Risk Management
Risk Identification
Rapid societal and technological advancements, coupled with climate change, market expansion, and frequent cyberattacks, have heightened operational volatility and business risks. Recognizing the urgency of effective risk governance, ChipMOS established the <Risk Management Policy and Procedures>. This framework defines our risk management scope and organizational responsibilities to strengthen corporate governance and build a resilient risk management mechanism.
Scope of Risk Management
The scope of the ChipMOS's risk management covers various risks faced in the process of operating activities, including operational risks, climate change risks, information security risks, financial risks, supply chain risks, and legal compliance risks.
Risk Management Organization Functions
The Board of Directors, is the highest decision-making body, formulates risk management policy and organizational structure with Audit Committee supervising the operation of risk management to ensure the effectiveness of the risk management mechanism. The Risk Management Team is the competent authority for implementing risk management. The first-level supervisor serves as the convener to drive the Risk Management unit including operation manufacturing, information technology, human resource, finance and accounting, purchase and logistics, legal and other units, covering finance, strategies, operation and disaster aspects. Department head, is assigned by each Risk Management unit, evaluates quantitatively the frequency, impact and control degree of potential risks through identification, analysis, evaluation and other procedures. Then implement necessary procedures and risk management works in compliance with rules, and ensure that the involved risks are controlled within the affordable scope and keep monitoring.

The Implementation of Risk Management
On August 12, 2025 the Audit Committee reviewed the ever-changing risk environment facing ChipMOS, the focus of the Company's enterprise risk management, risk assessment and risk mitigation actions to be taken, and briefed to the Board of Directors.
Case Sharing: Severe Infectious Diseases (COVID-19) Pandemic Control Strategies and Response
