HOME / ESG / Risk Management

Risk Management

01Risk Management:

In recent years, turbulence in the global political and economic landscape and rising geopolitical risk have made the corporate operating environment increasingly complex. The automotive electronics industry also faces multiple challenges — raw material price volatility, shifting customer demand and information security — adding to the pressure on business operations and resource management.

To address the uncertainty and latent risks that rapid change in the internal and external environment may bring to operations, the Company follows its Risk and Opportunity Management Procedure as the basis for corporate risk management. Through institutionalised management and regular review, we strengthen our ability to identify risks and respond flexibly, ensuring that all operating activities can advance steadily within a controllable risk range. The scope of risk management covers operations, finance, regulatory compliance, the supply chain, information security and sustainable development, and serves as an important foundation supporting the Company’s sustainable operations.

Since 2023, JET Optoelectronics has worked with each of its sites to carry out an annual risk assessment. Using the PDCA management cycle, we systematically review the risks and opportunities arising in the course of operations, continuously examine the completeness and effectiveness of the risk management system, and progressively raise the maturity of our overall risk management in order to strengthen long-term operational resilience.

Standard Post with Image

02Risk Management Organizational Structure

The Board of Directors is the Company’s highest governing body for risk management and is responsible for overseeing the formulation and implementation of overall risk management policy. The Sustainability Development Committee, established under the Board, is responsible for reviewing how risk management is implemented across the Company, and the project execution team set up beneath it acts as the principal implementing unit, responsible for planning and executing risk management. Each year the project execution team consolidates the risk assessment results and reports them to the Sustainability Development Committee and the Board of Directors, providing management with an important reference on risk trends and countermeasures to support decision-making.

Risk Management Organizational Structure

Sustainability Development Committee, Audit Committee, Board of Directors

Senior Management

INTERNAL

Management control Entity-level risk Internal audit Internal control system Process-level risk

EXTERNAL

External audit Verification body audit

03Risk Management Process

In accordance with its Risk and Opportunity Management Procedure, the Company has designed a “Risk and Opportunity Assessment Form” as its principal management tool for identifying, assessing, responding to and tracking all categories of risk and opportunity. Through this institutionalised, form-based approach, the Company is able to quantify potential impacts systematically and to strengthen cross-departmental risk control and continuous improvement.

Under this procedure, the Company requires each department to score identified risks quantitatively using the formula “risk coefficient = risk severity × likelihood of occurrence,” and to classify them by score into three levels: low, medium and high risk. Low-risk items are accepted and incorporated into routine management; for medium- and high-risk items, countermeasures and control measures are established, together with subsequent review and adjustment mechanisms, to ensure that risk control measures remain effective.

Each year the Company reviews the risk management objectives set for the previous year to confirm the effectiveness and attainment of each risk control measure. Where an item falls short of expectations, the department concerned must propose an improvement plan and carry out follow-up tracking.

Risk Management Process

  1. Risk collection
    & review
  2. Departmental
    risk assessment
  3. Consolidate results
    & review
  4. Establish control
    measures
  5. Regular
    tracking

04Implementation of Risk Management

In 2025 the Company carried out its annual risk identification exercise across all sites, assessing risks in light of changes in the internal and external environment. Following a review by the project execution team, 22 risks and 14 opportunities were identified, covering operational, financial, regulatory, supply chain, information security and sustainability-related topics.

Among these results, the Company identified 4 high-risk items, for which the relevant units have formulated and implemented corresponding countermeasures and controls according to the nature of each risk. The risk identification results and the responses to them were reported to the Sustainability Development Committee on 9 December 2025, providing management with an important basis for understanding the Company’s overall risk position and for decision-making.

High-risk items identified in 2025

Category Risk item Assessment result Response
External Changes in international politics increase the uncertainty of export sales. Tariff barriers add to trade obstacles and raise export costs, affecting product margins. Adjust shipping arrangements flexibly in line with tariff policy.
Information security incidents or system outages. An information security incident (such as hacking, ransomware or an internal data leak) could cause business interruption and damage customer trust, in turn affecting the Company’s reputation and regulatory compliance. 1. Conduct TISAX information security verification on a regular basis.
2. Hold at least one training session each year, supplemented by ad hoc awareness campaigns and phishing tests to raise employee vigilance.
3. Upgrade endpoint protection.
Internal Failure to obtain patent protection for key technologies, or new technologies alleged to infringe the patent rights of others. 1. Alleged patent infringement may lead to litigation, requiring substantial damages and legal costs.
2. The Company may be forced to halt or modify products, resulting in additional costs and lost market opportunities.
1. Establish a process for producing patent maps when developing new product lines, in order to avoid infringing the patents of others and to define the patent scope of key technologies.
2. Set annual patent KPIs targeting defensive or offensive patents.
3. Hold regular intellectual property training each year to improve colleagues’ patent knowledge and practical capability.
Insufficient key technical personnel or attrition within the R&D team, preventing innovation projects from progressing smoothly or creating gaps in R&D knowledge. 1. Delays to R&D schedules may make technology transfer difficult, with specialist talent hard to replace quickly.
2. The speed and quality of innovative technology development decline, eroding competitive advantage.
3. Greater resources must be invested in recruiting and training new staff, raising operating costs.
1. Review the quality of the R&D team regularly and strengthen the technical capabilities of R&D personnel.
2. Recruit key technical personnel into the team and increase retention incentives.