- Ethical Technology
- What suppliers agree to
Ethical Technology · Suppliers
What suppliers agree to
A commitment the group makes cannot stop at its own boundary. Thirty-eight suppliers handled group or client data at 30 June 2026, and each signed the Charter schedule before the first record moved. Fourteen of those services are material, and each carries an audit right, an annual evidenced review and a tested exit plan.

Commitments
- Every supplier handling group or client data signs the Charter schedule before the first record moves.
- No supplier trains its product on group or client data, and none retains prompts or outputs.
- A supplier that cannot state the origin of its training data is not approved for decision work.
- A material change to a supplied system is a new approval rather than an upgrade.
- No supplier holds more than three material services for the group.
- Contractors answer to the Code of Conduct and may raise concerns at whistleblowing@iguako.tech.
The Charter as a contract term
The Third-Party Risk and Outsourcing policy carries the Charter into every supplier contract as a schedule. The schedule is not negotiable on its substance. A supplier may negotiate notice periods, service levels and fees. It may not negotiate whether it trains on group data or whether the group is entitled to audit it.
The schedule binds sub-processors on the same terms and forbids the addition of one in a new country without written consent. It requires deletion certificates at exit that cover backups. It requires notice of a security incident within 24 hours of discovery, whether or not the supplier has yet established what happened.
- No training, tuning or evaluation of any product on group or client data.
- No retention of group prompts, documents or outputs beyond the session that produced them.
- No onward disclosure, and no sub-processor in a new country without written consent.
- An audit right the group may exercise on notice, with access to the relevant records.
- Notice of a security incident within 24 hours of discovery.
- Return of the data and a deletion certificate covering backups at the end of the service.
Diligence before signature
Diligence covers ownership and control, financial standing, where the work is performed, who can reach the data, the security evidence the supplier can produce and the sub-processors it uses. For a supplier of a system that learns, it also covers what the system was trained on and who holds the outputs it produces.
That last question decides more cases than the others. A supplier that cannot state the origin of its training data is not approved for any use supporting a decision, however capable the product. Two suppliers were declined in the twelve months to 30 June 2026, one on that ground and one because it would not accept the audit right.
Diligence is repeated at renewal rather than treated as an onboarding formality. A supplier that changes ownership, moves its processing to a new country or replaces the system it supplies is reassessed before the change takes effect. The group may terminate where the change cannot be accepted.
The fourteen that matter
Fourteen services are classified material, meaning the group could not continue a regulated activity, serve a client or close a reporting period without them. Each has a named owner inside the group, a monthly service report, an annual evidenced review and an exit plan tested on a two-year cycle.
Concentration is limited by rule. No supplier holds more than three material services for the group, and no material service runs from a single site without a documented alternative. The Operational Resilience policy sets the recovery expectations and the Chief Operating Officer reports against them each quarter.
The annual review is evidenced rather than attested. The group reads the audit reports, the incident log and the access records for the period, and visits the supplier where the service touches client data. Eleven of the fourteen reviews in the year to 30 June 2026 included a visit.
Suppliers whose systems learn
A system supplied by a third party that learns from data is registered exactly as a system built inside the group is registered. It takes a class, a purpose, an accountable executive and a scope, and its approval lapses on the same twelve-month cycle. The supplier inherits no part of the accountability.
A material change to the system is a new approval rather than an upgrade, and the supplier notifies the change before it is deployed. The contracted environment is inspected on the same cycle as the review. A supplier that deploys a changed system without notice is in breach and the use is suspended on discovery.
Nine of the 26 approved uses at 30 June 2026 ran on systems supplied by third parties. Each was tested by the group before approval against the prohibited inferences recorded in its register entry, using held-out cases the supplier did not see and could not have prepared for.
People who are not employees
Contractors, seconded staff and outsourced teams working on group business are held to the Code of Conduct and to the Charter, and their managers inside the group answer for that. Access is granted for a named mandate and for a stated period, and it ends automatically on the date recorded.
They may raise a concern at whistleblowing@iguako.tech on the same terms as an employee, with the same protection from retaliation. Two concerns were raised through that route by people who were not employees in the twelve months to 30 June 2026, and the General Counsel investigated both.
Also on ethical technology