Risk Management

Risk Management Organizational Structure

To ensure stable operations and sustainable development, the Company has established a comprehensive risk management organizational structure based on its scale, business characteristics, and risk profile. This structure is overseen by the Board of Directors, implemented by senior management, and fully participated in by all operating units.

Risk Management Body Responsibilities
Board of Directors The highest supervisory body for risk management, responsible for approving risk management policies, procedures, and the overall framework; ensuring consistency between business strategies and risk management policies; overseeing the establishment and effective operation of the Company’s overall risk management system; and ensuring the adequacy of resources allocated for risk management.
Audit and Risk Committee Assists the Board of Directors in fulfilling its supervisory responsibilities over risk management and internal control, including reviewing risk management policies, procedures, and frameworks, and evaluating their applicability and effectiveness; approving the Company’s risk appetite (risk tolerance) and risk classification levels; overseeing the identification, assessment, and response measures for major risk items; and reporting the status of risk management operations to the Board of Directors on a regular basis (at least annually).
Risk Management Promotion and Execution Unit Established under the Audit and Risk Committee, this unit is responsible for planning, promoting, and integrating the Company’s overall risk management mechanism. Its duties include formulating and revising risk management policies, procedures, and related operational guidelines; identifying and analyzing the Company’s overall risk sources and categories; consolidating and periodically reporting the implementation status of risk management across departments; assisting and supervising operating units in the execution of risk management practices; and promoting risk management education and training to strengthen the Company’s risk management culture.
Operating Units Act as the execution units for risk management. Each unit is responsible for identifying, analyzing, and assessing risks related to its business functions, planning and implementing risk response and control measures, and periodically reporting risk management information to the Risk Management Promotion and Execution Unit.

Risk Management Process

The Company’s risk management process is systematic and sequential, encompassing the following five key components. Through continuous operation and review, the effectiveness of risk management is ensured.

1. Risk Identification

Based on the Company’s strategic objectives and operational activities, potential risks that may affect the achievement of objectives are comprehensively identified, including strategic risks, operational risks, financial risks, information risks, compliance risks, integrity risks, and emerging risks such as climate change.

2. Risk Analysis

The likelihood of occurrence and potential impact of risk events are analyzed, taking into account the effectiveness of existing control measures.

3. Risk Assessment

In accordance with the approved risk appetite, each risk is evaluated and classified to determine its priority for risk response.

4. Risk Response

Depending on the nature and level of impact of each risk, appropriate risk response measures—such as risk avoidance, mitigation, transfer, or acceptance—are adopted, and relevant management and control activities are implemented.

5. Monitoring and Review

The implementation status of risk management activities is reviewed on a regular basis. Ongoing supervision is conducted by the Audit and Risk Committee and the Board of Directors, and improvements are made as necessary.

Status of Risk Management Implementation

To strengthen the Company’s risk management mechanism, in 2025 the Company integrated the risk management function into the Audit Committee, and accordingly renamed it the Audit and Risk Committee. At the same time, the Company established the Risk Management Policies and Procedures as the highest governing principles for its risk management practices.The implementation status of risk management is summarized as follows:

On August 14, 2025, the Board of Directors resolved to integrate the risk management function into the Audit Committee, rename it as the Audit and Risk Committee, and approve the Risk Management Policies and Procedures.