Notwithstanding any other provision of these Compliance Requirements, You shall comply with all applicable laws (including the Bribery Act 2010, the Control of Asbestos Regulations 2012, the Health and Safety at Work etc. Act 1974, the Housing Act 1988, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the Proceeds of Crime Act 2002 and the Immigration Act 2014).

1.        Definitions

Anti-Bribery and Conduct Provisions” means the provisions contained in clause 3 of these Compliance Requirements.

Anti-Human Trafficking and Forced Labour Provisions” means the provisions of clause 6 of these Compliance Requirements.

Compliance Requirements” means these ASK4 Compliance Requirements.

Economic Sanctions” means any trade, economic or financial sanctions or trade embargoes imposed from time to time by any Sanction Authority, including any sanction applied in respect of a particular type of economic activity, including sectoral sanctions.

Governmental Authority” means any supranational, national, federal, state, municipal or local government (including any subdivision, court, administrative agency or commission or other authority of the same) or any quasi-governmental, industry or trade or private entity or person exercising regulatory, quasi-regulatory, taxing, importing or other governmental functions (including securities exchanges and competition authorities), together with any entity that is majority controlled by any of them.

Government Official” means any officer, employee, agent, or representative of any Governmental Authority, any candidate for public office and any official or representative of a political party.

Personnel” means any individual deployed by You to perform the goods or services, including employees, temporary workers and subcontractor staff.

Provider” means the person or entity providing goods or services to ASK4 and includes its affiliates and any subcontractors engaged in connection with those goods or services. In these Compliance Requirements, “You” and “Your” mean the Provider.

Representatives” means Your officers, directors, employees, agents, contractors and subcontractors and any person acting on Your behalf.

Restricted Party” means any person or entity that, at the time of any relevant activity under the agreement between You and ASK4 is:

(A)        appearing on, or owned or controlled by a person appearing on, a sanctions list maintained by a Sanction Authority, whether in relation to all economic or trade activities or only a particular type of economic activity, including a sector activity;

(B)        the government of a Sanctioned Country or a Governmental Authority of a Sanctioned Country; or

(C)        a national or resident of or legal entity formed or existing or operating under the laws of a Sanctioned Country.

Sanction Authority” means any Governmental Authority in any jurisdiction in which You operate or provide services to ASK4, as well as (i) any Governmental Authority in the United States (including the US State Department, the US Department of Commerce and the US Department of the Treasury (and in particular, the Office of Foreign Assets Control)), (ii) the United Nations Security Council, and (iii) the European Union.

Sanction Provisions” means the provisions of clause 4 of these Compliance Requirements.

Sanctioned Country” means any country or territory subject to country-wide Economic Sanctions imposed by a Sanction Authority, including Cuba, Iran, Libya, North Korea, South Sudan, Sudan, Syria, Crimea and any foreign-occupied regions of Ukraine.

For the avoidance of doubt, references in these Compliance Requirements to any applicable law include any amendment, re-enactment or replacement of that law and any substantially similar law in any jurisdiction.

2.          Onboarding Requirements

2.1        You shall at Your own cost comply with the ASK4 Compliance Requirements in respect of onboarding, including the following, as applicable:

2.1.1   completing the prequalification forms;

2.1.2   responding to audit questions;

2.1.3   providing health and safety programme documentation;

2.1.4   providing a bank account verification letter;

2.1.5   providing evidence of company and tax registration;

2.1.6   providing modern slavery statements (or other evidence of compliance);

2.1.7   providing ESG statements; and

2.1.8   providing evidence of insurance at the levels and on the terms required by ASK4.

2.2        You shall use reasonable endeavours to achieve compliance with these Compliance Requirements prior to entering into any agreement between You and ASK4 or shortly thereafter.

2.3        You shall maintain compliance throughout the term of any agreement between You and ASK4 and shall complete any renewal to remain an approved Provider of ASK4.

2.4        Where You provide goods or services that require a Representative to attend a location where the Services are performed, You must maintain current insurance certificates and provide them to ASK4 upon request. Any lapse in cover may result in ASK4 suspending orders or access.

3.           Anti-bribery and Conduct Provisions

3.2        You warrant and undertake that:

3.2.1   neither You nor any of Your Representatives has breached or will breach any applicable anti-bribery laws and regulations, including the United Nations Convention against Corruption, the OECD Convention on Combating Bribery of Foreign Public Officials in International Business Transactions, the Foreign Corrupt Practices Act 1977 and the UK Bribery Act 2010 (the “Anti-Bribery Laws”); and

3.2.2   You and Your Representatives will comply with the Anti-Bribery Laws in carrying on the business and activities contemplated by any agreement between You and ASK4.

3.3        You warrant and undertake that neither You nor any of Your Representatives has or will, directly or indirectly, offer, give, request or receive anything of value to:

3.3.1   influence any acts, decisions, or omissions made by any Government Official or any other person or entity to obtain or retain business or secure an improper business advantage;

3.3.2   induce any person or entity to act improperly in violation of such person’s or entity’s duty;

3.3.3   induce any Government Official or any other person or entity to use influence with a Governmental Authority or any other person or entity to commit an improper act or to obtain or retain business; or

3.3.4   have the purpose or effect of public or commercial bribery, acceptance or acquiescence in extortion, kickbacks or any other unlawful or improper means of obtaining or retaining business.

3.4        You warrant and undertake that:

3.4.1   no ownership interest, direct or indirect, in the Provider is held or controlled by or for the benefit of any Governmental Authority, Government Official or any close family members of a Government Official; and

3.4.2   none of Your Representatives is a Governmental Authority or Government Official.

3.5        You will notify ASK4 promptly if this changes or is likely to change.

4.          Sanctions Provisions       

4.1        You warrant and undertake that You have not:

4.1.1       provided or received goods, services or technology, including credit and financial services or products, to or from any Sanctioned Country or Restricted Party in breach of an Economic Sanction;

4.1.2       imported, exported or facilitated the import or export of any product, service or technology, including credit and financial services and products, from or to any Sanctioned Country or Restricted Party in breach of an Economic Sanction; or

4.1.3       otherwise engaged in any financial or other business transaction with any Sanctioned Country or Restricted Party in breach of an Economic Sanction.

4.2        You undertake that You will not engage in or assist any of the actions listed in this clause 4.

5.            Criminal Finances Act 2017

5.1        ASK4 does not tolerate tax evasion and is committed to ensuring that none of its employees, agents or third party representatives engage in tax evasion.

5.2        You confirm that You have implemented reasonable procedures to prevent tax evasion by Your employees, agents or other third parties.

5.3        You further acknowledge that You understand Your responsibilities under Part 3 of the Criminal Finances Act 2017 (“Part3”) and that You have put in place reasonable prevention procedures (as referred to in Part 3) to ensure that neither Your employees, nor Your agents, nor Your relevant third parties will commit the criminal offences referred to in Part 3.

5.4        On reasonable notice given to You by ASK4, You will provide ASK4 such information and assistance as it may reasonably require enabling it to satisfy itself of Your compliance with Part 3.

6.            Anti-Human Trafficking and Forced Labour Provisions

6.1        You warrant and undertake that neither You, nor any of Your Representatives, has violated or will violate any domestic or international anti-human trafficking or forced labour laws (the “Modern Slavery and ESG Laws”) including, without limitation: (i) the UK Modern Slavery Act 2015; (ii) the California Transparency in Supply Chains Act; (iii) the U.S. Government’s Federal Acquisition Regulation on Ending Trafficking in Persons; (iv) the Forced Labour Convention, 1930 (No.29); (v) the Abolition of Forced Labour Convention, 1957 (No.105); (vi) the Uyghur Forced Labor Prevention Act, or (vii) any applicable anti-human trafficking or labour laws in any jurisdiction in which You conduct business.

6.2        If You become aware of or reasonably suspect a violation of domestic and/or international anti-human trafficking or forced labour laws in any jurisdiction, You shall provide notice to ASK4 promptly after becoming aware of or reasonably suspecting the violation and, in any event, upon any investigation, formal complaint or claim relating to any actual or potential violation of law.  You agree to provide notice to ASK4 within thirty (30) days of such investigation, formal complaint, or claim.

6.2.1        As part of our commitments under the Modern Slavery and ESG Laws, ASK4 may require You to: sign up to Supplier Ethical Data Exchange (“SEDEX”) as a member, complete Your profile to provide a risk assessment score, maintain an active registration, and connect with ASK4 on the SEDEX platform;

6.2.2       ensure that any ethical or social audits undertaken by You, by third parties on Your behalf, or by third parties on Your operations are recorded on the SEDEX platform and made available to ASK4 (each an "Audit"); and

6.2.3       at Your own cost, perform appropriate remedial actions to address any issues or failures identified through an Audit.

7.           Responsible Sourcing of Minerals

7.1        You warrant and undertake that any minerals used in products supplied to ASK4 (including tin, tantalum, tungsten and gold) are sourced responsibly and do not directly or indirectly finance or benefit armed groups or contribute to human rights abuses.

7.2        You warrant and undertake to maintain appropriate supply chain due diligence and traceability measures aligned with the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas and, where applicable, EU Regulation 2017/821.

7.3        You warrant and undertake not to knowingly source minerals from Conflict-Affected and High-Risk Areas (CAHRAs) without appropriate risk assessment, mitigation controls, and documented due diligence, and You shall provide evidence of compliance upon request.

7.4        You warrant and undertake to cascade these Compliance Requirements contractually throughout Your own supply chain, including to sub-tier suppliers and hardware manufacturers.

8.            Equality Act 2010

8.1        You shall comply with ASK4 policies (as notified to You from time to time) relating to the treatment of all residents, prospective residents, and their guests in a fair, professional manner without regard to age, disability, race, nationality, ethnic or national origin, religion, belief or lack of religion/belief, sex, sexual orientation, being pregnant or having a child, gender reassignment, and in accordance with all jurisdictional guidelines, and furthermore, You accept the responsibility to train Your Representatives to comply with those policies.

8.2        If You fail to adhere to ASK4 policies referred to in clause 8.1 and the Equality Act 2010, ASK4 may terminate any agreement between You and ASK4 with immediate effect.

9.           Screening of Workers

9.1        You agree to exercise due diligence in not placing any Personnel or other employees, workers or subcontractors to carry out the Services at ASK4 client sites without a DBS certificate (or local equivalent) which:

9.1.1        is dated not more than twelve (12) months prior to that individual(s) commencing the Services;

9.1.2       has been checked and signed off in accordance with Your internal policies; and

9.1.3       is renewed at least every three (3) years from the date of issue of the previous DBS certificate, to the extent the individual continues to work with You to provide the Services to ASK4.

9.2        You understand that it is Your duty to use responsible hiring practices and acknowledge ASK4 policies regarding the background screening of Your Representatives.

10.        Product Certification and Compliance

10.1     In this clause 10 “Products” means all goods and services supplied to ASK4 by You.

10.2     All Products shall comply with all applicable laws, regulations, and standards governing the sale and distribution of such products in all markets that ASK4 operates (being the United Kingdom, European Union, the United States of America and any country as is notified to You by ASK4). Without limiting the generality of the foregoing, You specifically warrant and undertake that all Products shall be:

10.2.1    duly marked with the CE and UKCA marks;

10.2.2    marked with any marking required (directly or to enable ASK4’s compliance) under the Waste Electrical and Electronic Equipment Regulations 2013, the Waste Electrical and Electronic Equipment Directive (and local implementations thereof) and Regulation (EU) 2023/1542 of the European Parliament and of the Council of 12 July 2023 concerning batteries and waste batteries;

10.2.3    compliant with all applicable safety, health, and environmental protection requirements and compliant with the regulations and standards set by the Federal Communications Commission (FCC) and the Consumer Product Safety Commission (CPSC);

10.2.4    compliant with the Electromagnetic Compatibility Directive (and local implementations thereof), ensuring that such Products do not generate, or are not affected by, electromagnetic disturbance or cause interference with other products or devices.

10.3     You shall ensure that all Products supplied hereunder are fit for purpose and may be legally sold, used, and placed on the market within the territories of the United Kingdom, the European Union and the United States. You shall obtain all approvals and certifications.

10.4     In the event that any Product is found not to comply with the provisions of this clause 10, You shall promptly take all necessary steps at Your own expense to ensure such compliance, including but not limited to, the modification, replacement, or recall of any non-compliant Product.

11.         Information Security Provisions

11.1     Where You supply, provide or make available goods, services or facilities for use in connection with the provision of ASK4’s public electronic communications network or public electronic communications service, You shall support ASK4’s compliance with the Electronic Communications (Security Measures) Regulations 2022 and section 105A(1) of the Communications Act 2003 (and any similar requirements implemented in other countries where ASK4 operates under Directive (EU) 2018/1972 establishing the European Electronic Communications Code). In particular, You shall:

11.1.1    identify security compromise risks in relation to ASK4's network or service that could be caused by Your goods, services, or facilities and notify and cooperate with ASK4 to mitigate those risks at Your own cost;

11.1.2    where You are a network provider with access to ASK4’s network or service or sensitive data, You must take such measures as are appropriate and proportionate for the purposes of (a) identifying the risks of security compromises occurring; (b) reducing the risks of security compromises occurring; and (c) preparing for the occurrence of security compromises;

11.1.3    enable ASK4 to monitor all activities undertaken or arranged by You in relation to its network or service;

11.1.4    cooperate with ASK4 in resolving incidents that cause or contribute to a security compromise in relation to ASK4’s network or service or that increase the risk of such a compromise;

11.1.5    ensure that all network connections and data sharing with ASK4, or arranged by You or any third party on Your behalf, are managed securely; and

11.1.6    have appropriate written plans to manage the termination of, and transition from, contracts with ASK4 while maintaining the security of the network or service.

11.2     Where You handle ASK4 confidential information or personal data (“ASK4 Data”), You shall ensure that You have in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of ASK4 Data and against accidental loss or destruction of, or damage to data, appropriate to the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures (those measures may include, where appropriate, pseudonymising and encrypting ASK4 Data, ensuring confidentiality, integrity, availability and resilience of its systems and services, ensuring that availability of and access to ASK4 Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of Your adopted technical and organisational measures).

11.3     Where You handle personal data in connection with the provision of a public electronic communications service, You shall notify ASK4 of any breach within twenty-four (24) hours. In respect of all other breaches of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data related to Your goods, services or facilities, You shall notify ASK4 within seventy-two (72) hours.

11.4     Where You are developing products, software or services for ASK4 or providing IT support services to ASK4, You shall use reasonable skill and care to ensure that the services are provided and/or developed in a secure manner, this includes, but is not limited to:

11.4.1     implementing secure coding practices to prevent common vulnerabilities such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF);

11.4.2    conducting regular security assessments, including code reviews and vulnerability scans;

11.4.3    ensuring, where appropriate, data encryption both in transit and at rest;

11.4.4    applying necessary patches and updates to address known vulnerabilities promptly; 

11.4.5    ensuring that third-party libraries and components used in the software are regularly updated and free from known vulnerabilities;

11.4.6    conducting rigorous security testing and rectifying any identified security issues promptly;

11.4.7    implementing appropriate access controls to ensure that only authorised Personnel have access to the software and related data; and

11.4.8    not incorporating any open-source software that is licensed under terms that require any distributed software or any derivative work thereof, to be distributed under the same open-source license (including but not limited to, software licensed under the GNU General Public License (GPL), Affero General Public License (AGPL)) (together, “Copyleft Open-Source Software”) into the developed software without the prior written consent of ASK4. You may use open-source software that is not Copyleft Open-Source Software.

12.         Processing of Personal Data

Unless otherwise agreed, where You handle ASK4 personal data as a data processor You shall do so subject to the ASK4 Data Processing (ASK4 Controller) Agreement (https://www.ask4.com/data-processing-agreement-ask4-controller) .

 13.        Health & Safety

13.1     You shall:

13.1.1    have the skills, knowledge, experience and behaviours and, where necessary, the organisational capability, to fulfil the relevant competency requirements applicable to Your role and provide ASK4 with relevant information to enable ASK4 to successfully assess Your compliance with applicable health & safety laws; and

13.1.2    keep and maintain records of mandatory health and safety training and make these available to ASK4 upon request.

13.2     Where You are carrying out “construction works” for the purposes of the Construction (Design and Management) Regulations 2015 or any other locally applicable implementation of European Directive 92/57/EEC (the “CDM Regulations”), You shall:

13.2.1    fulfil the role of the Principal Contractor and/or Principal Designer as required by the CDM Regulations;

13.2.2    provide ASK4 with visibility of working practices at the Site and all documentation produced for the purposes of the CDM Regulations; and

13.2.3    comply with Part 2A of the Building Regulations 2010 and, where carrying out work in connection with a “higher-risk building” (as defined in the Higher-Risk Buildings (Descriptions and Supplementary Provisions) Regulations 2023 (SI 2023/275)), the Building (Higher-Risk Buildings Procedures) (England) Regulations 2023 (SI 2023/909).

13.3     You warrant and undertake that You have not been subject to any serious sanction imposed by any health and safety regulator (including the Building Safety Regulator, the Health and Safety Executive, any successor body or any local or public authority), nor committed any similar misconduct under the Building Regulations 2010.

14.        Additional Provisions

14.1     You warrant and undertake that at all relevant times, there is no allegation, charge, proceedings, investigation or request for information from You or any of Your Representatives by any Governmental Authority regarding any actual or potential violation of these Compliance Requirements. You will immediately inform ASK4 if this changes or is likely to change.

14.2     You warrant and undertake that all payments made in connection with the performance of any agreement between You and ASK4 shall be:

14.2.1     properly and accurately recorded in Your books and records, including amount, purpose and recipient;

14.2.2    maintained in accordance with Your internal procedures along with supporting documentation; and

14.2.3    maintained in accordance with all other applicable laws relating to the preparation and maintenance of books, records or accounts, in each case in a manner that provides sufficient assurance that all Your transactions are recorded in a form that permits compliance with these Compliance Requirements.

14.3     You warrant and undertake that neither You, nor any of Your Representatives, has:

14.3.1    circumvented any internal accounting controls;

14.3.2    falsified any books, records or accounts;

14.3.3    established or maintained any fund or asset that has not been recorded in the books and records of any such entity; or

14.3.4    attempted to coerce or fraudulently influence, an accountant in connection with any audit, review or examination of Your financial statements.

14.4     You undertake that You will not engage in any of the above activities during the term of any agreement between You and ASK4.

14.5     ASK4 and its authorised representatives may audit, examine and make copies of Your books, records, accounts and any other documents that relate to any agreement between ASK4 and You in whatever form they may be kept to verify Your adherence with these Compliance Requirements. You will keep and preserve all such records and accounts throughout the term of any agreement between You and ASK4 and for (i) three (3) years after the expiration or termination of any agreement between You and ASK4 or (ii) the length of time dictated by Your data retention policy (whichever is the greater). You agree to cooperate fully with such audits. The rights contained in this clause 14 must be explicitly included in any subsequent subcontract or agreement formed between You and any of Your Representatives in connection with the performance of any agreement between You and ASK4.

14.6     You shall provide anti-bribery and anti-corruption training to Personnel and to any employees of subcontractors providing services under any agreement between You and ASK4, or, at ASK4’s request, permit ASK4 to provide such training.

14.7     You warrant and undertake that You and Your Representatives maintain, and will continue to maintain, adequate policies, procedures and controls (including a whistle-blowing procedure) to ensure that services provided under any agreement between You and ASK4 comply with these Compliance Requirements. These include policies and procedures relating to (i) accounting and financial transactions, (ii) training of Personnel, and (iii) due diligence on third parties. You shall ensure that Your Representatives are aware of those policies, procedures and controls and shall promptly provide ASK4 with copies or details of them upon written request.

14.8     If You become aware of, or reasonably suspect, any violation of these Compliance Requirements in connection with the performance of any agreement between You and ASK4, You must immediately notify ASK4 in writing. You undertake:

14.8.1    to commence an investigation and take immediate steps to suspend any illegal or unethical activity identified in the notice pending the outcome of the investigation;

14.8.2    to cooperate fully with any ASK4 investigation to determine whether a violation has occurred and, as soon as practicable and in any event within ninety (90) days after notice, to provide a written report to ASK4’s General Counsel describing the method, scope and results of the investigation. The report must include a proposed remedy for any actual or potential violation. You must carry out any further investigation and revise the proposed remedy as necessary to obtain ASK4’s approval within a reasonable period after submitting the report, and You must implement any approved remedy; and

14.8.3    that ASK4 may disclose information relating to a probable violation of the Anti-Bribery Provisions, including the existence and terms of any agreement between You and ASK4, to any relevant Governmental Authority and to any other person ASK4 or its legal counsel considers has a legitimate need to know.

14.9     If ASK4 should believe, acting in good faith, that You or any of Your Representatives has violated any of these Compliance Requirements in any way that may subject ASK4 to liability or to a material loss of reputation, ASK4 will have the unilateral right exercisable immediately upon written notice to You to:

14.9.1    end ASK4's obligation to pay the compensation set forth in any agreement between You and ASK4; and/or

14.9.2    terminate any agreement between You and ASK4 immediately.

 14.10  You shall indemnify ASK4 against all losses and expenses arising out of or in connection with any breach of these Compliance Requirements. This includes any reasonable third-party costs (including reasonable legal and other professional fees and expenses), fines, damages and other out-of-pocket monetary liabilities (including repayment of revenues or profits) suffered or incurred by, or imposed on, ASK4 in connection with the existence, findings or outcome of any complaint, investigation or proceeding relating to Your compliance with these Compliance Requirements. If any provision of this indemnity is void or unenforceable under applicable law, it shall be deemed modified to the extent necessary to make it legal, valid and enforceable. If such modification is not possible, the provision shall be deleted and the remaining provisions shall continue in full force and effect and, where necessary, be interpreted to give effect as closely as possible to the intended purpose of this indemnity.

14.11  ASK4 may conduct ongoing due diligence on You (the scope, method, nature and duration of which shall be at the sole reasonable discretion of ASK4). You agree to cooperate fully with any ongoing due diligence and agree to respond promptly and accurately to any due diligence request for information or documents.

14.12  Unless a separate written agreement expressly signed by ASK4 states otherwise and governs the relevant supplies, all supplies are provided subject to and in accordance with the ASK4 Terms for Purchase (https://www.ask4.com/legal/ask4-terms-of-purchase). Those terms apply to the exclusion of any other terms (including any referred to in quotations, acknowledgements, invoices, delivery notes, catalogues, or terms implied by trade, custom or course of dealing). Where a separate signed agreement states that it covers all supplies between the parties, it will take precedence for its stated scope and duration. Otherwise, the ASK4 Terms for Purchase continue to govern all other orders and apply to all supplies made to ASK4.

14.13  You will provide ASK4 at least annually or upon ASK4's request with a certificate confirming compliance with these Compliance Requirements

Updates

On 16 February 2024, these Compliance Requirements were updated to include a new section 8 (subsequent sections being re-numbered). This new section applies to all supplies of Products (as defined in the update) made on or after that date.

On 20 June 2024, these Compliance Requirements were updated to include a new section 9 (subsequent sections being re-numbered). This new section applies to all supplies of Products made on or after that date.

On 8 July 2024, these Compliance Requirements were updated to include a new section 5.2 (subsequent sections being re-numbered). This new section applies to all Providers.

On 11 November 2024, these Compliance Requirements were updated to include a new section 10 (data processing). This new section applies to all relevant Providers.

On 13 March 2025, these Compliance Requirements were updated to include a new section 11 (health & safety). This new section applies to all relevant Providers.

On 6 October 2025, these Compliance Requirements were updated to include a new section 12.11 (purchasing terms). This new section applies to all Providers.

On 23 February 2026, these Compliance Requirements were updated to include typographical and language corrections, clarifications to defined terms, amendments to certain definitions (including the addition of specified regions to the definition of Sanctioned Country and the additions to Modern Slavery and ESG Laws), and the introduction of a new section 7 (Responsible Sourcing of Minerals) (subsequent sections being re-numbered), together with related compliance provisions. This update applies to all Providers.