Corporate Social Responsibility

Adhere To The Principle Of Sustainable Development To Create A Better Life

Corporate Governance


We consistently comply with applicable laws, regulations, and regulatory requirements, and continuously enhance our governance standards to ensure the lawful and compliant operation of our business.

Compliance Management


Joincare adheres to a path of compliance and prudent operations, actively contributing to the creation of social value. We are committed to building a robust compliance management system to ensure high-quality and standardized operations. In addition, the Group conducts comprehensive audits of all subsidiaries on an annual basis, with audit coverage spanning all areas of operation. In 2024, the Group’s Audit and Supervision Department conducted audits across the full spectrum of business processes.

 

Joincare Haibin has obtained ISO 37301 Compliance Management System certification, which remains valid as of 2024.

 

The compliance management performance in 2024 is as follows

0 cases of embezzlement and bribery;

0 cases of fraud;

0 cases of money laundering;

0 conflicts of interest;

0 cases of discrimination and harassment;

0 cases of customer privacy data breaches.

Risk Management


Joincare has established a comprehensive risk management system and implemented the Joincare Pharmaceutical Industry Group Co., Ltd. Comprehensive Risk Management System. We have built a “three lines of defense” structure for risk management and internal control, standardized the risk assessment and management process, and set enterprise-wide risk management objectives to enhance our overall risk prevention and control capabilities. The Board of Directors is the highest decision-making body for risk management and is responsible for overseeing all related activities.

 

We continuously gather information to identify internal and external risks, formulate risk management strategies, implement mitigation measures, and monitor and provide early warnings of risks. Regular risk reports are prepared to evaluate the effectiveness of risk management practices, with follow-up actions taken to address identified issues. Each year, we assess the company’s risk exposures, evaluate internal controls over financial and non-financial risks in key business areas and high-risk domains, and conduct internal audits on risk management. We also engage independent third parties to perform external risk audits and apply sensitivity analysis to assess goodwill impairment risks.

Information Security


Joincare has established a comprehensive information security management system and formulated group-wide policies and standards, including the Computer Information System Security Management Policy, IDC Data Center Operations Management Requirements, Data Backup Policy, and Reporting Procedures for Information Security Incidents. We have also established an organizational structure for information security management, with the President serving as the highest authority responsible for overseeing information security across the Group.

 

Information Security-Related Business Continuity Plans

To effectively respond to unexpected disaster events, the Group has formulated and implemented the Network Server System Emergency Plan and Information System Disaster Recovery Plan. These plans clearly define the response mechanisms, handling procedures, and mitigation measures in the event of an emergency. Regular emergency drills are conducted to test the feasibility and completeness of these plans, thereby strengthening our information security defenses and ensuring business continuity. We also conduct annual tests on backup appliances and carry out data disaster recovery drills to verify the effectiveness of related contingency plans.

 

Annual Information Security Vulnerability Analysis

As part of our daily operations, the Group has deployed Endpoint Detection and Response (EDR) systems to defend against malware attacks on endpoint devices. We have implemented next-generation firewalls and conducted network penetration testing to assess system security in depth, alongside regular security assessments, vulnerability scanning, and analysis. In addition, we have established an Intrusion Prevention System (IPS) centered on intrusion detection, leveraging multi-layered defense technologies to accurately identify security threats in real time and promptly halt intrusion activities.


Information Security Audits

The Group is committed to continuously enhancing its information security management. Each year, we engage independent third-party institutions to conduct audits of our information systems and related security policies. In parallel, we carry out internal audits covering the information security management system, IT infrastructure, and operational environments to ensure the effective functioning of our information security framework.

 

Escalation Process for Employees to Report Incidents, Vulnerabilities or Suspicious Activities

Joincare has established a structured procedure for employees to report information security incidents, vulnerabilities, or suspicious activities. This process covers detection, internal reporting, incident assessment, response, feedback, and communication, with detailed guidelines provided for each stage.

 

Employees who identify any suspicious activities, vulnerabilities, threats, or violations related to information security are required to promptly document the relevant details—such as time, location, individuals involved, and a description of the incident—and report them to the Information Security Team via email, the internal reporting system, or other designated channels.

 

The Information Security Team will then assess and investigate the reported incident and take appropriate actions, which may include patching vulnerabilities, enhancing security measures, activating the incident response plan, initiating legal procedures, or other necessary steps. Timely updates and feedback will be provided to the reporting employee throughout the process.