德英生物科技

Risk Management

Risk Management Policies and Procedures

Item Description
I. Risk Management Policies and Procedures To effectively identify, assess, and monitor various risks faced in the course of the Company’s operations and to ensure business sustainability and shareholders’ rights and interests, the Company has established risk management policies and procedures. The Board of Directors bears the ultimate responsibility and authorizes the management team to carry out risk assessment, monitoring, and improvement in accordance with the internal control system, so as to ensure that all business activities comply with regulatory requirements and the Company’s strategies.
II. Scope of Risk Management The scope of the Company’s risk management includes, but is not limited to:
  • Political and economic risks
  • Financial risks (including market risk and liquidity risk)
  • Information security risks
  • Operational risks (including human resources, supply chain, compliance, etc.)
  • Environmental, occupational safety and health, and climate change risks
III. Implementation of Risk Management Each department periodically identifies potential risks based on its responsibilities and implements management measures, while the administration department consolidates the annual risk assessment report for submission to the Board of Directors for review.
Main implementation measures are as follows:
  1. Conduct periodic internal audits and follow-up on improvements in relation to regulatory compliance, financial status, and operational performance.
  2. The IT department implements information security protection measures, including access control management and regular backup mechanisms.
  3. The HR department promotes occupational safety training to reduce workplace safety risks.
  4. The finance department monitors market changes and manages foreign exchange and interest rate risks.
  5. The Sustainability Committee continuously reviews the impact of climate change and environmental regulations on the Company.
IV. Future Risk Management Plans To enhance overall risk management effectiveness, the Company will:
  • Continue to refine risk identification and assessment mechanisms and introduce quantitative analysis models.
  • Integrate corporate information security governance and adopt ISO 27001 or related standards.
  • Establish ESG sustainability risk monitoring indicators and incorporate them into the Board’s decision-making reference.
  • Strengthen supply chain management and emergency response drills.
  • Review risk policies and implementation results annually to ensure alignment with the Company’s strategies.

※ On mobile devices, you can swipe horizontally to view all table columns; on desktop, the full width is displayed without truncation.