gained from these processes inform Tieto's strategy process and decision-making."

S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concerns
Reported

Processes to remediate negative impacts and channels for own workforce to raise concerns

Reference: page 105

Listed in the ESRS content index as "Processes to remediate negative impacts and channels for own workers to raise concerns" at page 105 (page 128).

"Where Tieto identifies that it has caused or contributed to a material adverse impact on its workforce, appropriate and timely remediation measures are implemented. These may include investigation, mitigation, and corrective actions, with lessons learnt systematically leveraged to prevent recurrence." (p.105)

Channels (pp.105-106). "Direct reporting to line managers, HR partners, or the Group Compliance function, as well as a whistleblowing channel operated by an external service provider, enabling anonymous submissions. The whistleblowing channel is accessible to all employees and other workers across all countries and subsidiaries. All reports submitted through this channel are logged, independently investigated, and handled confidentially."

Escalation (p.106). "Severe or sensitive cases are escalated to the company's Escalation Committee, composed of the Head of Corporate Governance and Compliance, Head of Group Legal & Compliance, Head of Internal Audit, Head of HR, and the Group Compliance Officer. Investigation outcomes are reported to the ARC on a biannual basis or as otherwise required."

Effectiveness (p.106). Assessed "through indicators such as reporting rates, the proportion of anonymous cases, and response times. Employees also contribute to evaluating the level of trust and accessibility of the grievance and complaints mechanisms through the annual employee survey." A new survey question introduced in 2025 measures perceived safety in reporting misconduct; the 2025 score was 8.5 out of 10 (p.119).

Awareness is built "through onboarding, annual Tieto Essentials training, and internal communication, including local employee handbooks" (p.106).

S1-3(was S1-4)Taking action on material impacts on own workforce
Reported

Taking action on material impacts on own workforce

Reference: page 106

Listed in the ESRS content index as the fuller 2023 title at page 106 (page 128).

Freedom of association and social dialogue (p.106). "During the reporting year, Tieto actively facilitated the formation and strengthening of employee representation committees and work councils in all countries of operation. In countries where collective bargaining is not legally recognized, alternative forms of employee dialogue that comply with local legislation were reinforced." A new employee survey measure of "employees' perception of their ability to express opinions and participate in the representation structure" was introduced.

Working time and work-life balance (p.106). "Overtime data is monitored monthly at both team and unit levels through time-tracking systems, managerial reporting, and employee feedback. Trends are analysed to identify hotspots and take corrective action... Where excessive overtime is identified, managers are required to review workloads and redistribute tasks."

Gender equality and diversity (p.106). Key 2025 actions were improvements to HR Rules and employee handbooks on inclusive hiring, a relaunch of mandatory DEI training for managers, and a new Employee Resource Group, "the Rainbow Network,... launched in Finland", alongside existing groups Women@Tieto in Sweden and Norway and iLead in India. New partnerships with Tjejer Kodar in Sweden and Mothers in Business in Finland were initiated. "Starting from 2024, the global pay gap analysis is an integral part of the annual compensation and performance review process. In 2025, flagged disparities were addressed through targeted salary adjustments."

Training and skills (pp.106-107). Tieto Tech Consulting "established a foundational leadership programme for women (Women in Leadership - Tieto Tech Consulting Foundation Programme)". Learning content "is available in multiple formats and languages".

Resources (p.107). "Related costs are embedded in operating functions rather than tracked as separate Capex/Opex lines. Consequently, the action plan for S1 topics did not involve significant operational (Opex) or capital (Capex) expenditures during the 2025 financial year."

S1-4(was S1-5)Targets related to own workforce
Reported

Targets related to own workforce

Reference: page 107

Listed in the ESRS content index at page 107 (page 128).

Material topicTarget20252024 restated2024
Gender equality and equal pay33% of underrepresented gender in all board positions by 202630%30%30%
Gender equality and equal pay30% of underrepresented gender in leadership positions by 203028%28%25%
Gender equality and equal pay37% recruitment of female recruits by 202530%37%34%
Gender equality and equal payUnexplained gender pay gap below 5%1.9%2.5%2.6%
Diversity100% people managers trained in DEI annually87%86%86%
Working time and work-life balanceOvertime not exceeding 3% of normal average working time1%1%1%
Secure employment90% completion rate for manager-employee dialogues93%71%81%
Training and skills developmentScore of at least 8/10 in the annual employee survey7.9N/AN/A

Misses explained (p.108). On female recruitment: "2025 has been a particularly challenging year due to reduced recruitment volumes and the absence of a graduate programme, which has typically attracted more female candidates." On DEI training: the 100% target "was not fully reached in 2025... it overlapped with organizational restructuring programmes and other ongoing learning activities in some business areas".

New in 2025 (p.107). A training and skills development target, approved by the Sustainability Steering Group, and "a clear and outcome-oriented target to strengthen collective bargaining, freedom of association and social dialogue across all countries of operation". For the latter, "Target-related activities will be implemented during 2026 and performance against the target will be disclosed in the 2026 Sustainability Statement", so no 2025 result is given.

Method and scope (pp.107-108). Base year is 2024 for most targets; 2020 for female recruits (baseline 27%) and 2025 for training and skills (baseline 7.9). Scope exclusions are listed for senior management by gender (Avega, Bekk, EVRY India) and DEI training (Bekk). "Measurements of the targets are not validated by any external body except for the assurance providers, and no milestones or interim targets have been set."

S1-5(was S1-6)Characteristics of the undertaking's employees
Reported

Characteristics of the undertaking's employees

Reference: page 108

Listed in the ESRS content index at page 108 (page 128).

Headcount (p.108). Total employees 14,966 at end-2025, against 16,737 restated and 24,092 as originally reported for 2024. "As a direct result of the divestment, the total number of employees at year-end decreased by approximately 30%." By gender: male 9,812, female 5,141, other 13, not reported 0. "After the divestment, the percentage of females at Tieto increased to 34% in 2024 and 2025."

Turnover (p.108). "In 2025, Tieto recorded an employee turnover rate of 17%, of which 8% represented voluntary turnover. In total, 2 654 individuals left the company."

Contract type (p.109). Permanent 14,704 (female 5,046, male 9,645, other 13); temporary 262 (female 95, male 167); non-guaranteed hours 8 (female 3, male 5).

By country, where at least 50 employees (p.109). Norway 2,869, India 2,440, Sweden 2,151, Finland 1,672, Ukraine 1,356, China 869, Latvia 772, Poland 767, Czech Republic 641, Bulgaria 577, Austria 269, US 89, Paraguay 86, Serbia 86, Germany 81, Lithuania 72, Denmark 63, Estonia 61, Slovakia below 50.

Method (p.108). "Employee data is collected via Workday as well as through a manual process from subsidiaries not integrated in Workday. For new hires, turnover is calculated based on average headcount on the last day of the previous year and the last day of the reporting year... Assumptions are not used in the reporting related to metrics in S1-6." Sustainability Statement figures are headcount; financial statement figures are full-time equivalents (p.72).

S1-6(was S1-7)Characteristics of non-employee workers
Not Material
S1-7(was S1-8)Collective bargaining coverage and social dialogue
Reported

Collective bargaining coverage and social dialogue

Reference: page 109

Listed in the ESRS content index at page 109 (page 128).

"The percentage of total employees covered by collective bargaining agreements during 2025 was 42% (42%)." "The percentage of total employees covered by workers' representatives in the EEA during 2025 was 71% (66%)." (p.109)

Comparability limitation, stated openly (p.109). "The collective bargaining coverage and social dialogue (S1-8) data for 2024 was collected through decentralised inputs and was not captured by business affiliation. Consequently, Tech Services employees cannot be reliably identified or separated retrospectively without significant assumptions or manual reconstruction, which would compromise the faithful representation of the information. As a result, the 2024 figures include Tech Services employees, while the 2025 figures exclude them, affecting comparability between the periods. The Group considers the restatement of S1-8 comparative information to be impractical in accordance with ESRS requirements and discloses this limitation to provide transparency to users of the sustainability statement."

Coverage bands by country (p.109). For 2025 the 0-19% band covers Bulgaria, Czech Republic, Estonia, Germany, Latvia, Lithuania, Netherlands, Poland, Romania and Slovakia; 40-59% Denmark; 60-79% Poland; 80-100% Finland, France, Germany, Lithuania, Poland and Sweden. Workplace representation in the EEA is tabulated separately.

Context from SBM-3: "the majority of Tieto's operations are in areas where the risks of violations of freedom of association and collective bargaining are low (58%). However, 42% of operations are in areas where these risks are higher or not fully guaranteed" per the ITUC Global Rights Index, naming China, Ukraine, Poland, India and Serbia (p.104). A European Works Council agreement is in place (p.109).

S1-8(was S1-9)Diversity metrics
Reported

Diversity metrics

Reference: page 110

Listed in the ESRS content index at page 110 (page 128).

Top management (p.110). "The number of female executives in the GET increased from one to two, while the number of male executives rose from eight to nine, resulting in an overall expansion of the top management team. Consequently, the proportion of women at the top management level increased from 11% to 17%." The table shows 9 male (82%) and 2 female (18%) at top management level in 2025, against 8 male and 0 female restated for 2024 and 8 male and 1 female as originally reported. [uncertain: the narrative gives 17% and the table 18%, a rounding difference the report does not reconcile]

Age distribution (p.110). "employees under 30 years of age represented 16% of the total workforce, compared to 18% in the previous year. The proportion of employees aged 30 to 50 increased slightly to 64% from 62%, while those over 50 years of age accounted for 20%, compared to 21% last year." In headcount: under 30, 2,382; 30-50, 9,550; over 50, 3,034.

Method (p.110). "Data is collected from Workday in terms of headcount by the end of the year", with age distribution collected "from Workday and via Excel".

The related target, 30% of the underrepresented gender in leadership positions by 2030, stood at 28% in 2025 (p.107).

S1-9(was S1-10)Adequate wages
Not Material
S1-10(was S1-11)Social protection
Not Material
S1-11(was S1-12)Persons with disabilities
Not Material
S1-12(was S1-13)Training and skills development metrics
Not Material
S1-13(was S1-14)Health and safety metrics
Not Material
S1-14(was S1-15)Work-life balance metrics
Not Material
S1-15(was S1-16)Compensation metrics (pay gap and total compensation)
Reported

Compensation metrics (pay gap and total compensation)

Reference: page 110

Listed in the ESRS content index as "Remuneration metrics (pay gap and total remuneration)" at page 110 (page 128).

Metric20252024 restated2024
Remuneration ratio32%32%34%
Gender pay gap12%14%12%
Adjusted gender pay gap1.9%2.5%2.6%

Unadjusted gap (p.110). "In 2025, the unadjusted pay gap amounted to 12%, representing the difference in average annualized full-time salary between male and female employees, expressed as a percentage of the average annualized full-time salary of male employees."

Adjusted gap (p.110). "The adjusted gender pay gap evaluation framework compares compensation within specific peer groups based on country, business, and job profiles... In addition, the analysis factors in several key variables, such as employee work-life experience, tenure within the company and their current role, and supervisory responsibilities."

Remuneration ratio (p.110). "determined by comparing the annual remuneration of the highest paid individual to the median annual remuneration of other employees, excluding the highest-paid individual". Data comes from Workday and includes "annualized salary, incentives, and cash allowances", with benefits in kind from local HR teams and "the World Bank's latest Purchasing Power Parity (PPP) conversion factor" applied to allow cross-country comparison.

"The 2025 results were influenced by organizational changes during the year, including the appointment of a new CEO and the divestment of Tech Services, both of which affected the overall composition of the workforce and the resulting total remuneration ratio." (p.110)

S1-16(was S1-17)Incidents, complaints and severe human rights impacts
Reported

Incidents, complaints and severe human rights impacts

Reference: page 110

Listed in the ESRS content index at page 110 (page 128).

Metric20252024
Incidents of discrimination and harassment730
Complaints filed through Tieto channels for raising concerns4462
Fines, penalties and compensation for damages00

"During 2025, a total of 44 cases were submitted to HR partners and the Whistleblowing Unit. Out of these, the number of reported discrimination and harassment incidents amounted to seven for the reporting year. Out of these, two cases contained discrimination allegations (one on basis of nationality and one on gender), while five cases were harassment-related. Following due investigation, four incidents of harassment were confirmed and remediated, while the remaining cases are still subject to action." (p.110)

"No cases of severe human rights incidents - including forced labour, human trafficking, or child labour - were reported during the year. If such incidents had occurred, the company would have disclosed the number of cases and the extent to which they represented non-compliance with the UNGPs, the ILO Declaration on Fundamental Principles and Rights at Work, or the OECD Guidelines for Multinational Enterprises." (p.110)

Data collection (p.110). Through the Whistleblowing Unit and HR partners, consolidated at period end, with complaints channelled to OECD National Contact Points collected from Group Legal and Compliance. Appendix B maps the paragraph 103(a) and 104(a) datapoints to S1-17 (p.131).

S2 – Workers in the Value Chain

S2-1Policies related to value chain workers
Reported

Policies related to value chain workers

Reference: page 111

Listed in the ESRS content index at page 111 (page 128).

Four instruments are named: the Human Rights Policy, the Code of Conduct, the Supplier Code of Conduct and the Source to Pay Policy (p.111). "The commitments in the Human Rights Policy apply equally to Tieto's own employees and to workers across its value chain. In addition to the Human Rights Policy and the Code of Conduct, the Supplier Code is the key document that addresses impacts on value chain workers."

Supplier Code (pp.111-112). "The Supplier Code is fully aligned with applicable ILO conventions, covering the prohibition of forced and child labour, the right to freedom of association and collective bargaining, as well as explicitly opposing all forms of modern slavery, including human trafficking." It "mandates that employees must not face discrimination or harassment - neither physical, sexual, psychological, nor verbal - based on gender, nationality, religion, race, age, disability, sexual orientation, pregnancy, marital status, political opinion, union membership, social or ethnic origin, or any other status protected by local laws". "In situations where local laws conflict with the principles in the Supplier Code, the higher standard shall prevail."

A stated gap (p.111). "should Tieto acquire new businesses, existing supplier contracts do not initially include Tieto's Supplier Code. However, the Supplier Code is incorporated into all new contracts and during any contract renewals."

Review and accountability (p.112). "No significant changes to the Supplier Code have been adopted during the reporting year." "Responsibility for implementing the Supplier Code lies with Tieto's Group Chief Procurement Officer (CPO)." The Source to Pay Policy is also owned by the Group CPO, with all employees trained through a mandatory e-learning module in Tieto Essentials.

Appendix B maps the S2-1 human rights, ILO due diligence and UNGP/OECD datapoints to S2-1 (p.132).

S2-2Processes for engaging with value chain workers about impacts
Reported

Processes for engaging with value chain workers about impacts

Reference: page 112

Listed in the ESRS content index as "Processes for engaging with value chain workers" at page 112 (page 128).

The company is unusually direct about the limits of what it does. "Given that most of Tieto's value chain workers are several tiers removed, the company has limited influence over their rights to equal treatment and opportunities. While direct engagement may occur during on-site audits or targeted dialogues, no general process for interacting with value chain workers has been established. As a result, the company does not currently assess the effectiveness of such engagement." (p.112)

"The company has not yet undertaken efforts to understand the perspectives of workers who may be particularly vulnerable or marginalized." (p.112)

What does happen (p.112). "Indirect engagement, primarily through the supplier's management, occurs via selected management reviews conducted as part of the follow-up activities from the company's annual risk assessment of its supplier base. The topics of these reviews vary yearly to address the company's identified material impacts, risks, and opportunities."

A first direct step in the reporting year (p.112). "As outlined under Actions (S2-4), in 2025 Tieto initiated direct dialogues with value chain workers at three facility management suppliers across four sites in Stockholm, Helsinki and Pune. These dialogues aim to enhance understanding of the company's impacts and guide future actions."

Accountability (p.112). "The Group CPO, along with Sourcing Managers and Group Sustainability, is responsible for ensuring that the engagement with suppliers occurs and that the results, when deemed valuable, influence Tieto's approach to supplier management."

S2-2(was S2-3)Processes to remediate negative impacts and channels for value chain workers to raise concerns
Reported

Processes to remediate negative impacts and channels for value chain workers to raise concerns

Reference: page 112

Listed in the ESRS content index at page 112 (page 128).

"The company offers transparent communication channels for all stakeholders to raise concerns without fear of retaliation, including a third-party-operated whistleblowing channel for anonymous reports from external parties, such as value chain workers." (p.112)

Three limitations disclosed (p.112). "Tieto has not assessed whether the value chain workers are aware of and trust the company's processes to raise their concerns or needs. Nor has Tieto explicitly required its suppliers to provide a channel for value chain workers to raise concerns. As a result, the company does not track or monitor the effectiveness of suppliers' channels."

Audit-based remediation (p.112). "On-site audits are one way to help identify significant risks to workers within the value chain. If an audit reveals a potential issue, Tieto collaborates with the supplier to develop an action plan to remedy it within a specified timeframe. In cases where a complaint or issue arises, Tieto monitors the situation closely until it is fully resolved, and conducts follow-ups with both the supplier and affected workers to ensure that improvements are effectively implemented and sustained."

"If Tieto is confirmed to have the obligation to offer or participate in providing remedy to value chain workers, such a situation would be dealt with individually and on a case-by-case basis. The effectiveness of remedies provided has not been assessed, as the company has not encountered a situation of material negative impact on workers in the value chain requiring remedial action." (p.112)

S2-3(was S2-4)Taking action on material impacts on value chain workers
Reported

Taking action on material impacts on value chain workers

Reference: page 112

Listed in the ESRS content index at page 112 (page 128).

Actions in 2025, all with counts (p.112).

  • Sustainability assessment "introduced in 2024 and embedded in the supplier selection process to evaluate sustainability commitment".
  • Annual risk assessment: "All suppliers are assessed and categorized by risk level, enabling targeted mitigation efforts. High-risk suppliers underwent follow-up activities."
  • "Pre-divestment reviews: Two management reviews with hardware suppliers were conducted in order to clarify material sourcing and mitigate risks from geopolitical instability and sanctions, helping ensure compliance with regulations like the EU Conflict Minerals Regulation."
  • "Supplier evaluations: Three comprehensive evaluations were carried out via digital meetings to assess suppliers' alignment with ISO 9001, ISO 14001, internal privacy and security standards, and the Supplier Code. No findings were identified."
  • "Supplier profile reviews: Three questionnaire-based reviews focused on adherence to ISO 9001, 14001, 27001, and 27701."
  • "SBT dialogues: Five targeted engagements encouraged suppliers to commit to setting or obtaining validation of their Science-Based Targets."
  • "Worker dialogues: Direct engagement with value chain workers (cleaning, canteen, and reception services) took place at three sites located in Stockholm, Helsinki and Pune."
  • Customer team support "in high-risk areas requiring heightened human rights due diligence".

Positive impacts (p.113). "Tieto has not implemented initiatives specifically aimed at delivering positive impacts for value chain workers and therefore does not monitor their effectiveness."

Resources (p.113). "No significant Opex or Capex was allocated to the material S2 topics in 2025. However, in 2025, Tieto invested EUR 0.1 million in a new Supplier Due Diligence tool to improve both automation and usability as well as reduce manual errors."

Incidents (p.111). "In 2025, Tieto did not identify any cases of actual or potential non-compliance with the UN Guiding Principles... involving value chain workers. One case from 2024, involving a customer inquiry relating to Tieto's suppliers located in Israel, remains partially open."

S2-4(was S2-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities

Reference: page 113

Listed in the ESRS content index at page 113 (page 128).

No outcome target yet, and the company says why. "In 2025, Tieto initiated target-setting efforts for the material sub-subtopics Diversity and Gender equality and equal pay for work of equal value, specifically in relation to workers within its value chain. The double materiality assessment indicated a potential negative impact, rather than a confirmed one, due to limited data availability. This lack of data makes it difficult to verify whether Tieto contributes to inequality among value chain workers." (p.113)

The stated plan (p.113). "Looking ahead to 2026, Tieto will carry out a targeted risk assessment of its supplier base, focusing on these material sub-subtopics. The aim is to identify suppliers with elevated risk profiles and initiate engagement to better understand potential impacts and identify actionable steps to foster diversity and gender equality. Based on insights from this process, Tieto aims to define a measurable, outcome-oriented target by the end of 2026, supported by continuous performance monitoring to ensure progress and accountability."

Consequence for engagement (p.113). "As the target has not yet been established, direct engagement with value chain workers has not yet taken place in the target-setting process, in tracking performance against future targets, or in identifying lessons learned and opportunities for improvement based on the company's performance to date."

The one ambition that is tracked is contractual: "the inclusion of the Supplier Code in all supplier contracts is a key ambition. Progress is monitored via Tieto's Supplier Dashboard" (p.113). No completion percentage for that ambition is given.

S4 – Consumers and End-users

S4-1Policies related to consumers and end-users
Reported

Policies related to consumers and end-users

Reference: page 114

Listed in the ESRS content index at page 114 (page 128).

"Tieto's main policies related to privacy for consumers and end-users and own workforce are the Privacy Policy and the Human Rights Policy." (p.114)

Privacy Policy (p.114). It "aims to ensure the rights and freedoms of all individuals, including the company's own workforce as well as consumers and end-users, in relation to their personal data. It establishes common principles for protecting personal data in line with data protection laws, particularly the GDPR." Key objectives are "ensuring transparency, security and user control over personal data. The policy addresses risks related to data breaches, privacy violations and regulatory non-compliance, while it also identifies opportunities in building trust and data-driven innovation."

Alignment is stated with the GDPR, other national and international data protection laws, and "parts of the policy are aligned with the UN Guiding Principles on Business and Human Rights (UNGP), particularly related to the protection of privacy as a fundamental human right" (p.114).

Scope (p.114). "The policy applies to Tieto's operations and value chain, including suppliers and partners handling personal data. It covers all regions where the company operates and includes key stakeholders such as all customers, employees, partners and end-users."

A candid limitation (p.114). "Stakeholder interests have not been considered when setting and reviewing the Privacy Policy - the policy is purely based on the requirements in the GDPR."

Accountability (p.114). "The CEO approves the Privacy Policy and the Head of Group Legal is responsible for implementing it. The policy is reviewed annually and no major changes were made to the policy during 2025." All employees complete an annual privacy e-learning, and an external Privacy Policy Statement "is made available upon request to external stakeholders".

S4-2Processes for engaging with consumers and end-users about impacts
Reported

Processes for engaging with consumers and end-users about impacts

Reference: page 114

Listed in the ESRS content index as "Processes for engaging with consumers and end-users" at page 114 (page 128).

The disclosure turns on Tieto's split role between Data Processor and Data Controller, and states an absence of direct engagement plainly.

As Data Processor (pp.114-115). "In this capacity, Tieto processes personal data strictly based on the instructions and requirements of its customers, who remain responsible for ensuring transparency and safeguarding the privacy of their consumers and end-users." "As a Data Processor, Tieto does not interact directly with consumers or end-users since the responsibility for ensuring data privacy and transparent communication with end-users rests with the company's customers, who act as Data Controllers."

As Data Controller (p.115). "when handling the personal data of its own workforce, contacts of customers or external partners, website or office visitors, and employee candidates", Tieto "ensures that individuals are informed about their personal data processing. Individuals are also given the opportunity to raise concerns, ask questions, or exercise their privacy rights. In cases involving employees, Tieto may engage with their representatives - such as members of the European Works Council (EWC) - to ensure full transparency."

Design controls (p.114). "Tieto integrates Data Protection by Design and Default into its services and products, as required by GDPR Article 25. Potential privacy risks to individuals, including those who may be particularly vulnerable, are assessed and mitigated throughout the development of products and services."

The systemic argument is set out at page 115: "As Tieto is a significant service provider working with many customers, any potential negative impacts on data privacy could have widespread or systemic consequences."

S4-2(was S4-3)Processes to remediate negative impacts and channels for consumers and end-users to raise concerns
Reported

Processes to remediate negative impacts and channels for consumers and end-users to raise concerns

Reference: page 115

Listed in the ESRS content index at page 115 (page 128).

Channels (p.115). "Tieto's own workforce has access to an internal Privacy Notice, while a public Privacy Notice is available for external individuals, such as customer representatives, partners, suppliers, visitors, and employee candidates. A personal data breach management procedure has been embedded into the security incident management process and system." The whistleblowing channel also accepts privacy concerns.

Where the channel is not Tieto's to provide (p.115). "When acting as a Data Processor, Tieto supports its customers (the Data Controllers) in managing personal data. However, it remains the Data Controller's responsibility to provide channels for consumers and end-users to raise privacy concerns or issues. If necessary, consumers and end-users can also submit complaints to their national data protection authority, as outlined by the GDPR. Tieto itself does not provide specific contact points for consumers or end-users, unless agreed upon in the customer contract, for example, through a service desk."

Effectiveness, with a stated gap (p.115). "To ensure the effectiveness of the company's channels for raising issues, the company conducts monthly evaluations of process performance and reports the results to top management at least twice a year. Tieto has not conducted a specific assessment to determine whether its privacy notice is deemed to be a trusted way to raise concerns, given its role as a Data Processor."

Remediation (p.115). Breaches are "investigated, resolved, and reported to relevant stakeholders according to GDPR Article 33", with corrective measures "such as data recovery, deletion, or compensation where appropriate. Lessons learned are applied to strengthen policies, controls, and training to prevent recurrence. Oversight is provided by the Group Privacy and Data Protection function, with material cases reported to the ARC."

S4-3(was S4-4)Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actions
Reported

Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actions

Reference: page 115

Listed in the ESRS content index at page 115 (page 128).

Group-level actions in 2025 (p.115).

  • "The divestment of the Tech Services business - where Group Privacy supported the transition from the privacy capabilities perspective."
  • "External ISO 27701 audit and certification - with the purpose of identifying privacy-specific non-conformities."
  • "Renewal of legacy IT systems, including the internal solutions portfolio, to ensure effective management and compliance with regulations such as privacy, security, and AI requirements."
  • "Process updates in Sourcing and Supplier Management - aiming to improve operative efficiency and quality of required privacy outcomes."

Assurance cycle (p.115). "Tieto also conducts ISAE 3000 audits on an annual basis as a means to evaluate the effectiveness of the company's privacy activities and processes. Tieto aims to complete the implementation of identified privacy improvement measures within a short-term time horizon, typically within 12 months of each annual audit."

Continuity with the prior year (p.115). "In line with disclosed action plans in 2024, the company carried out activities under its privacy framework, with a particular focus on integrating necessary updates into the Sourcing and supplier management processes and providing training for key internal stakeholders."

Risk assessment tooling (p.114). "Tieto conducts Privacy Impact Assessments (PIAs) in its capacity as a Data Processor for customers who act as Data Controllers. PIAs are also carried out when Tieto acts as a Data Controller for its own workforce's personal data. In addition, enhanced Data Protection Impact Assessments (DPIAs) are performed in accordance with the requirements of the GDPR."

Resources (p.115). "operative privacy adjustments in 2025 were run as Group Legal operating costs. The action plan did not involve significant operational (Opex) or capital (Capex) expenditures during the 2025 financial year."

S4-4(was S4-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities
Reported

Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunities

Reference: page 116

Listed in the ESRS content index at page 116 (page 128).

Material topicTarget20252024 restated2024
Privacy for consumers and end-users and own workforce100% of employees completed the annual Privacy e-learning97%97%97%
Privacy for consumers and end-users and own workforceZero GDPR-related fines imposed by data protection authority000

Basis and scope (p.116). The fines target has a 2020 base year with a baseline value of 0. "As stated in the BP-1, all entities within the Tieto Group are included in the target for 'Zero GDPR-related fines imposed by data protection authorities'. However, compliance can only be tracked within Europe, as data on non-compliance outside Europe is unavailable." The measurement limitation is repeated at page 68: performance is tracked using the CMS.Law GDPR Enforcement Tracker, so "the scope of the target is limited to cases recorded in this register."

The e-learning target has a 2020 base year and baseline value of 89%, and covers all entities "with the exception of the subsidiary Bekk, as it operates fully as a portfolio company" (p.116).

Who was involved (p.116). "Internal stakeholders are involved in setting privacy targets and monitoring performance. While consumers and end-users are not directly engaged in these processes, Tieto employees - including privacy professionals - and key Group functions such as security, risk management and IT play an active role in identifying privacy-related lessons and driving improvements."

Monitoring (p.116). Quarterly follow-up by Group Privacy, shared at business and Group level, with an annual privacy maturity survey. "An assurance provider is the only type of external body that has provided validation of the targets and no milestones or interim targets have been set."

G1 – Business Conduct

G1-1Business conduct policies and corporate culture
Reported

Business conduct policies and corporate culture

Reference: page 118

Listed in the ESRS content index at page 118 (page 128).

Corporate culture (p.118). "A positive corporate culture is an important enabler of Tieto's business success... The company promotes a culture grounded in openness, trust and diversity through communication, training, development and employee engagement. Evaluation of corporate culture is conducted through employee surveys, and monitoring of indicators such as turnover, diversity and whistleblowing metrics."

Whistleblower protection (p.118). "Tieto's Whistleblowing Rules promote an open corporate culture by offering a safe mechanism for reporting suspected or actual misconduct, including breaches of law and Tieto's Code of Conduct, without fear of retaliation. The rules specify that reports may be submitted anonymously and are accepted from both internal and external stakeholders including suppliers, partners and customers." "The whistleblowing system operates independently of line management and meets legal requirements, including those set out in Directive (EU) 2019/1937."

Service levels are stated: "Reports are acknowledged within seven calendar days and feedback provided within three months." In 2025 "subtitles and translations were added to remove barriers to understanding", and a new employee survey question was introduced to gauge perceived safety in reporting; the result was 8.5 out of 10 (pp.118-119).

Anti-corruption rules (p.118). "aligned with international frameworks such as the UN Convention against Corruption and the OECD Guidelines for Multinational Enterprises, and are applied in all jurisdictions where the company operates. Where local laws are absent or insufficient, the Code of Conduct and internal rules prevail." Stakeholder input in 2024 on gifts, hospitality, sponsorships and donations "led to an update to the rules which has been in force from early 2025".

Risk mapping (p.118). "Corruption risks for Tieto are linked to roles with significant decision-making authority, where individuals influence contracts and key business relationships, particularly in high-value transactions and negotiations", plus functions with access to confidential or sensitive information. "No major update was made to the Code of Conduct in 2025."

G1-2Management of relationships with suppliers
Not Material
G1-2(was G1-3)Prevention and detection of corruption and bribery
Reported

Prevention and detection of corruption and bribery

Reference: page 119

Listed in the ESRS content index at page 119 (page 128).

"Tieto maintains zero tolerance for corruption and bribery... These are supplemented by Know Your Counterparty Rules and other corporate processes which contribute to the prevention of misconduct and support a robust legal and compliance framework. Internal controls embedded in financial processes are designed to prevent the execution of illegal or fictitious transactions." (p.119)

Training (p.119). "Training on business conduct, which includes sections focusing on anti-corruption and bribery, is mandatory for all employees including members of the administrative, management and supervisory bodies. The training is delivered through the annual Code of Conduct e-learning, and provides practical guidance on assessing business-related gifts and hospitality using real-life scenarios. All employees have access to additional, in-depth ABC training modules through the company's learning management platform."

A gap the company states about itself (p.119). "The company will roll out role-specific anti-corruption training for at-risk personnel during 2026, as no such training was provided in 2025." The same point appears at page 118: "targeted anti-corruption training for identified high-risk functions will be introduced, measured and reported from 2026 onward."

Independence of investigations (p.119). "Suspicions or incidents of corruption and bribery are escalated and investigated by the Group Whistleblowing Unit in accordance with the principles of the Whistleblowing Rules. The Group Whistleblowing Unit and the Escalation Committee operate independently from line and financial process management, ensuring impartiality and objectivity in investigations. Outcomes of investigations are reported to the ARC on a biannual basis."

Completion of the annual Code of Conduct e-learning reached 97% in 2025, against a 100% target (p.119). No breakdown of functions at risk by percentage of employees trained is given.

G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conduct
Reported

Targets related to business conduct

The report is prepared under the 2023 ESRS, where business conduct targets fall under MDR-T rather than a numbered G1-3. Tieto discloses them under that heading, and the ESRS content index lists "ESRS 2 MDR-T Targets related to business conduct" at page 119 (page 128).

Reference: page 119

Three targets are tabulated (p.119):

Material topicType of IROTarget20252024 restated2024
Corruption and bribery (prevention and detection)Actual positive impact100% of employees completed the annual Code of Conduct e-learning97%96%96%
Corruption and bribery (incidents)Potential negative impactZero incidents of corruption detected by the Whistleblowing Unit000
Corporate culture, protection of whistleblowersActual positive impactScore of at least 8/10 in the annual employee survey on safety when reporting misconduct8.5N/AN/A

New in 2025 (p.119). The whistleblower-safety target was "proposed and formulated" this year and approved by the Sustainability Steering Group; the two corruption targets were approved by the Group Executive Team in 2024. The survey question is "I feel safe to report when suspecting or observing misconduct or unethical behavior", scored 0-10, and "All employees, except those working for Avega and Bekk, are included in the scope."

Definitions and assumptions (p.119). For the incidents target, "an 'incident' refers to a case of corruption that has been formally investigated and substantiated by the Whistleblowing Unit during the reporting period... This target assumes that existing processes are effective, trusted, and widely known." For the training target, "The underlying assumption is that employees who complete the training are more likely to detect, prevent and report suspicions or incidents of corruption or bribery"; base year 2019 with a baseline of 90%, raised to 100% in 2024.

"An assurance provider is the only type of external body that has provided validation of the targets and no milestones or interim targets have been set." (p.119)

G1-4Incidents of corruption or bribery
Reported

Incidents of corruption or bribery

Reference: page 119

Listed in the ESRS content index as "Confirmed incidents of corruption and bribery" at page 119 (page 128).

Metric20252024
Confirmed incidents of corruption or bribery00
Fines for violation of anti-corruption and anti-bribery laws00
Confirmed incidents where own workers were dismissed or disciplined00
Confirmed incidents where contracts with business partners were terminated or not renewed00
Convictions for violation of anti-corruption and anti-bribery laws00

(page 120)

"During the reporting year 2025, Tieto recorded zero convictions for violations of anti-corruption or anti-bribery laws. No fines or penalties were paid in relation to such matters. Consequently, the company did not undertake any actions to provide for, cooperate in, or support the provision of remedy related to corruption or bribery during the year." (p.119)

The open legacy case, disclosed in full (p.119). "one alleged case related to corruption remained open throughout 2025. The case was originally reported in 2018 and involved a former employee of Tieto who was convicted in Belarus for bribing a public official. This incident led to charges in 2020 against Tietoevry Banking Latvia SIA (formerly SIA Tieto Latvia), alleging deficiencies in internal controls and tax evasion. The case is currently subject to ongoing court proceedings in the Riga District Court. Tieto denies the charges and continues to defend its position."

Appendix B maps the paragraph 24(a) fines datapoint and the paragraph 24(b) standards datapoint to G1-4 (p.132).

G1-5Political influence and lobbying activities
Not Material
G1-6Payment practices
Not Material