(Incorporatedin the Cayman Islands with limited liability) Stock Code . 01530
CONTENTS
Our 2024: Steady Progress and Continuous Improvement 3
ESG Rating Results 3
ESG Key Performance in 2024 3
Environmental Performance 3
Social Performance 3
Governance Performance 3
ESG Governance 4
Sustainable Development Concept 4
ESG Management Framework 4
Identifying Material Topics 6
Communication with Stakeholders 6
Analysis of Material Topics 7
Corporate Governance 10
Corporate Governance Framework 10
Risk and Compliance Management 12
Compliance Management System 12
Risk Management Mechanism 17
Audit Mechanism 20
Business Ethics and Anti-corruption 22
Business Ethics and Anti-corruption System 22
Supervision and Reporting System 24
Anti-corruption Management for Suppliers 24
Information Security and Privacy Protection 26
Medical Research Ethics 29
Animal Welfare 29
Protection of the Rights and Interests of Subjects 32
Product Responsibility 33
Product Quality Control 33
Quality Control System 33
Quality Inspection 39
Corrective and Preventive Actions 42
Drug Safety Management 43
Pharmacovigilance System 43
Product Recall Mechanism 49
Handling Client Complaints 50
Responsible Marketing 51
Employee Development Responsibility 54
Employees' Rights, Interests and Welfare 54
Labor Management 54
Employee Benefits 56
Communication with Employees 59
Human Capital Development 61
Talent Introduction and Retention 61
Employee Selection and Promotion 63
Talent Training and Support 64
Occupational Health and Safety 69
Safety Production 69
Occupational Health 73
5. Environmental Protection Responsibility 76
5.1 | Environmental Management System | 76 | |
5.2 | Pollutant Reduction | 78 | |
Wastewater Management | 78 | ||
Waste Gas Management | 80 | ||
Solid Waste Management | 82 | ||
5.3 | Climate Change Mitigation and Adaptation | 83 | |
Climate Change Governance | 83 | ||
Risks and Opportunities in Climate Change | 84 | ||
5.4 | Efficient Use of Resources | 86 | |
Energy Management | 86 | ||
Water Resources Management | 89 | ||
6. | Supply | Chain Responsibility | 90 |
6.1 | Resilient Supply Chain | 90 | |
6.2 | Responsible Supply Chain | 94 | |
7. | Social | Contribution Responsibility | 96 |
7.1 | Supporting Healthcare Development | 96 | |
R&D Innovation and IPRs Protection | 96 | ||
Supporting the Development of Biopharmaceutical Industry | 97 | ||
7.2 | Enhancing Accessibility to Medicines and Medical Services | 102 | |
Medical Inclusion | 102 | ||
Supporting Development of Primary Care | 103 | ||
8. | Appendix | 104 | |
8.1 ESG Datasheet and Notes | 104 | ||
Compliance | 104 | ||
Anti-corruption | 106 | ||
Products and Client Service | 106 | ||
Employees Responsibility | 107 | ||
Environmental Responsibility | 109 | ||
Supply Chain Responsibility | 111 | ||
Social Contribution Responsibility | 112 | ||
8.2 Description of Topics of High Materiality | 113 | ||
8.3 Index to the Environmental, Social and Governance Reporting Guide of the Hong Kong Stock Exchange (the version effective since December 31, 2023) | 116 | ||
8.4 About the Report | 118 | ||
Basis of the Report | 118 | ||
Scope of the Report | 118 | ||
Data Description | 118 | ||
Principles of Reporting | 119 | ||
Reporting Responsibility and Assurance | 119 | ||
Our 2024: Steady Progress and Continuous Improvement
ESG Rating Results
As a responsible corporate citizen, 3SBIO (the "Company" or "3SBIO" and collectively referred to as the "Group" with its subsidiaries) makes environmental, social, and governance ("ESG") management a priority of its management agenda and has been working to improve ESG management.
The Group's ESG management work has been recognized by the society and the capital market. In 2024, we continued to receive an A- rating under the evaluation of ESG rating agency SynTao Green Finance, and issues such as business ethics, governance structure, employee development, pollutant emissions, and compliance management are all at the industry-leading level. In addition, for the fifth consecutive year, the Group has maintained its "B" rating (management level) in the questionnaire on climate change by the Carbon Disclosure Project (CDP), a globally renowned non-profit organization. This further proves the Group's long-term and effective management and response strategies on climate change issues.
3Sbio | Climate Change 2023 | 2023 | Submitted | B |
3Sbio | Climate Change 2022 | 2022 | Submitted | B |
3Sbio | Climate Change 2021 | 2021 | Submitted | B |
3Sbio | Climate Change 2020 | 2020 | Submitted | B |
ESG Rating Score by SynTao Green Finance Scores in CDP Climate Change Questionnaire
ESG Key Performance in 2024
Environmental PerformanceNon-hazardous waste intensity 0.45 kg/RMB10,000, down approximately 29.82% year-on-year
Hazardous waste intensity 0.90 kg/RMB10,000, down approximately 31.07% year-on-year
Social PerformanceTraining hours per person averaged approximately 22.64 hours
Governance PerformanceThe percentage of anti-corruption training for Board directors reached 100%
1. ESG Governance
Sustainable Development Concept
Driven by the mission of "making innovative biopharmaceuticals reachable", the Group has been devoted to solving medicine-related problems for patients. Surmounting disease-related challenges one after another, it strives to improve patients' life quality with high-quality medicine and safeguard people's health.
The Group regards compliance operation as the foundation of its Corporate Social Responsibility (CSR), honoring its commitments to stakeholders, including shareholders, clients and consumers, employees, members of the public and community, and the government and regulators. The Group takes active measures to fulfill its CSRs, provides doctors with reliable treatment tools and patients with trustworthy medicines, helps the government reform the medical system, extends care and support to its employees, and brings hope of life to patients and their families in poverty.
Mission
Making innovative biopharmaceuticals reachable
Vision
To be a leading China-based global biopharmaceutical company
Values
Innovation, Quality, Win-win cooperation
Philosophy
Cherish life, Care for life, Create life
Corporate Governance
Product Liability
Employee Development Responsibility
Environmental Protection Responsibility
Supply Chain Responsibility
Social Contribution Responsibility
ESG Management Framework
The Group has set up a top-down ESG management framework. The ESG Committee, with the participation of the Board of Directors of the Company, is responsible for the ESG strategic directions and matters across the Group, makes decisions regarding ESG, and oversees the execution. To ensure precise execution of ESG work, the Group has established an ESG Working Group, responsible for specific daily operations and execution under the guidance of the ESG Committee.
The ESG Committee is committed to continuously optimizing the Group's overall performance in environmental, social, and corporate governance while elevating its ESG performance standards. Its ultimate goal is to establish the Group as an ESG leader in the biopharmaceutical industry. The powers, duties, and operation mechanism of the ESG Committee are specified in the Terms of Reference of Environmental, Social and Governance (ESG) Committee on the Group's official website.
Board of DirectorsESG decision-making layer
ESG Committee ESG Working GroupESG implementation layer
Group functionsManufacturing base departments
Communication Feedback
ESG Management Framework of 3SBIO
Quality Department
EHS
Labor Union
Legal Department
Pharnacovigilance Department
IT Department
Marketing Department
Medical Department
Research & Development Center
Finance Department
Human Resources Department
Procurement Department
Audit Department
Public Relations Department
Risk Compliance Department
StakeholdersThe ESG Committee is responsible for guiding and reviewing the management of the Group's key ESG topics, including medical inclusion and health care accessibility, product quality and safety, human capital development, emissions management, and climate change mitigation and adaptation. The Committee regularly reviews the Group's performance on key ESG topics, reviews the progress in achieving the goals through quarterly reports, interim reports, annual reports, and special reports, provides recommendations on actions to be taken to achieve the goals, and reports regularly to the Board of Directors on the progress of management to ensure that the Board of Directors understands and manages the Group's ESG risks and promote continuous improvement of the Group's ESG management performance.
The Group has set goals for ESG management in respect of the discharge of hazardous wastes, reduction of greenhouse gas emissions, and improvement of energy use efficiency. The target-related functions rely on a professional ESG data management system to collect and compile data indicators related to the ESG targets on a quarterly or semi-annual basis, taking into account the actual management needs, and submit them to the ESG Committee for review.
The Board of Directors performs management oversight responsibilities for important ESG topics and ESG strategies of the Group no less than twice a year, discusses and sets ESG management action goals for the following year at the beginning of each year, and provides advice and necessary support on actions to be taken to achieve management goals. The Group's Board of Directors exercises oversight responsibility for the Group's ESG performance and the remuneration performance of Board directors is linked to key ESG indicators of concern to the Group.
Identifying Material Topics
Communication with Stakeholders
The Group fully recognizes the significance of stakeholders in its long-term development and consistently adheres to the fundamental principle of stakeholder participation in ESG management. The Group maintains efficient and smooth communication channels with stakeholders, respects them, and gets full insights into their views and demands. The Group further responds to reasonable concerns from all stakeholders and incorporates them in the decision-making and execution process.
Stakeholders' Key Concerns and Responses
Key stakeholders Issues of concern Communication and responsesShareholders and investors
Compliance operation
Corporate governance
Business ethics
Product quality and safety
R&D innovation
Information disclosure as a listed company
Shareholders' meetings
Investors' meetings
Employees • Employees' rights, interests, and welfare
Occupational health and safety
Human capital development
Diversification, equality, and inclusiveness
Labor Union and Congress of Employees
Environment, Health and Safety (EHS) management system
Regular training, performance assessment, and job promotion
Customers and Consumers
Product quality and safety
Medical inclusion and health care accessibility
Compliance operation
Responsible marketing
Quality management system
Drug donation activities for public welfare
Standardized drug use training
Client service system
Sales Force effectiveness (SFE) management system
Government and Regulators
Compliance operation
Business ethics
Product quality and safety
Establishment and management of compliance system
Daily policy implementation
Participation in and giving suggestions on policy making
Suppliers • Industry development
Supply chain resilience
Intellectual property rights (IPRs) protection
Industry activities, such as exhibitions and seminars
Coordinated development
Standardized supplier management system
Transparent and fair procurement
Public and Community
Community relations
Emissions management
Resource conservation and utilization
Medical research ethics
Climate change mitigation and adaptation
Various programs for public welfare
Laboratory animal management system
Environmental impact analysis, plan and control
Analysis of Material Topics
The Group regularly identifies and updates ESG material topics as the basis for the Group's ESG management efforts. Based on the Group's vision, values and industry characteristics, the Group benchmarks domestic and international industry policy standards, combines stakeholder communication and expert judgment, and comprehensively identifies material topics and ranks them in terms of their importance to the Group. The Group conducts stakeholder questionnaire research and quantitative communication once every 2 years.
During the reporting period, the Group conducted surveys and communicated with all stakeholders, taking into account the latest policy requirements, material topics of peers, and its work priorities for the year. The Group updated and adjusted material topics per the rigorous Procedure for the Analysis of Material Topics.
Procedure for the Analysis of Material Topics
Company Characteristics Analysis
Identify social responsibility issues relevant to the Group through the Group's vision, values, business research and analysis, and keeping alignment with peer companies.
Policy and Standards Analysis
Identify the current hot topics of social responsibility faced by the Group through benchmarking analysis of domestic and international policies and industry standards.
Communication with Stakeholders
Communicate with internal and external stakeholders of the Group and collect their feedback through questionnaires.
Expert Judgment
Analyze and judge the material topics and determine the importance ranking based on various analysis results.
Verification and Report
The Board of Directors decides the integrity of material topics. Topics of high materiality are highlighted in the ESG reporting.
After the identification and adjustments in the reporting period, the Group has 13 topics of high materiality, including "R&D Innovation", "Product Quality and Safety", "Compliance Operation", "Supply Chain Resilience", "Medical Inclusion and Health Care Accessibility", "Occupational Health and Safety", "Industry Development", "Information Security and Privacy Protection", "Intellectual Property Rights (IPRs) Protection", "Corporate Governance", "Climate Change Mitigation and Adaptation", "Business Ethics", and "Emissions Management".
Matrix of Material Topics
High
Topics of medium materiality Topics of high materiality
R&D innovation
Product safety and quality
Occupational health and safety Compliance operation
Materiality to stakeholdersMedical inclusion and health care accessibility Industry development
Supply chain resilience
Employees' rights, interests, and welfare Information security and
privacy protection
Intellectual property
Emissions management
Climate change mitigation and adaptation Business ethics
Human capital development
Diversification, equality, and inclusiveness
rights (IPRs) protection
Corporate governance
Community relations
Responsible marketing
Medical research ethics
Resource conservation and utilization
Low Materiality to the Company High2. Corporate Governance
Corporate Governance Framework
The Group maintains rigorous corporate governance practices to safeguard shareholders' rights and interests, bolster corporate value, and foster accountability. The Group employs the Corporate Governance Code (the "Code") as set out in Appendix C1 of the Rules Governing the Listing of Securities on the Stock Exchange of Hong Kong Limited as the principles and basis for corporate governance, adhering to all applicable provisions of the Code. The Group will continue to review and supervise the daily corporate governance of the Group to ensure compliance with the provisions of the Code.
According to the Code, the Group has established an effective Board of Directors, tasked with leading and overseeing the Group's operations. The Board of Directors features the following framework and responsibilities:
Framework and Responsibilities of 3SBIO Board
Board of Directors
Key responsibilities: Overall leadership of the Group, overseeing the Group's strategic decisions and monitoring business performance
Audit Committee
Key responsibilities: Review and supervise the Group's financial reporting procedures and internal control systems, review and approve related transactions, and providing opinions to the Board of Directors
Remuneration Committee
Key responsibilities: Review and make recommendations to the Board of Directors regarding compensation plans, bonuses and other compensation terms for Directors and senior executives
Nomination Committee
Key responsibilities: Make recommendations to the Board of Directors regarding the appointment and succession of Directors
Following the Rules Governing the Listing of Securities on the Stock Exchange of Hong Kong Limited, the Group appoints Directors, ensures the proportion of independent non-executive Directors in the composition of the Board of Directors, and assures that Directors possess requisite professional qualifications and industry experience. During the reporting period, a non-executive Director retired and a new non-executive Director was appointed; and one independent non-executive Director retired. The composition of the Board of Directors and Board of Directors meetings are as follows:
Composition of the Board of Directors of 3SBIO
Directors
6
Executive Directors
2
Non-Executive Director
1
Independent Non-Executive Directors
3
Percentage 50%
Director, medical expert
3
Percentage 50%
Director, financial management expert
3
Percentage 50%
Meeting of the Board of Directors of 3SBIO
General Meeting of Shareholders
1
Board Meetings
4
Directors' Committee Meeting
3
The Group recognizes and values the diversity of its Board of Directors, considering it as one of the key elements of its competitive advantages. The Group has formulated the 3SBIO Board Diversity Policy, which stipulates that the Nomination Committee of the Board of Directors reviews the framework, size, and composition of the Board of Directors annually. Taking into account factors such as gender, age, cultural and educational background, professional qualifications, skills, knowledge, industry, and regional experience, the Nomination Committee formulates quantitative targets for implementing this policy and provides effective recommendations for changes to the Board of Directors when appropriate to achieve these targets.
Regarding gender diversity, the Board of Directors includes three female directors, respectively serving as executive Director, non-executive Director and independent non-executive Director, representing 50% of the board membership. The Board will review the implementation and effectiveness of the Board diversity policy annually and evaluate gender diversity in case of changes in Board of Directors to determine whether follow-up planning measures need to be taken.
Risk and Compliance Management
The Group implements a compliance strategy of "from overarching framework to phased deepening and solidification", focusing on five key areas: anti-commercial bribery, anti-monopoly, fiscal and tax compliance, data and information security, and product promotion. Its risk compliance management system covers the entire process of risk identification, assessment, monitoring, and mitigation, employing preventive measures, in-process controls, and post rectification. During the reporting period, the Group was recognized as one of the Top 30 Most Contributing Compliance Teams in the WELEGAL Legal Alliance Compliance Rankings, setting a benchmark for operational compliance management in the pharmaceutical sector. Additionally, Sunshine Guojian was honored as a Shanghai Model Enterprise for Contract Compliance and Creditworthiness, achieving the highest AAA credit rating for contract integrity.
Compliance Management System
The Group has put in place and constantly improved a well-established system for risk identification and compliance management. It has introduced the 3SBIO Compliance Management Regulations, the Compliance Guidelines for Daily Medical Interactive Communication and Standard Operating Procedures for Academic Activities and Conferences, setting out compliance requirements for various sections of business operations. During the reporting period, the Group continued to improve its compliance management regulations for various processes and updated some regulations to offer compliance guidance for business activities.
During the reporting period, the Group renamed the "Compliance Management Committee" to the "Risk and Compliance Management Committee" as the highest management body for risk and compliance management to further improve the compliance governance structure of the Group. The Risk and Compliance Management Committee mainly establishes and promotes the improvement of the compliance management system, determines the organizational framework, and appoints or dismisses responsible persons of the risk and compliance management departments. It is responsible for formulating the Group's risk and compliance management policies and approving the Group's compliance management regulations, annual compliance management work plans, and regular compliance reports.
The Risk and Compliance Management Committee consists of executive members including the Chairman, and the rotating members, the Committee Secretary and base compliance execution supervisor. Manufacturing base heads serve as the base compliance execution supervisors. The Risk Compliance Department, as the executive department of the Group's daily compliance management, is closely connected with the compliance management of each manufacturing base. The general manager of each manufacturing base serves as the base compliance execution supervisor, their main responsibilities include: attending committee meetings to report on compliance management work in their respective bases or respond to inquiries, submitting opinions and suggestions to the committee, and overseeing the implementation of the committee's resolutions within their base. The establishment of this role further strengthens the Group's control over compliance management efforts in each base.
The Group convenes its Risk and Compliance Management Committee at least semi-annually, with extraordinary meetings as needed. During the reporting period, three committee sessions were held to formulate compliance management plans and conduct phased reviews, ensuring sustained compliant operations. These plans focus on key pharmaceutical industry priorities, including academic conferences, sponsorships/donations, and third-party collaborations, with enhanced monitoring and auditing of both employee conduct and external partners. Furthermore, the Group actively participates in industry policy research and analysis to track regulatory trends. It refines internal risk management measures for areas highlighted by regulators and industry guidelines, promptly disseminates compliance updates to staff, and intensifies compliance audits to maintain controllable risk exposure.
Under the guarantee of various internal systems, the Group has always centered on its three lines of defense against compliance risks (including the overall risk management of the Group, information security compliance management and early warning and handling of crisis events) to strengthen and deepen compliance governance.
Compliance Risk Defense System
Defense Line III: Crisis event warning and handling system
Defense Line II: Information security compliance management system
Defense Line I: Group risk compliance management system
Risk Compliance Department and Public Relations Department: Sort out crisis events, reclassify and optimize crisis warning and supervisory routine; group-wide publicity and employee awareness development
Risk Compliance Department and Information Technology Department: Sort out the authority management of the relevant systems of the Group, with the principle of minimization of information and data for compliance management
Risk Compliance Department: Compliance management before, during and after the event, linked to employee performance assessment; inspection of the implementation of the existing compliance system, systematic analysis of high-risk items; compliance culture promotion and employee awareness cultivation
The Group follows the strategy of "front-loaded compliance management" and front-loads compliance management at strategic and operational levels. At the strategic level, the Group integrates compliance risk identification and guidance procedures into the discussion and planning stages of its business strategy. At the operational level, it manages compliance on a project specific basis. During the project initiation stage, it thoroughly analyzes compliance risks, and upon project completion, it undertakes a comprehensive compliance audit covering the entire project lifecycle to ensure full compliance implementation.
Employees play both the roles of compliance management executors and compliance requirements implementers. At the employee management level, in order to further enhance the core of the compliance culture, the Group organizes diversified compliance activities, increases employee compliance participation, and cultivates a compliance atmosphere.
Employee Compliance Education and Management Measures
Description Measure Effect
Compliance training • Board of Directors: Compliance training
during meetings of the Board of Directors;
Entire Group: Annual compliance training;
Marketing center: Responsible marketing training;
Third parties: Conduct a series of compliance training.
During the reporting period, the Group conducted a series of compliance training on topics such as anti-commercial bribery and anti-fraud, responsible marketing, data and information security,
and medical insurance fund maintenance, reaching 33,000 persons or instances.
Compliance leadership program
A compliance leadership program was launched, with the Chairman personally leading management participation, interpreting the connotation of compliance leadership (i.e., the ability to lead the company towards a compliant future), and promoting the improvement of management's compliance management capabilities through a series of activities and training.
Three sessions were conducted during the reporting period, covering 139 persons.
Compliance Ambassador Day
The first Compliance Ambassador Day was established to deepen the concept of Compliance Ambassadors as regional compliance partners, and continuously promote Compliance Ambassadors
to assist regional managers in policy interpretation, compliance consultation and coaching.
During the reporting period, a total of 76 Compliance Ambassadors participated in the Group Compliance Day activities, and the results of the activities will be promoted to various teams for learning. The activities include legal case drills to enhance
the understanding of medical audits; commend outstanding ambassadors to encourage work results; carry out team building and strengthen partnerships.
Description Measure Effect
Compliance culture week, compliance micro classes, compliance stories and other routine compliance promotion
The activities aim to encourage procurement, human resources, finance, information technology, public relations, legal affairs and other departments to participate in compliance promotion activities, regularly carry out compliance culture week, compliance micro classroom and other activities, publish articles such as compliance stories, let employees understand compliance knowledge, and build the compliance culture of the Group.
During the reporting period, a total of 6 compliance activities were carried out and 112 related
promotional papers were released.
Crisis event drills • In order to better cooperate with the
government's medical industry audit, the Group cooperates with a third-party law firm to regularly carry out crisis event
drills, covering key functional departments such as the Group's Risk Compliance Department, Financial Management Department, and Marketing Center.
Relevant departments of the four major bases participated in the drills for the first time to ensure the legality and compliance of the process.
During the reporting period, the drills covered a total of 6,790 persons or instances.
Compliance scorecard • The Group continuously uses the
employee behavior compliance scorecard to conduct compliance quantitative assessments on the Group's marketing personnel, and formulate a comprehensive compliance evaluation model including compliance training, flight inspections, expense compliance monitoring, and project pre-review assessment. The score of the employee behavior compliance scorecard is directly linked to the current salary/bonus assessment;
During the reporting period, the proportion of compliance training in the employee behavior compliance scorecard assessment was increased.
For the assessment of some compliance training, the management assumed joint responsibility for assessment to strengthen the business management's participation in pre-compliance supervision.
The Group drives continuous improvement in employee compliance awareness and behavior through employee compliance performance appraisals, and uses scorecards to provide management with clear compliance management tools to improve management effectiveness.
In recent years, Chinese authorities have promulgated regulations such as the Regulations on Supervision and Administration of Healthcare Insurance Fund Use to rigorously combat fraudulent activities targeting healthcare insurance funds and to strengthen whole-process oversight. In proactive response to national policies and to prevent such violations, the Group conducted publicity campaigns on relevant laws and established mechanisms for investigating/reporting irregularities during the reporting period. The Group organized mandatory training for relevant personnel, and conducted comprehensive audits of insurance-related projects, and required employees/partners to sign compliance pledges, ensuring secure and lawful healthcare fund usage.
Continuously enhancing its compliance system and executing compliance management, the Group actively participates in the development and improvement of the industry's compliance knowledge system. It participated in the solicitation of opinions on the Compliance Guidelines for Pharmaceutical Enterprises to Prevent Commercial Bribery Risks of the State Administration for Market Regulation and the Medical Representative Registration Measures of the National Medical Products Administration. During the reporting period, the Group also co-authored the Hospital-Enterprise Collaboration Compliance Guidelines, providing best practices for institutional compliance and hospital-business interactions. As an expert unit of the Health Development Research Institute, the Group participated in the pilot project of pharmaceutical commercial bribery compliance management and provided compliance advice. The Group also went deep into medical institutions to discuss compliance issues of hospital-business interactions with the Office of Conduct and Discipline Inspection Department, providing practical support for building an enterprise-business relationship with transparent information and risk sharing.
Risk Management Mechanism
Continuously enhancing its awareness and capability in compliance risk management, 3SBIO has established a sound and robust risk management mechanism to fully prevent and respond to compliance risks in various fields. It has developed a closed-loop compliance risk management system in combination with its compliance strategy and industry trends. This system consists of three subsystems: a compliance risk prevention system, a compliance risk monitoring system, and a compliance risk response system.
Compliance Risk Management System
Compliance risk prevention systemCompliance organizational system:
Build a compliance governance structure with cross-departmental shared governance
Basic compliance management: Perform risk identification, formulate compliance policies and control procedures
Compliance management system: Manage the system through the use of employee behavior compliance scorecards, etc.
Standardize and govern the handling and response to breaches and external crises
Timely improve and perfect high-risk or newly discovered risk area
Compliance risk monitoring systemVerify whether the compliance policies and procedures of the Group have been effectively implemented
Identify new or high compliance risks during the monitoring process
To further enhance its compliance management framework, the Group established a Process Project Department during the reporting period. This department is responsible for initiating authorized management of various processes within the Group, reviewing the necessity and compliance of each business process, gradually optimizing these processes, and improving the Group's authorized management and risk prevention capabilities.
To ensure proactive risk management, the Group closely monitors domestic and international developments of laws and regulations. Through this monitoring, the Group identifies emerging risks that may potentially impact its business and formulates preemptive countermeasures accordingly. The Group's identification of emerging risks and countermeasures taken during the reporting period include but are not limited to:
Identification of Emerging Risks and Countermeasures (Partial)
Region Law/Regulation Risk Description Countermeasure
Chinese mainland Shanghai Pharmacovigilance
Management Measures (for Trial Implementation)
The Shanghai Medical Products Administration has imposed strict requirements on the timeframe, scope and content of the reporting of adverse drug reactions.
Failure to report suspected adverse reactions in a timely, accurate and complete manner may expose the Group to legal liability and reputational damage.
The countermeasures are to improve the pharmacovigilance system, optimize the process of monitoring and reporting
of adverse reactions, ensure the timeliness and accuracy of information collection, analysis and reporting, and introduce information technology system to enhance efficiency.
Compliance Guidelines for Pharmaceutical Enterprises to Prevent Commercial Bribery Risks
The Group faces risks such as confusion of duties, behavioral transgressions, transfer of benefits and irregularities in filing in academic visits and exchanges, which may lead to allegations of commercial
bribery or compliance penalties.
The countermeasures are to strictly regulate academic visits and exchanges, to ensure
that the behavior of medical representatives and promoters is in compliance with laws and regulations, and to strengthen internal supervision and training.
On the basis of a thorough understanding of relevant laws and regulations, the Group adheres to the principle that "compliance risks arise from compliance obligations, and compliance obligations stem from business activities" to continuously enhance risk management capabilities. The Group regularly conducts surveys and interviews to assess risk identification capabilities and key control points across business units, sorts out types of business activities, and performs risk evaluations based on legal requirements, industry standards, and internal policies. Through training programs and compliance reviews, the Group educates employees on risk awareness and policy requirements while verifying the compliance of business operations. Bimonthly compliance reviews are conducted to facilitate top-down discussions with business management regarding periodic compliance achievements and challenges, with proactive exploration of improvement measures to gradually strengthen the compliance of business practices.
Furthermore, the Group engages employees in compliance risk identification through questionnaire surveys and interviews to increase their participation in risk awareness initiatives. During the reporting period, the Group completed four effective surveys and updated compliance-related policies based on survey analysis, business operation models, and new industry regulations.
Audit Mechanism
The Group is committed to establishing a long-term and regular audit and supervision mechanism, having formulated the 3SBIO Group System for Internal Audit, 3SBIO Group Work Flow for Internal Audit, and other systems. It completes a full internal audit procedure once every three years to improve internal control system and business management and forestall business risks.
The Group attaches great importance to the role and position of audits in corporate management, emphasizing the independence and significance in the design of the audit organization framework and reporting mechanism. The Group's Audit Department reports directly to the Chairman and is accountable to the Board of Directors. The Group's Audit Department has two separate audit teams. One team is responsible for the internal control audit of Sunshine Guojian, while the other team oversees the internal control audits of the manufacturing bases in Shenyang, Shenzhen, and Hangzhou, as well as other branches and subsidiaries.
Audit Organizational Framework
Level of Board of Directors
Chairman
Group level
Audit Department of the Group
Branch or subsidiary levels
Audit team in Shanghai
Audit team in Shenyang
During the reporting period, the Group conducted business training for the audit team, including risk-oriented auditing, internal control process design, information system security operation and maintenance and hotspots of medical research projects, etc., aiming to enhance the professional competence of the audit staff and strengthen the team's ability to identify and respond to risks in a complex environment. The training was conducted in a combination of online and face-to-face instruction to ensure 100% coverage of all audit staff and further enhance the professional quality of the team.
The Group's Audit Department has fully implemented the establishment of a mechanism for the full integration of internal audit and control, and conducted audit analysis, special audits, audit supervision and audit evaluation based on audit findings.
The Operation Process of the Mechanism Integrating Internal Audit and Control
Audit Analysis
Conduct in-depth analysis and adjust the audit focus in a targeted manner based on any suspicious issues found in the internal audit.
Special Audits
Issue a special audit report according to the findings, taking positive actions to rectify the relevant problems. The HR department is then responsible for dealing with the responsible persons.
Audit Supervision
Supervise relevant departments to make scientific justification for the project and implement rectification based on audit evidence and audit conclusions.
Audit Assessment
Organize relevant departments to conduct timely audit assessments and actively coordinate with various departments, adjusting the direction and objectives of the work in a timely manner based on the assessment conclusions for projects that involve multiple departments and are controversial.
The Group strengthens its ability to operate in compliance through internal and external audits. During the reporting period:
The Group carries out routine monitoring of related processes.
The Group, in addition to its routine audits, has also engaged a third-party professional organization to conduct special audits on the settlement of three construction projects in progress, focusing on project quality, environmental protection, sustainability principles, and anti-corruption efforts. In terms of sustainability principles, the Group pays attention to recycling, the proportion of non-hazardous materials in construction materials, and the procurement of eco-friendly facilities. In terms of anti-corruption, no corrupt behavior has been found within the scope of audits.
The Group continuously conducts internal control audits on the key business cycles of each manufacturing base, covering sales and receivables, procurement and payables, expenses, fund management, financial statements and closure of accounts, long-term assets, research and development, and investments. 3SBIO conducts internal control audits on a three-year basis, while its subsidiary Sunshine Guojian undergoes a full-process audit yearly.
The Group conducts anti-corruption audit investigations involving all financial and physical processes such as procurement, fund management, R&D projects, fixed assets, and human resources, and extends the audit to relevant positions and responsible persons.
The Group engages third-party representatives to provide services for or on behalf of the Company in the normal course of business. During the reporting period, third parties conducted independent external audits of the Group per the provisions of relevant laws and regulations and regulatory requirements and issued relevant reports per the regulatory timelines.
Business Ethics and Anti-corruption
Business Ethics and Anti-corruption System
The Group places great emphasis on business ethics and anti-corruption. The 3SBIO ESG Code of Conduct includes Anti-Corruption and Anti-Bribery Policies that cover all employees, directors, and third-party representatives, explicitly prohibiting the payment of facilitation fees. Meanwhile, the Group actively followed up on the national regulatory policies in the retailing of pharmaceutical products, conducted filing and internal training of pharmaceutical representatives in accordance with the Management Measures for Registration of Medical Representatives (Interim) and updated the compliance management system and procedures of the retailing line in accordance with the Measures for Quality Supervision and Administration of Drug Distribution and Use. During the reporting period, the Group did not engage in any corruption litigation cases against the Company or its employees.
To eliminate corruption and commercial bribery, the Group has established a sound anti-commercial bribery compliance management system that covers the entire process from pre-event, in-event, to post-event control methods.
Anti-commercial Bribery Compliance System
Pre-event
Regular annual compliance training on anti-commercial bribery, anti-corruption compliance for all members of the Group, Board of Directors, and third-party partners
In-event
Focus on academic interactions with drug development personnel and conduct periodic unannounced inspections to verify the authenticity and compliance of academic interactions
Post-event
Perform compliance audit sampling of delivery results through precise data analysis, and verify and identify
anti-bribery compliance risks to ensure effective control of the entire anti-bribery chain
In the area of academic promotion, the Group has established the Norms for Management of Academic Promotion Publicity and Educational Materials of 3SBIO. These norms ensure that promotional and educational materials used by employees in direct or indirect contact with patients, healthcare professionals, and medical institutions adhere to national laws and regulations, drug management regulations, and industry standards. To ensure the implementation of these systems and procedures, the Group has established pre-event training and interpretation to inform employees of the systems and encourage their compliance, in-event audits to confirm the legality and compliance of academic promotion materials used, and post-event compliance monitoring to verify employees' compliance with internal regulations in the use of promotional materials.
The Group executed rigorous pre-event compliance establishment procedures for third-party-funded academic conferences and other donation projects to ensure that all activities undergo strict compliance reviews. The Group intensified the compliance monitoring of the entire process for these projects to ensure that each step, from project establishment to execution, meets the requirements of applicable regulations.
Regarding projects related to Internet platforms, the Group has further enhanced its compliance control over the operations of third-party platforms. Specific measures include but are not limited to thorough reviews of various compliance risks in platforms, such as potential commercial briberies, the legality of product promotion activities, the effectiveness of personal information protection mechanisms, and cybersecurity measures.
Supervision and Reporting System
The Group has put in place a supervising and reporting system. The Group's Risk Compliance Department has put through multiple reporting channels via e-mails and telephones, inviting real-name or anonymous tip-offs about existing or suspected irregularities against systems and regulations from employees, third-party representatives, and business partners. The systems and regulations include: the 3SBIO Group Regulations for the Group's Internal Compliance Investigation, the Code of Conduct and Ethics for Employees, and the Grants, Sponsor and Donate Program Conduct Guidelines.
The Risk Compliance Department will report the tip-offs to the Compliance Management Committee. A case will be filed and investigated in accordance with the 3SBIO Group Regulations for the Group's Internal Compliance Investigation. A detailed reply and confirmed investigation report will be offered within one month to the informer (including anonymous informers), who will be protected with the following measures:
The informers' personal information and the tip-offs will be kept completely confidential. The Group will mete out harsh punishment to those breaking confidentiality rules and hold them accountable per the law.
Those retaliating against informers or related witnesses will face the consequences based on the severity of their behaviors, including but not limited to removal from a post, termination of labor contracts, and transfer to judicial organs for handling.
Anti-corruption Management for Suppliers
Through the 3SBIO Group Supplier Management System and supplier management system, the Group conducts anticorruption management on suppliers from three aspects: management requirements, assessment and supervision, training and motivation.
Clarify management requirements
Assessment and Supervision
Training and Motivation
Conduct risk assessment of suppliers when they are admitted and require them to sign the
Anti-Corruption and Anti-Bribery Commitment in the Code of Ethics and Business Conduct for Suppliers
The Code of Ethics and Business Conduct for Suppliers provides hotlines and e-mails for tip-offs, encouraging suppliers to report any corruption acts that they spot.
If a supplier fails to comply with any term in the statement, the Group may terminate the cooperation with the suppliers
In the day-to-day management process, carry out graded management based on the compliance
risk assessment at the time of admission and the
implementation of the service content
of the supplier
Conduct regular annual spot-check audits of high-value, high-risk suppliers
- Conduct training
at the anti-corruption level to raise awareness of compliance and ethics among suppliers
According to the 3SBIO ESG Code of Conduct, the Group stipulates that suppliers should have an appropriate anti-corruption policy in place, conduct regular audits against the anti-corruption system to ensure the effectiveness of the system, and agree to be audited by the Group or a third party engaged by the Group to verify the supplier's compliance with anti-corruption principles.
The Group developed the Code of Ethics and Business Conduct for Suppliers, which includes anti-corruption and anti-bribery policies and a reporting hotline or email address for reporting on corruption and briberies. The Group requires key suppliers to sign the code at least once a year and regularly monitors their conduct, including on-site inspections. For non-key suppliers, the Group requires them to sign the code during the supplier access stage to ensure that all suppliers are aware of the anticorruption and anti-bribery policies outlined in this code. As of the end of the reporting period, approximately 96.58% of suppliers had signed the Code of Ethics and Business Conduct for Suppliers.
3SBIO has established a supplier compliance management module to strengthen the full compliance supervision of suppliers:
Pre-event training and promotion: Via training and promotion, the Group requires suppliers to commit to providing services per the Group's compliance management principles;
Supplier access review: The Group strictly controls supplier access management and due diligence, focusing on controlling the bribery risks of service suppliers; it also conducts timely compliance audit investigations on abnormal or early warning third parties through dynamic monitoring;
Annual compliance audits: The Group conducts compliance audits covering the entire process of business application, execution and delivery for no less than 33% of regular suppliers every year and all suppliers every three years. The audits include but are not limited to anti-corruption and anti-bribery, advertising and publicity, personal information protection, etc. The Group checks whether the supplier had completed compliance training and signed compliance commitments as required.
During the reporting period, the Group continuously carried out compliance training for all suppliers, requiring them to adhere to industry regulations and 3SBIO's standards. The training aimed to introduce and interpret compliance management requirements such as "anti-corruption and anti-commercial bribery requirements", "conflict of interest behaviors", and "entertainment and prohibited behaviors". The Group also informed suppliers of the channels for reporting violations. In addition to the above, the Group offered tailored compliance training to new suppliers.
Information Security and Privacy Protection
To ensure the information security of the Group and its partners and protect patients' privacy, the Group has put in place the Regulations for Personal Information and Data Safety Management, the Guidelines for Commercial Secrets Management, the Group Information System and Cybersecurity System, and the Clinical Information System Management System to comply with its confidentiality principle regarding non-public information about clients, employees, and agents. During the reporting period, no incidents of violation of laws and regulations related to information security and privacy protection occurred.
The Group has implemented the Trade Secret Management Policy. This policy establishes a classification system for trade secrets and stipulates that the Risk and Compliance Management Committee, Risk Compliance Department, and departments involving trade secrets should cooperate to create a firewall to protect the Group's trade secrets. During the reporting period, the Group formulated the Trade Secrets Management Manual on the basis of this policy in order to refine and implement the management of the Group's trade secrets and to promote the conscious protection of the Group's trade secrets by all employees of the Group.
Trade Secret Management Departments and Their Responsibilities
Department Responsibilities
Risk and Compliance Management Committee
Establishing the Group's trade secret management policy and setting phased management objectives;
Deliberating and approving systems and regulations for trade secret management;
Deliberating and approving reports on trade secret management within the Group;
Evaluating the effectiveness of the Group's trade secret management policy and organizing self-inspections across departments to optimize and enhance the protection of trade secrets.
Risk Compliance Department
Designing the trade secret management framework for the Group;
Summarizing the management rules and measures related to trade secrets of departments and submitting them to the Risk and Compliance Management Committee for approval;
Organizing regular meetings on trade secret management and reporting to the Risk and Compliance Management Committee;
Continuously optimizing and improving the Group's trade secret protection and management.
Departments involving trade secrets
Creating and optimizing own trade secret protection system;
Taking measures to protect trade secrets;
Reporting and coordinating to handle events related to trade secrets.
In addition, the Group formulated the Data Classification and Categorization Process Management System to provide reference standards for the classification, categorization, identification and labeling of data assets. Based on reasonable costs, the subsidiary adopted corresponding protective measures for data assets of different importance levels to prevent them from being destroyed, misused, or accessed without authorization and to ensure their confidentiality, integrity, and availability.
To enhance the development of the information security system and day-to-day management, the Group focused on building basic security capabilities and improving the information security management system. It ensured information security from the perspectives of attack prevention, event detection, defense reinforcement, and security recovery. As at the end of the reporting period, the Group's official website had obtained Grade 2 of the information system security protection grade.
Information Security Protection System
Information Security Management of the Group
Information security management mechanism
Established an Information Security Committee as the supreme governing body for information security management and data security management. The committee is chaired by a board member serving as the Chief Information Security Officer (CISO), who is responsible for making critical decisions regarding data security management and establishing information security classification and grading requirements. Under this committee, an Information Security Management Team has been formed to guide the Cybersecurity Implementation Team in executing various information security measures to safeguard the Group's information security.
Information security emergency plan
Implemented the Emergency Plan for Security Drills for Webpage Tampering Scenarios, Emergency Plan for Encrypted Blackmail Scenarios, Emergency Drill Plan for Phishing Emails, Emergency Drill Plan for Network Attack Scenarios, Emergency Drill Plan for Malicious Program Scenarios, and Emergency Drill Plan for Information Leakage Scenarios.
Information security protection measures
Access security: Sorted out user access and minimized user access configuration;
Baseline security: Developed security baselines for operating systems, middleware, and databases;
Network access control: Sorted out Alibaba Cloud and local security group policies and refined security access control;
Exposure security: Detected the open ports of the Internet and closed unnecessary Internet mapping ports;
Security vulnerabilities: Conducted vulnerability assessments for third-party application systems and server systems, including the evaluation of application systems such as AD account management systems, application systems, and official websites, as well as security vulnerability scanning and rectification work for Alibaba Cloud and local data centers;
Penetration testing: Carried out penetration testing and rectification for application systems.
Information security feedback channel
Established an information security feedback channel, clarified the first contact for information security, and established a 3SBIO information security email group.
Supplier Information Security Protection
Security standards for new system development
Clarified the security standards for new system development of suppliers and provided a detailed security requirement comparison form to standardize the parts related to host security, cybersecurity, and application security in such development.
Privileged account management
Fully launched the privileged account system during the reporting period, which effectively protects the information security of suppliers by pre-setting the scope of use.
Signing of confidentiality agreement
Urged suppliers to fulfill their confidentiality obligations by encouraging them to sign confidentiality agreements for their projects, sorted out their account numbers, and conducted minimal access management to fully safeguard information security and privacy in cooperation with suppliers. During the reporting period, all suppliers signed project confidentiality agreements or confidentiality clauses.
Client
Information Security Protection
Client
information access management
Necessary client information is collected and managed through our Sales Force Effectiveness (SFE) system, whose access is strictly restricted. Users of different hierarchical levels only have limited access to the data in different visual forms. Any information regarding businesses, hospitals, or other clients can only be viewed and used in the system. Downloads of the information in any form are strictly prohibited.
Cultivation of Employee Information Security Awareness
Information security training and inspection
Carried out annual information security awareness training and examinations for all employees of the Group, and regularly tested the sensitivity risks of employees in routine compliance awareness through information technology. During the reporting period, a total of 5,550 employees actively completed business secrets and information security training, including 2,665 employees in the marketing team and 2,885 employees in various manufacturing bases, and the pass rate for the information security exams was essentially 100%;
Carried out online and offline information security publicity every quarter, including employee anti-leakage guides, phishing email trap reminders, terminal security publicity, security system publicity, etc., in the form of corporate WeChat posts, setting up roll-up banners, etc;
Carried out office information security inspections at various manufacturing bases, offices and subsidiaries to improve employees' awareness of routine business behavior compliance and personal information and information security.
Medical Research Ethics
Animal Welfare
The Group has constructed laboratory animal centers in three manufacturing bases, namely Sunshine Guojian, Shenyang Sunshine, and Sciprogen, which involve the use of laboratory animals in pre-clinical pharmacological and pharmacological efficacy studies, pharmacogenetic toxicological studies and animal in vivo testing and abnormal toxicity testing and pyrogen testing during the product release stage. The Group highly values medical research ethics during research and development, continuously strengthens the management of laboratory animals and safeguards their welfare.
Animal Welfare Management System
Animal Welfare System Construction
The Group follows the Laboratory Animal - General Requirements for Animal Experiments (GB/T 35823-2018), Laboratory Animal - Guideline for Ethical Review of Animal Welfare (GB/ T 35892-2018), Laboratory Animal - General Code of Animal Welfare (GB/T42011-2022), and Laboratory Animal - Environment and Housing Facilities (GB14925-2023), and other National Standards.
The Group has developed and improved management systems such as the Animal Welfare and Animal Experimentation Ethics Review System, Laboratory Animal Facility Operation and Management System, Laboratory Animal Welfare Protection System, Management Procedures for Cleaning and Disinfection of Animal Experimentation Center Environment and Animal Cage Equipment, and Standard Operating Procedures for Animal Experimentation Protocol Review, etc., so as to safeguard the environment of animal rearing and to reduce non-necessary injuries in the course of experimentation.
Animal Welfare Management Mechanism
The Group has established a laboratory animal management committee in the animal experimentation center of each manufacturing base, which is responsible for implementing laws and regulations related to laboratory animal work, formulating laboratory animal management systems, inspecting the licensing status of laboratory animal use, strengthening the quality control level of animal experiments, managing animal laboratories and improving the business level of practitioners.
Shenyang Sunshine developed and released the Management Procedures for Technical Service Contracts specifically for laboratory animal suppliers and third-party consigned clinical trials involving laboratory animals. The procedures outline the review process before supplier access, communication and supervision mechanisms during trials, and review and revision steps after trials. It also clarifies the qualification materials that suppliers should provide, including the Animal Use License and the Animal Quality Certificate. In terms of laboratory animal quality and genetic quality control, Shenyang Sunshine evaluates suppliers and screens those that meet the requirements to ensure that the quality of animals provided meets the standard requirements.
