Business Risk Management

Business Risk Management

Business Risk Management

Risk Assessment Process

1Goal Setting and Strategic Planning

When setting annual goals and strategic plans, it is necessary to review whether they support the corporate vision and mission. Strategies are formulated through methods such as information gathering, analysis, and assessment.

2Risk and Opportunity Identification

In accordance with corporate strategic objectives and the “Risk Management Policy and Procedures,” each operating unit conducts a comprehensive identification of risks and opportunities pertaining to its respective business functions and sustainability-related issues. Business functions encompass strategic, operational, financial, and compliance domains, while sustainability issues cover climate change, energy utilization, biodiversity, human rights, supply chain management, and information security.

3Risk and Opportunity Analysis

Identified risk and opportunity events are analyzed based on their nature and characteristics, taking into comprehensive consideration existing control measures, past experience, peer cases, and their potential impacts on financial performance and cash flows; subsequently, risk assessment personnel evaluate the probability of occurrence and the impact severity in accordance with risk analysis and measurement standards.

4Risk and Opportunity Assessment

Based on the analysis results, risk and opportunity events are prioritized to identify those requiring immediate mitigation, following which corresponding response plans are formulated and executed.

5Risk and Opportunity Response Strategy

For risk and opportunity events requiring response actions, a response method is developed considering corporate strategy, stakeholder perspectives, risk appetite, resources, and cost- effectiveness. Specific measures, responsible units, required resources, and implementation timelines are also clearly defined to ensure relevant personnel understand and execute the actions, while continuously monitoring implementation progress.

6Risk and Opportunity Monitoring and Review
  • Significant risks and opportunities identified through assessment as key priorities are subject to appropriate monitoring mechanisms established by the responsible departments.
  • The risk governance team regularly monitors response measures and risk trends to ensure that actions are implemented according to plan. Recordings or minutes are maintained and reviewed by the convener of the risk governance team as a basis for subsequent management activities.

2025 Risk Assessment Results

In accordance with the risk management process, the Company identifies material risks and opportunities across operational, strategic, financial, regulatory compliance, and environmental and energy management dimensions. During this assessment process, risk values are estimated following the risk analysis workflow, compared against the risk appetite established for each risk category, and addressed with appropriate response measures.

The identified items exceeding the Company’s risk appetite encompass operational risks: “Business Continuity Risk” and “Information Security and Privacy Protection Risk,” for which corresponding response strategies and optimization actions are continuously executed. The Company also regularly conducts sensitivity analyses for financial risks—including foreign exchange risk and interest rate risk—and performs stress testing for information security risk.

 

Major Risks

Description

Response Strategy

Business Continuity Risk Inadequacies in power or network supply may impact production and business continuity.
  • Formulate emergency response procedures and conduct regular drills to ensure the rapid resumption of operations in the event of unexpected incidents.
  • Establish contact networks with regulatory authorities and business partners to ensure immediate support when necessary.
Vulnerabilities in information security or a lack of employee awareness may lead to system disruptions and operational impediments.
  • Establish a Business Continuity Committee, formulate management manuals and procedural documents, regularly review risks, update contingency plans, and conduct drills.
  • Maintain and operate the Information Security Management System (ISMS) in accordance with the ISO 27001 framework, and establish a dedicated committee to ensure system security and operational stability.
Emerging infectious diseases may impact employee attendance and supply chain stability, thereby affecting operations.Formulate infectious disease protection guidelines, encompassing reporting procedures, remote and split-site work plans, protective supply management, and environmental hygiene maintenance.
Privacy Protection and Information Security Risk With global operations and widespread digitalization, insufficient information security controls may lead to systems suffering cyberattacks or operational disruptions.
  • Conduct regular internal and external audits in accordance with ISO 27001 and internal control requirements to ensure compliance across all sites.
  • Implement access controls, environmental monitoring, and availability surveillance within data centers to mitigate risks related to power, air conditioning, and fire outbreaks.
  • Establish a High Availability (HA) architecture, conducting regular drills and backups to ensure rapid system restoration.
A lack of information security awareness or human error may lead to the leakage of confidential data and the loss of critical information.
  • Establish network access regulations and security baselines for devices, changing default passwords, installing antivirus and endpoint protective software, and regularly updating patches to address vulnerabilities and improve system performance.
  • Implement vulnerability management procedures, conducting regular device assessments and deploying immediate hotfixes.
  • Ristrict USB access, prohibit unauthorized software installation, and mandate authentication and filtering for both email and network access.
  • Formulate a strong password policy, defining requirements for length, complexity, rotation frequency, and lockout duration.
  • Enforce strict authorization controls for system login and data access privileges, mandating two-factor authentication (2FA) for VPN and external email connections.
  • Deploy encryption protection for sensitive data, requiring authentication through the Company's key management server to mitigate data exfiltration risks.
Privacy protection and information security governance impact corporate reputation, compliance, and operational stability.
  • Require employees to sign Non-Disclosure Agreements (NDAs) and codes of conduct to explicitly define responsibilities and prohibited actions. 
  • Promote physical and online information security training, and continue related communication and awareness-building efforts. 
  • Conduct regular social engineering drills and phishing email tests. Employees who fail must undergo retraining and assessment.

 

 

2025 Sustainability Opportunity Identification Results

 

Risk management extends beyond controlling negative impacts; it concurrently aims to transform risk uncertainties into tangible value for enterprise. During the annual risk and opportunity management process, Inventec identifies “Industry 4.0 and Smart Manufacturing” and “Artificial Intelligence and Computing Performance Enhancement” as its core development opportunities.

 

Opportunity

Description

Expected Impact on the Company

Capital Allocation Items

Industry 4.0 and Smart ManufacturingBy optimizing smart equipment, data platforms, and predictive systems, the Company achieves real-time monitoring and agile production, thereby boosting manufacturing efficiency.
  • Short-term: Increased costs
  • Medium-term: Improved energy efficiency and carbon emission management
  • Long-term: Building differentiated capabilities and unlocking new business opportunities
  • Automated equipment and systems
  • Platform operation and maintenance expenses
  • R&D expenditures, talent cultivation and upskilling costs, and certification fees (e.g., Lighthouse factory certification)
Artificial Intelligence and Computing Performance AdvancementEnhancing AI technology and computing performance, particularly for processing massive datasets and complex tasks, thereby driving market analysis, operational efficiency, and cost reduction, while further unlocking new business models.
  • Short-term: Increased expenses; improved energy efficiency and carbon emission management
  • Medium-term: Strengthened customer relationships or acquiring new customers
  • Long-term: Pioneering new operating models
  • High-computing power platforms and energy-efficient data centers
  • Expenses for cloud data optimization and machine learning model development
  • R&D project expenses, and talent cultivation and upskilling costs

Emerging Risk Management 

 

The identification of emerging risks is based on external environmental analysis. By gaining a profound understanding of issues widely prioritized by the industry and benchmark companies, and extensively gathering input from risk owners and relevant personnel, the Company systematically filters emerging risk items highly relevant to Inventec. These items are ultimately confirmed and consolidated into the emerging risk events for 2025.

 

Emerging Risk Event

Description

Countermeasures / Risk Management Measures 

Weaponization of Key Technologies, Resources, and Supply ChainsGeopolitics and regional conflicts have turned key technologies (e.g., semiconductors), critical resources (e.g., natural gas, rare earths), and supply chains into strategic weapons under national policies. This elevates operational complexity, subsequently impacting operating costs, and potentially causing supply chain disruptions.
  • Implement a globally diversified footprint to reduce reliance on any single country.
  • Fortify supply chain resilience by establishing a diversified supplier base and inventory buffering strategies.
  • Construct dynamic monitoring and early warning mechanisms, activating contingency plans as necessary.
  • Align with sustainability trends, dynamically adjusting sustainability strategies, and collaborating with supply chain partners to achieve established goals.
AI Application BiasDue to data or design biases, AI applications may result in negative impacts, including discrimination or prejudice stemming from algorithmic errors, flawed decisions that triggered cascading operational disruptions, regulatory non-compliance, or malicious exploitation.
  • Strengthen data governance and quality control to ensure the completeness and objectivity of training datasets.
  • Implement an AI governance framework to guarantee fairness, transparency, and explainability.
  • Safeguard privacy and information security by deploying encryption technologies and complying with international regulations.
  • Establish accountability and review mechanisms to regularly detect algorithmic biases and update models.
Impact of Artificial Intelligence and Quantum Technology Development on Cybersecurity Artificial intelligence may be exploited by threat actors to launch automated cyberattacks, fabricate disinformation using deepfake technology, and significantly increase the success rate of social engineering campaigns. Meanwhile, quantum computing possesses formidable computational power capable of cracking existing encryption algorithms in the future, rendering traditional cryptographic defenses obsolete. Concurrently, the rapid evolution of emerging technologies intensifies the complexity of cyberattacks, exposing the Company heightened security threats and necessitating the preemptive deployment of advanced cybersecurity strategies.
  • Build expertise in post-quantum cryptography, comprehensively assessing the potential threats posed by quantum technology development to the Company.
  • Deploy AI-powered cybersecurity defenses to fortify security verification and anomaly detection mechanism.
  • Promote organization-wide information security training and drills, establishing cross-departmental contingency plans.
  • Adhere to international information security standards and frameworks, dynamically updating corporate management systems and protective technologies in a timely manner.

 

Report download
SDGs