Corporate Governance

Green Operation
Phison is committed to environmental sustainability, continually promoting green designs and green supply chains to produce energy-efficient products and operations with lower emissions. Furthermore, we expect to develop a sustainable future with our stakeholders.

Trust and Transparency
Phison values long-term sustainable operations. By building a comprehensive corporate governance structure, we strengthened the transparency or our corporate governance and increased mutual trust and understanding with stakeholders, driving a virtuous cycle in the supply chain of relevant industries to gather strength and take action to better society.

Giving Back to Society
Phison adheres to the philosophy "take from society, give back to society." Therefore, we develop our strategies of social investment in pursuit of common good by leveraging our core businesses in combination with internal and external resources, and committing to five social work themes, namely "support for students", "support for the disadvantaged", "environmental protection", "community care", and "social innovation." In doing so, we hope to use our specialties to help solve social issues and exert Phison's unique social impact.
Corporate Governance

Green Operation
Phison is committed to environmental sustainability, continually promoting green designs and green supply chains to produce energy-efficient products and operations with lower emissions. Furthermore, we expect to develop a sustainable future with our stakeholders.

Giving Back to Society
Phison adheres to the philosophy "take from society, give back to society." Therefore, we develop our strategies of social investment in pursuit of common good by leveraging our core businesses in combination with internal and external resources, and committing to five social work themes, namely "support for students", "support for the disadvantaged", "environmental protection", "community care", and "social innovation." In doing so, we hope to use our specialties to help solve social issues and exert Phison's unique social impact.

Trust and Transparency
Phison values long-term sustainable operations. By building a comprehensive corporate governance structure, we strengthened the transparency or our corporate governance and increased mutual trust and understanding with stakeholders, driving a virtuous cycle in the supply chain of relevant industries to gather strength and take action to better society.
Artificial Intelligence Governance
Phison is committed to promoting responsible and trustworthy artificial intelligence. To ensure compliance and credibility, Phison has established the AI Governance Committee, which operates independently of the existing Information Security Management Committee. Led by senior executives, the committee comprises cross-functional representatives from legal, information security, human resources, and business units. The AI Governance Committee is responsible for overseeing the implementation of the governance framework, reviewing the design of AI application mechanisms, and regularly evaluating the effectiveness of AI ethics and fairness management. Furthermore, the committee has formulated the ” Artificial Intelligence Governance Policy” to ensure that relevant regulations and international governance principles are strictly adhered to throughout the AI lifecycle.
Commitments
- Ensure that artificial intelligence development complies with regulations and corporate policy requirements.
- Ensure that artificial intelligence development aligns with the Company’s sustainability goals and information security policies.
- Enhance employees’ artificial intelligence literacy and sense of responsibility.
- Ensure that artificial intelligence applications respect data privacy.
- Ensure that the artificial intelligence system development lifecycle complies with cybersecurity standards.
- Prevent potential biases within artificial intelligence applications.
- Retain human-in-the-loop mechanisms within artificial intelligence applications.
- Ensure the transparency and explainability of artificial intelligence applications, and clearly label AI-generated content and AI-driven decisions.
- Establish and implement artificial intelligence governance and clear accountability mechanisms.
- Clearly define the boundaries of what artificial intelligence can and cannot perform, and restrict access permissions to sensitive artificial intelligence functions (e.g., biometric recognition, internal surveillance).
- Balance low-carbon and sustainable development by actively evaluating and promoting energy efficiency and ecological footprint management for artificial intelligence applications.
- Prohibit the use or deployment of artificial intelligence applications that involve manipulative behaviors, exploitation of vulnerable groups, social scoring, or unauthorized biometric surveillance.
Responsible Artificial Intelligence Programs and Actions
- Regulatory Compliance
Artificial intelligence development continuously aligns with government regulations, laws, and relevant guidelines, with regular reviews of its compliance and implementation status.
- Education and Training
Plan and promote artificial intelligence education, training, and awareness mechanisms. All employees receive basic training in artificial intelligence ethics and risk awareness. Departments directly using or operating artificial intelligence tools (such as human resources recruitment teams, cybersecurity/compliance teams, R&D, and sales) receive advanced training to strengthen their risk awareness, ethical understanding, and legal compliance capabilities. In 2025, a total of 1,685 participants completed training courses related to artificial intelligence.
- Data Governance and Privacy
Protection Introduce and implement artificial intelligence data governance and privacy protection mechanisms. In accordance with personal data protection regulations and the Company’s privacy policy, the principles of personal data protection, purpose limitation, data minimization, storage and deletion, and the lawful use of third-party data are followed throughout all stages of artificial intelligence data collection, training, development, deployment, and maintenance.
- Cybersecurity
Implement mechanisms such as secure design, access control, encryption, vulnerability management, penetration testing, prompt injection attack protection, and incident response throughout the artificial intelligence system development lifecycle to ensure the security, integrity, and availability of systems and data.
- Ethics and Fairness
Establish and execute ethical and fairness management mechanisms for artificial intelligence applications. Referencing international artificial intelligence governance principles (such as the OECD AI Principles), adopt bias identification, fairness testing, representative data verification, and continuous monitoring mechanisms to prevent artificial intelligence from causing unfair, discriminatory, or biased results for specific groups. Artificial intelligence applications used for recruitment or performance evaluation screening are prioritized for fairness audits and reviewed at least once a year.
- Human-in-the-Loop
Ensure that artificial intelligence applications incorporate human-in-the-loop mechanisms. For artificial intelligence decisions involving significant rights, high risks, or irreversible impacts, mechanisms for human review, intervention, secondary review, termination, or overwriting are retained, and full automation is prohibited. At this stage, the Company explicitly mandates that the following scenarios require human review and retention of the final decision-making power, and final outcomes must not be executed automatically by AI:
-
- Human resources recruitment, interview scoring, or performance evaluation screening.
- Access control involving gates/biometric recognition and internal surveillance applications.
- Automated response decisions for cybersecurity or legal compliance incidents.
- Transparency and Explainability
When planning, introducing, and utilizing artificial intelligence systems, disclose the purpose, capabilities, limitations, risks, and decision-making basis of the artificial intelligence in an understandable manner. Clearly inform users in appropriate contexts that they are interacting with an artificial intelligence system rather than a real person. AI-generated content provided externally or internally, as well as decision-making outcomes assisted or driven by AI (such as recruitment screening results), must be clearly labeled as AI-generated or AI-assisted decisions.
- Management and Accountability Mechanisms
Explicitly establish management and accountability mechanisms for artificial intelligence:
-
- AI Business Owner: Assumed by the head or designated representative of each business unit introducing/using the artificial intelligence application, responsible for the business justification and impact assessment of the application.
- Model Owner: Assumed by the Technical System Integration Division, responsible for model technical security reviews, performance, and vulnerability management.
- Data Owner: Assumed by the data-owning department, responsible for data source legality, quality, and privacy compliance.
- Risk Review Unit: Assumed by the Legal Affairs Department (or risk management unit), responsible for regulatory compliance and risk reviews.
- Cybersecurity Review Unit: Assumed by the Safety & Resource Integration Department, responsible for cybersecurity risk reviews.
In addition, establish mechanisms for artificial intelligence incident notification, investigation, remediation, and traceability of responsibility. Establish appeal/review channels (which may be integrated with existing employee grievance or whistleblowing mechanisms) for colleagues or third parties (such as job applicants) affected by artificial intelligence decisions, in order to identify, assess, and mitigate related risks.
- Usage Regulations and Safeguard Mechanisms
Formulate artificial intelligence usage regulations and safeguard mechanisms, and implement management across all stages of the artificial intelligence system development lifecycle. Explicitly regulate authorized uses, capability boundaries, prohibited uses, and exception escalation review mechanisms. Restrict access permissions for sensitive artificial intelligence functions (such as biometric recognition and behavior monitoring) to authorized personnel only. Introduce risk control and documentation management to ensure traceability, compliance, and to prevent function abuse, creep, or unintended uses.
- Low-Carbon and Sustainability
When adopting internal or third-party artificial intelligence models, computing resources, and data centers, evaluate their energy efficiency, carbon intensity, water consumption, computational optimization, and renewable energy usage, prioritizing solutions with a lower ecological footprint. Reference the carbon emissions and energy consumption data from the Company’s existing ESG/Sustainability Report as a baseline, and integrate the quantified impact of artificial intelligence-related initiatives on sustainability outcomes (such as energy saving benefits and computing efficiency improvements) into existing sustainability KPI disclosures.
- Prohibition of Improper Applications
Establish verification mechanisms to prohibit the use or deployment of artificial intelligence applications that involve manipulative behaviors, exploitation of vulnerable groups, social scoring, or unauthorized biometric surveillance. Authorized biometric uses, such as for access control or attendance tracking, may continue to be used in accordance with current regulations (and employees must be informed of the purpose and scope of use); however, any unauthorized or covert employee behavior monitoring, emotion/behavior scoring, or social scoring applications are strictly prohibited.
- Maintenance and Monitoring
Establish and execute artificial intelligence system maintenance and monitoring mechanisms to continuously monitor model performance, data drift, bias, and security incidents. If the scope of this policy extends to suppliers in the future, supplier risk assessments and compliance reviews will be strengthened.