Risk Management

FEDS has set up an appropriate risk management system to ensure the Company can actively engage in various business developments under the risk management system and reduce the impact on consumers and the society. Through regular analysis and assessments of the risks of business activities and work execution, FEDS actively takes measures to prevent the occurrence of risks, develop measures to minimize the impact of risk, and prevent their recurrence. The scope of the risk management is not limited to the internal management system, but also the impact of external changes on the business. Systemic risks are categorized to research the commonality. Non-systematic risks that may occur under specific conditions require comprehensive risk management and response measures.

FEDS has established a comprehensive risk management mechanism in accordance with its Risk Management Policy. Systematic and non-systematic risks are identified, assessed, monitored, and addressed by responsible units and cross-functional teams to strengthen risk controls and reduce potential economic, social, and environmental impacts.

The Board of Directors is the highest decision-making body for risk governance and approves risk management policies and directions. The Audit Committee oversees the effectiveness of the risk management system, while management units integrate risk management into daily operations. Risk management performance is reported to the Board at least annually. To enhance operational resilience, FEDS maintains real-time response mechanisms and forms cross-functional teams when needed to address major risk events. The Audit Office conducts risk-based annual audits. In 2025, it completed 90 audit projects and provided recommendations to prevent risks and support stable operations.

A Cyclical and Actionable Risk Management Process

FEDS follows international risk management principles and has established a comprehensive risk management cycle from strategy to execution. Through seven key steps, FEDS continuously identifies, assesses, and monitors risks. This cyclical approach supports continuous improvement in risk management, strengthens corporate governance, and enhances decision-making and long-term business resilience.

Systemic and Non-systemic Risk Management and Response

FEDS has established a “Risk Management Policy” to comprehensively manage and respond to various types of risks based on the causes of “systemic risk” and “non-systemic risk,” carried out by responsible units or cross-departmental functional organizations. To ensure the implementation of various operations under a sound risk management system, we regularly evaluate business activities and execution risks, take preventive measures to prevent risks and minimize the impact of risk occurrence.


Risk Management Procedure
  1. Establishment of awareness
    Conduct training to enhance the understanding of risk management policies and risk identification among supervisors and employees.
  2. Goal setting
    When conducting strategic planning activities, each department should ensure that the associated risks are within acceptable limits.
  3. Risk identification
    Each department must identify the potential risks in its management operations.
  4. Risk assessment
    Each department evaluates and analyzes identified risk events based on practical circumstances, assessing the likelihood of their occurrence.
  5. Risk response
    Develop contingency plans and action strategies to address risk events that have occurred.
  6. Risk monitoring
    Each department should complete its own self-assessment form and submit to the President on a regular basis annually.
  7. Risk disclosure
    Information related to risk management is disclosed in the annual report, sustainability report, or company website.

Professional auditing and risk management enhancement


Risk Management Procedure
  1. Establishment of awareness
    Conduct training to enhance the understanding of risk management policies and risk identification among supervisors and employees.
  2. Goal setting
    When conducting strategic planning activities, each department should ensure that the associated risks are within acceptable limits.
  3. Risk identification
    Each department must identify the potential risks in its management operations.
  4. Risk assessment
    Each department evaluates and analyzes identified risk events based on practical circumstances, assessing the likelihood of their occurrence.
  5. Risk response
    Develop contingency plans and action strategies to address risk events that have occurred.
  6. Risk monitoring
    Each department should complete its own self-assessment form and submit to the President on a regular basis annually.
  7. Risk disclosure
    Information related to risk management is disclosed in the annual report, sustainability report, or company website.
Audit Office

Risk Identification Results and Key Risk Response

In 2025, FEDS identified 16 risks across five areas: legal, operational, financial, environmental and energy, and information security. The top three priorities were climate change and energy policies, cybersecurity, systems, and data security, and interest rate risk. Relevant units have implemented measures including energy conservation, smart equipment management, enhanced cybersecurity, and optimized fund allocation, with ongoing monitoring.

Risk Matrix

Professional Audit Organization Operations

The Audit Office conducts on-site inspections, data sampling, and process reviews in areas including product and food safety, mall operations, information security, and human resources, in accordance with the annual audit plan. It assesses potential risks and provides improvement recommendations to strengthen internal controls and reduce operational risks. The 2025 audit results are as follows:

71

Annual Audit Cases

19

Ad Hoc Audits

Enhancing Risk Management

Commodity and Food Safety Risk

  • Inspect product labeling, expiration dates, liability insurance, and food safety in accordance with the latest regulations.

Information Security Management Risk

  • Supervise the procurement, inspection, and payment of IT hardware and software, and review IT asset disposal.
  • Audit information security incident response, system access rights, personal data protection, and VPN account management.

Human Resource Management Risk

  • Verify headcount, attendance scheduling, leave applications, and HR system data accuracy to ensure legal compliance and fairness.

Shopping Mall Operational Risk

  • Inspect emergency call systems and EV areas to ensure a safe shopping environment.
  • Spot-check inventory to reduce asset loss risks.
  • Review counter accounting, cosmetics disclosures, and company vehicle management.
  • Conduct ad hoc inspections of gas shut-off valves and control-room linkages at food and beverage counters.

Procurement Acceptance payment Management Risk

  • Review procurement price negotiations and amended work-item pricing.
  • Supervise capital expenditure acceptance and verify payment documents.
  • Spot-check FEDS’s GHG inventory and sustainability report data for assurance and compliance.
  • In 2025, supervised 6,926 procurement negotiation, acceptance, and payment cases.

Financial Management Risk

  • Advise the financial management unit on regulatory and subsidiary requirements.
  • Spot-check loans, guarantees, and functional committee operations.
  • Conduct on-site checks of securities, working capital, vouchers, and vault security.

Regulatory Compliance Risk

  • Execute the annual audit plan and reporting in accordance with regulatory requirements.
  • Revise the internal control system and internal audit implementation guidelines.
  • Regularly track regulatory changes and updates from the Financial Supervisory Commission and Taiwan Stock Exchange, and conduct timely reviews accordingly.

Financial Risk Management

Monitors the Changes in Capital and Money Markets
Financial management faces systematic risks, including political, economic, and social factors such as economic fluctuations, currency inflation, and government policy directions, leading to financial market volatility. FEDS closely monitors financial market trends, convening weekly risk management team meetings to review changes in asset and liability values, adjusting operational cash flow adequacy ratios in a timely manner to reduce the impact of systematic financial risks.

Formulating Compliance Direction

FEDS has long been attentive to revisions in various legal regulations, aiming to reduce the impact of systemic legal risks. Through the three aspects of establishing systems, implementing management, and educating employees, FEDS has formulated a direction to promote corporate compliance with regulations, in order to prevent systemic legal risks. FEDS has established strict measures for operations, processes, products, and services in the operation of department stores, ensuring compliance with various government regulations. This approach aims to minimise the company's risk of legal violations, thereby avoiding unnecessary financial and reputational losses.

Regulatory Risk Management

Information Security Risk

Identifies the Sources of Trade Secret Risks

In accordance with the "Internal Control System Processing Guidelines for Publicly Traded Companies," FEDS has a Chief Information Security Officer, an Information Security Team, a Security Supervisor, and two dedicated security personnel to coordinate information security-related affairs. The team consists of members from diverse backgrounds such as legal, information, and operations. Their responsibilities include coordinating, planning, monitoring, and executing all information security management operations to prudently safeguard corporate information security and ensure the security of critical information. Additionally, as information security incidents have occurred frequently among industry peers in recent years, FEDS has continued to review its internal core systems, making adjustments to system architecture and upgrading security measures to defend against external intrusions and reduce the risks of operational disruption and data leakage.

Maintaining Personal Data Management

FEDS' "Information Security and Personal Data Protection Management Committee" assisted in reviewing the use and storage of personal data within various internal units to ensure proper protection and management of all personal data. In early 2024, FEDS established the "FEDS Personal Data File Security Maintenance Plan" in accordance with relevant laws such as the "Personal Data Protection Act" and the "Comprehensive Retail Industry Personal Data File Security Maintenance Management Measures," and formally implemented the ISO 27001 and BS 10012 management systems crucial for information security and personal data protection. This initiative aimed to establish a management system for FEDS' information security and personal data, conducting personal data inventory and risk identification accordingly.

Information Security Risk