Risk Management

Issue Date: August 19, 2026

 

Risk Management

To identify and manage potential internal and external risks that may impact the Company's operations, the Company has established a “Risk Management Policy”. Based on this policy, risk factors are identified and prioritized to define the scope of risk management. In accordance with the latest standards and professional practices in internal auditing, the Company monitors potential risks and implements preventive measures to strengthen risk management, enhance crisis response capabilities, and achieve risk control objectives. These efforts further enhance shareholder value, maintain competitiveness, and establish a solid foundation for sustainable operations.

Risk Management Scope

 

Based on changes in the global economy, finance, environment, and industry conditions, and in alignment with the Company’s sustainable operation objectives, annual material topics, and stakeholder concerns, the Company classifies its risk identification scope into six major categories: enterprise risk, financial risk, information security risk, operational risk, human capital risk, and emerging risk.

 

 

Risk Management Organization

 

The “Risk Management Team” integrates various risk management units under the ESG Committee, with the Chief Financial Officer (CFO) overseeing the operations of the Risk Management Team. In accordance with the “Risk Management Policy” approved by the Board of Directors in 2025, the Company conducts risk factor identification and risk control activities to enhance the efficiency of coordination, self-assessment, and execution within the risk management organization. The operational status for 2024 was reported to the 2nd meeting of the 12th Board of Directors on July 28, 2025. The responsibilities at each level of the risk management organization are described below:

 

風險管理小組

Implementation

 

The Company has actively promoted the implementation of risk management mechanisms since 2017. From 2020, the Company has provided regular annual reports to the BOD on the operation. As of July 2023, the Company annually reports to the Audit Committee and the BOD. The Audit Office will also be responsible for submitting risk assessments as part of the annual audit plan and reporting the Company's risk management implementation to the Audit Committee and the BOD. The following shows the implementation from every year:

  • The scope, organization, and structure of the risk management were established in 2017.

  • The risk management organization was re-structured based on the organizational change in 2018. Each risk management unit was combined into a “Risk Management Team” that is subordinated to the ESG Committee and led by the Chief Financial Officer for identification of risk factors and risk control. This makes the command and control, self-evaluation, and operation of the risk management organization become more efficient.

  • The risk detection, analysis, and identification for the risk management had been continuously implemented in 2019. In addition, the emerging risk issues, such as the information security and climate change risk, were included in the management policies for effective control. The Company offered the risk management courses about quality, products, and information security. A total of 253 people attended them with a total of 114 training hours.

  • 2020
    - The risk management policy of the Company has been developed and approved by the Board of Directors. The Company will continue the risk detection, analysis, and identification for the risk management to enhance the crisis response abilities to prevent and solve them and the ability to quickly recover after crises for effective risk control.
    - Moreover, the Company offered the risk management courses about quality, information security, and climate change. A total of 83 people attended them with a total of 116 training hours.
    - Response measures of key risk issues: 【COVID-19】, 【Climate Change】and【Information Security】.

  • 2021
    - The Company offered the risk management courses about quality, information security, climate change and RBA. A total of 2,591 people attended them with a total of 3,362 training hours. Furthermore, to enforce the detection, analysis, and identification of risks within the scope of risk management to capture the internal and external risks that the Company will face in business operations, we conducted the biennial risk factor identification at the end of 2021 to achieve advance assessment, countermeasure establishment, and prevention.
    - Response measures of key risk issues: 【COVID-19】, 【Climate Change】and【Information Security】.
    - To effectively detect, analyze, and identify risks within the defined scope of risk management and to address potential internal and external risks the Company may face during operations, Coretronic conducts a comprehensive risk identification in 2021, which is carried out every two years.

  • 2022
    - We have conducted risk management courses related to risk identification, information security, climate change, and occupational health and safety. These courses include "Safety Risk Identification and Control," "Environmental Issues Identification," "Production Safety Management and Occupational Safety and Health Products Use and Management," "Occupational Disease Prevention and Control," "Handling of Occupational Accidents," and "Information Security." These courses aim to enhance employees' risk awareness. The total number of participants was 2,658, with a total training duration of 1,718 man-hours.
    - Response measures of key risk issues: 【Drastic Change in Technology and Industry】, 【Supply Chain Shortage】and 【Hard to Sttract and Retain Employees】.

  • 2023
    - We have offering risk identification, information security, climate change, and occupational safety andhealth-related risk management courses, such as: "Safety Risk Identification and Control," "Environmental Issues Identification," "Production Safety Management and Occupational Safety and Health Products Use and Management," "Occupational Disease Prevention and Control," "Handling of Occupational Accidents," and "Information Security" etc., to enhance employees' risk awareness. A total of 3,784 people participated in the training, with a total of 5,841 personhours of training.
    - Response measures of key risk issues: 【Climate Change】and 【Information Security】.
    - Furthermore, to enforce the detection, analysis, and identification of risks within the scope of risk management to capture the internal and external risks that the Company will face in business operations, we conducted the biennial risk factor identification at the end of 2023 to achieve advance assessment, countermeasure establishment, and prevention.

  • 2024
    - Three risk-related issues have been implemented in the company's operations. First, introduce the Task Force on Climate-related Financial Disclosures (TCFD) framework, conduct climate change risk and opportunity identification and impact analysis, and develop energy-saving and carbon-reduction strategies centered on low-carbon products and green operations to mitigate the greenhouse effect. Second, set annual information security management objectives, develop evaluation data based on their characteristics, and use data-driven indicators and standardized processes to propose improvement suggestions for non-compliance or identified risks, and track their implementation. Third, based on the latest risk identification results, monitor potential risks, develop management strategies, and implement preventive measures to strengthen risk management, enhance crisis response capabilities, and achieve the goal of risk control.
    - Response measures of key risk issues: 【Geopolitical Instability or Material Scarcity】, 【Political Risk / Uncertainty】and 【Rapid Changes in Market Trend】.

  • 2025
    - Response measures of key risk issues: 【Information Security】and 【Climate Change】.
    - To effectively detect, analyze, and identify risks within the defined scope of risk management and to address potential internal and external risks the Company may face during operations, Coretronic conducts a comprehensive risk identification in 2025, which is carried out every two years.

Risk Identification and Management Process

 

To strengthen the risk management mechanism and identify internal and external risks that may affect operations, the Company initiated its biennial risk identification process at the end of 2025. Through four systematic steps (identification, assessment, analysis, and response), the Company establishes pre-emptive evaluation and response measures to achieve proactive risk control. Relevant management results are reported to the Board of Directors annually.


For risk identification, the Company referenced Aon’s Global Risk Management Survey and, after comprehensively considering trends in the global economy, finance, environment, and industry developments, the Risk Management Team initially identified 39 general risks across five major categories: corporate, financial, information security, operational, and human capital risks. In addition, based on the top 10 global long-term risks, top 10 corporate long-term risks, and top 5 Eastern Asia long-term risks identified in The Global Risks Report 2025 published by the World Economic Forum (WEF), the Company further identified 12 emerging risks.


Subsequently, supervisors of relevant operating units and senior management conducted a two-stage evaluation and discussion based on “likelihood of occurrence” and “impact level”. The results were used to develop a risk matrix, which serves as the core basis for subsequent risk control and resource allocation.

 

 

 

Risk Matrix

 

The Company determines the risk level of each risk issue by comprehensively evaluating its “impact level” and “likelihood of occurrence”, while also aligning the assessment with the Company’s risk appetite. Risks are categorized into three levels: high, medium, and low. To ensure rigorous risk control, the Company includes highly impactful extreme events, such as fatalities, complete operational disruptions, major financial losses, or severe damage to brand reputation, within the scope of medium-risk (or above) management, even when the likelihood of occurrence is extremely low and exceeds the organization’s risk appetite. This approach strengthens preventive measures and dynamic monitoring mechanisms.


In 2025, through the risk identification survey, the Risk Management Team comprehensively evaluated likelihood, impact, and risk appetite, identifying a total of 20 key risk issues. These consisted of 15 general risks (including 4 high-risk issues and 11 medium-risk issues) and 5 emerging risks that may emerge over the next 10 years. For key risks requiring priority attention, the Company has established corresponding risk mitigation measures and contingency plans to reduce potential impacts and ensure operational resilience.

 

 

 

Risk Management Strategy

 

Risk Aspect

Key Risk Issues

Control Focus

Mitigation Measures

Economic/Enterprise

Geopolitical Volatility

  • Closely monitor changes in international politics, economics, and regulations, and incorporate geopolitical risks into the overall risk assessment and governance framework.

  • Identify potential impacts on operations, supply chains, investment deployment, and markets, while strengthening cross-departmental information integration and decision support.

  • Diversify markets and supply sources to enhance supply chain resilience and operational flexibility.

  • Strengthen regulatory compliance, sanctions, and trade control management mechanisms to mitigate the risk of violations and operational disruptions.

  • Establish business continuity and scenario response plans to reduce the impact of unexpected geopolitical events on the Company.

Rapidly Changing Market Trends
  • Continuously monitor industry developments, customer demands, and changes in the competitive environment, and incorporate market trend risks into strategic and risk management decisions.

  • Strengthen cross-departmental information integration and data analysis capabilities to enhance early warning and response to market changes.

  •  Maintain flexibility in product and solution portfolios, and promote innovation and business model adjustments to respond to market changes.

  • Diversify markets and customer structures to reduce dependence on a single market or product.

  • Establish agile decision-making and resource allocation mechanisms to reduce the impact of rapid market changes on operations and finance.

Increasing Competition
  • Continuously monitor industry competition dynamics and peer strategies, and incorporate competitive risks into the Company’s strategy and risk management framework.

  • Analyze differentiated advantages in products, services, and market positioning to support senior management decision-making and resource allocation.

  • Continue to strengthen R&D innovation and service optimization to enhance product and brand competitiveness.

  • Diversify product portfolios and market deployment to reduce dependence on a single market or customer segment.

  • Strengthen market intelligence collection and rapid response capabilities to maintain stable operations and long-term value.

FinancialExchange Rate Fluctuations
  • Regularly monitor exchange rate changes of major operating and transaction currencies and assess the impact of exchange rate fluctuations on finance and cash flow.

  • Establish internal foreign exchange risk policies and authorization procedures.

  • Use derivative financial instruments (such as forward contracts and options) for hedging.

  • Optimize the allocation of revenue and procurement currencies to reduce exposure to a single currency.

  •  Adjust pricing strategies to transfer part of the exchange rate risk.

  • Strengthen financial forecasting and sensitivity analysis.

Emerging Risk Management Strategy

 

Risk Aspect

Key Risk Issues

Control Focus

Mitigation Measures

State-Based Armed Conflict

Military confrontations or warfare between sovereign states arising from political, territorial, resource, or ideological factors not only affect the conflict zones themselves, but may also directly or indirectly impact the operations and strategies of enterprises in non-conflict regions through the globalized system. This represents a high-impact, multi-dimensional, and difficult-to-predict systemic risk.

  • Affect operations through supply chains, energy, raw materials, and international trade.
  • May lead to supply disruptions, logistics interruptions, and increased operating costs.
  • Fluctuations in market demand may affect business performance.
  • Continuously monitor international developments and incorporate them into the overall risk management framework.
  • Diversify supply sources and strengthen supply chain resilience.
  • Implement regulatory compliance measures and establish business continuity and contingency mechanisms.
Misinformation and Disinformation

False, misleading, or intentionally manipulated information may spread rapidly through digital and social channels, affecting stakeholder trust, corporate reputation, and market confidence, while also influencing their business operations and decision-making processes.

  • Affect stakeholder trust, corporate reputation, and market confidence.
  • May cause short-term fluctuations in stock prices and revenue, as well as customer loss.
  • Increase public relations, compliance, and operating costs, thereby harming long-term value.
  • Strengthen information governance and external communication management, and promptly monitor and respond to risks.
  • Promote cross-departmental collaboration, transparent disclosure, and establish crisis response mechanisms.