Draft template — legal counsel review required. This page is a structural draft prepared to the framework of GDPR (Regulation EU 2016/679), the EU Whistleblower Directive (2019/1937) where relevant, and applicable Kosovo law. It is not legal advice. Final text must be reviewed and approved by qualified legal counsel before publication.

1. Scope

This policy applies to all employees, officers, and directors of ERAM Group Ltd. and its subsidiaries, and to any third party acting on behalf of the Group, including contractors, consultants, agents, distributors, resellers, and joint venture partners.

2. Zero tolerance

ERAM Group prohibits all forms of bribery and corruption. Neither the Group, nor any person acting on its behalf, will offer, give, request, accept, or receive any payment, advantage, or favour with the intent of improperly influencing a business decision, securing an unfair advantage, or rewarding the improper performance of a function.

This prohibition applies whether the recipient is in the public sector or the private sector, and whether the conduct takes place in Kosovo or in any other jurisdiction.

3. Prohibited conduct

The following are expressly prohibited:

  • Bribery of public officials (cash, in-kind benefits, employment offers, contracts to connected parties).
  • Commercial bribery in the private sector.
  • Facilitation payments — small unofficial payments to secure or speed up routine government action.
  • Political donations made on behalf of the Group.
  • Hospitality, gifts, or entertainment exceeding the thresholds set in the Group's gifts and hospitality procedure.
  • Engagement of third parties without due diligence appropriate to the corruption risk of the engagement.

4. Hospitality and gifts

Modest, reasonable, and proportionate hospitality and gifts that are properly recorded are permitted within the limits set in the Group's gifts and hospitality procedure. The procedure is maintained by the Compliance Officer and is available to all staff and to third parties on request.

5. Public tenders

Public-sector tenders are responded to under specific compliance protocols including: documented conflict-of-interest screening, no contact with evaluation panels outside the formal tender process, no engagement of intermediaries with undisclosed relationships to the contracting authority, and post-award documentation retention for the period required by law plus three years.

6. Due diligence on third parties

Third parties (agents, consultants, joint venture partners, resellers) are subject to risk-based due diligence before engagement and at periodic intervals during the relationship. The depth of due diligence is proportionate to the country risk, the sector risk, and the nature of the engagement.

7. Compliance affirmation

Senior managers submit a quarterly compliance affirmation. The affirmation confirms compliance with this policy, declares any conflicts of interest, and confirms the integrity of any expense claims and supplier engagements within scope.

8. Reporting and protection

Suspected breaches of this policy must be reported through the Group's whistleblowing channel or to a member of senior management. Retaliation against any person making a good-faith report is itself a breach of this policy and is contractually enforceable.

9. Consequences

Breach of this policy is grounds for disciplinary action up to and including dismissal for employees, and for termination of contracts with third parties. Conduct that may constitute a criminal offence will be reported to the competent authorities.

10. Ownership and review

This policy is owned by the Board of Directors and reviewed annually. Last reviewed: [date]. Next review: [date].