Organizational, Management, and Control Model

1 DEFINITIONS

The following definitions refer to all parts of the Organizational, Management, and Control Model, without prejudice to any additional definitions contained in the individual Special Parts.

Senior Management: those who, regardless of the specific role held, hold functions of representation, administration, or management of the Entity or of one of its organizational units with financial and functional autonomy, as well as those who, even de facto, exercise management or control of the Entity.

Risk/Sensitive Areas: corporate areas of the Company exposed to the risk of committing one or more offenses.

Risk/Sensitive Activities: activities in the performance of which there is a risk of committing Offenses.

CCNL: National Collective Labor Agreement applied by the Company.

Code of Ethics or Code of Conduct: code of ethics adopted by the Company.

External Collaborators: Partners, Consultants, Counterparties, Suppliers, and On-call Workers collectively considered.

Consultants: parties acting in the name and/or on behalf of the Company by virtue of a mandate agreement or other contractual relationship of professional collaboration and consultancy.

Counterparties: contractual counterparties, including Consultants and Suppliers, with whom the Company enters into any form of contractually regulated collaboration.

Legislative Decree 231/2001 or Decree: Legislative Decree No. 231 of June 8, 2001, and subsequent amendments, containing provisions on the Administrative Liability of legal entities, companies, and associations, including those without legal personality.

Legislative Decree 81/08: Legislative Decree No. 81 of April 9, 2008, Consolidated Act on workplace safety.

Environmental Consolidated Act: Legislative Decree No. 152 of April 3, 2006, and subsequent amendments.

Delegation: internal act of attribution of functions and tasks, reflected in the organizational communication system.

Delegation of functions: Article 16 of Legislative Decree No. 81 of April 9, 2008, Consolidated Act on workplace safety.

Recipients: corporate officers, employees, and consultants of Computer Design S.r.l. as identified in the General Part of this document, who are required to comply with and apply the Model.

Employees: parties having an employment relationship with the Company or those who perform work activities for the Company by virtue of a contract with it.

Entity/Entities: entities with legal personality and companies and associations, including those without legal personality. Corporate Officers: Board of Statutory Auditors, managers, consultants, and sales agents.

231 Training: training activities related to Legislative Decree 231/2001 and the Model that are periodically organized by the Management of Computer Design S.r.l. and monitored by the Supervisory Body; Training is provided to all employees of the Company.

Suppliers: suppliers of goods and services to the Company.

Risk Corporate Functions: corporate functions that, operating within Risk Areas, are exposed to the risk of committing a Predicate Offense.

Guidelines: Guidelines adopted by Confindustria, the relevant trade association, for the preparation of Organizational, Management, and Control Models pursuant to Article 6, paragraph three, of Legislative Decree 231/2001.

231/2001.

Model: Organizational, Management, and Control Model provided for by Article 6 of Legislative Decree 231/2001. 231/2001.

Risk Operation: any single operation or act falling within the scope of Risk Activities.

Supervisory Body/SB: internal control body responsible for supervising the functioning and observance of the Model and ensuring its updating.

P.A.: public administration and, with reference to offenses against the Public Administration, public officials and persons in charge of a public service.

Third Parties: contractual counterparties of Computer Design S.r.l., both natural and legal persons (suppliers, consultants, etc.) with whom the Company enters into any form of contractually regulated collaboration and who are intended to cooperate with the company within risk areas.

Power of Attorney: unilateral legal act by which the Company grants powers of representation vis-à-vis third parties.

Predicate Offenses: categories of offenses to which the provisions of Legislative Decree 231/2001 on the administrative liability of Entities apply.

Periodic Report: information flow to the SB that follows the periodicity indicated from time to time within the Model and consists of a description of activities carried out and/or critical issues identified within Risk Areas.

Internal Manager: internal party of Computer Design S.r.l. to whom is attributed, by delegation from the Administrative Body, sole or shared responsibility with others for operations in Risk Areas.

Administrative Body, sole or shared responsibility with others for operations in Risk Areas.

Administrative liability: liability to which Computer Design S.r.l. may be subject in the event of commission of one of the offenses provided for by Legislative Decree 231/01, liability which, if ascertained, results in the application of sanctions to Computer Design S.r.l.

Company or Computer Design S.r.l.: refers to Computer Design S.r.l., a company specializing in the provision of software and IT consultancy.

Computer Design S.r.l. manages the trade, rental, and maintenance of computers, equipment, and electronic systems for data processing.

Subordinates: those who, although endowed with autonomy (and therefore liable to incur offenses), are subject to the direction and supervision of senior management. This category must also include any quasi-subordinate or temporary workers bound to the Company by collaborative relationships and therefore subject to more or less intensive supervision and direction by Computer Design S.r.l.

2 LEGISLATIVE DECREE OF JUNE 8, 2001, NO. 231: ADMINISTRATIVE LIABILITY OF ENTITIES

Legislative Decree of June 8, 2001, No. 231, which contains the “Regulation of the administrative liability of legal entities, companies, and associations, including those without legal personality” (hereinafter also referred to as “Legislative Decree 231/2001” or the “Decree”), entered into force on July 4, 2001, in implementation of Article 11 of Enabling Law No. 300 of September 29, 2000, and introduced into the Italian legal system, in accordance with European Union provisions, the administrative liability of entities, where “entities” means commercial companies, both corporations and partnerships, and associations, including those without legal personality.

This new form of liability, although defined as “administrative” by the legislator, has the characteristics of criminal liability, as the competent criminal judge is responsible for ascertaining the offenses from which it derives, and the same guarantees recognized to persons under investigation or defendants in criminal proceedings are extended to the entity.

The administrative liability of the entity derives from the commission of offenses, expressly indicated in Legislative Decree 231/2001, committed in the interest or to the advantage of the entity itself by natural persons holding functions of representation, administration, or management of the entity or of one of its organizational units with financial and functional autonomy, or who exercise, even de facto, its management and control (so-called “senior management”), or who are subject to the direction or supervision of one of the parties indicated above (so-called “subordinates”).

In addition to the existence of the requirements described above, Legislative Decree 231/2001 also requires ascertainment of the entity’s culpability in order to establish its liability. This requirement is attributable to “organizational fault,” to be understood as the entity’s failure to adopt preventive measures adequate to prevent the commission of the offenses listed in the following paragraph by the parties identified in the Decree. Where the entity is able to demonstrate that it has adopted and effectively implemented an organization suitable for preventing the commission of such offenses, through the adoption of the organizational, management, and control model provided for by Legislative Decree 231/2001, it will not be liable for administrative liability.

2.1 Offenses provided for by the Decree

The offenses from which the administrative liability of the entity derives are those expressly and exhaustively referred to in Legislative Decree 231/2001 and subsequent amendments and supplements (so-called predicate offenses). The latter are fully indicated and described in the Annex to this model, to which reference is made (Annex No. 1: List of predicate offenses pursuant to Legislative Decree No. 231/2001).

A brief list of the offenses currently included in the scope of application of the Decree is also provided below, noting, however, that this is a list destined to expand in the near future.

  1. Article 24 Legislative Decree 231/01 – Undue receipt of disbursements, Fraud to the detriment of the State, a public entity, or the European Union or for obtaining public disbursements, Computer fraud to the detriment of the State or a public entity, and fraud in public supplies o Article 316-bis Criminal Code: Embezzlement of public disbursements (article amended by Decree-Law No. 13/2022) o Article 316-ter Criminal Code: Undue receipt of public disbursements (article amended by Law No. 3/2019 and Decree-Law No. 13/2022) o Article 353 Criminal Code: Disturbance of freedom of auctions (article added by Decree-Law 105/2023) o Article 353-bis Criminal Code: Disturbance of freedom of contractor selection procedure (article added by Decree-Law 105/2023) o Article 356 Criminal Code: Fraud in public supplies (introduced by Legislative Decree No. 75/2020) o Article 640, paragraph 2, No. 1 Criminal Code: Fraud to the detriment of the State or other public entity or the European Communities o Article 640-bis Criminal Code: Aggravated fraud for obtaining public disbursements (article amended by Decree-Law No. 13/2022) o Article 640-ter Criminal Code: Computer fraud to the detriment of the State or other public entity o Article 2, Law December 23, 1986, No. 898: Fraud to the detriment of the European Agricultural Fund (introduced by Legislative Decree No. 75/2020)

D.L. no. 13/2022) or Art. 353 c.p.: Disturbed freedom of bids (article added by D.L. 105/2023) or Art. 353-bis c.p.: Disturbed freedom of the procedure for choosing the contractor (article added by D.L.

105/2023) or Art. 356 c.p.: Fraud in public supplies (introduced by Legislative Decree no. 75/2020) or Art. 640, para. 2 no. 1 c.p.: Fraud against the State or another public body or the European Communities or Art. 640-bis c.p.: Aggravated fraud for the purpose of obtaining public funds (article amended by

D.L. no. 13/2022) or Art 640-ter c.p.: Computer fraud against the State or another public body or Art. 2. L. 23/12/1986, no. 898: Fraud against the European Agricultural Fund (introduced by Legislative Decree no. 75/2020)

  • Article 24-bis Legislative Decree 231/01 – Computer crimes and unlawful data processing (article added by Law No. 48/2008; amended by Legislative Decrees No. 7 and 8/2016, Decree-Law No. 105/2019, and the Cybersecurity Bill) o Article 491-bis Criminal Code: Computer documents o Article 615-ter Criminal Code: Unauthorized access to a computer or telecommunications system o Article 615-quater Criminal Code: Unauthorized possession, dissemination, and installation of equipment, codes, and other means suitable for accessing computer or telecommunications systems (article amended by Law No. 238/2021) o Article 617-quater Criminal Code: Unlawful interception, impediment, or interruption of computer or telecommunications communications (article amended by Law No. 238/2021) o Article 617-quinquies Criminal Code: Unauthorized possession, dissemination, and installation of equipment and other means suitable for intercepting, impeding, or interrupting computer or telecommunications communications (article amended by Law No. 238/2021) o Article 629, paragraph 3, Criminal Code: Computer extortion o Article 635-bis Criminal Code: Damage to information, data, and computer programs o Article 635-ter Criminal Code: Damage to information, data, and computer programs used by the State or other public entity or in any case of public utility o Article 635-quater Criminal Code: Damage to computer or telecommunications systems o Article 635-quater.1 Criminal Code: Unauthorized possession, dissemination, and installation of equipment, devices, or computer programs designed to damage or interrupt a computer or telecommunications system (article introduced by Cybersecurity Law No. 90/2024) o Article 635-quinquies Criminal Code: Damage to computer or telecommunications systems of public utility (article amended by Cybersecurity Law No. 90/2024) o Article 640-quinquies Criminal Code: Computer fraud by electronic signature certifier o Article 1, paragraph 11, Decree-Law September 21, 2019, No. 105: Violation of provisions on National Cybersecurity Perimeter
  • Article 24-ter Legislative Decree No. 231/2001 – Organized crime offenses (article added by Law No. 94/2009 and amended by Law 69/2015) o Article 416 Criminal Code: Criminal association o Article 416-bis Criminal Code: Mafia-type association, including foreign (article amended by Law No. 69/2015) o Article 416-ter Criminal Code: Electoral exchange with the mafia (thus replaced by Article 1, paragraph 1, Law April 17, 2014, No. 62, effective April 18, 2014, pursuant to Article 2, paragraph 1 of the same Law 62/2014) o Article 630 Criminal Code: Kidnapping for extortion o Article 74, Presidential Decree October 9, 1990, No. 309: Association for the purpose of illicit trafficking in narcotic or psychotropic substances (paragraph 7-bis added by Legislative Decree No. 202/2016) o All offenses if committed by taking advantage of the conditions provided for by Article 416-bis Criminal Code to facilitate the activities of the associations provided for by the same article (Law 203/91) o Article 407, paragraph 2, letter a), No. 5, Code of Criminal Procedure: Illegal manufacture, introduction into the State, sale, transfer, possession, and carrying in public places or places open to the public of war weapons or war-type weapons or parts thereof, explosives, clandestine weapons, as well as multiple common firearms excluding those provided for by Article 2, paragraph three, of Law April 18, 1975, No. 110

or Art. 416-ter c.p.: Political-mafia electoral exchange (as replaced by art. 1, paragraph 1, Law no. 62 of April 17, 2014, effective from April 18, 2014, pursuant to the provisions of art. 2, paragraph 1 of the same Law 62/2014) or Art. 630 c.p.: Kidnapping for the purpose of extortion or Art. 74 Presidential Decree no. 309 of October 9, 1990: Association for the purpose of illicit trafficking in narcotic or psychotropic substances (paragraph 7-bis added by Legislative Decree no. 202/2016) or All crimes if committed by taking advantage of the conditions provided for by art. 416-bis c.p. to facilitate the activity of the associations provided for by the same article (Law 203/91) or Art. 407, para. 2 letter a) no. 5) c.p.p.: Illegal manufacture, introduction into the State, sale, transfer, possession, and carrying in a public place or place open to the public of weapons of war or war-type weapons or parts thereof, explosives, clandestine weapons, as well as multiple common firearms excluding those provided for by article 2, paragraph three, of Law no. 110 of April 18, 1975

  • Article 25 Legislative Decree No. 231/2001 – Embezzlement, misappropriation of money or movable property, extortion, undue inducement to give or promise benefits, corruption (amended by Law No. 190/2012, Law 3/2019, and Legislative Decree No. 75/2020 and Decree-Law 92/2024) o Article 314 Criminal Code: Embezzlement (limited to the first paragraph) (introduced by Legislative Decree No. 75/2020) o Article 314-bis Criminal Code: Misappropriation of money or movable property (introduced by Prison Decree No. 92/2024) o Article 316 Criminal Code: Embezzlement by taking advantage of another’s error (introduced by Legislative Decree No. 75/2020) o Article 317 Criminal Code: Extortion (article amended by Law No. 69/2015) o Article 318 Criminal Code: Corruption for the exercise of function (amended by Law No. 190/2012, Law No. 69/2015, and Law No. 3/2019) o Article 319 Criminal Code: Corruption for an act contrary to official duties (article amended by Law No. 69/2015) o Article 319-bis Criminal Code: Aggravating circumstances o Article 319-ter Criminal Code: Corruption in judicial acts (article amended by Law No. 69/2015) o Article 319-quater Criminal Code: Undue inducement to give or promise benefits (article added by Law No. 190/2012 and amended by Law No. 69/2015) o Article 320 Criminal Code: Corruption of a person in charge of a public service o Article 321 Criminal Code: Penalties for the briber o Article 322 Criminal Code: Instigation to corruption o Article 322-bis Criminal Code: Embezzlement, extortion, undue inducement to give or promise benefits, corruption, and instigation to corruption of members of international courts or bodies of the European Communities or international parliamentary assemblies or international organizations and officials of the European Communities and foreign States (amended by Law No. 190/2012 and Law No. 3/2019) o Article 346-bis Criminal Code: Trafficking in illicit influence (amended by Nordio Law No. 114/2024)

75/2020 and by D.L. 92/2024) or Art. 314 c.p.: Embezzlement (limited to the first paragraph) (introduced by Legislative Decree no. 75/2020) or Art. 314-bis c.p.: Undue destination of money or movable property (introduced by Prisons Decree no. 92/2024) or Art. 316 c.p.: Embezzlement by profiting from the error of others (introduced by Legislative Decree no. 75/2020) or Art. 317 c.p.: Extortion by a public official (article amended by Law no. 69/2015) or Art. 318 c.p.: Corruption for the exercise of the function (amended by Law no. 190/2012, Law no. 69/2015 and Law no.

3/2019) or Art. 319 c.p.: Corruption for an act contrary to official duties (article amended by Law no. 69/2015) or Art. 319-bis c.p.: Aggravating circumstances or Art. 319-ter c.p.: Corruption in judicial acts (article amended by Law no. 69/2015) or Art. 319-quater c.p.: Undue inducement to give or promise benefits (article added by Law no. 190/2012 and amended by Law no. 69/2015) or Art. 320 c.p.: Corruption of a person in charge of a public service or Art. 321 c.p.: Penalties for the corrupter or Art. 322 c.p.: Instigation to corruption

Art. 322-bis c.p.: Embezzlement, extortion, undue inducement to give or promise benefits, corruption and instigation to corruption of members of international Courts or bodies of the European Communities or international parliamentary assemblies or international organizations and officials of the European Communities and foreign States (amended by Law no. 190/2012 and Law no. 3/2019) or Art. 346-bis c.p.: Illicit trafficking in influence (amended by the Nordio Law no. 114/2024)

  • Article 25-bis Legislative Decree No. 231/2001 – Counterfeiting of currency, public credit instruments, revenue stamps, and instruments or signs of recognition (article added by Decree-Law No. 350/2001, converted with amendments by Law No. 409/2001; amended by Law No. 99/2009; amended by Legislative Decree 125/2016) o Article 453 Criminal Code: Counterfeiting of currency, spending and introduction into the State, by prior agreement, of counterfeit currency o Article 454 Criminal Code: Alteration of currency o Article 455 Criminal Code: Spending and introduction into the State, without agreement, of counterfeit currency o Article 457 Criminal Code: Spending of counterfeit currency received in good faith o Article 459 Criminal Code: Counterfeiting of revenue stamps, introduction into the State, purchase, possession, or circulation of counterfeit revenue stamps o Article 460 Criminal Code: Counterfeiting of watermarked paper used for manufacturing public credit instruments or revenue stamps o Article 461 Criminal Code: Manufacture or possession of watermarks or instruments intended for counterfeiting currency, revenue stamps, or watermarked paper o Article 464 Criminal Code: Use of counterfeit or altered revenue stamps o Article 473 Criminal Code: Counterfeiting, alteration, or use of trademarks or distinctive signs or patents, models, and designs o Article 474 Criminal Code: Introduction into the State and trade in products with false marks

409/2001; amended by Law no. 99/2009; amended by Legislative Decree 125/2016) or Art. 453 c.p.: Falsification of currency, spending and introduction into the State, by prior agreement, of falsified

currency or Art. 454 c.p.: Alteration of currency or Art. 455 c.p.: Spending and introduction into the State, without prior agreement, of falsified currency or Art. 457 c.p.: Spending of falsified currency received in good faith or Art. 459 c.p.: Falsification of revenue stamps, introduction into the State, purchase, possession or putting into circulation of falsified revenue stamps or Art. 460 c.p.: Counterfeiting of watermarked paper used for the manufacture of public credit papers or revenue stamps or Art. 461 c.p.: Manufacture or possession of watermarks or instruments intended for the falsification of currency, revenue stamps or watermarked paper or Art. 464 c.p.: Use of counterfeited or altered revenue stamps or Art. 473 c.p.: Counterfeiting, alteration or use of trademarks or distinctive signs or patents, models and designs or Art. 474 c.p.: Introduction into the State and trade of products with false signs

  • Article 25-bis.1 Legislative Decree No. 231/2001 – Offenses against industry and commerce (article added by Law No. 99/2009) o Article 513 Criminal Code: Disturbance of freedom of industry or commerce o Article 513-bis Criminal Code: Unlawful competition with threat or violence o Article 514 Criminal Code: Fraud against national industries o Article 515 Criminal Code: Fraud in the exercise of commerce o Article 516 Criminal Code: Sale of non-genuine food substances as genuine o Article 517 Criminal Code: Sale of industrial products with false marks o Article 517-ter Criminal Code: Manufacture and trade in goods made by usurping industrial property rights o Article 517-quater Criminal Code: Counterfeiting of geographical indications or designations of origin of agri-food products

Art. 517 c.p.: Sale of industrial products with misleading signs or Art. 517-ter c.p.: Manufacture and trade of goods produced by usurping industrial property titles or Art. 517-quater c.p.: Counterfeiting of geographical indications or designations of origin of agri-food products

  • Art. 25 ter Legislative Decree no. 231/2001 – Corporate crimes (article added by Legislative Decree no. 61/2002, amended by Law no.

190/2012, by Law 69/2015, by Legislative Decree no. 38/2017 and by Legislative Decree no. 19/2023) or Art. 261 c.c.: False corporate communications (article amended by Law no. 69/2015) or Art. 2621-bis c.c.: Minor facts or Art. 2622 c.c.: False corporate communications of listed companies (article amended by Law no. 69/2015) or Art. 2625, para. 2, c.c.: Prevented control or Art. 2626 c.c.: Undue return of contributions or Art. 2627 c.c.: Illegal distribution of profits and reserves or Art. 2628 c.c.: Illicit operations on shares or social quotas or of the parent company or Art. 2629 c.c.: Operations to the detriment of creditors or Art. 2629-bis c.c.: Omitted communication of conflict of interest (added by Law no. 262/2005) or Art. 2632 c.c.: Fictitious capital formation or Art. 2633 c.c.: Undue distribution of social assets by liquidators or Art. 2635 c.c.: Corruption between private individuals (added by Law no. 190/2012; amended by Legislative Decree no. 38/2017 and Law no. 3/2019) or Art. 2635 bis c.c.: Instigation to corruption between private individuals (added by Legislative Decree no. 38/2017 and amended by

Law no. 3/2019) or Art. 2636 c.c.: Illicit influence on the assembly or Art. 2637 c.c.: Agiotage or Art. 2638, para. 1 and 2 c.c.: Obstruction of the exercise of the functions of public supervisory authorities or Art. 54 Legislative Decree 19/2023: False or omitted declarations for the issuance of the preliminary certificate (added by Legislative Decree no. 19/2023)

  • Article 25-quater Legislative Decree No. 231/2001 – Offenses with purposes of terrorism or subversion of the democratic order provided for by the Criminal Code and special laws (article added by Law No. 7/2003) o Article 270 Criminal Code: Subversive associations o Article 270-bis Criminal Code: Associations with purposes of terrorism, including international, or subversion of the democratic order o Article 270-bis.1 Criminal Code: Aggravating and mitigating circumstances (introduced by Legislative Decree No. 21/2018) o Article 270-ter Criminal Code: Assistance to associates o Article 270-quater Criminal Code: Recruitment with purposes of terrorism, including international o Article 270-quater.1 Criminal Code: Organization of transfer for purposes of terrorism (introduced by Decree-Law No. 7/2015, converted, with amendments, by Law No. 43/2015) o Article 270-quinquies Criminal Code: Training in activities with purposes of terrorism, including international o Article 270-quinquies.1 Criminal Code: Financing of conduct with purposes of terrorism (Law No. 153/2016) o Article 270-quinquies.2 Criminal Code: Removal of assets or money subject to seizure o Article 270-sexies Criminal Code: Conduct with purposes of terrorism o Article 280 Criminal Code: Attack for purposes of terrorism or subversion o Article 280-bis Criminal Code: Act of terrorism with deadly or explosive devices o Article 280-ter Criminal Code: Acts of nuclear terrorism o Article 289-bis Criminal Code: Kidnapping for purposes of terrorism or subversion o Article 289-ter Criminal Code: Kidnapping for purposes of coercion (introduced by Legislative Decree 21/2018) o Article 302 Criminal Code: Instigation to commit any of the offenses provided for in Chapters one and two o Article 304 Criminal Code: Political conspiracy by agreement o Article 305 Criminal Code: Political conspiracy by association o Article 306 Criminal Code: Armed gang: formation and participation o Article 307 Criminal Code: Assistance to participants in conspiracy or armed gang o Article 1, Law No. 342/76: Seizure, hijacking, and destruction of an aircraft o Article 2, Law No. 342/76: Damage to ground installations o Article 3, Law No. 422/1989: Sanctions o Article 5, Legislative Decree No. 625/79: Operative repentance o Article 2, New York Convention of December 9, 1999

Art. 270 c.p.: Subversive associations or Art. 270 bis c.p.: Associations for the purpose of terrorism, including international terrorism, or subversion of the democratic order or Art. 270 bis.1 c.p.: Aggravating and mitigating circumstances (introduced by Legislative Decree no. 21/2018) or Art. 270 ter c.p.: Assistance to associates or Art. 270 quater c.p.: Recruitment for the purpose of terrorism, including international terrorism or Art. 270 quater.1 c.p.: Organization of transfer for the purpose of terrorism (introduced by D.L. no.

7/2015, converted, with amendments, by Law no. 43/2015) or Art. 270 quinquies c.p.: Training for activities for the purpose of terrorism, including international terrorism or Art. 270 quinquies.1 c.p.: Financing of conduct for the purpose of terrorism (Law no. 153/2016) or Art. 270 quinquies.2 c.p.: Embezzlement of assets or money subject to seizure or Art. 270 sexies c.p.: Conduct for the purpose of terrorism or Art. 280 c.p.: Attack for the purpose of terrorism or subversion or Art. 280 bis c.p.: Act of terrorism with deadly or explosive devices or Art. 280 ter c.p.: Acts of nuclear terrorism or Art. 289 bis c.p.: Kidnapping for the purpose of terrorism or subversion or Art. 289 ter c.p.: Kidnapping for the purpose of coercion (introduced by Legislative Decree 21/2018) or Art. 302 c.p.: Instigation to commit any of the crimes provided for by Chapters one and two or Art. 304 c.p.: Political conspiracy by agreement or Art. 305 c.p.: Political conspiracy by association or Art. 306 c.p.: Armed band: formation and participation or Art. 307 c.p.: Assistance to participants in a conspiracy or armed band or Art. 1, Law no. 342/76: Taking possession, hijacking and destruction of an aircraft or Art. 2, Law no. 342/76: Damage to ground installations or Art. 3, Law no. 422/1989: Sanctions or Art. 5, Legislative Decree no. 625/79: Active repentance or Art. 2 New York Convention of December 9, 1999

  • Article 25-quater.1 Legislative Decree No. 231/2001 – Practices of female genital mutilation (article added by Law No. 7/2006) o Article 583-bis Criminal Code: Practices of female genital mutilation
  • Article 25-quinquies Legislative Decree No. 231/2001 – Offenses against individual personality (article added by Law No. 228/2003; amended by Law No. 199/2016) o Article 600 Criminal Code: Reduction or maintenance in slavery or servitude o Article 600-bis Criminal Code: Child prostitution o Article 600-ter Criminal Code: Child pornography o Article 600-quater Criminal Code: Possession of or access to pornographic material (article amended by Law No. 238/2021) o Article 600-quater.1 Criminal Code: Virtual pornography (added by Article 10, Law February 6, 2006, No. 38) o Article 600-quinquies Criminal Code: Tourist initiatives aimed at exploiting child prostitution o Article 601 Criminal Code: Trafficking in persons (amended by Legislative Decree 21/2018) o Article 602 Criminal Code: Purchase and sale of slaves o Article 603-bis Criminal Code: Unlawful intermediation and exploitation of labor o Article 609-undecies Criminal Code: Grooming of minors (article amended by Law No. 238/2021)

228/2003; amended by Law no. 199/2016) or Art. 600 c.p.: Reduction to or maintenance in slavery or servitude or Art. 600 bis c.p.: Child prostitution or Art. 600 ter c.p.: Child pornography or Art. 600 quater c.p.: Possession of or access to pornographic material (article amended by Law no.

238/2021) or Art. 600 quater.1 c.p.: Virtual pornography (added by art. 10, Law February 6, 2006 no. 38) or Art. 600 quinquies c.p.: Tourism initiatives aimed at the exploitation of child prostitution or Art. 601 c.p.: Trafficking in persons (amended by Legislative Decree 21/2018) or Art. 602 c.p.: Purchase and sale of slaves or Art. 603 bis c.p.: Illicit intermediation and labor exploitation or Art. 609 undecies c.p.: Grooming of minors (article amended by Law no. 238/2021)

  1. Article 25-sexies Legislative Decree No. 231/2001 – Market abuse offenses (article added by Law No. 62/2005) o Article 184, Legislative Decree No. 58/1998: Abuse or unlawful communication of inside information. Recommendation or inducement of others to commit abuse of inside information (article amended by Law No. 238/2021) o Article 185, Legislative Decree No. 58/1998: Market manipulation (article amended by Legislative Decree 107/2018 and Law No. 238/2021) o Article 187-quinquies, Legislative Decree No. 58/1998: Other cases of market abuse (article amended by Legislative Decree No. 107/2018) o Article 14, EU Regulation No. 596/2014: Prohibition of insider dealing and unlawful disclosure of inside information o Article 15, EU Regulation No. 596/2014: Prohibition of market manipulation

or Art. 184 Legislative Decree no. 58/1998: Abuse or illicit communication of inside information. Recommendation or inducement of others to commit insider abuse (article amended by Law no. 238/2021) or Art. 185 Legislative Decree no. 58/1998: Market manipulation (article amended by Legislative Decree 107/2018 and Law no. 238/2021) or Art. 187 quinquies Legislative Decree no. 58/1998: Other cases regarding market abuse (article amended by Legislative Decree no. 107/2018) or Art. 14 EU Reg. no. 596/2014: Prohibition of insider abuse and illicit communication of inside information or Art. 15 EU Reg. no. 596/2014: Prohibition of market manipulation

  1. Article 25-septies Legislative Decree No. 231/2001 – Offenses of manslaughter and serious or very serious negligent injury, committed in violation of accident prevention regulations and protection of hygiene and health at work (article added by Law No. 123/2007; amended by Law No. 3/2018) o Article 590 Criminal Code: Negligent personal injury o Article 589 Criminal Code: Manslaughter
  2. Article 25-octies Legislative Decree No. 231/2001 – Receiving stolen goods, money laundering, and use of money, goods, or benefits of illicit origin, as well as self-laundering (article added by Legislative Decree No. 231/2007; amended by Law No. 186/2014 and Legislative Decree No. 195/2021) o Article 648 Criminal Code: Receiving stolen goods (article amended by Legislative Decree 195/2021) o Article 648-bis Criminal Code: Money laundering (article amended by Legislative Decree 195/2021) o Article 648-ter Criminal Code: Use of money, goods, or benefits of illicit origin (article amended by Legislative Decree 195/2021) o Article 648-ter.1 Criminal Code: Self-laundering (article amended by Legislative Decree 195/2021)

Legislative Decree no. 195/2021) or Art. 648 c.p.: Receiving stolen goods (article amended by Legislative Decree 195/2021) or Art. 648 bis c.p.: Money laundering (article amended by Legislative Decree 195/2021) or Art. 648 ter c.p.: Use of money, goods or benefits of illicit origin (article amended by Legislative Decree

Article 25-octies.1 Legislative Decree No. 231/2001 – Offenses concerning payment instruments other than cash (article added by Legislative Decree 184/2021) o Article 493-ter Criminal Code: Unlawful use and counterfeiting of payment instruments other than cash o Article 493-quater Criminal Code: Possession and dissemination of equipment, devices, or computer programs designed to commit offenses concerning payment instruments other than cash o Article 640-ter Criminal Code: Aggravated computer fraud by the execution of a transfer of money, monetary value, or virtual currency o Article 512-bis Criminal Code: Fraudulent transfer of assets (article added by Decree-Law 105/2023)

(article added by Legislative Decree 184/2021) or Art. 493 ter c.p.: Undue use and falsification of payment instruments other than cash or Art. 493 quater c.p.: Possession and dissemination of computer equipment, devices or programs aimed at committing crimes regarding payment instruments other than cash or Art. 640 ter c.p.: Computer fraud aggravated by the realization of a transfer of money, monetary value or virtual currency or Art. 512-bis c.p.: Fraudulent transfer of values (article added by D.L. 105/2023)

  1. Article 25-octies.1, paragraph 2, Legislative Decree No. 231/2001 – Other cases concerning payment instruments other than cash (article added by Legislative Decree 184/2021)
  2. Art. 25 novies, Legislative Decree no. 231/2001 – Crimes regarding copyright infringement (article added by

Law no. 99/2009) or Art. 171, para. 1 letter a-bis), Law no. 633/1941: Abusive duplication, for profit, of computer programs; importation, distribution, sale or possession for commercial or entrepreneurial purposes or leasing of programs contained in media not marked by SIAE; preparation of means to remove or circumvent protection devices for computer programs. Making available to the public, in a system of electronic networks, through connections of any kind, a protected intellectual work, or part thereof

or Art. 171, para. 3, Law no. 633/1941: Crimes referred to in the previous point committed on works of others not intended for publication if the honor or reputation is offended or Art. 171 bis, para. 2, Law no. 633/1941: Reproduction, transfer to another medium, distribution, communication, presentation or demonstration in public, of the content of a database; extraction or re-use of the database; distribution, sale or leasing of databases or Art. 171 ter, Law no. 633/1941: Abusive duplication, reproduction, transmission or dissemination in public by any process, in whole or in part, of intellectual works intended for the television, cinematographic, sale or rental circuit of discs, tapes or similar media or any other medium containing phonograms or videograms of musical, cinematographic or assimilated audiovisual works or sequences of moving images; literary, dramatic, scientific or educational, musical or dramatic-musical, multimedia works, even if included in collective or composite works or databases; reproduction, duplication, transmission or abusive dissemination, sale or trade, transfer for any reason or abusive importation of more than fifty copies or specimens of works protected by copyright and related rights; introduction into a system of electronic networks, through connections of any kind, of an intellectual work protected by copyright, or part thereof or Art. 171 septies, Law no. 633/1941: Failure to communicate to SIAE the identification data of media not subject to marking or false declaration or Art. 171 octies, Law no. 633/1941: Fraudulent production, sale, importation, promotion, installation, modification, use for public and private use of devices or parts of devices suitable for the decoding of conditional access audiovisual transmissions carried out over the air, via satellite, via cable, in both analog and digital form (art. 171-octies law no. 633/1941).

  1. Art. 25 decies Legislative Decree no. 231/2001 – Inducement not to make statements or to make false statements to the judicial authority (article added by Law August 3, 2009, no. 116, and then replaced by Legislative Decree July 7, 2011, no. 121) or Inducement not to make statements or to make false statements to the judicial authority (art. 377-bis c.p.).
  2. Art. 25 undecies Legislative Decree no. 231/2001 – Environmental crimes (article added by Legislative Decree no. 121/2011, amended by Law no. 68/2015, amended by Legislative Decree no. 21/2018) or Art. 452-bis c.p.: Environmental pollution or Art. 452-quater c.p.: Environmental disaster

Art. 452-quinquies c.p.: Culpable crimes against the environment or Art. 452-sexies c.p.: Trafficking and abandonment of high-radioactivity material or Art. 452-octies c.p.: Aggravating circumstances or Art. 727-bis c.p.: Killing, destruction, capture, removal, possession of specimens of protected wild animal or plant species or Art. 733-bis c.p.: Destruction or deterioration of habitats within a protected site or Art. 137 Legislative Decree no. 152/2006: Discharges of industrial wastewater containing dangerous substances; discharges on the ground, in the subsoil and in groundwater; discharge into sea waters by ships or aircraft or Art. 256 Legislative Decree no. 152/2006: Unauthorized waste management activities or Art. 257 Legislative Decree no. 152/2006: Pollution of the soil, subsoil, surface waters or groundwater or Art. 258 Legislative Decree no. 152/2006: Violation of the obligations of communication, keeping of mandatory registers and forms or Art. 259 Legislative Decree no. 152/2006: Illicit waste trafficking or Art. 260 Legislative Decree no. 152/2006: Organized activities for illicit waste trafficking or Art. 260-bis, Legislative Decree no. 152/2006: False indications on the nature, composition and

chemical-physical characteristics of waste in the preparation of a waste analysis certificate.

  • Art. 279, Legislative Decree no. 152/2006: Sanctions
    • Environmental crimes provided for by Law no. 150/1992
  • Environmental crimes provided for by Law no. 549/1993
  • Environmental crimes provided for by Legislative Decree no. 202/2007
  1. Art. 25 duodecies Legislative Decree no. 231/2001 – Employment of third-country nationals whose stay is irregular (article added by Legislative Decree no. 109/2012, amended by Law October 17, 2017 no. 161) or Art. 22, para. 12 bis, Legislative Decree no. 286/1998: Employment of third-country nationals whose stay is irregular or Art. 12, para. 3, 3 bis, 3 ter, 5, Legislative Decree no. 286/1998: Provisions against illegal immigration
  2. Art. 25 terdecies Legislative Decree no. 231/2001 – Racism and xenophobia (article added by Law November 20, 2017 no. 167, amended by Legislative Decree no. 21/2018)

Art. 3, paragraph 3-bis, Law October 13, 1975, no. 654

  • Art. 25 quaterdecies Legislative Decree no. 231/2001 – Fraud in sports competitions, abusive exercise of gaming or betting and gambling exercised by means of prohibited devices (article added by Law no. 39/2019) or Art. 1, Law no. 401/1989: Fraud in sports competitions or Art. 4, Law no. 401/1989: Abusive exercise of gaming or betting activities
  • Art. 25 quinquesdecies Legislative Decree no. 231/2001 – Tax Crimes (article added by Law no. 157/2019 and by Legislative Decree

no. 75/2020) or Art. 2 Legislative Decree no. 74/2000: Fraudulent declaration through the use of invoices or other documents for non-existent operations or Art. 3 Legislative Decree no. 74/2000: Fraudulent declaration through other artifices or Art. 4 Legislative Decree no. 74/2000: Unfaithful declaration (introduced by Legislative Decree no. 75/2020) or Art. 5 Legislative Decree no. 74/2000: Omitted declaration (introduced by Legislative Decree no. 75/2020) or Art. 8 Legislative Decree no. 74/2000: Issuance of invoices or other documents for non-existent operations or Art. 10 Legislative Decree no. 74/2000: Concealment or destruction of accounting documents or Art. 10-quater Legislative Decree no. 74/2000: Undue compensation (introduced by Legislative Decree no. 75/2020) or Art. 11 Legislative Decree no. 74/2000: Fraudulent evasion of tax payment

  • Art. 25 sexiesdecies Legislative Decree no. 231/2001 – Smuggling (article added by Legislative Decree no. 75/2020)

o Art. 282 Presidential Decree no. 43/1973: Smuggling in the movement of goods across land borders and customs areas o Art. 283 Presidential Decree no. 43/1973: Smuggling in the movement of goods in border lakes o Art. 284 Presidential Decree no. 43/1973: Smuggling in the maritime movement of goods o Art. 285 Presidential Decree no. 43/1973: Smuggling in the movement of goods by air o Art. 286 Presidential Decree no. 43/1973: Smuggling in extra-customs zones o Art. 287 Presidential Decree no. 43/1973: Smuggling through the improper use of goods imported with customs facilities o Art. 288 Presidential Decree no. 43/1973: Smuggling in customs warehouses o Art. 289 Presidential Decree no. 43/1973: Smuggling in cabotage and circulation o Art. 290 Presidential Decree no. 43/1973: Smuggling in the export of goods eligible for refund of duties o Art. 291 Presidential Decree no. 43/1973: Smuggling in temporary import or export

Art. 291-bis Presidential Decree no. 43/1973: Smuggling of foreign manufactured tobacco o Art. 291-ter Presidential Decree no. 43/1973: Aggravating circumstances for the crime of smuggling foreign manufactured tobacco o Art. 291-quater Presidential Decree no. 43/1973: Criminal association aimed at smuggling foreign manufactured tobacco o Art. 292 Presidential Decree no. 43/1973: Other cases of smuggling o Art. 295 Presidential Decree no. 43/1973: Aggravating circumstances of smuggling

  • Art. 25 septiesdecies Legislative Decree no. 231/2001 – Crimes against cultural heritage (Article added by Law no.

22/2022)o Art. 518-bis c.p.: Theft of cultural property o Art. 518-ter c.p.: Embezzlement of cultural property o Art. 518-quater c.p.: Receiving stolen cultural property o Art. 518-octies c.p.: Falsification of private writing relating to cultural property o Art. 518-novies c.p.: Violations regarding the alienation of cultural property o Art. 518-decies c.p.: Illicit import of cultural property o Art. 518-undecies c.p.: Illicit exit or export of cultural property o Art. 518-duodecies c.p.: Destruction, dispersal, deterioration, defacement, soiling and illicit use of cultural or landscape assets o Art. 518-quaterdecies c.p.: Counterfeiting of works of art

  • Art. 25 duodevicies Legislative Decree no. 231/2001 – Money laundering of cultural property and devastation and looting of cultural and landscape assets (Article added by Law no. 22/2022) o Art. 518-sexies c.p.: Money laundering of cultural property o Art. 518-terdecies c.p.: Devastation and looting of cultural and landscape assets

2.2 Sanctions provided for

The sanctioning system described by Legislative Decree 231/2001, following the commission of the crimes listed above, provides for the application of the following administrative sanctions, depending on the offenses committed:

  • pecuniary sanctions;
  • disqualifying sanctions;
  • confiscation;
  • publication of the sentence.

Disqualifying sanctions, which can be imposed only where expressly provided for and also as a precautionary measure, are the following:

  • prohibition from exercising the activity;
  • suspension or revocation of authorizations, licenses or concessions functional to the commission of the offense;
  • prohibition from contracting with the Public Administration;
  • exclusion from facilities, financing, contributions and subsidies, and/or revocation of those possibly already granted;
  • prohibition from advertising goods or services.

Legislative Decree 231/2001 provides that, should there be grounds for the application of a disqualifying sanction that orders the interruption of the entity’s activity, the judge, instead of applying said sanction, may order the continuation of the activity by a judicial commissioner (art. 15 of the Decree) appointed for a period equal to the duration of the disqualifying penalty that would have been applied, when at least one of the following conditions occurs:

  • the entity performs a public service or a service of public necessity whose interruption may cause serious harm to the community;
  • the interruption of the activity may cause significant repercussions on employment, taking into account the size of the entity and the economic conditions of the territory in which it is located.

2.3 The exempting condition for administrative liability

Art. 6 of Legislative Decree 231/2001 establishes that the entity is not liable by way of administrative responsibility, if it proves that:

  • the governing body has adopted and effectively implemented, before the commission of the act, organization, management and control models suitable for preventing crimes of the kind that occurred;
  • the task of supervising the functioning and observance of the models and ensuring their updating has been entrusted to a body of the entity endowed with autonomous powers of initiative and control (so-called Supervisory Body);
  • the persons committed the crime by fraudulently eluding the organization, management and

control models;

  • there has been no omitted or insufficient supervision by the Supervisory Body.

The adoption of the organization, management and control model therefore allows the entity to avoid the imputation of administrative liability.

The mere adoption of this document, by resolution of the entity’s administrative body, is not, however, in itself sufficient to exclude said liability, as it is necessary for the model to be effectively and efficiently implemented.

With reference to the effectiveness of the organization, management and control model for the prevention of the commission of the crimes provided for by Legislative Decree 231/2001, it is required that it:

  • identifies the corporate activities within which crimes may be committed;
  • provides for specific protocols aimed at planning the formation and implementation of the entity’s decisions in relation to the crimes to be prevented;
  • identifies methods for managing financial resources suitable for preventing the commission of crimes;
  • provides for information obligations towards the body responsible for supervising the functioning and observance of the models;
  • introduces a disciplinary system suitable for sanctioning non-compliance with the measures indicated in the organization, management and control model.

With reference to the effective application of the organization, management and control model, Legislative Decree 231/2001 requires:

  • a periodic verification and, in the event that significant violations of the prescriptions imposed by the model are discovered or changes occur in the organization or activity of the entity or legislative changes, the modification of the organization, management and control model;
  • the imposition of sanctions in case of violation of the prescriptions imposed by the organization, management and control model.

By virtue of the integration of Art. 6 of Decree 231, by Law no. 179/2017, and the recent update provided for by Legislative Decree 24/2023, the Model must also provide for:

  • one or more channels that allow for the submission, to protect the integrity of the entity, of detailed reports of unlawful conduct, relevant under Decree 231 and based on precise and consistent factual elements, or of violations of the Model, which they have become aware of by reason of the functions performed; these channels guarantee the confidentiality of the whistleblower’s identity in the management activities of the report;
  • the prohibition of retaliatory or discriminatory acts, direct or indirect, against the whistleblower for reasons linked, directly or indirectly, to the report;
  • that the disciplinary system provides for sanctions against those who violate the protection measures for the whistleblower, as well as those who make reports that prove to be unfounded with intent or gross negligence.

The effective preparation of the Model also presupposes that:

  • the Entity has proceeded to establish an internal control body with the task of supervising the functioning, effectiveness and observance of the Model, as well as ensuring its updating (“Supervisory

Body / SB”);

  • the control body is not guilty of omitted or insufficient supervision regarding the implementation and observance of the Model;
  • the Entity has prepared a system for periodic verification and possible updating of the Model; – the perpetrator of the Crime acted by fraudulently eluding the provisions of the Model.

2.4 Crimes committed abroad

The entity may be called to account in Italy for crimes – contemplated by Legislative Decree no. 231/2001 itself – committed abroad (art. 4 Legislative Decree no. 231/2001) also within branches or permanent establishments of the Italian entity, upon the occurrence of the following conditions:

i. the crime must be committed by a person functionally linked to the entity, pursuant to art. 5, paragraph 1, of Legislative Decree no. 231/2001; ii. the entity must have its main headquarters in the territory of the Italian State; iii. the entity can only be held liable in the cases and under the conditions provided for by articles 7, 8, 9, 10 of the criminal code (in cases where the law provides that the guilty party – natural person – be punished at the request of the Minister of Justice, proceedings are taken against the entity only if the request is also made against the entity itself) and, also in compliance with the principle of legality referred to in art. 2 of Legislative Decree no. 231/2001, only for crimes for which its liability is provided for by an ad hoc legislative provision; iv. provided that the cases and conditions referred to in the aforementioned articles of the Criminal Code exist, the State of the place where the act was committed does not proceed against the entity.

2.5 The Confindustria “Guidelines”

Art. 6 of Legislative Decree 231/2001 expressly provides that organization, management and control models can be adopted on the basis of codes of conduct drawn up by the representative associations of the entities.

For the purposes of preparing the model, the “Guidelines for the construction of organization, management and control models pursuant to Legislative Decree 231/2001” (hereinafter only “Guidelines”) drawn up by Confindustria and approved by the Ministry of Justice with Ministerial Decree 4 December 2003 and subsequent updates are therefore taken into consideration. The subsequent update, published by Confindustria on 24 May 2004, was approved by the Ministry of Justice, which judged these Guidelines suitable for achieving the purposes provided for by the Decree.

These Guidelines, subsequently updated by Confindustria in 2008 (as of 31 March 2008, then approved by the Ministry of Justice on 2 April 2008), were updated again in March 2014 and approved with a note from the Ministry of Justice on 21 July 2014, after hearing the concerting Ministries, CONSOB and the Bank of Italy. The Guidelines were last updated in June 2021.

In defining the organization, management and control model, the Confindustria Guidelines provide for the following design phases:

  • risk identification, i.e. the analysis of the corporate context to highlight in which areas of activity and according to which methods the crimes provided for by Legislative Decree 231/2001 may occur in the corporate context;
  • the preparation of a control system suitable for preventing the risks of crime identified in the previous phase, to be carried out through the evaluation of the existing control system and the relative degree of adaptation to the prevention needs expressed by the Legislative Decree. 231/2001.

The most relevant components of the control system outlined in the Confindustria Guidelines to guarantee the effectiveness of the organization, management and control model are summarized below:

  • the provision of ethical principles and behavioral rules in a Code of Ethics;
  • a sufficiently formalized and clear organizational system, particularly with regard to the attribution of responsibilities, lines of hierarchical dependence and the description of tasks;
  • manual and/or IT procedures that regulate the performance of activities, providing for appropriate and adequate controls;
  • authorization and signature powers consistent with the organizational and management responsibilities attributed by the entity, providing, where appropriate, for spending limits;
  • management control systems, capable of promptly signaling possible critical issues; – information and training of personnel.

The Confindustria Guidelines also specify that the components of the control system described above must comply with a series of control principles, including:

  • verifiability, traceability, consistency and congruity of every operation, transaction and action;
  • application of the principle of separation of functions and segregation of duties (no one can independently manage an entire process);
  • establishment, execution and documentation of control activities on processes and activities at risk of crime.

2.6 Representation of the entity in court

The recent sentence of the Court of Cassation no. 13002/2024 establishes that “on the subject of liability for crimes of entities, the legal representative under investigation or accused of the predicate crime cannot proceed, due to the condition of incompatibility in which they find themselves, to the appointment of the entity’s defense counsel due to the general and absolute prohibition of representation set by art. 39 of legislative decree 8 June 2001, no. 231.”

In application of this principle, Computer Design S.r.l. has provided for precautionary rules for possible situations of conflict of interest of the legal representative under investigation for the predicate crime, valid to provide the Company with a defense counsel, appointed by a specifically delegated person, who protects its interests. Therefore, to overcome any incompatibility, the appointment of the entity’s defense counsel is delegated:

  • primarily to the Managing Director, in the event that the Chairman of the

BoD;

  • secondarily to another member of the Board of Directors, in the event that the investigations also concern the Managing Director.

This safeguard is implemented in accordance with what was defined by the United Sections,“the legal representative and the legal person find themselves in a situation of objective and irremediable procedural conflict, since the legal person could have an interest in demonstrating that its representative acted in their exclusive interest or in the interest of third parties or in proving that the crime was committed through a fraudulent evasion of the organizational models adopted, in this way excluding its own liability and thus making it fall on the representative alone. The prohibition of representation established by art. 39 is, therefore, absolute and does not allow for exceptions, as it is functional to ensuring the full guarantee of the right of defense to the collective subject; on the other hand, this right would be completely compromised if the entity participated in the proceeding through the representation of a subject carrying conflicting interests from a substantive and procedural point of view. For this reason, the existence of the ‘conflict’ is presumed iuris et de iure and its existence does not have to be ascertained in concrete terms, with the further consequence that there is no burden of motivation on the point by the judge: the prohibition is triggered in the presence of the situation contemplated by the rule, i.e. when the legal representative turns out to be accused of the crime on which the administrative offense depends, so that the judge only has to ascertain that this prerequisite occurs, without a verification being required regarding an actual situation of incompatibility” (United Sections, Gabrielloni no. 33041 of 28/05/2015).

3 ADOPTION OF THE MODEL BY COMPUTER DESIGN S.R.L.

3.1 The Company Computer Design S.r.l. and the objectives pursued with the adoption of the Model

Computer Design S.r.l. (Tax Code 02598060966/VAT no. 11980150152), with registered office in Santo Stefano Ticino (MI), Via Piave 46 CAP 20011, is a company that mainly deals with the supply of software and IT consultancy (Ateco Code 62.01).

Specifically, Computer Design S.r.l. has as its object the following activities:

  • Trade, rental, export, import, maintenance, repair of computers,

electronic equipment and systems for data processing and materials relating to said products;

  • The production and development of software;
  • The provision of services and the realization of training courses relating to the above;
  • Technical-organizational assistance, also through the preparation of appropriate programs, to companies, formed in any way, institutions, entities and professional firms.

As regards, instead, the organizational chart and functions, reference is made to the documentation kept constantly updated.

Consistently with its activity, therefore, the Company has adopted an internal control system compliant with the provisions of the relevant laws and regulations.

The Company, in order to ensure conditions of fairness and transparency in the conduct of its activities, deemed it appropriate to proceed with the adoption – and subsequent periodic updating activity – of an organization, management and control Model pursuant to the Decree that was always updated to current legislation, jurisprudence, and best practices relating to its corporate reality.

To this end, the Company carried out a complete preliminary activity of updating the risk analysis with the support of legal consultants specialized in this sector and, through the Board of Directors, adopted the Organization, Management and Control Model.

The Company has also appointed a Supervisory Body to which it has entrusted the task of supervising the functioning, effectiveness and observance of the Model itself, as well as ensuring its updating.

All operations falling within the Risk Areas must therefore be carried out in compliance with current laws, company procedures and the rules contained in this Model.

3.2 The organizational system in general and the function of the Model

The purpose of this Model is the construction of a structured and organic system of procedures and information flows, as well as control activities, aimed at preventing the commission of the various types of Crime contemplated by the Decree.

In general, the organizational system of Computer Design S.r.l. adheres to the essential requirements of clarity, formalization, communication and separation of roles, particularly as regards the attribution of responsibility, representation, definition of hierarchical lines and operational activities.

Also in support of what is indicated in this Model, Computer Design S.r.l. has adopted organizational tools (policies, procedures, code of ethics) based on the above requirements.

In this regard, the organizational tools already adopted and those possibly still to be adopted, as well as the behavioral principles indicated in this Model are characterized, where deemed appropriate and necessary due to the complexity of the process and the corporate structure, by:

o separation within each process between the subject who initiates it, the subject who executes and concludes it and the subject who controls it; o traceability of each relevant step of the process; o adequate level of formalization.

As regards specifically this Model, once the Risk Areas of the Company have been identified (i.e. the areas of activity within which the possibility of Crimes being committed is considered highest), with the preliminary activity of corporate risk analysis, it aims to:

  • sensitize Corporate Officers, Employees and External Collaborators and disseminate behavioral rules and established procedures at all levels of the Company;
  • determine, in all those who operate in the name and on behalf of the Company in the Risk Areas, the awareness of being able to incur, in case of violation of the provisions reported therein, an offense liable to sanctions, on a criminal and administrative level, not only against themselves but also against the Company itself;
  • reiterate that such forms of unlawful behavior are strongly condemned by the Company as (even in the event that the Company were apparently in a position to derive interest or advantage from them) they are in any case contrary, in addition to the provisions of the law, also to the ethical-social principles to which the Company intends to adhere in the performance of its activity;
  • allow the Company, thanks to a monitoring action on the Risk Areas, to intervene promptly to prevent or counter the commission of the Crimes themselves.

3.3 The methodology adopted for the construction of the Model

Computer Design S.r.l., in consideration of the provisions of the Decree, has launched a project aimed at drafting its own Model and, therefore, at preparing this document, conferring a specific mandate to external consultants.

The fundamental elements developed by Computer Design S.r.l. in defining the Model can be summarized as follows:

  • the mapping of sensitive activities, with examples of possible ways of carrying out crimes and instrumental processes within which, in principle, the conditions and/or means for the commission of crimes relevant under the Decree could occur (activities which must therefore be subjected to periodic monitoring);
  • a set of company procedures and policies that oversees all company activities, including in particular for the purposes of this Model those activities which, following the aforementioned mapping activity, were found to be exposed to a potential risk of commission of the crimes referred to in Legislative Decree 231/2001;
  • the establishment of a Supervisory Body with a monocratic composition, and attribution to the same of specific supervisory tasks on the effective implementation and actual application of the Model;
  • a sanctioning system aimed at ensuring the effective implementation of the Model and containing the disciplinary actions and sanctioning measures applicable to the Recipients, in case of violation of the prescriptions contained in the

Model itself;

  • the provision of information and training activities on the contents of this Model;
  • the provision of behavioral and control principles broken down by instrumental/functional process aimed at regulating the decisions of Computer Design S.r.l. broken down in the Sections of the “Special Part” of this Model.

3.4 Code of Ethics

Computer Design S.r.l., sensitive to the need to base the conduct of corporate activities on respect for the principle of legality, has adopted its own Code of Ethical Conduct (hereinafter, alternatively the “Code” or the “Code of Ethics”).

The Code establishes a series of principles, values and rules of conduct to be applied in corporate management that the Company recognizes as its own and of which it demands observance by both its corporate bodies and employees, and by third parties who, for any reason, maintain commercial relations with it.

The Model, whose provisions are in any case consistent and compliant with the principles of the Code of Ethics, responds more specifically to the needs expressed by the Decree and is, therefore, aimed at preventing the commission of the types of crime included in the scope of operation of the Legislative Decree. 231/2001.

The Code of Computer Design S.r.l. affirms, in any case, principles of correct conduct of corporate affairs also suitable for preventing the unlawful behaviors referred to in the Decree, thus acquiring preventive relevance also for the purposes of the Model, and therefore constituting an element complementary to it.

3.5 Methodological Path for Defining the Model: mapping of activities at risk of crime-instrumental processes and safeguards

Legislative Decree 231/2001 expressly provides, in its art. 6, paragraph 2, letter a), that the organization, management and control model of the entity identifies the corporate activities within which the crimes included in the Decree can potentially be committed.

Consequently, the Company proceeded, with the support of an external consultant, to an in-depth analysis of the same. Within this activity, the Company first analyzed its organizational structure represented in the company organizational chart which identifies the corporate Departments/Functions, highlighting their roles and hierarchical-functional reporting lines. Said document is kept at the administrative office, and is available for consultation on the company intranet.

Computer Design S.r.l. subsequently analyzed its corporate activities on the basis of information collected from corporate referents (i.e. Function Managers) who, by reason of the role held, are provided with the widest and deepest knowledge of the operations of the corporate sector of their competence.

As anticipated, the results of said activity were collected and formalized in a descriptive document that forms an integral part of the Model, called “Mapping of activities at risk of crime”, which illustrates in detail the risk profiles of Computer Design S.r.l. relating to the commission of the crimes included in the Legislative Decree. 231/2001.

In particular, in said Mapping of activities at risk of crime, the areas of activity at risk, the corporate activities at risk of commission of crimes (so-called “sensitive activities”), the corporate Functions involved, the types of crime provided for by Legislative Decree 231/2001 and considered relevant within the corporate reality of the Company and associable with sensitive activities, examples of possible methods and purposes of carrying them out as well as the processes in whose performance, again in principle, the conditions and/or means for the commission of the crimes themselves could be created, are detailed.

3.5.1 Areas of activity at risk of crime and relevant cases

The risk of potential commission of the crimes provided for by Legislative Decree 231/2001 was found in the areas of corporate activity listed in each special part of this Model for each corporate process and which are reported as indicated in the Mapping of activities at risk of crime.

Specifically, Computer Design S.r.l. has adopted the Special Parts relating to the Crimes for which Risk Areas and Risk Activities were detected and, precisely:

  • Crimes committed in relations with the P.A.;
  • Crimes of inducement not to make statements or to make false statements to the judicial authority;
  • Corporate crimes (which also include crimes of corruption between private individuals);
  • Crimes of money laundering, use of money, goods or benefits of illicit origin and self-laundering;
  • Crimes of manslaughter or serious or very serious injuries committed with violation of the rules on the protection of health and safety at work and employment of third-country nationals whose stay is irregular;
  • Computer crimes and illicit data processing, crimes regarding payment instruments other than cash and crimes regarding copyright infringement;
  • Crimes against industry and commerce;
  • Environmental Crimes;
  • Tax crimes;
  • Organized crime offenses;
  • Smuggling;
  • Crimes against individual personality;
  • Crimes of forgery in coins, in public credit cards, in revenue stamps and in instruments or signs of recognition.

Reference is made to the individual Special Parts of this Model for the analytical description of the individual Crimes listed above.

3.5.2 Structure of the Model: General Part and Special Parts based on the different crime hypotheses

This Model consists of a “General Part” and “Special Parts” referring to the individual categories of crime with respect to which, for Computer Design S.r.l., there is an abstractly theoretical risk of committing the crime.

The corporate processes, analyzed individually in the Mapping of activities at risk of crime, are identified as follows:

  1. Relations with the public administration
  2. Process for Purchasing goods and services, assignments and consultancies
  3. Commercial and contract execution
  4. Selection, hiring and management of personnel and expense reports
  5. Management of fulfillments regarding health and safety in the workplace
  6. Management of administrative, accounting and tax fulfillments
  7. Security management and maintenance of information systems
  8. Management of gifts, liberalities and sponsorships
  9. Management of environmental fulfillments

From the corporate risk analysis conducted for the purposes of adopting the Model, it emerged that the Risk Activities, at present, concern the following types of crimes:

  1. Crimes committed in relations with the P.A.;
  2. Crimes of inducement not to make statements or to make false statements to the judicial authority;
  3. Corporate crimes (which also include crimes of corruption between private individuals);
  4. Crimes of money laundering, use of money, goods or benefits of illicit origin and self-laundering;
  5. Crimes of manslaughter or serious or very serious injuries committed with violation of the rules on the protection of health and safety at work and employment of third-country nationals whose stay is irregular;
  6. Computer crimes and illicit data processing, crimes regarding payment instruments other than cash and crimes regarding copyright infringement;
  7. Crimes against industry and commerce;
  8. Environmental Crimes;
  9. Tax crimes;
  10. Organized crime offenses;
  11. Smuggling;
  12. Crimes against individual personality;
  13. Crimes of forgery in coins, in public credit cards, in revenue stamps and in instruments or signs of recognition.

The individual Special Parts have the function of:

  1. detailing the procedural principles that the Recipients are called to observe for the purposes of the correct application of the Model;
  2. providing the Supervisory Body and the managers of the various corporate areas who cooperate with it, the executive tools to exercise the control, monitoring and verification activities provided for by the Model.

Reference is made to the individual Special Parts of this Model for the analytical description of the specific Risk Activities relating to each category of Crime.

3.5.3 Modifications and additions to the Model

Modifications and additions to the Model are left to the Company’s Board of Directors also upon proposal of the Supervisory Body.

Proposals for modification and addition to the Model may also be presented by the SB on the basis of indications coming from the managers of the individual functions.

4 GENERAL RULES OF CONDUCT

4.1 The system in general

In carrying out operations relating to the management of the Company, Corporate Officers and Employees and Collaborators must respect the rules of conduct provided for by this Model and those indicated both in the General Part and in the individual Special Parts.

Corporate Officers and Employees must first of all know and respect:

  1. the Company’s Articles of Association;
  2. the Code of Ethics of Computer Design S.r.l.;
  3. any other internal regulation relating to the internal control and reporting system adopted by the Company (e.g. company policies, general preventive control procedures, procedures, information flows, etc.).

The rules, policies, procedures and principles referred to in the tools listed above are not reported in detail in this Model, as they are part of the broader organization and control system that it intends to integrate and that all Recipients, in relation to the type of relationship in place with the Company, are required to know and respect.

These rules, policies, procedures and principles, if they have a direct or even indirect relevance to the regulation of Risk Activities (or are in any way connected to Risk Areas), are intended here to be referred to as part of the Company’s Model. Corporate Officers and Employees must be periodically updated on the operational procedures adopted for the prevention of Crimes, just as External Collaborators and counterparties of the Company must be made aware of the adoption of the Model in its always updated version whose principles, through specific contractual clauses, must be respected as contractual obligations.

4.2 The system of delegations and powers of attorney

4.2.1 General principles

The organizational structure of Computer Design S.r.l. must have a clear, formalized structure consistent with the division of powers between the various corporate functions.

The attribution of delegations, powers of attorney and powers must always be consistent with the Articles of Association and the exercise of powers cannot disregard the express conferral of them according to the methods and in compliance with the limits provided for by the Articles of Association.

The Company can be committed externally only by subjects provided with a written delegation or power of attorney where the conferred powers are specifically indicated.

In consideration of the above, in Computer Design S.r.l. the following must find precise application

principles of:

  • exact delimitation and segregation of powers, with an absolute prohibition on the attribution, at various levels, of unlimited powers;
  • definition and knowledge of powers and responsibilities within the organization;
  • consistency of authorization and signature powers with the assigned organizational responsibilities.

On the basis of these principles, the system of delegations and powers of attorney must be characterized by elements of “certainty” for the purposes of preventing crimes and allowing the efficient management of corporate activity.

4.2.2 Essential requirements

Each of these acts of delegation or conferral of signature powers provides, for the purposes of effective crime prevention, the following indications:

  • delegating party and source of their power of delegation or power of attorney; or delegated party, with explicit reference to the function attributed to them and the link between the delegations and powers of attorney conferred and the organizational position held by the delegated party; or object, consisting of the list of types of activities and acts for which the delegation/power of attorney is conferred. Such activities and acts are always functional and/or strictly related to the skills and functions of the delegated party. In no case may a generic mandate be conferred to perform any act in the interest of the party conferring the power of attorney;
  • value limits within which the delegate is authorized to exercise the power conferred upon them. This value limit is determined based on the role and position held by the delegate within the corporate organization; or mandatory double signature: no power of attorney may confer a power to bind the company toward third parties through a single signature.

Furthermore, Legislative Decree 81/08 (“Consolidated Law on safety in the workplace”) has incorporated the dominant jurisprudential orientation regarding the effectiveness of the delegation of functions.

Specifically, Art. 16 of the aforementioned Legislative Decree provided:

“1. The delegation of functions by the employer, where not expressly excluded, is permitted with the following limits and conditions:

  1. that it results from a written deed bearing a certain date;
  2. that the delegate possesses all the requirements of professionalism and experience required by the specific nature of the delegated functions;
  3. that it attributes to the delegate all the powers of organization, management, and control required by the specific nature of the delegated functions;
  4. that it attributes to the delegate the spending autonomy necessary for the performance of the delegated functions; e) that the delegation is accepted by the delegate in writing.
  5. Adequate and timely publicity must be given to the delegation referred to in paragraph 1.
  6. The delegation of functions does not exclude the obligation of supervision on the part of the employer regarding the correct fulfillment by the delegate of the transferred functions.”

This obligation is understood to be fulfilled in the event of the adoption and effective implementation of the verification and control model referred to in Article 30, paragraph 4 (as amended by Legislative Decree 106/09, the so-called “Corrective Decree to the Consolidated Law on safety”).

4.2.3 Conferral, management, verification

The attribution of delegations does not constitute a way to attribute exclusive competencies, but rather the solution adopted by the Company to ensure, from the point of view of the organization of the top administrative body at the time of the delegation, the best operational flexibility.

Delegations and powers of attorney are communicated by means of letters of appointment drawn up on the Company’s letterhead, promptly registered, as well as signed “for acceptance” by the recipient.

Powers of attorney with external relevance are then registered at the competent Business Register Office.

Individual updates are implemented immediately in the event of a change in function/role/task of the individual subject.

Delegations, powers of attorney, and any modifications made to them are communicated and made available to the SB, which periodically verifies, with the support of other competent functions, the system of delegations and powers of attorney in force and their consistency with the entire system of organizational communications, recommending any changes in the event that the management power and/or the qualification does not correspond to the powers of representation conferred on the delegate or there are other anomalies.

5 THE SUPERVISORY BODY

5.1 Identification of the Supervisory Body

Pursuant to Art. 6, lett. b) of the Decree, an indispensable condition for the proper functioning of the adopted Model is the attribution to a body of the Entity endowed with autonomous powers of initiative and control of the task of supervising the functioning and observance of the Model, as well as ensuring its updating.

In compliance with the provisions of the Decree, Computer Design S.r.l. has decided to attribute this task to a monocratic body consisting of an external professional.

The SB remains in office for a period of three years from appointment and is renewable.

The provisions on the powers, duties, and responsibilities of the SB are provided within the SB Regulations, established for this purpose.

Each member of the Supervisory Body must not have a professional and personal profile that could prejudice the impartiality of judgment, authority, and ethics of conduct.

The Administrative Body of the Company, therefore, in choosing the member of the Supervisory Body, must evaluate the following elements:

  1. Autonomy and independence

The requirement of autonomy and independence presupposes that the SB reports, in the performance of its functions, to the administrative body. Upon appointment of the SB, its autonomy is ensured, among other things, by the obligation of the annual provision of adequate financial resources which the SB may use for every need necessary for the correct performance of its duties (e.g., specialist consultancy, etc.). Finally, independence presupposes that the Supervisory Body intended as a whole is not in a position, even potential, of conflict of interest with the Company nor in operational activities that would undermine its objectivity of judgment at the time of verifications on compliance with the Model.

  • Honorability and causes of ineligibility

The following cannot be elected members of the Supervisory Body and, if they are, they necessarily and automatically forfeit the office:

o those who are in the conditions provided for by Article 2382 of the Civil Code, namely the incapacitated, interdicted, bankrupt, or those convicted of a penalty that entails interdiction, even temporary, from public offices or the incapacity to exercise managerial offices; o those who have been subjected to prevention measures ordered by the judicial authority pursuant to Legislative Decree September 6, 2011, n. 159 “Code of anti-mafia laws and prevention measures, as well as new provisions regarding anti-mafia documentation”; o those who have been convicted following a sentence even if not yet final or issued pursuant to Art. 444 et seq. of the code of criminal procedure or, even if with a conditionally suspended sentence, saving the effects of rehabilitation:

  • for one of the crimes provided for in Title XI of Book V of the Civil Code (Criminal provisions regarding companies and consortia) and in Royal Decree March 16, 1942, n. 267, and its subsequent amendments or additions

(discipline of bankruptcy, composition with creditors, and compulsory administrative liquidation);

  • to a custodial sentence, of not less than one year, for one of the crimes provided for by the rules governing banking, financial, securities, insurance activities and by the rules regarding markets and securities, payment instruments (among these, by way of example and not exhaustive, the crimes of illegal banking and financial activity referred to in Art. 130 et seq. of the Consolidated Banking Act, the crimes of counterfeiting of coins, spending and introduction into the State, after concert, of counterfeit coins referred to in Art. 453 of the criminal code, the crimes of fraudulent damage to insured goods and fraudulent mutilation of one’s own person referred to in Art. 642 of the criminal code);
  • for a crime against the public administration, or to imprisonment for a time not less than one year for a crime against public trust, against property, against public order, against the public economy or for a crime in tax matters;
  • to imprisonment for a time not less than two years for any non-negligent crime;
  • in any case and regardless of the extent of the penalty for one or more offenses among those strictly provided for by Legislative Decree 231/01; those against whom the accessory administrative sanctions provided for by Art. 187 quater TUF (Legislative Decree n. 58/1998) have been applied.

C) Proven professionalism, specific skills in terms of inspection and consultancy activities

The Supervisory Body must possess technical-professional skills adequate to the functions it is called upon to perform. These characteristics, combined with its independence, guarantee its objectivity of judgment.

It is necessary, therefore, that within the Supervisory Body there are subjects in possession of adequate professionalism in legal matters, control systems, and corporate risk management. The Supervisory Body may also, by making use of external professionals, equip itself with competent resources in specific matters.

In particular, the SB, as a whole, must be in possession of adequate specialist skills such as:

  • knowledge of the organization and the main corporate processes typical of the sector in which the Company operates;
  • legal knowledge such as to allow the identification of cases likely to constitute hypotheses of crime;
  • ability to identify and evaluate the impacts, descending from the reference regulatory context, on the corporate reality;
  • knowledge of the specialist techniques proper to those who carry out “inspection” activities.

The Supervisory Body carries out on a continuous basis the activities necessary for supervision regarding the correct application of the Model with adequate commitment and with the necessary powers of investigation, ensuring its updating.

The SB does not perform operational tasks that could condition and contaminate that overview of corporate activity that is required of it.

In this regard:

  • the activities carried out by the SB cannot be reviewed by any other body or corporate structure; the SB has free access to all functions of Computer Design S.r.l. – without the need for any prior consent – in order to obtain any information or data deemed necessary for the performance of the tasks provided for by the Model;
  • the SB may make use – under its direct supervision and responsibility – of the assistance of all the structures of the

Company or, as indicated above, of external consultants.

The Board of Directors evaluates, before the installation of the SB and, subsequent to such installation, through periodic evaluations, the existence of the mentioned professional and personal requirements in its member.

In this regard, at the time of appointment, adequate information must be provided regarding the presence of the requirements indicated above, also by attaching the curriculum vitae to the relative minutes.

5.2 Function, powers, and tasks of the Supervisory Body

The SB of the Company is entrusted with the task of supervising:

  • on the observance of the prescriptions of the Model by the Recipients;
  • on the suitability and effectiveness of the Model in relation to the structure of the Company and its eventual changes;
  • on the opportunity to update the Model, in relation to changed structural conditions and legislative and regulatory novelties.

On a more operational level, the SB of the Company is entrusted with the task of:

  • verifying the efficiency and effectiveness of the organizational Model adopted pursuant to Legislative Decree n. 231/2001;
  • developing control and monitoring systems aimed at the reasonable prevention of irregularities pursuant to Legislative Decree n. 231/2001;
  • verifying compliance with the standards of behavior and the procedures provided for by the organizational Model and detecting any behavioral deviations, through analysis of information flows and reports to which the managers of the various Corporate Functions at Risk (the “Internal Manager(s)”) are bound; for the performance of the verification and control activities referred to in this point and the previous ones, the SB may make use of the verification activities of the control functions;
  • reporting periodically to the Board of Directors (with a frequency not exceeding one year) about the state of implementation and operation of the Model;
  • promoting and/or developing, in concert with the corporate functions appointed for this purpose, internal information and communication programs, with reference to the Model, the standards of behavior, and the procedures adopted pursuant to Legislative Decree n. 231/2001;
  • promoting and/or developing the organization, in concert with the appointed corporate functions, of training courses and the preparation of information material useful for the communication and dissemination of the ethical principles and standards by which the Company is inspired in the performance of its activities;
  • providing clarifications regarding the meaning and application of the provisions contained in the Model;
  • ensuring the updating of the system for identification, mapping, and classification of Areas at Risk;
  • collecting, processing, and storing information, including reports, relevant to compliance with the Model;
  • periodically carrying out targeted verifications and inspections on certain operations and specific acts, carried out in the Areas at Risk as identified in this Model;
  • reporting to the administrative body, for appropriate measures, those ascertained violations of the

organizational Model that may involve the onset of liability for the Company;

  • formulating proposals to the Board of Directors for any updates and adjustments to the adopted organizational Model and its constituent elements, as a consequence of: – significant violations of the prescriptions of the organizational Model; – significant changes in the internal structure of the Company and/or the methods of carrying out business activities; or changes in the performance of corporate activities; – regulatory changes.
  • introducing, if necessary and without prejudice to the provisions of this document, other operational rules relating, for example, to the frequency of its meetings, any specific tasks entrusted to individual members or the management of information acquired in the exercise of the assignment. All activities carried out by the SB, in the performance of its tasks, are not subject to the review of any other body or structure of the Company. For everything pertaining to the functioning of the SB, reference is made to the Regulations approved by the same body.

5.3 Reporting of the SB to the Corporate Bodies

The Supervisory Body will inform the Board of Directors regarding the activity carried out through:

  • annual reports;
  • whenever the need and/or opportunity arises and is recognized.

The aforementioned reports must contain, in addition to the account of the activity carried out, also the indication of any critical issues encountered and the planned corrective and improvement interventions, as well as their state of implementation. The SB may be convened at any time by the Board of Directors or may in turn make a request in this sense to report on the functioning of the Model.

Written evidence of every meeting of the SB with the Board of Directors must remain kept among the Company’s records.

5.4 Information flows to the Supervisory Body

Art. 6, 2nd paragraph, lett. d) of the Decree requires the provision in the Model of information obligations toward the SB appointed to supervise the functioning and observance of the Model itself.

The obligation of a structured information flow conceived as a tool to guarantee the supervision activity on the effectiveness and efficiency of the Model and for the eventual a posteriori assessment of the causes that made possible the occurrence of the crimes provided for by the Decree.

The effectiveness of the supervision activity is based on a structured system of reports and information coming from all Recipients of the Model, with reference to all acts, behaviors, or events, of which they become aware, that could determine a violation of the Model or that, more generally, are potentially relevant for the purposes of the Decree.

As provided for by the Confindustria Guidelines and by best practices, the information flows toward the Supervisory Body refer to the following categories of information: – ad hoc information flows; – periodic information.

5.4.1 Ad hoc information flows

The ad hoc information flows addressed to the SB by Corporate Officers or by third parties relate to current or potential critical issues and – without prejudice to the provisions of paragraph 5.4.4. on the subject of Whistleblowing – may consist

in:

A. Occasional news in relation to which immediate information to the Supervisory Body is appropriate.

The information obligation concerns:

  • measures and/or news coming from the judicial authority, or from any other authority, from which the performance of investigations/assessments emerges, concerning the Company, even against unknown persons, for the crimes or administrative offenses referred to in the Decree;
  • requests for legal assistance by managers and/or employees in the event of the initiation of judicial proceedings for the crimes provided for by the Decree;
  • news relating to the effective implementation, at all corporate levels, of the disciplinary system provided for in the Model with specific evidence of the disciplinary proceedings activated and any sanctions imposed, or of the measures for filing such proceedings with the relative reasons;
  • reports and accounts from which elements with profiles of criticality with respect to compliance with the rules of the Decree may emerge;
  • the possible existence of conflict of interest situations between one of the Recipients and the Company;
  • any accidents in the workplace, or measures taken by the Judicial Authority or other Authorities regarding the matter of health and safety at work;
  • any incidents or occurrences within the activities of the Production Units that may involve an environmental risk.

B. Information from any source, concerning the possible commission of crimes or in any case violations of the Model.

The information obligation concerns:

  • the commission of crimes or the performance of acts suitable for the realization of the same;
  • the commission of administrative offenses (relevant pursuant to the Decree);
  • behaviors not in line with the Model and with the relative protocols;
  • variations or deficiencies in procedures within Sensitive Areas;
  • failure to comply with corporate procedures within Sensitive Areas;
  • variations or deficiencies in the corporate structure;
  • operations that present risk profiles for the commission of crimes. Reports must be made, in writing, in the following ways:
  • Employees will inform their hierarchical superior who will direct them to the Internal Manager and the latter will proceed to inform the SB without delay. In case of lack of channeling toward the SB (directly by the Internal Manager) or in any case in cases where the Employee is in a situation of psychological discomfort in making the report to the hierarchical superior, the report may be made directly to the SB. The SB may also take into account anonymous reports but only on condition that they are sufficiently detailed and such as to be credible and well-founded in its unquestionable judgment;
  • Consultants, Suppliers, On-call workers, and Partners, as far as their activity carried out toward Computer Design S.r.l. is concerned, make the report directly to the SB. Suitable information of this circumstance is given within specific contractual clauses. The SB evaluates the reports received and determines any initiatives, possibly listening to the author of the report and/or the person responsible for the alleged violation and/or any other subject it deems useful, justifying in writing every conclusion reached. In order to facilitate the flow of reports and information toward the SB, an e-mail box of the Supervisory Body has been established in order to guarantee its autonomy and independence:

In addition to the news indicated above – which concern facts or events of an exceptional nature – relevant information concerning the following activities must also be immediately communicated to the Supervisory Body

recurring:

  • le modifiche che intervengano all’articolazione dei poteri e al sistema delle deleghe (e procure) adottato dalla Società; 
    • eventuali trasferimenti finanziari che non trovino giustificazione in uno specifico contratto stipulato a condizioni di mercato; 
    • la documentazione relativa all’attività di informazione e formazione svolta in attuazione del Modello e alla partecipazione alla medesima da parte del personale (con indicazione di eventuali assenze ingiustificate), all’esito di ogni evento formativo;  
    • any inspection reports on environmental matters by Public Entities and/or control Authorities and any other relevant document on environmental matters; in particular, immediate information must be given to the SB regarding the start of the inspection and the final report issued by the competent authority at the end of the verification;
    • le procedure poste a presidio della salute e sicurezza nei luoghi di lavoro (in occasione della loro emissione), gli aggiornamenti delle stesse, eventuali modifiche che intervengano sulla struttura organizzativa e sui protocolli di Computer Design S.r.l. riguardanti tale materia, nonché i documenti rilevanti ai fini del sistema di gestione della salute e sicurezza sul lavoro (quali ad esempio il Documento di Valutazione dei Rischi (DVR), il Registro degli infortuni, il Piano di emergenza, i verbali relativi alle riunioni periodiche di prevenzione e protezione dai rischi, alle analisi ambientali e ai sopralluoghi negli Uffici); sarà a tal riguardo indicato all’OdV anche il riferimento della funzione aziendale che provvederà alla conservazione di tali atti e/o documenti; 
    • news relating to any accidents occurring in the Company as well as so-called “near misses”, i.e., all those occurrences that, although not having given rise to harmful events for workers, can be considered symptomatic of any weaknesses or gaps in the safety and health system, taking the necessary measures for the purpose of adjusting protocols and procedures.

5.4.2 Periodic information

Internal Managers periodically inform the Supervisory Body according to the information flows and frequency specifically regulated within each Special Part of this Model.

Within each Periodic Report provided for in the individual Special Parts, all ad hoc flows that were the subject of an Evidence Sheet in the reference period are reported.

5.4.3 Reports to the SB by the managers of the Areas at Risk

All Recipients of the Model are required to inform the SB regarding every act, behavior, or event of which they have become aware and which could determine a violation of the Model or, which, more generally, are potentially relevant for the purposes of the Decree.

Operations at risk of commission of one of the Predicate Crimes must be brought to the attention of the SB by the Internal Managers.

Internal Managers within the identified Areas at Risk have the task of having the Evidence Sheets and Reports filled out by their subordinates and transmitting them to the Supervisory Body which takes care of their filing and carries out the relative control of the contents also during the hearings it can plan periodically with the various Internal Managers.

5.4.4 Whistleblowing

Law November 30, 2017, n. 179 introduced the institution of so-called “whistleblowing” into the discipline referred to in Decree 231/2001 (Art. 6, paragraphs 2-bis et seq., Legislative Decree n. 231/2001).

The discipline regarding “whistleblowing” has been subject to substantial changes by Legislative Decree March 10, 2023, n. 24, which introduced significant novelties. The legislation applies to Entities that in the last year have employed an average of at least 50 subordinate workers with permanent or fixed-term employment contracts. Furthermore, to Entities that, even if in the last year they have not reached the average of 50 subordinate workers, fall within the scope of application of the Union acts referred to in parts I.B (financial services, products and markets and prevention of money laundering and terrorist financing) and II (marketing and use of sensitive and dangerous products) of the annex to Legislative Decree n. 24/2023. Finally, to entities that, even if in the last year they have not reached the average of 50 subordinate workers, have adopted a 231 MOG (among which Computer Design S.r.l. is included).

Legislative Decree n. 24/2023 also modified Art. 6 of Legislative Decree n. 231/2001, requiring that “The models referred to in paragraph 1, letter a), provide, pursuant to the legislative decree implementing Directive (EU) 2019/1937 of the European Parliament and of the Council of October 23, 2019, the internal reporting channels, the prohibition of retaliation, and the disciplinary system, adopted pursuant to paragraph 2, letter e)”.

Computer Design S.r.l., in accordance with the provisions of Legislative Decree n. 231/2001, Legislative Decree n. 24/2023, and the Guidelines published by ANAC and Confindustria, has established an internal reporting channel, suitable for guaranteeing the confidentiality required by the legislation on the matter. It has also provided for regulating the mechanism for presenting and managing reports of relevant offenses pursuant to Legislative Decree n. 231/2001 and violations of this Model, the Code of Ethics, and the connected procedures within a specific procedure published on the Company’s website in the specific “Whistleblowing” section, to whose regulation full reference is made.

5.4.5 Tasks of the SB regarding information flows

The SB may carry out further checks on what is transmitted through the information flows of which written evidence will be given.

The SB may in any case ask each Internal Manager to be constantly updated regarding specific topics and/or events based on its own control needs.

5.5 Confidentiality obligations

The member of the Supervisory Body ensures the confidentiality of the information they come into possession of, relating to reports regarding alleged violations of the Model and Legislative Decree 231/01 through the WB Manager. In such circumstances, in fact, the latter must involve the SB in order to coordinate its management activity.

The member of the SB also refrains from using confidential information for purposes other than those referred to in the previous paragraphs and in any case for purposes not conforming to the functions of supervision and investigations following reports, except in the case of express and conscious authorization.

Furthermore, in accordance with the provisions of Legislative Decree 24/2023, Whistleblowing reports are managed in such a way as to guarantee protection against any form of retaliation or discriminatory behavior, direct or indirect, for reasons directly or indirectly linked to the report.

6 INFORMATION AND TRAINING SYSTEM

6.1 The dissemination of the contents of the Model

The Model or an extract of it – updated and integrated – is:

  • made available on the website of Computer Design S.r.l.
  • kept in hard copy at the registered and operational office of Computer Design S.r.l.

The same methods of dissemination and communication are adopted:

  • for new hires; or for new professionals or external consultants.

In the phase of first adoption of the Model, the Board of Directors, in close collaboration with the Supervisory Body, prepared the mandatory training of all recipients of the same through targeted sessions to ensure their adequate knowledge, understanding, and application.

6.2 Training activity

Following adoption, training on the contents and updates of the Model can be implemented by the Supervisory Body, based on an annual training plan relating, among other things, to:

o sessions for new hires (in addition to what is prepared as information on the subject during the hiring phase); o session directed to all recipients for updates; o specific sessions by role, based on sensitive processes and relevant procedures, to be established based on organizational, legislative changes, and risk perception.

Regarding clarifications on the interpretation of the precepts contained in the Model and the procedures, employees can turn to their superiors or to the Supervisory Body.

6.3 Information to External Collaborators

Upon signing the contract with third parties, External Collaborators will be provided with specific information regarding the Model adopted by the Company.

7 DISCIPLINARY SYSTEM

7.1 General principles

The definition of a disciplinary system and sanctions (which must be proportionate to the violation and endowed with deterrent power) applicable in case of violation of the rules referred to in this Model constitutes, pursuant to Art. 6 paragraph 1 of the Decree, an essential requirement of the Model.

The application of the aforementioned sanctioning system presupposes the mere violation of the provisions of the Model: it, therefore, will apply regardless of the initiation, performance, and outcome of the criminal proceedings eventually initiated by the judicial authority in the event that the behavior to be censured also constitutes one of the crimes.

By virtue of the provisions of the legislation on Whistleblowing and with reference to any recipient of the Model, it is specified that among the behaviors liable to sanction must also be considered the violation, in any way, of the measures to protect the whistleblower, as well as the presentation with malice or gross negligence of reports that prove to be unfounded.

7.2 Sanctions for employees

Behaviors held by employees of the Company in violation of the individual behavioral rules deduced in this Model are defined as disciplinary offenses.

With reference to the sanctions that can be imposed on employees, excluding managers, they fall among those provided for by the disciplinary code, in compliance with the procedures provided for by Article 7 of Law May 30, 1970, n. 300 (Workers’ Statute) and any applicable special regulations.

In particular, the sanctions applicable to employees, whether they are middle managers or office workers, in accordance with the type of sanctions provided for by the reference CCNL, are the following:

  1. verbal or written reprimand: applies to the worker who violates the prescriptions provided for by this Model (for example, who does not observe the procedures referred to, fails to communicate the prescribed information to the SB, etc.) or who adopts, in the performance of activities in the Areas at Risk, a behavior not conforming to the prescriptions of the Model itself;
  2. fine not exceeding 3 hours of pay: applies to the worker who repeatedly violates the prescriptions of the Model or who adopts, in the performance of activities in areas at risk, a behavior repeatedly not conforming to the prescriptions of the Model itself, even before said shortcomings have been individually ascertained and contested;
  3. suspension from service and pay for a maximum period of three days (in adherence to the sector CCNL): applies to the worker who, in violating the prescriptions of the Model or adopting in the performance of activities in the Areas at Risk a behavior not conforming to the prescriptions of the Model itself, performs acts contrary to the interest of Computer Design S.r.l.;
  4. dismissal with indemnity in lieu of notice and with severance pay: applies to the worker who adopts, in the performance of activities in the Areas at Risk, a behavior not conforming to the prescriptions of this Model and directed in a clear way to the commission of a Crime sanctioned by the Decree;
  5. dismissal without notice and with severance pay: applies to employees who, in carrying out activities in Risk Areas, adopt behavior clearly in violation of the provisions of this Model and such as to determine the concrete application against the Company of measures provided for by the Decree, or to employees who violate, in any way, the measures protecting the whistleblower, or who make reports with intent or gross negligence that prove to be unfounded. If, within the scope of supervisory activities, violations of the Model and the rules contained therein emerge, the Supervisory Body has the task of activating the relevant company function responsible for sanctioning/disciplinary power, which transmits the results of the investigations carried out to the bodies to which it must report pursuant to and in accordance with the procedures set forth in paragraph 5.3 above.

Such violations and disciplinary proceedings are the subject of the Supervisory Body’s periodic report to the Board of Directors.

8 OTHER PROTECTIVE MEASURES IN CASE OF NON-COMPLIANCE WITH THE MODEL’S PROVISIONS

8.1 Measures Against the Board of Directors

In case of violation of the Model by the Board of Directors, the Supervisory Body shall promptly inform the

other shareholders.

In the event of a conviction, even at first instance, for the offenses provided for by the Decree and subsequent amendments, the

convicted Chairman of the Board of Directors must immediately notify the Supervisory Body.

In any case, the Company reserves the right to seek compensation for any damage, including reputational damage, and/or liability that may arise from conduct in violation of this Model.

8.2 Measures Against External Collaborators

Any conduct by External Collaborators that conflicts with the lines of conduct indicated by this Model and such as to entail the risk of committing an offense sanctioned by the Decree may result, as provided for by specific contractual clauses, in the termination of the contractual relationship, without prejudice to any claim for compensation should such conduct result in concrete damage to the Company, as in the case of application by the court of the measures provided for by the Decree.

9 PERIODIC AUDITS

Pursuant to paragraph 5.3, the Supervisory Body prepares an annual report for the administrative body.

The Supervisory Body may conduct both previously scheduled and unannounced audits and inspections.

In carrying out its activities, the Supervisory Body may avail itself of the support of individual company functions (or external consultants) depending on the operational sector subject to inspection from time to time, drawing on their respective skills and expertise.

During such audits and inspections, the Supervisory Body is granted the broadest powers in order to effectively perform the tasks assigned to it.

With regard to the subject matter of the audits, they may be distinguished as follows:

  1. audits of documents: periodically, a review shall be conducted of the main documents and the most significant contracts concluded by the Company in the Risk Business Areas;
  2. audits of procedures: periodically, the actual functioning of this Model and the procedures referenced therein shall be verified according to the methods established by the Supervisory Body, as well as the degree of awareness of personnel regarding the criminal offenses provided for by the Decree, through sample interviews.

As a result of the audit, a report shall be prepared for submission to the Board of Directors (in conjunction with one of the quarterly reports prepared by the Supervisory Body) highlighting possible deficiencies and suggesting actions to be taken.

Any subsequent modification or integration of the General Part and Special Parts of the Model, signature authorities, the Disciplinary System, and the Supervisory Body Regulations shall be made by decision of the

Board of Directors, after consulting the Supervisory Body

DATE: 07/28/2024

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.