Roche is committed to applying best effort and diligence in managing risks to the benefit of its
stakeholders and avoiding any detriment to an extent that is reasonably possible. To effectively
manage risk a systematic and structured Group Risk Management Process is operated. This
process clearly addresses uncertainty in defined metrics and terms so that all stakeholders
understand the variables for analysis. In this process the assessment of above-mentioned risks is
followed by Risk Treatment. The objective of Risk Treatment is to implement necessary responses
to achieve the target risk level (by reducing or modifying negative impact, or likelihood of an
adverse occurrence). These responses are to establish Controls, Actions and Fallback plans for
mitigating the risk.