Importance
The Company recognizes risk management and internal control as fundamental elements of good corporate governance and essential drivers of effective, transparent, and sustainable business operations. The Company has adopted an Enterprise Risk Management (ERM) framework to systematically identify, assess, manage, monitor, and review risks across the organization. This is supported by a robust internal control system designed to address evolving business conditions, technological advancements, and regulatory requirements, while enhancing organizational resilience and supporting the achievement of the Company’s strategic objectives.
Mission
- Strengthen the Enterprise Risk Management (ERM) framework to comprehensively address strategic, operational, financial, technology, and ESG-related risks.
- Maintain an effective, transparent, and robust internal control system that supports accountability and independent assurance.
- Foster a risk-aware culture by embedding risk management into the day-to-day operations and decision-making processes across all business functions.
- Regularly monitor, assess, and review risks to ensure the Company remains resilient and responsive to evolving business conditions.
- Support informed business decision-making through effective risk management practices aligned with the Company’s strategic objectives.
- Conduct an annual enterprise-wide risk assessment covering 100% of material risks.
- Perform an annual assessment of the effectiveness of the internal control system covering 100% of material business processes.
- Maintain zero material incidents resulting from deficiencies in the internal control system.
- Report risk management and internal control performance to the Board of Directors in accordance with the approved governance plan (100% completion).
Key Performance Highlights
| Performance Indicators | 2023 | 2024 | 2025 | Target |
|---|---|---|---|---|
| Enterprise-wide Risk Assessment Completed as Planned | 100% | 100% | 100% | 100% |
| Internal Control System Assessment Completed as Planned | 100% | 100% | 100% | 100% |
| Material Incidents Resulting from Internal Control Deficiencies | 0 | 0 | 0 | 0 |
| Risk Management Reporting to the Board of Directors Completed as Planned | 100% | 100% | 100% | 100% |
Peace, Justice and Strong Institutions
Partnerships for the Goals
Risk Management
The Company has established a risk management governance structure that clearly defines the roles and responsibilities of the Board of Directors, the Audit Committee, the Management, and relevant business functions. This governance framework ensures that risk management is effectively integrated across all levels of the organization. Risk exposures are regularly monitored, reviewed, and reported to the Board of Directors to support informed decision-making and strengthen the Company’s long-term resilience.
Risk Management Framework
The Company has established a comprehensive Risk Management Framework that integrates its governance structure with the enterprise risk management process. The framework encompasses the systematic identification, assessment, mitigation, monitoring, and reporting of risks, enabling informed decision-making and supporting effective, resilient, and sustainable business operations.
Risk Management Process
| Process | Implementation Approach |
|---|---|
| Risk Identification | Identify risks arising from internal and external factors that may affect the Company’s business operations and strategic objectives. |
| Risk Assessment | Assess the likelihood and potential impact of identified risks to determine their significance and prioritize risk management efforts. |
| Risk Response | Define and implement appropriate risk treatment measures to mitigate, control, transfer, or accept risks within the Company’s risk appetite. |
| Monitoring & Reporting | Monitor the effectiveness of risk mitigation measures and regularly report risk management performance to Management and the relevant Board committees. |
| Review & Improvement | Periodically review and continuously improve the risk management framework and processes to ensure alignment with the evolving business environment and emerging risks. |
Risk Appetite, Risk Assessment Criteria and Key Risk Indicators
The Company has established a Risk Appetite framework to define the level of risk it is willing to accept in pursuit of its strategic objectives. Risks are assessed based on their Likelihood and Impact to determine their significance and prioritize appropriate risk management actions. In addition, the Company has established Key Risk Indicators (KRIs) to monitor early warning signals and emerging risks on an ongoing basis, enabling timely response and effective risk mitigation.
Risk Appetite
Define the level of risk the Company is willing to accept in pursuit of its strategic objectives.
Risk Assessment
Assess risks based on their likelihood and potential impact to determine their significance.
Key Risk Indicators (KRI)
Continuously monitor key risk indicators and early warning signals to enable timely risk response.
Risk Response Strategies
Following the risk assessment process, the Company selects the most appropriate risk response strategy based on the nature and significance of each identified risk.
| Strategy | Approach |
|---|---|
| Avoid | Eliminate or avoid activities that expose the Company to unacceptable levels of risk. |
| Reduce | Implement controls and mitigation measures to reduce the likelihood and/or impact of risks. |
| Transfer | Transfer or share risks through mechanisms such as insurance coverage or contractual arrangements. |
| Accept | Accept risks that are within the Company’s risk appetite while continuously monitoring and managing them. |
Key Risk Factors
- Strategic Risk
- Operational Risk
- Compliance Risk
- Financial Risk
- ESG Risk
Emerging Risks
| Emerging Risk | Potential Impact | Management Approach |
|---|---|---|
| Climate Change | Environmental regulations, increased operating costs, and changing demand for environmentally friendly products and services. | Monitor climate-related regulations and standards, assess the Company’s carbon footprint, expand environmentally friendly products and services, and promote Circular Economy principles. |
| Pandemic & Health Risk | Disruption to branch operations, workforce availability, and customer service. | Maintain a Business Continuity Plan (BCP), implement health and safety measures, and strengthen emergency preparedness to ensure business continuity. |
| Human Rights in the Supply Chain | Reputational risk, regulatory non-compliance, and loss of stakeholder trust. | Select and assess suppliers based on human rights principles and labor standards, while continuously monitoring and strengthening supply chain due diligence. |
Internal Control
The Company has established a comprehensive Internal Control System covering business operations, financial reporting, legal and regulatory compliance, and information systems. The system is designed to support effective, transparent, and accountable business operations while ensuring that risks are appropriately managed. The Company continuously monitors and evaluates the effectiveness of its internal control system to strengthen governance, improve operational performance, and support the achievement of its strategic objectives.
Internal Control Framework
Employees
Shareholders
Government Agencies and Regulatory Authorities
