Strong governance and ethical excellence underpin stc's sustainability strategy and are central to how the company creates long-term value for stakeholders.
stc group's governance framework promotes responsibility, transparency and compliance through clear Board charters, strengthened policies and rigorous checks and balances. Key pillars of stc's approach include the following:
Strengthening transparency and regulatory compliance
Protecting and promoting human rights
Safeguarding privacy, data security and online safety
Ensuring an ethical, responsible supply chain and procurement management
Corporate governance
stc group's Board of Directors demonstrates a strong commitment to embedding best-in-class corporate governance practices through a structured and integrated framework that clearly defines the roles, responsibilities and authorities of both the Board and Executive Management. This framework forms the foundation for effective oversight, enabling disciplined decision-making, strengthening compliance and ensuring the consistent application of robust risk management practices across the group.
Board diversity in 2025
11
Board members
18%
female participation on the Board
4
year average tenure
Percentage of Board seats occupied by independent directors
55%
2023: 36% | 2024: 55%
Executive members of the Board of Directors
0
2023: 0 | 2024: 0
Non-executive members of the Board of Directors
11
2023: 11 | 2024: 11
Independent members of the Board of Directors
6
2023: 4 | 2024: 6
Non-independent members of the Board of Directors
5
2023: 7 | 2024: 5
stc group’s 11-member Board of Directors combines diverse skills and experience for effective governance and oversight. The Board includes leaders from various backgrounds.
Board members' skills
90%
Economic/ finance
90%
Risk
90%
Innovation / technology / IT
20%
Engineering
50%
Others
Board members' experience
90%
Industry
60%
Banking
20%
Academic
70%
ESG
90%
Public administration
60%
Marketing
Performance evaluation and remuneration
The Board Nomination and Remuneration Committee ensures a diverse Board with expertise in technology and telecommunications and conducts annual evaluations of Board performance. The updated policy includes clawback and malus clauses for ethical practices, while the Executive Long-term Incentive Plan sets stock ownership and non-executive shareholder guidelines. Performance is measured by clear criteria aligned with ethics and governance. All governance documents and reports are published online for transparency, including meeting results and minutes.
Our commitment to sustainable value creation is embedded within the group performance management ecosystem, with a direct linkage to executive remuneration. This ensures that sustainability priorities are integrated into leadership accountabilities and collectively owned across the executive layer. See Target setting and progress monitoring section for more details executive performance and remuneration.
Business ethics
stc maintains integrity by prioritizing transparency, accountability and ethical business practices. The stc group follows regional standards, respects human rights and enforces strict governance to protect stakeholder interests. Risk management systems actively combat corruption and support accountability.
Code of ethics
stc group's Code of Ethics, "Integrity takes us forward," reflects its values – Dynamism, Devotion and Drive – and offers detailed guidance for expected behavior. Covering 16 major risks to integrity, the Code serves as a reference for employees, customers, partners, suppliers and stakeholders. The Anti-Corruption and Fraud Policy complements the Code and strictly bans facilitation payments throughout stc and its subsidiaries.
As part of stc’s new operational model, ethics is embedded across all parts of the organization through the Compliance program, which includes half-day ethical leadership workshops for senior leaders, focusing on the importance of leadership in shaping an ethical culture and addressing issues like anticorruption, conflicts of interest and handling gifts. All employees, executives and leaders must follow the Code, which also applies to suppliers and contractors; every employee signs a statement confirming they have read and understood it. Integrity training is mandatory for everyone and violations can result in disciplinary actions, including termination.
In 2025, stc maintained its focus on ethical governance and transparency to remain aligned with its compliance objectives. An independent ethics and compliance audit was conducted in December 2024, with such audits now scheduled every three years to drive continuous improvement and accountability. The review confirmed robust ethics and compliance oversight at both Board and Executive Management levels, consistent with international standards.
100%
signed the code of ethics across entire group for more than 3 years
Business ethics training
At stc, integrity and ethical conduct form the foundational elements of corporate culture. To uphold these values, all personnel, ranging from senior leadership to new hires, are required to complete the Basic Online Integrity program. This program educates participants on the stc Code of Ethics, underscoring stc group's unwavering commitment to ethical business practices. Additionally, employees are mandated to complete the Advanced Online Integrity course, which offers detailed guidance on compliance topics relevant to their respective roles and responsibilities. The integrity training curriculum consists of 21 modules, nine are mandatory for all staff, while the remainder are assigned based on job function and associated risk exposure. This approach ensures employees at every level are equipped with the necessary knowledge and resources to make principled decisions and effectively address compliance risks.
Furthermore, all employees, including part-time staff and contractors, must complete a mandatory data privacy and cybersecurity annual training. This ongoing education reinforces their responsibility to protect sensitive information and maintain a secure digital environment.
Anti-bribery and corruption
stc's code of ethics and group-wide Anti-bribery and Corruption Policy prohibits facilitation payments at all company levels, including subsidiaries. These policies follow Transparency International guidelines and are regularly updated. The company maintains zero tolerance for bribery and corruption, ensuring fairness, transparency and accountability in every business transaction. In 2025, there were no recorded legal cases of corruption involving stc KSA or its staff. During the year, 9,544 employees (99.8% of the workforce) completed anti-corruption training through multiple sessions, both online and in person, while a further 344 contractors received training during the onboarding process.
The Anti-bribery and Corruption Policy is applicable to all suppliers and contractors across the stc group, including subsidiaries and joint ventures. Suppliers found to be non-compliant may face contract termination or be required to implement corrective action plans, subject to the severity of the violation. All suppliers must complete mandatory annual training, accessible through stc's dedicated online partner hub portal. Furthermore, suppliers are expected to establish and maintain robust anti-corruption policies and programs to ensure ongoing compliance.
0
legal cases raised by external entities regarding corruption in 2025
Anti-corruption awareness was communicated to
100%
of stc's business partners
100%
of employees and governance body received communication on stc's anti-corruption policies and procedures in 2025.
Whistleblowing
stc has implemented a Whistleblowing Policy as part of its corporate integrity framework, providing secure channels for employees and stakeholders to report unethical behavior, fraud or misconduct. Reports are handled discreetly under a zero-retaliation policy, ensuring protection for those acting in good faith. The Whistleblowing Policy (Speak Up) and reporting mechanisms are regularly communicated, keeping all stakeholders informed and supporting stc's commitment to transparency and accountability.
In 2025, a total of 564 reports were submitted through the whistleblowing channels. More than 57% of recorded complaints were related to internal policies and procedures and 30% of cases were categorized as "other" which include HR, safety and security-related areas. Only 7% remain open and under investigation.
Speak Up whistleblowing platform
stc fosters a culture of integrity that empowers employees to report concerns with confidence. Employees and stakeholders are encouraged to communicate integrity-related issues using designated Speak Up channels, including direct managers, interdepartmental managers, the stc HR team, the Business Integrity team and the dedicated Speak Up email (speak-up@stc.com.sa). The option to report anonymously via the Speak Up email ensures individuals can raise concerns without fear of retaliation. All reports are managed with strict professionalism and confidentiality.
stc maintains ongoing communication regarding the availability and importance of Speak Up channels and incorporates this guidance into compliance and ethics training. The Business Integrity team evaluates every integrity-related allegation to confirm its validity and conducts an initial assessment to identify the appropriate resolution pathway. If a report does not meet established integrity criteria, it is referred to the relevant business unit or corporate function for appropriate action.
In 2023, the rate of substantiated whistleblower inquiries, complaints or issues received has decreased from 80% to 30%, reflecting the effectiveness of the corrective actions implemented and the awareness sessions conducted across the organization to strengthen ethical practices and reinforce a speak-up culture.
The group enforces a robust Anti-retaliation Policy, protecting those who report concerns in good faith or participate in compliance investigations. Disciplinary actions following investigations may include formal warnings up to termination, depending on the gravity of the incident. The disciplinary process takes all contextual factors into account and ensures employees alleged to have committed misconduct are given the opportunity to respond before any decisions are rendered.
Anti-competitive behavior
A competitive market is vital for economic health and growth. stc ensures fair competition by strictly following competition laws and regulations. stc group's policies aim to prevent monopolistic or anti-competitive conduct while managing legal risks. Senior management supports the Code of Ethics, which highlights key principles for fair competition, and these are practiced across the organization. All employees must complete training on fair competition.
We participate in government consultations and regulatory activities to encourage fair competition, advocate for sustainability, and discourage unfair practices. We back government initiatives to enhance economic competitiveness wherever we operate.
In 2025, as in previous years, stc received no legal penalties for anti-competitive behavior, anti-trust and monopoly practices, with no monetary losses associated with same.
Group-wide compliance
stc's Corporate Compliance function drives ethical standards throughout the organization, supported by Internal Audit reviews and periodic external audits of all business units carried every three years in accordance with the Institute of Internal Auditors (IIA) guidelines. These regular evaluations and independent oversight help stc maintain accountability, upholding ethical standards across all business areas.
stc's Compliance function operates under a dual reporting framework to both the Board Audit Committee and the Governance, Risk and Compliance (GRC) Committee. The latter oversees compliance reports and ethics policy implementation, while the Enterprise Risk Management and Compliance teams continually monitor risks to strengthen governance. This approach highlights stc's commitment to the highest standards of transparency and accountability, reinforcing ongoing efforts to uphold and increase ethical practices across all facets of stc business operations.
Internal compliance monitoring and reporting
stc's corporate compliance sector ensures consistent adherence to compliance and ethical standards. The Executive Management Sustainability Committee, chaired by the GCEO, oversees compliance and ethics by reviewing reports on the code of ethics' implementation.
Compliance with laws and regulations
In 2025, stc strictly complied with all applicable laws and regulations in every country where it operates. The company maintained strong relationships with regulators, safeguarded shareholder rights and actively monitored non-compliance cases to address issues and prevent recurrence. No violations of environmental, social or national law occurred throughout the year, reflecting stc's commitment to integrity and compliance.
0
incidents of non-compliance with laws and regulations related to society and national economy
0
legal and regulatory fines and settlements Environmental, society and national economy regulations
0
non-monetary sanctions from Environmental, society and national economy regulations
0
incidents of non-compliance with environmental laws and/or regulations
Preventing workplace discrimination and harassment
stc has strict rules to prevent workplace discrimination and harassment, as outlined in the Code of Ethics and Fair Employment Policy. stc group prohibits discriminatory remarks of any kind, including offensive comments or gestures, whether made in person or virtually, as well as jokes about others related to physical appearance, religion, gender, ethnicity, nationality, disability, tribal affiliation or any other characteristic that may cause offense.
stc values diversity and enforce a zero-tolerance approach to harassment or bullying. Employees can report any issues through the Speak Up channels, while the Diversity, Equity and Inclusion team works to increase awareness and leaders foster an inclusive environment. You can review the Code of Ethics and Fair Employment Policy here.
Supply chain compliance
stc group recognizes that ethical responsibility extends beyond the organization to its suppliers and business partners. The company partners only with suppliers who share its commitment to high ethical standards. All suppliers and companies with whom the company conducts business are required to adhere to the same principles of integrity, compliance and ethical conduct as stc. To formalize these expectations, stc has developed the Supplier Code of Conduct, which establishes the minimum standards for doing business with stc group and its entities.
100%
of stc's suppliers adhere by the supplier code of conduct in 2025
Our commitment to human rights
At stc group, respect for human rights is fundamental to its identity and business operations. This guides interactions with stakeholders and reinforces a proactive approach to managing risks. Robust human rights commitments extend well beyond protecting the company's reputation to strengthening confidence among stakeholders, forming a cornerstone of resilient, responsible and sustainable business performance.
stc closely collaborates with the Saudi Human Rights Commission, focusing on key areas such as workplace rights, supply chain ethics and community engagement. The Human Rights Policy covers essential topics including privacy, diversity, fair labor conditions, prevention of forced or child labor and employee development, setting high standards within the sector.
Implementation is overseen by Legal Affairs, Procurement and HR, with training programs ensuring that ethical decision-making is integrated across all units. Accountability is maintained through regular reporting and stc's Speak Up tool supports transparent, retaliation-free reporting of concerns.
Supplier accountability involves strict pre-qualification and ongoing compliance checks, with all major contracts containing clauses on fair wages, working hours, age requirements and safety. stc group's Supplier Code of Conduct bans child and forced labor and discrimination, and encourages diversity and responsible practices, in line with international conventions and national standards.
Human Rights Policy
stc group's Human Rights Policy, approved by the GCEO, reaffirms its commitment to the highest standards of ethical conduct and humanitarian protections. The policy aligns with the Universal Declaration of Human Rights, ILO core conventions, the UN Guiding Principles on Business and Human Rights and Saudi labor law. It prioritizes the most material human-rights, risks such as workplace rights, labor conditions, supply-chain ethics, community impacts and security practices. In addition, it strengthens implementation in collaboration with the Saudi Human Rights Commission.
Key commitments include:
- Protecting privacy and confidentiality
- Promoting diversity, inclusion and equality
- Ensuring safe, healthy working conditions
- Upholding fair employment contracts, working hours and wages
- Prohibiting child, forced labor and human trafficking
- Supporting employee skills development
Enterprise risk management (ERM)
Introduction
The telecommunications sector continues to undergo a structural shift, with demand for traditional voice services maturing while data traffic and digital usage grow at pace. This evolution is supported by accelerating adoption of advanced connectivity, cloud-enabled services and digital platforms, which is reshaping customer expectations and business models and increasing the need for continuous innovation across the industry.
Enterprise risk management governance
The Board of Directors is committed to maintaining strong corporate governance through ongoing review of relevant best practices and their appropriate implementation. The Board Risk Committee provides dedicated oversight of the enterprise risk management framework, related strategies and policies, and the effectiveness of stc's risk management system. As part of its mandate, the Committee reviews risk families across a wide range of exposures, assesses the principal risks and evaluates management's approach to monitoring, controls and risk treatment.
During the year, stc elevated and enhanced its risk appetite to ensure it remains aligned with the stc group's strategic direction and decision-making. The updated approach strengthens consistency across the organization by cascading risk appetite principles and metrics to subsidiaries and enabling a consolidated company view of risk capacity and tolerance. This supports clearer accountability, more consistent risk-based decisions and improved oversight across stc and its subsidiaries.
100%
of business units analyzed for risk related to corruption over the past 3 years
Safeguarding trust in a digital world
Data privacy and security
In terms of data security and privacy, stc follows strict policies and complies with all relevant laws in countries where it operates. Its Data Privacy and Security Policy sets out robust protection measures with zero tolerance for risks leading to data breaches. stc group safeguards all personal data entrusted to it by customers, employees and partners, adhering to high standards for authenticity and classification. The Data Governance Policy applies across all stc sectors, employees and contractors, and requires the immediate reporting of any actual or suspected personal data leakage in accordance with internal procedures.
stc continuously monitors threats and update systems, integrating privacy requirements into business processes through controls such as Identity and Access Management (IAM), Data Loss Prevention (DLP), encryption and Digital Rights Management (DRM). The Data Governance Council and Steering Committee oversees data quality and regulatory compliance, supported by executive leadership. The company also has strict guidelines for suppliers and partners to maintain data protection controls to uphold its standards. Furthermore, the data governance framework promotes high data quality, operational excellence and shared responsibility, led by a Stewardship Lead, ensuring stc's commitment to responsible, compliant and ethical data management across the organization.
The Data Protection and Privacy department manages assessments, enforces controls and defines customer rights, including support through the mystc app. stc maintains ongoing training to ensure staff awareness, including onboarding for new hires and an annual Privacy Day. In 2025, stc group processed over 2,093 data-sharing requests, included data protection clauses in all contracts, and automated data destruction certificates to make sure vendors effectively wipe stc data upon project completion.
stc group Privacy Notice complies with laws in Saudi Arabia, Bahrain and Kuwait, tailoring notices for each subsidiary. It outlines data practices, audits, staff training and transparency through governance reports. Regular updates keep stc aligned with regulations such as the Personal Data Protection Law (PDPL) and CST standards.
Data governance policies and compliance
Data ownership
The Stewardship Lead serves as the data governance authority, ensuring corporate data is accurately defined and appropriately utilized throughout stc.
Risk minimization
The protection of sensitive data is a collective responsibility. stc's unwavering commitment to implementing robust data protection controls and adhering to regulatory requirements is fundamental to maintaining a secure data environment. It is imperative that the company honors customers' trust by safeguarding their privacy and protecting their information.
Data Protection and Privacy Framework
stc's Data Protection and Privacy (DPP) Framework establishes 10 core principles that every employee must uphold, irrespective of their location.
Accountability
Transparency
Choice and consent
Limiting data collection
Use, retention and destruction
Access to data
Data disclosure limitation
Data security
Data quality
Monitoring and compliance
Cybersecurity
As cyberattacks and data breaches grow in frequency and sophistication, organizations must regularly assess and update their security strategies. As a leading ICT company managing critical infrastructure and telecommunications data, stc maintains a cybersecurity strategy that protects systems, facilities and networks. The Cybersecurity Synergy and Enablement Committee advises senior management on relevant topics and collaborates with industry-leading consultancies to remain at the forefront of cybersecurity developments. stc maintains high levels of compliance with applicable cybersecurity and regulatory requirements, in alignment with national frameworks.
Cybersecurity: Progress for 2025
In 2025, stc group enhanced cybersecurity by reducing incident response times to under two hours, monitoring online assets across 13 subsidiaries and strengthening brand trust. It also promoted thought leadership at over 20 events, 93.9% completion rate for mandatory data privacy and protection training across employees, subsidiaries, and contractors, and improved executive awareness through workshops and used the hackathon to promote innovation for cybersecurity.
Building on this progress in 2025, stc group achieved a global milestone by localizing the software for eSIM through a strategic partnership with Thales, a worldwide leader in cybersecurity and digital identity. This collaboration secures the next generation of Internet of Things (IoT) and made stc group the first telecom operator globally to attain the GSMA Security Accreditation Scheme for UICC Production (SAS UP), a certification that upholds the highest security standards in eSIM production.
Further, stc has implemented various security controls to bolster digital security and protect organizational assets.
Database activity monitoring:
These controls help to detect fraudulent/illegal activities, minimizing disruptions to operations and productivity.
Encryption:
Data is transformed into ciphertext, accessible only to individuals possessing the appropriate decryption credentials.
Identification and access management (IAM):
Ensures that only authorized users can access designated resources (applications or data) via approved devices, while preventing unauthorized interference.
Data classification:
Information is categorized according to type, sensitivity and organizational value, allowing for targeted risk mitigation.
Data leak prevention:
Controls are in place to detect and prevent unauthorized data exfiltration or loss of sensitive information.
Digital rights management (DRM):
Measures that restrict user access to specific digital assets.
Cybersecurity Policy
stc's Cybersecurity Policy aligns with international standards and best practices, subject to regular review to maintain its effectiveness. The policy covers 19 security domains, safeguarding information assets and ensuring confidentiality, integrity, availability and business continuity.
Protection against cyberattacks
In response to the increasing frequency and sophistication of cyber threats, stc tightened protocols and reinforced defensive capabilities.
In 2023, stc recorded zero data security breaches, zero incidents involving customers' personally identifiable information (PII), no regulatory actions related to data protection violations and no financial losses from legal proceedings concerning customer privacy in KSA, Bahrain or Kuwait.
Preventive measures include:
- Vulnerability assessments
- Risks assessments
- Penetration testing
- Cyber resilience assessments
- Third-party assessment
- AI assessment
Assurance assessments are carried out using a mix of methods:
- Automatic ad hoc vulnerability assessments
- Periodic assessments conducted covering all stc assets
- Mandatory assessment before the launch of any new service or products
- Red teaming assessment
- Compliance assessment
- Crowd sourcing – bug bounty (national/international)
93.9%
completion of mandatory data privacy and protection training
Zero
incidents involving customers' PII
Achieved 100% compliance with National Data Management Office (NDMO) requirements, reinforcing customer trust and mitigating governance and regulatory penalties.
Responsible AI
As artificial intelligence technologies become increasingly integrated into digital services and internal operations, stc is committed to ensuring that AI is developed and deployed responsibly, ethically and securely. stc group's Responsible AI approach aligns with its broader data governance, cybersecurity and privacy frameworks, ensuring that AI solutions uphold transparency, accountability and data protection.
stc implements strict policies and procedures governing the use of AI technologies, ensuring AI systems are designed and deployed in a way that protects user privacy and maintains strong cybersecurity safeguards. AI initiatives are assessed through established governance mechanisms to maintain compliance with internal policies and international best practices.
To further strengthen oversight, stc established a comprehensive Responsible AI governance framework in 2023, supported by formal policies designed to mitigate implementation risks and ensure ethical and compliant deployment at scale. As part of this framework, stc certified 22 reusable AI models and registered more than 90 models, enabling controlled, secure and standardized adoption of AI solutions across the organization.
To support responsible adoption, stc provides training and awareness programs for employees, helping teams understand the ethical, legal and operational considerations associated with AI technologies. These programs make certain that employees can leverage AI tools effectively while maintaining high standards of data protection, responsible innovation and cybersecurity.
In 2023, stc soft launched an internal AI platform designed to support employees in performing their roles more efficiently while maintaining a safe, secure and innovative working environment. The platform enables teams to use AI capabilities for productivity and knowledge management while operating within stc's established governance and security controls.
Data privacy and security training and awareness
stc is entrusted by its customers, employees and stakeholders to protect personal information, a responsibility taken with utmost seriousness. Mandatory data privacy and protection training is provided for stc KSA employees, subsidiaries and contractors, reinforcing a company culture that prioritizes data privacy and protection. Comprehensive training in cybersecurity and data privacy is offered to all employees and business partners, covering topics such as personal data protection, cybersecurity risks, secure digital practices, responsible use of emerging technologies and compliance with applicable regulations, including Personal Data Protection Law (PDPL).
Awareness company-wide campaigns address key areas such as phishing, password security, secure remote working, data protection practices and responsible use of digital platforms. In addition, role-based awareness programs are tailored and delivered to teams with specific responsibilities or privileged access (such as the special projects team, executive leaders, VPs, service provider contractors, social media team, cybersecurity team and administrative people with privileges). These initiatives support company efforts to mitigate cybersecurity and data privacy risks while reinforcing a responsible and secure management of information across all operations.
Data privacy and security audits
With the ongoing enhancement of data privacy, protection and security regulations, organizations managing personal information are subject to increasingly rigorous compliance mandates. To ensure stc group's continuous alignment with these standards, stc conducts regular independent external audits of its data privacy and security procedures at minimum every two years. Such audits encompass evaluations in accordance with the National Cybersecurity Authority's Essential Cybersecurity Controls (NCA ECC), Data Cybersecurity Controls (DCC), the CST and ISO 27001 requirements. Furthermore, stc is subject to annual and quarterly audits by Saudi Arabia's CST, underscoring stc's dedication to upholding exemplary regulatory compliance and data protection protocols.
stc Security Pass program: Safeguarding data for suppliers and partners
stc encourages its suppliers and business partners to adopt strict data protection measures and undergo compliance checks every two years to maintain certification. The Security Pass program is available to all existing and prospective partners. Through the program, partners register and provide documentation of their third-party inspections and audits to fulfill the program's criteria. To be awarded a Security Pass Certificate, partners must:
- Assess their tier level
- Fulfill the relevant Security Pass Certification obligations
- Complete the Partner Compliance Cybersecurity Certificate report
- Submit an authorized audit certificate
An stc authorized auditing firm ensures partners comply with stc's supplier security standards by performing validations and issuing certifications in cybersecurity. These standards are found in the documents, stc Partners Cybersecurity Standard supported by stc Partners Cybersecurity Controls Guideline to help suppliers understand and fulfill the cybersecurity controls' requirements. Partners are also tasked with sending monthly progress reports on certification to stc's Cybersecurity GRC department. By enhancing privacy and data protection efforts, stc proactively shields customers' information and secure shared data with its partners. This initiative demonstrates stc's dedication to upholding top-tier security in its network, building trust and confidence in its services. You can find additional details about the Security Pass Certificate here.
Promoting online safety and protection for children
stc embraces its role in creating a safer digital environment for children. As a key player in digital connectivity, the stc group pledges to safeguard children's rights throughout operations and actively help both parents and young users become responsible digital citizens. Its initiatives focus on equipping families with the right tools, resources and knowledge to confidently navigate the online world. stc publishes the Cyber Security Heroes magazine for children and the parental guide booklet (Secure Cyberspace for your Kids). The guide provides practical advice on parental controls, identifying online dangers, encouraging open conversations about internet use and promoting positive digital habits. These efforts are further supported by animated awareness videos, interactive school sessions and hands-on training programs. During the reporting period, stc trained and empowered 900 students with essential skills to recognize cyber threats and protect themselves online.
Complementing these internal awareness initiatives, as a key enabler of digital transformation, stc group actively supports the Child Online Safety Initiative and promotes digital safety awareness and skills for children, youth, parents and educators. stc showcased its contributions to the initiative while serving as a strategic partner at the Global Cybersecurity Forum (GCF) 2025.
900
students with essential skills to recognize cyber threats and protect themselves online.
Supply chain management
stc group's commitment to sustainable procurement focuses on sourcing environmentally friendly goods and services, when feasible, and promoting sustainable practices across its entire supply chain. stc holds its suppliers and business partners to high standards, expecting their operations to align with the company's sustainability criteria and adhere to its principles regarding critical issues, including safety, human rights, ethical business conduct and environmental stewardship.
Integrating sustainability into our supplier assessment
As part of stc's comprehensive supplier assessment process, all suppliers and contractors undergo thorough evaluation for environmental and social considerations. Suppliers with access to customer data are required to comply with legally binding agreements and adhere to the Supplier Code, which includes specific requirements on data protection. Throughout project execution, stc continuously assesses suppliers based on performance, compliance and ethical standards, which determines their rankings and future selection opportunities. Evaluation criteria encompass quality, sustainability, risk management, customer service, innovation, delivery, operational excellence and cost efficiency. Serious violations, such as breaches of confidentiality or unauthorized disclosures, may result in disqualification or contract termination. Furthermore, all significant investment agreements and contracts at stc contain human rights-specific clauses that are rigorously reviewed to ensure adherence to ethical standards. In 2025, stc reaffirmed its commitment to responsible sourcing by making certain that 100% of new suppliers were screened against environmental, labor and human rights criteria, thus strengthening its dedication to sustainable and ethical business practices.
Supplier engagement and development initiatives
stc strengthens supplier relationships through structured engagement avenues that promote transparency, collaboration and shared value creation. Annual initiatives such as Partner Day provide strategic updates, communicate business priorities and align partners with stc's long-term objectives.
The Partner Awards recognize outstanding contributions to strategic initiatives, innovation and operational excellence, including the rawafed category, which supports localization and the development of national capabilities within the supply chain.
Beyond recognition, stc actively supports supplier development through continuous dialogue, knowledge sharing and performance feedback sessions. Additionally, and in line with sustainability objectives, the company motivates and supports suppliers integrating sustainability practices. These engagements enhance supplier capabilities, encourage innovation and foster long-term partnerships built on mutual growth and shared sustainability ambitions.
2025 Local procurement spending – stc KSA
98%
2025 Local procurement spending – stc group
76%
Promoting SMEs
stc supports small and medium enterprises (SMEs) through its procurement activities, helping local businesses grow and diversify the economy. In 2025, stc collaborated with over 211 SMEs, reaffirming its commitment to developing local industries and promoting sustainable growth.
SME suppliers engaged at a group level in 2025
211
SME suppliers engaged at stc KSA in 2025
49
Partner Development Program (PDP)
stc continues to strengthen its local supply chain through the Partner Development Program (PDP), delivered in collaboration with the Public Investment Fund (PIF). The program focuses on upskilling local SME partners, enhancing collaboration, and supporting long-term capability building.
The PDP offers structured training and coaching across key areas, including:
- Product Management
- Project Management
- Cybersecurity Essentials
- Finance for Business Success
- Business Proposal Writing
Training is delivered through stc Academy and expert-led coaching, combining practical application with technical knowledge.
Program progress:
2024 cohort:
20 companies, 125 participants, 250 training seats
2025 cohort:
20 companies, 125 participants, 250 training seats
2026 cohort:
20 companies targeted (in progress)
The program continues to play a key role in enabling SME partners to contribute to stc's ecosystem and local content objectives.
Toward sustainable logistics and inventory management
stc group aims to create shared value and minimize environmental damage through sustainable logistics and inventory management. Its key goals are to enhance demand planning for responsible consumption, streamline operations to cut emissions and boost efficiency, and support a circular economy via material reuse and safe disposal.
stc uses 100% biodegradable bags in warehouse operations and is committed to reducing its consumption of these bags by:
- Reusing the bags multi-times
- Consolidating the demand
- Reducing the thickness of the bag
Building a digital ecosystem across procurement practices
stc's main office has adopted a fully paperless procurement process using its internal system, stc HUB and the Oracle Procurement System. Now, 100% of bidding, work orders and letters of award are managed digitally, eliminating paper use in procurement.
100%
average paperless procurement process across stc group
Maximizing local content through rawafed
rawafed is stc's flagship program to maximize local content in the ICT sector, directly supporting Saudi Vision 2030 by localizing spending, attracting investment, fostering innovation and enriching national capabilities.
Local content, as defined by the Local Content and Government Procurement Authority (LCGPA), is a national agenda that aims to enhance Saudi Arabia's economy by engaging all economic sectors, including the public sector, private sector and individuals.
To date, rawafed-supported local spending exceeds % 65 billion. The program operates under a formal governance model that embeds local content requirements and compliance controls into stc group procurement. This model defines mandatory local-content clauses, price-preference mechanisms, SME preferences, certification processes and regular compliance reviews. It serves as a sector reference and is continually assessed to improve alignment with laws, market needs and best practices.
With the launch of the rawafed local content updated strategy in 2025, a fresh roadmap is set to amplify economic and social benefits over the long term through four key strategic pillars.
Through strategic initiatives and partnerships, stc significantly reinforced local spending with enterprises and SMEs
Increase and stimulate opportunities for the national industries in the telecom and ICT verticals
Increase digital and ICT enhancement and use. Improve ability and practice in the R&D aspect
Create additional employment opportunities for Saudis in the ICT sectors and develop skills of the local capabilities