Governance, Risk & Compliance

Approved by: Ian Chadwick — 20/01/2026

Our Governance Approach

WBP Equip is committed to maintaining high standards of governance, accountability, and responsible innovation across all aspects of our operations.

As an early-stage technology and product development company operating within the built environment and wellbeing ecosystem, we recognise that trust, transparency, and proportionate oversight are essential — both in how we develop our technology and in how we conduct our business.

This Governance, Risk and Compliance Statement provides a high-level overview of our governance framework and the principles that guide how we manage risk, protect data, use technology responsibly, and engage with third parties.

Board Oversight and Accountability

The Board of WBP Equip has overall responsibility for governance and strategic direction. The Board sets the tone for ethical conduct, approves policies and statements, and oversees the management of risk across the business.

As the company grows, governance structures will be developed further to reflect increased complexity and operational activity.

Risk Management and Control

We take a proportionate, risk-based approach to governance. Key areas of focus include:

  • Technology and AI risk — ensuring responsible use, transparency, and human oversight;
  • Data protection and privacy — safeguarding personal data in line with UK GDPR;
  • Information security — protecting the confidentiality, integrity, and availability of information assets;
  • Legal and regulatory compliance — meeting applicable legal obligations;
  • Supplier and third-party risk — ensuring appropriate oversight of external partners; and
  • Ethical considerations — maintaining fairness, integrity, and accountability in all activities.

Responsible Use of Technology and AI

As a company developing technology that incorporates AI-driven capabilities, we are committed to using and deploying these responsibly. Our approach includes maintaining human oversight, ensuring transparency, designing for fairness, and embedding accountability.

Further detail is set out in our AI Governance and Oversight Policy Statement.

Data Protection and Information Governance

We are committed to processing personal data lawfully, fairly, and transparently, in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.

Our Data Protection and Privacy Statement and our Privacy Policy set out how we manage personal data across our operations.

Information Security

We apply proportionate security measures to protect information and systems. This includes access management, secure system design and development, monitoring, and incident response.

Our Information Security Overview sets out our approach at a summary level.

Independent Assurance and Advisory Support

Where appropriate, we engage independent, third-party expertise to support technical validation, assurance, and advisory functions.

Our Supplier and Independent Assurance Statement sets out how we govern these relationships.

Transparency and Review

We are committed to being transparent about our governance arrangements and to reviewing our policies and statements regularly. This statement will be reviewed at least annually, or earlier if there is a material change in our operations or regulatory environment.