Governance
Transparency and responsible corporate governance are key elements in adequately addressing internal and external requirements.
Governance on ESG
Sustainability at ams OSRAM encompasses the consideration of relevant environmental and social aspects across the value chain. These aspects are integrated into corporate management and existing business processes and help support the company's long-term development and future business opportunities.
As a member of the UN Global Compact and the Responsible Business Alliance, we align our activities with their principles. This integration is embedded within our governance structures, including an ESG Committee at Supervisory Board level.
Further information on policies, processes and governance structures is available in our Sustainability Policy and on our Corporate Governance website.
On our Corporate Governance website, you will find information on corporate governance, such as the Charter of the Supervisory Board’s ESG Committee or the Policy on Composition and Diversity.
We consider CSR and ESG to be synonymous with sustainability.
Compliance & Whistleblowing
Compliance with legal and internal requirements is an integral part of ams OSRAM’s business operations. The Compliance Management System (CMS) provides the framework for this.
The CMS is designed to address potential violations in areas such as anti-corruption, competition law, anti-money laundering, data protection, and export controls, and to implement appropriate measures for prevention, detection, and response (Prevent – Detect – Respond).
Whistleblowing
If you are aware of unethical or illegal conduct related to ams OSRAM’s own business operations or our supply chain, please use our secure electronic reporting channel, “Tell ams OSRAM,” to inform us of potential risks or violations.
“Tell ams OSRAM” is available to all employees and external parties around the clock—in multiple languages, confidentially, and anonymously. Of course, anyone who reports in good faith is protected from retaliation.
Please help us identify potential misconduct. Your voice is important, and we need your support.
Supplier Management
Managing supplier risks is an integral part of ams OSRAM’s business operations. Relevant environmental and social considerations are taken into account when selecting suppliers and collaborating with them.
Standardized risk analyses, processes, and tools are used for this purpose. In addition, control mechanisms are in place, including those related to human rights due diligence and the handling of conflict minerals.
Quality
Quality and product safety are integral parts of ams OSRAM’s business operations and are taken into account throughout the entire product life cycle. This includes product development as well as procurement and production processes.
The underlying processes and management systems are certified according to recognized standards such as ISO 9001 and—for the automotive sector—IATF 16949.
Data Protection, Cybersecurity, and Responsible AI
Data Protection
ams OSRAM and its affiliates take the protection of personal data into account in the course of their business activities. The Privacy Policy describes what data is collected and processed, as well as the purposes for which this is done, in accordance with applicable legal and regulatory requirements.
Cybersecurity
The increasing digitization of business processes requires appropriate measures to ensure the availability, integrity, and confidentiality of data and systems. Cyber and information security are addressed at ams OSRAM within the framework of corresponding governance and management processes. Below you will find further information on information security governance, data protection, and relevant certifications at ams OSRAM. Contact: security@ams-osram.com
Responsible AI
The use of artificial intelligence is governed by defined internal guidelines. The AI policy outlines principles, requirements, and limits of use, as well as how to manage relevant risks associated with AI systems.
Incident Management
Reports of potential incidents can be submitted via the 'Tell ams OSRAM' reporting channel.
Further Information on Cyber Security
The board of ams OSRAM has defined a global information security strategy aligned with the company's risk management and business strategy. The Information Security Management System (ISMS) has been globally certified according to the ISO27001 standard.
Governance of Information Security
As part of the overall information security strategy, ams OSRAM has established a global information security organization coordinated by a Corporate Information Security Officer (CISO). The CISO reports directly to the Chief Information Officer and reports at least quarterly to the board members in the "IT Board," defined as the company's "Information Security Committee." Responsibility for cyber and information security within the board lies with the Chief Financial Officer (CFO) and the Audit Committee regularly deals with associated risks. Identified cybersecurity risks are also addressed within the framework of Enterprise Risk Management and monitored by the Audit Committee.
Information Security Policy
The board of ams OSRAM has issued company-wide policies for information security and data protection. The CISO leads and oversees the implementation of the Information and Cyber Security Management System (ISMS), including this policy worldwide. Mandatory training on information security and data protection ensures that employees are familiar with relevant security policies and procedures. These training courses take place at least once a year. Global awareness tests are conducted regularly. All employees are bound by the applicable laws to protect the personal rights of others and to protect the company from harm through responsible behavior in line with the training. Effective prevention against information and data protection risks is an important part of our management approach, leadership responsibility, and individual behavior.
To extend our data protection and information security requirements to our suppliers, we have included them in our Supplier Code of Conduct: We require our suppliers to protect the personal data of their employees and business partners and to use it only for legitimate purposes. The laws on data protection and information security and regulatory requirements must also be observed when collecting, storing, processing, transmitting, and sharing personal data.
Our ISMS includes all relevant elements such as governance, risk management, information and system management, threat and incident management, and business continuity management. This includes not only monitoring and responding with adjustments to security risks (threats). Rather, threat and incident management is part of ams OSRAM's global incident and crisis management. Additionally, an emergency service provider has been contracted in case of a severe cyber-attack.
Our ISMS is regularly externally validated. The ISO 27001 certification covers the global ISMS process of ams OSRAM, and individual production sites are certified according to ISO27001 or TISAX concerning local (physical) security requirements. Furthermore, the
ISMS is continuously improved, and its effectiveness is monitored through internal audits and vulnerability analyses. In addition to the annual external re-certification within the framework of ISO27001 and TISAX certifications, Corporate Audit initiates at least one external verification audit of information security-relevant processes and procedures annually, such as so-called Table Top Exercises or simulated hacker attacks. All automotive production sites worldwide are also certified at least with TISAX Level 2 and at least one with Level 3. This validates our global processes.
In the area of data protection, a comprehensive data protection management system is implemented, and a globally valid corporate policy ensures company-wide standards for handling personal data. Further development of data protection is promoted, among other things, through training for all employees and the enforcement of uniform technical-organizational measures, especially when processing data by external service providers.
Various channels are available for employees to report cases, including the whistleblower system "Tell ams OSRAM." This is also accessible to external parties via our website.
Further information and documents can be found in the "Downloads" section.
Downloads
Governance on ESG
Sustainability Policy
Tax Policy ams OSRAM
Compliance & Whistleblowing
Code of Conduct for Employees ams OSRAM
Rules of Procedure for the complaints procedure
Overview reporting channels at ams OSRAM
Supplier Management
Code of Conduct for Suppliers ams OSRAM
Policy - Human Rights in the Supply Chain
Policy on Conflict Minerals ams OSRAM
Quality
Quality Policy ams OSRAM
ISO 9001 Certificates ams OSRAM
IATF 16949 Certificates ams OSRAM
Cyber Security
TISAX
ISO27001 - Premstaetten
ISO27001 - Munich
ISO27001 - Regensburg
Contact us
Contact information
As a company, our mission is to forster a sustainable future through innovation and collaboration.
For further information get in touch with us!
Contact: sustainability@ams-osram.com