Business Integrity

Eective corporate governance is the cornerstone for sustainable development of enterprises. We see Ethical Corporate Management as the supreme principle, implement sound risk management, comprehensive information security management, and actual compliance with laws and regulations. As a means to achieve the goal of sustainable co-prosperity, we took a proactive approach to understand and respond to the needs of various stakeholders through a variety of information disclosure channels on top of rigorously safeguarding shareholders' rights and interests and ensuring that all shareholders enjoy fair and equal rights.
 

Corporate Governance

ECOVE sees ethical business management as the basic principle of corporate governance, and it is our objective on top of focusing on robust organizational growth and satisfying investors and various stakeholders. We have established multiple channels to provide relevant information, such as holding regular investor conferences and annual shareholders' meetings, as well as setting up a special zone for investor relations, a special zone for corporate sustainability, and a special zone for stakeholders, etc., in order to continue to strengthen the disclosure of information, to respect the rights and interests of all stakeholders, and to achieve eective communication.
 
ECOVE not only focuses on resource recycling-related fields in investment planning but also places great importance on implementing sustainable development. Through transparent, professional, and robust corporate governance principles, ECOVE has been consistently ranked in the top 5% of the "Corporate Governance Evaluation"for listed companies for 12 consecutive years. This demonstrates our commitment to being a responsible corporate citizen and serves as a model for information disclosure and ethical business practices.
 

Governance Structure

The Board of Directors of ECOVE is the Company's highest decision-making body, responsible for overseeing the Company's operations and formulating major strategies. To ensure sound corporate governance, we have established an Audit Committee and a Remuneration Committee under the Board of Directors, which are responsible for overseeing the Company's finances and compensation system, respectively. Additionally, a sustainable information management organization has been set up to manage the planning and execution of audit operations. The unit not only reports on audit activities to the independent directors on a regular basis but also attends meetings of the Audit Committee and the Board of Directors to provide reports.
 

Transparent and Efficient Operations

The operation of our Board of Directors follows the "Rules Governing Procedure for Board of
Directors' Meetings" and "Guidelines for Board of Directors Meeting Operations Management."The Board holds meetings at least once per quarter, adheres to conflict of interest regulations, and any director with personal interests involved in a board resolution automatically recuses themselves and does not act as a proxy for other directors in voting. The average attendance rate of all directors on the Board of Directors in 2025 was 97.8%, which is above and in compliance with the 85% corporate governance rating metric. The Chairman of ECOVE has the primary responsibility of overseeing the executive management to ensure that the Company's operations and business execution align with the corporate philosophy. The President's primary responsibility is to lead the management team and ensure the overall operations are carried out in accordance with the directives of the Board of Directors. The Chairman does not concurrently hold the position of President to avoid conflicts between their respective responsibilities. However, the Chairman is also a member of the management team and serves as the Chair of the Strategy Committee, enabling the Company to respond swiftly to various challenges. Meanwhile, the Chairman remains subject to the Company's conflict of interest and recusal policies applicable to board members, and duly abstains from voting on relevant agenda items in accordance with such regulations, thereby ensuring the independence and integrity of the decision-making process.
 

Board Diversity and Independence

To ensure the independence of the Board of Directors, we have implemented a strict candidate nomination system, whereby the shareholders' meeting elects from the list of director candidates. Directors may be re-elected consecutively. As of the end of 2025, the average tenure of our Board of Directors is 8.1 years. In addition, the Company amended its Articles of Incorporation in May 2025, stipulating that the Company shall have five to nine directors, each serving a term of three years, with the possibility of re-election. Among these, the number of independent directors shall not be less than three and shall not be less than one-fifth of the total number of directors.
 
In addition, we are committed to promoting a diverse structure for the Board of Directors. The Company's Corporate Governance Principles explicitly state that the composition of the Board of Directors should take into account diversity, including but not limited to basic qualifications such as gender, age, nationality, and culture, as well as professional knowledge and skills. Furthermore, specific management objectives for the Board's diversity policy shall be formulated based on the Company's operations, business model, and development needs. These objectives include that the number of directors who concurrently serve as executives of the Company shall not exceed one-third of the total Board seats, there should be at least one female director, and at least two independent directors whose consecutive terms do not exceed three terms.
 
The current Board of Directors consists of 9 members, of which 2 members are employees
(approximately 22% of the total board), and also includes 1 female director (approximately 11%) and 3 independent directors (approximately 33%), in accordance with the diversity policy. The Board is responsible for formulating the Company's business policies and important strategies. All members of the Board possess the professional knowledge, experience, and qualifications necessary to perform their duties, including expertise in engineering and environmental protection, industrial safety, water resources, finance, and sustainable environmental practices. They are well-versed in international perspectives, decision-making leadership, and crisis management capabilities to respond to changes in economic, environmental, and social aspects. Information regarding the Board members' positions on other Boards has been disclosed in the Company's most recent Annual Report.
 
Profiles of Board members and their respective roles and responsibilities;the Board diversity policy and its implementation

Directors' Further Training and Performance Evaluation

To strengthen corporate governance, enhance the effectiveness of the Board of Directors,
establish performance objectives, and improve the efficiency of Board operations, the Company has established the "Regulations Governing the Board Performance Evaluation,"which stipulates that the Board of Directors of the Company shall conduct an internal performance evaluation annually, and shall be evaluated by an external professional independent organization or a team of external experts and scholars at least once every three years, and that the scope of the evaluation shall include the entire Board of Directors, individual members of the Board of Directors, and functional committees. The evaluation methods include internal self-assessments by the members of the Board of Directors and functional committees (Remuneration Committee and Audit Committee), and performance evaluations conducted by external professional organizations and experts or other appropriate methods. The results of the internal and external performance evaluations of the Board of Directors shall be completed before the end of the first quarter of the following year. In order to enhance the quality of decision-making, ensure that the decisions of the Board of Directors are closely aligned with the goals of sustainable corporate development, strengthen governance eectiveness, and respond to stakeholder expectations, the performance evaluation indicators for the Board of Directors have been updated in December 2023 to include an evaluation item of "participation in sustainable management (ESG)."The individual performance evaluation of directors will serve as a reference for determining their compensation.
 
The Company appointed Taiwan Corporate Governance Association, an external professional and independent organization, to conduct a performance evaluation of the Board of Directors at the end of 2024. The evaluation results and proposed follow-up measures have been presented at the 13th Board meeting of the 9th term on May 5, 2025. The next performance evaluation will take place at the end of 2027. The results of the Board's performance evaluation, as well as subsequent reviews and improvements, will be reported to the Board and disclosed in the annual report and on the Company's website.
 
All members of the Board of Directors of the Company have completed relevant training in accordance with the "Guidelines for Continuing Education for Directors and Supervisors of Exchange-listed and OTC-listed companies."The training sessions are coordinated by the Group's Secretariat of the Board of Directors in accordance with the needs of the directors' professional functions or external trends. The training content covers corporate governance, business ethics and compliance, risk management, corporate sustainability, information security, etc., aiming to enhance the Board's understanding of emerging issues and the eectiveness of corporate governance. In 2025, director training programs covered topics including geopolitical risks and forthcoming IFRS Sustainability Disclosure Standards, with the aim of strengthening directors' ability to identify and manage risks arising from global developments and evolving sustainability regulations. In 2025, the average training hours for the Company's directors reached 6.7 hours, with all directors meeting the requirement of a minimum of 6 hours of training under the "Guidelines for Continuing Education for Directors and Supervisors of Exchange-listed and OTC-listed companies."Related information is disclosed on the Market Observation Post System.
 

The internal performance evaluation results of the Board of Directors
The external performance evaluation results of the Board of Directors

Remuneration Structure for Directors and Managers

The remuneration of the Company's Directors and General Manager follows the guidelines and criteria set forth by the Remuneration Committee and the Board of Directors, including the "Guidelines for Director Performance Evaluation and Remuneration System"and the "Guidelines for General Manager Performance Evaluation and Remuneration System."The remuneration takes into account industry norms, as well as the Company's performance, individual contributions, and achievements, aiming to provide reasonable compensation.
 

The Chairman and Managers (including those who concurrently serve as directors) are also subject to annual performance assessment. The assessment encompasses the achievement of various financial goals (approximately 50% weightage), and non-financial performance indicators (approximately 50% weightage). Since 2022, ESG items have been incorporated into performance objectives, accounting for 10% of the total weighting. Discussions on target setting are conducted at the beginning of the first quarter each year, with achievement levels reviewed in the fourth quarter. Key performance indicators include results in domestic and international sustainability ratings, carbon reduction benefits, the promotion of off-site environmental education initiatives, and ESG management of suppliers. In addition, the annual salary adjustments and performance bonuses are calculated based on their performance evaluation results. The performance results, salary adjustments, and annual bonuses are reported to the Remuneration Committee and the Board of Directors for discussion:
Furthermore, within the annual performance assessment, supervisors have ESG self-assessment items to encourage them to actively participate in various internal and external ESG activities or awards within the group. This aims to ensure the implementation of the Group's ESG sustainable goals in daily work.
 

The president, managers, and remaining employee remuneration and welfare protection are also inline with the general management's regulations. However, there are exceptions for the allocation of stock options and pensions for senior managers, where the distribution of warrants is reviewed by the Remuneration Committee, while pension is set out based on the coverage rate of the old pension mechanism and is controlled by the Pension Supervision Committee and an actuarial firm to protect the retirement rights and interest of senior managers as employees.
 

The Remuneration Committee and the Board of Directors shall regularly review the reasonableness of the remuneration, and shall review the remuneration system from time to time according to the actual operating conditions and relevant laws and regulations. They shall not guide the directors, president, and vice president to engage in acts beyond the Company's risk appetite in pursuit of remuneration, so as to avoid improper circumstances such as the Company suering losses after payment of remuneration. The distribution of remuneration to employees and directors is regularly reported to the shareholders at the annual shareholders' meeting.
 

Business Ethics and Legal Compliance

Business Ethics

ECOVE upholds the principle of ethical management. To ensure that its daily operations comply with corporate ethics and moral standards, the Company has established the "Corporate Governance Principles," "Ethical Corporate Management Principles," and "Code of Ethical Conduct," all of which have been approved by the Board of Directors and apply to directors, managers, and all employees as behavioral guidelines to be observed by all personnel. In addition, ECOVE has established work rules to provide guidance for all employees in the conduct of daily business activities. The Company's Group Shared Services is responsible for the development and subsequent implementation of the Corporate Integrity Management Plan, and the General Manager, the highest decision-making authority of the Group Shared Services, determines and supervises the implementation of the Corporate Integrity Management Plan. The Company reports the results of the "Policy for Promoting Corporate Integrity" to the Board of Directors once a year.

To uphold fair dealing and prevent corruption and bribery, ECOVE strictly requires, in accordance with its Code of Ethical Conduct and No-Gift Policy, that employees must not offer preferential treatment when engaging in transactions with related parties. Employees are also prohibited, in the performance of their duties, from requesting, promising, giving, or accepting gifts, entertainment, kickbacks, bribes, or other improper benefits for their own benefit or for the benefit of others. In addition, the Company's Code of Ethical Conduct stipulates that employees must not, by any means, influence other employees to make political contributions, support a specific political party or candidate, or participate in other political activities. For all operating sites, ECOVE identifies and mitigates relevant risks through its internal control system. According to the results of the 2025 assessment, no material corruption risks were identified.
 
In order to ensure that all ECOVE employees are familiar with the various management standards, since 2020, all employees, regardless of their positions, including newly hired sta, are required to sign the "Employee Ethics Commitment Letter." In 2025, the signing rate reached 100%. During the orientation and training for new employees, the importance of ethics and integrity is emphasized, along with an introduction to ECOVE's "Code of Conduct," "No Gift Policy," "Whistleblowing Website," and other legal compliance regulations and reporting mechanisms. Since 2017, a "Code of Conduct for Procurement Personnel" has been established, requiring all procurement sta to sign it upon employment. The code explicitly prohibits the solicitation of improper benefits and provides guidelines and reporting procedures regarding the giving and receiving of gifts so as to prevent conflicts of interest or the compromise of the impartiality of procurement decisions. As of 2025, the signing rate is 100%. Since 2018, ECOVE also requires all employees of aliated companies to sign the "Confidentiality, Non-Competition, and Intellectual Property Commitment Letter." In 2025, there were no incidents of corruption or bribery, and our commitment to ethical management in business operations has received recognition and approval from our partners.
 
Furthermore, ECOVE continuously strengthens the commitment to ethical management, and has incorporated "ethics" as part of the annual performance evaluation criteria for all employees, accounting for 5% of the performance evaluation metrics. This aims to deepen the connection between ethics and positive employee behaviors. Meanwhile, each year, the Company organizes both internal and external activities and training sessions related to ethical management for all employees. In 2025, two online ethical corporate management courses were conducted for all employees, with a total of 1,835 participants in both sessions. The number of employees who completed the courses was 1,835, representing 100% of all employees. In addition, the education and training program for new recruits also includes courses related to ethics and integrity, such as Code of Conduct, Code of Ethical Conduct, and Business Secrets, and the participation rate is 100%. The total number of training hours for the above related courses is 2,753. All board directors also underwent courses related to ethical corporate management issues, and advocacy was further conducted on the issues of legal compliance, avoidance of interest, improper political contributions and donations, with a completion rate of 100%, thereby strengthening the concept of ethical management at the governance level.
 

Training Results for Ethical Management Courses in 2025

Through practical actions, we strengthen the ethical business management with vendors, during interactions with vendors, such as requesting for quotations, tender meetings, going through ordering procedures, etc. we will express CTCI's and ECOVE's resoluteness in ethics by means of words, written and verbal. Prior to a tender meeting, we will execute Integrity Moment actions, announcing and explaining the contents of the Supplier Code of Conduct to vendors, simultaneously informing the prohibition of private interests, and providing information to the whistleblowing mailbox. Additionally, the implied covenant of good faith and fair dealing is also added to purchase orders to vendors and engineering commission contracts.
 

Corporate Governance Standard
Ethical Corporate Management Best Practice Principles
Code of Ethical Conduct

Compliance

The Company's business scope covers four major areas: energy and resources, recycling and reuse, renewable energy, and system facility installation and maintenance. We regularly review the latest legal changes and updates both domestically and internationally and are committed to establishing a culture of compliance. In 2025, ECOVE did not face any legal actions related to anti-competitive behavior, antitrust and monopoly practices, non-compliance with product and service information and labeling regulations, or violations of marketing and promotion (regulatory or voluntary guidelines). In 2025, ECOVE and its subsidiaries had no regulatory violations resulting from "major occupational accidents" as defined under Article 37 of the Occupational Safety and Health Act, nor any material regulatory violations involving a single fine exceeding NT$1,000,000.
 

Whistleblower and Consultation Mechanism

To ensure effective management of whistleblowing cases involving the Company, and to establish accessible reporting channels and impartial investigation procedures, ECOVE has established the "Whistleblowing Operation Management Measures." These measures are not only available on the Company's internal employee education platform, but are also published on the official website for both internal and external personnel to download and reference. During the onboarding training for new employees, the reporting channels and the relevant rights of whistleblowers are included in the training materials to ensure that all employees understand the operation of the reporting mechanism and their rights.
 
Whistleblowing cases are received by the Human Resources unit, which conducts a preliminary review and provides initial recommendations. The cases are then submitted to the President for review and, where appropriate, formally registered for investigation. Internal and external personnel who discover any violations of laws, regulations of the Company, or other improper conduct that may aect the interests of the Company may freely choose to report such incidents either by providing their names or anonymously. Internal whistleblowers wishing to file a report may do so through the Employee Feedback Platform's employee mailbox ( HR@ecove.com) or by utilizing the reporting website established by the third-party impartial organization, KPMG Taiwan, to protect the rights of the whistleblower and ensure that the reported cases are properly investigated and addressed.
 

Furthermore, we are committed to maintaining the confidentiality of the whistleblower's information. All participants in the investigation and interviewees required for the case must sign a confidentiality agreement, pledging to uphold the confidentiality of the investigation process and any case-related information they may encounter. Additionally, we will protect the whistleblower from being dismissed, removed from their position, demoted, or subjected to any detrimental treatment that may harm their legal rights, contractual entitlements, or customary benefits as a result of their whistleblowing.
 

If employees have concerns or inquiries regarding the various codes of conduct or ethical business practices, they can consult with their supervisors or contact the internal complaint mailbox (HR@ecove.com). In 2025, no grievance cases were received. ECOVE will continue to follow the brand positioning of "Most Reliable" and continue to implement the Ethical Corporate Code of Integrity, reaffirming and reinforcing employees' beliefs in integrity - honesty, commitment, and sincerity, including: organizing training courses to deepen trust in the corporate culture; organizing online ethical and integrity training courses for all employees and signing of declarations, etc., as well as ensuring a smooth channel for employees to report operations, and increasing the resolve of colleagues to expose malpractices.
 
 

Risk Management

In order to strengthen the operational quality and competitiveness of the Company and its subsidiaries, the Company systematically identifies and evaluates the risks it may face in the course of its operations and formulates appropriate risk management strategies to reduce the likelihood of the occurrence of risks and their negative impacts, as well as implements an allemployee risk culture, promotes the Company's core values to its employees, sets behavioral indicators, and strengthens the organization's behavioral and internalized awareness of risks.
 

Risk Management Framework

ECOVE focuses on the risks faced in the course of operation to integrate the corporate risk management framework and build a perfect risk management organization and system. In 2017, ECOVE issued the "Risk Management Guidelines" and set up the "Risk Management Committee" to formulate the "Risk Management Policies," which serves as the supreme guiding principle of the Company's risk management, and clearly regulates the policy, purpose, scope, and organizational structure of risk, unit's authority and responsibility, risk management mechanism and execution process, and incorporate the risk management system to implement risk management.
 
ECOVE's Board of Directors serves as the highest governance body responsible for risk management. The Company has also established an Audit Committee composed of 3 independent directors to assist in overseeing the management and control of existing and potential risks. The Risk Management Committee reports on the implementation status of risk management to the Audit Committee and the Board of Directors at least once a year. The most recent report, titled "Operation of the Risk Management Committee in 2025," was presented on December 11, 2025, to ECOVE's 4th Audit Committee at its 15th meeting and the 9th Board of Directors at its 16th meeting.
 

The Company has established the "Risk Management Committee." The Chairman/President serves as the Commissioner, and the heads of each department and the Presidents of subsidiaries serve as committee members. The committee meets quarterly and is responsible for approving risk management policies and guidelines, reviewing management reports, strategies, and improvement plans of each unit, ensuring the efficectiveness of risk management measures, etc., and continually reviewing the effictiveness of the control measures through audits to help the Board of Directors and managers to ensure that the risks are eectively controlled. The risk control representative is appointed by the Commissioner of the Risk Management Committee. The representative is responsible for overseeing the convention of the Risk Management Committee meetings, as well as organizing and tracking relevant data and files, ensuring the continuous effectiveness of the risk management mechanisms. The Risk Management Committee in 2025 has convened four meetings to monitor the status of existing risk improvements and the results of the major risk item inventory.
 
Each member of the Risk Management Executive Committee shall bear full responsibility for risk management, which includes risk identification, assessment, reporting, and the execution, supervision, and improvement of daily control measures. The Risk Management Committee's roles and responsibilities include promoting, supervising, identifying and managing significant risks, compiling and compiling risk profiles and improvement plans for each company, collecting and monitoring significant risk events in each company, evaluating the extent of impacts, reporting significant risks and related improvement plans to each company's general manager, communicating risk management guidelines to members, identifying, analyzing, evaluating, handling and reporting the risks of the units under our control, ensuring the efficective implementation of the risk management and related control procedures of the units under our control, participating in the meetings related to the risk management of the units under our control, providing the opinions related to the risk management and control, accepting the related risks of the units under our control, proposing the risk mitigation plans/measures of the units under our control and handling and tracking the control according to these plans/measures, informing the colleagues of the units under our control of the items that should be followed and cooperated with by us, and assigning a responsible person for the management and control of the risk management projects as necessary.
 

Risk Management Mechanism

ECOVE categorizes risks into three main types: climate and natural risks, operational risks, and project risks. To mitigate the operational impacts caused by internal and external uncertainties, a comprehensive risk management process is implemented. This process includes systematic risk identification, risk analysis, risk assessment, and response measures to address and manage risks that may pose threats (or opportunities) to the Company. The aim is to avoid or reduce the impact on operations. All employees are also responsible for identifying and reporting risks. If any significant risk events that may aect the Company's operations are discovered, they should be reported immediately to their respective supervisors.
 

ECOVE conducts a comprehensive review of poten tial risks across the business scope of each department through regular Risk Management Committee meetings. ECOVE primarily adopts the "Risk Consequence Severity and Probability Assessment Method" and the "Risk Quantification Indicator Method" to comprehensively evaluate risks. The assessment takes into account both financial indicators, such as impacts on gross profit, and non-financial indicators, including corporate image, reputation, and occupational safety impacts, while also considering the likelihood of occurrence. Based on these factors, ECOVE establishes risk levels to clearly measure the impact and probability of identified risk items, ensuring that risks are properly identified in accordance with their respective risk ratings.
 
After identifying key risk items, the relevant risk responsibility units will discuss and evaluate them to establish "alert standards" and "action standards." These will be submitted to the Risk Management Committee for resolution, and will be implemented upon approval by the President, serving as the basis for risk mitigation and control. If the alert standards are met, each risk management unit shall report to the supervisors of their respective units and monitor the situation according to procedures. If the action standards are met, an emergency risk response team will be established to handle and respond to urgent risk events.
 

Risk Review

Each risk management unit shall conduct risk identification, risk analysis, risk assessment, and risk control processes at least once every six months. This includes identifying potential risks that the Company may face within its business scope, analyzing the degree of impact and probability, selecting appropriate risk control measures based on each identified risk, and formulating mitigation strategies. The findings shall be submitted to the Risk Management Executive Committee for review to assess the eectiveness of risk control measures and action management, and to continuously monitor the status of risk improvement.
 

Risk Assessment and Analysis

According to the scope covered by the risk management framework, in the assessment results for 2025, ECOVE has identified the following 3 major high-risk items:

Based on the aforementioned risk assessment results, appropriate risk control measures will be selected for the primary identified rather high risk items. This will involve the formulation of risk mitigation action plans, including risk control and improvement strategies. Continuous monitoring of the implementation of these mitigation actions will be conducted to ensure that the mitigation plans are eectively executed. The main risk mitigation action measures are described as follows:
 

Emerging Risk Management

Emerging risks refer to issues that may have significant potential impacts, but whose nature and scope of impact have not yet been fully clarified or assessed. Such risks are generally dicult to quantify precisely and are accompanied by a high degree of uncertainty and variability. To proactively identify the potential impacts of emerging external issues on its key business operations, ECOVE screens and identifies major emerging risk items through its risk identification and analysis process. The Company further develops corresponding risk mitigation and response strategies to enhance its adaptability to changes in the external environment.
 

The major emerging risk items identified by ECOVE in 2025, along with the related operational impacts and risk mitigation measures, are detailed below:
 

In the face of a rapidly changing external environment, ECOVE recognizes that integrating the identification and management of emerging risks into daily operations and long-term strategic planning is essential for advancing steadily amid growing uncertainty. Looking ahead, the Company will continue to strengthen its risk management mechanisms, promote cross-departmental collaboration and resource integration, and transform challenges into opportunities through agile adaptability. While safeguarding the quality of its environmental services, the Company will continue to create longterm, mutually beneficial value for shareholders, customers, and society.
 

Strengthening Risk Culture

• Risk Training for Directors and Senior Executives

To strengthen the risk awareness and governance capabilities of ECOVE's directors and executives, all directors and executives continued to participate in relevant training programs in 2025. The topics covered included "Future Market Trends from the Perspective of Global Financial and Economic Changes" and "Key Principles and Practices of the IFRS Sustainability Disclosure Standards and CTCI's Response Strategies." The training focused on key issues such as global financial and economic developments, the evolution of sustainability disclosure standards, corporate sustainability actions, risks associated with artificial intelligence applications, and cybersecurity resilience. These programs helped directors, including non-executive directors, and senior executives stay informed of changes in the external environment and emerging risk trends, while deepening their understanding of risk management principles, risk governance frameworks, and risk appetite planning linked to strategic objectives.
 

• Risk Training for All Employees

The Company is committed to enhancing the eectiveness of risk management. In addition to implementing policy communication and awareness initiatives through each control unit, the Company has also established systematic mechanisms to help all employees identify and assess operational risks. After completing risk assessments and response planning, the Company not only requires rigorous execution in daily operations, but also continues to dynamically update and revise operating standards based on business characteristics, operating scale, and current operational conditions. At the same time, regular training programs are conducted for managers and employees to strengthen risk awareness across the workforce and ensure that risk management practices remain up to date.
 

In addition, ECOVE holds Compliance Week activities on a regular annual basis to strengthen employees' understanding of regulatory knowledge and operating procedures, enhance their capabilities in risk identification, prevention, and response, and help employees understand the compliance matters that require attention during business execution, thereby preventing compliance incidents from occurring. The courses cover areas such as occupational safety and health, quality, administration, and human resources, with key topics including workplace sexual harassment prevention, gender equality, the Code of Ethical Conduct, personal data and trade secret protection, integrity and legal compliance, and occupational safety and health regulations. In 2025, a total of 484.5 training hours were completed. In addition, new employees who joined after Compliance Week were arranged to receive compliance training as part of their onboarding training in the month of employment, ensuring a 100% participation rate among all employees. In addition, ECOVE oers elective courses through CTCI University, covering topics such as integrity and legal compliance, the Personal Data Protection Act, prevention of unlawful infringement, the Labor Standards Act, and overwork prevention, helping employees further strengthen their awareness of human rights and legal compliance.
 

• Risk Control Metrics and Incentives

To enhance the eectiveness of risk management, ECOVE aligns with the Group's annual risk control objectives each year and requires all units to implement risk control measures, while measuring and monitoring progress against the established risk control targets. In 2025, the Group's risk control objectives were the "Implementation Rate of High-Risk Management Training" and the "Implementation Rate of High-Risk Control Measures." The measurement items included the coverage rate of risk management training, the implementation status of risk control measures, and the timely completion of improvements for nonconformities.
 
For all employees, ECOVE continues to deepen its risk culture, with "safe behavior" and "integrity" as the key focus areas. Employees are required to strictly comply with standard operating procedures, proactively identify situations that may aect safety, and report them in a timely manner. Meanwhile, employees are required to uphold the principle of integrity, comply with laws and regulations, employee codes of conduct, internal systems, and procedures, and are encouraged to report, disclose, and prevent conduct that may harm the interests of the organization. To further strengthen the implementation of its risk culture, ECOVE has established incentive measures. Criteria for rewards and disciplinary actions have been set out in the "Employee Reward and Disciplinary Measures" and the "Proposal Incentive Measures," under which dierent levels of commendations and bonuses are granted based on the nature of the relevant conduct.
 

Internal Control System

ECOVE's internal control system is based on the "Regulations Governing Establishment of Internal Control Systems by Public Companies" issued by the Financial Supervisory Commission. It incorporates elements such as control environment, risk assessment, control activities, information and communication, and monitoring. Designed by managers, approved by the Board of Directors, and implemented by the Board of Directors, managers, and other employees, the system aims to promote sound business operations, ensure operational eectiveness and eciency, reliable and timely information reporting, and compliance with relevant laws and regulations. It is regularly reviewed to adapt to changes in the internal and external environment, ensuring the ongoing effectiveness of system design and implementation. In 2024, the Company established an internal control system for sustainable information management, which was approved by the Board of Directors in December 2024.
 
ECOVE has an internal audit unit under the oversight of the Board of Directors. The unit has established an internal audit system, which is approved by the Board of Directors. It is staed with a dedicated audit manager and works in conjunction with the Audit Committee to assist the Board of Directors and managers in examining and reviewing deficiencies in the internal control system, measuring operational eectiveness and eciency, and providing improvement recommendations as necessary. This ensures the continuous and eective implementation of the internal control system and serves as a basis for reviewing and revising the system.
 
The audit department develops an annual audit plan based on risk assessments and submits it for approval by the Board of Directors. It then carries out various audit procedures according to the plan. Identified deficiencies and abnormal issues related to the internal control system are disclosed in audit reports, which are tracked and followed up after submission. Follow-up reports are prepared at least quarterly until improvements are implemented to ensure that relevant departments have taken timely and appropriate corrective measures. The audit manager reports the results of the audit plan execution to independent directors monthly and has individual faceto-face meetings with independent directors at least once a year to discuss internal control and audit-related matters. The audit manager also attends Audit Committee and the Board of Directors meetings to present audit business reports and demonstrate the eectiveness of the audit function. Audits of the sustainability information management operations were conducted in May and November 2025, with no deficiencies identified in either audit.
 

Information Security

ECOVE is committed to protecting customers' core intellectual assets. Through a sound information security governance system, regular information security risk assessments, and diverse information security management mechanisms, ECOVE strengthens the reliability and quality of project execution, ensures compliance with project owner requirements and applicable laws and regulations, and continuously enhances customer trust. The Company proactively identifies and mitigates information security risks in accordance with applicable regulations, including the Regulations Governing Establishment of Internal Control Systems by Public Companies, the Trade Secrets Act, the Personal Data Protection Act, and the Cyber Security Management Act, thereby comprehensively enhancing the quality of information security.
 
To comply with legal requirements and operational demands, and to protect the personal data of the Company's employees and relevant individuals, the "Principles for the Protection of Personal Data Security" have been formulated. These principles apply to all employees hired by the Company (including its subsidiaries) as well as personnel dispatched to work at the Company. The responsible units include the Human Resources Department, Information Services Center, Safety and Health Management Department, all department heads, and the Personnel Committee. In 2025, ECOVE conducted internal training on the Personal Data Protection Act, with total training hours reaching 947 hours and a completion rate of 100%. This demonstrates the Company's
strong emphasis on personal data protection and its commitment to eective implementation.
 
In 2025, ECOVE did not experience any information security incidents, nor were there any substantiated complaints concerning breaches of customer privacy. This fully demonstrates the effectiveness and robustness of the Company's information security management mechanisms.
 

Information Security Management System

ECOVE complies with the requirements of Article 9-1 of the Regulations Governing Establishment of Internal Control Systems by Public Companies, and has announced the establishment of a dedicated information security unit in 2023. A dedicated head of information security and a dedicated employee of information security have been appointed. The Chief Information Security Ocer oversees the promotion, coordination, and supervision of the Company's information security policies, with dedicated information security personnel responsible for planning and executing various information security operations.
 
In terms of governance mechanisms, the Company is required to convene an Information Security Management Review Meeting at least once a year to review matters related to information security management. Where necessary, the meeting may be held jointly with the Risk Management Executive Committee. In accordance with the "Risk Management Guidelines," the Risk Management Executive Committee serves as the Company's primary body for promoting risk management. The results of information security audits are required to be submitted regularly each year and incorporated into the Risk Management Executive Committee Report, which is presented annually to the Board of Directors on the status of annual work and related plans.
 
The dedicated employee of information security has passed the training of the new version of ISO27001:2022 for leading auditors. We have re-examined the "Information Security Management Guidelines" and the accompanying standards in the spirit of ISO/IEC 27001 to strengthen the Company's information security management system, in order to ensure the confidentiality, completeness, and usability of information under the Company's jurisdiction, and to further safeguard the rights and interests of the Company and all colleagues.
 
In 2025, ECOVE, its subsidiaries, and domestic and overseas factories, projects, and sites were randomly inspected for a total of 33 safety audits, with a total of 55 items, all of which have been improved.
 

Information Security Risk Assessment

To proactively identify possible risks to information security, we conducted an annual risk assessment exercise to analyze key items from a combination of potential threats and vulnerabilities, including:
 

Information Security Management Mechanisms

Information Security Management Mechanisms

In order to continuously strengthen information security management operations, ECOVE continues to invest resources in information security-related matters every year. In 2025, the investment in information security-related software, hardware, and service rentals reached NT$13.62 million. Resource allocations include strengthening security defense equipment, relocating the email system to the cloud, upgrading and revising antivirus software, replacing outdated equipment, establishing remote backup validation mechanism, implementing a PAM system, commissioning external professional cybersecurity vendors for security assessments and improvements, and reinforcing security management systems and education training. These eorts span from management to technical aspects to enhance information security capabilities.
 
Due to the significant damage caused to well-known companies by ransomware attacks in recent years, ECOVE has established a "Social Engineering Attack Prevention" website and a "Fraudulent Email Reporting Inbox" to assist employees in identifying and avoiding risks associated with "fraudulent/phishing emails" and more precise "Business Email Compromise (BEC)" attacks.
 
Based on information security risk considerations, we have conducted a comprehensive inventory and implemented security protection work, such as the replacement of old equipment and improvement of old systems, the replacement of the work hour management system, and the expansion of the deployment of MDR threat detection and response services. To eectively distribute the potential losses caused by information security risks, the Company purchased "Electronic Equipment Comprehensive Insurance" in 2025, with a total coverage amount reaching NT$56.51 million. 
 
Employees in the Information Service Center have set dierent items and goals for their respective responsibilities within the "2025 KPI Performance Targets and Scoring Method," including incidents of computer infection within the domain, network, servers, application systems, etc., unplanned service interruptions, non-disaster or external force-induced service disruptions, high-risk individuals in social engineering drills, security inspections, information security audits, etc., to ensure the implementation of various information security measures.
 
In terms of outsourcing management, the Company has established comprehensive outsourcing management guidelines within the Information Security Management Guidelines. All outsourced vendors must sign a Non-Disclosure Agreement, and their project personnel are also required to individually sign a Confidentiality Agreement for Project Personnel of Outsourced Vendors to ensure that responsibilities for information security are clearly delineated. In addition, we require all outsourced vendors to cooperate with the Company in executing the project information security audit to maintain the overall security standards of the information environment.
 

Business continuity plan

To ensure the continuous operation of business and to minimize the impact of significant incidents or disasters on critical operations, ECOVE has established a business continuity management procedure for information services. This procedure involves conducting risk assessments and identifications regarding the severity of the impact of various system architectures on critical operational processes. The severity levels (degree) are defined and serve as the basis for determining the frequency of disaster recovery drills. To verify the eectiveness of the Business Continuity Plan and ensure that relevant personnel are familiar with the latest plan content, the Company mandates that a test drill be conducted at least once a year. In 2025, the Company completed two major drills, covering an IIS website server failure and reset scenario and an AD domain server failure and reset scenario, respectively. These drills comprehensively reviewed and strengthened the Company's disaster recovery capabilities.
 

Information Security Incident Notification

According to the "Information Security Management Guidelines," if employees detect a computer virus intrusion or other malicious software, they should immediately notify the nearest Information Center or the computer administrator of their department for handling. In practice, when the Information Service Center receives notifications from the antivirus system (indicating that automatic cleaning or isolation has failed), they proactively intervene to prevent individual employees from neglecting the antivirus system's alarm notifications. In 2025, there were 0 warnings or notifications of computer virus infection, 0 automatic cleanups, 0 automatic quarantine, and 9 notifications of information security incidents, which did not result in any data loss or customer damage. However, internal education training has been held to address the potential risk factors associated with the reported incidents. In the future, we will continue to refine and review the relevant processes to comprehensively improve the management of information security and align with the international quality requirements.
 

Raising Awareness on Information Security Risks

To enhance employees' understanding of the importance of information security, improve their awareness of security issues and emergency response capabilities, and effectively manage risks, we continue to promote social engineering drills and conduct these drills every quarter. According to the results of the drill, the occurrence rate for high-risk incidents in 2025 is 0%, while the occurrence rate for medium-risk incidents is 0.197%.
 

In addition, various types of educational training are conducted based on different training targets, eectively enhancing cybersecurity awareness and protective capabilities. Furthermore, for those identified as moderate to high risk based on the drill results, educational training on "Understanding Social Engineering Attacks and Key Cybersecurity Awareness" is provided. As of 2025, a total of 1,484 people have participated in the training sessions, amounting to a total of 907.5 hours.
 

Business Results and Industry Outlook

Management Performance

Tax Governance and Transparent Disclosure

ECOVE recognizes that sound tax governance serves as the foundation for business sustainability development and the fulfillment of its corporate citizenship responsibilities. The Company is committed to bearing a reasonable tax burden in all jurisdictions where it operates, and publicly discloses various financial data to investors on its ocial website. Through transparent tax governance, ECOVE puts sustainable development into practice. ECOVE's tax governance framework designates the Board of Directors as the highest decision-making and oversight body, ensuring that the Company's tax strategy is aligned with its overall business strategy and risk management objectives. Among the members of the Board, ECOVE has appointed an independent director with extensive expertise in accounting and taxation. These independent directors are not only independent from the Company's management, but also communicate directly with the certifying CPA on a regular basis to gain an in-depth understanding of the Company's tax cost structure, potential tax risks, and compliance with relevant regulations. Through their professional judgment and independent oversight, they effectively enhance the objectivity and rigor of tax governance, thereby creating long-term value for shareholders and all stakeholders. In addition, ECOVE maintains active and open communication with stakeholders, including government agencies, investors, and academia, through diverse channels. ECOVE responds to international tax initiatives and supports tax reform through concrete actions, working together with stakeholders to foster a sound tax environment.
 

Sustainable Economic Activities

ECOVE actively assesses and enhances the positive impact of its economic activities on the environment and society, based on the six environmental objectives defined in the "Guidance for Identifying Sustainable Economic Activities (Second Edition)." The Company achieves these objectives by introducing innovative technologies and optimizing processing procedures, continuously improving the sustainability of its economic activities.
 
In 2025, approximately 83.4% of the total revenue of ECOVE can be categorized as sustainable-related economic activities. Among these, general activities account for about 4.6% (including waste removal, waste treatment, and recycling), while supportive activities account for approximately 78.9% (including solar energy and waste-to-energy). Sustainable economic activities not only contribute to "mitigating climate change" and "circular economy" but also demonstrate the Company's concrete actions in implementing green energy transformation and low-carbon operations.
 

Industry Outlook

In 2025, ECOVE continues to integrate SDGs, deepens the domestic market, expands overseas presence, and strives for more project collaboration opportunities. In addition, in response to market trends toward sustainable energy and circular economy models, we are actively advancing the integrated application of technologies and optimizing operating models that enhance the eciency of resource circulation. Building on our core competencies and existing businesses, we will continue to expand our operating scale. Looking ahead, we will further deepen our presence in four key areas: "energy and resources," "circular reuse," "renewable energy," and "system facility development and maintenance," demonstrating to the world Taiwan's technological capabilities and strengths in the sustainable energy and circular economy industries.
 

Sustainable Solutions for Future Cities ―

The Application of Green Technologies from
Seawater Desalination to Carbon Capture

ECOVE strengthens the integration of its core capabilities with sustainable innovation. In response to major risks such as water resource risks caused by climate change, net-zero transition and regulatory trends, and compliance pressures related to industrial waste reduction and resource circulation, the Company has adopted "Group Integration" as its strategic focus. ECOVE works closely with its parent company, CTCI Corporation, leveraging CTCI's integrated EPC advantages, while combining its own expertise in long-term O&M, reuse processes, and energy management. Through green investments, ECOVE integrates engineering development with operational services to create sustainable solutions that are fee-based, replicable, and scalable, further driving stable operating income and expansion into new markets.