Operation and Governance
Enterprise Risk Management
The USI Audit Committee comprises five directors, with more than half being independent directors. To meet internal control and audit requirements and ensure sustainable business achievements, USI follows internal audit mechanism to organize a Risk Management Committee and applies ISO 31000 Risk Management-Principles and Guidelines to execute annual risk management activities according to business environment, industrial trend, and company operations. The COO acts as the Chair, committee members are representatives chosen from Vice Presidents of business units, functional units, and manufacturing sites. USI determines risk appetite based on its internal control and audit framework, and Enterprise Risk Management (ERM) is established as an important part of the internal control system and incorporated into the corporate governance structure.
First line of defense (operational risk ownership)-manufacturing sites, functional units, and business units: The operating units of Risk Management Committee are responsible for the first line risks management. According to evaluation of risk level, the committee takes responsibility to adopt countermeasures and ensure the risk management policy can be executed by each operation unit.Second line of defense (risk management and compliance oversight)-Risk Management Committee: The committee secretariat will approve risk response strategy, action plans, and risk appetite, track the targets of risk management activities from each operating unit. And the achievements will be presented to Vice President of the Risk Management unit.
Third line of defense (independent audit unit)-Audit Center: The Audit Center establishes a risk-based internal audit system and performs internal audit activities in accordance with the annual audit plan approved by the board of directors.
Risk Governance Process:
USI implements an ERM framework across its global manufacturing sites, business units, and functional units to identify, assess, and mitigate enterprise risks. Risk mitigation plans are regularly monitored to ensure effective risk control and to integrate risk management into strategic decision-making, supporting sustainable operations and business objectives.
The Risk Management Committee reviews the Company's risk exposure twice annually. A top-down assessment is conducted mid-year to identify key risks arising from macroeconomic conditions and global operational developments. A bottom-up assessment is conducted at year-end to review operational risks identified by business units, manufacturing sites, and functional units.
Annual Risk Assessment & Countermeasures
In the risk assessment phase, USI requires each business unit to identify the risk level by occurrence frequency and possibility according to different business relevance and facility's location, and evaluate the enterprise significant risk impact levels from the dimensions of finance, reputation, and continuing operations. Comprehensive both of risk possibility and significance of impact, we scale our existing controls and countermeasures and decide an action plan needs to be developed. Please refer to 2025 USI Risk Assessment & Countermeasures.
USI risk assessment mechanism of internal control system is as below:
- Define clear objectives to enable risk identification.
- Assess potential risks for achieving company objectives across the entity and its potential for fraud, then analyze these risks as the basis for risk management.
- Identify and assess changes that could significantly impact the internal control system.
Independent third-party audit:
To demonstrate USI’s commitment to the implementation and processes of enterprise risk management, we engaged an independent third party to conduct a verification based on the ISO 31000 Risk Management Principles and Guidelines. As a result, USI successfully obtained a Statement of Conformity to ISO 31000:2018, enhancing the transparency and credibility of our risk management framework.
Business Continuity Management Policy
As global risks continue to rise, if a factory is damaged or ceases operation due to hazardous risks, it may reduce production capacity and lead to the loss of important customers, and have a significant adverse impact on the company's operations and financial performance. By implementing a Business Continuity Management System (BCMS), an organization can increase its resilience and ability to recover from disruptive events, and develop plans and procedures to ensure the continuity of its operations in the event of a disruption.
- USI's operation management shall have risk awareness, and integrate risk management into the business strategy and organizational culture to meet the commitment of applicable requirements.
- Establish a management and risk response mechanism for identification, assessment, and control of major risks, and perform business impact analysis in accordance with operational objectives to establish business continuity objectives, strategies, and plans, and continue to improve. Embed crisis management into employees' awareness and skills and conduct regular drills to ensure effectiveness.
- Openly and actively communicate risk information with stakeholders.
|
BCMS Milestones |
2022 KPIs | 2026 Objectives |
|---|---|---|
| Nantou Facility Passed ISO 22301 Verification | Introduce BCMS to worldwide critical sites |