Risk management and Cyber Security

Risk Management System and Structure

Sustainable Operations Philosophy
  • The risk management policy will be adopted on March 15, 2022 as the highest guideline of risk management of the Company. The policy follows international standards and takes learning from benchmark companies. This policy is a realization of regulatory compliance to ensure Compal's sustainable operations.
  • Compal adopts a management system for finances, business and accounting pursuant to the FSC's Regulations Governing the Establishment of Internal Control Systems by Public Companies; and evaluates and monitors risk in operating activities. Managerial personnel ensure that any such risk is within an acceptable range by drawing up a risk management plan and response guidelines.
  • The Company adheres to regional government policies and regulations of its critical production base.
Designed for full participation in internal controls
  • The internal control system is based on the structure of the organization, authority and responsibilities, as well procedure control points. It is implemented through internal self-assessment and performance audits.
  • In 2023, internal self-assessments throughout all levels of operations and across 421 units are carried out (including departments and independent units). A total of 294 assessments were conducted according to procedure (including directors, vice-directors, general managers, independent directors, and other relevant managerial personnel).
Ethical Management and Risk Management Organization Structure
  • The Ethical Corporate Management Best Practice Principles and Procedures for Ethical Management and Guidelines for Conduct were established by the Company in accordance with the Ethical Corporate Management Best Practice Principles for TWSE/GTSM Listed Companies and Procedures for Ethical Management and Guidelines for Conduct published by the TWSE.
  • The actual functions of the Company organizational structure as well as the 3 Lines of Defense structure for risk management published by the IIA were used as a reference by the Company to formulate our management organization and process for risk management.
          
            Source of the materials: ECIIA/FERMA Guidance on the 8th EU Company Law Directive, Rule 41

2024 Risk identification and corresponding strategy

Compal performed Identification, Analysis and Evaluation based on the ISO 31000 framework and methodology, and determined 24 risk issues in five areas: Strategy, Finance, Operations, Regulatory Compliance, and the Environment. Considering the Company's resources, these issues were then prioritized in a risk matrix.

Following an analysis of the matrix, we determined specific risks for the three main risks based on the internal and external environment and drafted the  strategy:

New & Emerging Risk