Leveraging its risk management organizational structure, the Company has established a three-lines-of-defense control mechanism comprising business departments, risk control management departments, and the audit & supervision department, with clearly defined roles and responsibilities at each level. The Board and its Audit Committee bear ultimate supervision and decision-making responsibilities for risk management; the management level (including risk control departments, business departments, and audit & supervision department) specifically executes risk control policies and processes, ensuring risk control permeates the entire business process.
Digitalized Risk-Management Processes
Building on the digital transformation of its risk management, the Company has established a comprehensive, closed-loop management system covering the entire process of risk identification, assessment, response, and early-warning monitoring. The Company uses risk dashboards and tracking reports to dynamically monitor and visualize the effectiveness of risk management measures.
Risk Identification
Drawing on insights into the macro environment and the Company’s business realities, the Company comprehensively identifies risks using tools such as questionnaire surveys, expert interviews, risk workshops, and risk incident reporting. It has established a comprehensive risk landscape covering six Level 1 risk categories: strategic, market, compliance, financial, operational, and ESG risks. These categories are further broken down by function and business process into 49 Level 2 risks and 216 Level 3 risks.
Risk Assessment
The Company conducts dynamic assessments of identified risks, determining their risk levels based on the likelihood of occurrence and magnitude of impact. Risks are categorized into four levels, namely red, orange, yellow, and green, and prioritized accordingly. A tiered management approach is implemented, whereby senior management identifies company-level top risks and designates responsible parties, while the remaining risks are managed on an ongoing basis by the relevant business units or functional departments.
Risk Response
For each risk being managed, the responsible departments define control objectives, risk level downgrade criteria and response measures. They continuously monitor implementation progress and assess the effectiveness of controls, while dynamically optimizing strategies to keep risks within acceptable tolerance levels.
Risk Early Warning
The Company has established 54 key risk indicators, which are cascaded across organizations into 176 sub-indicators for dynamic monitoring and early warning. Early-warning alerts are promptly communicated to responsible departments for root-cause analysis and response-plan formulation. Follow-up continues until alerts are closed, forming a management mechanism of “monitoring – early warning – response – closure”.
Risk Appetite Management
1. Formulate risk appetite: Guided by corporate strategy, the Company sets differentiated risk appetite for each business unit over its operating cycle, taking into account business objectives, business development stage and changes in the external environment.
2. Risk appetite approval by management: Risk appetite statement is submitted to the Company’s senior management for approval and serves as a basis for business decision-making.
3. Monitor risk appetite implementation: Track and assess deviations between each business unit’s risk exposure and the appetite boundaries.
4. Dynamically evaluate and adjust risk appetite: Conduct evaluation and adjustment of risk appetite on an annual basis, or whenever material changes occur to strategy, business objectives or the external environment
Risk Management in Practice
Risk |
Risk Level |
Assessment Methodology |
Risk Description and Impacts |
Risk Mitigation Actions |
Supply chain price volatility risk |
Likelihood: Medium Impact: Medium |
Assessed by synthesizing macroeconomic outlook, industry supply-demand balance and historical price volatility. |
Changes in macro policies, shifts in market supply-demand and cyclical industry fluctuations may lead to fluctuations in the prices of key raw materials (e.g., polysilicon, silver paste), which may create pressure on supply chain cost control. |
• Diversify supply channels to reduce reliance on individual suppliers or regions, enhance bargaining power and strengthen supply chain resilience.
• Establish a price trend analysis mechanism, dynamically optimize procurement strategies, and appropriately allocate long term agreements and spot purchases to mitigate the impact of cyclical price fluctuations.
• Enhance production-sales collaboration to precisely align demand, production and procurement schedules. |
R&D information security risk |
Likelihood: Medium Impact: Medium |
Assessed based on industry practices and the Company’s current R&D information-security controls. |
Core technical documents and data generated through R&D activities constitute critical technical assets. Risks of core technology leakage may arise from staff turnover, external collaborations and data transmission, which could adversely impact the Company’s technological competitiveness. |
• Establish R&D confidentiality policies to define confidentiality requirements for all stages, and implement full-lifecycle management of R&D documents.
• Conduct regular confidentiality reviews and inspections, and strengthen cybersecurity, endpoint security, and physical security safeguards.
• Deliver special training and case briefings on R&D confidentiality to reinforce all employees’ confidentiality awareness and accountability. |