We are committed to conducting our business with the highest ethical standards, applying strict expectations to both our own employees and all partners who work with us. Our zero-tolerance stance on bribery, fraud and any form of unethical conduct is fundamental to the long-term sustainability of our operations and the well-being of the communities in which we operate. In addition to complying with all applicable laws and regulations, we align with international best practice and uphold robust corporate governance principles.
At the centre of our ethical framework is our Code of Conduct (the Code), which sets out the values and principles that guide integrity across all aspects of our operations. The Code prohibits conflicts of interest, bribery, bullying, substance abuse and the misuse of confidential or insider information, among other behaviours. Approved by the Board of Directors, the Code is regularly reviewed and updated by the relevant Board Committee, with ongoing oversight provided by senior management and the internal audit function.
All employees are required to acknowledge, understand and comply with the Code. In 2025, our training programmes were further expanded to ensure a deeper and more comprehensive understanding of the Code across all employee groups. During the year, we also relaunched our own corporate learning portal, providing all employees with direct access to these courses for self-paced completion. At the same time, the core compliance and ethics modules remain mandatory as part of the onboarding process, ensuring consistent standards from day one. Looking ahead, we plan to further develop proprietary training content in these focus areas and continually enrich our internal knowledge base, strengthening capability, awareness and long-term organisational resilience.
Additionally, employees of the Security Department conduct regular in-person anti-corruption training sessions at our operational sites, delivered on a targeted basis with particular focus on business units and functions where the risk of potential non-compliance is assessed to be higher; thereby strengthening awareness and reinforcing controls in areas of greatest exposure. In total, the programme covered 2,500 employees and contractors during the reporting period, with 14 training sessions conducted across our operations.
Our ethical standards are supported by a suite of corporate policies – including the Supplier Code of Conduct, Anti-Bribery and Corruption Policy and Whistleblowing Policy. In 2025, we also updated and reinforced our Data Privacy Policy, which affirms the Company’s commitment to the ethical handling of all stakeholder data and strict adherence to data protection principles.
We conduct a comprehensive review of the Code and all related policies every three years, with updates approved by the Board of Directors to ensure continued relevance and effectiveness. All policies are publicly available on the Company’s website, reinforcing transparency and stakeholder access. Through regular benchmarking against leading mining industry practice, we systematically align our policies with evolving best-in-class standards and applicable national legislative developments in the jurisdictions where we operate.
The Company also maintains a strict prohibition on political contributions. No donations were made to political parties, organisations or independent election candidates in 2025 (2024: none), unless expressly authorised in advance by a shareholder resolution. Beyond this, the Company does not make any contributions to lobbying groups, trade associations, tax-exempt entities, government officials or any other groups that may influence political campaigns, public policy formation or legislation, nor to any organisations or individuals whose activities are inconsistent with the Code..
Bribery is a criminal offence in all jurisdictions where we operate, carrying significant legal and reputational risks. Our Anti-Bribery and Corruption Policy applies universally across all our business dealings, covering Directors, managers, employees, business partners and other relevant individuals and entities. The policy strictly prohibits the payment, offer or acceptance of bribes, facilitating payments or any other corrupt practices. The Board upholds a zero-tolerance approach, ensuring that any acts of bribery and corruption by employees or business partners are actively prevented, investigated and addressed. The Audit and Risk Committee conducts regular policy reviews to maintain the effectiveness of our anti-bribery and corruption measures.
To reinforce our commitment to ethical business practices, we maintain a robust Whistleblowing Policy, aligned with international anti-corruption standards. This policy enables confidential reporting of unethical conduct or illegal activities, ensuring that all concerns are independently investigated. Retaliation against whistleblowers is strictly prohibited and biannual reports to the Audit and Risk Committee provide updates on policy implementation and any reported violations. No employee has been denied access to the Committee and protective measures are in place to safeguard whistleblowers from any adverse personnel actions.
Our confidential Hotline, accessible through our corporate website, allows anyone to anonymously report violations of the law or ethical standards via email or phone. Each report is thoroughly investigated – confidentially and impartially – and anonymity is maintained upon request. In 2025, 381 violations of the Code of Conduct were identified among the Company’s employees and contractors, reported through various sources, including the Hotline. These were investigated and comprehensive measures taken in accordance with the Code.
During the reporting year, no corruption-related incidents were identified; nor were any legal actions concerning bribery or corruption brought against Solidcore or any of its employees. We nevertheless maintain a proactive and continuous approach to preventing corruption risks. This includes regular monitoring, awareness-raising initiatives and ongoing strengthening of our internal controls. In 2025, we delivered targeted anti-bribery and corruption seminars for high-risk employee groups and contractors, further reinforcing our compliance culture and commitment to the highest standards of ethical conduct.
sb@solidcore-resources.kz
Solidcore works with a broad network of more than 2,500 contractors and suppliers who provide goods, materials, services and works essential to the Company’s operational and infrastructure activities. With a global supply chain, Solidcore places strong emphasis on sustainability, integrity and responsible business conduct at every stage of procurement. Our Supplier Code of Conduct sets clear and stringent expectations on safety, labour practices, environmental performance and ethical behaviour, ensuring that all suppliers operate in line with our corporate values. Building supplier awareness of these standards remains a core priority, reinforcing a culture of accountability and continuous improvement across the value chain.
We actively manage supply chain risks through comprehensive due diligence, transparent supplier selection processes and robust risk assessment tools designed to identify and mitigate potential issues early.
In line with leading supply chain stewardship practices, we assess suppliers’ commitment to sustainability using our dedicated questionnaire, publicly available on the Company’s website. To further strengthen oversight, we are currently planning the implementation of an ESG-score system for key suppliers in 2026, enabling more structured performance evaluation and deeper integration of sustainability considerations into procurement decisions. We also continue expanding cooperation with suppliers to enhance traceability, promote lower-carbon and environmentally efficient solutions and increase visibility into upstream impacts. This approach supports long-term partnerships built on transparency, shared responsibility and continuous improvement – ensuring that our procurement ecosystem contributes meaningfully to the Company’s broader sustainability objectives.
We select partners through an open-tender process, with our e-procurement system ensuring uniform application of Procurement Policy standards. A multi-layered due diligence process guarantees that suppliers meet our operational and ESG requirements:
In 2025, we conducted assessments of 2,594 suppliers and contractors, resulting in the termination of co-operation with three and placing 111 under high-risk monitoring for enhanced oversight.
The Company maintains rigorous oversight of its supply chain through proactive engagement with contractors and counterparties. In 2025, the Company’s Security Department initiated 23 claims totalling approximately $10,000 for breaches of contractual obligations, alongside 106 claims amounting to approximately $58,000 for violations of access control protocols and the Company’s Code of Conduct. Across the Group as a whole, 512 formal claim letters were issued to counterparties for inadequate performance of contractual obligations during the reporting period. This systematic approach to supplier accountability reinforces Solidcore’s commitment to ethical business practices, ensuring that all partners operating across its value chain adhere to the standards of integrity, safety, and compliance that the Company upholds in its own operations. Additionally, our human rights and diversity training materials are made available to suppliers, reinforcing our commitment to ethical sourcing.
Prioritising local sourcing strengthens regional economies, reduces our carbon footprint and enhances supply chain resilience, particularly in remote areas. In 2025, 58% of our procurement was regional, a 3% increase compared with last year. To increase the share of local suppliers, we have embedded a location-based criterion into our procurement strategy, giving preference to locally manufactured goods whenever feasible. Our commitment to supporting local communities is also formally integrated into supplier contracts, the Procurement Policy, the Supplier Code of Conduct and the Community Engagement Policy, ensuring that local development objectives are consistently upheld across all operations. Global trends in responsible supply chain management increasingly highlight the strategic importance of local procurement – not only as a socio-economic driver – but as a key enabler of operational stability, reduced logistics risks and improved community relations. By aligning with this best practice, Solidcore aims to build stronger partnerships with local businesses, foster shared values and contribute to long-term regional resilience. An example of such cooperation is demonstrated by the Company’s initiative to finance start-up projects to create a sewing workshop and greenhouse in the city of Zhitikara.
Solidcore upholds a robust compliance framework grounded in applicable national legislation, leading international standards and best global practice. The Company is committed to ensuring the highest levels of integrity, product responsibility, quality and safety across its operations and throughout the value chain.
In the area of compliance and product responsibility, Solidcore reaffirms its commitment to the World Gold Council Responsible Gold Mining Principles (RGMPs), integrating their requirements into its governance, risk management and operational practices. The Company is also progressing towards alignment with the Conflict-Free Gold Standard, reinforcing responsible sourcing, transparency and conflict-sensitive supply chains. This approach is equally important in the context of human rights, as it strengthens safeguards against human rights risks, supports due diligence across the value chain and promotes respect for internationally recognised human rights standards in all areas of operation.
During the reporting period, no complaints were received regarding breaches of customer privacy and Solidcore was not subject to any significant fines or legal proceedings related to socio-economic regulations, product quality, health and safety requirements or other compliance matters. The Company maintains proactive and transparent engagement with regulatory and supervisory authorities and systematically strengthens its internal controls. Where internal or external audits identify areas requiring improvement, Solidcore promptly undertakes corrective and preventive actions, reinforcing a culture of accountability, continuous improvement and responsible business conduct.
Solidcore is committed to respecting and upholding human rights across all aspects of its business, ensuring that all stakeholders – employees, communities and partners – are treated fairly and with dignity. We align with the Universal Declaration of Human Rights, the UN Global Compact, the ILO Declaration on Fundamental Principles and Rights at Work and the Responsible Gold Mining Principles, Voluntary Principles on Security and Human Rights (VPSHR) while fully complying with national labour laws in all operational regions. As part of our ongoing commitment to ethical business, we annually publish our Modern Slavery Act Transparency Statement, outlining the steps we take to prevent forced labour, human trafficking and human rights violations within our operations and supply chain. Local communities’ rights remain a core focus and, in 2025, we recorded no conflicts related to land use or historical and cultural sites in our operational regions. As part of our ongoing engagement with local communities, we conduct Environmental Impact Assessments (EIA) and Environmental and Social Impact Assessments (ESIA) for development projects, ensuring early identification and mitigation of potential risks. We also implement dedicated environmental initiatives in our regions of operation, with further details provided in the Environment section of this Report.
Our approach is guided by our Human Rights Policy, the UN Guiding Principles on Business and Human Rights (UNGPs) and informed by the IFC Performance Standards and UK Modern Slavery Act. In 2025, the HR Department conducted its annual human rights risk screening across all operational sites, covering key areas including labour practices, community health and safety, potential impacts on vulnerable groups and other relevant operational aspects. As of 31 December 2025, the overall risk level is assessed as low, consistent with the previous year’s assessment. No cases of discrimination based on gender, age, race, nationality, religion, social origin, health status, marital status, beliefs or any other grounds were recorded in 2025.
Solidcore recognises that the activities of security providers — both in-house and contracted — carry human rights risks. These risks are managed under the Security and Human Rights Standard, developed on the basis of the Voluntary Principles on Security and Human Rights (VPSHR), IFC Performance Standard 4, the UN Guiding Principles on Business and Human Rights, the International Code of Conduct for Private Security Service Providers (ICoC), and the UN Basic Principles on the Use of Force and Firearms. The Standard applies to all Group entities and all security contractors.
Key principles. The Standard enshrines five core principles of security operations: unconditional respect for human rights; proportionality and non-escalation in the use of force; zero tolerance for complicity in human rights abuses; respect for the rights of local communities — including access to traditional lands and freedom of peaceful assembly; and intolerance of corruption. Force may be used only after non-violent means have been exhausted and must be proportionate to the threat; lethal force may be used solely to protect human life.
Risk assessment. Each operation conducts a security and human rights risk assessment, which includes identifying vulnerable groups located near the sites and determining measures for their protection.
Requirements for security providers. Respect for human rights, appropriate use of force, and respectful treatment of employees and members of local communities are embedded in contracts with security providers as a mandatory condition of engagement. Interaction with public security forces is likewise conducted in accordance with the VPSHR. All security personnel receive training on human rights, the Code of Corporate Conduct, and the rules on the use of force.
Protection of vulnerable groups. The Standard sets out specific requirements for security personnel when interacting with vulnerable groups: searches of women are conducted only by female security officers, interaction with children takes place in the presence of a responsible adult, and communication with persons who do not speak the language of the site is facilitated through interpreters. Any instances of gender-based violence or sexual harassment by security personnel are treated as a material incident, triggering immediate notification of senior management, an independent investigation, and disciplinary or contractual measures.
Accountability. The Company maintains a zero-tolerance policy towards any form of abuse, intimidation, or excessive use of force. Grievance mechanisms are available to everyone — including anonymously, in local languages, and without risk of retaliation. The Security Service conducts regular internal reviews of security personnel; the Standard also provides for independent audits of security operations. Oversight of compliance rests with the Audit and Risk Committee of the Board of Directors.
Information security and personal data protection at Solidcore are managed by the Information Security Unit within the Security Service. This function is responsible for safeguarding corporate information and ensuring compliance with internal standards and regulatory requirements.
The Group’s approach to information protection is set out in the Information Security Policy approved by the Board of Directors of Solidcore Resources plc. The Policy establishes uniform principles and minimum information protection requirements for all Group entities and serves as the basis for the information security regulations developed at their level. Oversight of adherence to the Policy’s principles rests with the Audit and Risk Committee. At the workplace level, these requirements are detailed in the Information Security Guidelines available on all employee workstations. The Group is committed to aligning with the ISO/IEC 27001 series of information security standards and is considering potential certification of its information security management system.
In line with global trends, cybersecurity has been identified as one of the key risks and is included in the Group’s corporate risk register.
As part of the onboarding process, all new employees are required to familiarise themselves with the information security policies and standards, sign a non-disclosure agreement, and complete initial training on the safe use of electronic devices and workstations.
To maintain awareness and foster a culture of digital responsibility, employees regularly receive information security newsletters and undergo training on information security and cyber hygiene.
Access to personal data is strictly limited to authorised personnel. An official register of workstations used for personal data processing has been established. In 2025, no incidents of information or employee personal data leakage, theft, or loss were recorded.
As part of its commitment to continuous improvement and alignment with industry best practices, Solidcore is implementing a dedicated roadmap to enhance performance in this area: a corporate online training programme on cyber hygiene and cybersecurity has already been launched under the roadmap and will be expanded and updated to reflect evolving threats.