Report of the Risk Management Committee
The Risk Management Committee performs duties as assigned by the Board of Directors. Its scope of duties and responsibilities is specified in the Charter of the Risk Management Committee.
In 2025, two Risk Management Committee's meetings were held to determine, review, and update the Risk Management Policy, Charter of the Risk Management Committee, Corporate Risk Management Framework, and Corporate Risk Management Process to the rapidly changing situations and the business operations, and also to provide recommendations on risk management guidelines that are consistent with the strategic direction of the business plan. This is to allow the Risk Owner to manage significant risks to Risk Appetite and to ensure that the Company has adequate and effective risk management in accordance with the Enterprise Risk Management Framework (COSO ERM 2017), as well as to continuously support the development of risk management at all levels to create the organizational culture of risk management.
The Risk Management Committee Meeting Attendance for the Year 2025
List of the Risk Management Committee
Number of Attendances / Total Number of Meetings
Mr.Atip Bijanonda
Chairman of the Risk Management Committee
2/2
Mr.Anant Gatepithaya
Director of the Risk Management Committee, Independent Director
2/2
Mr.Tritecha Tangmatitham
Director of the Risk Management Committee
2/2
Mr.Krid Chancharoensuk
Director of the Risk Management Committee
2/2
Secretary of the Risk Management Committee: Ms.Toopthong Hirunyanulak
In addition, there is follow-up, evaluation, review and approval for the risk management plan, which covers various types of major risks, including Strategy Risk, Operation Risk, Financial Risk, Compliance Risk, Corruption Risk, Market Risk, Cybersecurity Risk, Emerging Risk, and Risks on the Company's sustainability issues covering Environmental, Social, and Corporate Governance Risk (ESG Risk), including Climate Risk and reporting the results of the risk management to the Board of Directors.
According to the performance of duties of the Risk Management Committee in the previous year, the Risk Management Committee had taken steps to ensure that risk management was adequate and appropriate, which had been implemented continuously until the risk was at an acceptable level for the Company. The implementation was as follows:
The significant performances of the Risk Management were summarized twice as follows
No. 1/2025
- Acknowledging the progress of the implementation according to the resolutions of the Risk Management Committee’s meetings and the Risk Management sub-committee’s meetings.
- Considering and approving the list of external stakeholders (business group/company name) for attending the 2025 Focus Group Meeting and approving the external stakeholder group for the 2026 Focus Group Meeting.
- Consider and approve the management of emerging risks.
- Acknowledge the results of the 2024 annual knowledge assessment on risk management.
- Acknowledge The Global Risks Report 2025 from the World Economic Forum.
- Acknowledge the results of the ESG risk assessment for suppliers and external contractors of Supalai Public Company Limited.
- Acknowledge the results of the Disaster Recovery Plan (DRP) test for data loss on Cloud Computing affecting the company's core systems.
- Workshop on Risk Management, Digital and AI Strategy Alignment Business Growth to ensure consistency with the company's growth strategy.
No. 2/2025
- Acknowledging the progress of the implementation of the resolutions of the Risk Management Committee’s meetings and the Risk Management sub-committee’s meetings.
- Considering and reviewing material issues on sustainability and risk management results on sustainability
- Identifying material issues on sustainability
- Assessment of the impact of sustainability issues on stakeholders.
- Prioritization of material sustainability issues.
- Alignment with SDGs 17 Goals.
- Goals / Strategies / Action Plans
- Identification of risks and opportunities.
- Determination of risk level for each sustainability issue (risk level).
- Table showing likelihood and impact assessment (risk matrix).
- Assessment of risk appetite.
- Definition of key risk indicators (KRIs) and KRI results.
- Risk Management Guidelines
- Considering and reviewing the risk map and risk radar chart of the organization
- Considering and reviewing the disclosure of management and operational risks (according to the topics specified by the SET)
- Considering and reviewing the policy on risk management
- Considering and reviewing the Charter of the Risk Management Committee
- Considering and approving the report of the Risk Management Committee.
- Considering and approving the risk management plan for the year 2026
- Acknowledging the risk management performance for the year 2025