Business Risk Management
Risk Assessment Process
When setting annual goals and strategic plans, it is necessary to review whether they support the corporate vision and mission. Strategies are formulated through methods such as information gathering, analysis, and assessment.
In accordance with corporate strategic objectives and the “Risk Management Policy and Procedures,” each operating unit conducts a comprehensive identification of risks and opportunities pertaining to its respective business functions and sustainability-related issues. Business functions encompass strategic, operational, financial, and compliance domains, while sustainability issues cover climate change, energy utilization, biodiversity, human rights, supply chain management, and information security.
Identified risk and opportunity events are analyzed based on their nature and characteristics, taking into comprehensive consideration existing control measures, past experience, peer cases, and their potential impacts on financial performance and cash flows; subsequently, risk assessment personnel evaluate the probability of occurrence and the impact severity in accordance with risk analysis and measurement standards.
Based on the analysis results, risk and opportunity events are prioritized to identify those requiring immediate mitigation, following which corresponding response plans are formulated and executed.
For risk and opportunity events requiring response actions, a response method is developed considering corporate strategy, stakeholder perspectives, risk appetite, resources, and cost- effectiveness. Specific measures, responsible units, required resources, and implementation timelines are also clearly defined to ensure relevant personnel understand and execute the actions, while continuously monitoring implementation progress.
- Significant risks and opportunities identified through assessment as key priorities are subject to appropriate monitoring mechanisms established by the responsible departments.
- The risk governance team regularly monitors response measures and risk trends to ensure that actions are implemented according to plan. Recordings or minutes are maintained and reviewed by the convener of the risk governance team as a basis for subsequent management activities.
2025 Risk Assessment Results
In accordance with the risk management process, the Company identifies material risks and opportunities across operational, strategic, financial, regulatory compliance, and environmental and energy management dimensions. During this assessment process, risk values are estimated following the risk analysis workflow, compared against the risk appetite established for each risk category, and addressed with appropriate response measures.
The identified items exceeding the Company’s risk appetite encompass operational risks: “Business Continuity Risk” and “Information Security and Privacy Protection Risk,” for which corresponding response strategies and optimization actions are continuously executed. The Company also regularly conducts sensitivity analyses for financial risks—including foreign exchange risk and interest rate risk—and performs stress testing for information security risk.
Major Risks | Description | Response Strategy |
|---|---|---|
| Business Continuity Risk | Inadequacies in power or network supply may impact production and business continuity. |
|
| Vulnerabilities in information security or a lack of employee awareness may lead to system disruptions and operational impediments. |
| |
| Emerging infectious diseases may impact employee attendance and supply chain stability, thereby affecting operations. | Formulate infectious disease protection guidelines, encompassing reporting procedures, remote and split-site work plans, protective supply management, and environmental hygiene maintenance. | |
| Privacy Protection and Information Security Risk | With global operations and widespread digitalization, insufficient information security controls may lead to systems suffering cyberattacks or operational disruptions. |
|
| A lack of information security awareness or human error may lead to the leakage of confidential data and the loss of critical information. |
| |
| Privacy protection and information security governance impact corporate reputation, compliance, and operational stability. |
|
2025 Sustainability Opportunity Identification Results
Risk management extends beyond controlling negative impacts; it concurrently aims to transform risk uncertainties into tangible value for enterprise. During the annual risk and opportunity management process, Inventec identifies “Industry 4.0 and Smart Manufacturing” and “Artificial Intelligence and Computing Performance Enhancement” as its core development opportunities.
Opportunity | Description | Expected Impact on the Company | Capital Allocation Items |
|---|---|---|---|
| Industry 4.0 and Smart Manufacturing | By optimizing smart equipment, data platforms, and predictive systems, the Company achieves real-time monitoring and agile production, thereby boosting manufacturing efficiency. |
|
|
| Artificial Intelligence and Computing Performance Advancement | Enhancing AI technology and computing performance, particularly for processing massive datasets and complex tasks, thereby driving market analysis, operational efficiency, and cost reduction, while further unlocking new business models. |
|
|
Emerging Risk Management
The identification of emerging risks is based on external environmental analysis. By gaining a profound understanding of issues widely prioritized by the industry and benchmark companies, and extensively gathering input from risk owners and relevant personnel, the Company systematically filters emerging risk items highly relevant to Inventec. These items are ultimately confirmed and consolidated into the emerging risk events for 2025.
Emerging Risk Event | Description | Countermeasures / Risk Management Measures |
|---|---|---|
| Weaponization of Key Technologies, Resources, and Supply Chains | Geopolitics and regional conflicts have turned key technologies (e.g., semiconductors), critical resources (e.g., natural gas, rare earths), and supply chains into strategic weapons under national policies. This elevates operational complexity, subsequently impacting operating costs, and potentially causing supply chain disruptions. |
|
| AI Application Bias | Due to data or design biases, AI applications may result in negative impacts, including discrimination or prejudice stemming from algorithmic errors, flawed decisions that triggered cascading operational disruptions, regulatory non-compliance, or malicious exploitation. |
|
| Impact of Artificial Intelligence and Quantum Technology Development on Cybersecurity | Artificial intelligence may be exploited by threat actors to launch automated cyberattacks, fabricate disinformation using deepfake technology, and significantly increase the success rate of social engineering campaigns. Meanwhile, quantum computing possesses formidable computational power capable of cracking existing encryption algorithms in the future, rendering traditional cryptographic defenses obsolete. Concurrently, the rapid evolution of emerging technologies intensifies the complexity of cyberattacks, exposing the Company heightened security threats and necessitating the preemptive deployment of advanced cybersecurity strategies. |
|