Page 307 - THAILAND PRIVILEGE ANNUAL REPORT 2025
P. 307
Annual Report 2025
7. Risk Management Performance
7.1 Risk Management Framework and Principles for Fiscal Year 2025
The Company’s enterprise risk management is conducted by integrating its vision, mission, mandates, and
strategic objectives as defined under the Corporate Plan and Annual Business Plan, together with the Key Performance
Indicators (KPIs) for Fiscal Year 2025, in order to analyze, identify, and assess potential events or situations that may
give rise to risks or adversely affect the Company’s operations. The Company has identified risk factors across four
core risk dimensions, in accordance with the COSO Integrated Enterprise Risk Management (ERM) Framework, together
with one additional significant risk dimension, in alignment with the risk management guidelines prescribed by the
State Enterprise Policy Office (SEPO) and in compliance with the Ministry of Finance Regulation on Risk Management
Standards and Guidelines for Government Agencies B.E. 2562 (2019). These risk categories comprise:
1. Strategic Risk
2. Operation Risk
3. Financial Risk
4. Compliance Risk (Risk relating to laws, regulations, and rules)
5. Reputation Risk
The Risk Management Plan for Fiscal Year 2025 establishes action plans and mitigation measures to
manage potential risks, with the objectives of preventing, reducing, and mitigating the impacts of risks that may
cause operational performance to deviate from the Company’s targets, ensuring that residual risks remain within
an acceptable level. Furthermore, the Company adopts an integrated approach to risk management, aligning risk
management activities with the implementation of key organizational plans, including the Corporate Plan, Annual
Business Plan, Internal Control Plan, Internal Audit Plan, and the Company’s Performance Indicators. This integrated
framework enables the Company to monitor, supervise, and evaluate the implementation of the risk management
plan on a continuous basis, through monthly and quarterly reviews, thereby reinforcing stakeholder confidence
that the Company is capable of achieving its objectives effectively and sustainably.
7.2 Risk Management Implementation in Fiscal Year 2025
The Company’s risk management implementation for Fiscal Year 2025 comprised the following key actions:
1. Review of the Risk Management Plan for Fiscal Year 2025. The Company conducted a review of the
Risk Management Plan for Fiscal Year 2025 to ensure alignment and linkage with the Corporate Plan and Annual
Business Plan, taking into account current operational performance and prevailing circumstances. The review also
emphasized integration with the Internal Control Plan and the Internal Audit Plan, in order to ensure consistency
and coherence across all governance and control frameworks.
2. Review of the Company’s Risk Management Manual. The Company reviewed the Risk Management Manual
for Fiscal Year 2025 (Revised Edition for Fiscal Year 2026) to establish and enhance risk management standards and
procedures. This review ensured full alignment with the COSO Integrated Enterprise Risk Management Framework
and the risk management criteria prescribed by the Ministry of Finance.
3. Appointment of the Company’s Risk Management Working Group. The Company appointed a Risk
Management Working Group to supervise, monitor, and evaluate the implementation of the Risk Management Plan
on a quarterly basis.
4. Appointment of the Risk Management and Internal Control Subcommittee. A Risk Management and
Internal Control Subcommittee was appointed to oversee and monitor the Company’s risk management performance
on a quarterly basis, as well as to provide opinions, recommendations, and approvals on risk management matters,
in accordance with the mandates delegated by the Board of Directors.
5. Quarterly Reporting of Risk Management Performance. The Company reported the results of the
implementation of the Risk Management Plan to the President, the Risk Management and Internal Control
Subcommittee, and the Board of Directors on a quarterly basis, in order to ensure timely awareness of the Company’s
risk status and emerging risk issues.
6. Preparation of the Risk Management Plan for Fiscal Year 2026. The Company prepared the Risk
Management Plan for Fiscal Year 2026, ensuring alignment and linkage with the Corporate Plan, Annual Business
Plan, and Key Performance Indicators for Fiscal Year 2026.
7. Review and Announcement of the Risk Management and Internal Control Policy. The Company reviewed
and announced its Risk Management and Internal Control Policy, clearly defining the roles and responsibilities of
executives and employees at all levels to ensure active participation in effective risk management. This initiative
aims to embed risk management as an organizational culture, fostering opportunity creation, value enhancement,
and organizational resilience for the maximum benefit of the Company and its stakeholders.
305

