United Hampshire US REIT - Annual Report 2025

Sustainability and Climate Report Our Approach and Progress [205-1] The Manager leads UHREIT’s risk management, identifying material risks and implementing mitigation measures. Guided by our ERM framework, we systematically evaluate hazards, including climate related risks, through combined top-down and bottom-up reviews. Key risks are monitored quarterly, and we perform a comprehensive semi-annual review of the risk universe to identify emerging risks and retire risks no longer considered material. We incorporate diverse stakeholder insights, such as inputs from our ESG consultant to map climate risks, gauge severity, and define mitigation actions that safeguard our operations and ensure regulatory compliance. As part of our progress, both our Singapore and U.S. operations were assessed for risks primarily linked to corruption, and no significant risks were identified. For more information on our risk management processes, please refer to the ERM Framework and 4-Step Risk Management Process portions of our annual report on pages 135 to 138. Cybersecurity and Data Privacy Importance of this Topic [3-3] Robust data governance and cybersecurity are critical to protecting employee and stakeholder information and to minimizing the risk of breaches and non-compliance. As cyber threats become more frequent and sophisticated, any compromise could result in the loss of confidential and time-sensitive data, disrupt operations, and create regulatory and reputational exposure. Prioritising cybersecurity and privacy therefore underpin organisational resilience and sustains stakeholder trust. Our Approach and Progress [418-1] UHREIT treats cybersecurity with utmost seriousness and maintains a zero-tolerance policy toward cybersecurity breaches, with a target of zero breaches of cybersecurity internally. To build a robust and resilient cybersecurity framework, we have implemented various policies and procedures. Table 17: UHREIT’s Cybersecurity and Data Privacy Policies [2-23] [2-24] Internal IT Policy Our internal IT Policy outlines our approach towards the handling and protecting of personal data. It further serves as a guideline for our employees to minimize the risk of loss of program functionality, exposure of sensitive information contained within the Managers computing network, the risk of introducing malware, and the legal exposure of running unlicensed software. The policy is reviewed every three years or whenever necessary to ensure they remain relevant to our operations. 99 ANNUAL REPORT 2025

RkJQdWJsaXNoZXIy NTM2MDQ5