← Governance framework
Platform Operations

Audit, Reporting and Transparency Policy

Requirements for external audit, public reporting, governance-effectiveness metrics and whistleblower protection.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-20
Next review
2027-07-19
Owner
CFO
Approver
Audit and Risk Committee
Anchored by content hashissued 2026-07-29
Payload hash
ec0edc0f5f5c7f78cb5cab89cd579f1c9d8de55163a09542136e403b501132a4
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:ec0edc0f5f5c7f78

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • Financial statements and fee accounting
  • IMI methodology and impact reporting
  • Governance and compliance operations

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Annual external financial audit engagement
  • Public Transparency Report at least annually
  • Whistleblower channel operated by the Ethics and Compliance Committee
  • Audit chain and admin provenance surfaced in /admin/provenance

1. External Audit

  • Annual independent audit of financial statements by a qualified Hong Kong firm.
  • Independent review of fee accounting and disbursement.
  • Periodic (at least biennial) third-party review of IMI methodology and TrustMark issuance controls.

2. Public Reporting

  • Annual Transparency Report covering IMI performance, verified action volume, complaints and outcomes, sub-processor changes and material incidents.
  • Quarterly headline metrics published on the public site.
  • Every material policy change announced with an effective date and rationale.

3. Governance Effectiveness Metrics

  • Policy review currency (percentage of policies reviewed within the last 12 months).
  • Time-to-resolve for complaints and disputes.
  • Verification decision quality (overturned appeals rate).
  • Incident MTTA and MTTR.

4. Whistleblower Protection

Confidential intake, protection from retaliation, and independent handling by the Ethics and Compliance Committee, escalating to the Audit and Risk Committee where financial integrity is implicated.

Questions or concerns about this policy? Contact the DPO.

Related policies