Risk Management

》Risk Management Policy

BES has formulated the BES Risk Management Policies and Procedures. Aligning with the Company’s overall operational guidelines, this document systematically defines various types of risks while establishing a management framework featuring early identification, accurate measurement, effective monitoring, and rigorous control to prevent potential losses within acceptable risk limits. Our Company will continuously refine risk management practices in response to shifts in internal and external environments. It is dedicated to protecting the rights and interests of employees, shareholders, customers, and all stakeholders, strengthening corporate value while optimizing resource allocation.

》Risk Management Organizational Structure

The BOD serves as the Company’s highest authority for risk management. Its objectives include complying with applicable laws and regulations, promoting and implementing enterprise-wide risk management, fully understanding operational risks, ensuring the effectiveness of risk management, and bearing ultimate accountability for risk management. The Audit Committee oversees the operation of risk management systems.

Under the BOD sits the Risk Management Team, chaired by the top supervisor of the business administration department, with heads of all departments as core members. This team proactively identifies and controls all risks arising from daily operations. Through quantitative analysis of business risks, the Risk Management Team assists in formulating risk management policies, developing corresponding response measures, and submitting relevant proposals to the BOD. It also presents a risk management report to the Audit Committee and the BOD at least once a year.

Heads of each functional unit are accountable for risk management within their respective businesses. They regularly analyze and monitor relevant risks and ensure the effective implementation of risk control mechanisms and procedures. BES held a risk management meeting on December 6, 2025, identifying 13 critical risk issues and outlining ongoing mitigation measures. Results were submitted to the Audit Committee and the BOD on December 23, 2025, for follow-up implementation.

》Risk Management Process

Our Company compiles historical risk data, follow-up items tracked by directors and supervisors, operational meeting minutes, external environmental trends, and material issues and governance supervision feedback identified through stakeholder engagement to serve as the foundation for risk identification. Risk analysis and assessment are conducted cross-functionally across 3 dimensions: economy (governance), environment, and society. Relevant factors, including company scale, industry, business characteristics, operational activities, and corporate sustainability, are considered. A total of 32 key risk topics is screened out, and corresponding risk response, reporting, and disclosure mechanisms are formulated to implement the Company’s risk management system.

》Risk Matrix

Based on the identified risk issues, BES analyzes and assesses the likelihood (from “almost impossible” to “almost certain”) and severity (from “negligible to catastrophic”) of their impact. The quantitative results were used to develop a risk matrix; high-risk issues (indicated in red in the diagram) are identified. Appropriate response measures are implemented to mitigate potential losses resulting from these risks.

》2025 Risk Matrix

》Risk Management Education and Training

To uphold the core corporate value of integrity, strengthen compliance and information security awareness, and build a gender-friendly workplace, we will launch a series of training courses including “Integrity Management and Corporate Governance,” “Legal Overview and Basic Civil and Criminal Law Concepts,” “Workplace Bullying and Illegal Infringement—Practical Case Analysis and Preventive Measures (Supervisor Version/Staff Version),” “Prevention of Workplace Sexual Harassment and Unlawful Infringement,” and “Basic Information Security Training for General Staff (including Personal Data Protection Act).” Courses will be developed into online learning modules on the internal learning platform.

Risk Management

》Risk Management Policy

BES has formulated the BES Risk Management Policies and Procedures. Aligning with the Company’s overall operational guidelines, this document systematically defines various types of risks while establishing a management framework featuring early identification, accurate measurement, effective monitoring, and rigorous control to prevent potential losses within acceptable risk limits. Our Company will continuously refine risk management practices in response to shifts in internal and external environments. It is dedicated to protecting the rights and interests of employees, shareholders, customers, and all stakeholders, strengthening corporate value while optimizing resource allocation.

》Risk Management Organizational Structure

The BOD serves as the Company’s highest authority for risk management. Its objectives include complying with applicable laws and regulations, promoting and implementing enterprise-wide risk management, fully understanding operational risks, ensuring the effectiveness of risk management, and bearing ultimate accountability for risk management. The Audit Committee oversees the operation of risk management systems.

Under the BOD sits the Risk Management Team, chaired by the top supervisor of the business administration department, with heads of all departments as core members. This team proactively identifies and controls all risks arising from daily operations. Through quantitative analysis of business risks, the Risk Management Team assists in formulating risk management policies, developing corresponding response measures, and submitting relevant proposals to the BOD. It also presents a risk management report to the Audit Committee and the BOD at least once a year.

Heads of each functional unit are accountable for risk management within their respective businesses. They regularly analyze and monitor relevant risks and ensure the effective implementation of risk control mechanisms and procedures. BES held a risk management meeting on December 6, 2025, identifying 13 critical risk issues and outlining ongoing mitigation measures. Results were submitted to the Audit Committee and the BOD on December 23, 2025, for follow-up implementation.

》Risk Management Process

Our Company compiles historical risk data, follow-up items tracked by directors and supervisors, operational meeting minutes, external environmental trends, and material issues and governance supervision feedback identified through stakeholder engagement to serve as the foundation for risk identification. Risk analysis and assessment are conducted cross-functionally across 3 dimensions: economy (governance), environment, and society. Relevant factors, including company scale, industry, business characteristics, operational activities, and corporate sustainability, are considered. A total of 32 key risk topics is screened out, and corresponding risk response, reporting, and disclosure mechanisms are formulated to implement the Company’s risk management system.

》Risk Matrix

Based on the identified risk issues, BES analyzes and assesses the likelihood (from “almost impossible” to “almost certain”) and severity (from “negligible to catastrophic”) of their impact. The quantitative results were used to develop a risk matrix; high-risk issues (indicated in red in the diagram) are identified. Appropriate response measures are implemented to mitigate potential losses resulting from these risks.

》2025 Risk Matrix

》Risk Management Education and Training

To uphold the core corporate value of integrity, strengthen compliance and information security awareness, and build a gender-friendly workplace, we will launch a series of training courses including “Integrity Management and Corporate Governance,” “Legal Overview and Basic Civil and Criminal Law Concepts,” “Workplace Bullying and Illegal Infringement—Practical Case Analysis and Preventive Measures (Supervisor Version/Staff Version),” “Prevention of Workplace Sexual Harassment and Unlawful Infringement,” and “Basic Information Security Training for General Staff (including Personal Data Protection Act).” Courses will be developed into online learning modules on the internal learning platform.