2026 Valero Report on Guiding Principles - Report - Page 55
Introduction
Safety
Environment
Employees
Community
Governance
Appendix
Vetting of Suppliers
Valero engages third-party companies to help manage supply chain and
contractor risks. Business partners are expected to participate in the thirdparty management systems and to maintain a minimum grade based
on Valero's proprietary assessment process and compliance with both
regulatory and Valero requirements.
Vendors undergo an initial screening and are monitored on an ongoing
basis for risks related to health, safety, environmental and quality
performance as well as supplier selection, employee training and
quali昀椀cations, insurance coverage, and 昀椀nancial strength and stability.
For more policies, visit our
website at
www.valero.com > Investors >
Governance & Engagement >
Governance Documents
The systems also assess contractor and supplier risk management
policies and practices regarding human rights and the environment,
and verify certi昀椀cations, such as ISO 14001. Additionally, audits may be
conducted to ensure that suppliers uphold all standards listed in Valero’s
Conduct Guidelines for Business Partners.
BOARD OVERSIGHT
Cybersecurity/IT
Oversight of risk management, including with respect to risks from cybersecurity threats, is the responsibility of our
Board, which exercises its oversight responsibilities both directly and through its committees. The Audit Committee
of our Board has formal oversight responsibilities established in its committee charter concerning our initiatives
and strategies respecting cybersecurity and IT risks. At least once annually, the heads of our information services
and internal audit teams provide a report to the Audit Committee on (i) cybersecurity and IT risks, as well as Valero’s
information security operations, structure, and framework; (ii) various cybersecurity and IT metrics; (iii) Valero’s
cybersecurity and information security management and improvement efforts; (iv) future projects; and (v) Valero’s
governance and assessments related to cybersecurity and IT. The chair of the Audit Committee reports to the Board a
summary of the information presented by the heads of our information services and internal audit teams during their
cybersecurity update. Periodically, the Board also receives reports on such matters directly and our cybersecurity
Incident Response Plan also contains noti昀椀cation procedures to the Board.
Cybersecurity Training and Incident Response Exercises
Our employees are typically required to complete at least annual cybersecurity
training. We also perform periodic tabletop exercises with a company-wide crossfunctional team that are facilitated by a third-party expert and are intended to
simulate a real-life security incident.
Cybersecurity Testing and Third-Party Expert
Review/Audit
We conduct penetration testing as needed and annually conduct Payment Card
Industry Data Security Standard testing and 昀椀rewall reviews, and have periodically
engaged a third-party expert to help therewith. We also periodically engage a thirdparty expert to conduct a review of our information security framework, which is designed to help identify existing and
emerging risks, and mitigate against such risks.
Artificial Intelligence (AI)
In 2024, we established a company-wide cross-functional team to assess the risks and opportunities from
conventional and generative AI and provided a formal report to the Board. We continued these assessments in 2025
and again delivered a formal report to the Board. We expect to continue these assessment efforts going forward.
The Audit Committee also periodically discusses the use of data, technology, and AI by Valero and its independent
auditor.
Valero Report on Guiding Principles •
55