Risk management
and control systems

Achieving our long-term strategic objectives inherently involves taking risks. This makes risk management an essential element of Basic-Fit's culture, corporate governance, strategy, and operational and financial management. Basic-Fit carefully considers the types of risks we take and our risk appetite in achieving our objectives. Basic-Fit’s risk management approach plays an important role in achieving our strong international growth ambitions and creating long-term value.

Description and governance

The responsibilities for risk management extend across all levels of the organisation, embedding these duties throughout the hierarchy. This comprehensive approach fosters a culture of accountability and vigilance, enabling us to identify and mitigate risks promptly while upholding high standards of governance and compliance.

The Management Board, under the supervision of the Supervisory Board, is responsible for identifying and managing the risks associated with the company's strategy, activities, and affiliated businesses. The Management Board therefore bears ultimate responsibility for designing and establishing Basic-Fit's risk management and internal control framework, and for creating and promoting an appropriate business culture and values. Based on the risk assessment, the Management Board designs, implements, and maintains adequate internal control and risk management systems. It monitors the design and operation of these systems and conducts a systematic assessment of their effectiveness. The Management Board reports to the Supervisory Board on the effectiveness of the internal risk management and control systems.

Members of the Leadership Team, consisting of the members of the Management Board, the Chief Operating Officer, and the Chief Commercial Officer, act as Risk Sponsors. In this role, they are responsible for setting risk appetite levels that align with the company's strategic objectives and the severity of these associated risks, providing feedback and recommendations on significant emerging risks, and overseeing measures implemented to mitigate these risks.

The Supervisory Board supervises the manner in which the Management Board implements the company's strategy and discusses the principal risks associated with it. The Supervisory Board focuses on the effectiveness of the company's internal risk management and control systems and on the integrity and quality of the financial and sustainability reporting. The Audit and Risk Committee prepares the Supervisory Board's decision-making in the above areas and reports on the methods used to assess the effectiveness of the design and operation of internal risk management and control systems on an annual basis. In this context, the Audit and Risk Committee facilitates discussions with the Management Board on the design and operating effectiveness of the internal risk management and control systems, thereby supporting the Management Board's reporting to the Supervisory Board.

The three lines of defence

Middle management and all employees help the Leadership Team to carry out risk, control, and corporate governance tasks on a daily basis, representing our first line of defence. They are encouraged to work in an entrepreneurial manner, provided they are equipped to manage risks and operate within the boundaries set by the Leadership Team. They serve as risk owners and risk champions, responsible for identifying and understanding risks within their area of responsibility and for developing and implementing mitigation measures to manage those risks; including performing control activities. Organisationally, those employees perform control activities centrally when they relate to Centralised Head Office functions and processes, such as Finance, HR, Marketing, Customer Care, IT, and Legal. We refer to the Head Office also as Headquarters (HQ) in this report. When these control activities are linked to Operations, they are performed locally. For a description of our regional operations, please see the Our Strategy section of this report.

The Risk and Control, Compliance and Data Protection, and IT Security functions represent the second line of defence and jointly protect and monitor Basic-Fit's risk strategy, risk culture and integrity. The second line coordinates risk assessment activities and supports the first line in designing related controls. They ensure that risks are managed within Basic-Fit's risk appetite by monitoring the performance of existing control activities and performing other assurance activities related to risk mitigation measures. The second line works closely with the internal auditor, who acts as the third line of defence, to align working methods and the approach to risk management and internal control improvements.

The second line follows up on the implementation of the internal and external auditor's recommendations and other control improvement plans. The second line reports to the Management Board on the state of risk management and control activities.

As the third line of defence, the internal audit function provides independent assurance by assessing and reporting on the effectiveness of governance, risk management and internal controls - implemented by the first and second lines of defence - to the Management Board and the Audit and Risk Committee. The internal auditors use a risk-based internal audit plan that enables them to provide the Management Board with independent assurance and insights into how Basic-Fit manages key risks, including the design and operation of related controls and other risk responses.

Risk management practices

Basic-Fit takes an entrepreneurial but prudent approach to risk taking. We identify and define risks across the spectrum of strategic, operational, financial, and compliance categories. This includes risks related to financial and sustainability reporting, which are addressed as part of the financial and compliance risk categories, respectively.

In the case of strategic risks, we concentrate on factors that could influence our ability to attract and retain members, such as service offerings, marketing effectiveness, brand perception and reputation, and competitive pressures. Risks associated with the implementation of the strategy translate into operational, compliance and financial (including reporting) risks. When assessing operational risks, we recognise the necessity of adaptability and resilience within our business model. A key aspect of these risks is the effective management of resources, which includes the timely adoption of new technologies, attracting and retaining talented people, securing suitable locations, maintaining strong supplier relationships, and the safeguarding our IT assets. Each risk highlights the vital role of operational efficiency and business continuity, as failures in these areas can disrupt service delivery, affect member satisfaction, and ultimately impede the company's growth objectives. When considering financial risks, we prioritise stability in our capital-intensive growth strategy, taking into account the potential impact of external factors such as inflation and market changes on cash flows and our financial health. When looking at compliance risks, we stress the importance of adhering to legal and regulatory standards to protect our reputation. A recurring challenge in this risk category is the increasing complexity of regulations, particularly those related to data security.

These perspectives help us to maintain a comprehensive view of the different categories of risks we currently face and may face in the future.

Risk Management Frameworks

We have established a well embedded risk management framework based on risk management practices guided by the COSO Internal Control – Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), which we use as a point of reference. We follow the principles of the COSO framework and selectively apply detailed points of focus based on their relevance and practicality in our operations. We conduct an integrity/fraud risk assessment on an annual basis, based on the SIRA (Systematic Integrity Risk Analysis) model to assess integrity risks. We continuously review and enhance our internal control systems to align with best practices and evolving business needs.

In managing certain types of risks, we utilise elements of other control frameworks that are more specific to the relevant risk type. These include, for example, ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection – Information Security Management Systems for IT security risks; ISO 37301:2012 Compliance Management Systems for compliance risks; the NOREA Privacy Control Framework (PCF) for privacy-related risks; and the OECD Tax Control Framework for the reporting of tax returns and disclosures. The level of implementation of these frameworks varies from a basic level of 'awareness and inspiration' to the most robust level, referred to as 'blueprint'. For financial and sustainability reporting risks, we utilise a separate internal control framework, which is also based on COSO but is more robust than the overall COSO framework and is therefore applied as a blueprint.

Risk Assessment

To increase our understanding of the risks we face, we evaluate risk severity, which is a combination of the impact and probability of each risk. We adopt a qualitative approach to evaluate the potential impact of risks. In determining the probability of a risk occurring, we take into account various factors, including any historical occurrence and the current state of the existing mitigation measures.

Additionally, we aim to clearly define our risk appetite for each risk, reflecting the level of risk we are willing to accept in pursuit of our strategic goals and objectives. The risk appetite depends upon the company's culture and corporate governance, and is articulated through Basic-Fit's strategy, values, code of conduct, policies, and procedures. For strategic risks, reflecting our entrepreneurial culture, we are generally prepared to take on higher levels of risk in pursuit of our ambitions, while recognising that many strategic risks cannot be managed because they are wholly or partially outside the company's sphere of influence. For the reporting year, we have set a medium risk appetite for this category balancing ambitions with the appropriate governance oversight to ensure that strategic risks are consciously assessed, monitored, and aligned with the company's long-term objectives. We weigh operational risks in relation to our executional stability and continuity in support of our strategic ambitions. Accordingly, we have set a low target risk appetite for the majority of operational risks. For specific operational risks, such as Business Model Diversification and Club Maintenance, a medium risk appetite applies. For Business Model Diversification, this risk appetite reflects a more entrepreneurial approach to developing secondary revenue streams. For Club Maintenance, this risk appetite reflects the operational complexity and practical challenges involved in managing a large and diverse club portfolio. We have adopted a prudent financial risk strategy to limit financial risks, maintain long-term solvency, remain within our bank covenants, and ensure reliable financial and tax reporting. Accordingly, we have set a predominantly averse risk appetite for financial risks. This includes Tax and Accounting risk, for which this risk appetite is consistent with the reasonable assurance statement on the effectiveness of the internal risk management and control systems with regard to financial reporting, as set out in the Statement on Risk Management and Internal Control in the Management Statements section. We strive for a high level of compliance within the legal and regulatory requirements and therefore apply a low appetite for compliance risks. This approach is supported by our newly updated Compliance Charter. Sustainability Governance risk - part of the compliance risk category - covers, among other things, risks related to sustainability reporting. The low appetite applied for this risk is consistent with the limited assurance statement on the effectiveness of the internal risk management and control systems with regard to sustainability reporting, as set out in the Statement on Risk Management and Internal Control in the Management Statements section.

This practice is in line with the recently adopted Dutch Corporate Governance Code (2025), which requires the Management Board to identify and analyse risks across strategic, operational, compliance, and reporting risk categories, establish the risk appetite, and implement measures to manage and control these risks.

The assessed level of risk severity, combined with the target risk appetite, determines the type and robustness of mitigation measures we undertake in response to a risk. In general, the higher the risk severity, and the lower the risk appetite, the more robust our mitigation measures must be. Our approach to assessing the effectiveness of established mitigation measures varies depending upon the risk category, with a differentiated approach applied to reporting and non-reporting risks.

Risk Monitoring

The following paragraphs describe how this differentiated approach is applied in practice for each risk category. We have developed a company-wide methodology for conducting enterprise risk management activities to ensure a consistent, structured, and comparable assessment of risks across the company.

For financial and sustainability reporting, we have implemented a robust process and a separate control framework that includes a comprehensive cycle of formalised control assessments, conducted at least quarterly by the second line of defence and at least annually by internal audit. Within this framework, we assess the effectiveness of IT general controls related to financial reporting and, during the reporting year, expanded the framework to include IT application controls, further strengthening our approach. Please see the Tax and Accounting risk card in the Financial Risks section, and Sustainability Governance risk card in Compliance Risks section, describing the framework. For specific risks and opportunities related to sustainability reporting, please see the Sustainability Statement in this report.
In line with this approach to financial and sustainability reporting, we state that our internal risk management and control systems provide reasonable assurance that financial reporting does not contain material inaccuracies. This represents a high, but not absolute, level of assurance, obtained through gathering sufficient and appropriate evidence. With regard to sustainability reporting, we state that the risk management and control systems supporting sustainability information provide limited assurance that sustainability reporting does not contain material inaccuracies. In designing these controls, we recognise that limited assurance represents a lower, but still meaningful level of confidence in the reliability of the information. Where appropriate, we apply the same materiality thresholds as those used for financial reporting when scoping our sustainability reporting controls. See the Statement on Risk Management and Internal Control in the Management Statements section of this report.

For operational and compliance risks, we utilise a less rigorous testing approach than for reporting risks. This testing approach is nonetheless designed to provide a basis for the statement that, as at the balance sheet date, we are not aware that the internal risk management and control systems do not provide sufficient comfort that those risks are effectively managed. This approach involves an annual review of internal documentary evidence provided by risk owners, risk champions, and other relevant parties, by the second line of defence. The evidence includes internal documentation, such as procedures, protocols, tools, and reports, as well as key performance indicators (KPIs), demonstrating that mitigation measures were in place and operating for the majority of the reporting year. We assess the effectiveness of risk management practices, represented by mitigation and control measures, as 'adequate' when we determine that the company sufficiently managed the associated risks in the past financial year, considering the established risk appetite. When a risk may temporarily have exceeded the risk appetite during the year, but management was actively implementing mitigation measures, we still conclude that, as at the balance sheet date, sufficient comfort has been achieved regarding the effective management of that risk. No changes are recommended when mitigation measures are deemed adequate. When measures are considered adequate but require further strengthening, we recommend enhancements, taking into account the target risk appetite and trend, which may be adjusted during the risk assessment process. As a result of the reporting year's assessment, enhancement actions were suggested and planned for the following risks: Managing Digital Transformation, Workforce and Talent, Suppliers, Health and Safety, Managing IT Security, Managing Expanding Operations, Club Maintenance, and Data Protection and AI. These enhancements resulted from adjustments to our target risk appetite, expanded risk descriptions, or increased organisational ambitions. Please see the relevant risk cards in the Operational Risks and Compliance Risks sections of this report. When deficiencies in the risk management and control systems have remained unremedied since the previous assessment - resulting in one or more risks remaining outside the company's defined risk appetite for a significant part of the year - the relevant mitigation measures are classified as ‘inadequate or absent’. Based on our described approach, no inadequate or absent mitigation measures had been identified as at the balance sheet date, nor were any material unresolved deficiencies observed that would require disclosure. See the Statement on Risk Management and Internal Control in the Management Statements section of this report.

For strategic and general non-reporting financial risks, we adopt a high-level approach that includes an annual risk assessment cycle based on management self-assessment. This assessment is conducted through interviews with risk owners or written confirmations provided by risk champions and risk owners. Please see the relevant risk cards in the Strategic Risks and Financial Risks sections. These risks are not covered by the Statement on Risk Management and Internal Control.

Developments in 2025

As in prior year, we continued to organise risk reporting through risk cards, which present all relevant risk attributes and mitigation measures. Please see the risk cards in the Key Risks section.
The reporting year continued to be shaped by a complex external environment, including persistent geopolitical tensions and armed conflicts in several regions, recurring extreme weather events linked to climate change, and ongoing economic uncertainty in a number of countries. The cyber threat landscape remained elevated, with ongoing risks of data breaches, ransomware attacks, and other significant cyber threats observed across sectors. These risks are addressed separately in the relevant risk cards, distinguishing between Macroeconomic and (geo-)political risks and Managing IT security. Despite the challenging external environment, we observed that the majority of risks facing the company remained stable during the year, with some risks stabilising further. An exception was the Data Protection and AI risk, which demonstrated a growing tendency during the year, reflecting the expanding use of data and artificial intelligence. In response to this growth, we updated the risk description to articulate the company’s strategic approach to the responsible use of AI, addressing both risks and opportunities, with planned enhancements to governance and training measures to support compliant and consistent use across the organisation.

The Clever Fit acquisition was a key highlight of 2025. Further details on this transaction are provided in the Our Strategy section of this report. The Clever Fit acquisition was financed through bank facilities, with the associated financial risks managed in line with the company’s prudent financial risk strategy. Please see the Currency and interest rate risk card. While this development created significant growth opportunities, it also introduced risks related to the integration of the acquired clubs in our network and the adoption of a franchise model. Although this development is reflected in several risk cards, we have specifically addressed it in a dedicated operational risk card, called Managing Expanding Operations, and increased its risk severity from low in the previous reporting year to medium in this reporting year. The associated enhancement action is the development and announcement of a clear strategy for adopting and implementing a franchise model, which is expected to support faster expansion through local partnerships. As the acquisition occurred late in the year and the integration of Clever Fit’s risk management, compliance, and sustainability control framework is still ongoing, the operational, compliance, and sustainability risks of Clever Fit are excluded from the scope of the Statement on Risk Management and Internal Control in the Management Statements section of this report. Clever Fit will be brought into the full scope of the risk management framework during 2026 as part of the integration programme and franchising strategy.

At the end of February 2026, the Group identified an unauthorised outflow of funds of €4.2 million through a social engineering scam at Clever Fit Germany, which at that time had not yet been fully integrated into the Group’s internal control framework. Investigations are ongoing to verify the exact facts, circumstances, and the cause hereof. Actions are taken to recover the funds, which is uncertain. Relevant controls are reinforced.

We continuously improve and develop our risk management processes and systems. The ‘Risk developments since the last assessment and future plans’ sections of each risk card summarise the key developments in 2025, together with planned actions for 2026, including enhancements to existing mitigation measures. The developments described below illustrate how this continuous improvement cycle was reflected in our risk management activities and mitigation measures throughout 2025.

In 2025, we continued to enhance our financial reporting internal control framework by consistently strengthening existing controls and introducing new ones. These enhancements followed recommendations from the second and third lines of defence, as well as findings communicated by the external auditor through the Management Letter and the final audit report of the prior year. We introduced additional controls within several significant financial reporting processes. In particular, we noted improvement areas (which were largely addressed during 2025) relating to the correct and timely authorisation and registration of (related party) lease contracts. We also enhanced IT application controls for key financial systems and expanded the coverage of IT general controls. For non-reporting risks, we implemented the following developments and measures in 2025:

  • The Suitable Sites risk was renamed to Suitable Sites and Terms to reflect the growth of our lease portfolio, which requires additional mitigation measures. These measures were updated to include club performance analysis throughout the lifecycle and the establishment of a centralised Real Estate function to support the execution of the real estate strategy;

  • Enhancement actions suggested in the previous reporting year for the Regulatory and Managing IT Security risks were successfully implemented, including the strengthening of employee awareness through specialised training on recognising and responding to potential security threats and the further enhancement of business continuity management;

  • For Health and Safety risk, a new mitigation measure was implemented focusing on strengthened central oversight and governance, including the introduction of an overarching Health and Safety policy, responsibility matrix and the Steering Committee;

  • Within the Suppliers risk area, a centralised team was established to further enhance supplier management practices and improve visibility and control over spend. This increased visibility enabled the identification of certain single-supplier dependencies, which was reflected in an updated risk severity. Discussions are ongoing with business owners to assess appropriate diversification opportunities;

  • Finally, the former Business Model Disruption risk was renamed Business Model Diversification to reflect the complementary and non-disruptive nature of our secondary revenue streams.

These summaries are not exhaustive. Certain risks or risk categories that currently have no significant impact may develop into key risks over time. The objective of Basic-Fit’s risk management systems is to identify changes in risk profiles and risk-related incidents in a timely manner, enabling the company to take appropriate and timely measures.

Sensitivity analysis

The risks that potentially have the greatest adverse effect on the achievement of Basic-Fit's objectives are described below in the Key Risks section. We have also looked at the sensitivity of the company's results to material changes in external circumstances.

ChangeOnImpact (in millions)Assumptions
Revenue (members)+1.0%Underlying EBITDA less rent14No change to yield
Revenue (yield)+1.0%Underlying EBITDA less rent14No change to volume
Operating expenses+1.0%Underlying EBITDA less rent(10)No change to revenue
Clubs+10 clubsUnderlying EBITDA less rent-No (material) EBITDA impact during the first year from opening clubs
Clubs+10 clubsNet debt113€1.3 million average capex per new club
Net debt2+€50 millionNet Profit-Paid from available cash and cash equivalents at year-end
Borrowings+€50 millionNet Profit(2)Stable interest rates
Interest rate+100 bpsNet Profit23Stable net debt
Interest rate-100 bpsNet Profit-24Stable net debt
  1. Net debt excluding lease liabilities
  2. Net debt excluding lease liabilities
  3. The impact reflects the non-hedged floating rate borrowings, as well as valuation changes of the derivative financial instruments. Excluding valuation changes of the derivative financial instruments, the impact would be minus €4 million.
  4. The impact reflects the non-hedged floating rate borrowings, as well as valuation changes of the derivative financial instruments. Excluding valuation changes of the derivative financial instruments, the impact would be €4 million.

Key Risks

Strategic risks

Customer Behaviour

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Attracting and retaining members is one of the core focus points of Basic-Fit's strategy. Being less attractive to our existing and new members, due to our offering, communication, marketing, competition, harm to our reputation, pricing and membership structure or changes in consumer preferences and behaviour, could impact future growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We focused continuously on offering optimal accessibility for our members across all channels by further developing our chatbot, self-service options and the constant training and coaching of our customer service employees. The availability of the live chat team has been extended by two extra hours in the evening and resulted in a response rate of 98% to the offered chats.

  • We improved our products and services to provide our members with the best possible tools to make fitness accessible to everyone and help them make it a habit they love.

  • We continued to proactively embrace developments that recognise the critical role of mental health in overall well-being, alongside physical health, by continuing and enriching the ‘Boost Your Mood’ campaign in all operating countries. With this campaign, we emphasise that exercise goes far beyond improving one's physical appearance; it fundamentally enhances overall well-being. Physical activity is a powerful tool for uplifting mood, relieving stress, and boosting self-confidence. By making fitness accessible to everyone, we aim to inspire people to take care of both their bodies and their minds, having a positive impact on society as a whole.

  • We rolled out the 'Be Comfortable' campaign in all countries. We aimed to encourage everyone to feel welcome in our clubs, regardless of age, level, weight, race, gender, and motivation. We sought to eliminate any typical fitness-related barriers that could be uncomfortable, such as feeling intimidated by the physical fitness level or body-type of others, the atmosphere (like lighting, sound, music, and smell), social safety, and knowledge of equipment.

Plans for 2026:
  • We will continue to improve our products and services providing our members with the best possible tools to make fitness accessible to everyone and to help them turn it into a habit they love.

  • We will continue providing customer service via established teams and digital tools.

  • We will continue to focus our communications on the two themes derived from our mission to make fitness accessible to everyone and to help individuals cultivate a habit they love. The first theme, ‘Be Comfortable’, encourages everyone to feel welcome and safe in our clubs. The second theme, ‘Well-Being’, will now be brought to life through the ‘Feel Good Club’ platform, which aims to foster greater awareness of the positive effects of physical activity on overall well-being.

Mitigation measures
Value for money: We continuously invest in an attractive value-for-money proposition and customer journey to remain relevant to our existing and new members. Our customers can use the Basic-Fit app, an in-house built customer-friendly app, offering a self-help service, new and extended online workouts and schedules, as well as improved features for club entrance. This approach strengthens our data-driven approach to member communications and motivation. Furthermore, the app offers the availability of an online coach to help our members to set their goals and build and maintain a fitness habit.
Membership model: We operate a transparent, flexible, affordable and straightforward membership model comprising three main forms of membership with attractive add-on opportunities. We continuously analyse new forms of membership structures and add-on opportunities to keep up with new market developments and trends, enabling us to adapt to market circumstances, such as rising inflation.
Innovative fitness products: Our investment in people, innovative fitness products and technologies for use both in and outside our clubs, complementary online products and on-site offerings, marketing campaigns and sales promotions all enable us to enhance the value of our brand and our members’ connection to our brand.
Customer experience: We have a dedicated customer service department focused on continuously improving the member experience and supporting the overall customer journey, which directly contributes to our Google review score. Our virtual assistant Ruby and AI-driven knowledge tools help members find answers quickly and provide our service agents with relevant guidance, enabling fast, consistent, and high-quality resolutions to a set of standard requests. Furthermore, we continue to expand self-service options to increase speed and efficiency. In addition, we actively respond to questions and feedback on public platforms, such as Google and Trustpilot, ensuring that member input is acknowledged, shared internally, and acted upon.

Unpredictable markets impacting expansion

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Our expansion potential could be influenced by different or changing market conditions, legal and regulatory requirements, pandemics, consumer preferences and discretionary consumer spending habits in our growth markets or potential new markets. This could impact future growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • With the acquisition of Clever Fit, we expanded our market presence from six to twelve countries, becoming not only the largest fitness franchise operator in Europe, but also the market leader in Germany.

  • We extended our market leadership in France, where the majority of our new club openings took place and where we expanded 24/7 operations to over 300 clubs. We were an official sponsor of the Tour de France.

  • We introduced strength circuit training and 'Relax and Recover' zones in selected clubs in the Benelux, capturing the fitness and wellness trends with the aim of further increasing the uptake of our Ultimate membership.

  • We won the NIMA Marketing Award for best marketing company in the Netherlands, which reflected our evolution into a brand that prioritises mental and emotional well-being, leveraging customer insights and digital innovation.

  • We followed our cluster strategy, which is aimed at enhancing our market position and increasing penetration.

  • We focused on further expanding and increasing the quality of our owned clubs and services provided in six countries, and earned higher Google ratings across all our countries, as compared to the previous year.

Plans for 2026:
  • We will develop a clear strategy for adopting the franchising model, enabling faster expansion in additional countries through a more capital-efficient approach, with franchise activities integrated into our internal control framework. Please see the 'Managing expanding operations' and 'Tax and Accounting' risk cards.

  • We will continue to follow our growth and club-network strategy to increase fitness penetration and maintain our long-term growth trajectory. We will update this strategy and present it at our Capital Markets Day.

Mitigation measures
Extensive research: Before entering a new market or region, we conduct extensive market research into growth opportunities and value creation for the medium and long term.
Site selection: We have a rigorous site selection process, driven by technology, local market insights and experience, which takes into account local competition, local demographics, local fitness penetration and required site characteristics.
Uniform club format: We have a system in place to review and register all our clubs in an automated 3D drawing system, which makes it easier to roll out a uniform club format and makes it possible to easily monitor the club with the correct data once operational.
Monitoring local laws: Our centralised international legal department closely monitors local legal and regulatory requirements in the places where we operate, with support from local external advisors if required.
Promotion: Our international marketing campaigns focus on promoting and positioning our brand and include group-wide and local marketing efforts, as well as localised sales promotions that appeal to each market.

Competition

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The health and fitness industry is highly competitive and local competitors could succeed in attracting existing and/or new members, impacting future growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • Our membership growth rates were significantly higher than those of previous years, driven by membership structure developments in all countries and in both mature and immature clubs.

  • With the acquisition of Clever Fit, we expanded our market presence from six to twelve countries, becoming not only the largest fitness franchise operator in Europe, but also the market leader in Germany.

  • We extended our market leadership in France, where the majority of our new club openings took place, and where we expanded 24/7 operations to over 300 clubs. We were an official sponsor of the Tour de France.

  • We introduced strength circuit training and 'Relax and Recover' zones in selected clubs in the Benelux capturing the fitness and wellness trends with the aim of further increasing the uptake of our Ultimate membership. We launched the ‘Boost Your Mind’ programme in conjunction with World Mental Health Day. This programme combines short, effective workouts with mindfulness exercises and practical tips for more energy, peace, and focus in daily life, and includes three two-week plans: ‘Boost Your Energy’, ‘Boost Your Zen’ and ‘Boost Your Sleep’.

  • We won the NIMA Marketing Award for best marketing company in the Netherlands, which reflected our evolution into a brand that prioritises mental and emotional well-being, leveraging customer insights and digital innovation.

Plans for 2026:
  • We will focus on optimising memberships, the profitability of new and existing clubs, and the Clever Fit integration.

  • We will continue to cater to our members' evolving needs and remain accessible to everyone.

  • We will update our strategy and present it at our Capital Markets Day.

Mitigation measures
Value-for-money: We continuously invest in offering an attractive value-for-money proposition to our existing and new members: by offering memberships at a low cost with longer opening hours.
Remote: We have opened more 24/7 clubs in the Netherlands, Belgium, Luxembourg, and France. We continue to roll out the implementation of a highly advanced remote surveillance system in some countries, to support higher levels of safety and security, as well as creating efficiencies in clubs and opening hours, all of which are in line with the highest standards of privacy compliance.
Marketing: We have localised marketing campaigns and sales promotions to win market share and increase the fitness penetration rate.
Cluster strategy: With our cluster strategy, we operate multiple clubs in close geographical proximity, thus making fitness more accessible to (potential) members.

Macroeconomic and (geo-)political risks

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The risk that market developments, such as (macro-) economic and (geo-)political developments, such as war and political unrest, inflation, natural disasters or pandemics, could have a possible adverse impact on our growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to closely monitor macroeconomic developments enabling us to adapt accordingly

  • We continued hedging interest rate risk, which reduced our vulnerability to interest rate fluctuations

  • We introduced an annual business continuity assessment to review critical business functions and define the necessary mitigation measures to minimise business continuity risks. Our smart refurbishing programme mitigates supply chain risks by reducing reliance on new equipment shipments through the refurbishment of existing fitness equipment and the extension of its useful life. Our suppliers have also introduced measures to minimise their business continuity risks.

  • We continued to be attentive to changes in regulations, i.e. regarding climate, and confirmed that developments have so far not triggered a need to modify the previous year's climate-related risks and opportunities assessment (CRRO). These risks were mapped to evaluate the resilience of our business as it related to climate-related risks.

  • Please see the 'Financial risk and inflation' risk card for details on how we managed inflation risk.

Plans for 2026:
  • We will continue working on climate change mitigation mainly through controlling our energy usage and developing adaptive solutions addressing the mapped climate change risks. We will actively work toward the development of a climate transition plan, including further steps to build a strong foundation for development. Our sustainability strategy involves other risks and impacts on people and the environment, including our employees, workers in our supply chain, our members and the communities in which we operate. See the Sustainability Statement section, subsection Climate change and energy, of this report.

  • We will continue to roll out our smart refurbishing programme, strengthening cost resilience and supply chain independence, while advancing climate goals by extending equipment life, reducing capital intensity, and lowering environmental impact.

  • We will integrate Clever Fit in our portfolio, expanding to six new countries and entering the franchise market. This move strengthens risk resilience through geographical and operational diversification while reducing capital intensity and operational risks. Please see the 'Managing Expanded Operations' risk card.

Mitigation measures
Diversified portfolio: Our diversified portfolio of over 2,150 clubs across 12 countries at year-end 2025, with local operational management and a franchise strategy to be developed, are mitigating factors against individual political, country, regional or local economic risk. We monitor these risks throughout the normal course of business.
Contribution: As the largest and fastest-growing fitness operator in Europe, we want to contribute to the growth of the entire fitness market, and we actively participate in the development of the industry and its standards at local, national and European levels. We advocate with policymakers and market stakeholders for the recognition of fitness as essential to physical and mental health and overall well-being.
Business model: We can benefit from our proposition in times of economic downturn, as people could downgrade to high-value, low-cost alternatives from mid-market and high-end offerings. Our attractive and affordable proposition enables potential customers to become members for a lower fee.
Long-term relationships: Increasing pressure on the cost of goods, shipment costs, scarcity of goods, inflation and unrest in several parts of the world, have so far not impacted Basic-Fit's potential to open clubs, due to our cooperation and long-term relationships with suppliers.
Business Continuity: Our Business Continuity Management Plan (BCMP) provides an integrated framework for the management of continuity risks. It includes sub-plans, procedures, and policies for tailored responses to incidents. As part of the BCMP, we conduct annual risk assessments of external risks that can affect critical business functions. We then identify and implement mitigation measures that reduce business continuity risks.
Water and electricity supply: Climate change is expected to increase the impact of climate-related risks in the longer-term, such as heat waves and droughts, which could impact resources supply. We constantly improve our management of energy use and control of costs.

Reputation

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The risk of negative publicity, incidents in our clubs, or ineffective marketing campaigns could have an adverse effect on the Basic-Fit brand.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to monitor our brand health and reputation across all channels and responded quickly across these channels as needed.

  • We proactively clarified our business model and brand proposition to stakeholders, highlighting the scalability and cost efficiency of our model and its potential for continued growth.

Plans for 2026:
  • We will enhance our social-media scraping capabilities—automated extraction of publicly available online content—to broaden and deepen our brand-monitoring insights.

Mitigation measures
Brand image and reputation: We have an extensive brand and corporate communications department and an investor relations department in place to manage our investor-related communications, commercial communications, corporate communications and public relations, and to protect our reputation and brand value.
Quick response system: We have insight into all publications and communications related to Basic-Fit in public markets through a news service, giving us a quick response system. If an incident occurs, we can measure the impact and take appropriate action as needed.
Monitoring our brand: We continuously monitor and track our brand recognition and awareness in the market. Basic-Fit has a strong and well-recognised brand position in the European fitness market. We also have a social listening and media monitoring system in place to monitor communications about Basic-Fit via social channels.
Integrity: The company has well embedded compliance, risk management and internal audit functions that work closely together, while respecting their independence, to mitigate risks and protect the company's integrity and reputation.

Operational Risks

Digital transformation

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The increasing demand for advanced digital capabilities poses a risk to sustaining our growth if we are unable to attract and retain top IT talent, ensure the alignment between IT and business objectives from a project's inception to its completion, and enforce stringent standards for critical software and cloud services.
Risk developments since the last assessment & future plans
Developments 2025:
  • We expanded the use of talent coaches, new development programmes, and formed additional partnerships with IT firms to address resource gaps.

  • We implemented a governance model to support structured prioritisation and initiation of initiatives. During the period, adherence to the agreed governance processes was not yet fully consistent across decision-making forums, particularly in ensuring timely involvement of all relevant business and IT stakeholders – please see enhancement actions below (amber arrows).

  • We introduced mandatory security and compliance checks in our procurement practices, embedding due diligence and external certifications.

Plans for 2026:
  • See the recommended enhancement actions below (amber arrows).

  • We will further strengthen and standardise IT General Controls for financially relevant systems, with the objective of enabling increased reliance on these controls over time. For a description of IT General Controls, please see the 'Manage IT security' risk card.

Mitigation measures
Attracting and retaining IT talent: To attract and retain top IT talent, we have branded our IT function as Basic-Fit.tech. We utilise talent coaches for development and retention and maintain partnerships with IT firms to address specialised needs and resource gaps. These efforts ensure we have a dynamic and skilled IT team ready to meet our evolving needs.
Proactive IT engagement in strategic planning: In our operational model, we have enhanced control over our IT agenda to fully support our business objectives. By actively participating as a strategic partner in the initial concept and scoping discussions across business domains, we ensure alignment on new initiatives from the outset. This proactive approach guarantees that our IT strategies are always in sync with our business goals.We will reinforce governance on objectives by re-communicating the operating model and highlighting deviations.
Reliable service providers: Prior to acquiring software tools to support business processes, engagement with IT and Legal teams is essential. For critical services, we require cloud service providers to meet specific standards, including third-party assurances and relevant certifications. This rigorous selection process ensures that we work with reliable partners who uphold the highest standards of service and security.
Digital maturity assessment: We will hire an independent external expert to perform a benchmarking of Basic-Fit's digital maturity level. This assessment will cover governance, the operating model, the technology landscape, data capability, and delivery practices. The output of the assessment will be used to validate current mitigation measures, identify potential gaps, and refine the digital transformation roadmap, including the formalisation and implementation of key digital and IT governance policies.

Suitable sites and terms

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The identification and securing of suitable new sites, obtaining necessary permits, and negotiating acceptable lease terms—both for new and existing locations—are critical to achieving our growth ambitions. Once a site has been secured, we commit to substantial lease payments, and delayed decisions to close financially underperforming clubs can adversely affect profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We established a renewal club analysis process that proactively reviews leases approaching expiry. This involves structured, multi-departmental assessments to support more strategic and effective lease renegotiations.

  • We strengthened our site evaluation capabilities by introducing a robust scoring model for our current lease portfolio. This model uses weighted parameters to perform unbiased scoring and systematically identifies potential causes of the financial underperformance of clubs.

Plans for 2026:
  • We will integrate the renewal club analysis process in our site selection tool to enhance coordination and decision-making.

  • We will expand the site scoring analysis to cover a broader population of clubs.

Mitigation measures
Real estate agents and local partners: We combine centralised and decentralised site selection and development approaches, leveraging local and regional real estate agents and dedicated contractors.
Site selection: We apply rigorous processes for site selection, the securing of new sites, and lease renewal analyses. These processes involve multiple internal departments and third parties, ensuring timely and controlled decision-making. We utilise an AI-based club layout tool, which is aimed at raising the 'success rate' of potential locations.
New Club Approval Analysis and Club Closing Assessment: New site projects require Management Board approval and a thorough investment analysis, including expected return on invested capital (ROIC). Lease contracts are signed only when a ROIC of at least 30% at maturity is expected. Club performance is monitored throughout the lifecycle, and closure decisions for underperforming clubs are made with Management Board approval.
Country expansion teams: Our knowledgeable country expansion teams support long-term growth by opening new clubs and exploring opportunities. These teams report to the centralised Real Estate function, ensuring a unified approach and alignment with the rest of the organisation to advance our real estate strategy.

Workforce and talent

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Any failure to recruit, train, motivate and retain service-minded staff in our clubs, customer care centre and HQs, or suitably qualified management, could impact future growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We finalised the leadership behaviours framework and will include it as part of our competency framework project for 2026 and 2027.

  • All global digital corporate training courses (except LinkedIn Learning) are now registered in our Learning Management System to ensure accurate tracking of learner completion data.

  • We started to focus more on ensuring our HR processes are applied consistently across all countries of operation. See our 2026 plans and actions to be implemented for more details.

Plans for 2026:
  • We will prepare for European Pay Equity Act by analysing and reviewing our job architecture and competency framework, ensuring all staff have a clear understanding of pay, roles and competencies at all levels of Basic-Fit.

  • We will continue to improve HR processes to ensure foundational processes are harmonised and sustainable for future growth. See the recommended enhancement actions below (amber arrows).

  • We will continue to integrate HR Systems with vendors i.e. learning providers, ensuring processes remain sustainable for future growth.

Mitigation measures
Continuous development: We have onboarding training and service training for club staff, in which employees are trained in many aspects and topics. For example, health and safety, company products, software systems, brand awareness, roles and responsibilities on how to run a club based on Basic-Fit standards. We also train all new Customer Service and Remote Operations managers on basic elements of communications with members and the foundations of member retention. We provide periodic webinars to club hosts and managers on basic communication and service skills.We will establish clear benchmarks for completion rates of mandatory training programmes and introduce structured follow-up protocols to ensure timely completion and consistent application across all markets.
Employee feedback: To remain an appealing employer, we aim to continuously improve our employee services through employee feedback by analysing our employee lifecycle. Currently, our analysis is focused on the beginning of the journey e.g. the candidate experience and the end of journey e.g. our offboarding survey. These are administered through our HR management tool and Microsoft tools. We analyse this data periodically and develop initiatives and strategies based on the insights gained. Additionally, every 18 months we issue our People Survey through an external objective supplier. This gives us an oversight of the complete employee experience and feeds back into our strategy development.
Mitigation measures
Performance and Talent Management: We have continuous performance and development cycles that ensure our employees are in constant dialogue with their managers about their current performance and development needs. Our cycle includes goal setting, continuous feedback and a year-end review. Our Talent Development Module enables Managers to assess Talent Potential in their teams and enables HR to use the insights to create development, engagement and retention strategies for the business. Furthermore, to ensure our employees can develop themselves in line with our business needs, we have pre-defined goals tailored for our Operations team. These goals ensure our people/employees understand what is expected of them.We will broaden the scope and consistency of talent assessments across the organisation to strengthen succession planning, leadership development, and long-term capability building.
Implemented HR systems: We have an internal communication platform in place to facilitate transparent, uniform and accessible communication with our people. This communication platform fosters employee communications and enhances the awareness of a broad spectrum of company developments. We have rolled out an Employee Information Hub in three countries to ensure we are compliant in terms of enabling our employees to have fast access to global policies and documents. Our internal communication platform also includes Manager groups to ensure we are more efficient in terms of facilitating transparent communications to all our critical stakeholders. Our HR function uses a professional HR management tool, which gives us a uniform and controlled HR approach in all of our countries, enabling us to collect and analyse the data we need; for example, global dashboards accessible to country HR teams that report headcount, diversity and turnover. These dashboards have enabled us to gain better insights and make fast and informed decisions.We will implement more robust system-based controls on how local HR teams follow the centralised processes. This could include, for example, whether letters have been sent to the candidates after certain recruitment steps have been completed and if the HR system's dashboards and reports are available to and used by local HR teams. We will strengthen system-based controls to ensure consistent adherence to centrally defined HR processes and will improve the availability and use of dashboards and reports.
Recruitment: Due to better brand recognition, we have greater visibility and are more attractive to candidates, which results in sufficient interest for vacancies. We have been making steady efforts to simplify and engage candidates across our countries. We now have simplified steps in the candidate, recruiter and hiring manager journey within our HR Management Tool, including centralised communications and notifications. This too has reduced bias in the hiring phase by issuing global interview templates. We continue to optimise our recruitment journey to further simplify the hiring process, ensuring that our managers can focus their attention on getting the right talent, in the right role, at the right time.We will further enhance oversight and monitoring of key recruitment and employee lifecycle steps to ensure consistent application of recruitment processes and timely execution of key steps across all markets.
Compensation and benefits: We have a Compensation and Benefits programme in place that includes conducting salary benchmarking in our countries of operation to ensure that our compensation levels align with market standards. This process involves comparing our salaries and benefits to external market data to ensure competitive and fair pay. We have established a comprehensive job grading system at Headquarters that all the countries are now using.We will continue to strengthen the consistent application of global reward principles and practices to support transparency, fairness, and long-term workforce sustainability.

Suppliers

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The limited number of suppliers for various aspects of our business makes us vulnerable to interruptions to existing and new operations and could impact future growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We initiated a process to diversify the supplier base in France, with assessments pending for other countries. We identified several single-supplier dependency situations, and discussions are underway with business owners to evaluate diversification opportunities. Please also see the ‘Clubs Maintenance’ risk card.

  • We hired a Procurement Manager to perform the central oversight role over procurement activities and to continue to develop standards and policies.

Plans for 2026:
  • We revised the risk appetite from medium to low in Q4 2025 to reflect our ambition to further strengthen risk discipline and resilience, and applied this revised level as the target thereafter. The enhancement actions (amber arrows) reflect the path towards this target.

Mitigation measures
Procurement governance: We currently embrace an autonomous approach, in which multiple employees (budget holders) have operational responsibilities for different procurement categories. We plan to change this to a more centralised approach, which is why we hired the Procurement Manager to perform the central oversight role over procurement activities and to develop standards and policies.We will finalise a contracting policy, which will be part of a wider procurement policy, and we will continue to develop and implement this in related processes across all departments.
Key suppliers and sourcing strategies: We maintain strong relationships with our largest suppliers and collaborate closely with them across various goods and services. We use a Requests for Proposals (RFP) approach for the selection of suppliers for new, large projects.We will gain more visibility over our spend. We are reviewing the possibility of developing and implementing long-term category management strategies that align with Basic-Fit's overall goals, as well as establishing distinct approaches for both tactical and strategic spend.
Contractual framework: By incorporating robust Service Level Agreements (SLAs), Key performance Indicators (KPIs), and penalty clauses, we hold suppliers accountable for maintaining high standards. We implemented dashboards and reporting tools in a tickets management system, where we register and communicate to suppliers all supplier-related incidents and their resolution times.We will continue improving suppliers' quality controls.

Health and safety

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Any failure to comply with external legal and regulatory requirements related to the health and safety of our employees, external parties, or customers—or to follow our internal procedures and policies—may negatively impact the company’s reputation and long-term growth. Note: topics related to facility management that involve health and safety requirements are excluded from this risk card and are addressed separately in the 'Club Maintenance' risk card..
Risk developments since the last assessment & future plans
Developments 2025:
  • We made Health and Safety a centrally managed process in the annual compliance programme, governed by a global Health and Safety (HS) Policy. Please see the newly established Central Oversight and Governance mitigation measure.

  • First-line and secondary care—provided by the Monitoring and Alarm Receiving Centre (MARC) and the Manager on Duty (MOD) team—are now centrally managed under Basic-Fit's Security function. This centralisation enhances efficiency in staff management, technical standards, operational requirements, and regulatory compliance. Two previous mitigation measures have been consolidated into one—see the Profound Security System mitigation measure.

Plans for 2026:
  • We will fully operationalise the global Health and Safety Policy across all relevant functions and geographies. See the recommended enhancement action below (amber arrow).

Mitigation measures
Central Oversight and Governance: To ensure compliance with international and local health and safety regulations, we have established a comprehensive Health and Safety Policy built on a structured, iterative methodology for continuous improvement. Through clear governance and defined procedures for monitoring incidents, regulatory compliance, and emerging trends, we aim to foster a proactive health and safety culture that prioritises the well-being of our employees and drives ongoing improvement.We will make the newly established Health and Safety Policy fully operational, with semi-annual meetings of the Steering Committee, and possibly with the establishment of a central oversight role. The policy goes beyond reporting, and also includes the setting of elaborate metrics (measurements and objectives) to implement a proactive approach to incidents.
Profound Security System: The Basic-Fit Security function oversees a 24/7 system comprising intercoms, alarm buttons, remote-controlled doors, speakers, and security cameras to optimise the safety of our members and staff. Both our EN50518:2019-certified Monitoring and Alarm Receiving Centre (MARC) and the Manager on Duty (MOD) team report directly to the Security function. MARC serves as the first line of response, handling intercom calls and performing alarm verification. The MOD team provides secondary support, operating according to comprehensive, impact-based protocols to ensure operational continuity, appropriate staffing, or temporary club closure when necessary.
Incident Reporting: We register member-related incidents in a central system, categorise them by significance, and report them to club operational management. These incidents include aggression, damage, theft, and life-threatening situations.
Prevention Officers: In all countries, we have appointed prevention officers, who are responsible for registering and following up on occupational incidents among our employees. They ensure that national occupational health and safety standards are sufficiently implemented.

Managing expanding operations

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Rapid and continuous growth can put constraints on the efficiency and availability of the centralised support organisation and requires continuous adaptation, balancing and flexibility of the strategy in line with each new phase of Basic-Fit. If we are unable to adapt and adjust our support operations in time, this could impact the company's profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • With the acquisition of Clever Fit, we expanded our market presence from six to twelve countries, becoming not only the largest fitness franchise operator in Europe, but also the market leader in Germany.

Plans for 2026:
  • We will explore the potential of expanding a franchise model under the Basic-Fit brand in our key growth markets of France, Germany, and Spain.

  • We will continue the expansion of our owned club network and we will join forces by bringing together our experience running company-owned clubs with Clever Fit's know-how in franchise operations to drive our growth strategy.

  • We revised the risk appetite from medium to low in Q4 2025 to align with the forthcoming update of our strategy, to be presented at the Capital Markets Day. This revised level will apply as the target from now on, with the enhancement action (amber arrow) reflecting the path towards this target.

Mitigation measures
Refer to relevant risk cardsManaging owned club network: We manage our own club network according to a balanced centralised vs local approach, that is described in several mitigation measures in the 'Suitable Sites and Terms'; 'Workforce and Talent', 'Suppliers', 'Health and Safety', and 'Club Maintenance' risk cards.
Managing franchised operations: We will develop and announce a clear strategy for adopting a franchising model, which will offer faster expansion opportunities through local partnerships. We will join forces by bringing together our experience running company-owned clubs combined with Clever Fit's know-how in franchise operations to drive a strong growth strategy.

Business model diversification

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
In addition to membership fees, the company offers a holistic range of fitness products and services that requires a disruptive business model. The revenue from the other operational activities and products, such as in-house NXT level nutrition products, vending machines, services of personal trainers and physiotherapists, as well as digital advertising, helps create our success. These activities are becoming increasingly important, and any major setback(s)/could have an impact on growth and profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to expand the presence of our NXT Level brand via FMCG channels (supermarkets) in the Benelux and France in 2025, which resulted in growth of revenue in this category of products.

  • For in-club media advertising, we established a 360-degree partnership with a major skincare brand, creating additional touchpoints, including floor stickers, locker doors, and in-store screens.

Plans for 2026:
  • We will continue to expand the presence of our NXT Level brand via FMCG channels (supermarkets) in the Benelux and France in 2026.

  • We will focus advertising sales on the fast-growing Spanish market.

Mitigation measures
Secondary products: We partner with suppliers and offer our members the opportunity to buy all products relevant to their fitness experience, such as padlocks, drinking bottles, towels, and NXT Level sports nutrition products. These products are available in vending machines and via the Basic-Fit webshop. We expanded the distribution of our NXT Level sports nutrition products and rolled out the sale of the products via FMCG channels.
Personal trainers: A dedicated team ensures co-operation with personal trainers within the clubs according to a Head Trainer concept. With this concept, we partner with external personal trainers who want to develop a team of personal trainers in a specific Basic-Fit location. The PTI (Personal Training Introduction) we offer to members is serviced by the certified personal trainers, all with the common goal of supporting members in their fitness journey. 
Advertising sales: We have an increased number of digital screens in our clubs for the digital out-of-home provision of media sales advertising services to our relatively young member base. This service is seeing strong demand among advertisers, as these target groups are difficult to reach via traditional media channels, such as live TV, radio and print. It is aligned with the general tendency of retail media developments, which is a growing business model.

Managing IT security

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The resilience of the Basic-Fit organisation in the face of cyber threats or a crisis is constantly under pressure. Attacks, threats and intrusion attempts are becoming increasingly sophisticated and are increasingly focusing on users. The combination of this with potential reduced awareness can result in attackers trying to gain access to our business-critical systems and data via the likes of ransomware. Not having the right procedures and controls in place could impact our business operation, our business continuity, reputation and brand. It is essential that Basic-Fit is prepared for such attacks by means of sufficient business continuity and crisis management procedures, which enable us to protect and recover our IT assets.
Risk developments since the last assessment & future plans
Developments 2025:
  • We improved IT security awareness by launching mandatory e-learning on security, privacy, and AI-related risks for all employees.

  • We improved resilience by establishing and testing disaster recovery protocols and updating business continuity management documentation.

  • We improved preparedness by conducting breach & attack simulations to assess organisational resilience.

  • We improved supplier security by implementing procedures and embedding them in the procurement practices.

  • We expanded our scope of security monitoring, increasing overall coverage and effectiveness.

Plans for 2026:
  • We will continue to improve business continuity by strengthening cyber resilience through regular penetration testing, structured vulnerability management, and disaster recovery for critical systems. See the recommended enhancement action below (amber arrow).

  • We will improve governance and awareness by enhancing security policies, training programmes, and monitoring to ensure ongoing compliance and risk mitigation.

Mitigation measures
Basic Cyber Hygiene: We maintain key cyber hygiene measures together with our security partner.
Awareness: We strengthen employee cyber resilience and awareness through a comprehensive programme that includes continuous training and awareness activities.
IT General Controls: We maintain an IT General Controls (ITGC) framework to ensure the integrity, confidentiality, and availability of our IT systems and data, mitigating risks, preventing unauthorised access, and ensuring regulatory compliance.
Business Continuity: We strengthen business continuity by assessing critical needs, establishing recovery protocols, and routinely validating restoration capabilities to minimise potential disruptions.We will continue to enhance organisational cyber resilience by strengthening safeguards around critical business processes.

Club maintenance

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
With the growth of the club portfolio, the importance of efficient club maintenance processes and systems is increasingly relevant to the management and monitoring of the quality and service levels in the clubs and safe and healthy environments for our customers and workforce. Not keeping up with this could impact profitability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to diversify our supplier base in France and Spain, as well as in our other markets.

  • Building on our existing HVAC expertise, we expanded the team to support the Benelux and Spain and initiated recruitment to strengthen capabilities in France.

Plans for 2026:
  • See the recommended enhancement action below (amber arrow).

Mitigation measures
Optimised Team Structure: We strengthened our Facility teams by adding specialised Heating, Ventilation, and Air Conditioning (HVAC) suppliers to our suppliers' pool, as well as country-specific experts. We also engaged an HVAC advisor who provides consulting support on HVAC services, including during the construction phase. In addition, we have a dedicated Facility Coordinator in each country to support the effective delivery and coordination of maintenance services.
Enhanced Supplier Management: To further enhance performance and ensure consistent service standards, our contracts include the requirement for Preventive and Corrective Maintenance reports to be delivered after every intervention. We have defined clear and comprehensive HVAC Planned Maintenance Specifications, and the report templates were built using these specifications to ensure complete, accurate, and standardised documentation across all countries.
Strengthened Contract Management: By incorporating robust Service Level Agreements (SLAs), Key Performance Indicators (KPIs), and penalty clauses, we have strengthened supplier accountability and established a more structured framework for performance management. We successfully implemented and signed these agreements in France and Spain, while the Benelux is still in progress.We will minimise the amount of maintenance services delivered without contracts.
Continuous Improvement Programme: We are committed to the proactive, ongoing assessment and enhancement of our maintenance processes through a structured Continuous Improvement Plan. This approach enables us to identify and address emerging challenges, mitigate health and safety risks, adapt to evolving operational and compliance requirements, and maintain high standards across all clubs. For more details on our policies and governance, please also see our 'Health and Safety' risk card.

Financial Risks

Financial risk and inflation

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
In line with our growth strategy, we manage a large number of capital-intensive projects to expand our club base. Overspending or price increases due to market developments or inflation could impact our cash flows. Lack of cash generation impacts the company's capital expenditure capability.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to strictly follow the site selection and investment approval processes, while managing the costs of club openings.

  • We reduced the number of new (owned) club openings to strengthen our balance sheet and increase net cash flow.

Plans for 2026:
  • We will continue to focus on the growth and profitability of our existing clubs. At the same time, we will continue to reduce the number of owned club openings, while developing a franchise model strategy to enable faster and more capital-efficient expansion. This capital-efficient strategy will enable us to generate additional cash.

Mitigation measures
CapEx planning: Each new club analysis process includes a detailed investment plan, and the required expansion and maintenance capital expenditure is analysed on a club-by-club basis.
Price risk: The centralised property department controls all our investments and tries to minimise the price risk. Please also see the ‘Suppliers’ risk card for other price-related risk mitigation measures.

Liquidity risk

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
We require access to capital to fund our growth ambitions. Any constraints on such access could limit our ability to execute our growth strategy.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to closely monitor our long-term cash flow expectations to be able to increase our available liquidity in a timely fashion if required.

  • We continued to be flexible with our club openings, to adapt to market developments and ensure we maintain sufficient financial liquidity.

Plans for 2026:
  • We will continue to closely monitor our long-term cash flow expectations to be able to increase our available liquidity in a timely fashion if required.

  • We will continue to focus on the growth and profitability of our existing clubs. At the same time, we will continue to reduce the number of owned club openings, while developing a franchise model strategy to enable faster, more capital-efficient expansion. This more capital-efficient strategy will enable us to generate additional cash.

  • We have bank financing in place to meet any redemption requests from convertible bond holders who wish to exercise the put option in 2026. At any rate, we will maintain a comfortable liquidity.

Mitigation measures
Fund our growth: Over the past few years, we have mainly relied on debt to finance our growth plans. In addition to our bank facilities, we issued a convertible bond.
Cash flow forecast: Cash is managed daily, while management prepares a monthly cash flow forecast to identify the company’s short-term cash needs.
Monitoring: We monitor our long-term liquidity needs on a quarterly basis.
Ample liquidity: Basic-Fit strives to have ample available liquidity to execute its growth strategy and to cope with unforeseen events that might have a negative cash impact. The aim is to have a minimum available liquidity of 10% of the Last Twelve Months (LTM) revenue.

Credit risk

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
The payment behaviour of our existing and future members could change, which would have an impact on our profitability and cash flows.
Risk developments since the last assessment & future plans
Developments 2025:
  • B2C continued to operate smoothly following the 2024 refinements to dunning (customer payment reminder and collection) processes, supported by a stable and experienced team. We strengthened B2B through the standardisation, automation, and improved communication of data.

Plans for 2026:
  • We will support operational and financial integration of the franchise business, plus assist with the adoption of EU-required invoicing processes.

Mitigation measures
Membership fees: As members need to pay membership fees upfront, credit risk is limited to those membership fees that cannot be collected upfront.
Collection agencies: We have a designated credit management department and we use collection agencies for receivables that have been past due for more than 120 days.
Cash: We avoid the concentration of credit risk with banks by spreading cash and cash equivalents over various reputable banks.
Credit Management Tool: We have implemented a credit management tool with tailored workflows and a personalised reminder process.

Currency and interest rate

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Significant changes in financial markets could impact our financial condition or performance.
Risk developments since the last assessment & future plans
Developments 2025:
  • In the year under review, we maintained a hedge ratio sufficient to cover at least 50% of our interest rate risk exposure, in line with our Treasury policy. Following the Clever Fit acquisition in November, our hedge ratio decreased to 40%. As we plan to limit owned club openings to 50 in 2026 - supporting a significant cash inflow - we expect the hedge ratio to increase to above 50% in 2026 and have therefore not taken any additional hedging actions.

  • The Clever Fit acquisition was financed through bank facilities. This increased our interest rate risk exposure, which was mitigated by increasing the hedged notional amount.

  • The acquisition of Clever Fit brought with it foreign currency risks. This is still limited and has not yet been hedged.

Plans for 2026:
  • We will actively manage our hedged notional to reflect a more capital-efficient growth strategy and potential convertible bond refinancing, ensuring an appropriate level of IRR hedging.

Mitigation measures
Currency: Basic-Fit operates mainly in the Eurozone, and we mitigate the limited currency conversion risk by purchasing in euros and entering into multi-year contracts with our equipment suppliers. With the acquisition of Clever Fit, we now also have limited foreign currency exposure risks, and we will look into acceptable levels of FX exposure risks and mitigating actions.
Interest rate: Interest rate risk arises from the bank financing facilities, which are linked to EURIBOR. With various hedge contracts in place, we aim to hedge a minimum of 50% of our variable interest exposure. We use floating-to-fixed interest rate swaps (IRS) to achieve this goal. An increase of 100 basis points in Euribor would result in an approximately €2.3 million increase in net profit (based on exposure at year-end 2025). This impact reflects the non-hedged floating rate borrowings, as well as valuation changes of the derivative financial instruments. Excluding valuation changes of derivative financial instruments would result in a decline of €4.2 million in net profit.

Tax and accounting

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Changes in tax and accounting legislation and standards may impact the reliability and consistency of our financial and tax reporting and, as a result, the quality of information used for decision-making.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continued to prepare for regulatory developments and new and changing tax-related legislation in all countries in which we operate clubs. Examples include legislation and changes to legislation issued by the European Union - like the ViDA roll-out, or updates issued by the OECD and subsequent guidelines stemming from those updates such as (public) CbCR and Pillar Two. In addition, Basic-Fit has voluntarily committed to comply with the Dutch Tax Governance Code, introduced in 2022, and has published its first tax transparency report alongside this annual report. Please see the Our Strategy section, subsection 'Approach to tax' of this report.

  • We integrated IT application controls in our Internal Control System and developed a testing methodology for these controls to further strengthen our robust approach to reliable financial reporting.

  • We fulfilled the requirements of the updated 2025 Dutch Corporate Governance Code related to the risk management statement (Verklaring omtrent risicobeheersing – VOR) applicable to listed companies. In doing so, we developed a company-wide methodology for conducting Enterprise Risk Assessments. For further details, please see the Risk management and control systems section of this report.

Plans for 2026:
  • We will continue to enhance our internal control framework by incorporating additional key processes and related controls to align with our evolving business landscape, including the Clever Fit acquisition.

  • We will continue to enhance our VOR methodology, based on input from internal and external stakeholders.

  • As a module within the internal control framework, we have established a tax control framework aimed at ensuring compliance with tax laws and regulations, mitigating risks, and effectively managing tax-related processes. The framework will initially focus on master data controls and will continue to build on and expand the manual tax controls already included in the internal control framework.

Mitigation measures
Internal Control Systems: Based on our internal control framework, we monitor control activities to ensure we obtain reasonable assurance that our financial reporting is free from material misstatements. We continuously enhance this framework in response to external and internal audit findings, as well as through our own improvement initiatives. When we identify control deviations or misstatements, we undertake corrective actions.
Tax Control Framework: based on our Tax Control Framework, supported by external advisors and auditors, we monitor tax-related processes and controls to ensure the accuracy and completeness of tax returns and disclosures in alignment with applicable regulations and OECD principles.

Compliance Risks

Regulatory

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Failure to comply with applicable laws and regulations, and with internal policies established to support regulatory compliance, could have a negative impact on our reputation, future growth and profitability. Furthermore, the regulatory framework is becoming increasingly complex, with numerous developments and new (European) laws due to come into effect in the years ahead. Following the acquisition of Clever Fit, six additional countries with their own national laws, legislative processes, and interpretations of European legislation must also be taken into account.
Risk developments since the last assessment & future plans
Developments 2025:
  • We strengthened our business continuity management by introducing formalised annually recurring processes to address continuity risks in critical business functions. Business Continuity Management is part of the Annual Compliance Plan.

  • We updated our Code of Conduct to provide clearer guidance on conflicts of interest, receiving gifts and anti-bribery controls.

Plans for 2026:
  • We plan to monitor and evaluate the health and safety policy on an annual basis to ensure that we remain aligned with laws and standards. Please see the ‘Health and Safety’ risk card.

Mitigation measures
Laws and regulations: We are committed to complying with the legal and regulatory requirements of the countries in which we operate. In specialist areas, the relevant country and centralised support teams are responsible for setting detailed standards to comply with legal and regulatory requirements that are relevant to their roles. We keep track of new laws and closely monitor whether they are, or may become, applicable to Basic-Fit. We also report on non-compliance issues to prioritise mitigating measures to management.
Legal, Risk and Compliance department: We have a well-embedded centralised Legal, Risk, and Compliance department, consisting of legal professionals for all jurisdictions, as well as a Risk and Control team, and a dedicated Compliance and Data protection team. The department's main focus is on compliance with legal and regulatory requirements in line with the business strategy and protecting the integrity and reputation of the Basic-Fit brand.
Mitigation measures
Annual compliance plan: We prepare an annual compliance plan to identify and address the most significant risks and topics and follow up on mitigating these risks, including a Business Continuity Assessment. This plan includes the most significant internal policies, Identified non‑compliance situations are assessed based on their nature, impact and likelihood and addressed through appropriate actions in line with the company’s risk appetite.
Aligned processes: The second line of defence (Risk and Control, Compliance and Privacy and IT security) and the internal audit function keep one another informed and share their activities and findings in quarterly meetings. On the basis of audits performed by the internal auditor, the second line of defence keeps track of findings and their follow up.
Integrity/fraud prevention: We conduct an integrity/ fraud risk assessment on an annual basis, based on the SIRA (Systematic Integrity Risk Analysis) model to assess integrity risks. We regularly review and update our Code of Conduct.

Sustainability governance

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
Basic-Fit is committed to integrating Environmental, Social, and Governance (ESG) principles in our business operations. However, the need to adapt to a continuously evolving regulatory landscape - including the introduction of the European Sustainability Reporting Standards (ESRS) and EU Taxonomy - presents potential risks in maintaining adequate governance of the sustainability reporting process. Additionally, limited data availability or inadequate data management systems may lead to risks related to accurate and timely disclosure.
Risk developments since the last assessment & future plans
Developments 2025:
  • We continuously monitor developments in the European regulatory environment, in particular the legal processes initiated in 2025. Specifically, we reviewed sustainability reporting requirements, including the Omnibus discussions affecting the European Sustainability Reporting Standards (ESRS) and the EU Taxonomy. This monitoring enables us to understand and prepare for upcoming regulatory changes and to adapt our reporting and processes as new requirements become applicable.

  • We applied lessons learned from preparing our first sustainability statement by initiating targeted improvement actions, including projects to enhance data quality (for example, remuneration metrics), the implementation of an automated system to support sustainability reporting, and preparations for reporting on additional metrics, such as training and skills development. In addition, we reassessed the outcomes of the double materiality assessment (DMA) performed in 2024 as the basis for our 2025 reporting and concluded that the identified impacts, risks, and opportunities (IROs) remain valid.

  • We continued to apply our internal control framework (ICF) to sustainability reporting, with data control processes for electricity and gas consumption, as energy use is a key material sustainability matter.

  • See other relevant information in the Sustainability Statement of this report, specifically in the Governance of Sustainability Matters sub-section.

Plans for 2026:
  • We plan to further refine the functionalities of the automated sustainability reporting system as it moves through its initial implementation phase.

  • We will carry out a new DMA to ensure we have an updated understanding of our material IROs. Its outcomes, beyond being valuable for our business strategy, will also serve as the basis for our sustainability reporting.

Mitigation measures
Internal Control System: Based on our ICF, we continuously monitor and review the effectiveness of controls related to gas and electricity data. Additionally, other areas are under review in closer cooperation between the control, compliance, and sustainability reporting teams.
Dedicated Team: The Director of Treasury, Investor Relations, and Sustainability is responsible for the development and execution of the strategy. The Director is supported by a dedicated team, who ensure understanding of the scope of required disclosure, manage the rollout of plans, liaise with key stakeholders for reporting, and monitor the evolution of reporting regulations. This team includes the Sustainability Reporting Manager and sustainability reporting specialists.
Top Management Accountability: The objectives of the Management Board for 2025 were aligned with the company's sustainability strategy through a shared focus on business growth and operational performance that supported the scalability and affordability of fitness services, and contributed to the 'Fitter people' and 'Fitter communities' pillars. Furthermore, the CEO’s specific objective to launch the franchise model supported the expansion of the company's reach, while the CFO’s objectives included a specific target related to the development of sustainability performance measurement and reporting.
Periodic reviews: Periodic review or specific assessments to ensure compliant reporting, e.g., materiality and/or climate-related risks and opportunities.

Data protection and AI

Risk categoryRisk severityRisk appetiteRisk tendencyRisk response
StrategicHighHigh
Mitigate
OperationalMediumMedium
Transfer
FinancialLowLow
Avoid
Compliance Averse Accept
Risk description
It is of the utmost importance that our general data and other privacy-sensitive data is secure and processed responsibly. Failure to follow the right procedures and respect rules and regulations could impact our continuity, image, and brand, which could in turn have an adverse impact on the company's profitability and reputation. The use of artificial intelligence tools can lead to infringements of confidentiality, privacy rights, copyrights and misuse. Nevertheless, Basic-Fit strives to balance these risks with the opportunities that responsible use of data and AI can bring, supported by strong governance and compliance frameworks.
Risk developments since the last assessment & future plans
Developments 2025:
  • We conducted AI impact assessments on new AI tools (Ruby chatbot in BF app, smart cameras in 24/7 clubs, AI features in Fitbuddy app) to ensure compliance with the AI Act.

  • We enhanced employee awareness through mandatory training on security, privacy and safe use of AI.

  • We performed a survey for all employees and interviews with frontrunners to map employee use of open AI tools and identify need for responsible use and support.

  • We published an AI Governance Policy to ensure AI is developed and used responsibly, ethically, and transparently.

Plans for 2026:
  • AI literacy: we will embed responsible AI use through mandatory e-learning and targeted training, ensuring awareness and consistent adoption across the organisation. See below the recommended enhancement action (amber arrow) to the 'AI governance and training framework'.

  • Privacy: we will enhance the Data Protection officer's organisational independence: see below the recommended action (amber arrow) to the 'Privacy compliance programme'.

  • Integrated approach: we will combine AI literacy and AI governance to foster a culture of responsible data use that enables innovation, while protecting privacy and trust.

Mitigation measures
Data protection: We have policies and responsibilities in place regarding data protection and GDPR compliance. Now that Basic-Fit is becoming an increasingly data-driven company, this topic will also become more important in the coming years. We have a data protection and security officer in place to support and advise the responsible managers and to periodically monitor and improve all existing procedures.
Safeguarding privacy rights: We have an adequate process in place with respect to privacy requests and complaints, which makes it easier for members to submit a request and for us to handle it within the legal parameters.
IT Security & Privacy Office: We installed our IT Security & Privacy Office together with an external partner, to monitor our IT security risks, security incidents and data breaches, and to implement solutions to mitigate cybersecurity risks.
Privacy compliance programme: We continuously monitor and improve our policies, procedures, the register of processing activities and our websites with respect to GDPR compliance, including up-to-date privacy and cookie statements and our camera policy.We will continue to strengthen the organisational independence of the Data Protection Officer (DPO) function to avoid any potential conflicts of interest, in line with GDPR expectations.
AI governance and training framework: We will establish an AI governance and training framework to ensure responsible, compliant, and consistent AI use across the organisation.