Consolidated Financial Statements of Eimskipafélag Íslands hf 2025 73
Non-Financial Reporting
Business ethics are governed through several key policies. The Company’s Code of Conduct serves as a central
framework, outlining expected behavior and reinforcing Eimskip’s values in daily operations. Additional policies
include the Supplier Code of Conduct, the Anti-Money Laundering and Sanctions Policy, and the Whistleblower
Procedure, all of which strengthen oversight and ethical compliance across the value chain.
In early 2025, Eimskip updated the Code of Conduct to improve clarity, practical relevance, and usability. The
revised version—available in Icelandic, English, and Danish. By the end of 2025, 81% of employees in the target
group have confirmed their acceptance of the reviewed Code of Conduct. The Company promotes a strong Speak
Up culture, offering multiple channels for raising concerns through managers, Human Resources, or formal
grievance procedures. A confidential Whistleblower mechanism is available for serious or unresolved matters,
supporting timely and responsible issue resolution.
Supplier code of conduct
Eimskip manages ESG-related risks across its value chain, ensuring that the Company’s core values guide daily
operations. Long-term supplier relationships are built on trust, responsibility, and shared objectives. The Supplier
Code of Conduct aligns with the UN Guiding Principles on Business and Human Rights, covering Health and Safety,
Human Rights, Labor Standards Business Ethics, and Environmental Protection. Eimskip is developing a due
diligence approach grounded in the OECD Guidelines for Responsible Business Conduct.
During the year, Eimskip further strengthened its due diligent framework in line with the OECD Guidelines. The
updated framework includes tailored assessment forms designed to identify and address the specific risks
associated with different supplier categories and operational contexts. Suppliers are expected to acknowledge the
Supplier Code of Conduct either directly or through their contractual agreements with the Company. Due diligence
training has been integrated into procurement training for the international employees, and the Company will
continue to develop and refine the training program.
Data ethics and responsible AI
Eimskip is committed to processing personal and business data in a lawful, fair, and secure manner, in alignment
with data ethics principles and the latest AI governance standards. The Company strives to comply with the General
Data Protection Regulation (GDPR), the EU AI Act, and other applicable laws, safeguarding the privacy and rights
of customers, employees, business partners, and stakeholders.
The Information Security Policy remains based on the NIST Cybersecurity Framework, which encompasses the
following key components: Govern, Identify, Protect, Detect, Respond, and Recover. In 2025, the policy was
updated to incorporate AI-specific risk management and ethical guidelines. These updates ensure that all AI use
aligns with Eimskip's values, legal obligations, and international standards. The policy now emphasizes ethical AI
practices, transparency when individuals interact with AI systems, and mandatory AI literacy training for employees
before granting access to AI tools.
To enhance data governance and prepare for responsible AI applications, Eimskip has extended its Data Security
Classification Framework to include AI datasets, ensuring transparency and fairness. All data used in AI-driven
processes is anonymized where appropriate and managed ethically to prevent bias or harm. The Company has
established an AI Center of Excellence to oversee compliance, maintain an AI Register for all use cases, and
implement post-market monitoring for AI systems. Furthermore, all AI solutions undergo compliance checks
against internal standards and the EU AI Act.
Eimskip continues to retain personal and business data only for as long as necessary, ensuring secure disposal when
no longer needed. The Company collaborates with third-party suppliers under a structured self-assessment
process to uphold compliance with internal and external standards. Educational materials on AI ethics and
cybersecurity have been added to the Eimskip Learning System, and AI literacy programs have been introduced for
employees.
By embedding data ethics and responsible AI principles into its operations, Eimskip reinforces its commitment to
security, transparency, and regulatory compliance