Compliance · Legislative Decree 231/2001

Modello 231

Organisation, Management & Control Model · MIP S.p.A. · Adopted March 2026

Compliance is not a constraint we endure: it is the way we choose to work. This document describes the Model that MIP S.p.A. has adopted pursuant to Legislative Decree 231/2001 to ensure legality, transparency and integrity in every relationship.

Chapter 01Introduction

In 2001 the Italian legal system introduced, through Legislative Decree no. 231 of 8 June 2001 ("the Decree"), the administrative liability — essentially criminal in nature — of entities for a range of offences committed, in their interest or to their advantage, by directors, managers, employees or external collaborators. This liability of the entity is additional to, and does not replace, the personal liability of those who physically commit the offence.

The entity may, however, be exempted from liability if it can demonstrate that it has organised itself in a manner suitable to prevent offences: by adopting and effectively implementing, before the offence is committed, an Organisation, Management and Control Model ("Modello Organizzativo" or "MOG") and entrusting oversight of it to a body endowed with autonomous powers.

From the outset, MIP S.p.A. has established rules and principles of conduct designed to ensure compliance with the law and transparency towards all of its stakeholders. These rules have been reorganised, supplemented where necessary to meet the requirements of the Decree and incorporated into this Model, which is adopted, implemented and continuously updated. The Model has been prepared in light of the Confindustria Guidelines and of an analysis of the offences set out in Articles 24 et seq. of the Decree.

Chapter 02Structure of the Model

The Model comprises a general part — this document — to which the following are annexed:

The company procedures and protocols, in the version in force from time to time, form an integral part of the Model: among others, the protocol on tax offences and administrative-accounting management, the regulation on the use of IT tools, the anti-corruption procedures and the procurement protocol. The Model is subject to periodic review and is updated whenever relevant regulatory, organisational or operational changes occur.

Chapter 03Code of Ethics

The Code of Ethics sets out the commitments and responsibilities that MIP assumes towards all those with whom it interacts — shareholders, corporate bodies, employees, collaborators, clients, suppliers and the community. Its recipients are all those who, in any capacity, act on behalf of the Company.

General ethical principles

The Company holds as an essential principle compliance with the laws and regulations in force in all the countries in which it operates, and prohibits conduct that constitutes a breach thereof, in particular conduct relevant under Legislative Decree 231/2001. It abides by the principles of fair competition, honesty, integrity, fairness and good faith, with respect for the legitimate interests of all stakeholders.

Standards of conduct

In both internal and external relationships, fraudulent conduct, acts of corruption, favouritism and any conduct contrary to the law and to the Code are prohibited. The Company promotes awareness of the rules, ensures adequate standards of quality and safety, and ensures the widest possible dissemination of the Code of Ethics, requiring its explicit acceptance at the outset of every relationship. The full text of the Code of Ethics is available in the PDF of the Model attached at the foot of this page.

Chapter 04Guidelines of conduct

The Model translates the principles of the Code of Ethics into operational guidelines that every recipient is required to observe:

Chapter 05Policies and declarations

The Model is completed by binding company policies, including the Anti-Corruption Policy — which governs gifts, hospitality, sponsorships, dealings with the Public Administration and the handling of payments — and the Policy on the use of electronic and IT tools, which establishes the rules for the proper and secure use of company systems in order to protect data and operational continuity.

Chapter 06Activities at risk of offence

The activities potentially exposed to the risk of the offences set out in the Decree have been identified through a dedicated analysis (risk assessment) conducted with the support of legal advisers, by means of interviews with the company functions and subsequent updates on the occasion of revisions of the Model. For each risk area, the offences abstractly conceivable, the functions involved and the level of risk are indicated, together with the relevant control safeguards. The areas include, among others, the application for and management of financing and grants, the management of IT systems and data, procurement, and administrative, accounting and tax management.

Chapter 07Decision-making protocols

For each risk area, the Model defines protocols designed to govern the formation and implementation of the Company's decisions. The core principles are the segregation of duties between those who authorise, those who execute and those who control; the traceability and documentability of every transaction; the existence of signing and spending powers consistent with the responsibilities assigned; and the ex-post verifiability of every material decision.

Chapter 08Management of financial resources

The management of financial resources is governed so as to prevent their use for unlawful purposes. Every transaction takes place through traceable channels, with segregation between the disposal and control functions, adequate supporting documentation, and a prohibition of cash payments above the legal thresholds or lacking justification. Controls are provided over receipts, payments, expense reimbursements and relationships with suppliers and consultants.

Chapter 09Disciplinary system

The disciplinary system is intended to prevent and sanction, on a contractual basis, breaches of the rules of the Model and the commission of the unlawful acts arising from the offences referred to in Legislative Decree 231/2001. The application of sanctions is independent of the outcome of any criminal proceedings and is complementary to — not a substitute for — the disciplinary system provided for by the applicable national collective bargaining agreement (CCNL). The measures are graduated according to the seriousness of the breach and apply to employees, managers, directors, collaborators and external partners.

Chapter 10Supervisory Body

Oversight of the functioning, effectiveness and observance of the Model, as well as of its updating, is entrusted to the Supervisory Body (OdV), which is endowed with autonomous powers of initiative and control and is independent of the management bodies. The OdV carries out periodic checks on the risk areas, reports to the corporate bodies and proposes the adjustments to the Model made necessary by regulatory or organisational changes.

Chapter 11Reporting to the Supervisory Body

The bodies, employees and collaborators operating in the risk areas are required to inform the OdV of the periodic results of control activities and of any anomaly or irregularity identified. The information flows concern, by way of example, the management of public financing and grants, the award of contracts and commissions, and any transaction relevant for the purposes of the Decree. The OdV may at any time request information and documents from all company functions.

Chapter 12Whistleblowing

Anyone who becomes aware of breaches of the Model, of laws or regulations, or of other irregularities, may report them freely. Every whistleblower is guaranteed confidentiality of identity, exemption from disciplinary sanctions and protection from retaliation of any kind — save for reports made in bad faith. Reports are submitted through the dedicated platform, which is managed independently and in compliance with the applicable legislation (Legislative Decree 24/2023).

Reporting channel

Make a report

The channel is operated by an independent external platform, which guarantees confidentiality and, if desired, anonymity. You can access it at any time.

Go to the platform

For any request relating to the Model or to the Supervisory Body: odv@makeitperfect.com

Modello 231 — Full text

PDF · General part · Adopted March 2026 · Italian

Download