GOVERNANCE Corporate Governance

1.Risk Management Policies and Procedures

In order to strengthen corporate governance and improve the risk management function for the purpose of sustainable operation, the Company revised and approved the Risk Management Policy at the Board of Directors' Meeting in 2022 and established a risk management team to regularly assess the internal and external risk environment, formulate risk management priorities, and set up implementation plans and countermeasures and report regularly to the Audit Committee. The Company reports to the Board at least once a year on the risk environment and the risk control measures adopted and the operation of risk management.
1-1)Risk Identification:Identify the risks associated with various business operations or procedural activities.
1-2)Risk Assessment:Analyze the nature and impact of identified risk factors, and establish appropriate quantitative or qualitative metrics to evaluate risk levels, risk appetite, and tolerance.
1-3)Risk Response:Based on the results of risk analysis and assessment, and considering the cost-effectiveness of the Company’s resource allocation, determine the priority of risk handling, control standards, response measures, restrictions, and exception management strategies. Implement risk prevention and mitigation actions to promptly identify irregularities and respond appropriately.
1-4)Risk Monitoring and Management:Establish risk monitoring mechanisms and performance evaluation indicators to ensure the efficiency and effectiveness of risk management operations, with timely and appropriate adjustments and continuous improvements.
1-5)Risk Information Communication and Reporting:Communicate and consult with stakeholders regarding the Company’s risk management policies. Submit relevant risk information and management reports to the responsible supervisors in accordance with the approved authority levels, and convene related risk management meetings to ensure effective reporting, review, and oversight. When necessary, depending on the nature and impact of the risk, material risk issues shall be reported to the Board of Directors. In addition, the Company discloses risk management-related information publicly in accordance with applicable regulations.

2.Risk Management Category
The Company should review its business and operational characteristics and incorporate the following risk types into its management: i) market risk; ii) operational risk; iii) financial risk; iv) food safety risk; v) legal compliance risk; vi) human resources risk; vii) information security risk; viii) other risks.

3.Risk Management Organizational Structure



4.Operation of risk management
4-1-1) Date reported to the Audit Committee in 2025: July 28, 2025
4-1-2) Date reported to the Board of Directors in 2025: July 28, 2025

4-1-3)The management framework recommended by Task Force on Climate-related Financial Disclosures (TCFD), the risks and opportunities arising from climate change should be integrated with the company's operational risks and corporate governance and measured as follows.
Risks/ Opportunities Item Description Potential financial impact Response/Future Planning Impact period
Risk Physical risk - water scarcity impact Uneven distribution of precipitation due to climate change, which increases the risk of water shortages Financial losses and reduced revenue due to production disruptions Understand the impact of water sources for OEMs and contingency plans
Short-Term(less than 3 years)
Physical risk - stability of raw material supply Abnormal weather conditions affect raw material harvests, which in turn affects the availability and price of raw materials for production Increase in production costs Strengthen the relationship between the company and the raw material vendor to ensure stable raw material supply Stabilisation of price fluctuations through inventory management at low points of price fluctuations and long term contracts
Mid-Term(3 to 5 years)
Transformation risk - agency commodity prices Vendor is affected by regulations related to climate change, resulting in higher operating costs, which in turn reflects higher prices/costs of goods imported Increase in purchase cost
Long-term contracts are available to stabilise price fluctuations for imports. Price volatility of a single product can be reduced through multi-sourcing of goods from multiple countries. Sources of vendors can be diversified to stabilise sourcing and quality
Mid-Term(3 to 5 years)
Opportunities Demand for low carbon products The low carbon emission plant-based products are rising due to the impact of global warming and livestock as a source of greenhouse gases The demand for low-carbon products increased and the market for plant-based products expanded, leading to increased sales revenue Plant-based product markets and low-carbon diets should be promoted on a continual basis. Long-Term(5 years or more)
Changing market preferences Increased sales of beverages and ice products as average temperatures rise due to warming Increased demand for beverages and ice products, leading to increased sales revenue Continue to drive sales of quality beverages and ice products to meet market demand with a diversified range of products Long-Term(5 years or more)
Risk Types Risk Description Risk management procedures 
 Market and Operational risk 1.Changes in consumption patterns 1.Sales channel adjustment: In addition to the existing modern channels (convenience stores, hypermarkets, and supermarkets) and distribution network, we will further expand our e-commerce channels (online shopping, group buying, and collaboration with e-commerce platforms).
2.Product structure adjustment 2.Product portfolio adjustment: In response to the era of home economy, we will increase the offerings of home DIY food, microwave-ready meals, epidemic prevention products, and storage solutions.
3.The impact of international shipping 3.Inventory level adjustment: In response to changes in international shipping costs, we will make reasonable adjustments to the inventory level of products on long-distance shipping routes.
4.Political risk 4.To cope with geopolitical risks, we will make timely adjustments to the proportion of imports and exports from different countries to avoid excessive reliance on a single country.
Financial risk 1.Credit risk 1.We will closely monitor the collection of accounts receivable and carefully assess the adequacy of collateral provided by distributors.
2.Currency risk 2.When purchasing and selling goods internationally, we will consider the impact of exchange rates as a key negotiating point and use appropriate financial tools as needed to ensure our profitability objectives are met.
3.Liquidity risk 3.We will review the adequacy of cash flow and avoid liquidity risk to ensure smooth fund flow.
Food safety risk 1.Supplier Management 1.In 2024, there were 10 domestic contract manufacturers, all of which (100%) were certified with ISO 22000 or FSSC 22000. Products manufactured by these contractors accounted for 29.91% of the annual standalone financial statement’s net operating revenue.
2.Product Labeling Management 2.We have established a standard procedure for the review and approval of packaging food labels to ensure proper product labeling management.
3.Product traceability 3.We have independently established a traceability system for our own-brand products, allowing customers to inquire about the upstream suppliers and distributors through product batch numbers for traceability purposes.
Legal and compliance risk 1.Patents and Trade Secrets 1.As of June 30, 2025, our company has acquired a total of 2 patents, and no patent infringement cases have been reported. We have formulated the "Intellectual Property Management Regulations" to govern our intellectual property rights.
2.Copyright 2.As of June 30, 2025, no copyright infringement cases have been reported. We have revised the "Company Standard Intellectual Property Declaration," "Intellectual Property Clauses," and "Signage and Advertisement Content Review Standard Procedure" to address intellectual property rights matters.
3.Trademark 3.As of July 31, 2025, our company has obtained a total of 219 trademarks, and there have been no reported cases of our company infringing upon the trademarks of others in relation to our trademark usage.Obtained registration of Kaisi trademark for tea beverages in Mainland China. 42 employees have completed intellectual property education training, with a total of 49.5 hours of training.
Human resources risk 1.Employee benefits 1.Holiday bonus, birthday gift, maternity/paternity gift, group insurance, employee shopping discounts, and occasional educational training are the benefits we provide to our employees.
2.Workplace Diversity and Equality 2.We strive for workplace diversity and equality, ensuring that both men and women receive equal pay for equal work and have equal opportunities for career advancement. We maintain equal remuneration conditions and equitable promotion opportunities, resulting in over 40% of female executives, promoting sustainable and inclusive economic growth. As of June 30, 2025, female employees make up an average of 66% of the workforce, and female executives account for an average of 48%.
3.Business performance is reflected in employee compensation 3.Our company conducts salary adjustments based on market salary levels, economic trends, and individual performance. For the fiscal year 2024, including both managerial and non-managerial positions, the average salary adjustment rate is 3.2%. For the fiscal year 2025, including both managerial and non-managerial positions, the average salary adjustment rate is 3.0%.
Information security risk 1.Information Security Protection Control 1. In 2024, three security patches were applied, and real-time disconnection alerts were added to enhance network incident response capabilities.
2. A filtering mechanism was configured on the email server to prevent the spread of spam messages. A migration to a cloud-based solution is planned for 2025.
3. System network operations utilize MPLS VPN connections to prevent unauthorized external access. In addition, HiNet enterprise security services are employed to block external attacks.
4. Antivirus software was renewed in June 2022 under a three-year contract. The software is in its third year of use as of 2025. Security patches for operating systems on servers are reviewed monthly and updated in real time.
5. Logging into company-issued personal computers and accessing internal systems requires account ID and password authentication. Passwords must be changed every three months; accounts will be locked if the password is not updated within the required period, and access will be suspended until a formal request is submitted. Passwords must be at least 8 characters in length and include a combination of numbers and letters.
6. In July 2024, a review of ERP system access permissions was completed, confirming the accuracy of the user list. The review for 2025 is scheduled to be conducted in July.
7. In 2024, vulnerability scans were completed on six servers and penetration tests were conducted on three servers. This included operating system upgrades and remediation of application vulnerabilities based on OWASP guidelines. The 2025 assessments are scheduled for September.
2.Enhancement of personnel information security awareness 1. All new employees are required to sign the “Computer Usage Policy Agreement” to ensure they understand the company’s regulations regarding computer use, network management, software installation, and related policies.
2. New employees are required to complete the “New Employee Information Access Application Form.” After confirmation by relevant supervisors and the IT manager, personal computer access permissions are granted. Additional system access may be provided based on job requirements, upon submission of the “Information Access Addition/Modification Application Form,” and approval by the department manager.
3. In 2024, regular cybersecurity awareness campaigns were conducted covering topics such as ransomware prevention, vulnerability mitigation, email security, and major amendments to the Personal Data Protection Act. Awareness messages are set to display upon startup of personal computers. As of 2025, six sessions have been completed, with monthly campaigns ongoing.
4. In 2024, four social engineering drills were conducted. Excluding new employees, staff across departments demonstrated increased cybersecurity awareness—upon receiving suspicious emails, they not only refrained from clicking on them but also promptly reported such incidents to the Information Security Department, thereby enhancing collective defense against cyber threats. As of 2025, one social engineering drill has been completed.
5. In 2024, the “Information and Communication Security Incident Response and Internal Reporting Plan” was established and released. It defines the standards and reporting mechanisms for security incidents, outlines the organization of the response committee, and specifies detailed roles and responsibilities. A drill is scheduled for 2025, with implementation planned for December.
6. In 2024, an online course on cybersecurity vulnerability prevention was arranged for new employees, followed by an online assessment. A total of 33 new employees completed the course and passed the test. As of 2025, 15 new employees have completed the training.
 
4-2-1) Date reported to the Audit Committee in 2026: July 28, 2026
4-2-2) Date reported to the Board of Directors in 2026: July 28, 2026

4-2-3)The management framework recommended by Task Force on Climate-related Financial Disclosures (TCFD), the risks and opportunities arising from climate change should be integrated with the company's operational risks and corporate governance and measured as follows.
Risks/ Opportunities Item Description Potential financial impact Response/Future Planning Impact period
Risk Physical risk - water scarcity impact Uneven distribution of precipitation due to climate change, which increases the risk of water shortages Financial losses and reduced revenue due to production disruptions Understand the impact of water sources for OEMs and contingency plans
Short-Term(less than 3 years)
Physical risk - stability of raw material supply Abnormal weather conditions affect raw material harvests, which in turn affects the availability and price of raw materials for production Increase in production costs Strengthen the relationship between the company and the raw material vendor to ensure stable raw material supply Stabilisation of price fluctuations through inventory management at low points of price fluctuations and long term contracts
Mid-Term(3 to 5 years)
Transformation risk - agency commodity prices Vendor is affected by regulations related to climate change, resulting in higher operating costs, which in turn reflects higher prices/costs of goods imported Increase in purchase cost
Long-term contracts are available to stabilise price fluctuations for imports. Price volatility of a single product can be reduced through multi-sourcing of goods from multiple countries. Sources of vendors can be diversified to stabilise sourcing and quality
Mid-Term(3 to 5 years)
Opportunities Demand for low carbon products The low carbon emission plant-based products are rising due to the impact of global warming and livestock as a source of greenhouse gases The demand for low-carbon products increased and the market for plant-based products expanded, leading to increased sales revenue Plant-based product markets and low-carbon diets should be promoted on a continual basis. Long-Term(5 years or more)
Changing market preferences Increased sales of beverages and ice products as average temperatures rise due to warming Increased demand for beverages and ice products, leading to increased sales revenue Continue to drive sales of quality beverages and ice products to meet market demand with a diversified range of products Long-Term(5 years or more)
Risk Types Risk Description Risk management procedures 
 Market and Operational risk 1.Changes in consumption patterns 1.Sales channel adjustment: In addition to the existing modern channels (convenience stores, hypermarkets, and supermarkets) and distribution network, we will further expand our e-commerce channels (online shopping, group buying, and collaboration with e-commerce platforms).
2.Product structure adjustment 2.Product portfolio adjustment: In response to the era of home economy, we will increase the offerings of home DIY food, microwave-ready meals, epidemic prevention products, and storage solutions.
3.The impact of international shipping 3.Inventory level adjustment: In response to changes in international shipping costs, we will make reasonable adjustments to the inventory level of products on long-distance shipping routes.
4.Political risk 4.To cope with geopolitical risks, we will make timely adjustments to the proportion of imports and exports from different countries to avoid excessive reliance on a single country.
Financial risk 1.Credit risk 1.We will closely monitor the collection of accounts receivable and carefully assess the adequacy of collateral provided by distributors.
2.Currency risk 2.When purchasing and selling goods internationally, we will consider the impact of exchange rates as a key negotiating point and use appropriate financial tools as needed to ensure our profitability objectives are met.
3.Liquidity risk 3.We will review the adequacy of cash flow and avoid liquidity risk to ensure smooth fund flow.
Food safety risk 1.Supplier Management 1.In 2025, the Company cooperated with 11 domestic contract manufacturers, of which 10 were included in the scope of the 2025 contract manufacturer evaluation (Note 2). Of these, 7 were evaluated directly by Tait Marketing & Distribution Co., Ltd., and 3 were evaluated by Uni-President. All 11 contract manufacturers obtained ISO 22000 or FSSC 22000 certification this year. Sales revenue from products manufactured by the above contract manufacturers accounted for 28.41% of the net operating revenue in the Company's parent-only financial statements for the year.
2.Product Labeling Management 2.We have established a standard procedure for the review and approval of packaging food labels to ensure proper product labeling management.
3.Product traceability 3.We have independently established a traceability system for our own-brand products, allowing customers to inquire about the upstream suppliers and distributors through product batch numbers for traceability purposes.
Legal and compliance risk 1.Patents and Trade Secrets 1.As of June 30, 2026, the Company had obtained a total of two patents, one of which had expired.
2.As of June 30, 2026, there had been no patent infringement cases.
3.The Company has established Intellectual Property Management Procedures to govern the management of intellectual property rights.
2.Copyright 1.As of June 30, 2026, no copyright infringement cases have been reported. 
2.We have revised the "Company Standard Intellectual Property Declaration," "Intellectual Property Clauses," and "Signage and Advertisement Content Review Standard Procedure" to address intellectual property rights matters.
3.Trademark 1.As of June 30, 2026, the Company had obtained a total of 216 trademark registrations, including 60 overseas trademark registrations.
2.As of June 30, 2026, there had been no cases in which the Company’s use of trademarks infringed upon the trademark rights of others.
3.The Company has obtained registration of the Kaishi trademark in Mainland China for tea beverages.
4.As of June 30, 2026, a total of 22 person-times had completed intellectual property education and training, representing 11 person-hours of training in aggregate.
Human resources risk 1.Employee benefits 1.Holiday bonus, birthday gift, maternity/paternity gift, group insurance, employee shopping discounts, and occasional educational training are the benefits we provide to our employees.
2.Workplace Diversity and Equality 2.We strive for workplace diversity and equality, ensuring that both men and women receive equal pay for equal work and have equal opportunities for career advancement. We maintain equal remuneration conditions and equitable promotion opportunities, resulting in over 40% of female executives, promoting sustainable and inclusive economic growth. As of June 30, 2025, female employees make up an average of 67% of the workforce, and female executives account for an average of 54%.
3.Business performance is reflected in employee compensation 3.Our company conducts salary adjustments based on market salary levels, economic trends, and individual performance. For the fiscal year 2025, including both managerial and non-managerial positions, the average salary adjustment rate is 3.0%. For the fiscal year 2026, including both managerial and non-managerial positions, the average salary adjustment rate is 3.5%.
Information security risk 1.Information Security Protection Control 1.In 2025, six security patch updates were performed for the firewalls and servers, and real-time notifications of network disconnection events were implemented to enhance network incident response capabilities. In 2026, the firewall firmware was further updated.
2.In 2026, the email server was migrated to the cloud-based Microsoft 365 (M365) platform. Multi-factor authentication and email filtering mechanisms were enabled to prevent the dissemination of spam emails. All users’ email client software was also updated.
3.System and network operations are connected through an MPLS VPN to prevent malicious external access. The Company also uses HiNet enterprise cybersecurity services to block external attacks.
4.The Company provides employees with personal computers and controls access to its internal systems. Users are required to enter an account name and password, and passwords must be changed every three months. Accounts will be locked if passwords are not changed by the specified deadline. Passwords must contain at least eight characters and include a combination of letters and numbers.
5.In 2025, access rights to the ERP system were reviewed once in each half of the year to verify the accuracy of the authorized user list.
6.In 2025, vulnerability scans were completed for six servers, and penetration tests were conducted on three servers. Operating systems were upgraded, and application vulnerabilities identified with reference to the OWASP guidelines were remediated.
2.Enhancement of personnel information security awareness 1.All new employees are required to sign the “Agreement on Compliance with Computer Use Rules” to ensure that they understand the Company’s requirements regarding computer use, network management, software installation, and other related matters.
2.New employees are required to submit an access authorization application form. Access rights to systems used on their personal computers are granted only after approval by the relevant supervisors at each level and the head of the information technology function.
3.In 2025, the Company conducted monthly cybersecurity awareness campaigns, completing a total of 12 campaigns covering the prevention of ransomware-related damage, protection against cybersecurity vulnerabilities, email security, and significant amendments to the Personal Data Protection Act.
4.Cybersecurity awareness messages are displayed when employees start their computers. Six campaigns had been completed in 2026, and the awareness campaigns continue to be conducted monthly.
5.In 2025, the Company conducted three social engineering exercises. Employees across all departments enhanced their cybersecurity awareness and, upon receiving suspicious emails, refrained from opening attachments and promptly reported such emails to the Information Security Department, thereby jointly strengthening information and communications security. Two social engineering exercises had been completed in 2026.
6.In 2025, the Company issued the “Information and Communications Security Incident Response and Internal Reporting Plan,” which establishes cybersecurity incident classification criteria and reporting mechanisms, as well as the organizational structure and division of responsibilities of the incident response committee. The Company also conducted an exercise simulating a change to the login password of the human resources system. Following the exercise, multi-factor authentication was introduced as an enhanced protective measure.
7.In 2025, the Company arranged an online course on cybersecurity vulnerability prevention for new employees, followed by an online assessment. All 33 new employees completed the course and passed the assessment. In 2026, nine new employees had completed the course and passed the assessment.