Governance

Risk Management

SDGs

Risk Management

On August 12, 2021, the Board of Directors passed a resolution establishing the SKS Risk Management Policy and Procedures. The Procedures guide the Company to achieve its sustainable development goals by implementing risk management checks and balances and reducing potential operational risks.

The Company's risk management covers a wide range of risks associated with business operations, including market, operational, financial, investment, compliance/contractual, information technology, human resources, occupational hazards, environmental, and other risks. The processes of risk identification, assessment, monitoring, and reporting are executed accordingly and are adjusted in a timely manner in response to changes in the external environment and internal operations.

Risk Management Operations & Supervision Mechanism

Under the Company’s risk management operating framework, each department regularly conducts risk identification and assessment based on its respective responsibilities and reports the relevant information to the Risk Management Task Force for consolidation. The Task Force annually compiles risk information identified by each department and convenes meetings for review and discussion to assess the likelihood and impact of various risks. It also continuously reviews the overall effectiveness of the risk management framework and tracks the implementation of improvement measures in order to monitor the Company’s overall risk exposure and management performance.

Climate change-related physical and transition risks are also incorporated into the existing risk management process for identification, assessment, and management, ensuring that environmental risks are managed under a consistent framework alongside other operational risks.

In addition, the Risk Management Task Force reports on the implementation of risk management and major risk issues to the Board of Directors at least once annually. The Board provides oversight and guidance to ensure the continued effectiveness of the risk management system and strengthen the Company’s overall operational resilience. 
 

  • Established the Risk Management Policy and Procedures and conducts timely reviews and revisions in response to changes in the operating environment.
  • Conduct annual risk assessments across all departments to identify major risks that the Company may face.
  • Regularly convene Risk Management Task Force meetings to review the implementation status of various risk management measures.
  • Report on the operation of the risk management system to the Board of Directors at least once annually.
  • Established an emerging risk management process covering risk identification, risk assessment, risk monitoring, risk reporting and disclosure, and risk response mechanisms, with evaluations conducted based on the likelihood and impact of risks.
  • The Audit Office formulates annual audit plans or special audit projects based on major risk items identified for the following year.


Risk Alert Assessment Process Make


Significant Risk Identification Results and Mitigation Measures


Internal Control System

The internal SKS Audit Office is an independent Company department, reporting directly to the Board of Directors. They primarily assist the Board of Directors and management in assessing and reviewing the implementation status of the Company’s internal control system. They also review the effectiveness and operational efficiency of related systems. When appropriate, they provide improvement recommendations, to ensure continued effective operations for the internal control system. Their recommendations also serve as a basis for reviewing and making corrections to the internal control system. They also produce the internal control system statement.

In accordance with legal requirements, the Audit Office also drafts the annual audit plan; once the plan is approved by the Board of Directors, the Audit Office implements it. They provide audit implementation status updates to all independent directors for review, on a monthly basis. The chief internal auditor also reports on audit implementation status at regular Board of Directors meetings, in order to strengthen Board of Directors oversight mechanisms for corporate governance and internal control systems.

2025 Internal Audit Operations
NO. of audit
90
Deficiencies (all of which were non-material)
15
already improved
12
Deficiency being tracked for improvements
3
Note:

As of December 31, 2025, 12 improvements have been made. There are also 3 improvements being tracked. Complying with information systems development and related responsible departments’ operating timelines, all improvements will be completed by the end of June, 2026.

Major internal SKS audit criteria include the operating processes of the Eight Major Internal Control Cycles; legal compliance audit criteria; subsidiary companies’ internal control operations; etc. These help ensure that all operational activities comply with their systems and with legal requirements.

In accordance with the Financial Supervisory Commission’s Regulations Governing Establishment of Internal Control Systems by Public Companies, the Company has also established a robust internal control system. This includes the Internal Accounting Controls, Internal Management Controls, and Internal Audit Implementation Rules. These regulations cover the Eight Major Cycles of control operations and 19 internal management systems, in order to strengthen the effectiveness of the Company’s governance and operational management.