Risk Management
Risk Management
Risk Management Policy
The Company's risk management policy is to shape a top-down business strategy and organizational culture that emphasizes risk management, and establishes an overall risk management system, which is jointly promoted and implemented by the board of directors of the Company , management personnel and employees at all levels. In accordance with the Company's overall operating policy, various risks are defined, and a risk management mechanism for early identification, accurate assessment, effective supervision and strict control of potential risks is established to maintain various risks that may be faced in operating activities within the range that can be tolerated, prevent possible losses, and serve as a reference for the formulation of business strategies, in order to reasonably ensure the achievement of the Company's strategic goals.
Risk management organizational structure
The Company's risk management organizational structure and responsibilities
- Board of Directors: The highest governance unit for risk management of the Company
- Audit Committee: The supervisory unit of the Company's risk management related operating mechanisms
- Sustainable Development Office: The company's risk management promotion and execution unit
- Members of the General Manager's Office (heads of each operating unit): Responsible for risk identification, analysis, assessment, and response of their units, as well as the establishment of relevant crisis management mechanisms
- Audit Office: Regularly audits the internal control and audit plans of each operating unit based on the risks monitored by the Audit Committee
Risk management process
In order to well-established the risk management function, the Company's risk management process includes five elements: risk identification, risk analysis, risk assessment, risk response, and supervision and review mechanism to clearly grasp the scope of each risk and adopt appropriate measures to ensure that relevant risks are properly managed.
Risk record
The process and results of risk management implementation by each operating unit of the company shall be recorded, reviewed, and reported through appropriate mechanisms, and properly retained for future reference, including risk identification, risk analysis, risk assessment, risk response measures, relevant information sources, and risk assessment results in the risk management process.
Risk reporting
Risk Management Promotion and Implementation Units compile the risk information provided by each unit and regularly issue risk management reports to the Audit Committee and the Board of Directors to ensure effective supervision of risk management.
Risk monitoring and review
The risk management promotion and execution unit reviews the implementation of risk management, proposes necessary improvement suggestions, and reports to the board of directors regularly (at least once a year) to accurately review risk management and execute the risk management decisions of the Board of Directors.
The main operational progress in 2025 as follows:
- Establish risk management procedure
- Define the category of risk management
- Establish the criteria for assessing the impact of risks
- Develop risk tolerance levels
- Each operating unit analyzes and identifies the sources and categories of company risks and conducts risk assessments and responses
- Complete and update the risk assessment and response plan for each operating unit