Ethics and transparency are fundamental pillars of our business development.

Oil & Gas
Energy transition and renewables
Innovation and technology
Climate change
Risk Management
ESG advocacy
Reglatory trends
Diversity, equity and inclusion
Human Capital
Compensation
Supply chain and market development
Finance and capital markets
Audit
Independent Board Member
CPC1
AC2
CC3
CDRC4
Susan Segal
Mauricio Doehner Cobian
Pierre-Jean Sivignon
Gérard Martellozo
Germán Losada
CPC1:
Corporate practices committee
AC2:
Audit committee
CC3:
Compensation committee
CDRC4:
Corporate Development and Risk Committee
The Board of Directors oversees the execution of Vista's sustainability strategy, as well as our corporate, sustainability and climate-related risk management.
The Corporate Practices Committee plays a key role in reviewing the implementation of the ESG plan, monitoring progress against established targets, and providing guidance to the Executive Team, ensuring that ESG considerations are integrated into the Company's strategic decision making.
At a corporate level, we have a cross-functional working group, composed of members of our Leadership Team, in charge of executing Vista’s ESG projects. Our ESG framework creates an effective portfolio with projects that have short- and long-term objectives and an accountability system to monitor our progress. We believe this framework enhances our capacity to design, execute and report progress on ESG projects and initiatives, and also assess and manage risks following TCFD governance recommendations.
Our ethics and compliance program is comprised by the following corporate integrity elements, which are applicable to and available for all employees, contractors, suppliers and other third parties that conduct with or perform activities for Vista:
Code of Ethics and Conduct
Policies and procedures associated to the Code of Ethics and Conduct
Contractors, suppliers, and other business partners are required, as a condition for onboarding and registration in Vista's systems, to adhere the Integrity Policy for Contractors and Suppliers.
Board oversight
Ethics Committee
Ethics Line
Web platform
Periodic training to management and employees
Integrity Policy for Contractors and Suppliers
We are aware of the impact and importance human rights play in all business sectors, including the energy industry, and have incorporated the risk of a breach in human rights principles into our Corporate Risk Matrix. Social risk management, a key element of our Social Management System, incorporates proactive risk assessment and management of social engagement, including human rights assessment.
Human Rights policy is available to our employees and all our stakeholders on our website.
Senthuman rights policyhuman rights policyHuman Rights watch clause included in the Terms and Conditions in all our contracts with service providers.
Sentintegrity policy for contractors & suppliersintegrity policy for contractors & suppliersInternal domestic violence protocol, including financial aid and legal advice to employees.
Direct dialogue channels with our communities publicly available on our website.
SentCommunity feedbackCommunity feedbackCommunity engagement framework, covering local community engagement and social risk and impact management.

We manage risks through our Enterprise Risk Management (ERM) framework, which provides a structured approach to identify, assess, prioritize and monitor risks that could impact our operations, financial performance and long-term strategy.
The Corporate Risk Matrix (CRM) is the main tool used to consolidate and monitor risk exposure across the organization. It includes a broad range of risk categories, such as macroeconomic conditions, regulatory and political factors, operational and infrastructure constraints, labor and social dynamics, compliance risks, internal process integrity and climate related risks. For each identified risk, the ERM assigns ownership, controls, and mitigation plans.
The CRM is monitored by the Executive Team and formally reviewed on a quarterly basis. Relevant updates are reported to the Corporate Development and Risk Committee, which oversees risk management activities and reports to the Board of Directors.

Climate-related risks are integrated into the ERM framework and managed through the same processes and tools. These include both transition and physical risks, which are assessed, monitored and incorporated into the CRM. Transition risks may arise from market, regulatory and technological developments, as well as potential reputational impacts, while physical risks relate to the potential effects of climate variability and extreme weather events on operations and infrastructure.

While the primary focus of the ERM framework is on risk identification and mitigation, the Company also considers certain opportunities associated with sustainability and climate-related factors, which are assessed using similar criteria.
During 2025, the Company completed the sixth year of implementation of internal control standards in accordance with the Sarbanes-Oxley Act (SOX) and performed a management assessment of internal control over financial reporting. Our independent external auditors concluded that, as of December 31, 2025, such controls were effective, with no material weaknesses or significant deficiencies identified. Accordingly, the Company was in compliance with SOX requirements for 2025. We are currently working on the 2026 SOX review, including the update of our risk control matrices, and initiating testing of the applicable controls.
Category
TransitionRisk name
Oil demand shiftsDescription
Mitigation efforts
Category
TransitionRisk name
GHG emissions regulation, market and data integrityDescription
Mitigation efforts
Category
PhysicalRisk name
Changes in freshwater availabilityDescription
Mitigation efforts
Category
TransitionOpportunity name
Resilient business modelDescription
Adaptation efforts
Category
TransitionOpportunity name
Long term value creation under slower energy transition scenariosDescription
Adaptation efforts
Category
TransitionOpportunity name
Technology and innovationDescription
Adaptation efforts
Our cybersecurity strategy aims to safeguard our technological assets and data, while enhancing the resilience of our entire value chain. This ensures the integrity and reliability of our operations.
Our practices aligned with the latest cybersecurity regulations set by the U.S. Securities and Exchange Commission in 2023, which seek to enhance and normalize reporting regarding cybersecurity risk management, strategy, governance, and incident disclosure.
The cybersecurity team reports periodically to the Executive Team through an internal Cybersecurity Committee, chaired by our CTO, which meets at least quarterly and reports to the Corporate Practices Committee, also on a quarterly basis. Our cybersecurity practices are aligned with standards such as the NIST Cybersecurity Framework 2.0, ISA/ IEC 62443, and the new SEC regulations.
1 Based on NIST (National Institute of Standards and Technology) CSF (Cybersecurity Framework) where maturity is assessed from 0 (lowest) to 5 (highest) across 108 categories. Our 2023 maturity level reported was validated by KPMG as of December 2023.
Contact us to learn more or share your questions about our work with local communities.