Governance
Corporate Governance Framework
Version 1.1 · October 2026
This Framework sets out the principles, structures and controls through which Neopillar (the “Company”) is directed, controlled and held to account. It binds the Board, executive management and every employee, and it governs the Company's dealings with its shareholders, partners, regulators and the public.
The Company is a private, unlisted company registered in the Kingdom of Saudi Arabia. Its shares are not listed or traded on any exchange, and it does not offer securities to the public. It is governed by the Companies Law and its Implementing Regulations, under the supervision of the Ministry of Commerce, and by its Articles of Association.
Because its mandates concern energy infrastructure, industrial capacity and critical materials of national importance, the Company voluntarily holds itself to the rigour and transparency expected of a sovereign-scale enterprise. Recognised governance practice — including the principles of the Corporate Governance Regulations that the Capital Market Authority issues for listed companies — informs this Framework as a reference. Those Regulations do not apply to the Company by law, and drawing on their principles implies no listing.
Where this Framework is stricter than applicable law, the Framework applies; applicable law prevails in every case.
Legal basis
- 01The Companies Law issued by Royal Decree No. M/132 dated 1/12/1443H and its Implementing Regulations, under the supervision of the Ministry of Commerce
- 02The Articles of Association of the Company
- 03The Anti-Bribery Law issued by Royal Decree No. M/36 dated 29/12/1412H and the Kingdom's integrity and anti-corruption framework
- 04The Personal Data Protection Law and the cybersecurity controls of the National Cybersecurity Authority
- 05Recognised governance practice, applied voluntarily as a reference
Governance structure
Shareholders
The owners of the Company, acting through their assembly in accordance with the Companies Law and the Articles of Association. They appoint the Board and the external auditor, and approve the financial statements.
Board of Directors
Sets strategy and the risk appetite, approves major commitments and holds executive management to account.
Board committees
Established as the Company's scale and mandate require — such as audit and risk — each under a mandate approved by the Board.
Executive Management
Led by the Chief Executive Officer. Executes strategy within the authority delegated by the Board and carries operational accountability for results.
Article I
Board Oversight & Strategic Mandate
- 1.1
Mandate of the Board
The Board holds ultimate responsibility for the Company's strategy, performance and conduct. It approves the strategic objectives, major investments, the risk appetite and the annual budget, and it monitors their execution by executive management.
- 1.2
Composition
The Board is composed to bring the competence, integrity, independence of judgement and range of expertise that the Company's strategy requires. Directors are appointed by the shareholders in accordance with the Articles of Association, and non-executive perspective is present in the Board's deliberations.
- 1.3
Distinct roles
The Board directs and oversees; executive management leads the Company within the authority delegated to it. Each role is exercised distinctly, so that oversight is never compromised by execution.
- 1.4
Delegation of authority
Authority is delegated through a written matrix approved by the Board. Matters reserved to the Board — including strategy, major transactions, related-party dealings above approved thresholds and the appointment of senior executives — may not be delegated.
- 1.5
Board committees
The Board establishes the committees its oversight requires, which may include audit, risk, and nomination and remuneration functions. Each operates under a mandate approved by the Board and reports to it regularly.
- 1.6
Conflicts of interest
Every director and senior executive discloses any direct or indirect interest in a matter before the Company. An interested person takes no part in deliberation or voting on that matter, and related-party transactions are approved in accordance with the Companies Law.
- 1.7
Evaluation and development
The Board reviews its own effectiveness periodically and ensures that every director receives the induction and continuing development the role requires.
Article II
Audit, Risk Management & Macro-Resilience
- 2.1
Audit oversight
The Board, directly or through a committee, oversees the integrity of financial reporting, the effectiveness of internal control and the independence of the external auditor.
- 2.2
External audit
The external auditor is appointed by the shareholders, is licensed in the Kingdom and is independent of the Company and its management. Financial statements are prepared in accordance with the accounting standards endorsed in the Kingdom by the Saudi Organization for Chartered and Professional Accountants.
- 2.3
Internal assurance
Internal assurance over governance, risk management and control is provided in proportion to the Company's scale, and reports to the Board or its delegated committee free of management interference.
- 2.4
Enterprise risk management
Risk is governed through an enterprise-wide framework in which the Board sets the risk appetite, management owns and controls risk, and oversight remains independent of execution. Principal risks are reported to the Board regularly and addressed before capital is committed.
- 2.5
Macro-resilience
The Company maintains a standing view of the macroeconomic, commodity, supply-chain, regulatory and geopolitical conditions that bear on its mandates. Material investments are tested against adverse scenarios before commitment, and exposures are reassessed as conditions change.
- 2.6
Operational accountability
Every programme has a named executive owner accountable for its schedule, budget, safety and outcomes. Performance against approved objectives is reported to the Board, and deviations are escalated without delay.
- 2.7
Business continuity
Critical operations are protected by business-continuity and crisis-management arrangements that are maintained, tested and approved at the appropriate level of authority.
Article III
Ethical Compliance, Anti-Bribery & Transparency
- 3.1
Zero tolerance
The Company prohibits bribery and corruption in every form — whether offered, given, requested or received, directly or through any intermediary. The prohibition binds the Company, its directors, employees and agents, and every partner acting on its behalf.
- 3.2
Legal compliance
The Company complies with the Anti-Bribery Law and the integrity framework of the Kingdom, cooperates fully with the competent authorities and observes the principles of the United Nations Convention against Corruption. Where a partner is subject to further anti-corruption legislation, the Company supports that partner's compliance.
- 3.3
Gifts and hospitality
Gifts and hospitality are permitted only where they are modest, transparent, recorded and incapable of influencing a decision. Facilitation payments are prohibited.
- 3.4
Third-party due diligence
Partners, suppliers and intermediaries are subject to risk-based due diligence before engagement, and to contractual commitments on integrity, sanctions compliance and anti-corruption.
- 3.5
Transparency
As a private company, the Company is not subject to public-disclosure obligations. It nonetheless provides its shareholders, financing partners and the competent authorities with accurate, complete and timely information on matters material to them, and keeps books and records that fairly reflect every transaction.
- 3.6
Code of Conduct
A Code of Conduct approved by the Board sets the standard of behaviour required of every person acting for the Company. Breaches are investigated independently and sanctioned proportionately.
- 3.7
Speaking up
Concerns may be raised in confidence through protected channels. The Company does not tolerate retaliation against any person who reports a concern in good faith.
Article IV
Data Sovereignty & Secure Architecture
- 4.1
Data sovereignty
Data entrusted to the Company by clients and partners remains their property. Data classified as sensitive or critical is hosted within the Kingdom unless its owner and applicable law permit otherwise.
- 4.2
Personal data protection
Personal data is processed lawfully, for specified purposes and to the minimum extent necessary, in accordance with the Personal Data Protection Law and the regulations issued under it.
- 4.3
Cybersecurity
The Company's information and operational technology environments are secured in line with the controls issued by the National Cybersecurity Authority, under policies approved by the Board and reviewed periodically.
- 4.4
Security by design
Security, resilience and data sovereignty are requirements from the first design decision of every system and asset the Company delivers — never additions made after deployment.
- 4.5
Access and accountability
Access to sensitive information and critical systems is granted on the principle of least privilege, recorded and reviewed. Every access is attributable to an accountable individual.
- 4.6
Incident response
Security and data incidents are contained, investigated and reported to the competent authorities and affected parties within the periods required by law.
Final provisions
- Review and amendment
- The Board reviews this Framework periodically and whenever law, regulation or the Company's mandate materially changes. Amendments take effect upon approval by the Board.
- Language
- In the event of any inconsistency between the Arabic and English texts, the Arabic text shall prevail.
Enquiries regarding this Framework may be addressed to the Company at info@neopillar.sa