
Corporate Governance Statement Risk management Remuneration report
131
Business review Sustainability Governance Review by the Board of Directors Financial Statements
Company Auditor
The AGM elects the Auditor annually. The Auditor’s
term of office ends at the end of the next AGM following
election.
The Auditor is responsible for auditing the Company’s
accounts, its financial statements and Neste’s admin-
istration. The Auditor’s Report covers the Consolidated
Financial Statements and the Parent Company’s Finan-
cial Statements, and can be found in the Financial State-
ments section of the Annual Report
Internal Audit
Neste’s Internal Audit provides independent and objec-
tive assurance and advisory services designed to add
value and improve the operations of Neste. As a com-
ponent in the corporate governance process, it supports
the organization by bringing a systematic approach to
evaluating and improving the effectiveness of gover-
nance, risk management and control processes.
Internal Audit’s activities encompass objective exam-
inations for the purpose of providing assessments to
Neste’s Board’s Audit Committee and management
of the adequacy and effectiveness of governance, risk
management and control processes at Neste. The
scope of Internal Audit assessments includes evaluat-
ing that risk management practices are in place, signifi-
cant risks are appropriately identified and managed, key
policies and guidelines exist and are documented and
effectively implemented, organizational structures and
governance models enable efficient decision making,
2023
The 2023 AGM elected KPMG Oy Ab as the Com-
pany’s auditor, and Authorized Public Accountant
Leenakaisa Winberg acted as the auditor with prin-
cipal responsibility.
The statutory audit fees in 2023 were EUR 1.6
million, and other fees charged amounted to EUR
1.1 million.
2023
Internal Audit performed internal audits set out in the
Internal Audit Plan 2023, and reported audit results
to the senior management and the Board Audit
Committee. The Internal Audit function continued
to strengthen cooperation with other Neste assur-
ance functions such as compliance, risk manage-
ment and internal controls with an aim of integrat-
ing activities and reporting to management. Neste’s
strategic investments, top risks and key business
processes were the focus during 2023, includ-
ing cybersecurity, privacy, the Rotterdam Capacity
Growth Project and operations at Neste’s foreign
subsidiaries.
the steering system, roles and responsibilities are clear,
and the results of operations and programs are consis-
tent with established goals and objectives.
Internal Audit work is carried out based on an annual
Internal Audit Plan. Neste’s strategic priorities, key proj-
ects and identified risks are key elements in the audit
planning process. The Vice President of Internal Audit
reports periodically to the senior management and the
Board Audit Committee Internal Audit’s activities relative
to the annual plan, including audit recommendations
and action plans established by organizations aiming for
the continuous improvement and mitigation of risks.
Internal Audit is also responsible for conducting spe-
cial assignments on behalf of management or the Board
Audit Committee. As a member of Neste’s Investiga-
tion Group, the Vice President of Internal Audit partici-
pates in the investigation of suspected misconduct and
breaches of Neste’s policies, principles, and applicable
laws and regulations. To assure an effective, efficient and
value-adding process, Internal Audit actively cooperates
with other Neste’s assurance service functions (Corpo-
rate Risk Management, Internal Control and Compli-
ance) and top management and shares best practices
from a process and governance perspective.
Internal Audit follows the mandatory elements of the
Institute of Internal Auditors’ International Professional
Practices Framework, including the Professional Prac-
tice of Internal Auditing. The Internal Audit reports directly
to the Board of Directors’ Audit Committee and adminis-
tratively to the President and CEO. The Board of Direc-
tors is responsible for approving the Internal Audit Char-
ter and the annual Internal Audit Plan. The Internal Audit
Charter includes the determination regarding the Internal
Audit position, operational model, process and reporting
lines. Internal Audit holds a non-executive meeting with
the Audit Committee members and the Audit Commit-
tee Chair at least annually. The Vice President of Internal
Audit is responsible for the internal audit activities spec-
ified in the Internal Audit Charter.
Compliance function
Neste is committed to high ethical standards and con-
ducts its business and operates in compliance with
applicable laws, regulations and generally accepted
good corporate governance practice. Neste’s Code of
Conduct sets the framework for Neste’s global busi-
ness operations and establishes the ethical practices
to guide Neste employees in their day-to-day business
activities and decisions. Neste also requires suppliers
and other business partners to comply with applica-
ble laws and expects them to follow equivalent ethical
business standards as stated in the Code of Conduct
and further described in our Supplier Code of Conduct.
More information about Neste’s Code of Conduct is in
Neste’s Sustainability Report and on Neste’s external
web pages.
The purpose of Neste’s Compliance function is
to develop, establish, facilitate and oversee compli-
ance procedures and programs aimed at ensuring that
Neste’s global organizations have effective systems and
processes in place for identifying, preventing, detecting
and correcting non-compliance with applicable laws,
regulations and Neste’s internal rules. The function sup-
ports Neste’s management in their responsibility for
overall compliance risk management, as well as Neste’s
organizational unit management in their responsibilities
to identify and manage compliance risks related to their
operations. The compliance function works in close col-
laboration with Neste’s business units, functions and
other internal assurance organizations, in particular the
Risk Management, Internal Control and Internal Audit
functions. The compliance function is headed by the
Chief Compliance Officer (CCO), who reports to Neste’s
General Counsel. The CCO reports regularly on compli-
ance activities to the Executive Committee and the Board
of Directors’ Audit Committee. Neste also has an Ethics
and Compliance Committee, which oversees and steers
the management of the ethics and compliance program
in Neste. Reports on suspected misconduct received
via the Company’s externally operated reporting system
and other reporting channels are investigated in accor-
dance with applicable laws and Neste’s internal Miscon-
duct Investigation Standard. More information about the
Misconduct Investigation Standard and reported sus-
pected incidents of misconduct can be found in the NFI
and Sustainability Report.
In addition to other reporting channels, Neste has an
externally operated misconduct reporting system, Eth-
ics Online, available to all Neste’s internal and exter-
nal stakeholders, including various actors in its supply
chains. Ethics Online serves as a grievance mechanism
and enables Neste’s stakeholders to raise concerns
related to alleged misconduct in Neste’s practices.
Neste’s Investigation Group is responsible for evaluat-
ing and investigating such reported cases. Neste has
a non-retaliation policy for concerns reported in good
faith. Neste’s main principles and policy followed in inter-
nal misconduct investigations is described in the Com-
pany’s internal Misconduct Investigation Standard. Any
irregularities or misconduct are reported regularly to the
Board of Directors’ Audit Committee.
Insider administration procedures
Neste complies with the EU Market Abuse Regulation
(596/2014), including related regulation, as well as Nas-
daq Helsinki Ltd’s Insider Guideline as a minimum stan-
dard on insider matters. In addition, the Board of Direc-
tors has approved the Company’s own Guidelines for
Insiders.