Tata Steel's approach to business includes a focus on ethical practices. The Company follows the Tata Code of Conduct and uses the Management of Business Ethics (MBE) framework, which is based on four key pillars:
Leadership
Committees at the Board and Management levels oversee vigilance mechanisms. The Senior Leadership team upholds the Company's values, communicating them to stakeholders. The Chief Ethics Counsellor (CEC) leads MBE initiatives and reports to the CEO & MD, who is also the Principal Ethics Officer. Divisional Ethics Coordinators and Ethics Champions implement business ethics, forming the Organisational Ethics Council (OEC). Additionally, POSH (Prevention of Sexual Harassment) programme representatives engage with employees to build trust and support harassment case reporting.
Compliance structure
The Company uses several IT systems for vigilance: Darpan for TCoC declarations, MBE Information System to manage Ethics Coordinators, Kashmakash for dilemma resolution, and Integrated Concern Management System. The 'Speak Up' third-party helpline ensures whistleblowing integrity with a 24/7 toll-free number in multiple languages.
Communication and training
Various channels are used to engage employees and stakeholders, including round-table discussions, vendor meetings, performances, town halls, training sessions, and mass meetings. Online and classroom tailored training programmes are conducted on topics such as POSH, the Tata Code of Conduct, Respectful Workplace, Conflict of Interest, Anti-Bribery & Anti-Corruption, and Third-Party Due Diligence.
Measurement
The annual MBE Survey and in-person discussions are used to assess the effectiveness of the process. The feedback is shared with the Senior Leadership to refine deployment strategy and activities. OEC activities are tracked through an online system.
Tata Steel's Apex Business & Human Rights Committee oversees human rights commitments and ensures accountability. The Company’s Business & Human Rights policy aligns with key global principles and is consistent with the Tata Code of Conduct, applying to Tata Steel and its subsidiaries. Mechanisms are in place for addressing grievances through various channels, with the Ethics Department investigating issues and providing recommendations. Concerns involving senior personnel are directed to the Audit Committee Chairperson. Tata Steel ensures its value chain partners comply with the SA8000:2014 standard to prevent human rights abuses. No reports of modern slavery or human trafficking were received in FY2024-25, and assessments indicated no evidence of such issues in the value chain.
Tata Steel navigates the complexities of regulatory changes while balancing the expectations of various stakeholders. By emphasising fairness and ethical behaviour, Tata Steel maintains the highest operational standards.
The Compliance function of Tata Steel continues to serve as a vital second line of defence, proactively identifying compliance gaps and enhancing internal controls. The team’s role extends to providing strategic guidance to management and offering comprehensive training programmes that empower employees to meet compliance obligations.
In FY2024-25, the Compliance function, underwent a scheduled surveillance audit under the ISO 9001:2015 Quality Management System framework. Tata Steel aims to secure the ISO 37301:2021 certification, adhering to best practices in organisational governance. Equally important is technology integration to streamline compliance processes, minimising potential errors, allowing for more efficient user follow-ups and improved management reporting. To further strengthen its compliance capabilities, Tata Steel plans to extend its oversight mechanisms to third-party relationships and continually enhancing its technology infrastructure to address emerging compliance challenges.
The Compliance function is wellequipped to uphold industry-specific standards throughout Tata Steel, driving a robust compliance culture at all organisational levels.
Tata Steel addresses key issues related to the collection, storage, retention, and transfer of personal data in compliance with applicable laws across all locations. The Company’s robust data security initiatives protect against unauthorised access and data loss or corruption throughout its lifecycle. Beyond regulatory compliance, we empower individuals connected with our organisation to understand and contribute to the protection of personal and sensitive information. We practise limited collection and sharing of personal data on a need-to-know basis to ensure confidentiality, integrity, and availability. To foster a culture of data protection and privacy, we offer workshops, campaigns, training sessions, and digital resources to all stakeholders.