Risk and Crisis Management
Supporting the SDGs
Risk management is an important process used by the Company to identify, assess, monitor, control, and manage risks that may arise from its business activities
thereby supporting the achievement of its strategic objectives and the creation of long-term value. It covers economic, environmental, social, governance, technological, and emerging risks that may affect stakeholders throughout the Company’s value chain.
Opportunities and Challenges
Businesses worldwide are currently facing challenges arising from economic volatility, climate change, the Energy Transition, technological advances, and changes in regulations and stakeholder expectations, which may affect business operations and organizations’ ability to create long-term value.
At the same time, these changes are creating new business opportunities for the energy industry, particularly through the growth of renewable energy, energy storage systems, greenhouse gas reduction technologies, and clean energy solutions, all of which play an important role in supporting the transition to a low-carbon economy.
The Company therefore prioritizes risk management at both the enterprise and project levels by integrating risk management into strategy formulation, investment decision-making, and operations throughout the value chain to effectively identify, assess, monitor, and manage potential risks and opportunities, as well as prepare for emerging risks that may affect its future business operations.
Through this approach, the Company seeks to build Business Resilience, strengthen stakeholder confidence, and support the stable and sustainable long-term growth of its renewable energy business.
Targets and Performance
Risk management system covering
Targets
Performance
Review and assessment of enterprise- and project-level risks
Targets
Performance
Continuous monitoring of emerging risks through analyses of economic, energy, technological, regulatory, and geopolitical trends in the countries where the Company invests, with a review conducted
Targets
Performance
Quarterly monitoring and assessment of the effectiveness of key risk management plans, with
Performance
Strategy and Management Approach
The Company recognizes that risk management is an important component of good corporate governance and a key mechanism supporting the achievement of strategic objectives, long-term value creation and the organization’s sustainable growth amid a rapidly changing business environment driven by economic, technological, climate-related, and regulatory factors, as well as changing stakeholder expectations.
The Company has therefore established an Enterprise Risk Management (ERM) process that systematically covers the identification, assessment, monitoring, and management of risks and business opportunities. Environmental, social, and governance risks (ESG Risks), including emerging risks, are integrated into the annual risk assessment process to ensure that material risks are considered comprehensively and in alignment with the Company’s strategic direction.
The Company assesses the likelihood and impact of risks on both the organization and its stakeholders and establishes risk management measures, assigns responsible persons, and defines Key Risk Indicators (KRIs) to maintain risks within the organization’s acceptable level (Risk Appetite). The Company also continuously monitors performance against its risk management plans.
In addition, the Company uses the results of risk assessments to support strategic planning, the consideration of investment projects, resource allocation, and business decision-making to enhance its ability to address uncertainty and create a long-term competitive advantage.
For risks that may affect business continuity, the Company has established a Business Continuity Management (BCM) system and emergency response plans to prepare for events that may affect its operations, assets, personnel, and stakeholders. These plans are regularly tested, reviewed, and improved.
The Enterprise Wide Risk Management Committee (ERMC) is responsible for overseeing and monitoring the organization’s material risks, including quarterly monitoring of performance against risk mitigation plans and the effectiveness of control measures. The results of risk management and reviews of the risk management system are reported to the Audit Committee at least twice a year and to the Board of Directors at least once a year, or whenever the organization is expected to be materially affected.
Risk Management Structure
The Company has established a risk management policy covering all levels of the organization, focusing on fostering a corporate culture that recognizes the importance of risk management and linking risk management with business strategy and corporate sustainability management to support long-term value creation for all stakeholder groups.
The Company applies the internationally recognized COSO Enterprise Risk Management framework (COSO ERM 2017) to ensure that risk management forms part of its strategic planning and decision-making processes. The framework covers economic, environmental, social, governance, technological, and emerging risks that may affect business operations in the short, medium, and long term.
The Company establishes its Risk Appetite and uses risk assessment results to support business decision-making, the consideration of investment projects, resource allocation, and the formulation of plans to mitigate potential risk impacts. Key Risk Indicators (KRIs) are also regularly monitored to maintain risks within levels acceptable to the organization.
In addition, the Company places importance on Business Continuity Management (BCM) as part of its preparedness for events that may affect its operations, personnel safety, information technology systems, and ability to provide services to stakeholders. Emergency response plans are continuously reviewed and improved.
The Company conducts comprehensive oversight and review of its risk management processes (Due Diligence) through the Board of Directors, the Audit Committee, the Enterprise Wide Risk Management Committee, management, and relevant departments to ensure that the risk management system is efficient, transparent, and aligned with good corporate governance principles.
The Company’s risk management structure is divided into three main parts based on the Three Lines of Defense Model, an internationally recognized practice that clearly defines the roles, duties, and responsibilities of relevant parties at each level to ensure efficient risk management throughout the organization, as detailed below:
First Line of Defense
BCPG Management Committee (MANCOM)
- Manages and oversees the Company’s operations in accordance with its corporate objectives, goals, and strategies.
- Considers and monitors performance under the Company’s policies, business plans, financial plans, and important work plans, including those of its subsidiaries and associates.
- Considers risks that may affect business operations and establishes risk management approaches aligned with corporate goals.
- Prepares, reviews, and monitors annual operational and strategic risk management plans for each function to maintain risks within levels acceptable to the organization.
- Prepares, reviews, and monitors annual operational and strategic risk management plans for each function to maintain risks within levels acceptable to the organization.
- Considers and screens the allocation of resources and budgets to support the efficient implementation of risk management measures and internal controls.
- Reports performance under risk management plans to the BCPG Management Committee and the Enterprise Wide Risk Management Committee.
Second Line of Defense
Enterprise Wide Risk Management Committee (ERMC)
- Establishes and reviews the enterprise-wide risk management policy, including the Risk Appetite and Risk Tolerance frameworks, in alignment with the organization’s strategic direction and goals.
- Oversees, monitors, and reviews the management of material risks, including ESG risks, climate change risks, cybersecurity risks, and emerging risks.
- Monitors the effectiveness of control measures and risk management plans to maintain risks within levels acceptable to the organization.
- Promotes a risk management culture and builds risk awareness at all levels of the organization.
- Reports the status of material risks, risk trends, and emerging risk issues to the Board of Directors.
- Reviews the Charter of the Enterprise Wide Risk Management Committee at least once a year.
Risk Coordinator
- Coordinates and supports the implementation of the organization’s risk management processes.
- Supports workshops on risk assessment and the preparation of risk management plans.
- Monitors and reports progress under risk management plans, including Key Risk Indicators (KRIs).
- Supports the collection of data and analysis of emerging risk trends.
Third Line of Defense
Audit Committee
- Provides oversight and independent assurance regarding the effectiveness of internal control, corporate governance, and risk management systems.
- Reviews the adequacy of the risk management system, including Business Continuity Management (BCM) and information technology risk management.
- Communicates and exchanges information with the Enterprise Wide Risk Management Committee to ensure that material risks are appropriately managed.
Internal Audit
- Independently assesses the effectiveness of the organization’s internal control system and risk management processes.
- Conducts internal audits in accordance with the Risk-based Internal Audit approach to assess the adequacy and effectiveness of risk control measures.
- Audits compliance by relevant departments with risk management policies, processes, and plans.
- Reports audit results, observations, and recommendations to the Audit Committee at least twice a year and continuously follows up on corrective actions.
Risk Management Structure
Note: RC (Risk Coordinator) is assigned by Executive Vice President or above to oversee risk coordination tasks.
Enterprise Risk Assessment
The Company conducts an Enterprise Risk Assessment to identify, analyze, and assess risk factors and business opportunities that may affect the achievement of strategic objectives, operations, and long-term value creation. The assessment covers both current and emerging risks that may arise from changes in the business environment, technology, climate, regulations, and economic, social, and geopolitical factors.
The Company uses the risk assessment results to support strategy formulation, investment decision-making, resource allocation, and business planning to manage risks within the level acceptable to the organization (Risk Appetite), while enhancing its ability to address uncertainty and build Business Resilience. The risk assessment process comprises three main steps, as follows:
1. Risk Identification
The Company identifies risk factors arising from both internal and external factors, covering risks that may affect business operations, investments, corporate reputation, stakeholders, and long-term competitiveness. The assessment also considers environmental, social, and governance risks (ESG Risks), climate-related risks, cybersecurity risks, and emerging risks.
Risk factors may arise from Internal Factors, such as personnel, work processes, corporate culture, information technology systems, and project management, or External Factors, such as economic conditions, regulatory changes, technology, climate, business competition, and geopolitical situations.
The Company classifies risks into five main categories:
|
1
Strategic Risk
|
2
Operational Risk
|
3
Financial Risk
|
4
Compliance and Reputation Risk
|
5
Emerging Risk
|
|---|---|---|---|---|
| Risks arising from changes in the business environment and external factors that may affect the achievement of long-term goals and operating plans, such as changes in energy policies, industry competition, the Energy Transition, economic volatility, and geopolitical risks. | Risks arising from operational processes, personnel, systems, or external events that may affect the efficiency and continuity of business operations, such as reduced power generation capacity, equipment deterioration, supply chain disruptions, and operational safety risks. | Risks that may affect the organization’s financial position, performance, or ability to conduct business, such as exchange rate fluctuations, interest rates, credit risk, insufficient financial liquidity, and investment risk. | Risks arising from non-compliance with laws, regulations, rules, standards, or the Business Code of Conduct, including events that may affect the organization’s reputation and credibility and stakeholders’ trust. | Risks that may not currently have a significant impact but are likely to affect the organization in the future, such as changes in energy technology, cybersecurity, climate change, geopolitical conflicts, changes in consumer behavior, and increasingly stringent carbon regulations. |
2. Risk Analysis
In analyzing risks, the Company considers both Inherent Risk and Residual Risk to assess the effectiveness of the established control measures and risk management plans. The assessment results are also compared with the organization’s Risk Appetite to determine risk management priorities.
The Company uses a Risk Matrix to assess and prioritize risks based on two dimensions: Likelihood and Impact. This enables the Company to determine appropriate response measures and allocate resources according to the level of risk.
For the assessment of the Likelihood of risks and opportunities, the Company considers the probability or frequency of risks arising from each risk factor based on historical data, the business environment, future trends, and the prescribed assessment criteria. The assessment also covers human rights risks, environmental risks, and emerging risks that may affect the organization. The Company has established four likelihood levels, ranging from low to high, to enable risks to be systematically compared and prioritized.
For the Impact assessment, the Company has established criteria for assessing potential impacts arising from risks and business opportunities, covering financial, operational, personnel, stakeholder, and corporate sustainability impacts. The assessment is divided into eight areas: financial; operational; employee development and satisfaction; human resources; customer; regulatory; human rights; and environmental. The Company has established four impact levels, ranging from low to high, together with assessment criteria for each area, so that risk assessments are conducted according to a consistent standard throughout the organization and appropriately reflect potential impacts on the achievement of the Company’s strategic goals. The impact assessment criteria for each area are as follows:
| Impact Category | Examples of Impact Assessment Criteria |
|---|---|
| Financial | Impacts on performance, financial position, profitability, and the organization’s ability to create added value arising from unforeseen risk events, based on indicators such as EBITDA, revenue, net profit, Credit Rating, expenses, and increased costs. |
| Operational | Impacts on the ability to conduct business, generate electricity, provide services, and maintain business continuity, including disruptions to information technology systems and production control systems, based on indicators such as the duration of operational disruptions, reduced electricity generation, asset availability, and damage to IT systems. |
| Employee Development and Satisfaction | Impacts on the ability to retain and develop personnel capabilities, particularly those of key and high-potential employees, including employee engagement and satisfaction levels, based on indicators such as turnover rate, employee engagement rate, and the achievement of personnel development plans. |
| Human Resources and Safety | Impacts on the lives, health, and safety of employees, contractors, and workers, including the organization’s operational capability, based on indicators such as the number of serious injuries, fatalities, accident rate, and lost days due to injury. |
| Customer and Corporate Reputation | Impacts on the confidence of customers, investors, communities, and stakeholders, including the organization’s image and reputation, based on indicators such as the number of complaints, the number of incidents attracting media attention, stakeholder protests, and impacts on public confidence. |
| Regulatory and Governance | Impacts arising from non-compliance with laws, requirements, or licensing conditions that may affect business operations and corporate reputation, based on indicators such as fines, license revocation, suspension orders, personal data breaches, and legal proceedings. |
| Human Rights | Impacts arising from human rights violations or stakeholder complaints throughout the value chain, based on indicators such as the number of human rights complaints, severity of incidents, remediation period, and impacts on affected persons. |
| Environmental and Climate | Impacts on the environment and climate change arising from the Company’s business operations, based on indicators such as greenhouse gas emissions, chemical or waste spills, impacts on air, water, and soil quality, and impacts on ecosystems and biodiversity. |
3. Risk Evaluation
Risk evaluation is an important process that enables the Company to identify, assess, and prioritize risks and determine appropriate risk management measures. The results of the Likelihood and Impact assessments are analyzed together using a Risk Matrix to determine the risk level of each risk factor. The Company has established four risk levels, as follows:
| Risk Evaluation | Risk Level | Explanation |
|---|---|---|
| Unacceptable |
Critical
|
Unacceptable risks due to the high impacts that affects the organizations and needs immediate mitigation plans |
| Unacceptable |
High
|
Unacceptable risks due to the high impacts that affects the organizations and needs mitigation plans |
| Acceptable |
Medium
|
Acceptable risks that need mitigation plan in place to reduce any negative impacts and prevent damages |
| Acceptable |
Accept
|
Acceptable risks that have low impacts to the organization |
Risks rated as high or very high are subject to additional risk management measures, with performance closely monitored by management and the Enterprise Wide Risk Management Committee.
The risk assessment results are compared with the organization’s Risk Appetite to support decisions on risk management, resource allocation, and strategic planning. The results are also used to monitor Key Risk Indicators (KRIs) to provide early warning and reduce the likelihood of events that may affect the organization.
Risk Prioritization
The Company prioritizes risks by considering the risk level, impacts on strategic objectives, the readiness of control measures, and its risk management capabilities to determine efficient risk response approaches appropriate to the business context.
In addition to considering risk levels derived from the Risk Matrix, the Company considers the following qualitative factors when prioritizing risks:
Adaptability
Complexity
Velocity
Persistence
Recovery
The Company reviews the results of its Enterprise Risk Assessment quarterly and continuously monitors the status of material risks, emerging risks, and the effectiveness of risk management measures to ensure that risks remain within levels acceptable to the organization and that the Company can respond effectively to changes in the business environment.
Risk Mitigation / Risk Treatment
Risk mitigation is an important process that enables the Company to reduce the likelihood of risk events and mitigate potential impacts on the achievement of its strategic objectives. Before implementing risk treatment, the Company considers the Inherent Risk, which is the level of risk existing before any control measures are established and assesses the effectiveness of Existing Controls to determine the Residual Risk.
The Company establishes risk management measures appropriate to the nature of each type of risk to ensure that risks are adequately managed and remain within the organization’s Risk Appetite. The effectiveness of control measures is continuously assessed through performance monitoring and internal audits.
For risks that remain at a high level after controls have been applied, the Company establishes an additional Risk Mitigation Plan specifying the responsible persons, implementation timeframe, and Key Risk Indicators (KRIs) to enable continuous monitoring and assessment of the effectiveness of the measures.
Risk Response
The Company establishes risk response approaches aligned with the risk level, potential impacts, and the organization’s Risk Appetite. The risk response approaches comprise:
Accept
Avoid
Reduce / Mitigate
Transfer / Share
Pursue Opportunity
| Degree of Acceptance | Existing Risk Management Measures | Risk Management Effectiveness | Risk Level | Required Action |
|---|---|---|---|---|
|
Accepted
|
Address the root cause of the risk and are effective | Effective risk management | Acceptable | Continue implementation and monitor changes |
|
Mitigating
|
Address the root cause of the risk but have not yet proven effective or workable in practice | Ineffective; stricter implementation of the risk management plan is required | Unacceptable | Ensure effective implementation of the existing measures or intensify their implementation |
|
Volatile
|
Do not address the root cause of the risk | Ineffective; additional measures or plans are required | Unacceptable | Introduce additional measures that address the root cause of the risk |
|
Unaccepted
|
None | Additional measures or plans are required | Unacceptable | Develop measures that address the root cause of the risk |
Cost-Benefit Analysis
Following risk prioritization, the Company conducts a Cost-Benefit Analysis of each risk management option to support effective decision-making and resource allocation, taking into account the expected benefits, associated costs, and impacts on the achievement of the organization’s strategic objectives.
The analysis covers financial, operational, environmental, social, and governance (ESG) impacts and is aligned with the organization’s Risk Appetite. The Company considers the following key factors:
Analysis of Options
Assessment of Benefits
Assessment of Costs
Comparison and Decision-Making
Once the Company has selected appropriate risk management measures, it assigns responsible persons and establishes implementation timeframes, required resources, success indicators, and Key Risk Indicators (KRIs) to monitor the effectiveness of the measures and continuously review performance.
The Company places importance on decision-making based on long-term cost-effectiveness, taking into consideration both financial impacts and impacts on stakeholders, as well as environmental, social, and governance impacts, to ensure that the selected risk management measures enhance Business Resilience and support the organization’s sustainable long-term growth.
Defining Risk Appetite and Risk Tolerance
The Company defines its Risk Appetite as a framework for decision-making and risk management in alignment with its strategic goals, business plans, and stakeholder expectations. Risk Appetite refers to the level and types of risk that the Company is willing to accept under appropriate management to create long-term business value and returns.
At the same time, the Company defines its Risk Tolerance as the acceptable range of deviation in performance before additional measures are required to control or mitigate risks and maintain them within the levels defined by the organization.
In determining its Risk Appetite and Risk Tolerance, the Company considers several key factors, including the results of the Enterprise Risk Assessment, trends in the business environment, economic and market volatility, regulatory changes, stakeholder expectations, and the organization’s risk management capabilities. The Risk Appetite and Risk Tolerance are reviewed at least annually or whenever significant changes affecting business operations occur.
Examples of the Company’s responses to key risks and the corresponding Risk Appetite and Risk Tolerance are as follows:
| Risks and Risk Levels | Climate-Related Risk | Risk Arising from Changes in External Factors in Countries in which the Company Invests |
|---|---|---|
| Inherent Risk Level | Moderate | Moderate |
| Potential Risks | Climate change may result in physical impacts, such as floods, droughts, landslides, and sea-level rise, as well as policy-related impacts, such as carbon taxes, which may reduce electricity generation or increase operating expenses. | Governments in individual countries may change their energy policies, while the Thai government may intervene in electricity prices to ease the financial burden on the public, such as by freezing the fuel adjustment charge (Ft), which may reduce the revenue of certain projects that depends on the Ft rate. |
| Mitigation Action | Pursue portfolio diversification across technologies and countries, and regularly monitor policy changes and climate change trends in each country in which the Company invests. | Maintain the highest possible Availability of power generation systems, accelerate the completion of efficiency enhancement projects ahead of schedule, and exercise prudent control over operating expenditure (OPEX) to mitigate the impact of the Ft rate freeze on the revenue of certain power plants. |
| Residual Risk Level | Low | Moderate |
| Risk Appetite | Accept low to moderate risk, provided that appropriate management measures and plans are in place to address climate-related impacts. | Accept moderate risk, supported by investment diversification and continuous monitoring of economic conditions, regulations, and government policies. |
| Risk Tolerance | Impact on revenue or overall operating results not exceeding 1%. | Impact on revenue, investment returns, or business expansion plans not exceeding 5%. |
Where monitoring results indicate that the Residual Risk is likely to exceed the organization’s Risk Appetite or has exceeded the defined Risk Tolerance, the Risk Owner prepares an additional risk management plan and reports it to the Enterprise Wide Risk Management Committee to determine appropriate control measures and closely monitor their implementation until the risk level returns within the thresholds defined by the organization.
Key Enterprise Risks
To reflect the risk issues to which the Company gives priority and continuously monitors, the Company prioritizes enterprise risks that may affect the achievement of its strategic goals by considering trends in the business environment, the likelihood of occurrence, potential impacts on the Company’s operations, and the status of Key Risk Indicators (KRIs) in order to determine appropriate risk management measures, as follows:
| Key Risk | Risk Category | Trend | Risk Management Approach |
|---|---|---|---|
| Volatility in electricity and natural gas prices | Financial Risk | Decreasing | Manage price risk through a Hedging Strategy and closely monitor energy market trends. |
| Counterparty creditworthiness | Financial Risk | Decreasing | Closely monitor the financial status of counterparties and manage accounts receivable. |
| Foreign exchange rate volatility | Financial Risk | Increasing | Manage foreign exchange risk and reduce exposure arising from foreign-currency loans and transactions. |
| Risk of impairment of assets and investments | Financial Risk | Stable | Monitor project performance and regularly review investment values. |
| Changes in business conditions and industry competition | Strategic Risk | Increasing | Review investment strategies and pursue new business opportunities aligned with the direction of clean energy development. |
| Competitiveness of investment projects | Operational Risk | Increasing | Enhance operational efficiency, control costs, and develop projects to maintain their long-term competitiveness. |
Project Risk Assessment Guidelines
In addition to assessing financial, operational, and regulatory risks, the Company requires all investment projects to consider environmental, social and governance (ESG) risks, as well as climate-related risks, to ensure that the projects are aligned with the Company’s sustainable growth strategy and do not cause significant impacts on stakeholders.
Before making an investment decision, the Company conducts project Due Diligence covering technical, financial, legal, environmental, social, and governance aspects to assess risks and opportunities that may affect the long-term viability of the investment.
Following investment approval, the Company requires project risks to be continuously monitored and reviewed throughout the project life cycle, from development and construction to commercial operation, to enable timely responses to changing risks and mitigate potential impacts on the Company’s performance.
Accordingly, investment project managers are required to conduct project risk assessments as part of proposals seeking budget or capital investment approval. They must prepare risk management plans aligned with the implementation timelines of the respective projects and assess the cost of the resources required to manage the risks. The project risk management plans must be endorsed by the Enterprise Wide Risk Management Committee before the investment proposals are submitted to the Board of Directors for approval.
Examples of Potential Risks in Each Project Phase
| Project Phase | Examples of Project Risks |
|---|---|
| Development | Delays in obtaining permits, community opposition, and regulatory changes |
| Design | Design errors and unsuitable technology |
| Construction | Accidents, contractor delays, and increased construction costs |
| Commissioning | Failure to pass system testing and delays in grid connection |
| Operation | Electricity generation below projections, natural disasters, cybersecurity risks, and changes in energy policies |
As part of the enterprise risk assessment and management process, Internal Audit reviews the effectiveness of the risk management, internal control, and corporate governance systems in accordance with the Risk-Based Internal Audit approach to provide assurance that material risks are appropriately identified, assessed, monitored, and managed. The audit results are reported to the Audit Committee and the Board of Directors to support the continuous improvement of the risk management system.
In addition, the Company is subject to audits and assessments by an External Auditor, as well as relevant certification bodies or independent experts, to enhance transparency and credibility and raise its risk management standards.
Emerging Risks
The Company recognizes the importance of identifying risk factors based on economic, social, and environmental trends to anticipate emerging risks that may arise in the future, as this is essential to its ability to adapt, respond, and maintain the sustainability of its business operations. The Company considers emerging risks arising from rapid changes across various dimensions at both national and international levels to identify risks directly related to its business operations and competitive advantage. Four key emerging risks have been identified, as follows:
Innovation Management
Category of Risk: Technological change
Risk Description

Possible Effects
- Opportunity costs and loss of invested capital if Vanadium Redox Flow battery technology becomes obsolete too quickly, which may prevent the Company from gaining efficiency and cost advantages in electricity generation and supply.
- Investment in or development of superior technologies by other power producers, which may reduce the Company’s competitive advantage.
- Declining investor confidence if the Company is unable to demonstrate its ability to apply technologies and capitalize on technological opportunities that could enhance its profitability.
Mitigation and Opportunities
- Pursue portfolio diversification across technologies, assess their feasibility and technological scalability, and regularly monitor market trends and demand drivers.
- Study and monitor the use of currently available technologies, such as Microgrids, Renewable Energy, Energy Storage, Big Data, and Smart Grids, to enhance the efficiency of energy management systems.
- Collaborate with major customers to provide P2P energy trading services and establish leadership in Digital Energy.
- Provide input to government agencies on the formulation of relevant policies and requirements, including the Subcommittee on Energy, the Power Development Fund, the Energy Regulatory Commission (ERC), the Electricity Generating Authority of Thailand (EGAT), the Metropolitan Electricity Authority (MEA), and the Provincial Electricity Authority (PEA).
- Design and develop systems to support services involving other technologies, including digital services, to comprehensively enhance the Company’s electricity generation capabilities in other areas.
Geopolitical Confrontation
Category of Risk: Geopolitical risk
Risk Description

Possible Effects
- Impacts on the continuity of business activities, including business interruption, if geopolitical risks and tensions intensify.
- Economic slowdown and changes in energy policies affecting stakeholders throughout the energy industry’s supply chain, which may delay investment in new projects.
- Declining revenue, profit, or business growth due to higher construction costs and deviations from the Company’s operating plans.
Mitigation and Opportunities
- Pursue portfolio diversification across types of renewable energy and countries of investment at both national and international levels to reduce geopolitical risk.
- Work with local partners in each country in which the Company operates to jointly develop businesses and regularly monitor changes in national policies and climate change trends to ensure comprehensive preparedness.
Cybersecurity and Digital Infrastructure Risk
Category of Risk: Cybersecurity and digital infrastructure
Risk Description

Possible Effects
- Disruption to electricity generation and supply.
- Loss or leakage of critical business information.
- Damage to the Company’s reputation and stakeholder confidence.
- Increased system recovery and operating expenses.
- Risk of non-compliance with data protection laws and requirements.
Mitigation and Opportunities
- Develop cybersecurity systems in alignment with international standards.
- Regularly test systems and assess cybersecurity vulnerabilities.
- Develop a Cyber Incident Response Plan.
- Enhance cybersecurity knowledge and awareness among employees and suppliers.
- Use digital technologies to enhance operational efficiency and create new business opportunities.
Climate Regulation and Carbon Market Risk
Category of Risk: Changes in climate regulations and carbon markets
Risk Description

Possible Effects
- Increased operating costs arising from carbon-related measures.
- The need for additional investment to comply with new requirements.
- Risk of failure to fully comply with applicable regulations.
- Potential impacts on the confidence of investors and financiers.
Mitigation and Opportunities
- Monitor developments in climate-related laws and policies in the countries in which the Company operates.
- Study and apply an Internal Carbon Price (ICP) in investment decision-making.
- Increase the proportion of investments in renewable energy and low-carbon technologies.
- Enhance climate-related disclosures in alignment with IFRS S2 and international standards.
- Pursue business opportunities arising from carbon markets and clean energy products.

Enterprise Risk Culture
The Company aims to promote risk management as an integral part of its corporate culture by encouraging employees at all levels to recognize the risks associated with their responsibilities and participate appropriately in identifying, reporting, and managing risks under the principle that “Risk is Everyone’s Responsibility.”
The Company encourages employees to openly and transparently report incidents, irregularities, concerns, or risk warning signs without concern about any negative consequences arising from such reporting. It also supports the application of Lessons Learned from past incidents to prevent recurrence and continuously enhance the effectiveness of enterprise risk management.
In addition, the Company integrates risk issues as part of setting performance targets, preparing business plans, making investment decisions, and evaluating new projects to ensure that business decisions comprehensively consider potential risks and opportunities.
Key Stakeholders
Investors/Shareholders
- Comprehensive and transparent disclosure and communication of material risks and emerging risks across all dimensions
- Enterprise risk management and Business Continuity Management (BCM) to address uncertainties arising from business operations
- Monitoring and management of geopolitical risks, exchange rate volatility, and changes in energy regulations in the countries where the Company invests
- Diversification of investments across countries and energy technologies to mitigate risks and generate sustainable returns
Employees
- Enhancement of employees’ risk management knowledge and capabilities to enable them to respond to crisis situations
- Provision of a risk management system and measures for responding to emergencies and crises
- Strengthening of Cybersecurity and information security awareness
- Emphasis on occupational health, safety, and a safe working environment
Suppliers
- Promotion of risk management and sustainable supply chain development in collaboration with suppliers
- Supplier Risk Assessments and monitoring of material ESG issues
Business Partners
- Regular communication and exchange of information on risks and risk management relating to joint business operations and investments
- Promotion of cooperation in innovation, technology, and strategic risk management to address changes in the energy industry
- Monitoring and assessment of the impacts of external factors that may affect joint business operations
Financial Institutions
- Monitoring and management of risks arising from fluctuations in renewable energy generation, including risks associated with changes in energy regulations and policies
- Monitoring and management of risks arising from fluctuations in renewable energy generation, including risks associated with changes in energy regulations and policies
- Preparation for ESG Risk Management and Sustainability-linked Financing to meet the requirements and expectations of financial institutions
- Development of infrastructure, technology, and risk management systems to strengthen competitiveness and support future business growth
Communities
- Listening to community opinions and concerns to assess risks and establish measures to prevent potential impacts
- Implementation of activities to build relationships and cooperation with communities to strengthen confidence and mitigate social risks
- Assessment and management of environmental and safety risks and impacts on the quality of life of communities surrounding the Company’s operating sites