Icon

Risk Management
and Crisis Management

Risk Management Structure

           The Company has established a risk management structure to ensure that risk management processes are carried out effectively and efficiently, while maintaining risks within an acceptable level. The Company has appointed a Risk Management Working Committee responsible for overseeing, monitoring performance, providing recommendations, and offering guidance to relevant internal operating units. The Risk Management Working Committee is also responsible for reporting risk management performance results to the Executive Committee and the Risk Management Committee, which is chaired by an Independent Director. In addition, the Company has an independent Internal Audit function responsible for assessing the adequacy and effectiveness of the organization’s internal controls and overall risk management practices to ensure that they are properly established, sufficient, and appropriate. The risk management structure is divided into three levels as follows
           1. Operating Units (First Line of Defense) The first line of defense consists of the heads of eight departments, who are responsible for overseeing, controlling, and initially monitoring risks arising within their respective areas of responsibility. The operating units comprise various departments within the Company, including the Sales and Marketing Department, Production and Service Department, Supply Chain Department, Procurement Department, Human Resources Department, Accounting and Finance Department, Information Technology Department, and Company Secretary Office.
           2. Committees and Management (Second Line of Defense) The second line of defense consists of C-Level executives who are responsible for establishing policies, rules, and standards, as well as providing oversight and advisory support to various operating units. Their responsibilities include communicating and transferring knowledge regarding established policies, rules, and standards, as well as developing policies and procedures to ensure that business operations comply with the defined requirements and standards.
          3. Independent Function (Internal Audit) (Third Line of Defense)The third line of defense consists of the Internal Audit function, which is responsible for assessing and reporting on the adequacy and effectiveness of the organization’s internal controls and overall risk management practices. The Internal Audit function independently evaluates whether the internal control systems and risk management processes are properly established, sufficient, and aligned with the requirements and objectives defined by the Company.

Risk Appetite
Risk Assessment Process
Risk Appetite
Risk Level Determination Based on the Risk Matrix

            The Risk Management Working Committee consists of the Chairman of the Risk Management Committee, representatives from various departments, and designated Risk Owners. Together, they are responsible for assessing risks and prioritizing risk levels based on two key factors: the likelihood of occurrence (Likelihood) and the potential impact (Impact), as illustrated in the following chart.

Risk Appetite








Acceptable Risk Level (Risk Appetite) and Acceptable Risk Deviation Range (Risk Tolerance)
Risk Appetite







Risk Level Assessment

           The risk level is determined by comparing the identified risks against the established criteria. The process includes risk identification, risk analysis, and risk prioritization by assessing the likelihood of occurrence (Likelihood) and the level of impact (Impact) on business operations, both directly and indirectly. The results of the assessment are used to prioritize risks and determine appropriate risk management actions. In addition, Key Risk Indicators (KRIs) must be established as early warning signals to alert relevant parties and enable them to respond to potential risks effectively and in a timely manner. The assessment is conducted by evaluating the Likelihood Score and Impact Score for risk factors across all five risk categories.