Risk Management Policy and Procedures
To strengthen corporate governance and establish sound risk management operations, the Company’s Board of Directors approved the Risk Management Policy and Procedures on December 19, 2024. These procedures guide all units to effectively identify, measure, monitor, and control risks in their business operations. The scope covers four major aspects: corporate governance, environmental protection, social inclusion, and innovation value, keeping risks within an acceptable level and supporting the Company’s sustainable operations.
Risk Management Organization Structure
Board of Directors
The highest responsible unit, responsible for approving risk management policies, supervising overall implementation, and ensuring effective risk control.
Audit Committee
Assists the Board of Directors in fulfilling its duties. A Risk Management Team is established under it and reports operational status to the Committee and the Board every six months.
Risk Management Team
Composed of the highest-level supervisors from each unit, responsible for ensuring that operating units properly implement the system and appoint execution personnel.
Risk Management Office
Handles matters assigned by the convener and assists in establishing, promoting, maintaining, and reviewing the risk management mechanism.
Audit Office
An independent unit that prepares the annual audit plan, audits risk-related activities, and provides recommendations to ensure that key risks are properly managed.
Risk Management Operation Summary
The 2025 risk management implementation progress reports were respectively submitted to the Audit Committee and the Board of Directors on August 5, 2025 and December 16, 2025, ensuring the effective operation of the management mechanism.
Information Security Policy and Management
To protect the confidentiality, integrity, and availability of the Company’s information assets, the Company has established the Information Security Policy in accordance with the Information Security Control Guidelines for TWSE/TPEx Listed Companies.
Information Security Management Goals
- Protect Information Assets:Prevent unauthorized access and modification.
- Regulatory Compliance:Comply with laws and continuously update policies.
- Awareness Enhancement:Conduct regular training to strengthen protection awareness among all employees.
- Business Continuity:Implement security controls and emergency response plans.
- Customer Satisfaction:Provide reliable services and enhance customer confidence.
Scope of Application
Applies to all employees, contractors, partners, and third parties who access the Company’s information assets, covering all information systems, networks, and data assets.
| Information Security Organization Role | Responsibilities |
|---|---|
| Convener | Served by the Chief Information Security Officer, responsible for coordinating departments in formulating and implementing information security policies and goals, and regularly reporting implementation status to the Board. |
| Dedicated Information Security Supervisor | Appointed by the convener, mainly responsible for internal information security management, status monitoring, responding to external control requirements, and handling related incidents. |
| Information Security Audit Unit | Assigned by the Audit Office, responsible for conducting internal and external information security audit tasks and ensuring compliance with regulations. |
| Information Security Promotion Unit | Served by relevant department supervisors, responsible for supporting information security policies and actively promoting and implementing internal department information security management. |
| Information Security Management and Document Control Unit | Responsible for daily information security management, records, response, and maintenance, as well as archiving and version control of information security documents. |
2025 Information Security Implementation Results
The Company continued to implement information security management, with no major information security incidents or operational damage during the year.
A total of 160 employees participated in social engineering training; vulnerabilities on 30 major server hosts were remediated; external information operation audits conducted with CPAs found no major deficiencies.
The Company officially introduced ChatGPT Business and GitHub Copilot Enterprise to improve development productivity and optimize decision-making quality.
Off-site backup data recovery drills were conducted; MDR external expert monitoring services were fully introduced for core business systems.
Intellectual Property Management Plan and Results
To strengthen and protect advanced industrial technologies and R&D achievements, the Company has established a management system based on patent, trademark, copyright, and trade secret laws.
Covers patent applications, technical assessments, and patent map expansion. An internal invention reward mechanism is established to encourage employees to propose R&D achievements.
Document classification is implemented; all employees sign confidentiality agreements (NDAs), and dedicated agreements are signed for core projects. Onboarding and offboarding communication is strictly implemented.
2. Professional Training:In February 2025, training on the Personal Data Protection Act and Trade Secrets was updated; in November, patent infringement assessment training was conducted and regulatory compliance self-assessment was completed.
3. Management Policy:The Company continues to strengthen evaluation and analysis before patent applications to enhance core technology protection. Currently, it has obtained 19 Cases.
| Category (as of the end of 2025) | Taiwan | China | Others (Japan / Korea) | Total Approved | |||
|---|---|---|---|---|---|---|---|
| Invention | Utility Model | Invention | Utility Model | Invention | Utility Model | ||
| Approved Patents (Pending) | 30 (4) | 82 (1) | 12 (8) | 59 (2) | 4 (2) | 0 | 187 Cases |
| Approved Trademarks (Pending) | 15 (8) | 4 | - | 19 Cases | |||