12 unchanged sentences
The Company’s Head of Information Security is responsible for developing and implementing these controls and training exercises with support from our information technology department.
−Removed: The Company’s enterprise risk management program has established an internal risk committee to evaluate information governance risks including risks associated with the Company’s use of artificial intelligence.
+Added: The Company’s enterprise risk management program has established an internal risk committee to evaluate information governance risks including risks associated with the Company’s use of AI.
This committee comprises members of management of the Company’s information technology, human resources, marketing, accounting, risk, procurement, training, finance, and legal functions, and is focused on performing risk assessments to identify areas of concern and implement appropriate changes to enhance its cybersecurity and privacy policies and procedures.
8 unchanged sentences
We can provide no assurances that there will not be incidents in the future or that they will not materially affect us, including our business strategy, results of operations, or financial condition.
−Removed: The Board has authorized the audit committee to oversee the Company’s risk assessment and risk management practices and strategies.
−Removed: This delegation includes maintaining responsibility for overseeing the Company’s enterprise risk management program.
−Removed: As a part of this oversight role, the audit committee receives regular updates from management on cybersecurity threats and privacy risks impacting the Company , which includes benchmarking these risks versus our industry.
+Added: The Board has authorized the Finance and Audit Committee to oversee the Company’s cyber, data, privacy, and AI risks.
+Added: As a part of this oversight role, the Finance and Audit Committee receives regular updates from the Company’s information governance and crisis/business continuity risk subcommittees (under the overall enterprise risk management program) on cybersecurity threats and privacy risks impacting the Company , which includes benchmarking these risks versus our industry.
Our Board members also engage in ad hoc conversations with management on cybersecurity-related news events, receive training specific to cybersecurity risks and threats, and regularly discuss any updates to our cybersecurity risk management and strategy programs.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.