Establishment of the Risk Management Policy:
The Company's "Policy and Procedures for Risk Management" (hereinafter referred to as the "Policy and Procedures") have been established by the Audit Committee and the Board of Directors in May 2021 and serves as the highest guiding principles and procedures for the Company's risk management. The Policies and Procedures clearly define the Company's management goals, organizational structure and responsibilities, and management procedures to effectively identify, measure, and control all various risks of the Company. In this way, the Company may contain the risks incurred from business operation in an acceptable range, to ensure the continuity of operation and protect the rights and interests of stakeholders.
Organization Structure and Operation:
In accordance with the Policy and Procedures, each department had established a risk management team in 2021, which is led by the respective department head, to be responsible for the risk management implementation in daily operations. The Strategy Research Unit (SRU) of the President Office will coordinate and review the suitability and adequacy of the risk management implemented by each team. The SRU is also responsible for submitting a risk management report to the audit committee and the board of directors annually.
The latest risk management report was published on December 10, 2025. The report includes current risks identified by each unit, based on frequency and impact severity, as well as viable mitigation measures.
2025 Risk Management Status Report:
The Company's "Policy and Procedures for Risk Management" (hereinafter referred to as the "Policy and Procedures") have been established by the Audit Committee and the Board of Directors in May 2021 and serves as the highest guiding principles and procedures for the Company's risk management. The Policies and Procedures clearly define the Company's management goals, organizational structure and responsibilities, and management procedures to effectively identify, measure, and control all various risks of the Company. In this way, the Company may contain the risks incurred from business operation in an acceptable range, to ensure the continuity of operation and protect the rights and interests of stakeholders.
Organization Structure and Operation:
In accordance with the Policy and Procedures, each department had established a risk management team in 2021, which is led by the respective department head, to be responsible for the risk management implementation in daily operations. The Strategy Research Unit (SRU) of the President Office will coordinate and review the suitability and adequacy of the risk management implemented by each team. The SRU is also responsible for submitting a risk management report to the audit committee and the board of directors annually.
The latest risk management report was published on December 10, 2025. The report includes current risks identified by each unit, based on frequency and impact severity, as well as viable mitigation measures.
2025 Risk Management Status Report:
- The Company has established the "Policy and Procedures for Risk Management," approved by the Audit Committee and the Board of Directors, to serve as the highest guiding principle for the Company's risk management. The Strategy Research Unit of the Office of the President is responsible for coordinating the operations of risk management to ensure the mechanism's adequacy. In accordance with regulations, this unit annually submits a report on the status of risk management operations to the Audit Committee and the Board of Directors.
- The Company's risk management system is fully integrated with its operational strategies and performance objectives to mitigate all factors that may impede the achievement of corporate goals. By regularly compiling updates to the risk files of each division, the Cross-divisional Risk Management Team reviewed the identified risks and control measures in April and September 2025 to achieve risk management objectives. This process also included making appropriate adjustments based on market changes in the first and second halves of the year.
- This report presents risk assessment conclusions and a summary of the Company's high-risk items and items warranting continued observation, which are listed as follows:
| Strategic risks | |
|---|---|
Status description
|
Risk mitigation and response measures
|
|
|
| Climate change/ environment protection-related risks | |
|---|---|
Status description
|
Risk mitigation and response measures
|
|
|
| Operating risks | |
|---|---|
Status description
|
Risk mitigation and countermeasures
|
|
|
|
|
| Financial risks | |
|---|---|
Status description
|
Risk mitigation and response measures
|
|
|
|
|
| Information Risk | |
|---|---|
Frequent cyberattacks -
|
Risk mitigation and response measures
|
| Legal compliance and integrity risks | |
|---|---|
Status description
|
Risk mitigation and response measures
|
| Other Emerging Risks – Geopolitical Risk | |
|---|---|
Status description
|
Risk mitigation and countermeasures
|
