Risk Management System and Structure
Sustainable Operations Philosophy
-
-
- Compal has established a Risk Management Policy, which was approved and became effective upon Board approval on March 15, 2022, serving as the highest guiding principle for the Company’s risk management practices. The core principle of the policy is to follow international standards and benchmark against leading enterprises while ensuring regulatory compliance to achieve sustainable corporate operations.
- The Company follows the Regulations Governing Establishment of Internal Control Systems by Public Companies issued by the Financial Supervisory Commission to establish financial, operational, and accounting management systems, and to evaluate and monitor operational risks. The management team actively participates in formulating risk management policies and corresponding guidelines to ensure that operational risks remain within acceptable levels.
- The Company also complies with local laws and regulations applicable to its major production sites. For example, it follows the guidance related to the “Basic Norms for the Internal Control of Enterprises” jointly issued by the Ministry of Finance of the People’s Republic of China, the China Securities Regulatory Commission, the National Audit Office, the China Banking Regulatory Commission, and the China Insurance Regulatory Commission.
Internal Control Design with Full Employee Participation
- Based on organizational structure, delegated responsibilities, and process control points, the Company has established an internal control framework. Through internal control self-assessments and performance evaluations, the Company ensures effective implementation of internal controls.
- The Company promotes internal control self-assessment covering both entity-level and operational-level controls. In 2025, a total of 380 units (department-level units or independent units) conducted self-assessments, with 249 individuals completing the self-evaluation process, including the Chairperson, President, independent directors, and related managerial personnel. The comprehensive coverage was sufficient to ensure the effective introduction and implementation of internal control procedures.
Ethical Management and Risk Management Organization Structure
- The Ethical Corporate Management Best Practice Principles and Procedures for Ethical Management and Guidelines for Conduct were established by the Company in accordance with the Ethical Corporate Management Best Practice Principles for TWSE/GTSM Listed Companies and Procedures for Ethical Management and Guidelines for Conduct published by the TWSE.
- The Company has also formulated its risk management organization and processes by referencing the Three Lines Model framework published by The Institute of Internal Auditors (IIA), while incorporating practical operational considerations based on the Company’s organizational structure.
- To promote risk management, each department head establishes responsible units according to their duties and responsibilities. These units are responsible for day-to-day risk management and, through communication, coordination, and collaboration among departments, jointly promote and execute annual plans and projects to implement comprehensive risk management across all business operations.
- Risk Management Training: To cultivate employees’ awareness of risk management and reinforce information security concepts among all employees, the Company provides educational training programs and seminars on Compal’s sustainable development, risk management, information security, and confidentiality awareness for all employees. These initiatives aim to strengthen employees’ risk awareness and vigilance.
.png)
Risk Identification and Priority for 2025
The Company follows the ISO 31000 framework and methodology to carry out the processes of risk identification, analysis, and evaluation. A total of 42 risk issues were identified and consolidated under five categories: Strategy, Finance, Operations, Compliance, and Environment. The Risk Analysis Matrix was then applied, taking into account the Company’s resources, to determine the prioritization of risk management efforts.

Risk Response Strategy
Based on the results of the risk analysis matrix, the Company analyzed both internal and external environments for the top three identified risks to confirm the specific nature of each risk. Corresponding response strategies were then developed, as detailed below in order of priority.

Identification of Emerging Risks

ETHICAL MANAGEMENT AND ANTI-CORRUPTION
Compal is committed to the establishment of the corporate culture of ethical management and upholds the principle of “zero tolerance” for unethical conduct, including bribery and corruption. See relevant policies on Compal website.

- To uphold a high standard of business integrity, Compal has always adhered to a zero-tolerance policy toward corruption and bribery. In order to effectively manage risks such as conflicts of interest, the Company has established an ethical management and anti-corruption system. This system is built with reference to the ISO 37001 Anti-Bribery Management System, aligns with the expectations of international organizations for transparency and disclosure, and complies with the regulations and requirements of competent authorities.
- The ethical management and anti-corruption management team periodically strengthens internal management and audit procedures in line with best practice at international benchmark companies, the US Foreign Corrupt Practices Act (FCPA), and the UK Bribery Act (UKBA) of 2010. Our efforts have laid down a solid foundation for our globalization strategy and quest to become a leading international enterprise.
Ethical management and Anti-corruption Training (Includes part-time employees and interns)
Worldwide Manager & Non Managers Training Metrics

Summary of Violations

Cyber Security
ISO 27001Information Security Policy
To achieve the information security strategy of "ensuring business continuity and enhancing customer satisfaction," Compal has implemented an information security management system. This includes formulating roles and responsibilities for information security, ensuring full participation from all employees and contractors. We identify information assets, conduct information security risk assessments, comply with laws and regulations, meet customer security requirements, and carefully evaluate overall information security risk items and acceptance criteria.
In response to the evolving digital environment and ever-changing new technologies, we strengthen digital resilience and implement information security controls with a proactive defense mindset. This includes identification, protection, detection, response, and recovery, aimed at maintaining the confidentiality, integrity, and availability of critical information assets. Through management reviews and performance evaluations, we continuously improve and maintain the effectiveness of the information security management system. Our goal is to gain customer trust, fulfill commitments to shareholders, and achieve sustainable business operations.
Compal Information Security Management Organization
Policies and Regulation for the Protection of Personal Data and Privacy
Compal formulates "Compal Group - Policies and Regulations for the Protection of Personal Data and Privacy", stating the employees should abide by and protect various forms of personal data processing procedures, the scope of application, corrective actions, and disciplinary actions. "Compal Group - Policies and Regulations for the Protection of Personal Data and Privacy" applies to all group-wide in Compal. The "Personal Data Management Team" (known as the "Data Management Team" is established across functions for the proper protection of privacy right, and the hotline at +886287978588#14385, or the e-mail at Compal_PIR@compal.com is set for filinging a complaint and reporting. Compal adopts a zero-tolerance policy for privacy protection. In the use of personal information, unless the individual explicitly agrees, Compal will not collect any personal information.
Compal strictly complies with privacy policy requirements regarding customer information and prohibits any secondary use of personal data. Internal monitoring in 2025 confirmed a 0% rate of secondary use, and no substantiated complaints of customer privacy breaches or data loss have been reported during the past three years. If any relevant personnel are found to be negligent or engaged in misconduct, Compal will impose disciplinary actions and corrective measures to protect data privacy.
ISO 27001 Certification
Compal Group Policies and Regulations for the Protection of Personal Data and Privacy