🔒 CONFIDENTIAL
v4.2.1 Report Period: FY2025 (Jan 1 – Dec 31) Published: March 15, 2026

Annual Compliance &
Regulatory Report

Aevum Zenth Conglomerate — Corporate Governance, Risk Management & Compliance Division

01

Executive Summary

During fiscal year 2025, Aevum Zenth Conglomerate maintained a 94.2% overall compliance score across all 400 subsidiaries operating in 62 jurisdictions. The consolidated entity processed $94.2 billion in revenue, operated under the oversight of 47 regulatory bodies, and completed 12,847 control assessments across 14 compliance domains.

This year saw successful implementation of the Zenth Protocol v3.0 — our unified compliance automation framework — reducing manual audit workload by 67% and achieving full GDPR/CCPA alignment across all data-handling subsidiaries. No material non-compliance events were reported to any regulatory authority.

Compliant

SEC Filings

All 10-K, 10-Q, 8-K filings submitted timely with zero material weaknesses.

Compliant

GDPR / EU Data

Full alignment with EU Data Protection Regulation and ePrivacy Directive.

Partial

China PIPL

Data localization requirements ongoing; 92% remediation complete.

Compliant

SOX 404

Internal controls over financial reporting certified as effective.

Monitoring

AI Governance

Implementing EU AI Act compliance ahead of final enforcement date.

Compliant

ISO 27001

All subsidiaries recertified under updated ISMS framework.

02

Compliance Framework

Aevum Zenth operates under a multi-layered compliance architecture known as the Integrated Governance Matrix (IGM), which harmonizes regulatory requirements across all business segments and geographic jurisdictions.

Framework Components

  • Zenth Protocol v3.0 — Automated compliance monitoring and reporting engine deployed across all 400 subsidiaries.
  • Regulatory Ontology Engine — Real-time mapping of regulatory changes to applicable controls using AI-driven NLP processing.
  • Control Domain Repository — Centralized library of 12,847 controls mapped to COBIT 2019, COSO ERM, NIST CSF 2.0, and ISO standards.
  • Third-Party Risk Program — Continuous vendor compliance monitoring for 4,200+ active third-party relationships.
  • Ethics Hotline & Whistleblower System — Multilingual reporting platform with 2,847 submissions this year; 98.2% closed within SLA.
  • Regulatory Change Management — Automated ingestion of 14,600+ regulatory updates; 1,200+ control adaptations deployed.

Standards Mapped

Standard / Framework Cards Scope Status
COSO ERM (2017) Enterprise-Wide Risk management & governance ✓ Compliant
COBIT 2019 IT & Data Governance IT governance & controls ✓ Compliant
NIST CSF 2.0 Cybersecurity Cybersecurity framework alignment ✓ Compliant
ISO 27001:2022 Information Security ISMS across all subsidiaries ✓ Compliant
ISO 14001:2015 Environmental Environmental management ✓ Compliant
ISO 45001:2018 Occupational Health Workplace safety & health ✓ Compliant
EU AI Act AI Governance High-risk AI systems compliance ◷ In Progress
China PIPL Data Localization Personal data in PRC subsidiaries ◐ Partial
03

Regulatory Portfolio

The conglomerate operates under the oversight of 47 regulatory bodies across 62 jurisdictions. The table below summarizes the compliance posture of each major regulatory domain.

Regulatory Domain Authority Controls Assessed Pass Rate Status
Securities & Exchange SEC (US) 1,240 99.8% ✓ Compliant
Financial Conduct FCA (UK) 870 99.5% ✓ Compliant
Data Protection EDPB (EU) 2,100 99.9% ✓ Compliant
Anti-Money Laundering FinCEN / FIU Global 960 98.7% ✓ Compliant
Export Controls BIS / EAR / ITAR 540 97.2% ◐ Partial
Antitrust / Competition EC / DOJ / MOFCOM 420 100% ✓ Compliant
Environmental Regulation EPA / EEA / Regional 1,680 96.8% ✓ Compliant
Labor & Employment ILAB / ILO / National 1,340 99.1% ✓ Compliant
Healthcare (FDA) FDA (US) 2,800 98.4% ✓ Compliant
Telecom & Spectrum FCC / ITU / Regional 680 99.3% ✓ Compliant
04

Risk Assessment

The Enterprise Risk Management (ERM) function identified and rated 342 risk events across the portfolio during FY2025. The following subsections detail the risk landscape and treatment actions.

Risk Scorecard by Category

Cybersecurity & Data Breach 96.8%
Regulatory & Compliance Risk 95.4%
Operational Continuity 94.1%
Financial Reporting & Internal Controls 98.7%
Third-Party & Vendor Risk 88.2%
Geopolitical & Sanctions Risk 82.6%
AI & Algorithmic Accountability 87.3%
Environmental & ESG Compliance 93.5%

Top Risk Events FY2025

Risk Event Classification Inherent Risk Residual Risk Treatment
Subsidiary data exposure (Zenth Health) Cybersecurity High Low Remediated within 4 hours
Export control gap in Aerospace division Regulatory Medium Low Control framework updated
Vendor cloud misconfiguration Third-Party High Medium Vendor contract renegotiated
Data localization lag (China PIPL) Data Privacy High Medium Migration in progress
AI model bias detection (Zenth AI) AI Governance Medium Low Fairness audit deployed
⚠️ Risk Alert: China PIPL Data Localization

Three subsidiaries handling personal data of Chinese residents have not yet completed full data localization to approved domestic cloud providers. Target completion: Q3 2026. Interim controls include data anonymization and restricted data transfer protocols under Standard Contractual Clauses.

05

Audit Findings

Internal and external audit activities during FY2025 yielded the following results across all 400 subsidiaries.

1,247
Total Control Tests Performed
▲ 34% vs FY2024
1,176
Controls Passed
94.3% pass rate
52
Minor Findings
▼ 18% vs FY2024
19
Material Observations
▼ 42% vs FY2024

Material Findings Summary

  • Finding #2025-014: Zenth Energy — Incomplete documentation for cross-border energy trading compliance in Southeast Asia. Remediation: Standardized documentation templates deployed; closed Q2.
  • Finding #2025-037: Zenth Healthcare — Delayed adverse event reporting in three EMEA facilities. Remediation: Automated alerting system implemented; all reporting now within 24h SLA.
  • Finding #2025-062: Zenth Capital Group — Inadequate segregation of duties in one regional fund operations unit. Remediation: Access controls reconfigured; independent review panel established.
  • Finding #2025-089: Aevum Properties — Building code compliance gaps in two emerging-market developments. Remediation: Local engineering audits commissioned; all identified gaps rectified Q3.

Audit Activity Timeline

January 15, 2025
Q4 2024 Internal Audit Cycle Completed
All FY2024 observations closed; baseline controls established for FY2025.
April 30, 2025
External Auditor Report (Deloitte) Issued
Unqualified opinion on financial statements; internal controls deemed effective.
July 15, 2025
Mid-Year Compliance Review
All SOX 404 controls tested; no material weaknesses identified.
October 20, 2025
Regulatory Examinations Completed
SEC, FCA, EDPB, and FDA examinations completed with no deficiencies noted.
December 31, 2025
FY2025 Internal Audit Cycle Completed
Full-scope audits across all 400 subsidiaries completed; 94.3% control pass rate.
March 31, 2026
Annual Report Publication & Board Submission
Compliance report to be submitted to Board Audit Committee and published.
06

Data Privacy & Protection

Privacy compliance spans all subsidiaries processing personal data across 62 jurisdictions. The following summarizes the key compliance posture.

100%
GDPR Compliance Coverage
Full alignment achieved Q1
100%
CCPA/CPRA Compliance Coverage
All CA data handling aligned
92%
China PIPL Compliance
Localization in progress
100%
DSAR Fulfillment SLA
Avg. response: 14.2 hours

Privacy by Design Implementation

  • Privacy Impact Assessments (PIAs) conducted on 1,847 new projects; 99.1% completed before project initiation.
  • 23 Data Protection Officers (DPOs) deployed across all regional offices.
  • Data retention policies automated via Zenth Protocol v3.0 — 100% of data flows catalogued.
  • Zero personal data breaches reported to supervisory authorities during FY2025.
  • 2,847 Data Subject Access Requests fulfilled; average processing time: 14.2 hours (well below 30-day SLA).
07

Environmental & ESG Compliance

Aevum Zenth's ESG compliance program is governed by its Sustainability & Environmental Stewardship Council and aligns with TCFD, SFDR, EU Taxonomy, and SASB reporting frameworks.

Key Environmental Metrics

-34%
Scope 1 Emissions Reduction (vs. 2020)
On track for 2030 net-zero
100%
Renewable Energy in Operations
Achieved 18 months ahead of target
47
Environmental Violations (All Remediated)
▼ 78% vs FY2024
€2.4B
Green Investment Portfolio
▲ 120% YoY
🌍 ESG Note: Scope 3 Emissions

Scope 3 emissions remain at 89% of total carbon footprint, primarily driven by logistics and supply chain. Aevum Zenth has committed to achieving Scope 3 reduction targets by 2035 through supplier engagement programs, alternative fuel mandates, and carbon offset investments.

08

Financial Compliance

Financial compliance encompasses SEC reporting, SOX 404, anti-money laundering, tax compliance, and transfer pricing across all subsidiaries.

SOX 404 Assessment

Control Category Tests Executed Passed Failed Pass Rate
Revenue Recognition 320 318 2 99.4%
Accounts Payable 280 279 1 99.6%
Payroll & HR 240 239 1 99.6%
Fixed Assets 180 178 2 98.9%
Intercompany 427 414 13 97.0%
🚨 Material Weakness: Intercompany Reconciliation

13 intercompany control failures identified across three regional finance units. While none resulted in material financial misstatement, the cumulative deficiency represents a potential control gap. Management has initiated automated reconciliation protocols targeting Q2 2026 closure.

Tax Compliance Summary

  • All 62 jurisdictions' tax filings submitted on time; zero late-filing penalties.
  • Transfer pricing documentation completed for 847 intercompany transactions per OECD BEPS guidelines.
  • Effective tax rate: 21.3% (within forecasted range of 20-23%).
  • OECD Pillar Two compliance deployed across all entities with revenue >€750M.
09

Workplace Safety & Labor Compliance

Aevum Zenth maintains a zero-tolerance policy for workplace violations. The following summarizes safety and labor compliance across all operations.

0
Fatal Incidents (FY2025)
3 consecutive years without fatalities
1.2
LTIFR (Lost Time Injury Frequency Rate)
▼ 45% vs industry average
100%
Labor Law Compliance
Zero violations across 62 jurisdictions
99.8%
Employee Ethics Training Completion
All 340K employees trained

Health & Safety Certifications by Division

Division ISO 45001 Certified Workplace Inspections Training Hours
Aevum Energy✓ Yes1,24048,500
Zenth Digital Systems✓ Yes86032,100
Aevum Aerospace✓ Yes1,58067,300
Zenth Health Sciences✓ Yes2,10054,800
Aevum Capital Group✓ Yes34012,600
All Other Divisions✓ Yes4,620128,400
10

Remediation Plan

All identified compliance gaps, material observations, and regulatory findings have assigned remediation plans with responsible parties and target completion dates.

Open Remediation Items

Item ID Findings Owner Priority Target Date Status
REM-2025-001 China PIPL data localization Zenth DPO Critical Q3 2026 ◷ In Progress
REM-2025-002 Intercompany reconciliation controls Chief Financial Officer High Q2 2026 ◷ In Progress
REM-2025-003 Export control framework (Aerospace) VP Export Controls High Q2 2026 ◷ In Progress
REM-2025-004 Vendor cloud security assessment CISO Medium Q4 2026 ◷ In Progress
REM-2025-005 EU AI Act compliance framework Head of AI Ethics Medium Q1 2027 ◷ In Progress
REM-2025-006 Scope 3 emissions measurement Chief Sustainability Officer Medium Q2 2027 ◷ In Progress
📌 Executive Note

Two critical-priority items remain open as of report publication. The Board Audit Committee has been briefed and has authorized the allocation of $48M in dedicated remediation resources. Progress will be reported in the Q1 2026 interim compliance update.

11

Approval & Sign-off

This compliance report has been reviewed and approved by the following senior leadership and board members.

📝 Authorized Signatories

EK
Dr. Elena Kuznetsov
Chief Executive Officer
✓ Approved — Jan 28, 2026
MR
Marcus Reynolds
Chief Financial Officer
✓ Approved — Jan 28, 2026
AT
Aisha Tanaka
Chief Compliance Officer
✓ Approved — Jan 27, 2026
JW
James Whitfield
General Counsel
✓ Approved — Jan 29, 2026
SH
Sofia Hernandez
Head of Internal Audit
✓ Approved — Jan 30, 2026
RB
Dr. Raj Bhatt
Board Audit Committee Chair
◑ Pending — Board Meeting Feb 15
12

Report Distribution

Recipient Entity Access Level Format
Board of DirectorsAevum Zenth ConglomerateFull (All Sections)Encrypted PDF + Web Portal
Audit CommitteeBoard of DirectorsFull (All Sections)Encrypted PDF + Web Portal
SECUS Securities & Exchange CommissionPublic (Redacted)EDGAR Filing
FCAUK Financial Conduct AuthorityRegulatory SummarySecure Portal Upload
EDPBEU Data Protection BoardPrivacy Appendix OnlySecure Portal Upload
ShareholdersAll Registered ShareholdersPublic (Executive Summary)Investor Relations Website
Deloitte LLPExternal AuditorFull (All Sections)Encrypted PDF