MEGA maintains a robust and effective governance structure designed to facilitate responsible decision-making and align the Company's management with the long-term interests of shareholders and other stakeholders.

Board of Directors

The Board of Directors plays a crucial role in overseeing and directing the Company, particularly regarding the approval and updating of its purpose, values, and mission, as well as the strategies, policies, and goals related to sustainable development. This body is responsible for ensuring that the proposed strategies align with corporate objectives and long-term viability.

MEGA's Board of Directors is composed of twelve members, elected and ratified at the General Shareholders' Meeting. Of these, four are independent directors selected for their experience, capability, and reputation, subject to the approval of the National Banking and Securities Commission (CNBV).

Our Board of Directors and management team are responsible for overseeing the implementation of the Company's Sustainability Strategy.

Committees

Strategic Committee

Audit Committee

Corporate Practices Committee

Ethics Committee

Sustainable Financing Committee

Code of Ethics

At MEGA, we actively promote respect for human rights and business ethics, which are the foundation to maintaining the Company's trust and credibility with the market and our stakeholders. Furthermore, we are committed to fostering an environment of integrity, transparency, and responsibility, both within and beyond our facilities, by upholding the highest ethical standards in alignment with our principles and values.

This document, updated in 2022, not only reflects the essence of our workforce but also focuses on elevating business conduct standards in relation to our stakeholders.

The Code includes the following aspects:

Whistleblowing line

The Company has a zero-tolerance policy toward discrimination and harassment, ensuring an equitable work environment free from retaliation. To support this commitment, we have established the ESCALA whistleblowing line, a confidential and anonymous resource available on all official Company pages. This channel allows employees to report any behavior that violates our Code of Ethics, including conflicts of interest, ensuring all matters are handled fairly and in line with our corporate values.

In 2023, a total of 474 reports were addressed through ESCALA.

Diversity Policy

At MEGA, we are committed to strengthening the institutionalization of diversity and gender equality to ensure a healthy, non-discriminatory work environment. Our Diversity Policy aims to guarantee equal opportunities and fair treatment for every employee in areas such as employment, working conditions, professional development, training, and participation in decision-making processes, in line with their respective responsibilities.

Conflict of Interest Policy

We are committed to maintaining ethical business relationships with suppliers and customers, avoiding situations that could lead to financial crimes. To support this, we have established a Conflict of Interest Policy, which provides guidelines for identifying, disclosing, and managing situations that could compromise the objectivity or impartiality of decisions made by all Company employees. This policy requires all organization members to declare any personal or professional situations that might be perceived as conflicting with the Company's interests.

Anticorruption Policy

In 2023, we updated our Anticorruption Policy and provided training to our workforce to ensure they understand and adhere to the guidelines designed to promote a culture of integrity within MEGA.

Throughout the year, a total of 47,392 training hours were provided on the Code of Ethics, Conflict of Interest, ESCALA, and Anticorruption.

2023 Trainings on policies and procedures

Stakeholder

Total Number

Percentage informed

Board of Directors

12

100%

Employees

19,581

83%

Executives

3

100%

Managers

316

100%

Operators and Administrative

19,265

100%

Policies and commitments are communicated through training on the internal UNIMEGA platform.

Cybersecurity

At MEGA, we have established policies, procedures, certifications, and a specialized cybersecurity team to develop a robust information defense framework. This team is responsible for protecting our critical infrastructures and ensuring compliance with security standards and guidelines in all the Organization’s areas.

Our Information Security Management System (ISMS) is based on the ISO 27001 standard.

Protecting our customers' data privacy is a top priority. We adhere to all relevant federal laws governing data privacy.

We have an Information Security Policy that sets precise guidelines for all employees in this area. To ensure compliance with all data privacy and information security policies, we train our team through the internal portal and conduct periodic assessments to stay updated with the latest developments.

In our ongoing effort to strengthen our cybersecurity strategy and mitigate potential risks, we have implemented several projects and processes throughout the year, including:

  • Risk analysis: We conducted semi-annual assessments to identify potential threats and their impacts on both our existing infrastructure and new projects. This allowed us to establish appropriate preventive and protective measures.

  • Application shielding: We have implemented an encryption tool in all our applications, both internal and those intended for our customers, ensuring that no information about the connections made can be accessed, thus strengthening our infrastructure.

  • Application firewall: We implemented protection at the application level for our internet-exposed infrastructure. This measure includes detecting bots attempting to infiltrate, ensuring our operations’ continuity, and protecting our systems from potential attacks.

Incident Response Plan
We have a strong incident response plan designed to monitor, detect, contain, and resolve issues efficiently without affecting the continuity of our operations. This plan is based on the recognized frameworks of the NIST (National Institute of Standards and Technology) and the CSF (Cyber Security Framework).

As part of our comprehensive security strategy, we conduct quarterly vulnerability tests on our applications and the infrastructure designated for customer service. These tests aim to identify potential weaknesses in operating systems and security risks.

In 2023, 33,295 training hours were provided to employees on personal data protection policies and procedures.