Good Corporate Governance is a cornerstone of driving the organization toward sustainable growth and building confidence among all stakeholder groups.

The Company is committed to conducting business transparently, ethically, responsibly, and accountably under corporate governance principles that align with applicable laws, good corporate governance guidelines, and international sustainability standards.

The Board of Directors plays a vital role in overseeing business operations, corporate strategy, risk management, and ESG topics to ensure that the Company considers impacts on the economy, society, the environment, and stakeholders throughout the value chain. The Board also promotes an organizational culture that upholds integrity, rejects all forms of corruption, and emphasizes strict compliance with the Code of Conduct.

The Company places importance on the transparent disclosure of accurate, complete, and timely information, as well as providing channels for stakeholder engagement and feedback to support decision-making and ongoing organizational development. This will lead to shared value creation and stable long-term growth.

Opportunities and Challenges

The Company recognizes the importance of good corporate governance as a cornerstone of sustainable business operations and a means of building confidence among all stakeholder groups throughout the value chain. The Company places importance on conducting its operations transparently, ethically, accountably, and in accordance with good corporate governance principles.

One of the key corporate governance challenges is communicating information concerning corporate governance, risks, and other key matters to stakeholders accurately, transparently, promptly, and appropriately, particularly amid changes in regulations, practices, or risk factors that may affect the organization and its stakeholders.

Nevertheless, the Company views this challenge as an important opportunity to enhance the effectiveness of its corporate governance system through the application of digital technologies, the development of personnel knowledge and capabilities, and the enhancement of management and information disclosure processes. These efforts aim to ensure that corporate governance is transparent and clear, responds to the expectations of all stakeholder groups, and supports stable and sustainable long-term growth.

Targets and Performance

Review of the Corporate Governance Policy, Code of Conduct, and Corporate Ethics by the Corporate Governance and Sustainable Development Committee and the Board of Directors
Targets
at least
a year, with the results communicated to employees
Performance
completed
Review of the charters of all Sub-committees
Targets
at least
a year
Performance
completed
Communication of information on the Code of Conduct, corporate governance, and organizational effectiveness
Targets
%
of employees
Performance
of employees
Cybersecurity threat, data leakage, and data theft incidents
Targets
cases
Performance
cases
(The Company followed its Incident Response and PDPA procedures. No customer data or core systems were affected, while cybersecurity measures were strengthened and vulnerabilities addressed to enhance long-term system security.)
Corruption-related complaints
Targets
cases
Performance
cases
Conflicts of interest
Performance
cases

Strategy and Management Approach

The Board of Directors places importance on good corporate governance (Corporate Governance: CG) as a key foundation of sustainable business operations. It has assigned the Corporate Governance and Sustainable Development Committee to formulate, review, and recommend the Corporate Governance Policy, Anti-Corruption Policy, Anti-Bribery Policy, business ethics, and the Code of Conduct within the framework of applicable laws, rules, regulations, and guidelines issued by domestic and international regulatory bodies.

These policies are considered, approved, and overseen by the Board of Directors to serve as best practice guidelines for all directors, executives, and employees. They also promote an organizational culture that upholds transparency, accountability, integrity, and ethical business conduct while supporting effective risk management, internal controls, and corporate governance.

The Company developed its Corporate Governance Policy upon its establishment and has continuously reviewed, revised, and enhanced it. The Board of Directors receives recommendations from the Corporate Governance and Sustainable Development Committee to ensure alignment with the Corporate Governance Code for Listed Companies 2017 issued by the Securities and Exchange Commission, Thailand (SEC), as well as relevant sustainability and governance practices. The Company conducted the tenth revision of its Corporate Governance Policy to align it with the business context, evolving risks, and stakeholder expectations.

Further information on the Company’s good corporate governance is available in the Good Corporate Governance Policy.

Board of Directors

The Company places importance on maintaining a diverse Board structure (Board Diversity) in terms of skills, knowledge, expertise, experience, gender, race, and nationality to align with its business strategy and sustainable organizational growth

The Company has developed a Board Skill Matrix covering the skills, knowledge, and expertise of the Board of Directors to support the nomination and assessment of the suitability of directors. It covers areas of expertise that are important to the Company’s business operations, including renewable energy, international business, accounting and finance, internal control, law, organizational development, social and environmental matters, safety, risk and crisis management, and information technology.

The Company also has a non-discrimination policy for the nomination and appointment of directors, with consideration based on qualifications, knowledge, capabilities, experience, and suitability for their roles and responsibilities. This enables the Board of Directors to apply diverse knowledge and perspectives in overseeing and advising the Company, setting its strategic direction, and supporting efficient, transparent, and sustainable business operations.

Board Structure

As of 31 December 2025, the Board of Directors comprised 12 directors, as follows:

  • Independent directors 7
  • Executive director 1
  • Non-executive directors 4
Female directors
representing
of all directors.
Average tenure of the Board of Directors
years
days
The Chairman of the Board is an independent director.
The Chairman of the Board does not concurrently serve as the Chief Executive Officer and President and is not a member of the Executive Committee
ensuring a clear separation of authority, duties, and responsibilities.
The Chairman of the Board has not been appointed as a member of any Sub-committee
ensuring independence in overseeing and effectively considering and scrutinizing the Company’s key agenda items.

Independent Directors

The Company requires independent directors to account for no less than one-third of the total number of directors to support transparent, independent, and effective corporate governance. All independent directors must fully meet the qualifications prescribed by applicable laws, the requirements of the Securities and Exchange Commission, Thailand (SEC), the Stock Exchange of Thailand, and the Company’s Articles of Association. In addition, no less than half of all directors must reside in the Kingdom of Thailand, as required by applicable laws.

The Company’s independent directors must possess diverse knowledge, capabilities, experience, and expertise that contribute to effective oversight, strategic advice, and supervision of the Company’s business operations. The Company requires at least one independent director to possess knowledge and experience in accounting and finance to support effective oversight of financial matters, internal controls, and risk management.

Further information on the requirements for independent directors and other requirements relating to the Company’s Board of Directors is available in the Good Corporate Governance Policy and the 2025 Annual Report (Form 56-1 One Report).

Skill Matrix

Skills and Expertise Number (Persons) Percentage (%)
1. Economics 2 16.67
2. Banking 2 16.67
3. Finance and Securities 2 16.67
4. Petrochemicals and Chemicals 1 8.33
5. Energy and Utilities 7 58.33
6. Commerce 2 16.67
7. Transportation and Logistics 1 8.33
8. Information and Communication Technology 2 16.67
9. Law 2 16.67
10. Accounting 4 33.33
11. Finance 6 50
12. Corporate Social Responsibility 1 8.33
13. Human Resource Management 1 8.33
14. Sustainability 1 8.33
15. Fund Management 1 8.33
16. Data Analysis 2 16.67
17. Negotiation 1 8.33
18. Project Management 1 8.33
19. Leadership 3 25
20. Strategic Management 4 33.33
21. Risk Management 1 8.33
22. Auditing 4 33.33
23. Budgeting 1 8.33
24. Corporate Governance/Governance 3 25
25. Public Administration 1 8.33
26. Business Administration 3 25

Board Performance Evaluation

The Company conducts performance evaluations of the Board of Directors and its Subcommittees at least once a year to assess their annual performance against their duties, authority, and good corporate governance principles. The evaluation results also serve as a basis for preparing development plans for the following year. In 2025, the Board of Directors evaluated the performance of the Board and its Subcommittees using the assessment forms developed by the Thai Institute of Directors (Thai IOD), comprising the following:

Board Self-Assessment (Board as a Whole)

covering:

  • Board structure and qualifications
  • Roles, duties, and responsibilities
  • Board meetings
  • Board culture and collaboration
  • Relationships with management and stakeholders
  • Director development
Individual Director Self-Assessment

covering:

  • Personal qualifications
  • Preparedness to perform duties
  • Participation in meetings
  • Roles, duties, and responsibilities
  • Relationships with stakeholders
Subcommittee Self-Assessment (Subcommittee as a Whole)

for the Audit Committee, Nomination and Remuneration Committee, Enterprise-wide Risk Management Committee, Corporate Governance and Sustainable Development Committee, and Investment Committee, covering:

  • Structure and qualifications
  • Roles, duties, and responsibilities
  • Meetings
  • Relationships with stakeholders
  • Training and necessary resources
  • Reporting
2025 Assessment Results
Board of Directors Board Self-Assessment (Board as a Whole)
Excellent
Board of Directors Individual Director Self-Assessment
Excellent
Sub-Committees
  • Audit Committee
  • Nomination and Remuneration Committee
  • Enterprise-wide Risk Management Committee
  • Corporate Governance and Sustainable Development Committee
  • Investment Committee

Management Team

The Management Team plays an important role in setting the Company’s strategic direction, making strategic decisions, driving business operations, and fostering sustainable growth. Executives must possess knowledge, capabilities, and experience in the management of resources both within and outside the organization, risk management, corporate governance, and building confidence among shareholders, investors, and all stakeholder groups.

The Company places strong emphasis on conducting business transparently and ethically, in compliance with applicable laws and regulations and in accordance with good corporate governance principles, to support stable and sustainable growth over the long term.

Performance Evaluation of the Chief Executive Officer and President

The Company has established a transparent and fair process for evaluating the performance and determining the remuneration of the Chief Executive Officer and President in alignment with the Company’s short-term and long-term performance. The Nomination and Remuneration Committee and the Board of Directors review and evaluate the performance annually using key performance indicators (KPIs) covering business growth, sustainable operations, and financial returns, as follows:

Growth
  • Investment & Divestment
  • Project Management
  • Pipeline Development
  • Development of the REC and carbon credit businesses
  • Efficiency improvements at solar power plants
ESG
  • Sustainability assessment results from external assessors
  • Investor relations performance and assessment scores from the Stock Exchange of Thailand
  • Employee Engagement
  • Succession Plan
Finance
  • Core Profit
  • Profits or added value generated through Improvement Programs
  • Corporate credit rating assigned by TRIS Rating

The evaluation results are used as key criteria in determining the remuneration of the Chief Executive Officer and President. The remuneration comprises short-term remuneration, including salary, bonuses, and other benefits, and long-term remuneration in the form of warrants to purchase the Company’s newly issued ordinary shares (BCPG ESOP WARRANT). This remuneration structure is designed to motivate and retain high-potential personnel and align executive remuneration with the Company’s long-term growth.

The Company applies a similar approach to the performance evaluation and remuneration of senior executives to ensure that their remuneration appropriately reflects their performance, responsibilities, and contribution to value creation for the organization.

The Company implemented the second series of warrants to purchase its newly issued ordinary shares (BCPG ESOP WS#2), issued on April 24, 2021, with a term of five years. The warrants were allocated to directors, executives, and employees of the Company and its subsidiaries to foster engagement and support the organization’s sustainable growth. However, in 2025, the Company had no additional long-term remuneration programs apart from this program.

Management Ownership

The Company places importance on overseeing securities holdings and trading by directors and executives to promote business conduct that aligns with shareholders’ interests and supports sustainable long-term value creation.

The Company believes that securities holdings by directors and executives serve as an important mechanism for promoting Alignment with Shareholders’ Interests and encouraging executives to contribute effectively to driving the Company’s performance and growth.

The Company has established clear guidelines governing securities holdings and trading by directors, executives, and related persons to prevent Insider Trading for personal gain and maintain transparency in its business operations. These guidelines comply with the Securities and Exchange Act B.E. 2535 (1992), the requirements of the Stock Exchange of Thailand, and those of the Securities and Exchange Commission (SEC).

In addition, the Company requires directors and executives to observe the Blackout Period before the disclosure of the Company’s material information and to report their securities holdings and any changes thereto in strict compliance with the applicable requirements.

The number of shares held by directors and senior executives as of 31 December 2025, is presented in the table below.

Securities Holder Position Number of Shares Held (Shares)
1. Mr. Prasong Poontaneat Chairman (Independent Director) -
2. Mr. Natthakorn Athithanavanich Vice Chairman (Director) -
3. Mr. Patiparn Sukorndhaman Director -
4. Pol. Gen. Visanu Prasattongosoth Director (Independent Director) 200,000
5. Mrs. Vilai Chattanrassamee Director (Independent Director) 374,214
6. Gen. Sakda Niemkham Director (Independent Director) -
7. Pol. Lt. Gen. Chaiwat Chotima Director (Independent Director) -
8. Ms. Salagjit Pongsirichan Director (Independent Director) -
9. Ms. Phatpuree Chinkulkitnivat Director -
10. Mr. Bundit Hansapaiboon (indirectly held through spouse) Director 5,584 85,318
11. Mr. Pornsit Poovanakijjakorn Director (Independent Director) -
12. Mr. Rawee Boonsinsukh Chief Executive Officer and President 5,000
13. Ms. Sattaya Mahattanaphanij Senior Executive Vice President, Corporate Excellence 240,000
14. Mr. Charnvit Trangadisaikul Senior Executive Vice President, Investment 164,545
15. Mr. Kongkiat Kanjanapan Acting Senior Executive Vice President, Finance and Accounting 223,600

Determination of Executive Remuneration

The Company has established a transparent and fair framework for managing executive remuneration in alignment with organizational performance, taking into account executives’ roles, duties, responsibilities, and business competitiveness to support long-term value creation and sustainable growth.

Executive remuneration is linked to the Company’s performance through Performance-linked Compensation and also takes into account individual performance, based on key performance indicators (KPIs) covering business growth, sustainable operations, and financial returns. The Company also uses benchmarking data from companies in the same industry to ensure that its remuneration levels are appropriate and competitive.

In addition, the Company considers external factors that may affect remuneration, such as economic conditions, industry trends, and overall business conditions, to ensure that remuneration remains appropriate and aligned with the circumstances of each year.

The Company transparently discloses employee and executive remuneration to reflect its fair and accountable approach to remuneration management. Details for 2025 are as follows:

Executive and Employee Remuneration (THB million/year) Total Average per Person
Annual remuneration of executives, including the Chief Executive Officer and President 94.28 18.86
Annual remuneration of all employees, excluding executives 339.00 2.19

Note Remuneration includes salaries, bonuses, provident fund contributions, and social security contributions.

Information Security Governance

The Company has incorporated information security and cybersecurity into Enterprise Risk Management and regularly reports cyber risk matters to senior management and relevant committees so that they can oversee, monitor, and continuously evaluate the performance of information security measures.

The Company continuously reviews and updates its information security policies in response to evolving cyber threats and technologies and relevant laws. It has also clearly defined the roles, duties, and responsibilities of personnel in safeguarding data and information systems.

In addition, the Company implements comprehensive cyber risk management measures, including:

  • Access Control based on roles and responsibilities
  • Continuous monitoring and surveillance of cyber threats
  • Information Security Incident Management
  • Testing and drills of cyber emergency response and business continuity plans (BCP/DRP)
  • Regular promotion of Cybersecurity and PDPA awareness among employees

Personal Data Protection and Information Security Policy

The Company places importance on information security and personal data protection by establishing Information Security policies and measures to prevent unauthorized access, disclosure, alteration, or loss of data and to support business continuity in compliance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA), relevant laws, and international information security standards. The Company has established policies under an information security management framework aligned with ISO 27001, the PDPA, and Cybersecurity practices to protect data and information systems and support business continuity, as follows:

Policies Guidelines
Information Security Policies
  • Establish organizational information security policies and measures
  • Communicate with employees and relevant parties to ensure their awareness and compliance
  • Regularly review and update the policies in response to evolving risks and technologies
Organization of information Security
  • Define roles, duties, and responsibilities for Information Security
  • Establish a committee or designate persons responsible for information security
  • Support risk management and Cybersecurity governance
  • Monitor Threat Intelligence to prepare for emerging risks
Human Resource Security
  • Establish security requirements before employment, during employment, and upon termination of employment
  • Build Cybersecurity and PDPA awareness among employees
  • Require the return of information assets upon termination of employment
  • Prevent unauthorized access to data by personnel
Asset Management
  • Establish an information asset register.
  • Designate Asset Owners
  • Classify information and determine its level of importance
  • Control the secure use, storage, and disposal of assets
  • Implement a system for inspecting devices and networks associated with information assets
Access Control
  • Grant access rights based on the Need-to-Know and Least Privilege principles
  • Control general user accounts and Privileged Accounts
  • Implement appropriate password management
  • Revoke access rights when an employee changes position or resigns
  • Periodically inspect and review access rights
Physical and Environmental Security
  • Prevent unauthorized access to critical areas
  • Control access to server rooms and other critical areas
  • Protect against damage caused by power outages, fires, floods, and other physical hazards
  • Provide an appropriate environment for information technology equipment
Operations Security
  • Establish IT operating standards
  • Control system changes through Change Management
  • Manage patches and vulnerabilities
  • Perform data Backup and Recovery
  • Protect against Malware and cyber threats.
  • Conduct technical vulnerability assessments at least twice a year
Communications Security
  • Protect data transmitted over networks
  • Control information exchanges within and outside the organization
  • Establish Network Security measures
  • Filter websites and control internet usage
  • Prevent data interception or alteration during transmission
System Acquisition, Development and Maintenance
  • Define Security Requirements from the system design stage
  • Apply Secure Development principles
  • Conduct security testing before systems are put into operation
  • Control system changes and maintenance
  • Reduce risks arising from software vulnerabilities
Supplier Relationships
  • Assess suppliers’ security risks
  • Include Security requirements in contracts
  • Monitor and evaluate suppliers’ compliance with the requirements
  • Control external parties’ access to data and systems
Information Security Incident Management
  • Establish incident reporting and response processes
  • Analyze, investigate, and document information security incidents
  • Take corrective and preventive action to prevent recurrence
  • Report incidents to management and relevant parties
Information Security Aspects of Business Continuity Management
  • Establish measures for responding to emergencies
  • Develop a Business Continuity Plan (BCP)
  • Develop a Disaster Recovery Plan (DRP)
  • Regularly test and review the plans
  • Ensure that critical systems can resume operations within the specified timeframe
Compliance
  • Comply with applicable laws, rules, and regulations
  • Comply with the PDPA, the Computer Crime Act, and IT Security requirements
  • Respect intellectual property rights and software copyrights
  • Continuously audit and assess compliance
Information Security for Use of Cloud Services
  • Establish criteria for selecting and using Cloud Service Providers (CSPs)
  • Assess risks before migrating data to the Cloud
  • Establish measures to protect data stored on the Cloud
  • Control access rights to data on the Cloud
  • Cover SaaS, PaaS, and IaaS services
Cryptography
  • Establish requirements for the use of encryption techniques to protect important data
  • Prevent unauthorized access to data
  • Control encryption Key Management
  • Apply encryption to both Data at Rest and Data in Transit

Information Security Practices

As a subsidiary of Bangchak Corporation Public Company Limited (“Bangchak”), the Company follows information security practices aligned with Bangchak’s policies. The Company is committed to using information technology to address stakeholders’ needs and places importance on using modern tools and security systems that comply with international standards to support business expansion in accordance with its corporate strategy and strengthen cybersecurity across all areas of its operations.

Under the agreement between the Company and Bangchak on the management of information technology and cybersecurity, the Company carries out such management within a structure aligned with that of Bangchak. Bangchak has established the Enterprise Architecture and Digital Roadmap Working Group to provide advice on technology suited to business needs. The Working Group collaborates with the Information Technology Committee and the Information Technology and Cyber Risk Management Committee, chaired by the Senior Executive Vice President, Corporate Management and Organization Development, with the Digital and Information Technology Department responsible for overseeing these matters. The Department reports its performance to the Management Committee and reports on information technology and cyber risk management to the subcommittee and the Enterprise-wide Risk Management Committee (ERMC).

In 2025, the Company obtained ISO/IEC 27001:2022 certification for its Information Security Management System (ISMS), raising its information security management standards and enhancing its preparedness to respond to changing business needs and potential cyberattacks. The certification demonstrates the Company’s responsibility for cyber risk management and its commitment to stable and secure business operations.

Protection against Threats to Assets, Data, and Information Systems

The Company places importance on safeguarding and protecting data. All data is stored in the Company’s data center, which has security systems that comply with international standards, including a firewall that prevents external parties from accessing the data. In addition, the Company strictly controls data access rights, permitting only relevant personnel to access the data.

In 2025, the Company operated in strict compliance with the Personal Data Protection Act (PDPA) by developing systems and measures to protect personal data within the Company’s operational systems. This demonstrates the Company’s commitment to protecting personal data and continuously building confidence among stakeholders.

In addition, the Company complies with its “Information Technology System Security Policy” to protect the organization’s assets, data, and information systems against threats. The policy covers security measures in three areas, as follows:

1
Risk Assessment and Contingency Planning
Assessment of risks associated with critical information systems; establishment of data backup systems and emergency response plans; and regular testing and drills of such plans.
2
Resource Management
Control over the use and maintenance of assets and equipment to ensure their availability, together with protection against unauthorized access to equipment and information systems during both on-site and off-site operations.
3
Data Management and Confidentiality
Establishment of strict data security measures, including control of access rights to and use of information systems according to the importance of the data, to prevent data leakage and misuse.

The Company also has measures in place to protect information systems against threats, covering both network intrusions and malicious programs. The four key approaches are as follows:

Risk Assessment and Contingency Planning
Assess risks, identify critical information systems, establish backup systems and emergency response plans, and continuously test and conduct drills of these plans.
Resource Management
Control the use of assets and equipment and keep them ready for use to prevent unauthorized access both on and off the premises.
Data Management and Confidentiality
Establish security measures governing access to and use of information systems according to the importance of the data.
Threat Protection
Detect and prevent threats, restore affected systems, and raise awareness among relevant parties; conduct system testing at least once a year and penetration testing by specialists every three to five years; and regularly assess and remediate system vulnerabilities.

Complaint Channels

The Company has been certified to ISO/IEC 27001:2022, an international standard for information security, with clear and systematic procedures for handling information security incidents. Employees who identify suspicious incidents may report them through the following three main channels:

1
Company Website:
The Company’s Whistleblowing System:
2
E-mail:
  • For reporting concerns involving employees E-mails should be addressed to the Audit Committee and the Head of the Internal Audit Office. e-mail: ico@bcpggroup.com
  • For reporting concerns or complaints involving an individual or a group of individuals (i.e., the Chief Executive Officer, directors, and/or subcommittees) E-mails should be addressed to the Chairman of the Board of Directors, the Chairman of the Corporate Governance and Sustainable Development Committee, and the Company Secretary. e-mail: cg@bcpggroup.com
3
Telephone:
Head of the Internal Audit Office: 02-335-8977
Company Secretary: 02-335-8941

Internal Communication to Raise Awareness and Improve the Efficiency of Information Technology System Use

The Company places importance on internal communication, particularly regarding digital technology, to raise awareness and improve the efficiency of information system use. It therefore provides employees with regular communication and training, as follows:

The Company conducts drills of its emergency response and business continuity plans by simulating a crisis in which the Company’s Data Center becomes unavailable. The drills are conducted jointly with affiliated companies and business partners responsible for the IT systems to practice and test system recovery plans. The feasibility and effectiveness of approaches for recovering and restoring information technology equipment are also assessed in accordance with the framework established under the Disaster Recovery Plan, in close coordination with the Corporate Strategy Department or personnel responsible for risk management.

Key Stakeholders

Investors/ Shareholders
  • Communication of policies, business strategies, performance, corporate governance, and sustainability progress through the Annual Report (One Report), the Company’s website, and shareholders’ meetings.
  • Accurate, complete, transparent, and equitable disclosure of information in accordance with good corporate governance principles.
  • Provision of complaint and whistleblowing channels concerning fraud and corruption through the Company’s website.
  • Risk management and business operations based on good governance, transparency, and business ethics.
Employees
  • Annual review of the Corporate Governance Policy, Code of Conduct, and Corporate Ethics by the Board of Directors, with the results communicated to employees throughout the organization.
  • Promotion of knowledge, understanding, and awareness of corporate governance, ethics, and regulatory compliance through training, internal communications, and assessments.
  • Promotion of an organizational culture of ethics, transparency, and compliance with good governance principles.
  • Collection of employee feedback through complaint channels and employee opinion surveys.
Suppliers, Contractors, and Business Partners
  • Continuous communication of the Corporate Governance Policy, Code of Conduct, and good governance practices to suppliers and business partners.
  • Promotion of transparent, auditable, and fair procurement processes in accordance with the Procurement Code of Conduct.
  • Encouragement of suppliers and business partners to participate in declarations of intent to prevent and combat corruption.
  • Support for sustainable supply chain management and joint risk management with suppliers.