Management Approach
Bora Pharmaceuticals adopts a top-down risk governance and management structure supervised by the Board of Directors and the Sustainability Committee, and coordinated by the Risk Management Team, integrating risk awareness into day-to-day decision-making and all operating units. Addressing strategic risk, operational risk, financial risk, information risk, compliance risk, integrity risk, and other emerging risks, we implement standardized procedures for risk identification, risk analysis, risk evaluation, risk response, and oversight and examination based on the established Risk Appetite. Through regular oversight and a dynamic management mechanism, we proactively respond to changes in the internal and external environment, optimizing the effective allocation of resources to minimize potential impacts, ensuring the accomplishment of objectives and strengthening long-term resilience.
Risk Management Policy and Procedures
To establish a risk management system, ensure steady business operations, and advance toward sustainable corporate development goals, the Company has formulated the “Risk Management Policy and Procedures” applicable to the Company and its subsidiaries. This Policy references international standards such as the COSO ERM Framework, ISO 31000, ICH Q9 (Quality Risk Management), and the “Risk Management Best Practice Principles for TWSE Listed Companies.”
In accordance with Article 20 (Implementation and Amendment) of the Policy, this document was resolved by the Sustainable Development Committee and approved by the Board of Directors on November 13, 2025, serving as the highest guiding principle for the Group’s risk management.
Implementation Status of Risk Management in 2025
The Company initiated the Enterprise Risk Management (ERM) in 2025. The annual operations focused on establishing a governance foundation and shaping a risk-aware culture. The key execution results are as follows:
A. Establishment of Risk Management Organizational Structure
Following the recommendations of the “Risk Management Best Practice Principles for TWSE Listed Companies,” the Company has established a comprehensive risk governance and management framework tailored to its operational scale, business characteristics, risk nature, and operational activities. The risk management organizational structure and responsibilities are clearly defined to ensure the implementation of risk management across all business areas through communication, coordination, and liaison among units.
The structure and responsibilities, summarized from Article 13 (Risk Management Organizational Structure) of the Policy, are as follows:
- Board of Directors: As the highest governance body for risk management, the Board aims to ensure legal compliance and promote the implementation of group-wide risk management. It holds ultimate responsibility for risk management, ensuring a clear understanding of operational risks and the effectiveness of risk management practices.
- Sustainable Development Committee: A functional committee established under the Board, responsible for handling risk control-related issues and supervising the overall execution and coordination of risk management operations.
- Risk Management Team: With the General Manager serving as the convener (or a representative appointed by the General Manager), the team convenes regular annual meetings to plan, execute, and supervise risk management-related affairs.
- Internal Audit Office: Responsible for internal audits and periodically reporting audit results to the Sustainable Development Committee and the Board of Directors.
- Risk Category Responsible Units: The primary units responsible for specific risk categories, charged with managing the various risks within their respective domains.
- Operational Units: Heads of operational units are responsible for managing day-to-day risks.
B. Formulation and Approval of Risk Management Policy and Procedures
Taking into account the specific characteristics of the pharmaceutical industry and integrating the ICH Q9 Quality Risk Management concepts, the Company drafted a Group-level risk management policy referencing international standards (COSO ERM Framework, ISO 31000) and the “Risk Management Best Practice Principles for TWSE Listed Companies” to establish a unified risk language.
Through the involvement of the Board of Directors, the Sustainable Development Committee, and senior management, risk management is aligned with the Company’s strategies and objectives. Major risk items were defined to enhance the comprehensiveness, foresight, and integrity of risk identification results. These were then cascaded down to promote corresponding risk controls and response measures, thereby reasonably ensuring the achievement of the Company’s strategic goals.
The Risk Management Policy was submitted to the Sustainable Development Committee for resolution and implemented following approval by the Board of Directors. It serves as the highest guiding principle for the Group’s risk management and has been published on the Company’s official website.
C. Operational Status for 2025
Following the approval of the Risk Management Policy and Procedures by the Board of Directors on November 13, the Company held the “Enterprise Risk Management Project Kick-off Meeting and Risk Management Training” on December 23. This session educated senior executives and departmental representatives on the risk management policy, outlined the enterprise risk management framework, and explained the implementation plan for 2026. The objective was to enhance colleagues’ capabilities in risk identification and assessment, thereby embedding a culture of risk management throughout the entire workforce.
Risk Identification and Response Measures
| Risk Type | Specific Risk Item | Risk Impact | Response and Control Measure |
|---|---|---|---|
| Information Security risk | Information Security Management | In the context of digital transformation, hacker attacks may lead to leakage of confidential and customers’ data, network paralysis, business discontinuation, financial loss, and reputational damage. | 1. Implement advanced endpoint protection (EDR/MDR) and anomaly detection mechanisms. 2. Conduct social engineering drills and system backup/recovery exercises on a regular basis to ensure business continuity (BCP). 3. Strengthen cybersecurity audits of supply chain partners to ensure overall supply chain security. 4. Implement group-wide cybersecurity training to enhance security awareness. |
| Operational risk | Product Liability and Safety | Regulatory updates may require adjustments to the manufacturing processes. Failure to respond in time may affect product quality, market trust, and may even lead to product recalls. | 1. Establish a real-time monitoring mechanism for regulatory changes. 2. Promote digitalization of the internal quality management system (QMS) to enhance flexibility. 3. Implement an annual product review (APR) and a risk management system to ensure prevention. |
| Operational risk | Process Safety | Abnormal temperature/humidity control or industrial safety incidents occurring in the drug manufacturing process may affect product quality and endanger employees’ safety. | 1. Introduce an intelligent environmental control system for real-time monitoring and automatic adjustment of environmental parameters. 2. Establish emergency response plans and regularly conduct occupational health and safety drills. |
| Strategic risk | Supply chain disruption | Fluctuations in geopolitics and tariff policies may lead to shortages in raw materials or price volatility, thereby affecting profitability. | 1. Establish diversified supplier systems to reduce dependence on a single source. 2. Build a flexible production and distribution network. 3. Develop strategic partnerships with key suppliers to jointly address market fluctuations. |
| Compliance risk | Regulatory compliance and insider trading prevention | The pharmaceutical industry is strictly regulated. As a listed company, failure to comply with regulations or the occurrence of insider trading may result in severe penalties and reputational damage. | 1. Establish a dedicated compliance department and introduce a compliance management system. 2. Periodically provide training to employees and insiders on regulations and “insider trading prevention” requirements. 3. Ensure that all departmental processes are compliant with laws and regulations. |
| Integrity risk | Business ethics and corruption | Any employees or suppliers who are involved in bribery, corruption, or conflicts of interest may severely damage the reputation of the Company and lead to legal sanctions. | 1. Formulate and implement the “Ethical Management Best Practice Principles,” “Procedures for Ethical Management and Guidelines for Conduct,” “Code of Conduct,” and “Anti-Corruption and Anti-Bribery Policy” strictly. 2. Establish a Speak Up whistleblowing hotline under the “Whistleblowing and Grievance System Management Guidelines” to provide internal and external stakeholders with a smooth reporting channel, with strict non-disclosure and non-retaliation protection for whistleblowers. 3. Conduct annual integrity and anti-corruption training for all employees and business partners. |
| Financial risk | Liquidity and exchange rate fluctuation | Global economic volatility and the need for funds for cross-border M&A may lead to foreign exchange losses or pressure on fund allocation. | 1. Formulate comprehensive hedging policies and implement foreign exchange hedging operations. 2. Continuously monitor cash flow and position to ensure sufficient liquidity to support operations. |
| Emerging risk | Extreme climate and energy | Extreme weather may threaten the safety of the facilities; the trend toward net-zero carbon emissions will increase carbon pricing and transition costs. | 1. Identify climate-related financial risks and opportunities in accordance with the TCFD framework. 2. Promote green manufacturing technologies and set short-, medium-, and long-term carbon reduction targets, such as the Canada site’s plan to submit its targets to SBTi for validation. |
| Emerging risk | Stricter domestic and international sustainability regulations and customer requirements | As regulatory authorities worldwide impose increasingly stringent requirements for sustainability information disclosures, international pharmaceutical customers increasingly incorporate ESG performance and carbon reduction commitments in their supplier evaluation metrics. Failure to comply with sustainability standards may result in the loss of international orders, weaken market competitiveness, and increase compliance costs. | 1. Monitor regulatory developments (e.g., IFRS S1/S2) more stringently to ensure legal compliance of sustainability information disclosures. 2. Actively respond to international customers’ sustainability assessment questionnaires and carbon reduction initiatives, and deepen the sustainable supply chain partnership. 3. Continuously improve greenhouse gas inventory and management mechanisms, and respond to stakeholders’ expectations for sustainability performance by taking specific actions. |