Material Sustainability Issues (Materiality Topics)

Risk management

Risk management

Building Organizational Resilience for Sustainable Growth in All Conditions

The company recognizes that effective risk management is the cornerstone of sustainable growth. Therefore, we have integrated a comprehensive risk management framework covering strategic, financial, operational, regulatory, and ESG aspects to build organizational resilience and proactively address emerging challenges, ensuring business continuity through any crisis.

0%

Percentage of Enterprise Risk Management (ERM) plans reviewed and updated to align with the current situation, successfully meeting the 2025 target.

0

Number of personal data breach complaints in 2025, reflecting robust control and risk management systems.

0

Frequency of senior management reviews of risk management policies and frameworks to ensure timely alignment with evolving changes.

Risk management

Composition of
Management Structure

Governance
Driven by the Corporate Governance and Sustainable Development Committee (CG & SDC) and the Audit Committee, with the Internal Audit Department independently reviewing the system.
Strategy
Adopting the COSO ERM 2017 international framework across the entire organization, with a focus on building resilience and ensuring effective crisis response.
Risk management
Continuously identifying, analyzing, and assessing key risks, with due consideration for emerging risk factors such as climate-related natural disasters.
Metrics and Targets
Closely monitoring risk appetite levels and the progress of risk mitigation plans.

Risk Culture & Innovation

The company is dedicated to integrating risk-based thinking into our organizational culture. Through the "Key Intellectual for Risk Owners" workshops, we are equipping our working groups with new perspectives and strategic tools. These sessions focus on brainstorming ESG-related risks, empowering leaders across all functions to accurately anticipate and address future challenges.

Operation

The company translates policies into practice through systematic operational processes:

(1) Emergency Response Planning: Establishing Business Continuity Plans (BCP) and emergency response protocols to address both natural disasters (e.g., floods) and social risks.

(2) Internal Control Integration: Assigning the Risk Management Department to collaborate with all business units (Risk Owners) to assess and manage risks at the operational level.

(3) Transparent Disclosure: Reporting risk management performance and sustainability issues via the 56-1 One Report in accordance with GRI Standards.

Performance Achievements (Impact & Results)

A robust and enterprise-wide integrated risk management system enables the company to maintain business stability, protect critical information, and stay prepared for unforeseen circumstances.

7d.jpg

1 %

Risk management plans have been reviewed.

1 cases

Annual Review of Risk Management Policy
7g.jpg

Long-term Targets (Commitment)

The company is committed to enhancing our Enterprise Risk Management (ERM) system to be agile and responsive to the evolving global landscape. We aim to consistently maintain a 100% review rate of our risk management plans and strive for zero personal data breach complaints, serving as a solid foundation for driving business and building long-term stakeholder confidence.

Towards an Agile and Sustainable Organization

Progress in Enterprise Risk Management