4. Governance information

This section covers the effects, risks, opportunities, governance, strategies, actions, and results of Deloitte's identified material governance topics. The ultimate responsibility for the topics in this section of the report rests with our Chief Quality & Risk Officer.

4.1 Quality of services

We are committed to maintaining the highest standards of quality in our audit and advisory service delivery and through our people. Our focus on quality is not merely a policy but a core value that drives our operations and interactions with clients and other stakeholders. This commitment is deeply reflected in our strategy.

Key results

Material impacts, risks and opportunities

In our Double Materiality Assessment as published on pages 93-98, we have identified the following material IROs for Quality:

  1. The opportunity to driving business growth and value by delivering high-quality, purpose-led services, thus enhancing client relationships and our reputation.

  2. The risk of irresponsible use of AI leading to degradation of public trust and financial and reputation damage to the Deloitte brand.

  3. Risk: Failure to deliver high quality services can lead to major economic damage and fines, and ultimately, to a loss of social trust in our firm;

Our related activities contribute to the following SDGs:

Governance

Our ambition is to be the undisputed leader in professional services. The governance on quality is therefore integral to our system of quality control, which incorporates the international quality management standard ISQM1.

The importance of quality is anchored in the role of the Chief Quality and Risk Officer (CQRO), who is a member of our Executive Board. The Quality, Integrity and Risk Committee, as a subcommittee of our Supervisory Board, plays a critical role in overseeing the quality and risk activities initiated by the Executive Board.

The primary responsibility for safeguarding the quality of our service delivery lies with our Engagement Partners, who oversee their teams and the professionals directly involved in the service delivery to clients. Supported by the Business Risk Leaders in our Businesses, the second line of responsibility is established through the CQRO in conjunction with the Risk and Reputation Leader (RRL), who ensure that appropriate risk management frameworks are put in place and are operating effectively.

Additionally, our Internal Audit Function conducts several third-line audits and reviews to provide independent assurance that our quality standards are being upheld. This multi-tiered governance structure promotes a culture of accountability and continuous improvement throughout the organisation.

Our governance is supported by robust policies and procedures to ensure high-quality service delivery and compliance with all applicable legislation. This is all reflected in our common Engagement Approach, which shows the various checks and balances we have in place in our engagement life cycle. This approach ensures that every engagement is subject to rigorous scrutiny, with multiple layers of review and oversight to mitigate risks and uphold our quality standards.

Policies

Our governance is supported by robust policies and procedures to ensure high-quality service delivery and compliance with all applicable legislation:

  • Independence

  • Engagement acceptance and risk classification.

  • Engagement continuance and risk assessment.

  • Quality assurance.

  • Portfolio risk review.

  • Member firm practice reviews.

These policies are implemented at the level of Deloitte Netherlands and are tailored to the specific needs of our businesses. Jointly, they address the material IROs included on page 141.

Engagement Approach

Activities 2025/2026

In 2025/2026, we maintained our broad range of quality initiatives and further enhanced our system of quality control, for example through the updated Risk Mitigation & Assurance Map, implementation of human-in-the-loop principles and enhanced consistency of processes in our Businesses.

The focus on periodic monitoring of the operating effectiveness of our key controls via the enhanced Risk Mitigation and Assurance Map, including enhanced reporting to the Risk & Reputation Executive, increasingly enables us to address operating effectiveness issues in key processes, ensuring the highest standard of quality in our client service delivery.

At Deloitte, we leverage Generative AI (GenAI) to accelerate research, analysis and drafting of documents to improve our service delivery to clients. This is what our clients expect from us. However, human oversight remains essential. The trust our clients place in us depends on careful quality checking and human supervision of any AI-generated content. Therefore, we published detailed human-in-the-loop principles for our professionals to ensure that for deliverables we create for our clients, the human is always in the loop.

After the implementation of the new common storefront last financial year, we now focus on enhancing the consistency of (quality & risk) processes across our Businesses.

Results

Progress on our ongoing focus on quality is measured based on a set of strategic performance indicators, e.g. Regulatory review score, Client satisfaction and Likelihood to recommend. We believe the latter two are reliable measures of our quality from the perspective of our clients.

Table 22: Satisfactory regulatory reviews as a percentage of all regulatory reviews issued and communicated in the reporting year

2025/2026

2024/2025

Satisfactory

100%

100%

Table 23: Client satisfaction score

2025/2026

2024/2025

Client satisfaction

8.4

8.3

Client satisfaction score : based on post‑engagement questionnaires and relationship conversations. For this KPI we used 140 questionnaires (2024/2025: 148) and 76 relationship conversations (2024/2025: 58); questionnaire response rate: 27%.

Table 24: Likelihood to recommend

2025/2026

2024/2025

Likelihood to recommend

8.7

8.6

Likelihood to recommend: based on post‑engagement questionnaires and relationship conversations. For this KPI we used 140 questionnaires (2024/2025: 148) and 63 relationship conversations (2024/2025: 43); questionnaire response rate: 27%.

Effective 2025/2026, we have revised our methodology for the Client Satisfaction and Likelihood to Recommend KPIs. These KPIs are now calculated as the average of all scores and include both engagement reviews and relationship reviews, resulting in a larger sample size and a more robust measure of client satisfaction. Comparative figures for 2024/2025 have been recalculated using the same methodology to ensure comparability (please see Annex 3: Basis of reporting).

­

4.2 Ethics and integrity

By living our shared values and holding one another to account, we make integrity part of our everyday work, not just words on a page. Our ethics team puts these standards into practice with clear guidance, regular training and safe, confidential reporting channels, and by encouraging a speak-up culture where concerns are welcomed, investigated and addressed without fear of retaliation.

Key results

Material impacts, risks and opportunities

In our Double Materiality Assessment as published on pages 93-98, we have identified the following material IROs for Ethics and integrity:

  1. Positive impact on employees of an ethical corporate culture with clear ethics guidance - including anti‑corruption and whistleblowing policies - enhancing our reputation, relationships and value;

  2. Financial and reputational risk of increased exposure to litigation and greenwashing concerns from inadequately disclosing, auditing, assuring or advising on non-financial risks.

Our related activities contribute to the following SDGs:

Governance

We bring diverse specialisms and backgrounds into the ethics team to reflect the changing profile of reporters and those implicated in reports. The team handles and resolves ethical reports, advises on complex cases and acts as a moral compass for anyone who faces an ethical conflict.

The Ethics Leader reports quarterly to the Executive Board and semi-annually to the Supervisory Board. Ethics is also a fixed component of the monthly reporting process, which is overseen by the newly established Reputation & Risk Executive. 

The central Ethics team is supported by an independent investigator, confidential counsellors and Ethics ambassadors in our Businesses. The ethics team also works closely with North–South Europe (NSE) colleagues to ensure consistent implementation of the firm’s global ethics programme across the region. A 24/7 Speak Up portal, operated independently, is also available for confidential reporting.

Deloitte Shared Values

Policies

To promote ethical behaviour and ensure compliance with prevailing anti-corruption regulations, Deloitte maintains the following policies and documents:

Policy

Description

EMEA (NSE) Code of Conduct

The EMEA Code of Conduct (previously NSE) sets out the values and ethical principles that guide how we serve clients, run our businesses, work together and contribute to society. The Code helps our professionals gain a deeper understanding of how ethics should drive individual behaviours and support their personal brand.

Ethics policy (DPM 2060)

The Ethics policy (DPM 2060) sets forth policies and guidance on developing, implementing and maintaining the ethics programme.

Non-retaliation policy (DPM 2061)

Our non-retaliation policy (DPM 2061) ensures that anyone who, in good faith, raises an ethics, compliance or related concern, or who assists in an investigation, is protected from retaliation.

Anti-Discrimination and Anti-Harassment policy (DPM 2062)

The Anti-Discrimination and Anti-Harassment policy (DPM 2062) underscores our commitment to providing a respectful and inclusive working environment. We aim to create a space that is free from harassment, sexual harassment and discrimination, ensuring that each person is treated with courtesy, dignity and respect, and that there are equal opportunities for all to succeed.

Familial and Personal Relationships policy (DPM 2063)

The Familial and Personal Relationships policy (DPM 2063) requires disclosure of close personal relationships within Deloitte to prevent conflicts of interest and protect confidentiality, morale and our culture of inclusiveness.

Social Media policy

The NL Social Media policy offers guidelines to help us continue to make responsible use of social media.

Anti-Corruption & Bribery policy (DPM 1550)

The Anti-Corruption & Bribery policy (DPM 1550) sets out principles for conducting business activities in accordance with the stance against corruption and bribery in any form to contribute to good governance, economic development and the improvement of social welfare wherever we do business. The policy should be read in conjunction with DPM 1551 (US FCPA), DPM 1552 (The UK Bribery Act), DPM 1560 (Business Relations), the NSE Entertainment & Gifts Policy and the FAQs.

AML policy (DPM    1549)

The AML policy (DPM 1549) sets out the minimum expectations for AML compliance and follows principles to stand firmly against money laundering, in order to comply with laws and regulations and to contribute to the principles above. Deloitte does not engage in any form of money laundering, nor do we facilitate or otherwise cause others to do so. This policy should be read in conjunction with Deloitte’s Netherlands Supplementary Policy on NSE Anti-Money Laundering Policy containing local (Wwft) obligations and requirements.

Trade Controls policy (DPM 1548)

The Trade Controls policy (DPM 1548) is committed to compliance with all applicable local Trade Control laws as well as the US, UN, EU and UK Trade Control regulations. This includes a commitment to conduct business in a manner that complies with applicable Economic Sanctions and Export Control laws. The policy aligns with Deloitte’s values, purpose and public interest commitment and should be read in conjunction with the FAQs.

People who want to report an ethics incidents have various channels to their disposal (line manager, a mentor, a trusted partner, the Ethics Officer or the Speak Up Line which is hosted independently and externally. A report can be made anonymously if desired. Throughout the process, the reporter is protected by our Non-retaliation policy. We are committed to ensuring that their concerns will be confidential, taken seriously and investigated.

Activities in 2025/2026

Ethics survey

In September 2025, we provided our practitioners the opportunity to complete both the Ethics survey and the Engage4Change (our Talent survey) in a combined questionnaire, which raised participation from around 30% to 50%, giving us a broader and more representative view.

Key outcomes

  • 95% believe Deloitte is an ethical place to work.

  • Reporting and accountability improving: less observed misconduct, more reporting and addressing, and fewer compromises of ethical standards; however, a small drop in those who feel they can report without fear of retaliation.

  • Ethical leadership requires improvement: fewer indicate their Partner or Supervisor discussed the importance of ethics and integrity.

  • Trust and awareness trending downward, though slightly more feel ready to respond when confronted with misconduct.

This feedback highlights the need for us to continue refining our efforts and reinforces our dedication to fostering an ethical workplace, ensuring that everyone feels empowered to speak up. Ethics case trends

For the first time in several years, we saw a decrease in the number of reported cases, notably with fewer reports being made to confidential counsellors. We do not interpret the lower count as evidence that there are fewer incidents. Although reported case numbers are lower, indicators such as an increase in anonymous reports, a modest rise in survey concern about retaliation and recurring themes raised during investigations suggest some colleagues may feel less comfortable coming forward. Current economic pressures may be amplifying this dynamic, with a growing perception that speaking up could have negative consequences. We view this as an opportunity to strengthen protections, improve communication about safeguards and increase visible leadership support for speaking up.

Ethics Risk Assessment

In January 2026, the annual ethics risk assessment for the Netherlands was conducted as an integral part of the NSE Risk Assessment. This process involved collaborative discussions with our Business Risk Leaders, the Ethics Leader and the Risk and Reputation Leader. We evaluated 11 ethical risks. The Ethics Risk Assessment identified an overall ‘medium risk’ profile for the Netherlands. Specifically, nine risk scenarios were categorized as ‘medium’ risk and two scenarios as ‘low/medium’ risks.

Among the nine medium risks, we remain attentive to several areas: underreporting and pressure to compromise standards; inconsistent tone and leadership role modelling; erosion of shared values and inclusiveness; misuse of AI; internal polarisation and perceived unsafety; and increased regulatory or media pressure.

To validate and surface additional or emerging issues, we ran two focus groups - a cross-business pre-manager session and a manager-up session - and held open discussions about current and future ethical risks. These sessions generated valuable insights and produced concrete areas for attention.

Our Ethics Learning activities

To reinforce role‑model behaviour and ethical leadership, we delivered classroom‑based training programmes for our leaders, training a total of 53 partners and directors.

To embed ethics from day one, we delivered 23 Ethics & Integrity onboarding sessions for new practitioners across all five businesses in 2025/2026. Our global award-winning Dilemma Season 2 e-learning, launched in October 2025, uses real-life scenarios to sharpen ethical judgement. It has been completed successfully by 98.3% of our partners and professionals, and was also delivered face-to-face in Amsterdam, Utrecht and Rotterdam.

Results

Table 25: Incidents: number of reported occurrence

2025/2026

2024/2025

2023/2024

Professional conduct

34

16

14

Fair treatment or inequality

80

97

105

Discrimination

9

12

5

Harassment and sexual harassment

8

26

24

Corruption

0

0

0

Other or inquiry

16

45

33

In 2025/2026, the total number of ethics cases declined from 196 to 147 — a drop of 25%. The overall decrease masks and interesting shift in how people are reporting concerns. The most striking change is in reports filed with our confidential counsellors, which dropped sharply from 88 to 40 (down 55%). At the same time, direct reports to our Ethics team rose from 67 to 77 (up 15%). These opposite trends suggest the story is more complex than a simple overall decline in reports filed.

 We believe several factors are at play. These include:

  • Fewer complex cases: 2024/2025 saw several difficult cases that needed extensive support from our confidential advisers. 2025/2026 did not have comparable cases, which explains much of the drop in reports to counsellors;

  • Changing reporting preferences: The increase in direct reports to the Ethics team suggests people may be choosing to report concerns differently; 

  • Not primarily about fear: While fear of retaliation is always a concern, the data does not strongly support this as the main driver. If people were mainly worried about speaking up, we'd expect to see more reports to confidential counsellors or anonymous channels, which was not the case.

An effective anti-corruption stance is central to the integrity, sustainability and commercial success of Deloitte. Therefore, we are committed to staying compliant with all relevant laws and regulations and to aligning with our values, purpose and public interest commitment.

Furthermore we have a robust anti-corruption framework in place to protect the firm from legal, financial and reputational harm, and to underpin the public interest function that the profession serves.

This framework consists of seven different elements . These elements include:

  • Policies, procedures and guidelines;

  • Training & communication;

  • Risk assessment, testing & monitoring;

  • Third-party due diligence;

  • Consultation and incident response;

  • Investigations, for which we have the ethics reporting channels in place.

It is evident that we ensure rigorous compliance with both local and international regulations, including the Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act. We have also woven anti-corruption measures into the very fabric of our operations, from client onboarding to ongoing project execution.

Financial Crime

In the past year, we have continued to strengthen our commitment to combat financial crime in general, focusing on the three financial crime pillars: anti-corruption, trade controls and anti-money laundering.

Alignment and effective collaboration across the three financial crime pillars are essential to manage risks coherently and efficiently. This cross-pillar work drives consistent decision-making and strengthens reporting to regulators. Ultimately, integrated collaboration protects reputation, supports regulatory compliance and delivers better outcomes for clients and stakeholders.

Every two years, the mandatory Financial Crime e-learning is launched to remind our partners and employees of expectations and obligations related to anti-corruption and financial crime compliance, to help them identify potential financial crime risks and how to address these risks. Additionally, all new joiners starting during the year receive an invitation to the mandatory Financial Crime e-learning course at the time they commence their employment. By the end of 2025/2026, the completion rate of this Financial Crime e-learning training was 99.2%. Compliance by Supervisory Board, Executive Board and Executive Committee members with the training requirement amounted to 100%.

4.3 Data security and privacy

Key results

Material impacts, risks and opportunities

Data security and privacy are critical in a rapidly changing world because they protect sensitive information, preserve stakeholder trust, and ensure operational resilience against evolving cyber threats. Embedding robust security and privacy practices enables us to meet regulatory obligations, support safe innovation, and safeguard reputation and long-term value. In our Double Materiality Assessment as published on pages 93-98, we have identified the following material IRO for Data Security and Privacy:

  1. Legal, reputational, and financial risk of non-compliance with privacy and data protection expectations due to inadequate data protection measures

Our related activities contribute to the following SDGs:

Governance

The Confidentiality, Privacy & Security Office is part of the RRL Office and is active in the following areas:

Area

Description

Confidentiality

Data breaches are reported to the Confidentiality team. If personal data is involved, the Privacy team is also added. New applications are assessed on confidentiality aspects of both client data and Deloitte data. We create awareness and training on handling confidential data.

Privacy

Vendor Impact Assessments (PIA & DPIA) are done for new applications that process personal data. This includes local applications and also globally implemented applications. We maintain a network of Privacy Champions who are the first line of defence in the organisation for privacy matters in the business. We create awareness and training in processing personal data.

Security

Travel Security: Travel to high-risk countries requires approval from the CPS team. Assistance is given to people that have an emergency in another country. Business Continuity Management (BCM) is coordinated by the CPS team. Physical security policies are maintained.

AI

New AI solutions are being assessed to ensure we adhere to the EU AI Act. We implement and maintain the AI responsible framework. We create awareness and training on AI fluency and responsible use of AI systems.

Our activities on Data security and privacy are subject to a rotating internal audit programme as part of the Deloitte Global Member Firm standards.

Deloitte Netherlands is ISO/IEC 22301 certified (Security & Resilience). This is the international standard for Business Continuity Management (BCM). In addition, Deloitte Netherlands is ISO/IEC 27001 certified (information security), which covers large areas of Confidentiality and Privacy.

Policies

To achieve a high level of data security and compliance with prevailing privacy legislation, we  maintains the following policies that mitigate the material risk above:

  • Deloitte Talent privacy policy;

  • Deloitte Privacy statement for business relations;

  • NL - Integrated security policy and generic implementing rules;

  • Acceptable use policy, Compliance and auditing policy, Security policy, Data classification & handling policy, Data privacy policy, Logical access security policy, Systems management policy, Personnel security policy, Physical security policy, Incident and crisis management policy, Business continuity management policy, Travel risk management policy.

Activities in 2025/2026

As an emerging technology trend, the world fully acknowledges the potential of GenAI such as OpenAI’s ChatGPT. This global development has a large impact on our way of working and service delivery. Throughout the reporting year, we contributed to Deloitte’s trustworthy AI framework, including company wide AI learnings and Human in the Loop guidance.

With continuous development and improvement mindset, the RRL Confidentiality, Privacy & Security Office maintains the privacy policy, Record of Processing Activities (RoPA) and increases the robustness of the Privacy Champions framework and data protection.

We are fine-tuning our controls for DORA (Digital Operational Resilience) and the upcoming NIS2 (Incident Reporting) directives.

Managing data security and privacy requires a continuous effort and alertness. Going forward, we will continue to uphold our relevant policies, maintain our level of activity and do whatever is needed to keep our systems and personal data trustworthy and secure.

Results

Through continued monitoring and controls, in 2025/2026 61 incidents were internally reported, of which 31 concerned personal data incidents. We received zero complaints regarding breaches of client privacy or loss of customer data and did not receive any complaints regarding personal data from vendors who are engaged by Deloitte. We notified two personal data breaches to the supervisory authority in conformity with the legal requirements of the ‘Wet meldplicht datalekken’ (Law on mandatory reporting of data leaks).

Although our efforts are aimed at reducing the number of data and privacy incidents to an absolute minimum, this topic is not suitable for defining quantitative targets. We continually evaluate and adapt our approach based on our ISO certification, compliance assessments and outcome of our investigations into incidents.