
Korea Circuit adheres to the Code of Conduct of the Responsible Business Alliance (RBA), a global responsible business initiative, as a fundamental principle of practicing ESG management. Based on this, we have established the "Korea Circuit Code of Conduct," which contains responsible management standards in areas such as labor, health and safety, environment, ethics, and management systems, enabling employees to implement the relevant principles in their work. In addition, we have independently established the "Korea Circuit Supplier Code of Conduct" to expand the scope of ESG management practices across the entire supply chain. Through this, we provide standards and directions for responsible management activities that suppliers must comply with, and we strive to internalize ESG principles throughout the supply chain with continuous communication and inspections.
In the first half of 2025, at the request of our clients, we conducted a Customer Managed Audit (CMA) based on the RBA VAP (Validated Assessment Program) standards, assessing the operational levels across labor, health and safety, environment, ethics, and supply chain management systems. Korea Circuit is continuously improving on identified areas from the audit and enhancing our management system. We plan to conduct the RBA’s official evaluation program, VAP, from the second half of 2026 to the first half of 2027. Through this, we aim to objectively verify the operational level of our ESG management system according to global standards and transparently present Korea Circuit’s commitment and performance in responsible management to stakeholders.
Korea Circuit identifies risks based on the RBA Code of Conduct to effectively respond to environmental changes occurring internally and externally. We plan to operate an enterprise-wide risk management system alongside the following management processes for impact analysis and response planning. The risk management areas are categorized into finance, human resources, health and safety, environment, quality, customer response, manufacturing, technology (intellectual property), and information systems (IT). We establish and manage specific criteria reflecting the characteristics of each area and conduct evaluations accordingly.
Korea Circuit safeguards key technical, managerial, customer, and employee-related information assets and complies with relevant laws and internal and external security requirements through the establishment and operation of a company-wide information protection system. To achieve this, we establish related policies and guidelines based on information protection governance, implementing administrative, technical, and physical protection measures across all areas of information protection, such as access rights and system security, data protection and business continuity, and response to security incidents. Additionally, we continuously improve and check these measures to proactively prevent security threats and enhance our level of information protection and response capabilities.
Korea Circuit operates information protection governance to securely protect key information assets and systems and to systematically respond to information security risks. The Chief Information Security Officer (CISO), who is the head of the IT division, oversees the overall information protection policies and directions and manages and supervises related tasks. The dedicated information protection team carries out comprehensive tasks related to information protection based on policies and guidelines, including account and access management, server and network security, data backup and recovery, asset management, and security incident response. Furthermore, the team continuously monitors the operational status of key systems and security infrastructure, and in the event of a security incident, minimizes damage by implementing pre-established procedures for initial response, root cause analysis, recovery, and recurrence prevention.

Korea Circuit operates a company-wide information security management system to protect key technologies, management information, and important information related to customers and employees. We establish policies and guidelines for overall information security, including servers, networks, data backup, user accounts, IT equipment, and security incident response. These guidelines are continuously reviewed and revised to address changes in the IT environment and security threats. Additionally, we regularly inspect the operational status of major information systems and physical security facilities, reporting on management outcomes to identify and mitigate security vulnerabilities in advance. Employees and in-house partner employees commit to protecting important information, such as trade secrets, upon joining. Contracts with vendors also include obligations to protect trade secrets and intellectual property rights, extending the scope of information protection to external stakeholders. We conduct regular training on personal information protection and cybersecurity for all employees and in-house partner staff, monitoring training completion and the implementation of internal standards.
Korea Circuit systematically manages user accounts and access rights to prevent unauthorized access and external leaks of important information. Access rights to information systems are granted differentially based on employees' roles and responsibilities. When reasons for changing permissions, such as job changes or retirement, arise, accounts and permissions are promptly adjusted or revoked to minimize unnecessary information access. We utilize information security systems such as ECM (K-DOC), NDLP, and DB-i to control the storage, output, screen capture, external dissemination, and database access of documents and data. Prior approval procedures are applied for external dissemination of important documents, and the validity period of security URLs and download limits are set to ensure safe management after dissemination. Firewalls and access control policies are implemented in server and network zones, with continuous checks on security settings and operational status to counter external intrusions and unauthorized access risks.
Korea Circuit operates a systematic backup and recovery system to prevent data loss due to system failures, disasters, and security threats, ensuring the continuity of essential business operations. Backup targets and schedules are set based on the importance and operational characteristics of major information systems and business data, with ongoing checks on backup results and storage status to manage data security and availability. Backup data is securely stored separately from the original data, and in the event of a system failure or data corruption, is managed to allow for rapid recovery following pre-established procedures. Procedures for device failure and system downtime, including reception, cause identification, repair, and normalization processes, are in place to minimize the scope and duration of business interruptions.
Korea Circuit has established and operates security incident response procedures to promptly and systematically handle various incidents such as information leaks, system breaches, malware infections, and service disruptions. A reporting system enables employees to immediately report security incidents or signs of anomalies to the responsible organization, and reported incidents are swiftly addressed according to type and impact scope. In case of a security incident, initial actions such as system isolation and access blocking are taken to prevent damage escalation, with analysis of causes and impact scope to facilitate data and system recovery and normalization. Incident outcomes and causes are shared with relevant organizations, and measures to improve security weaknesses and management processes are established and implemented to minimize the recurrence of similar incidents.

Korea Circuit operates a quality management system based on global standards such as ISO 9001 (Quality Management System), IATF 16949 (Automotive Quality Management System), VDA 6.3 (German Automotive Industry Association Quality Audit Standard), and SQ Certification (Supplier Quality Certification System) to strengthen quality management. We continuously acquire and maintain qualifications for each certification and actively support training courses for employees to become auditors for internal quality risk management. Additionally, we make organizational investments to enhance capabilities in responding to quality risks.
Korea Circuit operates an internal accounting management system to enhance the transparency of financial information and provide reliable information to external stakeholders. We comply with relevant laws and regulations, such as the Act on External Audit of Stock Companies and its enforcement decree, and operate based on internal accounting management regulations and guidelines. A dedicated team leads inspections and management of the internal accounting management system, conducting design and operational evaluations and reporting the results to the audit committee, board of directors, and shareholders' meeting. Issues identified during evaluations are continuously improved through collaboration among auditors, the dedicated team, and field personnel. We strive to establish a stable management environment and effective internal accounting risk management, maintaining a transparent and robust financial management system to provide highly reliable information.
Korea Circuit strictly adheres to tax laws as a fundamental principle, handling all tax-related matters accordingly. We continuously monitor the latest tax law information and respond swiftly to legal changes. We actively support external training to enhance our employees' tax skills, encouraging systematic acquisition of tax-related knowledge. For important issues where tax interpretation is unclear, we engage professional external tax advisors to receive objective and expert advice, identifying and preventing potential tax risks beforehand. Through these multifaceted efforts, we minimize tax risks, achieve stable financial operations, and realize transparent management. We will continue to focus on tax risk management by complying with laws, enhancing internal capabilities, and collaborating with external experts.
Korea Circuit transparently discloses key management information to domestic stakeholders through the Financial Supervisory Service's Electronic Disclosure System (DART). To enhance information accessibility for global stakeholders, we also post business and audit reports on the company's global website. This supports various stakeholders, including domestic and international investors, customers, and partners, in conveniently accessing the company's financial status and management performance. Starting from 2026, beginning with the [2025 Korea Circuit Sustainability Management Report], we plan to publish English translations of the Sustainability Management Report on our global website, transparently conveying key policies and achievements in environmental, social, and governance areas to overseas stakeholders. Korea Circuit will continue to improve the accessibility and utility of disclosed information and strengthen trust-based communication with domestic and international stakeholders.