Risk Management Policy of IT City Public Company Limited

IT City Public Company Limited (the “Company”) has realized the importance of risk management. Under the operating conditions of all activities, which is uncertain that may affect the operation or goals of the organization.  Therefore, the company needs to manage risks that may arise systematically. By identifying any risk factors that affect the organization’s operations or goals. Analyze risks from opportunities and impacts that occur. Prioritize risks, including setting risk management guidelines to prevent and control risks that may arise from uncertain circumstances that will affect the overall success of the organization.

Risk Definition and Risk Management

Risk is an opportunity or event with uncertainty that will cause mistakes and damages. Leakage, waste or untoward events, or any actions that may occur under uncertain circumstances that may occur in the future and affect the image and reputation of the organization, or cause the operation to fail to achieve the objectives and goals of the organization. Operational, Financial and Administrative

Enterprise Risk Management is a process carried out by the Board of Directors. The risk management process is designed to be able to identify potential events that have an impact on the organization and to manage risks to a level acceptable to the organization in order to gain reasonable confidence in achieving the objectives set by the organization.

The Company’s Risk Management Policy and Guidelines

The Company conducts risk management by organizing a factor management system and controlling various operational activities to reduce the causes of damage, so that the level of risk and impact that will occur in the future is at an acceptable level. Assessable Controllable and systematically monitored. Taking into account the achievement of the Company’s objectives and goals. Therefore, the following guidelines are set for the following objectives:

  1. To have integrated risk management throughout the organization with systematic and continuous management. Reduce the risk of all missions or activities to a minimum.
  2. The risk management process shall be established in a systematic and standardized manner throughout the organization.
  3. The risk management results shall be monitored and evaluated and reviewed and improved every quarter.
  4. Make risk management a part of normal operations.

STAKEHOLDERS

ROLES  AND RESPONSIBILITIES

Board of Directors

Understand the risks that can have a serious impact on the organisation and ensure that appropriate actions are in place to manage them.

Risk Management Committee

  • Determine and review the risk management framework, policies and management processes, as well as make recommendations on risk management guidelines related to the Company’s business operations appropriately and effectively in line with the direction of the operational strategy. Business plans and changing circumstances
  • Support and develop risk management at all levels throughout the organization, including various tools continuously and effectively, as well as promote the development of risk management culture in the organization.
  • Supervision Monitoring and reviewing important risk management plans and reports, as well as providing recommendations to ensure effective and appropriate risk management at an acceptable level. In line with the risk management policy.
  • Report on the results of important risk management to the Board of Directors In the event of a significant factor or event that may have a significant impact on the Company. It must be reported to the Board of Directors for consideration as soon as possible.
  • In the course of its duties, the Risk Management Committee may seek the approval of an independent advisor. When deeming it necessary and appropriate, the Company is the one to bear the expenses.

Management Team

  • Monitor critical risks across the organization and ensure proper management plans are in place.
  • Promote risk management policies and ensure that risk management processes are implemented throughout the organization.

Managing Director

  • Monitor strategic risks and critical operational risks and ensure proper risk management planning is in place.
  • Promote a risk management culture and ensure that the Deputy Managing Director prioritizes risk management in his department.

Deputy Director

  • Ensure adequate operational assessment and risk reporting.
  • Encourage employees in the department to be aware of the importance of risk management.

Department managers, department managers, supervisors and employees.

  • Identify and report risks related to operations to their supervisors in their line of work, and participate in the preparation of risk management plans and implement plans.
  • Operating under the Risk Management Framework

Agencies or persons in charge of risk management
(Working Group)

  • Perform daily duties on behalf of the Risk Management Committee.
  • Prepare a risk framework and process for the agency and propose it to the Risk Management Committee for approval.
  • Provide support and guidance on risk management processes to various departments within the organization as requested.
  • Ensure appropriate internal controls for risk management and compliance controls.
  • Ensure that the risk management system is properly implemented.
  • Review the performance of their own agencies.
  • Communicate within their own departments to understand risks and conduct internal audits based on identified risks.

Monitoring and Evaluation

Monitoring and evaluation are carried out to ensure that risk management is quality and appropriate, and to ensure that all risks that have a significant impact on the achievement of the organization’s objectives are reported to the responsible management. Risk management monitoring can be done in two ways as follows:

  • Continuous monitoring is a regular operation. To be able to respond to changes in a timely manner and be considered as part of the operation.
  • Follow-up on a case-by-case basis is an action after the incident occurs.

 

This policy shall be effective from April 24, 2023 onwards.

  Mr. Sophon Intanate

President
                                                                                      IT City Public Company Limited