Risk and Crisis Management

     The Company places significant importance on sound corporate governance and has adopted the COSO Enterprise Risk Management Framework to ensure a systematic and effective approach to risk management across the organization. Management and employees at all levels are responsible for managing risks in accordance with the Company’s policies, enabling the Company to maintain risks within acceptable levels, enhance operational efficiency and transparency, and support sustainable business growth while strengthening stakeholder confidence.

Risk Management Structure

     The Company has established a risk management structure by appointing a Risk Management Committee (with reference to the announcement on the appointment of the Risk Management Committee pursuant to the resolution of the Board of Directors Meeting No. 2/2025 dated 15 May 2025) to define frameworks, guidelines, and policies in alignment with the organization’s objectives, as well as to oversee, monitor, and assess the overall risk profile at all levels. The Company has also appointed a Risk Management Working Team to implement such policies, with emphasis on identifying, assessing, and managing operational risks in collaboration with relevant departments, including regularly reporting the results to the Committee. This is to ensure that risk management is effective and supports the sustainable achievement of the Company’s objectives. The Company’s risk management structure comprises the following relevant persons and functions.

The Company’s Risk Management Structure

     To ensure that risk management and the internal control system are efficient and effective, the Company has arranged for a review by external auditors, coordinated by Ms. Monthira Praphachan, Senior Internal Audit Manager. This process is carried out in accordance with the governance principles of the Three Lines Model to ensure clarity in roles and responsibilities, effective control, and independent assurance.

Objectives of Risk Management

  1. To ensure that management and operational functions understand the principles and processes of risk management.
  2. To ensure that operational functions are informed of the steps and processes for risk management planning.
  3. To serve as a risk management tool for departments at all levels.
  4. To serve as a communication tool, promote understanding, and link risk management with the organization’s internal control system.
  5. To reduce the likelihood and adverse impact of risks that may affect the Company.

The Company’s Risk Management Framework

     The Company recognizes the importance of risk management in line with the principles of good corporate governance and has therefore adopted the internationally recognized COSO ERM 2017 framework. The framework emphasizes integration with strategy-setting and performance to support decision-making, create value, and increase the likelihood of achieving objectives sustainably. The framework covers the following key components.

1. Governance and Culture

     This includes the role of the Board, governance structure, organizational values, and the development of a risk management culture. The Company has established an appropriate risk management structure, including both the Risk Management Committee and the Risk Management Working Team, to drive systematic risk management across the organization.

2. Strategy and Objective-Setting

     This focuses on aligning business context analysis, strategy formulation, business objectives, and acceptable risk levels in the same direction, while considering both risks and opportunities, including ESG-related issues that may affect the achievement of the organization’s goals.

3. Performance

     This covers the identification, assessment, prioritization, and response to risks, as well as an enterprise-wide view of risks to support decision-making and the appropriate allocation of resources.

4. Review and Revision

     This focuses on monitoring significant changes, reviewing risk management results, and improving processes, tools, or measures to remain appropriate for the evolving business context.

5. Information, Communication and Reporting

     This covers the use of data and technology to support risk management, the appropriate communication of risk information to relevant parties, and the reporting of risks, culture, and performance to management and the Board.

     The Company has prepared the 2025 annual risk management plan, which has been approved by the Risk Management Committee and the Board of Directors. The plan specifies risk treatment measures, responsible persons, implementation timelines, and systematic monitoring through the annual risk register, as set out in the 2025 Risk Register document.

Risk Management Process

     The risk management process is used to identify, analyze, assess, prioritize, and manage risks that may affect the achievement of the Company’s objectives, with appropriate control approaches and response measures determined to keep risks within an acceptable level. The success of this process depends on the Company’s personnel having the necessary knowledge and understanding and operating in the same direction.

1. Risk Identification

     The Company identifies risks by considering both internal and external factors that may affect its objectives and performance. External factors include economic conditions, government policies, laws and regulations, competitors, and consumer behavior, while internal factors include strategy, organizational structure, work processes, personnel, and technology. Risk identification covers significant events, including low-likelihood but high-impact risks, using a variety of tools and methods such as interviews, brainstorming, workshops, historical data analysis, as well as SWOT and PESTEL analysis. All risk information is systematically compiled and managed through the Risk Register, which records details such as risk category, risk factors, impacts, risk level, responsible persons, and control measures, covering four categories of risk: Strategic (S), Financial (F), Operational (O), and Compliance (C).

2. Risk assessment

     is the process of considering the likelihood and impact of each identified risk to determine its severity and prioritize it accordingly. In general, both inherent risk and residual risk are considered. If the residual risk remains above the acceptable level, the organization must establish additional measures to reduce the risk to an appropriate level. The assessment is based on two factors: the likelihood of occurrence and the resulting impact, as illustrated in the following chart.

See the impact severity and likelihood assessment criteria here.

Risk Appetite and Risk Tolerance

     The Company defines its Risk Appetite and Risk Tolerance with reference to the severity criteria in the Risk Matrix. If the residual risk after controls is rated High to Very High, or scores 8 or above, it is considered outside the acceptable tolerance range and additional risk management measures must be established.

Score Risk Level Color Number of Cells Meaning of the Risk Level
1 - 3
เสี่ยงน้อย Low
5 An acceptable risk level for the organization without the need for additional controls. No further risk treatment is required.
4 - 6
เสี่ยงปานกลาง Medium
5 A moderately acceptable risk level, but control measures are required to prevent the risk from escalating to an unacceptable level.
8 - 12
เสี่ยงสูง High
7 An unacceptable risk level that requires risk treatment to bring it down to an acceptable level.
15 - 25
เสี่ยงสูงมาก Very High
6 A very severe and unacceptable risk level that requires immediate action to reduce the risk to an acceptable level.

3. Risk treatment measures

     involve selecting practical approaches for managing risks. The available options should be considered considering acceptable risk levels and whether the costs incurred are worthwhile compared with the expected benefits. Depending on the circumstances, one method or a combination of methods may be selected, based on the 4T risk response principles as follows.

- Tolerate or Accept Risk :

       For risks that are within an acceptable level for the organization and do not create significant impact.

- Treat or Mitigate :

       By establishing control measures or improving processes to reduce likelihood or impact.

- Transfer Risk :

       For example, through insurance or outsourcing to external parties.

- Terminate :

       By discontinuing or avoiding activities that give rise to risk.

Key Risk Indicators (KRIs)

     The Company has established Key Risk Indicators (KRIs) for each risk issue to systematically monitor and track risks, while also serving as an early warning mechanism. This enables the risk management function to anticipate potential future risk trends and implement preventive measures in a timely manner. Relevant functions responsible for each risk area are required to report monitoring results regularly. If any irregularities or trends that may give rise to risk are detected, the Company will immediately implement a mitigation plan to keep the risk within an acceptable level.

4. Performance Reporting and Preparation of Risk Management Reports

     The key functions responsible for risk management are required to report risk management results to the Risk Management Working Team at least twice a year and to prepare an annual risk management report for submission to the Risk Management Committee and other relevant committees.

5. Review of the Risk Management Plan

     The Company requires the risk management plan to be reviewed and updated regularly to ensure that the risk management system remains complete and aligned with the current situation. The Risk Management Committee monitors results after implementation and evaluates the effectiveness of control measures to determine whether any measure should be continued, improved, or discontinued.

Risks to the Company's Business Operations

     The Company analyzes and assesses risk factors that may significantly affect its business operations, covering both Key Risks, which are risks likely to arise and may directly affect the Company’s current operating results and performance, and Emerging Risks, which arise from changes in the business environment, technology, or external factors that remain uncertain in the future. These are summarized as follows.

1. Key Risk

     refers to a risk or risk factor that is significant to the achievement of objectives, strategy, performance, business continuity, financial position, reputation, legal compliance, or organizational sustainability, and therefore must be regularly monitored, controlled, and reported to management or the Board. The related risk factors are as follows.

Risk of Maintaining Existing Business Growth

The inability to sustain growth in the existing business may significantly reduce revenue and net profit and weaken the competitiveness of the Company’s current business groups. The Company conducts customer satisfaction surveys twice a year to improve service quality and organizes annual promotional activities to retain its customer base and drive sales. It also places importance on continuously studying and updating new products to support decisions on changing models or brands, coordinate with relevant departments and customers to expedite deliveries and procurement planning, review or change delivery channels in urgent cases, and considers additional outsourcing or suppliers to reduce reliance on a single supplier.

1) Liquidity Management and Funding Risk 

Volatility and high uncertainty in the global and Thai economies may increase the cost of accessing funding and impose stricter conditions than under normal circumstances. The Company therefore strengthens its liquidity management by diversifying funding sources and carefully planning risk management to accommodate potential volatility. It ensures sufficient working capital for ongoing operations and future expansion, builds relationships with financial institutions to increase financing options and bargaining power, studies and adopts new financial instruments, and uses forward contracts to reduce the risk arising from exchange rate fluctuations.

 

2) Credit Risk from Trade Receivables 

       If customers are unable to pay on time or make late payments, the Company’s cash flow may decline, requiring it to recognize provisions for bad debts, which may in turn affect profitability, financial position, and the confidence of investors and financial institutions. To reduce this risk, the Company verifies and assesses customers’ credit information before approving credit terms, suspends the sale of goods and services when customers fail to pay as due, and applies follow-up, reminder, and collection measures for overdue customers. These efforts focus on identifying causes and reaching appropriate solutions together with customers in order to support proper repayment, build sustainable customer relationships, and reduce the risk of bad debts.

1) Risk of Talent Shortage to Support Business Growth 

The shortage of capable personnel or specialized talent may reduce work efficiency, increase recruitment and training costs for new staff, and adversely affect long-term competitiveness or prevent business growth from proceeding as planned. The Company therefore emphasizes its “Organization of Opportunities” initiative, which aims to foster an organizational culture that promotes learning and growth opportunities for employees. Risk control measures are divided into three main areas: recruitment and selection, employee development, and employee retention. In addition, the Company regularly conducts exit interviews and employee engagement surveys to analyze information and improve retention strategies, as well as to enhance the employee experience and working environment.

 

2) Fraud Risk in the Procurement Process

As the Company’s operations largely involve project work with both public and private sector entities, it may face fraud risks in procurement processes, which could affect finances, reputation, and the continuity of projects or overall operations. The Company has established governance and good corporate governance measures through the appointment of, and charter for, the Corporate Governance and Sustainability Committee to define, review, and monitor relevant policies, criteria, and practices. It also has a vendor selection and evaluation process, requiring key suppliers and new business partners with procurement value exceeding THB 1 million to undergo an ESG Risk Assessment, together with onsite audits to assess and continuously monitor suppliers’ ESG performance.

 

3) Workplace Safety and Operational Management Risk

Workplace safety risks may arise from unsuitable environments, such as inadequate lighting, damaged equipment, incomplete accident prevention measures, and insufficient employee safety knowledge or training, all of which increase the likelihood of accidents and workplace safety issues. The Company has therefore installed fire extinguishers in accordance with safety standards and Thai law, prepared building layouts and evacuation routes in appropriate locations, arranged annual health checks for employees, distributed face masks to employees who are unwell, and considered temporarily suspending fingerprint scanning to reduce shared contact. It also conducts workplace environment inspections relating to lighting and performs annual inspections and safety analysis of electrical equipment to ensure that equipment and the working environment comply with legal standards and to effectively prevent fire-related risks.

Risk of Non-Compliance with Relevant Laws and Regulations

Changes in government policy, laws, regulations, and other requirements are risks that directly affect the Company’s business operations. If the Company is unable to comply, it may face legal penalties as well as damage to its reputation and credibility. The Company has established a Code of Conduct as a guideline for employees at all levels to follow common standards of practice, together with regular annual training. It has also established comprehensive compliance policies for various operational matters and communicates them to all employees, closely monitors amendments or additions to laws relevant to the Company’s business, and maintains a register of laws that affect the business.

2. Emerging Risk

     refers to a newly arising risk or an existing risk whose nature has changed. There may not yet be sufficient information to clearly assess its likelihood or impact, but it has the potential to affect the organization’s strategy, operations, financial position, reputation, legal compliance, or sustainability in the future. It therefore requires continuous monitoring, analysis, and review. The related risk factors are as follows.

     Climate uncertainty directly affects business continuity and increases the likelihood of natural disasters such as storms, floods, wildfires, and droughts in many areas. To reduce such risks, the Company regularly prepares and reviews its Business Continuity Plan (BCP) to ensure alignment with the current situation and changing risks. It also tests and drills the BCP at least once a year to evaluate effectiveness and improve the plan as appropriate, provides uninterruptible power supply (UPS) systems to support servers and critical information systems in the event of a main power failure, and maintains All Risks property insurance to protect assets and reduce the financial impact of unexpected events.

     Siam TC Technology Co., Ltd., an affiliated company, has been licensed to manage and preserve mangrove forests for carbon credit benefits, which is considered a climate technology business under the Nature-based Solutions category. The projects comprise 22,318.64 rai of mangrove planting for external parties and 154,932.01 rai for community-based mangrove planting, totaling 177,250.65 rai over a 30-year period. However, climate uncertainty has caused tree survival rates to fall below the required threshold, resulting in the actual volume of certified carbon credits as of the assessment date being lower than projected, thereby reducing profitability. 

     The Company regularly monitors and assesses issues, obstacles, and impacts arising from forest plantation projects, prepares planting and replanting plans suited to the timing and characteristics of each area, and selects appropriate tree species to improve survival rates. It also closely monitors changes in laws, standards, and regulations related to carbon credits and digital assets, while applying AI and other new technologies to monitor tree growth and land use—such as drones, satellites, and radar—to improve the accuracy of analysis and strategic decision-making, as well as enhance the credibility of carbon credit calculation and certification.

     System and service disruptions may delay the delivery of goods and services, while the leakage of important and sensitive information may lead to loss of confidence among customers and stakeholders as well as legal penalties. The Company has established a formal information security policy, installed antivirus software, firewall systems, and email filtering systems, and regularly updates and monitors their operation. It also assigns appropriate system access rights, reviews software usage for legal compliance, requires users to update security regularly, maintains data backup systems and a Business Continuity Plan to reduce the impact of disruptions in a timely manner, performs vulnerability scanning using Nessus Expert, and encrypts wireless network usage to prevent intrusion attacks.

Risk of Non-Compliance with Relevant Laws and Regulations

Changes in government policy, laws, regulations, and other requirements are risks that directly affect the Company’s business operations. If the Company is unable to comply, it may face legal penalties as well as damage to its reputation and credibility. The Company has established a Code of Conduct as a guideline for employees at all levels to follow common standards of practice, together with regular annual training. It has also established comprehensive compliance policies for various operational matters and communicates them to all employees, closely monitors amendments or additions to laws relevant to the Company’s business, and maintains a register of laws that affect the business.

     Technology change risk may cause the organization to lose competitiveness if it cannot adapt quickly enough to developments in AI/AGI, resulting in delays in developing new products or services that rely on such technologies as a core component. In addition, the organization may face difficulties in attracting and retaining younger employees or highly skilled technology talent if it cannot create a work environment that supports the effective use of AI. The Company has therefore provided ChatGPT for Business for pilot use in certain work processes as a starting point for assessing the benefits and limitations of AI, with a focus on reducing repetitive tasks and testing integration with existing systems before expanding to other departments. It is also developing AI skills for employees at all levels, beginning with weekly knowledge content distributed through various internal channels, providing training from AI fundamentals to more advanced usage tailored to each function, and holding meetings with management to define a clear organizational direction for AI adoption. This is intended to build shared understanding of strategic objectives and operating frameworks so that AI implementation aligns with the Company’s long-term vision and development direction.

Risk Management Plan Development Guide

PDF Risk Management Plan Development Guide

Business Continuity Plan (BCP)

PDF Business Continuity Plan (BCP)