internal audit system
Beijing Shenzhou Cell Biotechnology Group Co., Ltd.
Chapter 1 General Provisions
In order to improve the corporate governance structure, standardize the company's economic behavior, improve the quality of internal audit work, prevent and control company risks, and protect the legitimate rights and interests of investors, in accordance with the "Audit Law of the People's Republic of China", "Provisions of the National Audit Office on Internal Audit Work", "Basic Standards for Enterprise Internal Control" and supporting guidelines, "Shanghai Stock Exchange Science and Technology Innovation Board Stock Listing Rules" and "Shanghai Stock Exchange Science and Technology Innovation Board Listed Companies Self-Discipline Supervision Guidelines No. 1" No. - Standardized Operations" and other relevant laws, regulations, normative documents and the "Articles of Association of Beijing China Cell Biotechnology Group Co., Ltd." (hereinafter referred to as the "Articles of Association"), this system is formulated based on the actual situation of the company.
The term "internal audit" as mentioned in this system refers to the activities in which the company's internal audit department and personnel implement independent and objective supervision, evaluation and recommendations on the financial revenue and expenditure, economic activities, internal control and risk management of the company and its holding subsidiaries (hereinafter referred to as the "company") to promote the company to improve its governance and achieve its goals.
The term "internal control" as mentioned in this system refers to the process by which the company's board of directors, audit committee, senior managers and other relevant personnel provide reasonable assurance to achieve the following goals:
(1) Comply with national laws, regulations, rules and other relevant provisions;
(2) Ensure the safety of the company’s assets;
(3) The financial information is true and complete;
(4) Improve the efficiency and effectiveness of the company's operations and promote the company's development strategy.
Chapter 2 Institutions and Personnel
An audit committee shall be established under the board of directors, of which the majority shall be independent directors. The members of the audit committee shall be directors who do not serve as senior managers of the company, and the accounting professionals among the independent directors shall serve as the convener.
The company has established an internal audit and compliance department to supervise and inspect the company's business activities, risk management, internal control, financial information and other matters. The Internal Audit and Compliance Department is responsible to the Board of Directors and reports to the Audit Committee.
The company allocates an appropriate number and quality of full-time personnel to engage in internal audit work. Internal auditors should adhere to the principle of seeking truth from facts, be loyal to their duties, be objective and fair, be honest and honest, and keep secrets; they must not abuse their power, engage in malpractice for personal gain, or neglect their duties.
The internal audit and compliance department should maintain its independence and should not be placed under the leadership of the finance department, or work together with the finance department.
The internal audit and compliance department should maintain professionalism, and internal auditors should maintain attention, study and in-depth interpretation of the regulatory environment and the latest policies.
All internal organizations and subsidiaries of the company shall cooperate with the Internal Audit and Compliance Department in performing their duties in accordance with the law and shall not hinder the work of the Internal Audit and Compliance Department.
Chapter 3 Responsibilities and Requirements
The Audit Committee guides and supervises the internal audit work and performs the following main responsibilities:
(1) Supervise and evaluate the work of external audit institutions, and propose to hire or replace external audit institutions;
(2) Supervise and evaluate internal audit work, and coordinate communication between management, internal audit and related departments and external audit;
(3) Participate in the assessment of the person in charge of internal audit;
(4) Review the company’s financial information and its disclosure;
(5) Supervise and evaluate the company’s internal controls;
(6) Control and manage the company’s related transactions;
(7) Laws and regulations, company articles of association and other matters authorized by the board of directors.
The Internal Audit and Compliance Department performs the following main responsibilities:
(1) Inspect and evaluate the integrity and rationality of the internal control systems involving high-risk businesses formulated by the company’s internal agencies and holding subsidiaries and the effectiveness of their implementation;
(2) Audit the accounting data and other relevant economic data of the company's internal institutions and holding subsidiaries involving high-risk businesses, as well as the legality, compliance, authenticity and completeness of the reflected financial revenues and expenditures and related economic activities, including but not limited to financial reports, performance forecasts, performance bulletins, voluntary disclosure of predictive financial information, etc.;
(3) Assist in establishing and improving the compliance and internal control system and anti-fraud mechanism, determine the key areas, key links and main contents of compliance risks, and reasonably pay attention to and inspect possible compliance risks and fraud during the internal audit process;
(4) Regularly report work to the Audit Committee, including but not limited to the implementation of the internal audit plan and the problems discovered during the internal audit work and their rectification status.
The Internal Audit and Compliance Department carries out audit work based on business links, and evaluates the rationality of the design and implementation effectiveness of internal controls related to financial reporting and information disclosure matters based on actual conditions.
Internal audit should usually cover all business aspects related to financial reporting in the company's operating activities, including but not limited to: sales and collections, procurement and payment, inventory management, fixed asset management, fund management, guarantee and financing, investment management, human resources management, information system management and information disclosure management, etc. The Internal Audit and Compliance Department can adjust the scope of the above business links based on risk orientation.
The audit evidence obtained by internal auditors should be sufficient, relevant and reliable. Internal auditors should clearly and completely record the name, source, content, time and other information of obtaining audit evidence in working papers.
The Internal Audit and Compliance Department shall keep confidential the information obtained, including but not limited to interview communication records, audit evidence obtained, audit conclusion communication records, audit reports, etc. Confidentiality work should comply with the following principles:
(1) Department boundaries: The scope of confidentiality is bounded by specific departments, that is, information obtained within a department shall not be disclosed to other departments unless with the written consent of the department head.
(2) Rank boundaries: Information between positions at the same level within the department will not be shared unless with the written consent of the parties concerned, but superiors within the department have the right to access relevant information of subordinates.
During the audit work, internal auditors shall prepare and review audit working papers in accordance with relevant regulations, and after the completion of the audit project, promptly classify and archive the audit working papers.
The internal audit and compliance department should archive and manage corresponding communication records, work papers, audit work reports and other materials for management's reference.
The Internal Audit and Compliance Department should comprehensively evaluate the effectiveness of the company's internal controls on high-risk businesses every year based on internal audit work and additional review procedures, and assist management in issuing internal control evaluation reports. The internal control evaluation report shall state the purpose, scope, review conclusions and suggestions for improving internal control.
Chapter 4 Specific Implementation
Internal audit work is cyclical and continuous, and generally has a semi-annual or annual audit cycle. The audit cycle is specifically confirmed based on audit matters, workload, and corresponding audit personnel and resources.
The specific process includes audit notification, preliminary business communication, formulating audit plans, implementing audit procedures, writing audit reports, reporting internal audit work to relevant management and the audit committee, etc.
After reporting, relevant business departments should actively cooperate in implementing rectification measures and improve the internal control processes of their respective departments.
Chapter 5 Liability for Violation
Departments and individuals that violate national laws and regulations, company management systems or this system and commit any of the following acts will be subject to sanctions, financial penalties, or be referred to relevant departments for handling depending on the severity of the case:
(1) Refusing to provide relevant documents, vouchers, account books, statements and supporting materials;
(2) Obstructing auditors from exercising their powers, resisting or undermining supervision and inspection;
(3) Committing fraud and concealing the truth;
(4) Refusing to implement audit decisions;
(5) Attacking or retaliating against auditors or whistleblowers.
If an internal auditor violates national laws and regulations, the company's management system or this system, and commits any of the following acts, he or she will be given sanctions and financial penalties depending on the severity of the case. If the case is serious and a crime is suspected, the internal auditor will be transferred to the judicial authority for investigation of criminal liability in accordance with the law:
(1) Taking advantage of one’s authority to seek personal gain;
(2) Engage in fraud and malpractice for personal gain;
(3) Neglecting duties and causing serious inaccuracies in the audit report;
(4) Leaking company secrets.
If internal auditors are attacked, retaliated against, or framed for performing their duties, the company shall promptly take protective measures and deal with the relevant responsible personnel. If the circumstances are serious and a crime is suspected, the company shall transfer it to the judicial authorities for investigation of criminal liability in accordance with the law.
Chapter 6 Supplementary Provisions
Matters not covered in this system shall be implemented in accordance with the provisions of relevant laws, regulations, departmental rules, normative documents and the "Articles of Association". If this system conflicts with the provisions of current laws, regulations, departmental rules, normative documents or the "Articles of Association", the current laws, regulations, The relevant provisions of departmental regulations, normative documents and the Articles of Association shall prevail. If this system conflicts with the mandatory provisions of laws, regulations, departmental rules and normative documents promulgated in the future, the provisions of relevant laws, regulations, departmental rules and normative documents shall prevail.
This system is interpreted and revised by the Board of Directors.
This system will become effective and implemented after being reviewed and approved by the company's board of directors, and the same applies when it is modified.
Beijing Shenzhou Cell Biotechnology Group Co., Ltd.
December 2025