Risk Management

Risk Management

Risk Management Mechanism

Hsin Tung Yang places great importance on identifying and managing the potential risks associated with its business operations. The Company conducts comprehensive risk assessments covering the organization as a whole, its manufacturing facilities, and all operating channels to identify and evaluate potential risks. Based on the nature of each risk, appropriate management mechanisms and corresponding mitigation measures are established to effectively control risks and strengthen preventive capabilities.

 

Risk Identification Results and Response Actions 
Risk CategoryRisk DescriptionResponse Actions
Climate Change and Natural Disaster Risk
  • Typhoons delay shipping schedules, extending product delivery times and affecting shelf-availability timing and product shelf life.
  • Earthquakes cause power, water, and gas outages, fires, structural damage, and other losses.
  • Extreme weather disrupts supply — for example, sun-dried products may face delays or shortages — increasing production uncertainty.
  • Employee attendance is affected, causing labor shortages. 
  • Incorporate climate change factors into strategic and operational risk assessment, with regular discussion and review of response measures.
  • Establish an "Emergency Response Guidelines" work instruction and provide regular training.
  • Establish an "Emergency Response Team" to activate corresponding measures when a disaster occurs.
  • Monitor climate reporting and, in coordination with channels, notify transport units in advance to bring forward or postpone deliveries.
Food Safety Risk
  • Product deterioration during storage and transport by external distributors or channel logistics damages brand reputation.
  • Because low-temperature products have short shelf lives, they readily exceed acceptance limits, resulting in product loss.
  • Establish procedural documents such as a food safety monitoring plan and implement them rigorously within operating processes to control related risks systematically.
  • Supplier qualification, evaluation, audits, and inspection mechanisms.
  • Establish a product traceability linkage mechanism to ensure product traceability, enabling prompt response should a food safety incident occur.
Regulatory and Compliance Risk
  • Channels' requirements for labeling and allergen warnings must exceed regulatory standards; labeling non-compliance could result in delisting and fines.
  • Establish a Channel Label Review Checklist, with dual verification by Quality Assurance and Sales & Marketing prior to product listing.
Market Competition Risk
  • Pressure from sustainability transformation: channels require plastic-reduced packaging or carbon-labeled products, and failure to meet these requirements may result in loss of shelf space. 
  • Develop channel-exclusive eco-friendly minimalist packaging or products.
  • Actively participate in green procurement programs run by channels to strengthen channel partnership cohesion.
Supply Chain and Operational Risk 
  • naccurate forecasting of holiday demand leads to shortages of best-selling items or to surplus products expiring and being written off.
  • Because goods are transported mainly by third-party carriers, delivery conditions are affected by weather.
  • Sales staff track channel sales data in real time and establish an internal stock-transfer mechanism to allocate inventory effectively across channels.
  • Defining accountability and quality acceptance criteria in supplier agreements. 
Information Security Risk
  • Information systems suffer downtime from unexpected disasters, or hackers intrude and steal data.
  • Internal employee lapses in the file-management process for personal-data-related files lead to leaks. 
  • Establish an Information Security Management Committee to conduct regular risk assessment and identification. 

Crisis Management Mechanism

When a potential risk escalates into an actual crisis, the relevant departments immediately activate the Company's crisis management mechanism to ensure a timely and effective response. In the event of a major emergency, the President convenes a dedicated task force comprising the responsible departments to evaluate the situation and determine appropriate emergency response measures. The incident and the corresponding response are subsequently reported to the Chairman and the Board of Directors. 

Information Security

Hsin Tung Yang has established a comprehensive information security management policy, covering the establishment of an organization-wide assessment mechanism, an information asset management mechanism, and the formulation and live drilling of an information security business continuity plan. It has also set up an Information Security Management Committee, responsible for determining the acceptable risk threshold and reviewing risk assessment results, risk improvement plans, and control measures. According to task requirements, four working groups have been established under the Committee to handle information security processing, document control, internal audit, asset inventory, and risk assessment. 

Information Security Management Organization Structure

Information Security Management Measures

In accordance with the ISO/IEC 27001 Information Security Management System (ISMS), Hsin Tung Yang has established management procedures and implemented action plans to strengthen information security governance. The Company's annual information security initiatives include website vulnerability scanning, server vulnerability scanning, social engineering simulation exercises, and information security verification. Resources dedicated to information security management include: 

  • Comprehensive deployment of endpoint protection software to safeguard the information security of all endpoint devices.
  • Engagement of professional consultants to perform vulnerability scanning of hosts and websites.
  • Collaboration with external information security consultants to monitor the security and protection of information systems, with regular meetings to discuss information security issues. 

Intellectual Property Management 

Hsin Tung Yang regards its brands and trademarks as important core assets. Its intellectual property management measures include strengthening trademark registration and brand protection, establishing a trade-secret management system, promoting employee confidentiality agreements and training, introducing document classification and access control mechanisms, and complying with relevant regulations to avoid infringement risk. At the same time, the Company incorporates intellectual property management into corporate governance and integrates it with operating strategy, so as to enhance corporate competitiveness and brand value.

Protecting Customer Privacy

Hsin Tung Yang obtains member registration information through its online shopping website and in-store membership registration. It safeguards the security and privacy of customers' personal data through prior notification of and consent to the collection of personal data, the establishment of a tiered access-control system, strengthened information security protection, the implementation of employee confidentiality training and management of outsourced vendors, and compliance with data retention and destruction mechanisms.

Intellectual Property Management 

The Company regards its brands and trademarks as core assets. Comprehensive intellectual property protection mechanisms have been established and closely integrated with its business strategy: 

 
Proactive Registration and Protection of Trademarks and Brands
 
Implement Trade Secret and Confidentiality Training
 
Implement Document Classification and Access Controls
Customer Privacy and Data Protection

The Company protects the personal data of both online and in-store members by strictly implementing personal data protection mechanisms. In 2025, no incidents of reported violations related to integrity principles were recorded: 

 
Provide Prior Notice and Obtain Explicit Consent
 
Implement Role-Based Access Control for Personal Data
 
Implement Regular Data Retention and Secure Disposal
Supply Chain Security Protection

To prevent procurement activities and raw materials from threats and counterfeiting, the Company has strengthened contract reviews and supplier evaluation processes while establishing coordinated protection mechanisms: 

 
Require the Signing of Anti-Corruption Agreements 
 
Conduct Supplier Food Defense Assessments 
 
Conduct Food Fraud Vulnerability Assessments 
Share on
  • Copied