Internal control system of Jinyao Pharmaceutical Co., Ltd.
Chapter 1 General Provisions
Article 1 In order to strengthen the corporate governance and internal control of Jinyao Pharmaceutical Co., Ltd. (hereinafter referred to as the "Company"), safeguard the company's legitimate rights and interests, and ensure the realization of the company's business objectives, this system is formulated in accordance with the "Company Law of the People's Republic of China", "Basic Standards for Enterprise Internal Control", "Shanghai Stock Exchange Stock Listing Rules" and the "Articles of Association" and other relevant provisions, combined with the actual situation of the company.
Article 2 This system applies to the company and its wholly-owned and controlled enterprises.
Article 3 The goal of internal control is to reasonably ensure that the company's operations and management are legal and compliant, asset safety, financial reports and related information are true, accurate and complete, improve operating efficiency and effectiveness, and promote the company to achieve sustained, healthy and stable development.
Article 4 The main contents of the company’s internal control include internal environment, risk assessment, control activities, information and communication, internal supervision and information disclosure, etc.
Article 5 The company shall establish and improve internal control and follow the following basic principles:
(1) Principle of comprehensiveness. Internal control should run through the entire process of decision-making, implementation and supervision, covering various businesses and matters of the company and its affiliated enterprises.
(2) Principle of importance. Internal control should be based on comprehensive control and focus on important business matters and high-risk areas.
(3) Principle of checks and balances. Internal control should form mutual constraints and mutual supervision in terms of governance structure, institutional setup, distribution of rights and responsibilities, business processes, etc., while taking into account operational efficiency.
(4) Principle of adaptability. Internal control should be adapted to the enterprise's operating scale, business scope, competition status, risk level, etc., and should be adjusted in a timely manner as the situation changes.
(5) Cost-benefit principle. Internal control should weigh implementation costs and expected benefits to achieve effective control at an appropriate cost.
Article 6 The company's board of directors shall bear the ultimate responsibility for the establishment, improvement, effective implementation and evaluation results of the company's internal control system.
Article 7 The Audit and Risk Control Committee of the Board of Directors (hereinafter referred to as the "Audit and Risk Control Committee") is responsible for supervising the establishment and implementation of the internal control system, and supervising and evaluating the establishment, improvement and effective implementation of the company's internal control system. For major internal control deficiencies discovered, the company may be ordered to make rectifications.
Article 8 The company's management is responsible for the establishment and improvement of the internal control system-related systems in the business operations, responsible for promoting the implementation of the internal control system, and inspecting the formulation and implementation of various special internal control-related systems by the company's functional departments and units.
Chapter 2 Internal Control Environment
Article 9 The internal control environment mainly includes governance structure, institutional setup and distribution of rights and responsibilities, internal audit, human resources policies, corporate culture and other aspects.
Article 10 The company shall establish and improve a sound and standardized corporate governance structure and rules of procedure in accordance with relevant national laws and regulations and the Articles of Association, clarify the responsibilities and authorities in decision-making, execution, supervision, etc., and form a scientific and effective division of responsibilities and checks and balances mechanism:
(1) The shareholders' meeting is the highest authority and exercises voting rights on major matters such as the company's operating policies, financing, investment, and profit distribution in accordance with the law.
(2) The board of directors shall be responsible to the shareholders' meeting and exercise the company's operating decision-making power in accordance with the law.
(3) The Audit and Risk Control Committee is responsible to the Board of Directors and supervises the company’s directors and senior managers to perform their duties in accordance with the law.
(4) The management is responsible for organizing and implementing the resolutions of the shareholders’ meeting and the board of directors, and managing the company’s daily operations.
Article 11 The company shall set up internal institutions based on business characteristics and internal control requirements, clarify responsibilities and authorities, and assign rights and responsibilities to each responsible unit. By establishing and improving various internal control systems, the company enables employees to understand the internal organizational structure, job responsibilities, business processes, etc., clarify the distribution of rights and responsibilities, and correctly exercise their powers.
Article 12 The company should strengthen internal audit work and ensure the independence of the internal audit organization, staffing and work. The internal audit institution must combine internal audit supervision to supervise and inspect the establishment and implementation of internal controls. The internal audit institution shall report internal control deficiencies discovered during supervisory inspections in accordance with the company's internal audit procedures; it shall have the right to report major internal control deficiencies discovered during supervisory inspections directly to the Audit and Risk Control Committee.
Article 13 The company should formulate and implement human resources policies that are conducive to the company's sustainable development, and ensure the improvement of the company's internal incentive mechanism and supervision and restraint mechanism by formulating and implementing human resources management and other rules and regulations and management processes.
Article 14 The company regards professional ethics and professional competence as important criteria for selecting and hiring employees, strengthens employee training and continuing education, and continuously improves employee quality.
Article 15 The company should strengthen cultural construction, cultivate positive values and social responsibility, advocate honesty and trustworthiness, dedication to work, pioneering innovation and teamwork spirit, establish modern management concepts, and strengthen risk awareness. Directors and senior managers should try their best to play a leading role in the construction of company culture. The company requires employees to abide by the employee code of conduct and conscientiously perform their job responsibilities.
Article 16 The company will strengthen legal education, enhance the legal awareness of directors, senior managers and employees, and strictly make decisions, act in accordance with the law, and supervise in accordance with the law.
Chapter 3 Risk Assessment
Article 17 Risk assessment aims to help the company promptly identify and systematically analyze the internal and external risks related to the achievement of internal control objectives in business activities, determine the corresponding risk tolerance, and thereby reasonably determine risk response strategies.
Article 18 The company shall comprehensively, systematically and continuously collect internal information and external relevant information based on the set risk categories and control objectives, and conduct risk assessments in a timely manner based on the company's actual conditions.
Article 19 When a company identifies internal risks, it should pay attention to the following factors:
(1) Human resource factors such as the professional ethics of directors, general managers and other senior managers, and the professional competence of employees;
(2) Organizational structure, business methods, asset management, business processes and other management factors;
(3) Independent innovation factors such as research and development, technology investment, and application of information technology;
(4) Financial conditions, operating results, cash flow and other financial factors;
(5) Safety and environmental protection factors such as operational safety, employee health, and environmental protection;
(6) Other relevant internal risk factors.
Article 20 When identifying external risks, a company should pay attention to the following factors:
(1) Economic factors such as economic situation, industrial policy, financing environment, market competition, resource supply;
(2) Legal factors such as laws, regulations, and regulatory requirements;
(3) Social factors such as safety and stability, cultural traditions, social credit, education level, and consumer behavior;
(4) Scientific and technological factors such as technological progress and process improvement;
(5) Natural disasters, environmental conditions and other natural environmental factors;
(6) Other relevant external risk factors.
Article 21 The company shall use a combination of qualitative and quantitative methods to analyze and rank the identified risks based on the likelihood of risk occurrence and degree of impact, etc., and determine the focus of attention and the risks to be prioritized for control. In risk analysis, consider using professionals to participate in risk analysis.
Article 22 The company shall reasonably analyze and accurately grasp the risk preferences of directors, operating management, and employees in key positions, and adopt appropriate control measures to avoid significant losses to corporate operations due to personal risk preferences.
Article 23 Companies should comprehensively use risk response strategies such as risk avoidance, risk reduction, risk sharing and risk tolerance to achieve effective control of risks.
Article 24 Companies should continue to collect information related to risk changes based on different development stages and business expansion situations, conduct risk identification and risk analysis, and timely adjust risk response strategies.
Chapter 4 Control Activities
Article 25 Control activities include: department setup, job responsibilities, business regulations, business processes, etc. The control measures adopted include: separation of incompatible duties, authorization approval, property protection, accounting, financial management, budget control, operational analysis and performance appraisal, etc.
Article 26 The company's functional departments should clarify the work responsibilities of each department and formulate various business management rules and regulations based on the actual work content.
Article 27 The company's functional departments should implement corresponding separation measures for incompatible positions involved in business processes based on actual work needs, so as to form a working mechanism in which each performs its own duties, assumes its own responsibilities, and restricts each other.
Article 28 The company establishes authorization management and clarifies the scope of authority, approval procedures and corresponding responsibilities of each position for handling business and matters. Managers at all levels of the company should exercise their powers and assume responsibilities within the scope of authorization. The company shall implement collective decision-making and approval for major businesses and matters.
Article 29 The relevant regulations of the company's internal control system shall cover all aspects of business activities, including sales and collections, procurement and payment, inventory management, fixed assets management, monetary and fund management, guarantees and financing, investment management, R&D management, human resources management, etc. In addition to covering all aspects of business activities, the relevant systems of the company's internal control system should also include special management systems in various aspects, including seal use management, budget management, asset management, information system management and information disclosure management systems, etc.
Article 30 The company shall implement the national unified accounting standards system, formulate financial management systems and methods, clarify the job responsibilities of financial institutions and accounting personnel, strengthen the company's accounting work behavioral norms, and improve the quality of accounting work. Establish a strict accounting control system for operating risks to ensure the company's healthy operations.
Article 31 The company shall establish and implement a performance appraisal system, conduct regular appraisals and objective evaluations of the work of various functional departments and all employees within the enterprise, and use the appraisal results as the basis for implementing the reward and punishment mechanism.
Article 32 The company shall establish a daily property management system and a regular inventory system, and adopt measures such as property records, physical storage, regular inventory, and account verification to ensure the safety of property.
Article 33 The company shall gradually improve its ability to comprehensively apply control measures based on internal control objectives and risk response strategies, and implement effective control over various businesses and matters.
Article 34 The company establishes and gradually improves a major risk early warning mechanism and an emergency response mechanism for emergencies, clarifies risk early warning standards, and formulates emergency plans, identifies responsible personnel, and standardizes handling procedures for major risks or emergencies that may occur, so as to ensure that emergencies are handled promptly and properly.
Chapter 5 Information and Communication
Article 35 Information and communication control is divided into internal information communication control and public information disclosure control.
Article 36 The company shall establish an internal information and feedback mechanism, formulate an internal information management system and an internal reporting system for major information, promote internal information communication, improve work efficiency, enhance management transparency, and reduce operating risks.
Article 37 The company shall establish an intelligent office system, make full use of the company's e-mail, network, and internal publications to build an internal information communication platform.
Article 38 The company should strengthen the control over information system development and maintenance, access and changes, data input and output, file storage and custody, network security, etc., to ensure the safe and stable operation of the information system.
Article 39 The company shall strictly fulfill its external information disclosure obligations stipulated by the regulatory authorities, formulate an "Information Disclosure Management System", and disclose relevant information comprehensively, truthfully and timely in accordance with the law in accordance with the prescribed forms and channels.
Article 40 The company shall establish and gradually improve the anti-fraud mechanism, formulate the "Anti-Fraud System", adhere to the principle of equal emphasis on punishment and prevention, and focus on prevention, clarify the areas of anti-fraud work and the responsibilities and authority of relevant institutions in anti-fraud work, and standardize the reporting, investigation, handling and reporting procedures of fraud cases.
Article 41 The company shall clarify the procedures for handling reports and complaints to ensure that reports and complaints become an important way for the company to effectively grasp information. The company's employees have the right to report the deficiencies and problems existing in the company's internal control to the company's board of directors or internal audit institution at any time in the form of letters or emails, suggest improvement measures to address existing problems, and make suggestions for the next development direction of the company's internal control system.
Chapter 6 Internal Supervision and Information Disclosure
Article 42 Internal supervision is a process of supervising and inspecting the design and operation of the internal control system, evaluating its effectiveness, discovering internal control defects and making timely improvements. Internal supervision is divided into daily supervision and special supervision. Routine supervision refers to the company's regular and continuous supervision and inspection of the establishment and implementation of internal control; special supervision refers to the targeted supervision and inspection of one or certain aspects of internal control when there are major adjustments or changes in the company's development strategy, organizational structure, operating activities, business processes, etc.
Article 43 The company’s internal audit institution shall supervise and inspect the company’s business activities, risk management, internal control, financial information and other matters. Should maintain independence and be accountable to the Audit and Risk Control Committee. During the supervision and inspection process, the company shall accept the supervision and guidance of the Audit and Risk Control Committee. If any major problems or clues are discovered about the company, they should be reported directly to the Audit and Risk Control Committee immediately. The Audit and Risk Control Committee participates in the assessment of internal audit leaders.
Article 44 Unless otherwise provided by laws and regulations, the Audit and Risk Control Committee shall supervise the Audit Department to inspect the following matters at least once every six months, issue an inspection report and submit it to the Audit and Risk Control Committee. If the inspection finds that the company has any violations of laws or regulations, irregular operations, etc., it shall report to the Shanghai Stock Exchange in a timely manner:
(1) The implementation of major events such as the use of funds raised by the company, provision of guarantees, related transactions, securities investments and derivatives transactions, provision of financial assistance, purchase or sale of assets, external investments, etc.;
(2) The company’s large capital transactions and capital transactions with directors, senior managers, controlling shareholders, actual controllers and their related parties.
The Audit and Risk Control Committee shall issue written evaluation opinions on the effectiveness of the company's internal controls based on the internal audit report and relevant materials submitted by the internal audit institution, and report to the Board of Directors. If the board of directors or the audit and risk control committee believes that there are major flaws or major risks in the company's internal control, or if the sponsor or accounting firm points out that there are major flaws in the effectiveness of the company's internal control, the board of directors shall report to the Stock Exchange in a timely manner and disclose it.
Article 45 The company's board of directors shall regularly conduct self-evaluation on the effectiveness of internal control based on internal supervision and issue an internal control evaluation report. The method, scope, procedure and frequency of internal control self-evaluation shall be determined by the company based on business adjustments, changes in operating environment, business development status, actual risk levels, etc.
Article 46 The company's board of directors shall, in accordance with the requirements of the relevant regulatory authorities, formulate a resolution on the company's internal control assessment report while reviewing the annual financial report and other matters, and disclose it to the public at the same time as the annual report.
Article 47 The company should strictly investigate responsibilities and strengthen supervision and warning. Those who fail to perform the internal control system execution responsibilities as required, and who conceal, omit, misreport or delay reporting of major risks and internal control deficiencies will be resolutely held accountable and the internal control system management responsibilities will be implemented at all levels.
Article 48: The company’s internal audit institution shall comply with relevant file management regulations for the preservation of relevant materials such as inspections, evaluations, reports, etc. of the company’s internal control.
Chapter 7 Supplementary Provisions
Article 49 Matters not covered by this system shall be implemented in accordance with relevant national laws, regulations, departmental rules and the provisions of the Articles of Association. If this system is inconsistent with the relevant national laws, regulations, departmental rules and the "Articles of Association", the relevant national laws, regulations, departmental rules and the "Articles of Association" shall prevail.
Article 50 The company’s board of directors is responsible for revising and interpreting this system.
Article 51 This system shall come into effect from the date of review and approval by the company's board of directors.