Anti-bribery and corruption
The Group is committed to conducting business with honesty, fairness, and transparency. Bribery and corruption are strictly prohibited in all forms, and every employee has a responsibility to uphold this standard. The policy expects all staff to act with integrity in their daily work and to avoid any behaviour that could compromise the company’s reputation or compliance with the law.
Bribery includes offering, giving, requesting, or accepting anything of value to improperly influence decisions, while corruption refers to the abuse of entrusted power for personal gain. Facilitation payments, small, unofficial payments made to speed up routine actions, are also prohibited.
We ask employees to avoid conflicts of interest, where personal interests interfere with professional duties, and must disclose any potential conflicts to management. Gifts and hospitality are only acceptable if they are modest, customary, and transparent. Cash gifts, lavish entertainment, or anything that could create an obligation are not permitted.
To support employees in following this policy, the company provides regular training sessions to help employees recognise and prevent bribery and corruption risks. Annual risk assessments are conducted across operations, supported by internal monitoring systems designed to detect and investigate suspicious activity.
Employees have the opportunity to raise concerns about any suspicion at the earliest possible opportunity. If they are unsure whether a particular act constitutes bribery or corruption, or if they have any queries these should be directed to the GMLRO, DMLRO, or by sending an email to Whistleblowing@osb.co.uk. Managers are responsible for ensuring compliance within their teams, and senior leadership at The Group provides oversight to ensure the policy is effectively implemented.
All financial transactions must be accurately recorded and subject to audit, and any gifts, hospitality, or charitable donations must be pre-approved by management.
The Group expects third parties to comply with all applicable laws, statutes, codes and regulations relating to the prevention of tax evasion (including but not limited to the Criminal Finances Act 2017), bribery and corruption (including but not limited to the Bribery Act 2010). Therefore, third parties must ensure that they have policies in place to stop all types of bribery, corruption and corporate tax evasion and that their employees, contractors and third parties abide by local laws and legislation including but not limited to any sanctions in place.
The Group will conduct due diligence and ongoing monitoring of third party relationships to ensure adherence to this policy and reserves the right to terminate any relationship where bribery or corruption risks are identified.
Alignment with Economic Crime and Corporate Transparency Act 2023
On 1 September 2025, the corporate offence of Failure to Prevent Fraud under the Economic Crime and Corporate Transparency Act 2023 came into effect. This legislation requires large organisations to implement reasonable procedures to prevent fraud carried out by associated persons acting for their benefit. The Group is committed to meeting these obligations and has embedded robust governance and risk management frameworks, including comprehensive fraud risk assessments, proportionate controls, and ongoing monitoring. Oversight is provided by the Board and Board Committees, supported by clear policies, staff training, and regular reviews, ensuring alignment with statutory guidance and reinforcing our zero-tolerance approach to financial crime.
Artificial intelligence governance
The Group operates a single, Board-approved AI governance framework that applies across the full AI value chain. It provides the authoritative basis for how AI is governed and used across the Group.
The framework enables the responsible and proportionate adoption of AI, with governance and oversight scaling in line with risk and impact. Executive accountability is embedded throughout, ensuring AI-related risks are managed transparently and in line with regulatory expectations while supporting safe innovation.
Conflicts of interest policy
The Groups policy, is focused on identifying and managing conflicts and commits to preventing them whenever possible. It is incorporated into the mandatory financial crime training for all employees and into the Vendor Management and Outsourcing Policy, ensuring an integrated and consistent approach. The Group Compliance function oversees the conflicts of interest register, which is reviewed quarterly and annually by the Group Nomination and Governance Committee for Executives and Directors.
Cyber security
The Groups cyber resilience programme is founded on recognised frameworks for cyber risk and controls, including those from the National Institute of Standards and Technology, the Microsoft Cloud Security benchmark, and the Centre for Internet Security. Oversight is provided across the conventional three lines of defence, with reporting structures established for governance committees and the Group Board. The framework not only facilitates effective reporting but also continuous improvement to our cyber security posture and in addressing potential vulnerabilities.
The cyber programme aims to deliver robust counter-measures, effective monitoring, and a responsive approach to incidents in the face of both existing and evolving threats. The Group conducts regular security testing and engages independent reviews from specialised CBEST-accredited third parties to evaluate the effectiveness of its operational and technical capabilities in cyber resilience, which are necessary for regulated financial services organisations.
Data privacy policy
The Group is committed to protecting the privacy and personal data of all individuals, including our customers, employees, suppliers, and stakeholders. We recognise that responsible data handling is essential to maintaining trust and complying with legal obligations. This statement outlines our approach to data protection, focusing on our internal policies and practices, and how we monitor and improve our performance.
We operate under a comprehensive data governance framework that aligns with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our internal policies define how personal data is collected, processed, stored, and shared across the Group. These policies are designed to ensure that data is handled in line with the key principles of data protection law.
Key practices include:
- Clear privacy notices that inform individuals about how their data is used and their rights.
- Role-based access controls to ensure that only authorised personnel can access sensitive information.
- Appropriate security measures, including encryption and secure storage controls, to protect data where applicable.
- Data minimisation principles to ensure we only collect what is necessary for specific purposes.
- Mandatory training for all employees on data protection responsibilities and ethical handling of information.
We also require our suppliers and third party partners to adhere to equivalent data protection standards through contractual agreements and due diligence processes.
How We Monitor and Improve Our Performance
The Group continuously monitors its data protection practices to ensure compliance and identify opportunities for improvement. We conduct regular audits, risk assessments, and internal reviews to evaluate the effectiveness of our controls and identify any vulnerabilities.
Our Data Protection Officer advises and monitors internal practices and reports to senior management on performance metrics, incident trends, and regulatory developments. We maintain a breach reporting protocol and investigate all incidents thoroughly, using findings to strengthen our safeguards.
We also engage with external experts and regulatory bodies to stay informed about evolving best practices. Feedback from customers, employees, and partners is actively encouraged and used to refine our policies and enhance transparency.
By embedding privacy into our culture and operations, we aim to uphold the highest standards of data ethics and ensure that personal information is treated with the care and respect it deserves.
Below are our privacy policies:
CCTV, Suppliers & Visitors Privacy Policy
Mortgages and Loans Privacy Policy
Documents and links
To contribute to a sustainable future, the Group aligns with but not limited to various organisations and initiatives, including:
ESG management
The Board approved ESG Strategy, annual materiality assessment and ESG Operating Framework are the key tools deployed by the Group for identifying, measuring, managing and reporting ESG risks while enabling the identification and pursuit of opportunities where the Group can create positive impact for our stakeholders.
We continue to evolve our understanding of the impacts ESG related topics have on the Group and the impact our business has on society and the environment. In 2025, we considered financial materiality and impact materiality within our assessment of risk and opportunity, the outputs of which are shared annually with the Board and Executive Committee for consideration in strategic planning.
Kal Atwal (Non-Executive Director) maintains responsibility for championing ESG matters on behalf of the Board, with Sally Jones-Evans (Non-Executive Director) designated as People Champion representing the views of employees within Board discussion and decision making.
To ensure accountability and monitor progress, the Group links ESG performance to executive and senior management compensation through the Performance Share Plan. Progress against targets linked to remuneration is reported to the ESG Forum, Group Executive Committee and the Board on a monthly basis.
The diagram shows the governance mechanisms that are in place to manage and oversee ESG matters across the Group, how often these committees and forums meet and the matters considered.
Find out more about our Governance chart
In 2025, the Group continued its commitment to sustainable business, making its second submission as a signatory of United Nations Global Compact. We continue to embed the ten principles of the UN Global Compact within our business operations though the ESG Operating Framework’s principles and commitments.
Financial crime policy including anti-money laundering (AML)
The Group is committed to preventing money laundering, terrorist financing, and financial crime across all areas of its business. We adopt a zero tolerance approach and comply fully with applicable laws and regulations, including the UK Money Laundering Regulations, the Proceeds of Crime Act, and guidance from the Financial Conduct Authority (FCA). The policies concerning Sanctions, Anti-Money Laundering, Anti-Bribery and Fraud have been integrated into a unified Group Financial Crime policy through ongoing improvement initiatives. The policy is a vital component of our Group Financial Crime Risk Management Framework and is reviewed and approved annually by the Group Audit Committee.
Roles and Responsibilities
The Groups policy, operates a ‘Three lines of defence’ model to manage and oversee Financial Crime Risk. The first line of defence is the business and support functions. The second line of defence comprises the Compliance and Financial Crime functions that oversee Financial Crime Risk. The third line of defence is the Group’s Internal Audit function which is an independent function that provides objective assurance that financial crime risk and the control arrangements implemented by the first line of defence and the second line of defence are designed effectively and are being executed as prescribed.
The Internal Audit function is led by the Group Chief Internal Auditor who reports directly to the Chair of the Group Audit Committee (GAC) and administratively to the Chief Executive Officer. The Board is responsible for this Policy and delegates the task of approving this Policy, together with the provision of direction and support to ensuring effective implementation and oversight to the Group Audit Committee and Group Money Laundering Reporting Officer (GMLRO). This policy applies to all employees, subsidiaries, contractors, and third parties acting on behalf of The Group.
Objectives
- Prevent and detect money laundering and related financial crimes
- Conduct customer due diligence (CDD) and enhanced due diligence (EDD) where required
- Identify and report unusual or suspicious transactions
- Verify clients and beneficial owners of unusual activity
- Take measures against clients using services for criminal conduct
- Maintain accurate records in line with regulatory requirements
- All employees participate in mandatory Financial Crime awareness training on an annual basis to foster a culture of vigilance and responsibility.
Group data retention policy
The policy and underlying procedures set out measures to protect the personal data of our customers, employees and third parties and ensure adherence to the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. We view effective privacy practices as vital to our corporate governance and accountability framework. The Group Data Protection Officer provides reports to both the Group Executive Committee and the Board.
Group operational resilience policy
The Groups policy, reflects our commitment to enhancing operational resilience in order to meet the needs of our customers alongside our financial and legal obligations. This policy is intended to ensure that the Group complies with the supervisory regulator requirements. The policy establishes the operational resilience framework which incorporates a range of activities to prepare for, prevent, detect, respond to, recover from, and learn from disruptions. Regular review and testing takes place to support our resilience strategies so the Group can adapt to new threats, regulatory changes, and business evolution.
Responsible marketing policy for group financial promotions and communications
The Groups policy is to ensure that all marketing activities are clear, fair, and not misleading. We aim to build trust with our customers by delivering accurate, transparent, and responsible communications that reflect our values and regulatory obligations. Our marketing practices are designed to support informed decision-making and uphold the highest standards of integrity.
Our communication and content
We ensure that all marketing communications provide accurate, complete, and understandable information. We also commit to disclosing any potential negative consequences associated with our products to support informed decision-making.
The Group aligns with Principle 12 (the Consumer Duty), and the underpinning rules, impose a higher and more exacting standard of conduct than Principles Six or Seven. This applies in respect of all financial promotions, marketing and communications to regulated mortgage customers (including Consumer Buy to Let) and ‘retail’ savings customers (e.g. consumers, micro-enterprises, and charities with a turnover of with a turnover of <£1m). Principles Six and Seven will remain a consideration for communications in respect of all other customers.
The Group adheres to the Anti-Greenwashing rule and related non-handbook guidance (FG24/3) in respect of communications about any products or services with sustainability characteristics and will ensure that sustainability-related claims are:
- Correct and capable of being substantiated.
- Clear and presented in a way that can be understood.
- Complete – they should not omit or hide important information and should consider the full lifecycle of the product or service.
- Fair and meaningful in relation to any comparisons to other products or services.
About our approvals process
All marketing materials undergo a structured approvals process to ensure compliance with regulatory standards and internal guidelines. This process involves 3rd party tools, designed to safeguard the clarity, accuracy, and appropriateness of our messaging before it reaches our audiences.
How we monitor distribution and data
We actively monitor the distribution of our marketing content to ensure it reaches the appropriate audience. Our data oversight practices help us assess the effectiveness and ethical impact of our campaigns, ensuring alignment with our commitment to responsible targeting and customer protection.
Policy governance
The governance of our Responsible Marketing processes is overseen by senior leadership and reviewed periodically to reflect evolving standards and stakeholder expectations. We remain committed to enhancing the scope and depth of our policy as part of our broader ethical and compliance framework.
Tax strategy
OSB GROUP PLC (‘OSBG’) is required to publish its tax strategy for the OSB Group (being OSBG and its subsidiaries as at 31 December 2025) (‘The Group’) in respect of UK taxation in accordance with paragraph 16(2) Schedule 19 Finance Act 2016.
The Group’s tax strategy as set out in this document was approved by the Group Audit Committee on 23 September 2025.
Our business
The Group is a specialist lending and retail savings group authorised by the Prudential Regulation Authority (’PRA’), part of the Bank of England, and regulated by the Financial Conduct Authority and PRA.
The Group primarily targets underserved market sub-sectors that offer high growth potential and attractive risk-adjusted returns in which it can take a leading position and where it has established expertise, platforms and capabilities. These include private rented sector Buy-to Let, commercial and semi-commercial mortgages, residential development finance, bespoke and specialist residential lending, secured funding lines and asset finance. The Group is predominantly funded by retail savings and diversification of funding is currently provided by securitisation programmes and the Bank of England’s Term Funding Scheme with additional incentives for SMEs.
The Group operates through a number of subsidiaries in England and the Channel Islands, all of which are tax resident in the UK. The only non-UK tax resident subsidiary is OSB India Private Ltd (‘OSBI’), which is incorporated in India and provides back office processing support. OSBI earns a management fee for this service under an arms’ length transfer pricing arrangement.
Approach to tax risk management and governance
The Groups approach to risk management ensures effective identification, assessment and management of risk and is aligned fully to the Group’s strategy and its vision to be a leading specialist lender within its chosen markets. Effective risk management has generated shareholder value through the optimisation of the risk-reward profile which is framed within the wider strategy and risk appetite context.
The Group has an established Enterprise Risk Management Framework (‘ERMF’) which is subject to periodic review and approval by the Board and its committees. The modular construct of the ERMF, further details of which can be found in the 2025 Annual Report and Accounts on pages 140, makes it a dynamic, versatile and enduring framework. The integrated nature of the ERMF provides for improved Board oversight, engagement, and monitoring of the Group’s risk profile.
The Group has a prudent and proportionate approach to risk taking and management, which is reflective of its straightforward business model and its tax risk appetite is aligned to this. The Group adopts a low risk appetite in its approach to its tax affairs and tax strategy.