R U N I T A S

Loading

Runitas successfully delivers the most appropriate, sector-specific solutions across cloud computing, data storage, database management, backup and archiving, server solutions, virtualization, disaster recovery, and business continuity.

Contact Us

1.1 Purpose
Runitas Bilisim Teknoloji A.S. ("Runitas Bilisim" or "Runitas") is committed to conducting business ethically, transparently, and in compliance with applicable laws, regulations, contractual obligations, and recognized compliance standards.
The purpose of this Third-Party Due Diligence Policy ("Policy") is to establish a documented, risk-based framework for the assessment, onboarding, approval, monitoring, and periodic review of customers and other third parties with whom Runitas establishes or maintains business relationships.
The Policy is designed to identify and appropriately address legal, regulatory, integrity, anti-bribery and anti-corruption, sanctions, conflict-of-interest, government-affiliation, and other relevant compliance risks.

1.2 Scope
This Policy applies, as appropriate, to new and existing third parties with whom Runitas has or intends to establish a business relationship, including:
• customers;
• suppliers and vendors;
• distributors and resellers;
• business partners;
• consultants and advisors;
• agents and representatives;
• subcontractors;
• service providers; and
• other intermediaries or third parties acting for or on behalf of Runitas.
The nature and extent of due diligence shall be proportionate to the nature, value, location, duration, and compliance risk of the relationship.

1.3 General Principles
Runitas applies a risk-based approach to Third-Party Due Diligence ("TPDD"). Third parties shall be assessed to a level appropriate to the risks associated with the proposed relationship.
• due diligence should be completed before establishing a material business relationship, where reasonably practicable;
• information obtained should be sufficient to understand the identity, ownership, activities, and relevant compliance risks of the third party;
• higher-risk relationships shall be subject to enhanced review;
• identified red flags shall be appropriately investigated and resolved before approval;
• due diligence decisions and approvals shall be documented;
• records shall be maintained in accordance with applicable legal, privacy, and record-retention requirements; and
• existing third parties may be reassessed when risk circumstances materially change.

1.4 Roles and Responsibilities
1.4.1 Business Owner
The Runitas employee or department initiating the relationship is responsible for:
• identifying the proposed third party;
• providing the legitimate business rationale for the relationship;
• obtaining necessary onboarding information and documentation;
• informing the Compliance Officer of known compliance concerns; and
• ensuring that required approvals are obtained before engagement.

1.4.2 Compliance Officer
The Compliance Officer is responsible for:
• overseeing the Third-Party Due Diligence framework;
• providing guidance regarding risk classification;
• reviewing higher-risk third parties and identified red flags;
• determining whether enhanced due diligence is required;
• documenting compliance-related decisions where appropriate;
• escalating material concerns to Senior Management; and
• supporting periodic review of the Policy and due diligence process.

1.4.3 Senior Management
Senior Management is responsible for supporting implementation of this Policy, reviewing material compliance concerns when escalated, approving higher-risk relationships where required, and ensuring appropriate resources are available for implementation of the due diligence process.

1.5 Third-Party Onboarding
Before establishing a new material business relationship, Runitas shall obtain and review information appropriate to the nature and risk of the relationship. Depending on the third party and associated risk, onboarding information may include:
• legal name;
• registered address;
• country of incorporation or operation;
• company registration information;
• tax identification information;
• nature of business;
• business purpose and expected relationship with Runitas;
• authorized representatives;
• ownership information;
• beneficial ownership information where appropriate;
• relevant government ownership or affiliations;
• banking or payment information where relevant;
• relevant references or business history; and
• other information considered necessary based on the risk profile.
Information may be obtained from the third party, reliable public sources, official registries, business databases, compliance screening tools, or other legally permissible sources.

1.6 Risk Classification
Third parties shall be assessed using a risk-based approach. Runitas may classify third parties as Low, Medium, or High Risk based on relevant factors, including:
• type of third-party relationship;
• geographic location and countries involved;
• value and nature of the proposed transaction;
• interaction with government entities or public officials;
• government ownership or affiliation;
• use of agents, consultants, intermediaries, or subcontractors;
• ownership structure;
• unusual payment arrangements;
• relevant sanctions exposure;
• integrity or adverse-media concerns;
• previous compliance issues;
• nature of the products or services involved;
• anti-bribery and corruption risk; and
• other relevant circumstances.
Risk classification determines the appropriate level of due diligence and approval.

1.7 Standard Due Diligence
Standard due diligence may include, where relevant and legally permissible:
• verification of company identity and registration;
• review of business activities;
• review of ownership information;
• identification of relevant beneficial owners where appropriate;
• sanctions and restricted-party screening;
• PEP and government-affiliation screening where relevant;
• conflict-of-interest review;
• review of relevant publicly available integrity information;
• review of known litigation, regulatory, or compliance concerns where appropriate; and
• confirmation of the legitimate business rationale for the relationship.
Not every check is required for every third party. The scope of review shall be proportionate to the identified risk.

1.8 Enhanced Due Diligence
Enhanced Due Diligence ("EDD") shall be considered for third parties presenting elevated compliance risk. Circumstances that may require EDD include:
• significant government interaction;
• government ownership or control;
• relevant PEP relationships;
• high-risk jurisdictions;
• complex or unclear ownership structures;
• significant use of intermediaries;
• unusual commissions or payment arrangements;
• material adverse integrity information;
• sanctions-related concerns;
• significant conflicts of interest;
• material red flags identified during standard due diligence; or
• other circumstances determined by the Compliance Officer.
Enhanced review may include additional ownership information, beneficial-owner review, references, supporting documentation, enhanced public-source research, enhanced sanctions/PEP/integrity screening, written compliance representations, additional contractual protections, and Compliance Officer and/or Senior Management approval.

1.9 Sanctions and Restricted-Party Screening
Where appropriate based on the nature and risk of the relationship, Runitas shall screen relevant third parties against applicable sanctions and restricted-party lists. Potential matches shall be reviewed before a business relationship proceeds. No transaction or business relationship shall knowingly be undertaken where prohibited by applicable sanctions or trade restrictions. Potential sanctions concerns shall be escalated to the Compliance Officer.

1.10 Politically Exposed Persons and Government Affiliations
Where relevant to the risk profile of the relationship, Runitas shall assess whether a third party, its relevant owners, directors, representatives, or other relevant persons are Politically Exposed Persons (PEPs), are government officials, are owned or controlled by government entities, have material affiliations with government entities or public officials, or present other government-related compliance risks.
The existence of a PEP or government relationship does not automatically prohibit a business relationship. Such relationships shall be assessed based on the relevant circumstances and may require enhanced due diligence and additional approval.

1.11 Beneficial Ownership
Where appropriate based on risk, Runitas shall take reasonable steps to understand the ownership and control structure of a third party and identify relevant beneficial owners. Complex, unusual, or insufficiently transparent ownership structures may require additional review. Where satisfactory ownership information cannot reasonably be obtained for a higher-risk third party, the matter shall be referred to the Compliance Officer.

1.12 Integrity and Adverse Information Review
Where appropriate, Runitas may review reliable and legally permissible public information relating to bribery or corruption allegations, fraud or financial misconduct, regulatory enforcement, sanctions violations, serious criminal or integrity concerns, conflicts of interest, and other information relevant to the proposed relationship.
Adverse information shall be assessed based on credibility, relevance, seriousness, and recency. The existence of adverse information shall not automatically result in rejection but may require additional investigation, mitigation, or approval.

1.13 Red Flags
Potential compliance red flags may include, but are not limited to:
• refusal to provide reasonable ownership or company information;
• unexplained or unusually complex ownership structures;
• requests for payment to unrelated third parties;
• payments to unusual jurisdictions or bank accounts;
• requests for cash or unusual payment methods;
• unusually high commissions or fees;
• lack of relevant experience or qualifications;
• close relationships with public officials;
• undisclosed conflicts of interest;
• material inconsistencies in information provided;
• relevant sanctions exposure;
• credible allegations of bribery, corruption, fraud, or other serious misconduct; and
• reluctance to accept reasonable compliance-related contractual provisions.
Employees shall not ignore identified red flags.

1.14 Escalation and Resolution of Red Flags
Material red flags shall be documented and referred to the Compliance Officer. The Compliance Officer may request additional information, require additional verification or EDD, require mitigating controls, recommend additional contractual protections, refer the matter to Senior Management, approve the relationship subject to conditions, or recommend that the relationship not proceed.
Material red flags shall be satisfactorily addressed and documented before a higher-risk relationship is approved.

1.15 Approval Workflow
The general Third-Party Due Diligence approval process is:

  1. The Business Owner identifies the proposed third party and business purpose.
  2. Required onboarding information is collected.
  3. The third party is assigned an appropriate risk classification.
  4. Applicable due diligence checks are completed.
  5. Results and identified red flags are documented.
  6. Medium or High Risk matters and material red flags are referred to the Compliance Officer as appropriate.
  7. Enhanced Due Diligence is performed where required.
  8. Compliance Officer and/or Senior Management approval is obtained for higher-risk relationships where required.
  9. Approval and supporting records are documented.
  10. The business relationship may proceed following completion of required reviews and approvals.

1.16 Contractual Compliance Requirements
Where appropriate based on the nature and risk of the relationship, contracts with third parties may include provisions relating to compliance with applicable laws, anti-bribery and anti-corruption, sanctions and trade compliance, conflicts of interest, confidentiality, data protection and information security, audit or information rights, notification of relevant compliance issues, and termination rights for material compliance violations.

1.17 Ongoing Monitoring and Periodic Reassessment
Third-Party Due Diligence is not necessarily limited to initial onboarding. A third party may be reassessed where the business relationship materially changes; ownership or management materially changes; significant new government relationships arise; material adverse information becomes known; sanctions or compliance concerns arise; the scope or value of the relationship significantly increases; or periodic review is considered appropriate based on the risk classification.
Higher-risk third parties may be subject to more frequent reassessment.

1.18 Record Keeping
Runitas shall maintain appropriate documentation relating to Third-Party Due Diligence, including where applicable onboarding forms, corporate registration information, ownership information, risk assessments, screening results, supporting research, identified red flags, explanations or additional documentation obtained, Compliance Officer assessments, management approvals, mitigation measures, contractual compliance provisions, and periodic review records.
Records shall be maintained securely and access shall be restricted to authorized personnel. Records containing personal data shall be processed in accordance with applicable personal data protection and privacy requirements.

1.19 Data Protection and Confidentiality
Information collected during Third-Party Due Diligence shall be limited to information reasonably necessary for legitimate business, compliance, legal, contractual, and risk-management purposes. Personal data shall be processed in accordance with applicable data protection legislation, including applicable requirements under Turkish personal data protection legislation. Due diligence information shall be treated as confidential and accessible only to personnel with a legitimate business need.

1.20 Training and Awareness
Employees involved in sales, procurement, finance, business development, contracting, third-party onboarding, and other relevant functions shall be informed of their responsibilities under this Policy. Relevant employees may receive periodic training regarding third-party compliance risks, red flags, anti-bribery and anti-corruption, sanctions and government-affiliation risks, escalation, and documentation requirements.

1.21 Policy Violations
Failure to comply with this Policy may expose Runitas to legal, regulatory, contractual, financial, or reputational risk. Employees who knowingly fail to follow required due diligence or escalation procedures may be subject to appropriate corrective or disciplinary action in accordance with applicable laws and internal policies.
Runitas reserves the right to decline, suspend, or terminate a third-party relationship where material compliance concerns cannot be satisfactorily resolved.

1.22 Policy Review
This Policy shall be periodically reviewed and updated where appropriate to reflect changes in applicable laws and regulations, changes in Runitas's business activities, identified compliance risks, internal or external review findings, contractual or business-partner requirements, and improvements to Runitas's compliance framework.