/Jiuqiang Biotech: Risk Management System
NEWS

Jiuqiang Biotech: Risk Management System

Shenzhen Stock Exchange
2025/10/29

Beijing Jiuqiang Biotechnology Co., Ltd.

risk management system

Chapter 1 General Principles

Article 1 In order to standardize the risk management of Beijing Jiuqiang Biotechnology Co., Ltd. (hereinafter referred to as the "Company"), establish a standardized and effective risk control system, improve the company's risk prevention capabilities, promote the company's continued and stable operation, and improve the level of operation and management, this system is formulated in accordance with the laws, regulations and other provisions and requirements of listed companies and in combination with the company's actual situation.

Article 2 This system applies to the company and its wholly-owned and controlled subsidiaries.

Article 3 The risks referred to in this system refer to the impact of future uncertainty on the company's achievement of business objectives, which are specifically divided into strategic risks, financial risks, market risks, operational risks and legal risks, etc.

Article 4 Risk management refers to the process and method by which a company focuses on its strategic goals and business objectives, implements basic procedures for risk management in all aspects of daily business management and operations, cultivates a good risk management culture, establishes and improves a risk management system, and provides reasonable guarantees for achieving the overall goal of risk management.

Article 5 Overall Objectives of Risk Management

(1) Ensure that risks are controlled within a range that is compatible with business objectives and tolerable;

(2) Ensure true and reliable information communication inside and outside the company;

(3) Ensure compliance with relevant laws and regulations;

(4) Ensure the implementation of the company’s relevant rules and regulations and major measures taken to achieve business goals, ensure the effectiveness of business management, improve the efficiency and effectiveness of business activities, and reduce the uncertainty of achieving business goals;

(5) Establish a risk response and crisis management mechanism for various major risks to protect the company from major losses due to catastrophic risks or human errors.

Article 6 The basic principles of risk management include:

(1) Strategic orientation principle: Risk management work should be oriented by the company's development strategy, proceed from strategic goals, and serve to achieve strategic goals;

(2) Compliance principle: Risk management must comply with national laws and regulations and the requirements and regulations of the board of directors, shareholders' meeting and company articles of association;

(3) Principle of materiality: Risk management should focus on key points on a comprehensive basis, and adopt strict control measures for important businesses and matters, high-risk areas and links, and control risks at an acceptable level;

(4) Principle of adaptability: Risk management should be consistent with the company’s business characteristics and operating model, and be able to effectively achieve risk control objectives;

(5) Cost-benefit principle: Risk management should not only effectively control risks, but also reasonably weigh the relationship between costs and benefits, and strive to achieve effective risk control at a smaller cost;

(6) Principle of prevention and control: Risk management should be promoted to the front end of daily management work, and the prior prevention and overall management of risks should be strengthened.

Chapter 2 Risk Management Organizational System and Division of Responsibilities

Article 7 The risk management organizational system includes:

The board of directors, management, audit committee, audit department, compliance department and various functional departments of the company. The company has established three lines of defense for its risk management system. Among them, the company's functional departments serve as the first line of defense for risk management, the most basic and critical line of defense in the risk management system, and the first person responsible for risk management. Compliance departments such as finance and legal affairs serve as the second line of defense for risk management. The board of directors, audit committee and audit department are the third line of defense for risk management.

Article 8 Division of Responsibilities of Risk Management Organization

(1) The board of directors is the highest decision-making body for the company's risk management work and is responsible to the shareholders' meeting for the effectiveness of risk management work. Its main responsibilities are as follows:

  1. Determine the company's overall risk management objectives, risk appetite, and risk tolerance, and approve the company's major risk management strategies and major risk management solutions;

  2. Responsible for supervising the design, implementation and supervision of the company's risk management mechanism and evaluating its effectiveness;

  3. Supervise the cultivation of corporate risk management culture.

(2) The management (general manager’s office) is responsible to the board of directors for the effectiveness of the company’s risk management work. The general manager or senior managers entrusted by the general manager are responsible for presiding over the daily work of risk management. Its main responsibilities are as follows:

  1. Formulate the company's overall risk management objectives, risk preferences, risk tolerance and risk management strategies;

  2. Supervise the company’s operations and business risk control and management;

  3. Regularly report the company’s risk management status to the board of directors;

  4. Handle other important matters related to risk management required by the board of directors.

(3) Each functional department of the company serves as the first line of defense, and the person in charge of each functional department is the first person responsible for risk management. The main responsibilities are as follows:

  1. Responsible for formulating and implementing risk management strategies and coordinating daily work of risk management;

  2. Responsible for researching and making recommendations on the judgment standards or mechanisms for major decisions, major risks, major events and important business processes related to the scope of responsibility;

  3. Organize risk assessments on major events and important business processes within the scope of responsibility, and propose risk response strategies and internal control optimization suggestions;

  4. Establish and improve early warning, reporting mechanisms and emergency plans for major risks related to the scope of responsibility;

  5. Complete other important tasks of risk management.

(4) The main responsibilities of the compliance department in terms of risk control are as follows:

As the second line of defense, financial, legal and other compliance departments are responsible for judging and checking the authenticity, completeness and accuracy of transactions from a control perspective, further judging compliance and rationality, and further strengthening risk control.

(5) The main responsibilities of the Audit Committee and the Audit Department in terms of risk control are as follows:

As the third line of defense, internal audit provides independent supervision of the company's management systems, processes, and various risk control procedures and activities.

Chapter 3 Contents of Risk Management

Article 9 The basic process of risk management includes:

(1) Collect risk information;

(2) Identify risks and conduct preliminary risk inspections;

(3) Conduct risk assessment and formulate risk management strategies;

(4) Propose and implement risk solutions

(5) Risk report;

(6) Supervise and improve risk management.

Section 1 Information Collection

Article 10 Risk information collection means that the company's functional departments comprehensively, systematically and continuously collect internal and external information that may affect business objectives based on the actual work carried out. The specific contents are as follows:

(1) In daily work, each department of the company collects and organizes internal and external information related to risks of the unit according to their respective businesses, including historical data and future forecast data, and organizes and records them;

(2) Regularly analyze the internal and external risk environment and prepare relevant reports or suggestions.

Section 2 Risk Identification

Article 11 Risk identification means that each functional department should timely identify factors that may hinder the realization of the company's goals, hinder the company's creation of value, or erode existing value based on the risk information collected. Risk identification includes internal risk identification and external risk identification.

(1) When companies identify internal risks, they should pay attention to the following factors:

  1. Human resource factors such as the professional ethics of directors, senior managers and other managers, and the professional competence of employees;

  2. Management factors such as organizational structure, operating methods, asset management, and business processes;

  3. Independent innovation factors such as research and development, technology investment, and information technology application;

  4. Financial conditions, operating results, cash flow and other financial factors;

  5. Safety and environmental factors such as operational safety, employee health, and environmental protection;

  6. Other related internal risk factors.

(2) When companies identify external risks, they should pay attention to the following factors:

  1. Global and domestic economic conditions, industrial policies, financing environment, market competition, resource supply and other economic factors;

  2. Legal factors such as laws, regulations, departmental rules, normative documents, and securities regulatory requirements;

  3. Social factors such as safety and stability, cultural traditions, social credit, education level, and consumer behavior; 4. Scientific and technological factors such as scientific and technological progress, technological innovation, and process improvement;

  4. Market demand for products or services in this industry;

  5. Natural environmental factors such as natural disasters and environmental conditions;

  6. Other relevant external risk factors.

Article 12 Companies may identify risks through questionnaire surveys, group discussions, expert consultation, scenario analysis, policy analysis, industry benchmark comparisons, interviews and other methods.

Section 3 Risk Assessment

Article 13 Risk assessment means that the company shall analyze and rank the identified risks based on the degree of risk impact and possibility of occurrence, and determine the risks that should be focused on and prioritized for control.

Article 14 Risk analysis methods generally adopt qualitative and quantitative methods.

Qualitative analysis can be used when quantitative analysis is not suitable for risk analysis, or when sufficiently credible data required for quantitative analysis cannot be obtained, or the acquisition cost is high.

Article 15 A company's risk analysis shall fully recruit professionals, form a risk analysis team, and carry out work in accordance with strict and standardized procedures to ensure the accuracy of risk analysis results.

Article 16 The company divides risks into "major risks", "important risks" and "general risks". The company's judgment on the importance of risks is mainly determined based on the possibility of risk occurrence and the degree of impact.

(1) Possibility of risk occurrence:

When the probability of risk occurrence is >0% but ≤5%, it is considered “extremely unlikely” to occur;

When the probability of risk occurrence is >5% but ≤50%, it is considered "possible";

When the probability of risk occurrence is >50% but ≤95%, it is considered "very likely" to occur;

When the probability of risk occurrence is >95%, it is “basically certain” to occur.

(2) Degree of risk impact:

  1. If the possibility of a risk occurring is "extremely unlikely", then the risk does not need to be considered;

  2. If the possibility of a risk occurring is "possible" and the impact of the risk is small, then this type of risk should be determined as a "general risk" and requires necessary attention and control;

  3. If the possibility of a risk occurring is "very likely" and the impact of the risk is relatively large, then this type of risk should be determined as an "important risk";

  4. If the possibility of a risk occurring is "basically certain" and the impact of the risk is large, then the risk should be identified as a "major risk" and needs to be focused on and prioritized for control.

Article 17 Formulating a risk management strategy means that the company weighs the risks and benefits based on the risk assessment results, combined with the causes and tolerance of the risks, and selects appropriate risk response strategies such as risk taking, risk avoidance, risk sharing, and risk reduction. Among them:

(1) Risk taking: The company is not prepared to take any control measures to reduce risks or mitigate losses after weighing the cost-benefit for risks that are within the risk acceptance level.

(2) Risk avoidance: For risks that exceed the risk acceptance level, the company avoids and mitigates losses by adapting, abandoning or stopping business activities related to the risk.

(3) Risk sharing: The company is prepared to use the power of others to adopt methods including business subcontracting, purchasing insurance, obtaining guarantees (mortgages) and appropriate control measures to control risks within the company's risk acceptance level.

(4) Risk reduction: After weighing the cost-benefit, the company is prepared to take appropriate control measures to reduce risks or mitigate losses, and control risks within the company's risk acceptance level.

Article 18 When determining specific risk response plans, each functional department of the company should consider the following factors:

(1) The impact of the risk response plan on the possibility of risk occurrence and risk impact, and whether the risk response plan is consistent with the company's risk tolerance;

(2) Comparison of costs and expected benefits of risk response plans;

(3) Compare possible opportunities in risk response plans with related risks;

(4) Fully consider the combination of multiple risk response plans;

(5) Reasonably analyze and accurately grasp the risk preferences of directors, senior managers, and employees in key positions, and adopt appropriate control measures to avoid significant losses to the company's operations due to personal risk preferences.

Article 19 The company should regularly summarize and analyze the effectiveness and rationality of the established risk management strategies, continuously collect information related to risk changes based on the company's different development stages and business expansion, conduct risk identification and analysis, and timely adjust risk management strategies.

Section 4 Risk Response

Article 20 Risk response is to formulate and implement specific control measures for various risks based on risk assessment results and risk management strategies. Based on the principles of consistency between business strategy and risk strategy, and balancing risk control with operational efficiency and effectiveness, internal control measures for risk resolution are formulated. The company develops reasonable and effective internal control measures, including the following:

(1) Separation control of incompatible duties

The company should comprehensively and systematically analyze and sort out the incompatible positions involved in the business process, implement corresponding separation measures, and form a working mechanism in which each person performs his or her duties, takes responsibility, and restricts each other.

(2) Authorization approval control

  1. According to the authorization regulations, the company clarifies the scope of authority, approval procedures and corresponding responsibilities of each position to handle business and matters. Managers at all levels of the company should exercise their powers and assume responsibilities within the scope of authorization.

  2. The company shall implement a collective decision-making approval or joint signature system for major businesses and matters. No individual may make decisions alone or change collective decisions without authorization.

(3) Accounting system control

  1. Companies should strictly implement the national unified accounting standards system, strengthen basic accounting work, clarify the processing procedures for accounting vouchers, accounting books and financial accounting reports, and ensure the authenticity and completeness of accounting information.

  2. The company shall set up an accounting institution in accordance with the law and staff it with accounting practitioners with corresponding qualifications.

(4) Property protection and control

  1. The company should establish a daily property management system and a regular inventory system, and take measures such as property records, physical storage, regular inventory, and account verification to ensure the safety of property.

  2. The company should strictly restrict access to and disposal of property by unauthorized personnel.

(5) Budget control

The company should implement comprehensive budget management, clarify the responsibilities and authority of each responsible unit in budget management, standardize the preparation, approval, release and execution procedures of budget, and strengthen budget constraints;

(6) Operation analysis and control

When a company establishes an operation analysis mechanism, it should comprehensively use information from research and development, production, purchase and sale, investment, financing, finance and other aspects, and conduct regular operation analysis through factor analysis, comparative analysis, trend analysis and other methods, discover existing problems, identify the causes in a timely manner and make improvements.

(7) Performance evaluation control

The company should establish and implement a performance appraisal system, scientifically set up an appraisal indicator system, conduct regular appraisals and objective evaluations of the performance of each responsible unit and all employees within the company, and use the appraisal results as the basis for determining employee salaries and job promotion, evaluation, demotion, transfer, dismissal, etc.

(8) Establish major risk early warning and emergency response mechanisms

In response to possible major risks or emergencies, the company formulates emergency plans, identifies responsible personnel, and standardizes handling procedures to ensure that emergencies are handled promptly and properly.

(9) Establish and improve the company’s legal advisory mechanism

  1. The company should strengthen the construction of legal risk prevention mechanisms and form a legal risk responsibility system that is led by the company's decision-makers, led by the company's legal department, with the company's legal advisers providing business guarantees, and with the participation of all employees.

  2. The company should improve the filing management system for major legal disputes.

Article 21 Risk monitoring and early warning refers to the overall evaluation of the effectiveness of the design and implementation of risk response strategies and management measures, and the proposing of improvement suggestions. All departments of the company conduct continuous daily monitoring of the major risks and related risks they manage, and report potential major risk changes to the management in a timely manner. When carrying out risk monitoring, continuous attention needs to be paid to the following risk information:

(1) Changes in key risk indicators;

(2) New risks or major changes in original risks;

(3) The implementation and effectiveness of the risk response plan.

Section 5 Risk Report

Article 22 Risk reporting means that each department of the company should conduct continuous daily monitoring of major risks and important risks that occur in its business and promptly report to the company's management, actively take preventive measures, and submit the implementation results to the company's management in a timely manner.

Section 6 Supervision and Improvement

Article 23 Each department of the company should establish information communication channels connecting superiors and subordinates and cross-departments according to their own functions and businesses to ensure timely, accurate and complete information communication and lay the foundation for risk management supervision and improvement.

Article 24 Each department of the company should conduct self-examination and inspection of its business-related risk management work, promptly discover defects and make improvements, and its inspection and inspection reports should be reported to the company's management in a timely manner.

Article 25 The company's audit department is the supervisory department of risk management. It is responsible for providing independent and objective confirmation and consultation on the appropriateness and effectiveness of organizational governance and risk management work, evaluating and improving the effects of risk management, control and governance processes, and promoting and assisting enterprises to achieve sustainable progress.

Article 26 The company shall regularly conduct self-evaluation of the effectiveness of internal control based on the internal supervision situation and issue an internal control self-evaluation report.

Chapter 4 Construction of Risk Management Guarantee System

Article 27 The company should integrate risk management with corporate operation and management, and implement risk management requirements into various internal management systems and processes based on risk assessment results and risk management needs.

Article 28 The company should apply information technology to all aspects of risk management, establish a risk management information system covering the basic risk management process and all aspects of the internal control system, and continuously improve the methods and approaches for company operation and management process supervision, so that information can be monitored, behavior can be traced, and faults can be traced.

Article 29 The company should establish a risk-aware corporate culture, promote the improvement of the company's risk management level and the risk management quality of its employees, integrate the construction of risk management culture into the entire process of company culture construction, transform risk management awareness into employees' common understanding and conscious actions, promote the company's establishment of a systematic, standardized and efficient risk management mechanism, and ensure the realization of the company's risk management goals.

Article 30 The company should vigorously strengthen the legal literacy education of employees, formulate employee ethics and integrity guidelines, and form a risk management culture in which everyone respects ethics and integrity and operates in compliance with laws and regulations. The company should seriously investigate and deal with violations of laws and ethics such as non-compliance with national laws and regulations and company rules and regulations, fraud, malpractice for personal gain, etc.

Article 31 All employees of the company, especially managers at all levels and business operators, should strive to spread the company's risk management culture through various forms, and firmly establish the awareness and concepts that risks are everywhere, risks are present at all times, pure risks are strictly prevented and controlled, opportunity risks are prudently handled, and job risk management responsibilities are of great responsibility.

Chapter 5 Supplementary Provisions

Article 32 Matters not covered by this system shall be implemented in accordance with relevant laws, regulations, normative documents, the listing rules of the Shenzhen Stock Exchange and the relevant provisions of the Articles of Association.

Article 33 This system shall take effect and be implemented from the date of review and approval by the board of directors.

Article 34 The Board of Directors is responsible for the interpretation and revision of this system.