For the Financial Year Ended 31 December 2025
1. Introduction
The Audit Committee (“the Committee”) is pleased to present its Annual Report to the Board of Directors for the financial year ended 31 December 2025. This report summarizes the Committee’s activities and how it discharged its responsibilities in accordance with its Charter, delegated authorities, applicable regulations, and recognized corporate governance best practices.
During the year, the Committee supported the Board in overseeing financial reporting, internal controls, risk management, cybersecurity, compliance and internal and external audit matters.
2. Committee Meetings, Attendance, and Access
During the year, the Audit Committee held six (6) meetings. Attendance by Committee members reflects strong engagement and commitment to the Committee’s fiduciary responsibilities.
| # | Name | Position | Feb 13, 2025 | May 1, 2025 | Jun 23, 2025 | July 31, 2025 | Oct 30, 2025 | Dec 3, 2025 |
|---|---|---|---|---|---|---|---|---|
| 1 | Khalid D. Al Faddagh¹ | Chairperson | • | • | • | • | • | • |
| 2 | Abdulatif S. Al Shami² | Vice Chairperson | • | • | • | • | • | • |
| 3 | Mohammed F. Al Ahmari² | Member | • | • | • | • | • | • |
The President & Chief Executive Officer, the Chief Financial Officer, the General Auditor (who also serves as Committee Secretary), as well as representatives of the External Auditor, are regularly invited to attend the Committee meetings. When required, other members are invited to address specific matters and provide deeper insight on topics relevant to the Committee’s responsibilities.
The General Auditor and the External Auditor had direct access to the Chairman of the Audit Committee and met in a private session with the Committee, without the presence of Executive Management when deemed appropriate. These sessions provided additional opportunity for open dialogue, independent discussion, and candid feedback.
Following each Audit Committee meeting, the Chairman of the Committee reported in every Board meeting to the Board of Directors key matters discussed, conclusions reached, and recommendations made.
1 Chairperson. 2 Member.
3. Financial Reporting and Financial Performance Oversight
The Committee reviewed and discussed with Management and the External Auditor the Company’s quarterly and annual financial statements prior to submission to the Board.
In accordance with the authority delegated by the Board of Directors, the Audit Committee approved the Company’s interim financial statements during the year.
The Committee also engaged with Management on the Company’s overall financial performance, challenging their key assumptions, drivers, and identified risks in order to enhance transparency and discipline in financial reporting.
4. External Audit
The Committee oversaw all matters related to the External Auditor during the year, including the review of audit scope, audit plan, fees, and key audit matters. Regular engagement with the External Auditor enabled open dialogue and constructive challenge, contributing to the overall audit quality and financial reporting integrity.
The Committee is satisfied that the External Auditor maintained independence and objectivity and performed its duties in accordance with applicable regulations and professional standards.
5. Internal Audit
The Committee maintained oversight of the Internal Audit function, ensuring its independence, effectiveness, and alignment with the Company’s strategy and risk profile.
During 2025, Internal Audit achieved several key milestones, including
- Full execution of the approved Annual Audit Plan with no carry-forward engagements.
- Optimization of the audit universe, completion of a comprehensive risk assessment, and development of a five-year rolling audit plan.
- Expansion of the advisory role through major assessments.
- Completion of a gap assessment against the Global Internal Audit Standards and implementation of actions to support full conformance.
- Advancement of audit digital maturity through automation and data analytics.
- Achievement of a high implementation rate for audit recommendations.
- Client satisfaction levels exceeding established target.
The Committee also reviewed and approved the Internal Audit Plan and budget for the year 2026.
6. Risk Management and Internal Controls
The Committee reviewed updates on the Company’s enterprise risk management (ERM) framework and internal control environment.
During the year
- An ERM maturity assessment was conducted, identifying opportunities for improvement.
- A number of recommended enhancements were implemented, contributing to an advancement in ERM maturity.
- A Risk Management Steering Committee was established to oversee key strategic risks.
- ERM reporting was enhanced through the introduction and integration of a velocity- based risk matrix concept.
In addition, the Company adopted the Saudi Aramco Controller’s Group Governance Framework (CGGF), strengthening governance over financial reporting and internal controls and aligning practices with COSO and IFRS principles.
7. Cybersecurity and Information Technology Risk Oversight
Cybersecurity and technology risks continued to receive focused attention from the Committee as part of its oversight of internal controls and risk management.
Key areas of oversight during 2025 included
- Enhancement of business continuity and resilience capabilities.
- Strengthening of employee onboarding and offboarding processes.
- Execution of cybersecurity awareness initiatives across the Company’s operations.
The Committee is satisfied that cybersecurity risks are appropriately governed and monitored.
8. Compliance, Ethics, and Whistleblowing
The Committee oversaw compliance activities and regulatory developments during the year. A key achievement was the approval of several critical policies and procedures, including those relating to insider trading, anti-corruption, privacy and data protection, competition law, international trade, and misconduct reporting and investigation.
The Committee also ensured that effective whistleblowing arrangements remain in place. No instances of fraud were reported during the year.
9. Governance and Other Matters
During the year, the Committee
- Considered relevant supervisory and regulatory matters.
- Received management assurances regarding internal controls, risk management, and cybersecurity.
The Committee maintained open and constructive dialogue with Management, Internal Audit, and the External Auditor throughout the year.
10. Conclusion
Based on the work performed and information received during 2025, the Audit Committee is satisfied that the Company’s
- Financial reporting processes are sound and transparent.
- Internal control and risk management systems are operating effectively.
- Cybersecurity and technology risks are appropriately mitigated and governed.
- Internal Audit and External Audit functions remain independent, objective, and effective.
- Overall governance maturity continues to strengthen.