Risk Management Policy and Procedures

 
RISK MANAGEMENT POLICY

Risk Management Policy and Procedures

To strengthen corporate governance and establish sound risk management operations, the Company’s Board of Directors approved the Risk Management Policy and Procedures on December 19, 2024. These procedures guide all units to effectively identify, measure, monitor, and control risks in their business operations. The scope covers four major aspects: corporate governance, environmental protection, social inclusion, and innovation value, keeping risks within an acceptable level and supporting the Company’s sustainable operations.

 

Risk Management Organization Structure

Board of Directors

The highest responsible unit, responsible for approving risk management policies, supervising overall implementation, and ensuring effective risk control.

Audit Committee

Assists the Board of Directors in fulfilling its duties. A Risk Management Team is established under it and reports operational status to the Committee and the Board every six months.

Risk Management Team

Composed of the highest-level supervisors from each unit, responsible for ensuring that operating units properly implement the system and appoint execution personnel.

Risk Management Office

Handles matters assigned by the convener and assists in establishing, promoting, maintaining, and reviewing the risk management mechanism.

Audit Office

An independent unit that prepares the annual audit plan, audits risk-related activities, and provides recommendations to ensure that key risks are properly managed.

Risk Management Operation Summary

The 2025 risk management implementation progress reports were respectively submitted to the Audit Committee and the Board of Directors on August 5, 2025 and December 16, 2025, ensuring the effective operation of the management mechanism.

Information Security Policy and Management

To protect the confidentiality, integrity, and availability of the Company’s information assets, the Company has established the Information Security Policy in accordance with the Information Security Control Guidelines for TWSE/TPEx Listed Companies.

Information Security Management Goals

  • Protect Information Assets:Prevent unauthorized access and modification.
  • Regulatory Compliance:Comply with laws and continuously update policies.
  • Awareness Enhancement:Conduct regular training to strengthen protection awareness among all employees.
  • Business Continuity:Implement security controls and emergency response plans.
  • Customer Satisfaction:Provide reliable services and enhance customer confidence.

Scope of Application

Applies to all employees, contractors, partners, and third parties who access the Company’s information assets, covering all information systems, networks, and data assets.

Information Security Organization Role Responsibilities
Convener Served by the Chief Information Security Officer, responsible for coordinating departments in formulating and implementing information security policies and goals, and regularly reporting implementation status to the Board.
Dedicated Information Security Supervisor Appointed by the convener, mainly responsible for internal information security management, status monitoring, responding to external control requirements, and handling related incidents.
Information Security Audit Unit Assigned by the Audit Office, responsible for conducting internal and external information security audit tasks and ensuring compliance with regulations.
Information Security Promotion Unit Served by relevant department supervisors, responsible for supporting information security policies and actively promoting and implementing internal department information security management.
Information Security Management and Document Control Unit Responsible for daily information security management, records, response, and maintenance, as well as archiving and version control of information security documents.
2025

2025 Information Security Implementation Results

2025 Results: Zero Major Information Security Incidents
The Company continued to implement information security management, with no major information security incidents or operational damage during the year.
April - August: Security Audits and Vulnerability Remediation
A total of 160 employees participated in social engineering training; vulnerabilities on 30 major server hosts were remediated; external information operation audits conducted with CPAs found no major deficiencies.
September: Technology Innovation and AI Security Governance
The Company officially introduced ChatGPT Business and GitHub Copilot Enterprise to improve development productivity and optimize decision-making quality.
November - December: Disaster Recovery Drills and External Monitoring
Off-site backup data recovery drills were conducted; MDR external expert monitoring services were fully introduced for core business systems.

Intellectual Property Management Plan and Results

To strengthen and protect advanced industrial technologies and R&D achievements, the Company has established a management system based on patent, trademark, copyright, and trade secret laws.

Patent Protection and Innovation Incentives

Covers patent applications, technical assessments, and patent map expansion. An internal invention reward mechanism is established to encourage employees to propose R&D achievements.

Trade Secrets and Confidentiality Agreements

Document classification is implemented; all employees sign confidentiality agreements (NDAs), and dedicated agreements are signed for core projects. Onboarding and offboarding communication is strictly implemented.

2025 Intellectual Property Implementation Results and Goals:
1. Patent Results:As of the end of 2025, the Company has accumulated 187 patents.
2. Professional Training:In February 2025, training on the Personal Data Protection Act and Trade Secrets was updated; in November, patent infringement assessment training was conducted and regulatory compliance self-assessment was completed.
3. Management Policy:The Company continues to strengthen evaluation and analysis before patent applications to enhance core technology protection. Currently, it has obtained 19 Cases.
Category (as of the end of 2025) Taiwan China Others (Japan / Korea) Total Approved
Invention Utility Model Invention Utility Model Invention Utility Model
Approved Patents (Pending) 30 (4) 82 (1) 12 (8) 59 (2) 4 (2) 0 187 Cases
Approved Trademarks (Pending) 15 (8) 4 - 19 Cases

Related Regulations and Report Downloads

Back