Enhancing Risk Culture Awareness
Nan Pao is committed to establishing a robust risk management framework. The Audit Committee and the Sustainability Development Committee serve as the highest-level bodies for risk management, assisting the Board of Directors in fulfilling its risk management responsibilities. These committees oversee different categories of risk through clear professional division of responsibilities to ensure effective risk control across various dimensions. Overall risk analysis is coordinated, consolidated, and managed by the Risk Management Task Force, which reports directly to the CEO. In addition, the Audit Team, which reports directly to the Board of Directors, is responsible for monitoring and auditing the entire risk management mechanism. Through internal audit activities, it ensures the effectiveness of risk controls and the proper management of potential risks. Senior management is required to report the evaluation results of risk management indicators at the relevant risk management meetings and is subject to sustainability KPI assessments, which directly impact their variable compensation.
The Board of Directors has established the "Risk Management Policy and Procedures" to define and regulate operational risks. To integrate sustainability risks into the overall risk management system, Nan Pao identifies ESG issues based on internationally recognized topics and the United Nations Sustainable Development Goals (SDGs). Stakeholder surveys are used to incorporate diverse perspectives, and a double materiality analysis approach is applied to identify operational risks. The Sustainability Office confirms the impact drivers, affected areas, assessment methods, and corresponding risks and management measures for nine material topics. At the same time, the Company references the overall Risk Assessment Analysis Report provided by the Risk Management Task Force to identify risk factors related to material topics and key sustainability management priorities. The execution effectiveness of risk mitigation measures by responsible units is subsequently tracked and disclosed in the Sustainability Report. The processes for materiality identification and sustainability goal setting are conducted annually.

| Level / Unit | Responsibilities |
|---|---|
| A. Board of Directors | The highest authority responsible for the Company's risk management. The Board approves risk management policies and related regulations, oversees the overall implementation of risk management, and ensures that risks are effectively controlled. |
| B. Audit Committee | Composed of independent directors of the Board, the Committee is responsible for overseeing and managing financial and internal control risks. |
| C. Sustainability Development Committee | Composed of three or more directors, with more than half being independent directors. The Committee is responsible for managing sustainability, compliance, and information security risks. |
| D. Audit Team | Serves as the third line of defense. Each year, based on the five components of the COSO internal control framework, past audit experience, the proposed budget for the following year, and the existing organizational structure, the Audit Team formulates an audit plan to independently assess management's oversight of internal and external environmental risks, the management of operational risks by each business division, and the effectiveness of the design and implementation of internal control systems. Audit reports are issued and regularly submitted to the Audit Committee and the Board of Directors. |
| E. Risk Management Task Force | Serves as the second line of defense and comprises the heads of each functional unit. It is responsible for establishing, implementing, and reviewing the risk management framework, and for determining risk appetite, approved by the Board. Financial risks apply quantitative thresholds (e.g., potential losses not exceeding a set percentage of annual revenue); operational and ESG-related risks use qualitative assessments, with ultimate supervision by the Board. |
| F. Sustainability Office | The Chief Sustainability Officer (CSO) serves as the highest-level management authority responsible for sustainability, supported by a dedicated Sustainability Planning Team and cross-functional teams comprising representatives from business units and plants, R&D and Innovation, Financial Management, Strategic Procurement, Information Management, Human Resources, and Legal Affairs. The Office reports work progress to the CSO monthly, and consolidates climate-related and sustainability risks and opportunities for reporting to management and the Board. |
| G. Operating Units | Serve as the first line of defense for risk management. They are responsible for identifying, assessing, managing, and continuously monitoring risks arising from their daily operations, implementing relevant control measures and risk management procedures, and regularly reporting on their implementation progress to the Risk Management Task Force. |
Nan Pao's risk management process encompasses key steps including risk identification, risk analysis, risk assessment, risk response, and risk monitoring and review. Each year, the Risk Management Task Force conducts regular assessments and discussions of the Company's potential and emerging risks across the three ESG dimensions — Environmental protection (including climate and natural resources), Social inclusion, and Corporate governance. These assessments take into account the likelihood of occurrence, severity of impact, and effectiveness of controls, and are periodically reported to the Audit Committee and the Board of Directors. In addition to consolidating the overall potential impacts of various risks on the Company, the Company also links the level of impact of each risk to its short-, medium-, and long-term operational objectives.

The Nan Pao Risk Management Task Force includes representatives from the Business Divisions, Operations Management, R&D and Innovation, Financial Management, Strategic Procurement, Information Management, Human Resources, and Legal Affairs:
For the 14 medium-to-high-level risks, corresponding risk response strategies and risk mitigation plans were developed. Risk management personnel then periodically track the implementation of these measures with each operating unit and maintain proper records.


To align with sustainability principles, Nan Pao conducts annual reviews of emerging risks by referencing the World Economic Forum's Global Risks Report and MSCI's Annual ESG and Climate Trends to Watch. Core management units discuss and confirm industry context and risk assessments, followed by the implementation of risk responses and monitoring. Through this process, the Company identifies and manages emerging risks, evaluates potential operational impacts and challenges, and develops mitigation measures.
Nan Pao has implemented a comprehensive risk management process, which includes assessing the Company's risk appetite and its capability to control risks, enabling systematic identification and management of potential risks. Through this process, the Company evaluates the major risks it faces and incorporates them into the overall risk management framework. Reports on the operation of this process are submitted to the Board of Directors annually, covering the assessment of risk scope, risk environment, implemented risk control measures, and the supervision of risk management.
The most recent report was presented to the Board of Directors onMarch 14, 2025.