Muirhouse Buxton Group · Governance

Building companies that earn trust

Muirhouse Buxton Group invests in and develops businesses that may handle money, personal information, digital identity, and access to essential services.

That responsibility requires more than commercial ambition. It requires clear accountability, disciplined decision-making, strong controls, and a commitment to acting in the long-term interests of customers, partners, employees, regulators, and the communities we serve.

Our governance approach is designed to support responsible growth across the Group and its subsidiaries.

01

Our governance approach

Muirhouse Buxton Group provides strategic oversight, ownership direction, and governance standards for the businesses within the Group.

Each operating company remains responsible for its day-to-day activities, regulatory obligations, customer outcomes, operational controls, and local market relationships.

The Group’s role is to establish the principles, oversight structures, and shared expectations that help each business operate responsibly and consistently.

Our framework is built around five priorities

Clear accountability

Responsibilities should be understood at every level of the organisation.

Boards, executives, employees, contractors, and third-party partners must understand the decisions they are authorised to make, the controls they are expected to follow, and the matters that must be escalated.

Responsible risk management

Risk is considered as part of strategy, product development, investment, partnerships, and daily operations.

We seek to identify financial, operational, regulatory, technology, cybersecurity, data, conduct, and reputational risks before they become customer or business failures.

Strong regulatory discipline

Our businesses are expected to operate in accordance with the laws, regulations, licences, approvals, and supervisory expectations that apply in each market.

Where a product or service requires regulatory approval, it will not be represented as available before the necessary approvals and operational arrangements are in place.

Customer-focused decisions

Governance should lead to better outcomes for customers.

Products must be designed and managed with appropriate consideration for transparency, accessibility, affordability, security, reliability, and the needs of customers who may be financially or digitally underserved.

Long-term stewardship

We aim to build durable companies rather than pursue growth at any cost.

Decisions are assessed against their long-term effect on customers, employees, partners, shareholders, regulators, and the resilience of the wider ecosystem.

02

Group oversight

The Group oversees matters that affect the long-term direction, integrity, and resilience of its portfolio. This includes:

  • Group strategy and capital allocation
  • Investment and acquisition decisions
  • Appointment and oversight of subsidiary leadership
  • Group-wide risk and control expectations
  • Brand and reputation management
  • Intellectual property ownership and protection
  • Cybersecurity and data-governance standards
  • Material partnerships and commercial arrangements
  • Financial reporting and performance oversight
  • Regulatory and compliance governance
  • Business continuity and operational resilience
  • International expansion and market-entry decisions

Oversight arrangements will develop as the Group grows, with governance structures designed to remain proportionate to the size, complexity, and risk profile of each business.

03

Subsidiary governance

Each subsidiary is expected to maintain governance arrangements appropriate to its activities, jurisdiction, and regulatory status. This may include:

  • A formally appointed board or governing body
  • Clearly documented executive responsibilities
  • Risk, compliance, finance, and audit oversight
  • Policies and procedures appropriate to the business
  • Defined approval and escalation authorities
  • Regular management and board reporting
  • Independent assurance where appropriate
  • Regulatory reporting and engagement
  • Monitoring of outsourced and third-party services

For regulated businesses, governance arrangements will be aligned with applicable licensing requirements and supervisory expectations.

04

Risk and compliance

We expect every Group company to take a structured and preventative approach to risk.

Material risks should be identified, assessed, owned, monitored, and reported. Controls should be proportionate to the potential impact on customers, partners, the business, and the financial system.

Key areas of oversight

Financial crime

Businesses handling financial transactions must maintain appropriate controls for customer due diligence, transaction monitoring, sanctions compliance, fraud prevention, anti-money laundering, and counter-terrorist financing.

Consumer protection

Products and communications should be clear, fair, and not misleading.

Customer fees, risks, limitations, eligibility requirements, and important terms should be presented in language customers can reasonably understand.

Data protection and privacy

Personal data should be collected for legitimate purposes, protected throughout its lifecycle, and retained only for as long as required.

Access to personal and commercially sensitive information should be limited, monitored, and reviewed.

Cybersecurity

Security is treated as a core business responsibility.

Our companies are expected to apply appropriate safeguards across systems, applications, infrastructure, suppliers, employees, and operational processes.

Operational resilience

Critical services should be designed to withstand disruption and recover safely.

This includes planning for technology failures, cyber incidents, supplier outages, financial stress, natural disasters, and other events that may affect customers or business continuity.

Third-party risk

Partners and suppliers can introduce significant operational, regulatory, security, and reputational risk.

Material third parties should be assessed before appointment and monitored throughout the relationship.

05

Ethics and conduct

We expect everyone representing Muirhouse Buxton Group or one of its subsidiaries to act lawfully, honestly, and responsibly.

Business decisions should not be influenced by bribery, corruption, undisclosed conflicts of interest, improper payments, or the misuse of confidential information.

Employees, directors, contractors, and relevant partners are expected to

  • Act with integrity
  • Treat customers and colleagues fairly
  • Protect confidential information
  • Disclose potential conflicts of interest
  • Follow applicable laws and internal policies
  • Raise concerns when conduct may be unsafe, unethical, or unlawful
  • Avoid retaliation against anyone who raises a genuine concern

Material concerns should be investigated fairly and escalated to the appropriate level of management or governance.

06

Responsible product development

Products should be governed throughout their lifecycle, from initial concept to launch, operation, review, and retirement.

Before launch, material products should be assessed for

  • Customer need
  • Legal and regulatory requirements
  • Financial and operational risk
  • Security and privacy
  • Accessibility and inclusion
  • Pricing and affordability
  • Customer communications
  • Complaints and support arrangements
  • Fraud and misuse scenarios
  • Operational readiness
  • Third-party dependencies
  • Performance monitoring

Where a product uses automated decision-making, artificial intelligence, or customer data to determine eligibility, pricing, access, or risk, additional oversight should be applied to fairness, explainability, accuracy, privacy, and potential bias.

07

Conflicts of interest

The Group recognises that conflicts may arise between companies, directors, employees, investors, partners, suppliers, and customers.

Actual, potential, or perceived conflicts should be disclosed and managed appropriately. Depending on the circumstances, this may require:

  • Independent review
  • Removal from a decision
  • Additional approvals
  • Changes to responsibilities
  • Disclosure to affected parties
  • Termination of an arrangement where the conflict cannot be managed adequately
08

Transparency and reporting

We aim to communicate accurately about our businesses, their stage of development, their regulatory position, and the services they provide.

We will not knowingly describe a product as operational, licensed, approved, or available where that is not the case.

As the Group develops, reporting may include

  • Business performance
  • Material risks
  • Regulatory developments
  • Customer outcomes
  • Security and operational resilience
  • Sustainability and social impact
  • Significant governance changes

Public reporting will develop in line with the maturity, legal obligations, and scale of the Group.

09

Speak up

Concerns about suspected misconduct, fraud, financial crime, conflicts of interest, data misuse, unsafe practices, or breaches of law or policy should be raised promptly.

Reports should be made in good faith and will be handled as confidentially as reasonably possible.

No person should face retaliation for raising a genuine concern or participating honestly in an investigation.

A formal reporting channel will be published as the Group’s governance and operating functions develop.

10

Governance that evolves with the business

Muirhouse Buxton Group is an early-stage organisation.

Our governance framework will continue to develop as the Group expands, enters regulated activities, appoints additional directors and executives, forms new partnerships, and operates across additional markets.

The standard remains constant: growth must be supported by appropriate oversight, responsible conduct, and decisions that protect the trust placed in our companies.

This statement reflects an early-stage governance framework and will be updated as the Group develops.