Risk Management


Risk Management

 
In an environment where competition is fierce and changing rapidly, effective risk management can improve organizational resilience and promote sustainable development of enterprises. CTCI has implemented a strong risk governance framework and management process that includes actions such as risk identification, risk analysis, risk evaluation, risk response and treatment, residual risk evaluation, and improvement tracking. This framework enables the company to implement riskmanagement strategies and measures such as prevention, reduction, transfer, or assumption when confronted with internal and external uncertainties. The goal is to increase risk awareness and tolerance while also strengthening competitive advantage and value creation capabilities.
 
  

Risk Management Policy and Governance Structure

CTCI follows the COSO Enterprise Risk Management-Integrated Framework and ISO 31000 Risk Management framework and procedures to conduct comprehensive risk assessment and management, set risk management and control goals, and closely integrate risk management with the company's goals to ensure the stability and sustainable development of business operations. The three-line of defense model of enterprise risk management is adopted for corporate risk governance to effectively control risks.
 

Policy and Governance Structure

CTCI has established "Risk Management Policies" and "Risk Management Regulations," which serve as the supreme guideline for risk management. The Board of Directors at CTCI is the highest governing body responsible for the company's risk management. Among the board members, five nonexecutive directors have professional backgrounds in risk management. The Audit Committee, under the Board of Directors, supervises the risk management operations. Additionally, there is an Executive Risk Management Committee that reports the annual risk management performance to the Audit Committee each year. The 2025 Risk Management Operations has been reported to the Audit Committee and the Board of Directors on November 5, 2025.
 

Risk Management Organization, Roles and Responsibilities

CTCI adopts the three line of defense model for enterprise risk management. The first line of defense comprises the operating units, which are responsible for understanding and managing risks in daily operations and implementing relevant risk control measures. The second line of defense is the Risk Management Executive Committee, chaired by the President and convened by the Head of Legal and Compliance Division, with members including the Head of Executive Management Office, and the Head of Business Operations. The committee convenes semiannually and holds ad hoc meetings as needed. Its responsibilities include examining risk management policies and relevant regulations, approving risk appetite, reviewing risk management reports and proposed improvement plans, evaluating the effectiveness of risk control mitigation measures, and overseeing the implementation of risk mitigation measures and improvement plans.
 
To ensure the continuous and effective operation of risk management mechanism, CTCI has established the Risk Management and Control Section as a dedicated risk supervision unit. This unit is tasked with establishing and promoting the risk management mechanism and culture, identifying and controlling daily risks, promoting risk management-related activities, organizing risk management review meetings, and supporting other related risk management tasks. The independent audit unit -Audit Department-under the Board of Directors serves as the third line of defense, responsible for evaluating the effectiveness of risk monitoring performed by the first and second lines of defense and providing timely recommendations for improvement. Internal audits are conducted regularly on an annual basis and reported to the Audit Committee to ensure the effective implementation of the company's risk management policies.
 

Risk Management Mechanism

In order to reduce the impact of internal and external uncertainties on operations, CTCI has a complete risk management process in place to systematically identify, evaluate and respond to the threats (or opportunities) the company faces. This helps avoid or mitigate the impact on business operations. All employees are also responsible for identifying and reporting risks. Upon detection of material risk events that may affect the company's operations, they shall be reported to their supervisors immediately.
 
CTCI divides risks into three categories based on the Group's operations, strategies, internal/external issues, among other things. Events, behaviors or potential issues that may affect the company's expected business goals, execute strategies, or even threaten the company's survival are within the scope of the company's risk management. CTCI's risk categories and primary risk aspects are as follows:
 
Key risk items have been identified and defined for each major risk aspect of "Corporate Operational Risk" and "Project Risk." The key risks are fully discussed and evaluated between the Risk Management and Control Section and the relevant responsible units, before formulating and proposing the "Alert Criteria" and "Action Criteria" as the company's risk appetite to the Risk Management Executive Committee for review and approval by the President for implementation. The approved risk appetite is incorporated into the relevant internal regulations (SOP) to serve as the criteria for risk monitoring, treatment and control. For daily risk appetite management, risks of medium severity or lower are within the company's risk appetite; risks with medium severity or above means that such risks have reached alert criteria; risks with significant severity or above means that such risks have reached action criteria. If the risk reaches the alert criteria, it shall be listed for management and tracking in accordance with SOP. If the risk reaches the action criteria, a response team must be formed to handle the risk event, and relevant actions must be reported to the management according to regulations. When the risk has been properly controlled, with consent, the case can be dismissed and closed.
 

 

Risk Management Implementation Procedures

CTCI identifies potential risks within each department's business scope through regular seminar meetings and, based on the "consequence/probability matrix method," draws a risk matrix to determine the risk rating by considering financial indicators (such as gross profit impact) and non-financial indicators (such as image, reputation, safety, etc.) of the consequence of risk consequences and the likelihood of the event. When it is difficult for the company to clearly or timely evaluate the consequence and probability of the identified risk items using the "consequence/probability matrix method," it will use the "Risk Index method" as the basis to evaluate rate risks. If the existing risk is rated as "High risk" and "Slightly High risk," an improvement plan should be immediately developed, and continuous tracking and improvement should be carried out after the implementation of various risk response measures to properly manage the risks.
 

 

Risk Management Implementation Status

Risk Identification, Analysis, Evaluation and Treatment

According to the scope covered by the risk management framework, CTCI has identified Risk Items of Key Concern and evaluated their risk rating in the 2025 risk assessment. Based on these risk rating, appropriate control methods and necessary mitigation measures were planned, implemented, and communicated to the stakeholders. Responsible units performed risk response and treatment based on the planned mitigation measures, while continuously implementing and monitoring the execution status of these plans to ensure they were fully and effectively implemented. Furthermore, the identified material topics (see "1.5 Materiality and Stakeholder Communication") have also been incorporated into the scope of risk identification. In 2025, a total of 39 risk items were monitored; the statistics by category and risk level are presented in the table below.
 
The main risk of Key Concern of each risk category and its mitigation measures are explained in the table below.

 

Risk Management Audit

Internal Audit

A sound internal control system enables more effective risk management, which in turn helps strengthen the foundation of enterprise operational resilience. CTCI's internal audit unit (Audit Department) prepares an annual audit plan based on the results of risk assessments to monitor the company's risk management. It also evaluates the self-assessment reports of each unit and subsidiary, so that they could be further evaluated by the President and Chairman as the basis for issuing the internal control system statement. The implementation of relevant internal control systems is subject to spot checks from time to time by the competent authority.
 
Pertaining to the requirements of various ISO standards (including ISO 9001 Quality Management System, ISO 14001 Environmental Management System, ISO 27001 Information Security Management System, and ISO 45001 Occupational Health and Safety Management System) in risk management, the responsible units also plan an annual audit schedule to conduct regular internal audits. These audits assess the compliance and effectiveness of the risk management processes. All nonconformities found during the audits are reviewed and improved, with root cause analysis conducted to prevent similar defect. The findings from the 2025 internal risk management audits have all been improved.
 
Furthermore, the CTCI follows the ISO 31000 Risk Management - principles, framework, and processes, as well as the company's risk management related SOPs, to monitor that risk management processes carried out by various risk control units are compliant. Internal risk audits are conducted at least every two years. The most recent audit was completed between June and September 2025, and all non-compliance issues have been improved by the responsible units.
 

External Audit

To ensure the effectiveness and compliance of CTCI's risk management processes, the relevant SOPs require a third-party audit of risk management principles, process architecture, and execution at least every two years. This is to confirm that the company's risk management system complies with the international risk management standard ISO 31000. Furthermore, in order to assess the company's risk management practice and improve overall risk management capabilities, CTCI commissioned SGS, an external verification 3rd party, to conduct a risk maturity audit in Nov. 2025. The audit result was " Role Model," indicating that CTCI has a good understanding of risk management, has a well-developed risk management system, and performs risk management at an exceptional level.
 

Continuous Improvement

CTCI has implemented a Lessons & Learned (L&L) mechanism. For major emergency risk events (ex. GVEH Accounts Receivable Recovery), the responsible units should submit risk treatment reports and L&L for review and approval. After the L&L has been reviewed and approved, the Risk Management and Control Section distributes it to relevant units so that necessary preventive measures can be implemented. The Risk Management and Control Section will also review and revise the relevant management mechanism depending on the preventive measures derived from L&L.
 

Deepening the Risk Culture

CTCI is committed to establishing and deepening a comprehensive risk culture. In addition to continuing to promote the company's risk management regulations and procedures to colleagues through all levels of management, the company ensures that colleagues are aware of risk management policies and risk management and control related requirements, so that they can be used in daily operations. In addition to the compliance and implementation, the supervisors at all levels and all colleagues also regularly organize awareness-raising or training activities to enhance the risk awareness of all colleagues.
 

Risk Management Indicators

To strengthen the implementation of risk culture and enhance the effectiveness of risk management, CTCI considers the direction of risk control and the expected achievement each year to plan the Group's annual risk management and control objectives. All risk management units are required to implement these measures, which are then measured and monitored. These objectives are also incorporated into the annual Key Performance Indicators(KPIs) of managers at all levels. The Group's risk management and control objectives for 2025 are "High implementation rate of ‘Risk Management and Control'" and "High implementation rate of ‘Risk Management Training.'" For all employees, the company has incorporated key elements of its risk culture―namely "safety behavior" and "integrity"―into the annual performance evaluation indicators. Employees are required to strictly adhere to SOPs, identify situations that may impact safety, and respond promptly. They are also expected to act with integrity, comply with laws, employee codes of ethical conduct, company policies, regulations and procedures, and are encouraged to report, disclose, or stop any behaviors that may harm the company's interests. This effectively
links the performance of risk control to the KPIs and rewards (performance bonuses) for both supervisors and employees.
 
In addition, the risk assessment process and indicators are also included in the product or service development process. Before CTCI implements each project, the project team would conduct risk assessment during the proposal stage and the execution stage (including the AEPCK Project Life Cycle and identify and manage foreseeable risks and opportunities, so as to reduce unfavorable factors and promote the realization of project goals. Please refer to the "2.1.C Customer Service/Project Evaluation and Community Communication" section for details and examples.
 

Motivation and Rewards

To mitigate the potential negative impacts of Risk Items of Key Concern, CTCI has not only established risk mitigation measures but also further implemented financial incentives tied to risk management indicators.
 
Taking the Risk Item of Key Concern regarding HSE (the impact of major occupational accidents on project progress and company reputation) as an example, CTCI has incorporated incentives related to on-site accumulative safety man-hours per completed project within the "Employees Reward and Punishment Regulations." Based on performance benchmark, different levels of awards and bonuses can be awarded to specifically encourage behaviors that reduce safety risks. In addition, CTCI selects outstanding projects and individuals that contribute to HSE protection. In 2025, seven projects were selected, and 44 outstanding colleagues received reward as encouragement. For the identified Risk Item of Key Concern―insufficient key project personnel―the Group also provides substantive bonuses through its employee referral program. In 2025, 60 bonus payments were issued across various stages of the internal recommendation process.
 
In response to the Key Concern of climate and nature risks, CTCI organized the "CTCI Group ESG Award" activity in 2025 to encourage employees to propose concrete plans for environmental action and awarded them with bonuses in expectation of mitigating the potential impact of climate and nature-related risks. Four bonuses were awarded. These collected action plans spanned engineering design optimization, AI system development, office energy conservation, resource recycling, and carbon footprint management, with many already being evaluated or adopted by the responsible units.
 

Risk Management Education for Directors and Senior Management

In order to enhance the risk awareness of the Group's directors and senior executives, the Risk Management and Control Section and Secretariat of the Board regularly review current affairs and internal control needs every year, and plan relevant risk education. In 2025, the company hosted a seminar titled "Global Financial and Economic Changes on Future Market," inviting the Vice President of the Chung-Hua Institution for Economic Research as the keynote speaker. The session focused on the "Global and Taiwan Economic Outlook," "The impact of Trump's rise to power and geopolitics," and "Response strategies and investment trends." A total of 61 participants attended, including Directors from CTCI Corporation, CTCI ASI, and ECOVE, as well as Corporate Governance Officers and other senior officers.

In addition, the company regularly organizes annual mandatory CTCI risk management education for non-executive directors to strengthen the board's understanding of risk management principles, the risk governance framework, and the risk tolerance planning linked to CTCI Group's strategic objectives. In 2025, 100% of all non-executive directors completed the "Risk Management Principles" education.
 

General Management (Line Manager) Training

To enhance the Group's risk management and control, CTCI conducted the "Group Risk Management Requirements Awareness Training (Management Level)" in 2025. Participants were taught on the concepts of risk and risk management, SOPs, risk management policies and objectives related to the Group's risk management, risk management roles and responsibilities of supervisors at all levels, risk classification, as well as risk control and risk audit. The goal was to establish supervisors' proper awareness of risk management and ensure their understanding of the basic requirements and provisions of the Group's risk management and control. Prior to the revision and issuance of risk management and control SOPs, relevant supervisors were invited to participate in joint reviews to strengthen communication, ensuring that the management team understood the provisions of the
SOP, the rationale for revision, and the underlying control objectives and principles.
 
Additionally, to enhance the capabilities to review and interpret engineering contract terms and their knowledge on risk control in contract performance, general management training activities were conducted, and experts from the Construction Management Association of The Republic of China (CCMA) were invited to share their insights on practical dispute resolution in engineering contracts in a workshop of the same name. In addition to the introduction of highlights in contract performance management, the workshop explored common performance dispute cases in two contract types, i.e., EPC and BOT. The trainees included CTCI Group's contract administrator, legal personnel, sales representative, and relevant supervisors at the project level (such as project managers and project contract managers), with 314 people in attendance.
 

Risk Training for All Employees

CTCI has conducted "Group Risk Management Requirements Awareness Training" based on risk management principles. The training covered all managers across Group companies as well as all employees, aiming to strengthen the understanding of risk management principles and overall risk awareness among all Group members. The completion rate in 2025 reached 99.4%. Furthermore, the company systematically plans risk education and training courses for all employees every year in response to specific risk aspects and core issues. In 2025, these courses focused on climate and natural risk, strategy/goals, legal compliance/intellectual property, integrity management, and HSE, to continuously enhance risk management capabilities.
 
In addition to the regular provision of training activities related to risk management, CTCI has also continuously shared risk management-related information with employees through diverse channels such as the internal website, internal communication zone, and the Group E-Newsletter; for example, in an article featured in the sustainable governance column of CTCI's ESG E-newsletter in September 2025, it focused on risk management and detailed how CTCI continuously optimized the risk control mechanism in response to the changes in the external environment, including addition of a gate review control mechanism in the project proposal stage and improvement of the Data Leakage Prevention (DLP) system. It aimed to cultivate employees' risk-oriented mindset and integrate risk management into daily conduct and work, thereby continuously improving all employee members' risk awareness and deepening the cultivation of a risk culture.