Status of Risk Management
Status of Risk Management
Risk Management Policy
The risk management policies and procedures of the Company and its subsidiaries were approved by the Board of Directors at the 15th meeting of the 9th Board on August 9, 2024. In line with the Company’s overall operating strategies, various types of risks are identified and defined, and a risk management framework is established to enable early identification, accurate assessment, effective supervision, and rigorous control of risks. Within an acceptable level of risk tolerance, the Company seeks to prevent potential losses and continuously adjusts and improves best risk management practices in response to changes in internal and external environments. These efforts aim to safeguard the interests of employees, shareholders, business partners, and customers, enhance corporate value, and achieve optimal allocation of corporate resources.
Scope of Risk Management
The Company’s risk management is conducted through a systematic process encompassing risk identification, risk assessment, risk response, risk monitoring, and risk reporting, in order to define the scope of operational risks and adopt appropriate measures to ensure effective management of related risks. The scope of the Company’s risk management covers the management of operational risks, financial risks, environmental risks, and business risks.
Organizational Structure
Operational Status in 2025 (Reported to the Board of Directors on December 16, 2025)
| Risk Item | Risk Level | Risk Identification and Assessment | Risk Response or Control Measures | Operational Status in 2025 |
|---|---|---|---|---|
| Reputation Risk | Low | Bad debt losses from accounts receivable |
|
|
| Strategic Planning Risk | Medium | Over-concentration of sales |
|
|
| Legal Compliance Risk | Medium | Unintentional violation of laws and regulations |
|
|
| Green Procurement Risk | High | Suppliers failing to comply with environmental, occupational safety, or labor rights requirements |
|
|
| Talent Recruitment and Training Risk | High | Difficulties in talent recruitment and loss of key personnel |
|
|
| Occupational Health and Safety Risk | Low | Labor safety and health |
|
|
| Information Processing and Technology Risk | High | Data leakage or damage due to cyberattacks |
|
|
| Information Processing and Technology Risk | High | Insufficient employee information security awareness |
|
|
| Information Processing and Technology Risk | Medium | Inadequate cybersecurity protection and incident response |
|
|
| Information Processing and Technology Risk | Medium | Cybersecurity vulnerabilities arising from AI development |
|
|
| Risk Item | Risk Level | Risk Identification and Assessment | Risk Response or Control Measures | Operational Status in 2025 |
|---|---|---|---|---|
| Investment Risk | Medium | Derivative transactions and long- and short-term investments |
|
|
| Exchange Rate and Interest Rate Risk | Medium |
|
|
|