


In a rapidly changing geopolitical and economic environment, enterprises face challenges across environmental, social, and governance dimensions. To strengthen Board oversight and organizational resilience, Ventec adopted the Risk Management Policy and Procedures at the fourth meeting of the Board in 2021, providing the foundation for sound operations and sustainable development.
Ventec's risk-management governance is organized across multiple levels. The Board of Directors serves as the highest risk-oversight body, responsible for legal compliance and for ensuring the effectiveness of risk management while maintaining clear visibility of material operating risks. The Audit Committee supervises the operation of the riskmanagement mechanism. Based on risk assessments, the Internal Audit Office formulates the annual audit plan and executes audit work to assist the Board in supervising and controlling potential risks. The Chief Executive Officer & General Manager coordinates risk-management activities across the Company. Each responsible function—the Finance Division, Administration Division, Marketing Division, Materials Division, Technology Division, Manufacturing Division, and Information Technology Office—acts as the first line of defense, analyzing, monitoring, and preventing risks within its remit.
Ventec's risk-management policy comprises five parts: effective identification, analysis and assessment, control and treatment, continuous monitoring, and company-wide risk awareness. The procedures cover risk identification, risk analysis and assessment, risk control and treatment, risk oversight and review, and risk communication and reporting. The scope of risks is defined by operating policies and includes environmental, market, operational, investment, credit, information security, legal/litigation, and other risks.
Pursuant to the Risk Management Policy, Ventec annually builds a risk-assessment model tailored to operating conditions and stakeholder expectations. Each department evaluates risks by frequency, severity, and detectability. In 2024, 63 risks were assessed and categorized as high, low, or general; three high-risk factors were identified. After resource evaluation, priority measures were formulated for these high-risk factors. The effectiveness of all mitigation strategies is reviewed regularly by the responsible functional heads to ensure business continuity.
