Corporate Governance in ESG
Performance Evaluation
To enhance the functions of the Board of Directors, the Company has established the "Board of Directors and Functional Committees Performance Evaluation Procedures." The Board of Directors and its functional committees conduct an internal evaluation once a year and an external evaluation every three years. Based on the results, improvement suggestions are proposed to further strengthen the effectiveness of the Board.
2024 Internal Performance Evaluation Results Exceeded Standards
(Evaluation score of 90 points or above)
Board of Directors / Audit Committee / Remuneration Committee / Sustainable Development Committee / Nomination Committee
Implementation Status of External Performance Evaluation Recommendations
In 2022 (2022.1.1~2022.12.31), the Company engaged the "Taiwan Corporate Governance Association" to conduct an external evaluation of the Board of Directors’ performance. Through the independence and professional review of external experts and scholars, the evaluation examined and provided recommendations on seven aspects: Board composition and structure, director selection and training, participation in company operations, decision-making quality, internal controls, sustainability and environmental responsibility, and value creation. The recommendations and follow-up measures are as follows:
RecommendationEstablish a mechanism whereby whistleblower letters are simultaneously forwarded to the independent directors (or a designated independent director), highlighting the Company’s commitment to fair handling of whistleblowing cases. It was also recommended that the evaluation and remuneration of the Head of Internal Audit be submitted to the Remuneration Committee for discussion. |
MeasuresRegularly report to the Board of Directors on stakeholder complaints and grievances, fully disclosing related matters to ensure that Board members are promptly informed and can conduct fair discussions. |
Implementation StatusReports on stakeholder (employee suggestions or complaints) communications were presented to the Board of Directors on August 8, 2024, and January 8, 2025. |
Business Ethics
Operate with the highest ethical standards, integrating integrity and ethical values into the company's business strategy. This ensures that the DNA of integrity is deeply rooted within the organization, fulfilling the mission of being a high-quality enterprise in harmony with society.
-
Education and Training
To ensure employees fully understand relevant regulations, the Company implements education, training, and awareness programs. All employees (including those at domestic and overseas sites) are required to sign the "Wiwynn Code of Conduct" and complete designated training courses. In 2024, the global employee signing rate reached 100%, and refresher training was conducted, with a training coverage rate of 100%.
-
Anti-Corruption and Anti-Bribery Advocacy
To maintain the highest standards of ethical behavior, any form of bribery is strictly prohibited. Before the three major holidays, internal emails and the employee information portal are used to communicate to all Wiwynn employees, reiterating the regulations regarding the acceptance of gifts.
-
Anti-Corruption and Anti-Bribery Reporting System
Wiwynn has established internal and external reporting channels:
1. Internal: Announced on the company’s TV wall and employee information website
2. External: Reporting mailbox provided on the official website
The company has formulated relevant regulations, clearly outlining reporting procedures and protection measures. From 2020 to 2024, no reports were received.
Reports can be made anonymously, and the company is committed to protecting whistleblowers and participants in the investigation, preventing improper handling or retaliation. -
Supplier Integrity Policy
Wiwynn requires new suppliers to sign the "Supplier Integrity Policy Letter," committing not to engage in improper benefit transfer. Those who do not sign are not eligible to become suppliers. In 2024, suppliers signed achieving a 100% completion rate.
-
Risk Assessment
Wiwynn conducts integrity and ethical risk assessments at major global locations in accordance with the RBA Code of Conduct. In 2024, there were no significant risks identified, and risk mitigation controls continue to be implemented.
Risk Management
In 2024, the Company established the "Risk and Security Management Policy and Procedures" and set up the Risk and Security Management Representative Committee. The members of the committee are appointed by the Chief Executive Officer and are responsible for consolidating risk and security issues. At least once a year, the committee submits proposals and reports on risk and security matters to the Audit Committee and the Board of Directors.
Organizational Chart
The Risk and Security Management Representative Committee consolidated 68 risk items and 825 risk factors, which were further categorized into 10 aspects comprising 69 risk items.
Risk Classification
Based on the results of the matrix analysis, there are 8 high-risk items, 13 medium-risk items, and 48 low-risk items. The 8 high-risk items were grouped into four major categories:
1. Paradigm shifts and industry changes driven by technological transformation
2. Trade protectionism and geopolitical issues
3. Information security
4. Material management
Corresponding response measures were developed and approved by resolution of the Audit Committee and the Board of Directors on February 27, 2025. The Company will continue to promote and foster a risk-aware corporate culture to advance sustainable development.
Risk Matrix
Risk Response Strategies
Risk Education × Performance Incentives
At the beginning of each year, approximately 200 global functional representatives receive "Risk and Opportunity" training. The program covers risk assessment and identification, regulatory compliance and internal controls, as well as continuous improvement and monitoring mechanisms. The purpose is to strengthen employees’ risk awareness and response capabilities. Tangible achievements in risk reduction are incorporated into performance evaluations, including indicators such as reduced employee turnover, decreased occupational injury rates, lower Lost Time Incident Rate (LTIR), and maintenance of third-party information security ratings. Incentives and rewards are linked to KPI attainment, thereby enhancing the overall effectiveness of the organization’s risk management.
Regulatory Compliance
Wiwynn continuously monitors regulatory changes and updates internal systems as needed to strengthen compliance management. Annual regulatory compliance audits are conducted to identify and manage risks. No major violations occurred in 2023.
The Company established an RBA Management Committee, committed to complying with the Responsible Business Alliance (RBA) Code of Conduct, and encourages suppliers to follow suit. Multiple ISO management systems have been adopted to enhance risk management, promote environmental protection, reduce waste, lower carbon emissions, improve energy efficiency, and safeguard human rights and workplace safety.
In 2024, the Company was not subject to any legal proceedings or penalties related to anti-competitive behavior, antitrust violations, or monopolistic practices.
In 2024, a total of 33,680 employees received training on regulatory compliance and management systems, amounting to 61,069 training hours.
Information Security
Information Security Management Structure
A cross-functional, top-level Information Security Management Committee was established to monitor current conditions, strengthen management, and ensure agile responses. The Chief Information Security Officer (CISO) reports annually to the Board of Directors, with the most recent update presented on January 8, 2025. The Board is responsible for overseeing information security matters.
In November 2024, Wiwynn obtained ISO/IEC 27001:2022 certification, covering critical systems and infrastructure at its Taipei headquarters, as well as core systems and data centers at the Tainan facility. This certification scope covers approximately 71% of the Company’s global core systems and will be progressively expanded to include other operational sites, such as subsidiaries in Malaysia and Mexico.
Information Security Management Procedures
In December 2023, Wiwynn obtained ISO/IEC 27001:2013 certification, covering critical systems and infrastructure at the Taipei headquarters as well as the data center at the Tainan facility. The certification scope covers approximately 51% of the Company’s operating sites (Note). The Company will progressively expand the certification coverage to include the Tainan facility and overseas subsidiaries such as Mexico.
Note: ISO/IEC 27001:2013 certification obtained by the Taiwan headquarters. Coverage percentage is calculated based on the proportion of employees at the Taiwan headquarters to the total number of indirect employees across all global sites.