Risk Management
Risk Management Policy and Organization
The new company has established the "Risk Management Policy and Procedures," creating an internal risk management system, with the board of directors serving as the highest decision-making body for risk management, responsible for approving the risk management policy and overseeing its effective operation.
Each department is responsible for managing operational risks. After fully understanding the risks faced by their respective business areas, they incorporate risk management-related mechanisms into various operational management regulations.
On the other hand, the company's audit office, as an independent unit directly under the board of directors, is responsible for reviewing the effectiveness of the risk management framework and internal controls.
Based on the results of the risk assessment, an annual audit plan is formulated and executed after approval by the board of directors, providing improvement suggestions for potential deficiencies in the internal control system. An annual report is submitted to the board of directors on the overall operation of risk management to ensure that risk control remains continuously effective.
Risk Management Process
The company's risk management process is divided into five main stages, ensuring that risks are effectively implemented through risk identification, risk analysis, risk assessment, risk response, and risk monitoring and review processes. The following is an explanation of each risk management process.
Risk Management Procedures and Execution Phase
| Procedure | Risk Management Stages | Description |
| 1 | Risk Identification | Each department identifies potential risk events that may lead to the inability to achieve strategic goals or cause losses based on the operating environment and strategic objectives. |
| 2 | Risk Analysis | Refer to relevant information to analyze the occurrence probability and impact level of risk events, and determine the risk level accordingly. |
| 3 | Risk Assessment | Compare the results of the risk analysis with the company's risk appetite, and determine the risk events that need to be prioritized for handling, serving as a reference for the subsequent formulation of response measures. |
| 4 | Risk Response | Risk response refers to the establishment of relevant handling plans to ensure that relevant personnel fully understand and execute them, and to continuously monitor the implementation of the relevant handling plans. The risk response plan should achieve a balance between achieving objectives and cost-effectiveness. |
| 5 | Supervision and Review | Review whether the risk management process and related risk countermeasures are continuously effective, and incorporate the relevant review results into performance measurement and reporting. |
Risk Management Item Identification and Results
The new risk management scope covers market risk, operational risk, financial risk, information security risk, and climate risk.
In 2024, no significant abnormalities were found. The following are the risk items identified and assessed by the new company in 2024.
To the new 2024 risk identification and assessment results
| ESG Aspects | Risk Items | Risk Description | Relevant Handling Plan |
| Governance | Market Risk | The US-China trade war continues (tariff barriers) |
|
| Governance | Climate Risk | Climate change is increasingly severe, with the frequency and intensity of extreme weather events (typhoons, floods, heavy rainfall, droughts, etc.) rising, leading to increased operating costs and capital expenditures. Additionally, as awareness of climate change increases, customer preferences for products/services are changing. If customer needs cannot be met, it may result in risks such as a decline in the company's operating revenue. |
|
| Governance | Operational Risk | High Inventory Stock |
|
| Governance | Financial Risk | Exchange Rate Fluctuation |
|
| Governance | Information Security Risk | 1. Virus, Hacker Intrusion 2. Information Equipment Failure |
|
Audit and Internal Control
Internal Audit Organization and Responsibilities
The internal audit department of the company is an independent unit directly under the board of directors. Depending on the company's size, business conditions, and management needs, dedicated internal audit personnel are assigned, including a manager and a total of 2 full-time auditors.
Mainly responsible for reviewing the internal control design and execution of all operational processes of the company, assessing their effectiveness and efficiency.
Internal Audit Operation Process
The new public company has established "Internal Control System Processing Guidelines" and related industry regulations to maintain a complete control operation cycle, covering internal control systems for sales and collections, procurement and payments, production, payroll, financing, real estate plant and equipment, investment, research and development, electronic data processing, and management operations, ensuring that all business processes are included in the risk prevention mechanism. The internal audit unit formulates and executes the audit plan approved by the board of directors based on the results of the risk assessment.
Suggestions for improvement regarding potential deficiencies in the internal control system should be proposed and compiled into an audit report, which will be reported to the board of directors regularly.
In addition to reporting at the regular board meetings, reports are also made to the chairman and independent directors on a monthly basis or as necessary.
Each department integrates corresponding control procedures into their daily operating standards and cooperates with the internal audit office for review and auditing to continuously strengthen internal control effectiveness.
In 2024, the audit department formulated and executed the audit plan, completing a total of 37 audit reports throughout the year.
After auditing various operations, no significant anomalies were found. For any deficiencies, the audit team will continue to track until improvements are implemented, and the audit supervisor will compile progress and report regularly to the board of directors and the chairman, serving as the basis for the board of directors to issue the internal control system declaration.
In addition, the internal audit department urges each department and subsidiary to conduct self-inspections of internal control systems annually, reviews their self-assessment reports, and provides comprehensive feedback to the board of directors to ensure continuous optimization of the company's risk management and internal control mechanisms.
Risk Identification and Planning > Audit Execution > Reporting and Communication > Tracking and Improvement > Continuous Optimization
