Risk Management Policies and Procedures

Sustainability Policies » Corporate Governance Policy

Risk Management Policies and Procedures

Article 1 Scope of Application

  • These Risk Management Policies and Procedures apply to Quanta Computer Group and its subsidiaries (collectively referred to as Quanta Group), covering all operational activities and related decision-making processes.

Article 2 Purpose

  • To ensure that Quanta Group practices sustainable corporate development and strengthens Corporate Governance and operational resilience, in addition to complying with existing management systems and internal control systems, this policy is established to integrate the identification, assessment, and management of risks and opportunities through board of directors-level participation and systematic management mechanisms, thereby reducing the impact of uncertainties on operations and capturing potential development opportunities.

Article 3 Basis

  • The Group establishes an integrated risk and opportunity management mechanism in accordance with relevant regulations, including the Financial Supervisory Commission's "Regulations Governing Establishment of Internal Control Systems by Public Companies" and the Stock Exchange's "Risk Management Best Practice Principles for TWSE/GTSM Listed Companies", to assess and monitor risk-bearing capacity, opportunity-seizing capability, and compliance with management procedures.

Article 4 Objectives of Risk and Opportunity Management

  • Through a comprehensive risk and opportunity management framework, the Group integrates it into operational activities and daily management processes to achieve the following objectives:
  • 1. Achieve the Company's operational and strategic objectives
  • 2. Enhance decision-making quality and management effectiveness
  • 3. Provide reliable financial and non-financial information
  • 4. Effectively allocate resources and control risks
  • 5. Identify and seize opportunities related to operations and sustainable development
  • 6. Enhance corporate competitiveness and long-term value

Article 5 Scope of Risk and Opportunity Management

  • The Group's risk and opportunity management covers strategic, operational, financial and investment, information security and digital transformation, legal compliance and integrity, sustainability management, emerging risks, and innovation opportunities.

Article 6 Risk and Opportunity Management Policy

  • The Group upholds the philosophy of sustainable operation, establishes and maintains a proactive and continuously improving risk and opportunity management mechanism, conducts operational impact and opportunity analyses by monitoring internal and external environmental changes, and continuously enhances corporate resilience to ensure stable operations and create long-term value. The Group also strengthens the culture of risk and opportunity management through mechanisms such as education and training, performance management, early warning notifications, and information disclosure, integrating it into daily operations and decision-making processes.

Article 7 Organizational Structure

  • 1. board of directors
    Serves as the highest governance body for risk and opportunity management and is responsible for approving policies and overseeing overall implementation.
  • 2. President
    Serves as the convener for promoting the Risk Management mechanism, coordinates the implementation of Risk Management systems across departments, and ensures that risk and opportunity management measures are practical and effectively implemented.
  • 3. Sustainability Development Steering Committee
    Assists the board of directors in carrying out risk and opportunity management responsibilities, regularly supervises implementation and provides improvement recommendations, reviews the applicability and effectiveness of the mechanism, and ensures effective responses to company risks; reports overall results and recommendations to the board of directors at least once annually.
  • 4. Risk Management Team
    Establishes and promotes the Company's Risk Management mechanism, including formulating Risk Appetite and qualitative and quantitative measurement standards, continuously analyzing and identifying the Company's risk sources and categories, and regularly reviewing their applicability. The team is also responsible for consolidating Risk Management implementation status and submitting relevant reports, while assisting and supervising departments in implementing Risk Management operations, facilitating cross-functional communication and coordination required for Risk Management operations, promoting implementation according to Group Risk Management decisions, and planning related training to enhance overall risk awareness and risk culture.
  • 5. Departmental Risk Officer
    Each department manager shall designate a representative as a risk liaison responsible for supporting the promotion and implementation of the Group's Risk Management mechanism. The primary responsibilities of the risk liaison include assisting in providing relevant information, participating in risk information collection and consolidation, and supporting risk analysis and assessment activities. Each department shall implement established risk control measures and management operations in accordance with Group policies and related regulations and shall be responsible for daily data collection, record maintenance, and the accuracy and completeness of related data. The risk liaison shall regularly consolidate implementation status and conduct internal reviews, report abnormalities or potential risks when necessary, and cooperate with relevant Group units in subsequent improvement and management activities. In addition, each department shall cooperate with the Group in Risk Management reviews and reporting activities and regularly provide necessary information to the Risk Management Team to ensure the effective operation of the overall Risk Management mechanism.
  • 6. Audit Unit
    Acts as an independent unit responsible for regularly auditing Risk Management procedures and the implementation of control measures at various risk levels, providing improvement recommendations, and reporting audit findings and follow-up results to the board of directors to ensure effective operation of the system.

Article 8 Risk and Opportunity Management Process

  • The Group's risk and opportunity management process includes the following
  • Stages: 1. Identification: Based on the Company's strategic objectives and materiality principles, identify risks and opportunities that may affect the achievement of objectives, including internal and external environments, stakeholder needs, and emerging issues, and establish an annual risk and opportunity list.
  • Stages: 2. Analysis: The Group shall establish Risk Appetite and risk tolerance as the basis for risk and opportunity assessment and the reasonableness of related resource allocation and shall review and adjust them regularly.
  • (1) Risks: Assess likelihood of occurrence and degree of impact
  • (2) Opportunities: Assess feasibility and potential benefit impact
  • Stages: 3. Evaluation: Prioritize according to Risk Appetite and strategic importance to determine significant risks and opportunities.
  • Stages: 4. Response and Promotion: Risk Management personnel and relevant personnel from each operating unit shall identify, analyze, and assess risks and opportunities based on the Company's strategic objectives, perspectives of internal and external stakeholders, Risk Appetite, and available resources, and select appropriate response strategies or opportunity development initiatives accordingly. For potential risks, risk mitigation plans shall be implemented; for valuable opportunities, corresponding enhancement or expansion measures shall be planned to improve overall operational performance.
    Each department shall establish prevention, response, crisis management, and BCP, Business Continuity Plan as necessary, while integrating opportunity management thinking so that related response measures not only effectively control risks but also promote organizational growth and innovation and achieve the best balance between goal achievement and cost-effectiveness.
    To ensure that all types of risks and opportunities remain within controllable and manageable scopes, relevant risk and opportunity management indicators shall be established. Risk Management personnel and relevant personnel from each operating unit shall continuously monitor and assess changes, report to the Risk Management Team in a timely manner, and prepare and retain related records for future tracking and decision-making reference.
  • Stages: 5. Monitoring: Continuously track the implementation status of risks and opportunities through indicators and management mechanisms to ensure they remain within controllable ranges and are continuously optimized.
  • Stages: 6. Reporting and Disclosure: To implement Honest Business Practices and Corporate Governance and strengthen information transparency in response to stakeholder expectations, the process and results of Risk Management implementation shall be recorded, reviewed, and reported through appropriate mechanisms, properly retained for reference, and relevant information disclosed in annual reports, ESG reports, or the Company website.

Article 9 Implementation and Amendment

  • This policy shall be implemented upon approval by the board of directors, and the same shall apply to any amendments.

Summary of Annual Implementation and Management Status

  • The Group adopts five major themes, namely risk identification, risk measurement, risk monitoring, risk reporting and disclosure, and risk response, as the procedures of Risk Management and implements them in accordance with management regulations. The Group shall communicate with stakeholders and disclose identified risks and management results and disclose information related to Risk Management in annual reports, ESG reports, and on the website.
  • Each year, with reference to risk incidents that occurred within the Group in the previous year and the opinions of external experts, relevant issues that may affect the operations of the Group and consolidated companies are established from the end of the current year to the beginning of the next year. These serve as the basis for the overall assessment and prioritization of operational risks for the new year. After matters such as recommended Risk Management actions for planned risk control items are approved, risk monitoring and/or risk treatment will be carried out.
  • The monitoring and treatment tools mentioned include, but are not limited to, implementing autonomous Risk Management actions to control risks (risk retention) or risk transfer (insurance).
  • The most recent reporting date was December 18, Year 114 of the ROC calendar.