Demaş A.Ş.

DEMAŞ A.Ş. Compliance Policy

DEMAŞ A.Ş. COMPLIANCE POLICY

1. OVERVIEW

DEMAŞ KUYUMCULUK İHRACAT İTHALAT SANAYİ VE TİCARET A.Ş. (hereinafter referred to as "DEMAŞ A.Ş.") undertakes to conduct its commercial activities in accordance with the highest ethical standards in combating money laundering and the financing of terrorism, complying with local laws and regulations as well as the relevant international standards.

The DEMAŞ A.Ş. Compliance Policy has been prepared in accordance with the provisions of Law No. 5549 on the Prevention of Laundering Proceeds of Crime, Law No. 6415 on the Prevention of the Financing of Terrorism, and Law No. 7262 on the Prevention of the Financing of the Proliferation of Weapons of Mass Destruction.

1.1 Purpose

The purpose of the DEMAŞ A.Ş. Compliance Policy is to establish the management principles and minimum requirements within the scope of the DEMAŞ A.Ş. Compliance Programme in order to prevent DEMAŞ A.Ş. from being used as an intermediary for money laundering or the financing of terrorism, and to guide all DEMAŞ A.Ş. employees, in the course of conducting business, in accordance with the laws and regulations concerning money laundering and the financing of terrorism.

1.2 Scope

Compliance is a company-wide responsibility at DEMAŞ A.Ş. and must be seen as an integral part of DEMAŞ A.Ş.'s daily operations. All employees at DEMAŞ A.Ş. (including Senior Managers, Managers and Employees) are under the responsibility of performing their duties to the highest standards of integrity, ethics and accuracy.

1.3 Policy Issued By

This policy has been prepared by the DEMAŞ A.Ş. Compliance Department and approved by the DEMAŞ A.Ş. Board of Directors.

1.4 Effective Date

This Policy is valid as of its date of publication.

1.5 Review

Unless otherwise required, this Policy is reviewed by the relevant parties at least once a year. If deemed necessary, the required updates are carried out and submitted for the approval of the Board of Directors.

1.6 Violations

A violation is defined as any case of non-compliance with this Policy where no approved exception request exists. If a policy violation is identified, the matter must be reported to the Compliance Department immediately. Failure to fulfil the requirements of this Policy may lead to disciplinary measures, including termination of the employee's employment contract.

1.7 Roles and Responsibilities

The adequate, effective and appropriate conduct of the entire compliance programme, in terms of the scope and nature of the obliged party's activities, is ultimately the responsibility of the Board of Directors. The Compliance Officer and the Deputy Compliance Officer are appointed by the Board of Directors.

2. COMPLIANCE RISK

Compliance risk is defined as the possibility of financial or reputational loss to which obliged parties may be exposed for reasons such as the use of the services they provide for the purpose of money laundering or the financing of terrorism, or the obliged parties' failure to fully comply with their obligations under the law.

3. COMPLIANCE PRINCIPLES

  • Compliance with Laws, Rules and Regulations
  • Promotion of Ethical Conduct and Acting Within Ethical Conduct
  • Avoidance of Conflicts of Interest
  • Protection of Confidentiality
  • Protection of DEMAŞ A.Ş. Assets
  • Protection of Customer Interests
  • Reporting
  • Avoidance of Disclosure

4. DEMAŞ A.Ş. COMPLIANCE MANAGEMENT STRUCTURE

The effective implementation of DEMAŞ A.Ş. Compliance Management is made possible through the implementation and supervision commitment of the Board of Directors and senior management, an organisational structure and allocation with the necessary personnel that is effective and correctly defined, written policies and procedures, and the components of monitoring, control and internal audit.

5. COMPLIANCE FUNCTION

Compliance with DEMAŞ A.Ş.'s policies and principles is within the responsibility of all employees. A Compliance Department has been established to ensure that compliance risk is managed effectively. The Compliance Department operates as an independent structure reporting to the Board of Directors.

6. AML/CFT POLICIES AND LEGAL REGULATIONS

DEMAŞ A.Ş. employees are obliged to comply with the regulations and recommended practices published under the legislation of the Republic of Turkey regarding money laundering and the financing of terrorism, applicable international standards, and DEMAŞ A.Ş. Policies and Procedures.

6.1 Relevant Laws

  • Law No. 5549 on the Prevention of Laundering Proceeds of Crime
  • Law No. 6415 on the Prevention of the Financing of Terrorism
  • Law No. 7262 on the Prevention of the Financing of the Proliferation of Weapons of Mass Destruction

6.2.1 Know Your Customer Policy (KYC)

DEMAŞ A.Ş. implements a KYC Policy containing the principles for the information required, the controls to be carried out and the approvals to be obtained in relation to the processes of establishing a business relationship. No business relationship is established with persons whose identity cannot be verified.

6.3 Retention of Records

All information, documents and records received from customers are retained for a period of 8 years in accordance with Article 8 of the Law.

7. RISK MANAGEMENT

Risk management activities cover, at a minimum, the identification, rating and assessment of customer risk, service risk and country risk; the monitoring and control of risky customers and transactions; and the tracking of national and international standards.

8. MONITORING AND CONTROL ACTIVITIES

DEMAŞ A.Ş. carries out its monitoring and control activities with a "risk-based approach" in order to ensure the correct and effective implementation of the Compliance Programme. In the event that suspicious transactions are identified, a report is made to MASAK (the Financial Crimes Investigation Board).

9. CONTINUOUS LEARNING PROGRAMME – TRAINING POLICY

All employees are regularly given training on money laundering, the financing of terrorism and codes of conduct. The Compliance Department submits training statistics to MASAK in the first quarter of each year.

10. INDEPENDENT AUDIT

The Board of Directors conducts audits regarding the adequate and efficient implementation of the compliance programme through the Compliance Department and other departments. Corrective action plans are created and monitored for the findings identified.