Framework of Risk Governance and Management

TOP

To effectively manage the various risks arising from the operations of SinoPac Holdings and its subsidiaries, the Board of Directors serves as the highest authority for risk oversight. In addition to approving risk management policies and risk appetite or limits, the Board delegates the responsibility of day-to-day risk management to the management team. Based on its authority, the management should supervise risk management activities, evaluate the performance of risk management, and make sure that each risk management officer works professionally and in line with the code of ethics.

The Audit Committee is composed of three Independent Directors. They assist in supervising the effective implementation of the internal control system of SinoPac Holdings, compliance with laws and regulations, controlling existing or potential risks, and assisting the Board of Directors in making decisions with its professional division of labor and independence. Its duties include receiving regular reports from the Risk Management Division on potential risks and their management, supervising the implementation of risk management by the Company and subsidiaries, and deliberating the Company's risk management policies.

The Risk Management Committee has been set up under the Chairman, who serves as the convener of the committee, to take charge of deliberating on the risk management policy, organization, system, and risk limit, reviewing overall exposures and risk profiles, supervising risk management activities of SinoPac Holdings and its subsidiaries, coordinating efforts to manage significant risk events, and deliberating on other issues related to risk management.

The Risk Management Division has been set up under the President to coordinate the formulation of overall risk management policies and standards as well as the establishment and planning of risk management systems for the Company and its subsidiaries. The Risk Management Division is responsible for promoting the policies, standards, and systems after they have been approved by the Board of Directors, and periodically evaluates the implementation results and management performance of each subsidiary.

Based on its authority, the management assigns the controlling unit or personnel to be responsible for the risk management of its business to ensure that all risks are properly monitored.


Risk Management Organizational Structure of SinoPac Holdings and Subsidiaries


SinoPac Holdings Risk Management Structure and Duties

Board of Directors

The Board of Directors is the highest supervisory unit. It is responsible for the approval of SinoPac Holdings' risk management policies, risk appetite, or limits, and granting authorization to the management for daily risk management.

Audit Committee

The Audit Committee is composed of 3 Independent Directors., and its purpose is to assist in overseeing the effective implementation of the Company's internal controls, compliance with relevant laws and regulations, and the management of the Company's existing or potential risks, as well as assisting the Board of Directors in making decisions through its division of professional duties and independent position. Its duties include receiving regular reports from the Risk Management Division on potential risks and their management, supervising the implementation of risk management by the Company and subsidiaries, and deliberating the Company's risk management policies.

Risk Management Committee

The Chairman serves as the convener of the Risk Management Committee to take charge of deliberating on the risk management policies, organization structure, systems and overall limits, reviewing the overall risk exposure, supervising the risk management activities of SinoPac Holdings and its subsidiaries, coordinating efforts to manage material risk incidents, and reviewing other issues related to risk management.

Audit Division

The Audit Division, under the Board of Directors, is responsible for independent auditing and is the third line of defense in the risk management hierarchy. The Chief Auditor is the highest-ranking person with responsibility for the planning and implementation of various types of audits.

Risk Management Division

The head of Risk Management Division is the highest-ranking officer of risk management units and oversees the formulation of the overall risk management policy and standards of the Company and subsidiaries and the establishment and plans of the risk management system. The policies, guidelines, and systems are approved by the Board of Directors and implemented by the Risk Management Division, which conducts regular evaluations on the performance of all subsidiaries in terms of risk management.