Risk Management Policies & Procedures
To strengthen corporate governance and establish an effective risk management system for stable operations and sustainable development, we have formulated the "Risk Management Policies and Procedures" under reference to the Sustainable Development Best Practice Principles for Listed Companies, the Risk Management Best Practice Principles for Listed Companies, and our company's own Sustainable Development Best Practice Principles. This policy was approved by the Board of Directors on March 9, 2026.
Risk Management Operations
1. To demonstrate integrity, sound corporate governance, and enhance transparency for stakeholders, all risk management processes and results must be recorded, reviewed, reported, and properly archived in accordance with our "Risk Management Policies and Procedures." This includes risk identification, risk analysis, risk evaluation, risk response and monitoring, relevant information sources, and risk assessment results.
2. The Risk Management Team shall report risk management operations to the Audit Committee and Board of Directors at least once a year.
3. Operations in 2026:
• March 9, 2026: Formulated the "Risk Management Policies and Procedures".
• August 28, 2026: Reported the "2026 First-Stage Risk Identification Procedures and Results" to the Audit Committee and Board of Directors.
Risk Management Framework
The company establishes a top-down risk management structure. In addition to having the Board of Directors act as the highest governing body, a Risk Management Team is formed. The Risk Management Team submits an annual report summarizing execution status, major risk assessments, and countermeasure plans to the Audit Committee and the Board. The members of this team consist of representatives from relevant departments.
Highest Governing Body
Responsible for approving risk management policies and frameworks, ensuring system effectiveness, and establishing a culture of integrity and risk awareness.
Oversight & Review
Assists the Board in monitoring internal controls, ensuring financial statement authenticity, and reviewing major risk control matters.
Execution & Control
Composed of heads of operational units and executing staff, responsible for identifying, analyzing, evaluating, and responding to risks in daily management.
Risk Management Procedures
Our risk management process consists of five progressive steps: risk identification, risk analysis, risk evaluation, risk response and monitoring, and risk reporting and disclosure, systematically assessing operational threats.
Risk Identification
Based on the principle of materiality, strategic objectives, and the Board-approved policies, the Risk Management Team identifies risks across various domains (such as strategic, operational, financial, information security, and other operation-related risks) at least once a year at both the management and operational levels, reporting findings to the Audit Committee.
Risk identification tools are used to thoroughly evaluate potential risk events that may cause loss or negative impacts, considering historical experiences, data, internal/external risk factors, and stakeholder concerns through a dual-way (top-down and bottom-up) analysis.
Risk Analysis
Assesses identified risks in light of risk appetite and risk tolerance:
1. Evaluates the probability and severity of risk events to determine the priority of control measures.
2. Uses statistical analysis and quantitative tools for measurable risks.
3. Uses qualitative analysis (textual description) for risks that are difficult to quantify.
4. Risk Appetite: Prioritizes and allocates sufficient resources to control risks exceeding acceptable thresholds, ensuring compliance with relevant rules in daily operations.
5. Risk Tolerance: The overall capacity or maximum manageable level of risk the company can bear.
Risk Evaluation
Executing personnel, in collaboration with business units, rank risks based on the analysis results and current control effectiveness against the approved risk appetite and levels. This helps prioritize risk items and guide the selection of response actions. All analysis and evaluation results are recorded and submitted to the Risk Management Team for approval.
Risk Response & Monitoring
Based on strategic goals, stakeholder views, risk appetite, and available resources, executing staff and business units select response strategies or implement risk mitigation plans, establishing prevention, response, crisis management, and business continuity plans to manage risks effectively and balance objectives with cost-benefit ratios.
Key performance indicators (KPIs) are developed to monitor risks continuously, reporting to the Risk Management Team and keeping records.
Risk Reporting & Disclosure
1. To demonstrate integrity and improve transparency, all risk management processes and results (including identification, analysis, evaluation, response, and monitoring) are recorded, reviewed, reported, and properly archived for reference.
2. The Risk Management Team reports the risk management operations to the Audit Committee and the Board of Directors at least once a year.
3. The policy, organization, and annual execution status are publicly disclosed and regularly updated in the annual report, official website, or Sustainability Report.