Risk Management and Audit System

Risk Management and Audit System

To ensure an appropriate balance between risk and return, and capital adequacy, and to achieve an appropriate balance between risk and return, the Company the Company has established the "Risk Management Policy and Guidelines" in accordance with the "Regulations Governing the Implementation of Internal Control and Audit Systems for Financial Holding Companies and Banking Industries", which serve as the foundation for risk management. TCFHC and its major subsidiaries are equipped with "Risk Management Policy and Guidelines" that are responsible for formulating risk management systems, policies, and monitoring indicators, and for overseeing the implementation of risk management activities.

To assist the Board of Directors and management in reviewing and evaluating the effectiveness of the internal control system and providing timely recommendations for improvement, the Company has established the "Audit Guidelines" in accordance with the "Regulations Governing the Implementation of Internal Control and Audit Systems for Financial Holding Companies and Banking Industries". These guidelines serve as the basis for establishing the internal audit system and for reviewing and enhancing the internal control system.


Risk Management Structure

The Company's Board of Directors serves as the highest risk management decision-making body and the ultimate accountable authority throughout the Group. The "Risk Management Committee", consisting of the Chairperson, the CEO, executive vice presidents, chief compliance officer, unit supervisors, and presidents of respective subsidiaries, acts as the highest management unit for risk management. It coordinates and oversees the risk management units (the second line of defense) and business units (the first line of defense) of the Company and its subsidiaries. The internal audit unit (the third line of defense) performs audits independently, and periodically reviews the Company's risk management procedures to ensure the effective operation of the risk management framework.

The chair concurrently serves as the chair of the "Risk Management Committee", and the E.V.P. & Chief Audit Executive is the highest management level for risk monitoring and auditing. Both report directly to the Board of Directors. The "Risk Management Committee" meets on a quarterly basis. TCFHC and its subsidiaries present reports for the current period on the overview of risk management, changes in capital adequacy, the handling of significant incidents, exposure analysis of key monitored counterparties and industries, and the implementation status of action items resolved at previous meetings.

Risk Appetite

Risk appetite is the aggregate level of risk that the Company is willing to accept within its overall risk-bearing capacity and is mainly based on the operational strategy and financial goals, and takes into consideration factors such as growth, risk, and returns. TCFHC has established a risk appetite management mechanism. Every year, the supervisory vice president of Risk Management Department and the business units responsible for each indicator meet to discuss and review the risk appetite framework. The Risk Management Department is responsible for summarizing and submitting results to the Risk Management Committee and the Board of Directors for review. After approval, those will be reported to the Risk Management Committee and the Board of Directors on a quarterly basis. In 2025, a total of 25 indicators were established, and the responsible units for each indicator reported their implementation status on a quarterly basis. In case of any indicator falling outside the approved threshold, related countermeasures shall be explained and implemented in order to strengthen the risk culture and enhance the risk management mechanism.


Risk Identification and Mitigation Strategies

Primary Risk Management

The Group conducts annual assessments of internal and external operational risks that may arise from its financial activities. Risk management is implemented proactively through authorization mechanisms, limit controls, and monitoring indicators. Risk-bearing capacity and corresponding response measures are regularly reported to the Board of Directors and senior management. Each subsidiary is also required to establish risk indicators and control procedures based on the nature of its products, business scale, and risk characteristics. To oversee the execution of risk management, the Company regularly monitors the Group's credit risk exposures and compliance with relevant limit controls, including but not limited to industry concentration limits, watchlist industries, high-risk industries in Mainland China, country risk, exposure limits for Mainland China, and large corporate group limits. In addition, statutory reports are submitted to the Financial Supervisory Commission within the prescribed deadlines for regular monitoring of exposure fluctuations and risk management performance.

After assessing internal and external risks and considering the potential impacts on the Company's business, the 2 major risks in 2025 are credit risk and operating risk.

Emerging Risk Management


Shaping Risk Culture

Risk Management Training

To strengthen the Group’s risk management framework, foster a climate governance culture, and enhance the risk awareness of directors, and senior executives regarding the latest international developments and evolving concepts, the Group arranges annual risk management training programs. In 2025, the Group conducted an educational training session for directors, and senior executives titled "Trends and Practices in Green and Transition Finance". A total of 43 people participated in the course. The training covered topics including the transition from TCFD to IFRS S2, transition plans and transition finance, as well as the shift in focus from climate-related issues to nature-related issues, while also discussing areas for future enhancement. In addition, to strengthen employees' risk awareness, establish an enterprise-wide risk management culture, and effectively implement the Group's risk management policies, TCFHC encourages employees to participate in various internal and external risk management training programs. In addition to in-person courses, the Group also leverages digital technology to conduct online training sessions and regularly disseminates the latest risk management regulations, trends, and practices for use in internal training across different units.

To strengthen crisis management mechanism, resolve and alleviate emergency events quickly or resume operations in time and minimize losses, TCFHC has the "Regulations Governing Emergency and Crisis Management" to activate the group-wide emergency reporting and communication system in the event of a manmade or natural disaster, faulty internal control, employee fraud, security maintenance, significant financial loss in business, or negative media coverage that can affect the Company's reputation and normal operation. The Crisis Management Task Force is also in charge of handling emergencies, giving instructions and speaking on behalf of the Company to outsiders according to the guidelines for spokespersons as needed.

Refining Risk Culture

The Group encourages employees to provide suggestions for optimizing operational processes, and rewards are granted for proposals that are adopted. In 2025, total rewards of NT$ 15,000 were distributed. During 2025, employees submitted 200 proposals, including optimization suggestions for branch-end transaction systems, credit investigation and loan approval systems, the foreign exchange IFX system, private banking management systems, online lending services, and mobile banking platforms. These initiatives helped strengthen operational and management efficiency while further enhancing risk management.

The Group has formulated the "Operational Risk and Control Assessment Management Directions", and employees who are familiar with the business process are responsible for the operation process analysis and risk identification. The operation risk self-assessment process completed in 2025 includes 118 from head office management units, 58 from business units and and 20 from overseas branch processes. Through the selfassessments results of risk control, the operational risks that should be paid attention to are summarized, and for projects with high risks, action plans are developed to respond in advance to reduce possible future operational losses, improve employees awareness and attention to risks, and integrate risk management awareness into in daily business processes.

TCB has formulated "Measures for Handling Financial Product Evaluations". Before developing financial products, it identifies and evaluates potential risks in advance and formulates relevant response plans to strengthen risk control.


Internal Audits

Organization and Functioning of Internal Audits

To establish an effective internal audit system and enforce risk management, the Company has established its "Audit Guidelines" and also follows the "Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries" promulgated by the Financial Supervisory Commission, creating a general audit system for overseeing audit operations. The Auditing Department, established under the Board of Directors, performs internal audits on the Company and each subsidiary every 6 months. It assists the Board of Directors and management in inspecting and evaluating whether the internal control system operates effectively and provides timely improvement advice, so as to both ensure that the internal control system can operate effectively and serve as a reference for further review and revision.

Furthermore, the FSC conducts general audits once every 2 years, as well as irregular special audits of the Company (1 general audit in 2025). The Company is also committed to making improvements based on audit feedback and creating an appropriate risk management mechanism. Regarding this, the internal audit unit continues to follow up on and review the improvement status of audit opinions or deficiencies identified by the FSC, accountants, the internal audit unit, and internal units through their self-audits, as well as on enhancement items listed in internal control statements. Improvements are submitted to the Board of Directors and the Audit Committee and are used as an important item for penalties, rewards, and performance evaluations of related units. This further promotes the effectiveness of the Group's overall operations and risk management.

In 2025, the Auditing Department under the Board of Directors completed all annual audit tasks and monitored the improvement status of audit findings for the Company's various departments and subsidiaries.

open a new link