Corporate Governance

Upholding integrity, professionalism and transparency to build a sound corporate governance system

Risk Management

Last Updated:May 7, 2026

Information Security Management

The company places a high priority on information security and has established a comprehensive information security management system to ensure the confidentiality, integrity, and availability of its information assets and to protect customer data and trade secrets.

Scope of Application

This information security management system applies to all departments, personnel, and information systems of the company, covering:

  • All of the company's information systems, network equipment, and related infrastructure
  • All data stored in the company's systems, including customer data, trade secrets, and personal data
  • All employees, outsourced personnel, and partners who use the company's information resources
  • Physical environments related to information security, including server rooms and offices
  • Outsourced information services and cloud services

Information Security Management Structure

The company has established an Information Security Committee chaired by the CIO, which holds regular meetings to review information security policies and their implementation. A dedicated information security unit under the committee is responsible for policy formulation, risk assessment, incident response, and training.

Information Security Measures

  • Deploy firewalls, intrusion detection systems, and antivirus software to defend against external attacks
  • Implement identity authentication and access control mechanisms to manage data access permissions
  • Regularly conduct security health checks and vulnerability scans to patch system vulnerabilities promptly
  • Establish data backup and disaster recovery plans to ensure business continuity
  • Encrypt the transmission of sensitive data to protect data transmission security
  • Implement network segmentation to reduce the spread of security risks

Information Security Training

The company regularly conducts information security training to raise employees' security awareness. Training covers topics such as social engineering prevention, password management, phishing email identification, and mobile device security, ensuring all employees have basic security knowledge and protective capabilities.

Information Security Incident Response

The company has established an information security incident response mechanism, defining incident classification standards and reporting procedures. When a security incident occurs, the response procedure is immediately activated to conduct investigation, impact assessment, damage control, and recovery, followed by review and improvement to prevent recurrence.

Information Security Certification & Audit

The company is certified under ISO 27001 for its information security management system and undergoes regular internal audits and external verification each year to ensure that the management system continues to operate effectively and meets international standards.

Internal Audit

The company has an independent internal audit unit reporting directly to the Board of Directors. It assists the Board and management in examining and reviewing deficiencies in the internal control system and in measuring operational effectiveness and efficiency, providing timely improvement recommendations to ensure the internal control system is continuously and effectively implemented and to serve as a basis for reviewing and revising it.

Audit Organization & Responsibilities

The internal audit unit has a dedicated chief auditor and audit staff. The chief auditor should be capable of leading and managing audit work, and internal auditors should have professional knowledge or practical experience in accounting, finance, information, law, operations management, and other fields.

Key responsibilities:
  • Formulate the annual audit plan and carry out audit operations
  • Evaluate the effectiveness of the internal control system
  • Verify the reliability of financial reporting
  • Review the effectiveness and efficiency of operating activities
  • Assess compliance with laws and regulations
  • Track the remediation of audit findings

Audit Scope & Procedures

The internal audit scope covers all of the company's operating activities, including finance, business, production, R&D, procurement, human resources, and information operations. Audits are conducted based on risk assessment results using both regular and project-based audits to ensure high-risk items receive appropriate attention.

Audit Result Reporting

Auditors should issue an audit report after each audit, documenting findings, recommended improvements, and the audited unit's responses. Audit reports should be regularly submitted to the Board of Directors and the Audit Committee, with significant anomalies reported immediately. The audit unit should also continuously track remediation to ensure deficiencies are effectively addressed.

Audit Independence & Professional Development

The company ensures the independence of the internal audit unit. Auditors maintain a spirit of detachment and independence when performing their duties, free from interference by other departments. The company also encourages auditors to pursue continuing education and attend professional internal audit training courses to enhance their expertise.

Whistleblowing Form

If you discover any violation of laws, internal policies, or misconduct within the company, you are welcome to report it through this form. We are committed to protecting the whistleblower's identity and investigating the reported matter.
Whistleblowing inbox: whistleblower@sellingware.com.tw
All reports are handled by dedicated personnel, with strict confidentiality of the whistleblower's identity and the report content.