Sustainable Governance

Sustainable Governance: Strategy & Goal
Short-term (1 year)
◆ Revenue and profit grow annually
◆ Ensure overall product competitiveness by technological innovation and IC cost reduction
◆ Maintain no significant fines (defined as a fine exceeding NT$1,000,000) arising from violations of laws or regulations
◆ Maintain a 100% execution rate for new employee training, including E-courses and advocacy courses on corporate governance and regulations
◆ Each functional department maintains responsibility of first-line risk management in daily work, conducting analysis, monitoring, and prevention of related risks to ensure the effective risk control mechanisms and procedures
◆ Report significant potential risks to the Company's operations or sustainable development to the Audit Committee and the Board on a regular basis, serving as the basis for effective risk management oversight
Medium- to long-term (2-10 years)
◆ Continuously expand the customer base and market sectors, and establish a forward-looking, swift product-sales response flexibility mechanism
◆ Explore new opportunities for new business and technological innovation
◆ Actively participate in domestic and international professional and technical organizations, jointly leading international industry trends, enhancing our market share and technological leadership
◆ Develop new customers, expand into new markets and marketing channels, deepen long-term partnerships, and expand market share through new product development
◆ Refer to the suggestions on corporate governance proposed by the competent authority, continuously improve the operation of the Board of Directors, and actively improve corporate governance evaluation results and improve information disclosure
◆ Establish a Risk Management Committee to strengthen the management of major risks
Sustainability Contribution in 2025
◆ The group's consolidated revenue for 2025 totaled NT$122.71 billion, an increase of 8.21% from 2024, while its net profit after tax was NT$14.75 billion
◆ Earnings Per Share (EPS): NT$28.77
◆ Cash dividend of NT$25.0 per share
◆ No material violations of economic, social, and environmental laws and regulations
◆ A total of 1,124 new employee attendances in advocacy courses on corporate governance and regulations (including E-courses), with a total of 1,517.9 instruction hours
◆ The Board of Directors and the Audit Committee provided one session of guidance and direction on risk management issues raised by the Risk Management Center, effectively implementing their responsibility for overseeing the corporate risk management
Board Governance Structure
Realtek considers organizational operations, industry business models, and long-term development needs when selecting board members based on basic qualifications, values, professional knowledge and skills (including expertise in environmental protection, social responsibility, corporate governance, and other aspects of corporate sustainability) to ensure a diversified composition of board members. The term of Realtek's directors is three years (the current term runs from May 30, 2024, to May 29, 2027). To enhance its oversight function and strengthen its management mechanism, the Board has established functional committees such as the Audit Committee, Remuneration Committee, Nominating Committee, and Sustainable Development Committee. All committee members are appointed by the Board.
The current (13th) Board is composed of 9 directors, including 1 female director and 3 independent directors. Their independence complies with the relevant provisions of the Regulations Governing Appointment of Independent Directors and Compliance Matters for Public Companies. The members of the Board have an average tenure of 12.5 years; 8 directors are over 50 years old and 1 director is between 30 and 50 years old, with an average age of 61.76. More than half of the members are also shareholders. Vice Chairman, Mr. Yung-Fang Huang, serves as the Chief Executive Officer (CEO), and Director Mr. Kuang-Yu Yen, acts as the President, steadily enhancing overall operational efficiency and decision-making execution. The specific management objective of Realtek's Board diversification policy focuses on 8 core competencies: operational judgment, accounting and financial analysis skills, business management skills, crisis handling skills, industry knowledge, international market outlook, leadership, and decision-making capability. For each competency, at least 5 directors must possess it, and each individual Board member must possess at least 4 of these 8 competencies. Currently, both the Board and its individual members meet the management objectives of the diversification policy. For the qualifications and competencies of individual Board members, please refer to page 5-6 of Realtek's 2025 Annual Report.
Board of Directors Functions
The Board of Directors diligently carries out corporate governance responsibilities by overseeing operational strategies of the Company′s management and evaluating business performance. At the same time, the Board listens to the strategic recommendations from the management team at the operating level and takes into account the viewpoints of stakeholders, providing professional and objective opinions with a high level of self-discipline and prudence to ensure the implementation of sustainable development. The Board is presided over and directed by Chairman Sun-Chien Chiu to strengthen corporate governance. It holds at least one meeting per quarter where each unit presents proposals to the Board on important topics such as corporate governance, economic, environmental, social, and risk management issues. In 2025, a total of 4 meetings were held, with an average attendance rate of 100% for Board members.
Board members of Realtek attended external continuing education courses in accordance with the Directions for the Implementation of Continuing Education for Directors and Supervisors of TWSE Listed and TPEx Listed Companies. Through continued learning, the Board members strengthen their professional competencies, keep abreast of evolving perspectives on corporate governance and sustainability, thereby reinforce corporate governance and promoting sustainable corporate development. In 2025, the themes of the Board's external training courses covered a range of professional topics, such as "Global Sustainability Regulatory Trends and Climate-related Disclosures," "2025 Taishin Net Zero Summit," "Business Intelligence & Data Analysis Approach," "Domestic and international development trends of carbon pricing mechanisms," "Sustainable supply strategies amid rising global risks," "Advanced Seminar on Anti-Money Laundering and Anti-Fraud Advocacy," "Corporate Governance Forum: ESG and Corporate Sustainable Operations," and "The future of AI and enterprise AI transformation." The directors collectively participated in these courses for a total of 33 hours.
Functional Committee
|
Audit Committee |
|
3 Independent directors 4 Meetings held in 2025 | Attendance rate 100% |
|
Authority and Responsibility To perform supervisory duties and exercise the powers specified by the Securities and Exchange Act, the Company Act, and other laws and regulations, including matters involving the personal interests of directors, material asset or derivative transactions, annual and semi-annual financial reports, and other important matters as specified by the Company or competent authorities. The Audit Committee meets regularly with the Company's certified public accountants, and reviews their appointment, independence, and performance. |
|
Remuneration Committee |
|
3 Independent directors 3 Meetings held in 2025 | Attendance rate 100% |
|
Authority and Responsibility To evaluate the linkage between the remuneration of directors and managers and the Company's business performance; to establish and periodically review the policies, systems, standards, and structures related to the achievement of the performance objectives and remuneration of directors and managers. The function of Remuneration Committee is to perform duties diligently with focus on sound management and then propose related recommendations to the Board for consideration. |
|
Nominating Committee |
|
3 Independent directors 3 Meetings held in 2025 | Attendance rate 100% |
|
Authority and Responsibility To establish the standards for the required professional knowledge, skills, experience, and gender diversity, as well as the independence of Board members, and based on these standards, to search for, review, and nominate director candidates; to construct and develop the organizational structure of the Board and its committees; to conduct performance evaluations for the Board, individual directors, and committees; and to establish and regularly review succession plans for directors and Top-level managers. |
| Sustainable Development Committee |
|
1 Independent directors, 2 Executive Directors 1 Meeting held in 2025 | Attendance rate 100% |
|
Authority and Responsibility To establish the standards for the required professional knowledge, skills, experience, and gender diversity, as well as the independence of Board members, and based on these standards, to search for, review, and nominate director candidates; to construct and develop the organizational structure of the Board and its committees; to conduct performance evaluations for the Board, individual directors, and committees; and to establish and regularly review succession plans for directors and Top-level managers. |
Board Performance Evaluation
The Board of Realtek conducts an internal performance evaluation for the year in December every year. The scope of evaluation covers the entire Board, individual Board members, and functional committees (including the Audit Committee, the Remuneration Committee, and the Nominating Committee; and it is planned to include the Sustainable Development Committee in the evaluation scope starting from 2026), and the evaluation is completed through internal self-evaluation of the Board and self-evaluation of Board members. The Nominating Committee acts as the executive unit in the evaluation process, collecting relevant information and implementing a scoring questionnaire. The evaluation results, along with specific explanations, are then compiled and reported to the Board of Directors to enhance corporate governance and achieve sustainable business operations. The performance evaluation results for the Board, Board members, and the three functional committees for the year 2025 were all rated "Excellent" and were reported to the Board on February 26, 2026. The performance evaluation results will serve as a reference for the remuneration and renomination of individual directors and members of the functional committees. For the performance evaluation results and dimensions, please refer to page 18 of Realtek's 2025 Annual Report.
- Board Performance Evaluation Aspect: Degree of Participation in Company Operations, Improving Board Decision Quality, Board Composition and Structure, Appointment and Continuing Education of Directors, Internal Control
- Board Member Performance Evaluation Aspect: Understanding of Company Goals and Missions, Understanding Board Responsibilities, Degree of Participation in Company Operations, Internal Relationship Management and Communication, Professionalism and Continuing Education of Directors, Internal Control
- Functional Committee Performance Evaluation Aspect: Degree of Participation in Company Operations, Understanding Functional Committee Responsibilities, Improving Functional Committee, Decision Quality Composition and Appointment of Members of Functional Committees, Internal Control
Remuneration Policies for Directors and Managers
The policy, standards, and structure of performance evaluation and salary compensation for Realtek's directors and managers are set and periodically reviewed by the Remuneration Committee, aiming for a balance between sustainable operation and risk control. The Remuneration Committee holds at least 2 meetings annually to discuss director compensation, manager compensation, manager salary adjustments, and manager bonuses.
The remuneration of directors and employees is carried out in accordance with the Company's Articles of Incorporation. That is, if the Company makes a profit in a year, no more than three percent should be set aside for directors' remuneration, and not less than one percent for employees' remuneration, of which no less than 0.5 percent of the annual profit shall be allocated as remuneration for rank-and-file employees. The remuneration of directors includes directors' remuneration and business execution expenses; the remuneration of managers includes salaries, bonuses, and retirement pensions, etc., which are regularly disclosed in the annual report each year. The remuneration of directors is formulated in reference to the results of the performance evaluation of the Board; the remuneration of managers is formulated in reference to performance evaluation indicators such as years of work and position, performance, contribution to company operations, industry level, and company profitability. The remuneration of directors and managers is approved by the Remuneration Committee in consideration of performance evaluation results, company performance, and future risks, and is proposed to the Board after resolution. After approval by the Board, it is implemented, and the remuneration of directors and employees is reported at the shareholders meeting.
To ensure that the decisions and actions of directors and managers align with the Company's overall ESG goals, the Remuneration Committee and the Board review and adjust remuneration policies continually in accordance with actual operations and relevant laws and regulations, and integrate ESG performance evaluation criteria as a basis for remuneration linkage. In practice, the Remuneration Committee regularly evaluates the ESG performance of directors and managers using various indicators, including green product innovation, carbon emission reduction, the proportion of renewable energy use, resource utilization efficiency, ecological protection, employee welfare, occupational health and safety, social philanthropy involvement, corporate governance, information security management, and risk management mechanisms. The results of these ESG performance evaluations are incorporated into the calculation of base salaries and bonus coefficients. The Board oversees the implementation of this policy, adjusting and optimizing it based on the Company's circumstances and sustainability goals. This incentivizes the board members and managers to remain committed to sustainable development, enhancing the Company's reputation and competitiveness while attracting ESG-focused investors and partners. Ultimately, this achieves a win-win outcome that balances economic benefits with social impact. For related information, please refer to pages 11-15 of Realtek's 2025 Annual Report.
- Performance Indicators Related to the Variable Compensation of the President
Variable compensation for Realtek′s president is determined based on performance indicators that reflect the company's financial status, operational efficiency, and strategic progress. Followings are the performance indicators relevant for our president′s variable compensation:
Variable compensation for Realtek′s President is determined based on performance indicators that reflect the Company's financial status, operational efficiency, and strategic progress. These indicators include:
♦ Financial Metrics (Weighting: 30% - 50%)
» Revenue Growth: Year-over-year or quarter-over-quarter growth in total revenue.
» Profit Margins: Metrics like gross margin, operating margin, and net profit margin.
» Earnings Per Share (EPS): Growth in EPS, which reflects profitability on a per-share basis.
» Return on Equity (ROE): Measures how effectively management is using shareholders’ equity to generate profit.
» Shareholder Return: The Dividends paid to shareholders.
» Free Cash Flow (FCF): Cash generated after capital expenditures, important for funding growth and returning value to shareholders.
» EBITDA: Earnings before interest, taxes, depreciation, and amortization, indicating operational profitability.
» Comparison to Peers: Comparison includes components of variable compensation and the above indicators of our peers.
♦ Operational Metrics (Weighting: 50% - 70%)
» Operational Efficiency: Measures like cost reductions, productivity improvements, and operational excellence.
» Market Share: Growth or maintenance of market share in the company's primary markets.
» Employee Engagement: Employee turnover rates, and other HR metrics.
» Innovation and R&D: Progress in new product development, patents filed, or new market entries.
» Supply Chain Efficiency: Measures like inventory turnover, supply chain costs, and lead times.
» Strategic Initiatives: Successful implementation of key strategic projects.
» Sustainability and ESG: Performance in environmental, social, and governance (ESG) criteria, including sustainability initiatives and corporate social responsibility.
» Regulatory Compliance: Maintaining compliance with relevant laws and regulations, avoiding fines, and ensuring ethical conduct.
» Corporate Culture and Leadership: Building and maintaining a strong corporate culture, effective leadership development, and succession planning.
- President Compensation structures in place to align with long-term performance
Compensation structures designed to align with long-term performance are crucial in ensuring that our President's interests are closely tied to the sustained success and growth of the company. The structures focus on long-term incentives and performance-based rewards that extend over three to five years. Followings are the components and strategies used to align our President’s compensation with long-term performance:
♦ Long-Term Incentive Plan (LTIP): The plan adopts performance periods of three to five years. Performance indicators cover financial measures such as revenue growth, profitability and return on shareholders′ equity. These measures are coupled with deferred payment mechanisms so that management decisions focus on long-term performance and sustainable value creation.
♦ Performance-Linked Bonus Program: Bonuses are granted based on the level of achievement over a specified performance period (usually three to five years) and are tied to the Company′s long-term strategic objectives, such as market expansion, major R&D milestones, or the advancement of ESG sustainability objectives.
♦ Retention Incentive Program: Designed to support key management personnel in their continued commitment to the Company′s long-term development and strategic execution.
♦ Clawback Provisions: In the event of failure to meet performance targets, misconduct, or financial restatement, the Company may, in accordance with applicable rules, reclaim awards that have already been granted, thereby strengthening accountability and governance transparency.
Operational Performance
Since i ts establishment, Realtek has maintained steady growth and profitability. Our corporate emblem, the crab, symbolizes unity and collaboration, in an environment that constantly demands innovation and change, we courageously embrace challenges and continuously invest in innovative R&D across various technologies and IC design fields. Our focus remains on enhancing product value and providing optimal solutions and services, firmly establishing ourselves among the world′s top ten IC design companies, securing the 7th position globally in 2025. Through the concerted efforts of all our employees, the Group′s consolidated annual revenue reached a record high of NT$122.71 billion, an 8.21% increase from the previous year.
- Economic Performance of Realtek Group′s Production and Distribution in the Past Three Years

Note:
- Dividends for the current year are distributed in the following year. For example, dividends for 2024 are distributed in 2025. Cash dividends do not include cash distributed from capital surplus.
- The financial data disclosed in this report has been audited by PwC and is publicly disclosed financial information. As of December 31, 2025, the tenure of the certified public accountants providing audit services to the Company is as follows: CPA Cheng, Ya-Huei, appointed on February 21, 2020, has provided audit services for 5.86 consecutive years; CPA Li, Tien-Yi, appointed on March 30, 2022, has provided audit services for 3.76 consecutive years.
- Financial data is rounded to two decimal places; therefore, slight discrepancies may occur in total values due to rounding.
- Payments to government (by country): As no fines arising from violations of laws and regulations have been incurred in past years, this item includes only income tax expenses.
![]() |
![]() |
Ethical Management
Ethical Corporate Management Policy

Realtek has established comprehensive internal management policies to ensure its operations comply with relevant laws and regulations. In 2025, the Group Tax Policy and Management Guidelines, Personal Data Security Maintenance Policy, and the Risk Management Methods and Procedures were newly established. Through the adjustments of these internal policies, the Company aims to enhance operational efficiency and risk management, safeguard the rights and interests of stakeholders, promote corporate culture and sustainable development, and ensure the Company's long-term, stable growth. For the detailed content of Realtek's key internal policies, please refer to the Corporate Governance section on the Realtek official website.
Realtek firmly believes that only by adhering to and implementing ethical conduct can sustainable business operations and win-win situations with customers be achieved. Realtek established important internal policies such as the Ethical Corporate Management Policy, Ethical Corporate Management Best Practice Principles, Procedures for Ethical Management and Guidelines for Conduct, Employee Code of Conduct, and Code of Ethical Conduct, all of which have been approved by the Board of Directors. From the Board to the management level, we actively implement the commitment to ethical management policy, strictly carry out ethical management practices in internal management and business activities, and require all employees to fully participate and comply. Information related to ethical management is disclosed on Realtek official website, providing management, employees, and stakeholders with understanding, ensuring the implementation of the Company's ethical management philosophy, preventing conflicts of interest, avoiding improper benefits and infringement of confidentiality, and maintaining fairness in competition and transactions. Article 10 of Realtek's “Ethical Corporate Management Best Practice Principles” clearly prohibits bribery and improper benefits. Realtek and its directors, managers, employees, mandataries, and Substantial Controllers may not, in the course of conducting business, directly or indirectly offer, promise, request, or accept any form of improper benefits from clients, agents, contractors, suppliers, public officials, or other stakeholders. Realtek's Board Meeting Rules stipulate that when a meeting item is related to the director's own interests, he/she should explain his/her interests and recuse himself/herself. If there is a risk of harm to the Company's interests, he/she may not participate in the discussion and vote and may not represent other directors in exercising voting rights. For the execution of director recusal, directors' positions in other companies, and shareholding status, please refer to pages 5-6 and 17 of Realtek's 2025 Annual Report. In 2025, Realtek was not involved in any legal proceedings related to violations of anti-competitive regulations.
Realtek has established the Procedures for Financial Transactions between Related Parties. It is used to strengthen the prevention of irregular transactions, improper benefit transfers in purchase and sale transactions between related parties, acquisition and disposal of assets, endorsements, guarantees, and loans. Furthermore, Realtek does not provide any contributions or expenditures to any political campaigns or organizations, lobbying groups, taxexempt entities, or other groups aimed at influencing political movements, public policies, and legislation. No political contributions were made in 2025.
- Whistleblowing and Disciplinary Measures
To implement Realtek's Code of Ethical Conduct and the concept of ethical management, and to encourage stakeholders to report any discovered violations of integrity and ethics, the Regulations Governing Realtek Internal (External) Personnel Whistleblowing on Illegal or Immoral Behaviors have been established. This includes the standard operating procedures for investigating reported items, subsequent measures to be taken after the investigation is completed, and related confidentiality mechanisms, to ensure that the reporting channel is unimpeded and the privacy of the whistleblower is protected. In 2025, Realtek received one whistleblowing letter. Based on the results of the investigation, this case was not related to issues of ethical management, and there were no instances of corruption or bribery at all operational locations.
Procedures for Handling Whistleblowing Cases

Fostering an Ethical Culture
Realtek continuously implements education, training, and promotional programs on ethical management and ethical conduct, including the new employee training camp and management seminars. Starting from 2026, ethical management and ethical conduct awareness and training courses will be regularly provided on an annual basis to all Realtek employees (including contractors). The courses include content covering the Company's ethical management policies, the employee code of conduct, and reporting mechanisms for unethical behavior. These efforts aim to raise employees' awareness of ethical management, effectively promote the Company's commitment to ethical management, and ensure its implementation in daily operations. In 2025, we provided training on ethical management totaling 357.8 hours, with a total of 1,588 attendances. Among the training courses, the total hours dedicated to Insider Trading Prevention training amounted to 47.33 hours, with 568 attendances attending the sessions. Every new employee joining Realtek is required to complete a mandatory ethics awareness course and must read and sign the Ethical Corporate Management Policy, Employee Code of Conduct, and Code of Ethical Conduct. In addition, in 2025, 100% of our key suppliers signed the Realtek Semiconductor Corp. Code of Conduct, which contains ethics and management system.

Internal Audits
The internal audit unit of Realtek is an independent operational unit under the Board of Directors. Internal audit officers shall regularly compile audit results and report regularly in Board meetings, and report to the chairman and president on an asneeded basis. Realtek's internal audit unit is staffed with dedicated audit personnel, including Audit Manager and Audit Specialists, who undergo continuing training annually to ensure their competence. Annual audits, which are carried out based on plans approved by the Board, shall ensure the effectiveness of self-evaluation and internal controls carried out by internal units and subsidiaries. Based on the selfevaluation reports, the audit unit issues a statement on internal control mechanisms to the Board and the Company president. Based on the audit results, a declaration of internal control was issued for 2025, confirming the design and implementation of internal control are effective and compliant with all laws and regulations.
Audit Unit Reporting Mailbox: audit@realtek.com
Compliance with Laws and Regulations
To ensure the Company's operations remain sound and in strict compliance with all applicable laws and regulations, Realtek has established a comprehensive risk control mechanism to prevent violations from having an adverse impact on its profitability and operations. The Company closely monitors changes in domestic and foreign policies and regulations, assesses their potential impact on its business or financial position, and assigns a dedicated Intellectual Property and Legal Department to provide professional legal advice and support to each business unit. In addition, the audit unit conducts regular annual audits of compliance with legal and regulatory requirements, and reports the audit findings and the status of follow-up improvements to the Audit Committee and the Board of Directors to fulfill their oversight responsibilities. In 2025, Realtek did not incur any significant fines or non-monetary sanctions resulting from violations of social, economic, or environmental laws and regulations.
Note: A major violation is defined as an incident penalized with a fine exceeding NTD 1,000,000.
Political Contributions and Other Expenses
Realtek does not provide any contributions or expenditures to any political campaigns or organizations, lobbying groups, tax-exempt entities, or other groups aimed at influencing political movements, public policies, and legislation. No political contributions were made in 2025.
Risk Management
Risk Management Policy

Risk Management Organizational Framework and Responsibilities
To effectively manage risks that could cause operational uncertainties for the Company, Realtek has established the Risk Management Policy and the Risk Management Methods and Procedures. The Board and the Audit Committee approved the amendments which define the Board of the Directors as the highest governance body, the Audit Committee is the highest supervisory body, with the Risk Management Center responsible for promoting and executing risk management. Furthermore, the independent internal audit unit under the Board is responsible for conducting internal audits to ensure the risk management system is consistently and effectively executed. Through our risk management procedures such as risk identification and clarification, contingency control, monitoring and prevention, and consolidated reporting, combined with preventive measures and systematic strategies, we aim to enhance stability and resilience in the face of risks, ensuring business continuity and sustainable development.
|
![]() |
Fostering a Risk Management Culture
Realtek recognizes that a robust risk management culture is a critical foundation for corporate sustainability and therefore incorporates “risk awareness” into corporate governance and daily operations. In addition to establishing comprehensive risk management systems and procedures, we continuously strengthen all employees′ awareness of and sensitivity to risks related to business operations, regulatory compliance, information security, and sustainability issues through systematic training and promotional activities.

Risk Assessment and Management
Realtek's risk management scope covers risks related to strategic planning, operational management, financial operations, and hazard events, while also incorporating climate change-related risks. We reference the Enterprise Risk Management (ERM) framework, through which the Risk Management Center implements a management process of risk identification, measurement, monitoring, response, reporting, and disclosure. Annually, based on the identification results of material sustainability issues, we conduct systematic risk assessments and identification to select key risk management topics, monitor potential risks, and implement preventive measures. This ensures Realtek's business continuity and mitigates the potential impact of these risks.
Based on the type of risk, Realtek's operational units implement corresponding risk management measures, and the Company promotes risk control and prevention across all employees. Each operational unit regularly submits information to the Risk Management Center to ensure the timely identification of significant potential risks that could affect operations or sustainable development. The Risk Management Center consolidates this information and reports to the Audit Committee at least once a year on the operation of risk management. The Audit Committee, in turn, reports at least annually to the Board on the operation and effectiveness of risk management, while an independent audit unit conducts internal audits, providing a basis for oversight and guidance. In 2025, the audit unit conducted an internal audit of risk management to ensure that the internal control system continues to be implemented effectively. On October 28 and 29, 2025, the Risk Management Center reported to the Audit Committee and the Board the Company′s risk appetite metrics, the results of the identification of material risk issues, and the implementation, operation, and outcomes of preventive measures regarding these material risk issues; the Audit Committee and the Board also held one oversight and guidance meeting on these material risk issues to strengthen relevant mechanisms and continuously optimize preventive measures, ensuring the Company's overall operational stability and sustainable development.
- Risk Management Procedures

- 2025 Realtek Material Risk Management Issues and Response Strategies


Information Security Management
To protect the information security of its employees, customers, investors, and partners, and to support the Company's vision of sustainable and steady operation and development, Realtek is committed to developing and continuously improving its information security strategies. This is to prevent risks such as theft, improper use, leakage, or destruction of information assets due to human negligence, deliberate actions, or natural disasters. Realtek has established an Information Security Risk Management Framework and continuously improves its risk management by strengthening governance strategies and personnel training, conducting assessments and reviews, and formulating supporting measures. This creates a solid, secure, and trustworthy digital environment for the Company, serving as a solid foundation for its sustainable operation. In 2025, no major information security incidents occurred, and there were no complaints from employees, suppliers, or customers due to violations of information security-related regulations.
Information Security Management: Strategy & Goal
Short-term (1 year)
◆ Continuously maintain the validity of our ISO 27001 and TISAX (Trusted Information Security Assessment Exchange) certification, as well as implement internal and external audits
◆ Conduct Email Social Engineering Drills 4 times per year, with attendance exceeding 15,000 attendances
◆ Hold more than 45 cybersecurity-related professional certifications
◆ Achieve an A rating for Cybersecurity Maturity in third-party risk assessments
Medium- to long-term (2-10 years)
◆ Integrate domestic and international information security standards and regulations with ISO 27001 to promote business and operational development within the Company
◆ Continuously enhance information security risk management
◆ Conduct Email Social Engineering Drills 4 times per year, with participations exceeding 25,000 attendances
◆ Hold more than 60 cybersecurity-related professional certifications
◆ Maintain an A rating for Cybersecurity Maturity in third-party risk assessments
Sustainability Contribution in 2025
◆ Completed the ISO 27001:2022 transition successfully and continuously maintains the Information Security Management System certification
◆ Achieved a 100% participation rate in information security training among new employees
◆Formulated the Realtek Supply Chain Information Security Management Policy and collaborated with supply chain partners to strengthen supply chain cybersecurity resilience
◆ Achieved an A rating for Cybersecurity Maturity in third-party risk assessments
Information Security Risk Management
To implement and enhance information security governance strategies and risk management, the Board of Directors of Realtek assumes ultimate oversight responsibility for information security and reviews the “Annual Information Security Report,” thereby keeping abreast of the Company′s information security risks and management performance through a regular reporting mechanism. Realtek established the Information Security Steering Committee, responsible for reviewing the establishment and execution of information security policies. The Information Security Steering Committee is chaired by the President, with first-tier managers from each unit serving as ex-officio members. The committee holds at least one meeting annually and reports the overall information security governance status to the Board.
In terms of management structure, Realtek has established the Corporate Security Center (Cyber Security Center, CSC), led by the Chief Information Security Officer (CISO). The CSC collaborates with dedicated units such as the Product Development Security Department, Industrial Network Security Department, IT/OT Security Department, and Security Education Team, to jointly build the Company′s information security defense system. Following international information security standards such as ISO 27001 information security management and TISAX automotive industry trusted information security assessment, the CSC coordinates the formulation and implementation of information security policies and all information security protection measures to ensure that information security management achieves the goals of confidentiality, integrity, and availability.
In 2025, the Cyber Security Center (CSC) submitted monthly reports to top-level management on the progress and effectiveness of information security initiatives (for a total of 12 briefings), conducted one review of policies and implementation performance through the Realtek Information Security Steering Committee, and delivered one report to the Board of Directors on the overall status of information security governance, in order to strengthen the Board′s oversight of information security risks and its decision‑making support.
- Cyber Security Risk Management Framework

Since Realtek is an IC design company, its business involves IC research and development, manufacturing, sales and offering of software and hardware applications and IP development for IC products. Through information technologies such as various communications equipment, instrumentation and information systems, it collaborates closely with the upstream and downstream partners of the industry chain, as well as customers, on product development and delivery. Realtek strengthens and maintains organizational information security by formulating the Information Security Risk Management Framework and implementing information security management mechanisms.
Realtek′s Information Security Risk Management Framework applies to all employees. The Company regularly promotes information security education, training, and responsibility awareness to strengthen information security awareness and execution capabilities, ensuring that all employees clearly understand their information security responsibilities. For third parties (including suppliers, outsourced manufacturers, and other partners), Realtek has established the Supply Chain Information Security Management Policy to protect the security of shared information and infrastructure. At the same time, Realtek continuously collects and analyzes the latest trends in cybersecurity risks, as well as domestic and international information security laws and regulations in order to formulate or revise relevant policies and management procedures. The Corporate Security Center (Cyber Security Center, CSC) performs the necessary information security-related operations each year to ensure the effective implementation of the Information Security Risk Management Framework and the continuous enhancement of the Company′s information security management measures.
As our operations expand and cyber threats grow more sophisticated, it is no longer possible to guarantee complete protection against serious cyber-attacks, even with multiple layers of defense. To address this, Realtek continuously and actively manages information security risks by assessing the materiality and significance of risks, and the corresponding improvement benefits to build a defense-in-depth mechanism. The Company follows the Plan-Do-Check-Act (PDCA) cycle to continuously strengthen its information security management system, supporting the requirements for business development, in order to reduce information security risks arising from human error or malicious attacks.
| Realtek introduced ISO 27001 and TISAX in 2023 and passed the ISO 27001:2022 transition certification in January 2025. For ISO 27001, Realtek will implement an internal audit and a third-party external audit annually; as for the TISAX assessment, the Company will conduct an internal audit once a year and a third-party external audit every three years to further enhance the reliability of the information security management system. | |
|
|
Privacy Protection
To ensure the privacy and personal data protection of customers, partners, and employees, and to establish standardized procedures for the collection, processing, and use of personal data, the Company has formulated a Privacy Policy, Personal Data Security Maintenance Policy, and Personal Data Management Procedures. These policies apply to all employees, suppliers, partners, and users of the Company's website. Management of privacy-related issues has been incorporated into the Company′s compliance management framework, under which it regularly assess regulatory compliance and conduct annual internal audits, risk assessments, customer-requested compliance audits, supply chain security audits, and other third‑party information security audits. In addition, a dedicated privacy protection mailbox (realtek_privacy@realtek.com) is available for stakeholders to report or provide feedback on privacy and personal data protection issues. In 2025, there were no privacy- or personal data-related reported incidents.
In 2025, Realtek strictly complied with personal data protection regulations. The personal data collected was used solely for its intended purpose and was not used for other purposes or secondary use. To ensure the effectiveness of its management measures, one customer personal data inventory and risk assessment was conducted in 2025, systematically reviewing security control points throughout the data lifecycle, and no high-risk issues were identified in the 2025 assessment. Leveraging this rigorous preventive framework and its effective implementation, the Company strengthened its personal data protection prevention mechanisms. Throughout the year, there were no personal data protection violations that resulted in penalties imposed by the competent authorities, and no complaints related to infringements of customer privacy rights were received, thereby safeguarding the security of customer information and their rights and interests.
- The 2025 quantitative data and management indicators related to personal data protection are as follows:
♦ Internal Management and Technical Protection: Conducted 1 customer personal data inventory and risk assessment operation.
♦ Incident Response and Risk Management: 0 incidents of violating the Personal Data Protection Act occurred.
Specific Management Plans and Resources Invested in Realtek Information Security Management
- Information Security Protection Measures
In the face of new and diverse external network attack threats, if protective measures are inadequate, they may lead to the interruption of the Company's critical information system services, the leakage or theft of sensitive information, and ultimately result in operational losses. Therefore, Realtek adopts a multi-layered defense-in-depth architecture and deploys mechanisms and systems such as firewall controls, antivirus software, endpoint detection and response (EDR), managed computers, personal account and password management, information system access rights management, and backup and redundancy for critical information, in order to strengthen access security for internal and external networks and block potential security threats. In addition, Realtek continuously remediates cybersecurity threats and vulnerabilities by performing regular vulnerability scans on critical information systems and collecting threat intelligence on malware and ransomware, converting such intelligence into defense policies to truly enhance its information security risk response capabilities. Building on this foundation, in order to further validate the effectiveness of defenses from an attacker′s perspective, Realtek also plans to introduce red team exercises. By simulating the mindset of real-world hackers, these exercises proactively identify potential blind spots in personnel, processes, and technologies, thereby effectively enhancing the organization′s overall cybersecurity defense capabilities.
In 2025, Realtek continued to implement the ISO 27001 Information Security Management System. Based on this framework, it established information security standards and supervisory mechanisms on this basis to rigorously review the formulation and implementation effectiveness of its information security policies. At the same time, through regular drills, testing, and audits, the Company continuously strengthened the effectiveness and resilience of its defense measures.
- Product Information and Cybersecurity Management
Realtek implements R&D network segmentation and process controls to ensure the proper use of core technologies. The Company also holds regular meetings to address known issues and prevent recurrences. These efforts achieve key objectives such as information protection, access control, contract compliance, data traceability, software quality, and software security, thereby preventing the leakage and improper use of product development intellectual property or sensitive information. In order to avoid product security vulnerabilities causing damage to customers and goodwill, if such incidents occur, Realtek follows the Company's information security reporting process to initiate vulnerability correction and response procedures and report to superiors. Through rigorous information security risk response measures, Realtek is able to strengthen trust and partnerships with stakeholders and advance long-term sustainable development.
To further enhance product security, in 2025 Realtek committed to strengthening employees′ secure development capabilities by regularly organizing product security training programs. During the development process, the Company continuously optimized vulnerability scanning, penetration testing, and patching mechanisms, and introduced product threat modeling analysis. At the same time, by implementing product sign-in and sign-off procedures alongside a product vulnerability disclosure and reward program, Realtek comprehensively enhanced product quality and security.
- Strengthened Staff's Awareness and Capabilities of Information Security
To enhance employees′ vigilance and information security awareness, and to ensure compliance with information security policies, Realtek regularly conducts information security training and specialized training programs. These courses cover topics such as Company-Wide information Security Awareness, Email Social Engineering Drills, and Protection of Trade Secrets, thereby fostering a culture in which employees actively participate in information security defense and enabling every employee to serve as the first line of defense in safeguarding the Company′s assets.
In information security governance, employee awareness is a critical factor. Accordingly, in 2025 Realtek continued to conduct social engineering drills quarterly. Through ongoing simulations, the Company aimed to gradually strengthen employees′ vigilance in identifying malicious emails and their ability to respond appropriately. The drill results served not only as objective indicators for evaluating effectiveness, but also as an important basis for optimizing the content of future training programs.
Drill Participation (Number of Attendances) by Quarter in 2025

- Supply Chain Information and Cybersecurity Management
Realtek attaches great importance to supply chain information security and privacy protection. In 2025, the Company revised the Realtek Supplier Code of Conduct to incorporate new requirements related to information security management and privacy protection, and formulated the Supply Chain Information Security Management Policy to clarify the principles and management requirements that suppliers shall follow in the areas of information security and data protection. Through these measures, Realtek works hand in hand with its supply chain partners to strengthen the overall information security resilience of the supply chain.
To ensure effective implementation of cybersecurity management across the supply chain, Realtek has introduced an information security assessment mechanism for key suppliers. Using information security questionnaires for quantitative evaluation, supplemented as needed by on-site audits for verification, Realtek gains a comprehensive understanding of suppliers' management measures and capabilities in information security governance, system protection, and data protection. This mechanism helps ensure the security of Realtek's data, systems, and customer information, reduces potential information security risks arising from supply chain collaboration, thereby reinforcing the foundation of mutual trust and promoting long-term, stable cooperative relationships.
The 2025 assessment results revealed that nine key supply chain partners had established comprehensive information security management mechanisms, and the overall maturity of their information security management was robust. Through ongoing assessment and communication, Realtek was able to promptly identify supply chain information security risks and drive corrective actions, thereby further enhancing the overall information security management capabilities and operational resilience of the supply chain.
2025 Information Security Measures Implementation Results

Summary of Realtek′s Information Security Incidents over the Past Three Years







