Empowerment and Accountability
MERRY proactively manages risks that may arise during its operations. The Risk Management Team establishes relevant risk management procedures by referencing the ISO 31000:2018 Risk Management Framework and ISO 22301: 2019 Business Continuity Management System. The team regularly assesses and monitors its risk appetite, the current status of accepted risks, determines risk response strategies, and ensures compliance with risk management procedures. The operational results are reported to the Board of Directors annually (most recently, the annual performance and next year's plan were reported to the Board of Directors on 2025/12/24).
The current scope of risk management encompasses 17 risk categories:
"Operational," "Quality," "Energy," "Environmental," "Technological," "Supply Chain," "Financial," "Taxation," "Information Security," "Human Resources," "Facilities," "Occupational Safety and Health," "Strategic," "Legal," "Integrity Management," "Business Interruption," and "Human Rights." Utilizing the risk assessment tools specified in the Risk Management Procedures document, risk measurement,based on likelihood and consequence, is categorized into 4 levels. Discussions are conducted with each accountable unit to determine if additional control measures are necessary for identified risk items, subsequently generating a risk matrix analysis.Furthermore, this risk operation also integrates implemented management systems such as I SO 9001, ISO 27001, ISO 45001, ISO 50001, TIPS, and GB/T 29490. The effectiveness of risk management control measures is confirmed through annual internal and external audits of each system. Additionally, to ensure the company's steady growth and sustainable operation objectives, the Risk Management Team has successively launched risk management education and training courses. It has also promoted the developed climate-related financial disclosure (TCFD) risk items to the group's subsidiaries. In the future, the company will continue to follow the Business Continuity Management (BCM) ISO 22301 standard, regularly exercising the Business Continuity Plan (BCP) established based on the results of the business impact analysis and the organization's current situation. Furthermore, to proactively address the risks arising from domestic and international economic trends and to enhance our comprehensive risk management system, we will reference the top ten risk trends disclosed in the World Economic Forumʼs (WEF) “Global Risk Report.ˮ In addition to existing operational risks, we will strengthen assessments in the following two key areas: in response to digital transformation and the widespread adoption of AI technology, we will designate information security protection and data privacy protection as core monitoring indicators; We will enhance monitoring of “cybersecurity risksˮ and incorporate“geopolitical risksˮ into the “MERRY Strategic Riskˮ framework, conducting stress tests and developing response plans for supply chain stability and market access restrictions. To improve risk early warning capabilities, we have introduced an“emerging risksˮ monitoring mechanism into our risk identification process. By scanning diverse dimensions such as the environment, society, and governance, we identify issues characterized by “high uncertaintyˮ but “potentially massive impact,ˮensuring that management can allocate resources in advance to transform risks into opportunities for operational transformation.
Estimated Residual Risk Distribution

| Unit Name | Risk Category | Identified Risk Items | Control Mechanisms |
|---|---|---|---|
| Electro-Acoustic Product Business Group |
Operational Risk | High Customer Concentration |
•Develop new customers and regularly review their revenue share |
| Power Application Systems Business Division |
Operational Risk | - | - |
| Technology Division |
Environmental Risk Energy Risk
|
- |
- |
| Supply Chain Division | Supply Chain Risk | - | - |
| Finance Division |
Financial Risk Tax Risk |
- | - |
| Information Division | Information Security Risk | Exploitation of software vulnerabilities, exploitation of device vulnerabilities / zero-day attacks, use of pirated software, malware / hacker intrusions |
•Update firewall firmware |
| Human Resources Division |
Human Resources Risk |
- |
- |
| Occupational Health and Safety Division |
Occupational Health and Safety Risk |
- | - |
| Corporate Management Office |
Strategic Risk Legal Risk Operational Disruption Risk |
Geopolitical factors and rapid changes in product demand lead to fluctuations in customer orders High liquidated damages for breach of confidentiality in specific contracts - |
Real-time Capacity and Inventory Management Reasonable Risk Transfer Third parties who may become aware of relevant information are required to maintain confidentiality - |
