Corporate Governance in ESG

Performance evaluation

The Company places great importance on the operational effectiveness of the Board of Directors and its various functional committees. Through regular internal performance evaluations and independent assessments conducted by external professional organizations, the Company reviews all aspects of the operations of the Board of Directors and the functional committees, and continuously monitors and implements improvements based on the evaluation results. 

Results of internal performance evaluation in 2025

01

Board of
Directors

Results of performance evaluation
Achieved a score of 90 or above

Exceeding
the standard
02

Audit
Committee

Results of performance evaluation

Exceeding
the standard
03

Compensation
Committee

Results of performance evaluation

Exceeding
the standard
04

Corporate Sustainability
Committee

Results of performance evaluation

Exceeding
the standard
05

Nomination
Committee

Results of performance evaluation

Exceeding
the standard

Status of the implementation of measures suggested by external performance evaluation

The Company commissioned the Taiwan Corporate Governance Association to conduct an external performance evaluation of the Board of Directors for 2025 (from July 1, 2024, to June 30, 2025). Through the independence and professional evaluations conducted by external experts, the evaluation reviews five major dimensions: composition and division of labor of the Board, guidance and supervision by directors, the Board's authorization and risk management, communication and collaboration within the Board, and the Board's self-discipline and improvement. The effectiveness of the Board of Directors is assessed through responses to the questionnaire and on-site evaluations. Evaluation suggestions are as follows: 

Suggestion


It is suggested that the Company conduct communication between the CPA and the Audit Committee through closed-door meetings without any members of the management on-site, and keep written records to enhance the supervisory function of the Audit Committee in auditing financial statements. Moreover, it is suggested to establish an orientation program for newly appointed directors to help them quickly understand the Company's current status and industry information, facilitating the execution of their duties.

Measures


Arrange a separate communication agenda between both parties before the Audit Committee to allow members to fully supervise the auditing of financial statements. In addition, the Company will also regularly arrange orientation meetings for newly appointed directors in the future. 

Implementation status


A separate communication agenda between both parties was added before the 16th meeting of the 3rd Audit Committee on November 7, 2025, and an orientation session on the Company's current status and industry information for newly appointed directors was arranged on October 22, 2025, to facilitate the quick understanding of the Company's current status by the new directors.

 

Key Performance Indicators (KPIs)

Regarding the remuneration of senior managers, it includes fixed salary, variable incentives (cash/stock), pensions, and other statutory benefits. The remuneration level is benchmarked against domestic and international peers and adjusted based on duties and responsibilities, performance, and the risks undertaken. Variable remuneration is closely linked to annual operational performance, with performance appraisal indicators covering financial, non-financial, and sustainable development aspects. 

 

Key Performance Indicators (KPIs)
President & CEO
Managers of each Business Units
(Including those responsible for each strategic objective)
Finance
Revenue, profit, growth rate, return on equity
Non-finance
Corporate governance, employee and customer satisfaction, supply chain management
Sustainable development
Commitment of using renewable electricity
10%
10%
The results of the global engagement survey align with the industry norm
Supply chain carbon reduction and greening
Reduce component usage

Business ethics

Running the business with the highest ethical standards and incorporate integrity and moral value with the Company's management strategies, so that integrity takes root within the DNA of the Company. We carry the mission of being a quality enterprise to thrive with the society.

Risk Management

The Company has established the "Risk and Safety Management Policies and Procedures" and set up the Risk and Safety Management Representative Committee, which is responsible for compiling risk and safety issues and reporting them to the Audit Committee and the Board of Directors at least twice a year. Furthermore, since 2024, sustainability information management has been incorporated into the internal control system and included in the annual internal audit plan to ensure that sustainability information and related management procedures are accurately and effectively implemented under internal control measures. 

Risk Management Organization

風險管理組織_EN

Risk Identification and Management

2026_Wiwynn-ESG-網頁-Pic_風險識別與管理_EN
In 2025, taking into account internal and external risk/opportunity factors, including material topics identified through the annual materiality analysis process and issues of concern to stakeholders, risk identification and analysis were conducted through various implementation committees and operational units (functional representatives/teams). Referencing global risk reports, the Risk and Safety Management Representative Committee compiled and summarized 30 risk/opportunity items across eight major dimensions. 

The Risk and Safety Management Representative Committee established risk measurement criteria (Likelihood * Visibility, maximum score of 10 points; Severity maximum score of 10 points) and risk appetite (Severity * Likelihood > 50), defining risk levels as High, Medium, and Low, and formulating corresponding response measures based on the different risk levels. 

Risk Matrix

2026_Wiwynn-ESG-網頁-Pic_風險_EN

In 2025, there were 8 high-risk items, 8 medium-risk items, and 15 low-risk items respectively; the 8 high-risk items were categorized into four major categories: "Paradigm Shifts and Industrial Changes Brought by Technological Innovation," "Trade Protectionism and Geopolitics," "Information Security," and "Materials Management," with corresponding response measures formulated accordingly. 

Risk Response Strategies

Risk Dimension / Category Risk Item Description Impact or Influence Response Measures
Strategic Risk
Emerging Risk
/ Economy, Technology
Paradigm Shifts and Industrial Changes Brought by Technological Innovation
  • Changes brought by transitions in server architecture, including: product demand, industry chains, brand-new product technologies and manufacturing processes, power planning, and the development of energy-saving and carbon-reduction technologies.
  • Response in critical technologies and human resources
  • Adaptation of capital structure
  • Rapid iteration of R&D technologies
  • Insufficient verification, equipment, and power supply
  • Continuously review internal organizational structure
  • Dynamically adjust capital structure
  • R&D technology investments / evaluation of technical alliances
  • Modular infrastructure, global capacity expansion, and power planning
Strategic Risk
/ Economy, Geopolitics
Trade Protectionism and Geopolitics
  • Political and economic wrestling among nations
  • Regional conflicts
  • New trade barriers and protectionist policies
  • Restrictions on origin, operating sites, and import/export countries of materials or goods
  • Operational disruption or business interruption
  • Material shortages
  • Labor shortages
  • Cost increases
  • Track import and export regulations in customer/supplier countries and formulate rolling response plans
  • Formulate Business Continuity Plans (BCP) and conduct regular drills
  • Increase automation and AI adoption to reduce reliance on manpower
  • Formulate rolling response measures to mitigate risks associated with manufacturing relocation
Information Risk
/ Economy, Technology
Information Security
  • Natural disasters requiring more considerations for IT infrastructure operation and maintenance.
  • Phishing emails or careless use of external network resources may lead to data breaches.
  • AI risks and regulations
  • Operational losses caused by business interruption
  • Major leaks of sensitive data affecting Company or stakeholder interests
  • Contingency of backup and recovery mechanisms
  • Establish a 24/7 Information Security Monitoring and Notification Center and introduce new defense technologies
  • Implement system restoration and backup mechanisms with regular drills
  • Establish an Information Security Emergency Response Team
  • Enhance employees' information security awareness and data protection awareness
  • Build data leak prevention mechanisms
  • Incorporate third-party verification mechanisms
  • Formulate AI policies
Operational Risk
/ Economy, Technology
Materials Management
  • With AI technology advancements, the demand for high-performance materials has increased significantly.
  • Anticipatory and risk-based inventory preparation
  • Obsolete and slow-moving inventory
  • Cost pressure affecting financial structure
  • Operational disruption or business interruption
  • Material shortages
  • Establish maximum risk tolerance limits for material inventory
  • Develop supply chain alternative solutions
  • Establish backup suppliers
Emerging Risk
Note: Market/Economy
AI Capital Expenditure Cycle Fluctuations
  • Changes in the pace of AI-related investments and demand structure may affect customer procurement volume and order visibility.
  • May impact capacity utilization, inventory management, and investment returns.
  • Modular design and inventory preparation management.
Emerging Risk
Note: Technology/Regulation
Data Center Power Supply Constraints
  • Factors such as power grid capacity, grid connection progress, and power permits may affect customer data center expansion schedules.
  • May affect customer deployment schedules and increase demands for product energy efficiency and manufacturing flexibility.
  • Continue developing liquid cooling and high-efficiency power technologies, and strengthen facility power planning.
Note: Emerging risks refer to risks that have been identified but not yet fully manifested, which may have an impact on the Company's operations in the long term.

Risk Education × Performance Rewards

At the beginning of each year, "Risk and Opportunity" education and training is conducted for more than 100 global functional representatives, covering risk assessment and identification, regulatory compliance and internal control, and continuous improvement and tracking mechanisms. The aim is to strengthen employees' risk awareness and response capabilities, and incorporate concrete risk reduction outcomes into performance evaluations—such as reducing turnover rate, lowering occupational injury rate, reducing Lost Time Incident Rate (LTIR), and maintaining third-party cybersecurity rating levels—linking them with compensation based on KPI achievements to further enhance overall organizational risk management effectiveness. 

 

 

Regulatory Compliance

Wiwynn Corporation continuously tracks regulatory changes, amends systems in a timely manner, and strengthens regulatory compliance management. Annual compliance audits are conducted to identify and manage risks. 
The Company has established the RBA Management Committee, committing to uphold the RBA Code of Conduct and encouraging suppliers to comply. Multiple ISO management systems have been introduced to enhance risk management, dedicating efforts to environmental protection, waste reduction, carbon emission reduction, energy efficiency enhancement, human rights protection, and workplace safety. 
In 2025, there were no major non-compliance incidents (with a single fine exceeding NT$500,000 defined as a major violation), nor were there any legal proceedings or sanction records involving anti-competitive behavior, antitrust or monopoly practices, insider trading, or money laundering. 
In 2025, the number of employees trained in regulatory and management system-related courses was 9,163 persons, totaling 80,973 hours. 

 

 

Information Security

Information Security Management Organization
A cross-departmental, highest-level Information Security Management Representative Committee was established, with primary missions to grasp the current status, strengthen management, and respond agilely. The Board of Directors serves as the highest supervisory body for cybersecurity issues, while the Audit Committee reviews and supervises the information security management system, internal controls, and implementation status, assisting the Board of Directors in fulfilling its supervisory responsibilities. The Chief Information Security Officer (CISO) reports to the Audit Committee and the Board of Directors annually. 

2026_Wiwynn-ESG-網頁-Pic_資訊安全管理組織_EN

 
Information Security Management Procedures
2026_Wiwynn-ESG-網頁-Pic_資訊安全管理程序_EN
Privacy protection

Tax Governance

Wiwynn Corporation pursues sound tax planning across four key dimensions: "Legal Compliance," "Information Disclosure," "Risk Management," and "Integrity Communication," and has established the "Tax Policy," which was approved by the Board of Directors on February 22, 2022, and took effect accordingly.

2026_Wiwynn-ESG-網頁-Pic_稅務治理_EN