Our business partners

>

Business partner management framework

We work with a range of business partners and expect them to share our commitment to ethical business practices and conduct. Business partners include our suppliers, customers, joint ventures (JVs), JV partners, service providers and other counterparties.

We have a comprehensive framework for managing the key risks associated with our business partners, from onboarding and ongoing monitoring through to offboarding. Through this framework, we seek to comply with applicable laws (including on corruption and bribery, sanctions, money laundering and tax evasion) and manage the reputational risks that can arise from engaging with certain types of business partners.

We assert our influence over JVs we don't control to encourage them to act in a manner consistent with our Values and Code of Conduct.

Our business partner management framework seeks to ensure that all business partners are assessed using a risk-based approach, which directs them to the most appropriate due diligence and management process. These processes include KYC, community investment due diligence and management, third party due diligence and management, or joint ventures, mergers and acquisitions, and disposals.

Know your counterparty processes

Our KYC processes differ for our marketing and industrial business counterparties. While we have a Group-wide approach to managing counterparties in our marketing business through the KYC Procedure – Marketing, counterparties engaged by our industrial assets are managed through local procedures which meet the minimum requirements of the KYC Standard – Industrial Assets to accommodate different local onboarding processes.

Each process applies a risk-based approach for suppliers, customers, service providers and trading counterparties (together referred to as counterparties).

The counterparty onboarding phase includes a preliminary step to determine the applicable process: KYC (marketing or industrial assets); third party due diligence and management; or joint ventures, mergers and acquisitions, and disposals. We then assign a risk rating (where applicable) and determine the type of due diligence required.

KYC Procedure – Marketing

The KYC Procedure – Marketing sets out the steps we take for marketing counterparties, including onboarding and due diligence of new counterparties, renewals of existing counterparties and, where required, mitigating measures and controls.

Our marketing counterparties include customers, suppliers, service providers and trading counterparties that are not classified as high-risk business partners under the Third Party Due Diligence and Management Procedure.

The KYC process is currently conducted through Diligent Third Party Manager (Diligent 3PM), a Group-wide system for implementation of the KYC Procedure – Marketing.

Where the KYC Procedure – Marketing applies, different levels of due diligence are applied depending on the risk rating of the counterparty.

Depending on the counterparty's assigned risk rating as well as any red flags identified in the course of due diligence, requirements may include:

  • screening the counterparty, its ultimate beneficial owners and directors in WorldCheck One, our sanctions and regulatory list screening tool;
  • screening the counterparty, its ultimate beneficial owners and directors, using our adverse media screening tools;
  • receipt of duly completed questionnaires (depending on the information to be requested from the business or counterparty);
  • collection and verification of company, ownership and directorship information from relevant sources, such as trade registers or other approved sources;
  • receipt of other supporting documentation (e.g., representation letters);
  • identification of the ultimate beneficial owners of the entity; and
  • receipt of a valid passport copy for ultimate beneficial owners.

Once due diligence is complete, the KYC team prepares a risk report which summarises:

  • relevant counterparty information;
  • the business justification;
  • any concerns or red flags; and
  • controls and mitigating actions to reduce identified risks.

This report is written by a KYC team member and then approved or rejected by a member of the Compliance team with the relevant seniority according to the risk rating of the counterparty. If the relevant Compliance team proposes to reject the counterparty, the rejection is discussed with, and ultimately agreed with, the Head of Compliance. If the business challenges Compliance's decision to decline a counterparty, the engagement may ultimately be escalated to the BAC. Following approval, Compliance is responsible for ensuring that any specific risk mitigating measures required prior to the engagement are implemented.

Diligent 3PM notifies Compliance shortly before a counterparty's KYC is due for renewal. The renewal process is effectively a repetition of the onboarding process. The frequency of the KYC renewal depends on a counterparty's risk rating.

Compliance documents any red flags and mitigating measures in Diligent 3PM. The business is expected to monitor these red flags and comply with identified mitigating measures.

In addition, Compliance monitors trades with certain counterparties identified as higher risk. If new trades are entered into the system with such counterparties, Compliance is notified and takes appropriate action. Compliance may also impose controls on payments to such counterparties by requiring outgoing payments to be approved by Compliance in the relevant payment system in order to be released.

Compliance also documents all counterparties under the KYC Procedure – Marketing and KYC Standard – Industrial Assets that have been rejected or are associated with material red flags in the Declined Party & Red Flag List.

Finally, counterparties are automatically screened by WorldCheck One overnight to identify any new red flags. Compliance reviews all hits and takes appropriate follow-up actions.

KYC Standard – Industrial Assets

Lower-risk counterparties engaged by the industrial assets are managed through local procedures which meet the minimum requirements of the KYC Standard – Industrial Assets. The standard sets out the due diligence requirements for engaging counterparties such as suppliers and service providers. The standard is risk-based and the requirements for counterparties are determined based on the category of goods or services provided, annual spend and supplier country. Under the standard:

  • the lowest risk counterparties are subject to overnight screening only;
  • most counterparties are also screened prior to onboarding; and
  • for certain types of counterparties, further information is gathered via a questionnaire, including on the identity of ultimate beneficial owners (UBOs) and directors. UBOs and directors are also subject to screening.

The standard establishes decision making, approval and escalation processes and sets out requirements for renewal and termination. It also requires procedures to be in place to block or deactivate counterparties where there are compliance concerns. These counterparties may not be reactivated without Compliance approval.

Third Party Due Diligence and Management Procedure

Our Third Party Due Diligence and Management (TPDDM) Procedure applies across our offices and industrial assets. It sets out a detailed, risk-based assessment process whereby we identify, manage, mitigate and monitor the corruption risk exposure of those third party engagements presenting the highest risk to our business.

Business partners determined to be higher-risk third parties include:

  • business-generating intermediaries (such as marketing sales and purchase agents, distributors, certain physical brokers, profit share partners and back-to-back purchasers); and
  • government-facing intermediaries (such as customs clearing agents/brokers, lobbyists, law and tax firms, port agents/agencies, freight forwarders and work permit/visa processors).

These third parties are higher risk because they often act on our behalf, interact with public officials on our behalf or engage in activities that have been identified as posing a heightened risk from a corruption perspective.

The TPDDM Procedure sets out the steps we take in respect of the management of third parties, including onboarding and due diligence, contract terms/scope of services, training, monitoring and payment reviews/controls, renewal, and termination and offboarding.

Disclosure of marketing sales and purchase agents

Given the inherent risks associated with marketing sales and purchase agents, we only engage marketing sales and purchase agents who provide a clear, tangible service that would otherwise need to be provided by our employees, and where we have no office or on-the-ground presence.

In line with our approach to transparency and the Natural Resource Governance Institute's recommendations, we publish and keep updated a list with the names and ultimate beneficial owners of all marketing sales and purchase agents. These agents perform substantive tasks for or on behalf of Glencore, such as engaging on business matters with existing and potential customers. Their contracts are renewed annually following fully refreshed due diligence and audit by an independent auditor.

Read more: Our approach to transparency

 

 

Third party lifecycle

The onboarding phase includes a number of steps, such as a risk assessment and due diligence.

After the third party has been classified in Diligent 3PM:

  • the proposing employee automatically receives an invitation to complete the relevant internal questionnaire and must provide a business justification for the engagement or transaction; and
  • the third party automatically receives an invitation to complete the relevant external questionnaire and must provide the required due diligence documentation.

With this information, the proposed engagement is assigned a risk score by Diligent 3PM, which is calculated based on the following criteria:

  • third party risk: considers the type of third party and its ownership;
  • country risk: the risks associated with the country in which the services are to be provided, taking into account a Glencore bespoke risk matrix (Anti-Corruption and Bribery Country Risk), which reflects leading anti-corruption indices such as Transparency International's latest Corruption Perceptions Index (CPI) Score and TRACE International's Bribery Risk Matrix; and
  • remuneration risk: considers the overall value of the engagement and proposed type of payment structure.

Third parties receive a risk rating of severe, high, medium or low based on their risk score. All third parties (including ultimate beneficial owners, directors, shareholders and employees working on the engagement) must at this stage be checked using relevant sanctions and adverse media screening tools. This screening includes checks against Compliance's Declined Party & Red Flag List, which includes entities which have previously been rejected, terminated or that are currently monitored for compliance reasons and with whom we prohibit or restrict business interactions. If a proposed third party appears on this list as a declined party, onboarding will not proceed unless an exception is approved by the Head of Compliance.

Compliance next performs due diligence on the third party. Depending on the third party's assigned risk rating, due diligence requirements may include:

  • completion of an enhanced due diligence report by an external service provider;
  • review of the third party's compliance policies and procedures (to the extent a third party has them);
  • conducting an interview with the proposing employee and separately with the third party;
  • conducting a reference check;
  • verification of the third party's standing against public online registers;
  • confirmation that the third party is the account holder of the bank account used for the engagement and that it is in the same country where the third party is incorporated or where services are being provided;
  • review of proposed compensation to ensure it is market-standard in the country in which the services are provided;
  • review of financial statements; and
  • identification of other red flags.

Once due diligence is complete, Compliance drafts a report which summarises the proposed engagement, including:

  • relevant third party-related information;
  • the business justification;
  • any concerns or red flags identified during the due diligence process;
  • any mitigating measures required to address identified red flags;
  • a recommendation from Compliance on whether the third party should be engaged; and
  • any applicable monitoring requirements.

By way of example, Compliance's red flag assessment includes whether:

  • the third party, its beneficial owners or shareholders have a track record of adverse media coverage or are listed on a sanctions watchlist;
  • the third party's employees, shareholders or beneficial owners are past or present public officials or politically exposed persons, or whose close relatives are/were;
  • the third party's employees, shareholders or beneficial owners have a close personal relationship with any public official or representative of a commercial counterparty;
  • the third party and/or its employees, shareholders or beneficial owners is/are associated with public entities;
  • the third party has been recently incorporated or has an unusual corporate structure (including complex or offshore ownership or banking structures);
  • the identification information cannot be readily verified or is inconsistent with the information in the external questionnaire;
  • the third party failed to provide complete responses to the due diligence;
  • the third party was unwilling to disclose its beneficial owners;
  • the third party uses subcontractors to deliver part of the services under the engagement;
  • the proposed payment terms contain upfront amounts, commissions, bonuses or elements dependent on success factors or they appear to be above market rate;
  • the third party offers gifts and entertainment to public officials;
  • there is a conflict of interest between the third party and a Glencore employee; and
  • the third party's policies and procedures (where provided) materially conflict in any way with Glencore's.

This report is reviewed, and the engagement is approved or rejected, by:

  • Compliance per defined approval levels;
  • for offices, the head of department or corporate function or the line manager of the employee proposing the third party engagement depending on the type of engagement; and
  • for industrial assets, the CEO, General Manager, CFO, or, in their absence, a senior member of management of that industrial asset or the line manager of the employee proposing the third party engagement, depending on the type of engagement.

If Compliance and the business cannot reach an agreement on whether to engage a third party, they may escalate the matter to the Head of Compliance. If an agreement cannot be reached, the Head of Compliance may refer the matter to the BAC.

Following approval, Compliance, in coordination with the employee responsible for the third party relationship, is responsible for ensuring that any mitigating measures included in the report are recorded on the third party's due diligence file and that any specific measures required prior to engagement are implemented.

The TPDDM Procedure does not permit us to start an engagement with any third party without having a written agreement in place. Compliance works with the proposing employee and Legal to include compliance clauses in the written agreement. Compliance ensures that documentation for the engagement is complete and that relevant documentation is uploaded onto Diligent 3PM.

We also have in place specific template service agreements with tailored compliance clauses that we use for our severe and high risk intermediaries and a template agreement we encourage to be used for any charitable contributions or sponsorships we provide.

Third parties ranked as severe or high risk also receive an onboarding pack which the third party must acknowledge receipt of and which includes:

  • a summary of our compliance requirements and what we expect from our business partners;
  • a copy of our Code of Conduct;
  • a copy of our Supplier Code of Conduct;
  • a copy of our Anti-Corruption and Bribery Policy;
  • a copy of our Responsible Sourcing Policy;
  • a description of our Raising Concerns Programme; and
  • for road transporters, a copy of our 'Say no to Facilitation Payments' leaflet.

They must also acknowledge that they have read, understood and will comply with our policies.

Compliance ensures that third parties onboarded under TPDDM Procedure receive relevant training in accordance with the Third Party Training and Monitoring (TPTM) Plan. Training requirements for third parties, including the frequency of training, vary according to the third party's risk rating and include digital training as well as in-person anti-corruption and bribery training. Where relevant to their engagement, third parties are also enrolled in market conduct digital training.

After third parties are engaged, in addition to training, Compliance actively monitors the engagement to ensure that third parties are providing the services they have been contracted to provide.

Compliance and the business work together to manage and monitor third parties in accordance with the TPTM Plan, which outlines requirements for third parties based on their risk rating and the nature of their engagement. GIAA also monitors the application of aspects of the TPDDM Procedure generally and the TPTM Plan on an ongoing basis.

For severe and high-risk third parties, the employee within the business who is assigned to work with that third party on a regular basis, must monitor the third party. They maintain records of communications and services provided by the third party, inform Compliance of any material changes to the way the third party provides its services, request and review the third party's activity reports and liaise with the Corporate Compliance Anti-Corruption and Bribery team prior to making any amendments to the third party's terms, commission levels or payment structures.

Group Compliance is required to review and approve in advance the invoices of and payments to all severe and high-risk business-generating intermediaries, to confirm that payments match the agreed contract rates, and that invoices include necessary details and are itemised to clearly indicate the services provided. Payments to third parties for any work carried out without a written agreement or acknowledgement in place are prohibited without approval from the Anti-Corruption and Bribery team. On a weekly basis, Corporate Compliance receives reports outlining:

  • invoices relating to customs clearance;
  • any new business partners that have been booked in the relevant payment system as providing customs clearance; and
  • any new law firms engaged to interact with public officials on Glencore's behalf.

These enable Compliance to mitigate the risks that business partners are not taken through the appropriate due diligence (TPDDM Procedure) when interacting with public officials (e.g., by conducting customs clearance or representing Glencore in legal proceedings) in high-risk jurisdictions.

Auditing and site visit requirements for third parties are two fundamental elements of the TPTM Plan. Depending on the third party's risk rating, these requirements may consist of a full financial audit performed by an external auditor and/or a site visit by Group Compliance. In addition to audits and site visits, Compliance, in consultation with the business, reviews activity reports containing detailed information on the nature of services that the third party performs.

For third parties rated severe and high risk, Compliance additionally corroborates the information received through the activity reports via interviews conducted periodically.

In total, depending on the third party's risk level, a third party's training and monitoring activities within a period of one year may include:

  • a full financial audit by external auditors;
  • twice-yearly reviews of activity reports and interviews;
  • digital learning and in-person anti-corruption training and, where appropriate, market conduct training;
  • onboarding and due diligence renewal;
  • daily adverse media and sanctions screenings;
  • compliance certifications; and
  • review and pre-approval by Compliance of any payment.

Compliance coordinates the process of renewing third party relationships with the proposing employee or the Glencore Business Third Party Manager, in accordance with the TPDDM Procedure.

Depending on the third party's assigned risk rating, the renewal process may include:

  • obtaining an updated internal questionnaire, or confirmation of no changes to the previous questionnaire;
  • obtaining an updated external questionnaire (or confirmation of no changes to the previous questionnaire) and relevant due diligence documents;
  • re-screening or requesting an updated enhanced due diligence report on the third party and its shareholders, beneficial owners and directors; and
  • preparation of a renewal compliance report reflecting any identified changes, including to beneficial ownership and scope of services and an assessment of whether there have been any issues identified by the business during the course of dealing with the third party, including lack of competence, difficulties raised over compensation, general ethical concerns, unusual requests and implementation of any mitigating measures.

If a severe or high-risk third party engagement expires without being renewed, or if the engagement is terminated, Compliance will coordinate with the business employee responsible for the relationship and Legal to send the third party an end-of-service termination letter. This letter will confirm that the engagement has expired/been terminated and that the third party must cease performing services for Glencore and will not be paid for any future services performed. The relevant business employee must ensure the third party is deactivated in the relevant accounting or finance systems at the office or industrial asset.

If a third party engagement is terminated due to compliance concerns (regardless of risk level), Compliance must add the third party to the Declined Party & Red Flag List, change the third party's status to inactive in Diligent 3PM, and liaise with the business to deactivate the third party from the relevant accounting or finance systems at the office or industrial asset. Any reactivation of declined third parties must be approved by the Head of Compliance.

If a third party engagement is not renewed and there are no compliance concerns, the third party is placed in inactive status in Diligent 3PM and the relevant accounting or finance systems and cannot be re-engaged without going through the onboarding process again.

We make discretionary and non-discretionary community investments that are intended to create a lasting social and economic benefit for the communities where we operate. The structures in place that facilitate these investments (e.g., a foundation or community investment agreement (CIA)) can be Glencore controlled or third-party controlled and often involve working with local stakeholders such as members of local communities, civil society organisations, local municipalities or other government institutions.

In some cases, we have limited or no control over the governance of third-party controlled structures, the selection of projects or the suppliers engaged in connection with the community investment. It is therefore not always possible to apply full KYC or TPDDM to the community investment, as we do when it is Glencore controlled.

The Community Investment Due Diligence and Management Procedure (CIDDM Procedure) caters to the nuances around community investments and enables us to adopt a more risk-based, proportionate approach to the compliance due diligence of community investments.

The purpose of the CIDDM Procedure is to set out:

  • the level of due diligence to apply when we seek to enter into a new community investment (i.e., we become a party to a foundation or other type of arrangement);
  • the level of due diligence to apply when we make a community investment directly or pursuant to an existing foundation or other type of arrangement; and
  • mitigating controls that we should seek to implement to manage the compliance risks associated with community investments.

Entering into new foundations or CIAs

While we may not always be able to negotiate the terms of our entry into new foundations or CIAs, for example, because they are non-discretionary, in principle we seek to avoid agreeing to enter into new third-party controlled foundations or CIAs where we are unable to implement appropriate mitigating controls, except in exceptional circumstances. Examples of mitigating controls include:

  • including Compliance-related representations and warranties in relevant agreements;
  • agreeing veto or voting rights over a project, supplier engagement and any other proposal in connection with a community investment;
  • monitoring and/or reviewing the foundation or CIA's compliance with, for example, the terms of the CIA, the provision of a community investment and the use of funds in connection with community investments;
  • including Glencore representation on relevant committees;
  • conducting due diligence on the suppliers and/or beneficiaries (as relevant);
  • conducting ongoing screening of suppliers and/or beneficiaries (as relevant) in our sanctions screening tool;
  • monitoring the use of funds where we have identified a specific compliance risk that we are seeking to manage;
  • reviewing annual reports, to the extent that a foundation or CIA publishes annual reports, financials and/or provides written updates to stakeholders; and
  • where appropriate, leveraging existing supplier networks to provide in-kind support to a project or procure the community investment ourselves.

To assess the mitigating controls that we should seek to apply, we conduct a compliance risk assessment. This assessment also determines whether we should, in principle, provide the community investment. Risk factors include:

  • whether it is made through a Glencore controlled or a third-party controlled vehicle (e.g., a fund or foundation);
  • whether it is discretionary or non-discretionary (e.g., pursuant to a court order or because it is required by law);
  • the country in which the community investment will take place;
  • whether any suppliers will be involved in the project selection, execution and/or management of the community investment;
  • any government institution, public official or politically exposed person (PEP) involvement;
  • whether the initiative might, directly or indirectly, personally benefit or otherwise provide anything of value to a public official;
  • the overall value and length of the project; and
  • the nature of the contribution (i.e., financial contributions, in-kind provision of goods/services and/or in-kind personnel time).

Where the community investment is made directly or via a Glencore controlled foundation, the risk assessment informs the decision on whether to apply KYC or TPDDM to the investment.

Where the community investment is made pursuant to an existing third-party controlled fund, foundation or other arrangement, the risk assessment also takes into consideration existing controls and determines any additional controls we should seek to implement in addition to the applicable due diligence we should apply to any suppliers engaged to manage or execute the community investment.

Our Joint Ventures, Mergers and Acquisitions, and Disposals Procedure (JVMAD Procedure) requires that our Ethics and Compliance Programme is implemented at all JVs that we control or operate.

For those JVs we do not control or operate, we seek to influence our JV partners to adopt our commitment to responsible business practices and implement appropriate compliance programmes accounting for the nature and risks associated with the JV and JV partners, and which meet the minimum requirements as determined by Glencore.

In respect of M&A activity, we conduct thorough pre-transaction due diligence. Our JVMAD Procedure requires us to rank the risk of each M&A and JV transaction on the basis of the information typically available in the early stages of the transaction, including considering the relevant jurisdictions, the future JV partners and/or target entity, and the level of control or ownership that we intend to acquire. The risk category assigned determines the compliance due diligence steps that we take in connection with the transaction which may only be varied with the approval of the Head of Compliance.

The pre-transactional due diligence process includes:

  • initial approval by the relevant head of marketing department or industrial lead;
  • due diligence of JV partner/purchaser and/or JV operation/M&A target;
  • assessment of due diligence findings;
  • determination of JV level of control;
  • determination of compliance provisions and Ethics and Compliance Programme requirements in the relevant agreement; and
  • preparation of a compliance report.

Transactions rated as "high risk" also require us to obtain a transaction-specific enhanced due diligence report from a third party on the relevant counterparties (i.e., target entity, JV partner/seller), and interview the representatives from the compliance function at JV partners/sellers and/or operating company.

To commence the process, the relevant commodity department seeking to enter into a JV/M&A transaction or dispose of an undertaking nominates an employee to serve as the transaction responsible person (TRP), who must manage the JV/M&A transaction or disposal with Compliance. Before starting due diligence, the TRP is required to obtain approval for the transaction/disposal in principle from the Head of Department and notify Compliance.

All JV partners and the target JV operation itself, regardless of our anticipated ownership or operational control of the proposed JV, are subject to due diligence. The TRP responds to an internal questionnaire and informs Compliance of any red flags that they are aware of or unusual payment requests made by any party. The TRP works with the Legal and Compliance functions to gather the documentation and information required from the JV partner/target entity to perform thorough due diligence, which includes responses to an external questionnaire and additional documents requested.

A post-transaction risk assessment and review for all target entities in which we acquire majority ownership or control is also required. This review consists of three primary components: (1) an initial risk assessment, to understand the risks particular to the newly acquired entity and its operation; (2) transaction testing, to assess the control environment and risk prevention mechanisms, as well as to identify any potential misconduct that may need to be reported; and (3) a compliance programme gap analysis to assist in implementing the Ethics and Compliance Programme. Upon completion of these activities, Compliance develops a compliance programme implementation plan to implement our Ethics and Compliance Programme at the entity.

When we dispose of our interest in JVs, business undertakings or operations, we conduct due diligence on the purchaser, which focuses on source of funds, reputational issues and money laundering risks.

Compliance assesses the compliance risks of the transaction by considering the risks associated with the proposed JV partners, the existing business or operations in which we will acquire an interest, the risks associated with the proposed business undertaking/operation of the JV/M&A activity going forward, and/or the risks associated with the purchaser in a disposal transaction (including the source of funds).

Compliance issues recommendations on mitigating any identified compliance risks, including working with Legal to set out the proposed mitigating actions and remedies in the JV, M&A or disposal agreements.

Compliance management in JVs

After the completion of due diligence and assessment of the compliance risks associated with a JV partner and its JV operation, Compliance, Legal and the relevant commodity department determine the level of control we should seek to exert over the JV in light of the risks identified, our commercial objectives, and our negotiating leverage with the JV partner(s). The extent of our control will generally be linked to the percentage of ownership we will have in the JV. However, if the compliance risks associated with the JV are assessed to be high, Compliance and the business may determine that in order to mitigate those risks we need to obtain control that is disproportionate to our level of ownership. The JV's compliance programme requirements will vary based on our level of ownership and control.

For non-controlled JVs where we hold 20% or more of the voting rights, and for independently managed JVs, we require that JVs implement a compliance programme that is appropriate for the JV, having regard to the nature and risks associated with the JV, and that meets certain minimum requirements. To ensure these requirements are met, relevant compliance provisions are included in the applicable agreements. For non-controlled JVs where we hold less than 20%, we make reasonable efforts prior to entering into the JV to influence the JV to adopt an appropriate compliance programme.

In respect of all non-controlled JVs, we seek to influence the JV's approach to compliance through the activities and advocacy of any board members that we appoint. Such board members undergo compliance training, which allows them to be aware of compliance risks, raise compliance issues during board meetings, regularly request and review audit reports, and ensure that dissatisfaction with board decisions we are unable to block is duly recorded. In addition to the JV board member training, we publish a brochure on our Ethics and Compliance Programme's core elements which provides additional key guidance for board members we appoint. Compliance also seeks to regularly liaise with a compliance contact at relevant JVs.

Existing non-controlled JVs

For non-controlled JVs already in existence when the JVMAD Procedure was initially rolled out in 2020, Compliance conducts risk assessments on a periodic basis, which include a review of the JV's compliance programme measured against the core elements of an effective compliance programme. Broadly speaking, this includes assessing:

  • compliance resources at the JV;
  • whether the JV has a code of conduct and compliance policies and procedures governing topics such as anti-corruption and bribery, gifts and entertainment, conflicts of interest, charitable contributions and sponsorships, whistleblowing, interactions with public officials, sanctions, anti-money laundering and data privacy;
  • how the JV manages third party relationships;
  • whether there is a confidential reporting structure and investigations process in place;
  • compliance incentives and disciplinary processes; and
  • monitoring, testing and review of the compliance programme in place.

Depending on the outcome of the risk assessment and any follow-up engagement with the JV partner, we may recommend additional compliance measures.

Types of JVs in our framework

Glencore-controlled JVs

A JV that is Glencore-controlled or-operated is an entity where we are responsible for controlling or operating the JV and implementing relevant policies, systems and controls. This model of control must be applied in any JV where we hold more than 50% of the voting rights. For controlled/operated JVs, we require that the JVs implement our Ethics and Compliance Programme, including all policies, standards and procedures. We monitor and implement controls where our Ethics and Compliance Programme applies, as we would with any other Glencore entity.

Non-controlled JVs

We differentiate between two types of non-controlled JVs: partner-controlled JVs and independently managed JVs.

Partner-controlled JVs

A JV in which the JV partner controls or operates the JV and implements compliance policies, systems and controls. This level of control creates more risk for us since it relies on the JV partner to control and operate the JV and implement appropriate systems and controls. It is therefore only acceptable if we hold less than 50% of the voting rights and if we are satisfied that the JV partner has (or makes commitments that it will have) the resources and ability to implement an appropriate compliance programme.

Independently managed JVs

JVs which operate independently from the shareholders, meaning that an independent board of directors, management and corporate functions, including finance, legal and internal audit, will be established for the purpose of operating the JV. The shareholders' involvement in the JV is typically limited to participation in the board and shareholder governance bodies. This level of control can be acceptable for all levels of Glencore ownership, although it is typically not implemented where we hold more than 50% of the voting rights. For independently managed JVs, we are required to ensure the JV has the resources (or makes commitments to expand its resources) to implement an appropriate compliance programme without the support of its shareholders.

Important notice
This material does not purport to contain all of the information you may wish to consider. For further important information, including in connection with forward-looking statements and other cautionary information, refer to the Important notice section of Glencore's latest Annual Report, which is available at glencore.com/publications.