Risk Assessment

The Company has the Board of Directors as the highest governance unit for risk management. The Board of Directors has overall responsibility for the Company's risk governance. The Audit Committee assists the Board of Directors in supervising the risk management system, including reviewing the Company's enterprise risk management structure and processes to facilitate the identification and management of risks, and report to the Board of Directors major issues, findings and recommendations related to risk management.

Currently the company's governance director is responsible for coordinating various departments to implement risk identification, assessment, management, response and supervision, and regularly reporting risk management results to the board of directors. The company established the Sustainability Promotion Taskforce in 2024 to serve as the unit responsible for executing risk management. In consideration of the company's overall scale, business characteristics, risk nature, and operational activities, we plan to formulate the "Risk Management Policies and Procedures" in 2026 with reference to the "Risk Management Best Practice Principles for TWSE/TPEx Listed Companies."

PTC's corporate governance director works closely with various functional organizations and departments to assist management in implementing the enterprise risk management structure to ensure that the company's risks are effectively assessed and managed.  To deepen risk-oriented thinking and fully integrate risk management into all company operations, PTC plans to formulate the "Risk Management Policies and Procedures" by the end of 2026, taking into account the company's scale, business characteristics, and risk profile with reference to the "Risk Management Best Practice Principles for TWSE/TPEx Listed Companies," and submit it to the Board of Directors for approval.

This policy will serve as the company's highest guiding principle for risk management, covering:
1. Risk management objectives
2. Risk governance and culture
3. Risk management organizational structure and responsibilities
4. Risk management procedures
5. Risk reporting and disclosure

Ensuring that risk management effectively supports the achievement of the company's operational goals through institutionalized risk identification, evaluation, decision-making, and monitoring mechanisms.

The company's risk management scope includes strategic risks, operational risks, financial risks, information risks, legal compliance risks, integrity risks, other emerging risks (such as risks related to climate change or infectious diseases), and risks not listed above, but this risk will cause the company to incur significant losses, such as major external hazard events, risks caused by extreme event losses, etc.

Each functional unit and department of the Company conducts risk management in accordance with a five-step cyclical process consisting of risk identification, assessment, response, monitoring, and review. Based on this framework, enterprise-level risk matrices and corresponding control measures are established. Continuous education and training programs are implemented to strengthen risk awareness and foster a risk-conscious mindset and culture.

The Company also organizes risk management education and training sessions or briefings on a periodic basis to communicate its risk management policies, procedures, and requirements, thereby enhancing employees’ risk management awareness and execution capabilities. By integrating risk management into operational activities and daily management processes, the Company aims to achieve the following objectives:

  1. To accomplish corporate objectives;
  2. To enhance management effectiveness;
  3. To provide reliable information;
  4. To ensure effective allocation of resources.