Risk Management
To ensure sound operations and sustainable development, Walsin Lihwa operates in accordance with an Enterprise Risk Management (ERM) framework, continuously identifying and evaluating potential risks, monitoring global environmental and industry developments, and formulating appropriate risk management strategies to reduce the likelihood and negative impact of risks, thereby effectively managing and mitigating the impacts risks bring.
The Organizational Structure of Risk Management
The Board of Directors, Audit Committee, Internal Audit Office, President and Sustainability Office, individual risk management units, business units and subsidiaries all participate in implementing risk management measures, forming a three-line-of-defense ERM mechanism:
The Policy and Operations of Risk Management
Walsin Lihwa has established the
Risk Management Policy and Procedures as the highest guiding principle and management procedure for the risk management of the Company and its subsidiaries. On January 26, 2024, it revised the risk management objectives, organizational structure, unit authority and responsibilities, management procedures, and control mechanisms, integrating risk management into daily operations and promoting company-wide participation in its implementation. The Company reviews its risk management status regularly each year and reports to the Audit Committee and the Board;
the reporting on risk management operations for 2025 was completed on October 31, 2025 and November 7, 2025, respectively.
The Implementation Mechanism of Risk Management
To reduce the impact of internal and external risks, Walsin Lihwa—in accordance with the materiality principle and the characteristics of its business and operations—identifies risk topics related to operations and corporate governance, the economy, the environment, and society, and plans the corresponding management and monitoring measures. The relevant risk response plans and mitigation measures can be found in the relevant chapters of this report or in the Walsin Lihwa Annual Report. For the management policies, strategies, or mechanisms of each risk category, please refer to Appendix 1 of the
Risk Management Policy and Procedures.
▪The Process of Risk Management
▪The Categories of Risk Management
- Financial Risks: Risks affecting financial targets arising from factors such as domestic and foreign interest rates, exchange rate fluctuations, raw material prices, and supply chain risks.
- Environmental & Decarbonization / Energy Risks: Risks arising from global climate change, geographic resources, the carbon-reduction progress of governments, and energy and related fiscal and tax policies.
- Information Security Risks: Risks that threaten the confidentiality, integrity, or availability of the Company's information assets and personal data due to natural, human, or technical factors.
- Strategic & Operational Risks: Risks arising from business strategy, domestic and foreign market competition, technology R&D, industry collaboration, and changes in policies and regulations.
- Corporate Sustainability Risks (ESG): Risks in the environmental, social, and governance dimensions arising from global corporate sustainability issues.
▪Risk Measurement Matrix
For the material risk events it monitors, Walsin Lihwa assesses the risk level based on the degree of impact on the Company and the likelihood of occurrence.
Note: Probability of Occurrence (1–5: Very Low to Very High); Impact Severity (1–5: Negligible to Catastrophic)
Walsin Lihwa's Risks and Control Measures
Based on its established risk management mechanism, Walsin Lihwa uses the Risk Measurement Matrix to assess and analyze risks across the two dimensions of likelihood of occurrence and degree of impact, identifying the extent to which each risk affects the Company's operations and sustainable development. For the risks that the assessment results indicate have a greater impact on Walsin Lihwa, the Company separately compiles the content of each risk, its potential impact, and the corresponding control measures as the focus for subsequent risk control and continuous monitoring.
2025 Emerging Risks
Walsin Lihwa integrates emerging risks into its ERM framework, with ongoing Board oversight. The Company monitors global environmental changes and development trends, taking into account business development and future planning, to identify emerging risks on an annual basis.
▪Process of Identification
▪Results of Identification
Intellectual Property Rights and Confidential Information Protection
Committed to high-value transformation and smart manufacturing, Walsin Lihwa adopted the Taiwan Intellectual Property Management System (TIPS) in 2020 and successfully renewed its TIPS Class A certification in 2025, ensuring that the results of its R&D innovation and process optimization are fully protected. As the organization has developed, Walsin Lihwa has brought procurement management within its scope of implementation and has concurrently deepened its trade secret management system and electronic confidential-labeling management mechanism to strengthen the resilience of its core technology protection.
In accordance with TIPS requirements, Walsin Lihwa formulates annual IP management policies and objectives and fulfills its governance responsibilities, regularly reporting the implementation status and annual promotion plan to the Board to ensure that its IP strategy is closely aligned with the Company's long-term growth goals. The most recent report was submitted to the Board on November 7, 2025.
Grievance and Suggestion System and Whistleblower Protection Mechanism
Walsin Lihwa encourages employees and outsiders to report corruption, bribery, dishonesty, or misconduct. The Company has established Stakeholder Feedback and Complaint Procedures and maintains a Stakeholder Communication Area on Walsin Lihwa's website. Stakeholders may use multiple communication channels, including anonymous reporting, to submit feedback and complaints to management or the head of internal audit. Employees may also use the Employee Suggestion Mailbox. The Company encourages reporting of any suspected unlawful or non-compliant conduct within the organization or with counterparties in order to prevent such incidents, and commits to maintaining confidentiality throughout investigations and ensuring whistleblower protection.
Upon receiving feedback or reports, the responsible departments will conduct an investigation and report the handling status to the Audit Committee. Walsin Lihwa's scope for reporting and preventing suspicious illegal or non-compliant activities covers the following key areas:
Internal Audit
Walsin Lihwa maintains a robust internal audit system, supported by an Independent Director mechanism, to ensure the effective operation of internal controls and reporting mechanisms. Audit activities are planned and executed based on the annual risk assessment results and the management places high importance on the effectiveness of remediating internal control deficiencies. To strengthen the quality of externally disclosed sustainability information and in response to the adoption of IFRS S1 and S2, the Company has incorporated sustainability information disclosure into its internal control system and has conducted audits of the collection and compilation processes for non-financial ESG data to ensure the accuracy and reliability of the Sustainability Report and related disclosures.
The Auditing Office is an independent unit staffed with a Chief Auditor and full-time audit personnel, reporting directly to the Board. In addition to regularly attending Board and Audit Committee meetings to report, the Chief Auditor communicates regularly with the independent directors at least once each quarter to report on internal control operations and legal compliance status. In the event of a material anomaly, the Chief Auditor may report to the Chairman, the convener of the Audit Committee, the independent directors, and the President at any time as needed, ensuring that material risk matters—including the risk of sustainability information disclosure—receive timely disclosure and appropriate handling.
Information Security
▪Information Security Governance and Strategy
To build a "digital sustainability" information system architecture and advance the Company's "digital transformation" goals, Walsin Lihwa—centering on "driving cloud-and-on-premises Zero Trust" and "strengthening cybersecurity resilience"—has established an overall cybersecurity protection platform, conducts simulation drills, and, combining AI-based proactive detection and prevention technology, deploys real-time detection and defense capabilities, in response to the government's policy that "cybersecurity is national security." Based on the NIST CSF and CISA ZTA frameworks, the Company has completed a cybersecurity map and a Zero Trust maturity assessment, implemented defense-in-depth, and applied timely control measures to reduce risk. In accordance with the Cybersecurity Control Guidelines for TWSE- and TPEx-Listed Companies issued by the competent authority and the stock exchange, the Company continuously optimizes its cybersecurity protection, has adopted an integrated cloud-and-on-premises cybersecurity management architecture, and is progressively migrating its information systems and backup mechanisms to the cloud to improve operational efficiency and cybersecurity standards.
▪Organization and Governance Mechanisms
- Dedicated Information Security Management Organization: Walsin Lihwa has established the Information Security and Systems Operations Department, appointing a Chief Information Security Officer (CISO), and assigned cybersecurity managers and dedicated personnel responsible for policy formulation, the advancement of control measures, risk assessment and management, and the execution of the annual cybersecurity plan.
- IT Steering Committee: Serves as the information security management and decision-making body for the Company and its business units; the Committee holds at least one management review meeting each year to review policies and their implementation; related resolutions and project outcomes are reported to the Audit Committee. In 2025, in accordance with the new ISO/IEC 27001:2022 requirements, four cybersecurity regulations were revised to respond to changes in regulations and the external environment.
▪Establishing and Complying with Information Security Management System (ISMS)
Walsin Lihwa adopted the ISO/IEC 27001 ISMS in 2022, covering areas such as information authorization, data backup, system development, outsourced vendor management, and intellectual property rights. It obtained ISO/IEC 27001:2013 certification in 2023, upgraded to ISO/IEC 27001:2022 certification in 2024, and passed recertification in October 2025 (
ISO 27001 certificate link), strengthening threat intelligence, configuration management, and cloud service protection. The Company applies the PDCA cycle to establish its management system and continuously optimizes it based on "prevention beforehand, monitoring during, and response afterward." In 2025, it completed four third-party external cybersecurity risk assessments.
▪Information Security Policy and Objectives
The Company aims to protect the confidentiality, integrity, and availability (CIA) of sensitive data (including customer data and business information). It has established an information security policy and set up business continuity and incident management, periodic compliance reviews, and education and training, strengthening management oversight and company-wide cybersecurity awareness; violators are handled in accordance with laws and company rules. By continuously enhancing its information security management system, the Company ensures information integrity and builds a solid data protection barrier. Through the real-time monitoring of cybersecurity threats, the review of and response to information security incidents, information security vulnerability analysis, and the conduct of cybersecurity incident drills and reporting, it refines the reporting and escalation processes for vulnerabilities or suspicious activities, strengthens all employees' responsibility for protecting information security and reporting cybersecurity incidents, and establishes cybersecurity requirements for third-party business partners (such as suppliers), comprehensively enhancing operational resilience.
▪Information Security Resilience and Systematic Management
In accordance with the six dimensions of "Govern, Identify, Protect, Detect, Respond, and Recover" and the five aspects of "Identity, Endpoint, Network, Application, and Data," the Company advances its cybersecurity control map on a rolling annual basis. This includes planning and building data protection mechanisms and strengthening the security of external information services to reduce the risk of confidential data leakage and improve the ability to block hacker attacks; continuously introducing advanced cybersecurity solutions to effectively protect and manage system, host, and network behavior; regularly conducting education and training and social engineering drills to promote the latest cybersecurity knowledge and raise employees' awareness; and performing disaster recovery drills for critical systems to ensure business continuity. On the technical side, the Company has deployed EDR endpoint protection and monitoring, implemented real-time SOC monitoring, strengthened cloud cybersecurity management and adopted Zero Trust, used M365 Security (AI automation) to assist detection and prevention, introduced Privileged Access Management (PAM), and applied security controls to physical office machines to ensure the security of printing, copying, scanning, and faxing data—overall enhancing the effectiveness of detection, response, and institutionalized management.
▪Information Security Education and Drills
Each year, Walsin Lihwa runs a month-long "Information Security Month" awareness campaign, raising employees' cybersecurity awareness through feature reports and knowledge articles on the corporate portal, and works with the HR department to advance a mandatory company-wide HRD course. On average, it conducts 2 social engineering drills every two months; in 2025, it conducted a cumulative total of 12 email social engineering drills, each with more than 2,900 participants. Those who fail must complete an online course and test. In addition, the Company has fully implemented cybersecurity incident reporting management and completed one drill covering the reporting organization, processes, and external communication mechanisms.
▪Customer and Personal Data Protection
Walsin Lihwa has established a personal data management system in accordance with the Personal Data Protection Act, covering data classification, access controls, outsourcing management, and incident reporting, with ongoing training and internal--audits. The complete policy, practices, and latest announcements are available in the Risk Management > Stakeholder Rights and Interests Area on the
Company's official website.
Regulatory Compliance
▪Foundation of Regulatory Compliance: Corporate Culture of "Commitment to Business Integrity"
The culture of "Business Integrity" requires all of the Company's business activities to comply with applicable laws and regulations in Taiwan and in all jurisdictions where it operates. Walsin Lihwa requires all members of the organization not to prioritize business profit at the expense of violating applicable laws and regulations.
▪Monitoring and Evaluation of Relevant Business Laws and Regulations
As a traditional manufacturing enterprise, Walsin Lihwa's principal legal compliance risks lie, on the manufacturing side, in the labor and environmental laws related to manufacturing and the ban on conflict minerals; on the sales side, in the protection of consumer safety, health, and other rights by industry competent authorities, as well as the Fair Trade Act; and regarding finance and accounting, mainly in tax laws in various jurisdictions and anti-money laundering regulations. As a listed company, Walsin Lihwa must comply with the Company Act, the Securities and Exchange Act, and regulations related to corporate governance and corporate sustainable development.
▪Violations and Penalties
In 2025, there were no incidents involving bribery and corruption, money laundering, violations of the Company Act, insider trading, conflicts of interest, personal data privacy breaches, or other business ethics-related violations. No employees were convicted of bribery-related offenses.
However, during the same year, the Company was fined NT$200,000 for extending working hours beyond the relevant provisions of the Labor Standards Act, and RMB 1.75 million for violating the relevant provisions of the Anti-Monopoly Law of Mainland China. All of the aforementioned penalties have been paid in accordance with the law, and the Company has completed a review of the causes and proposed corresponding improvement plans to prevent similar incidents from recurring.
Note: Material penalty events refer to violations with fines exceeding NT$100,000 or RMB 22,000.