Innovation for Sustainability
Innovation for Sustainability
Modernform regards innovation and digital technology as key mechanisms for creating competitive advantage. Innovation investment in 2025 therefore focused on elevating operational efficiency, creating products that address well-being needs, and reducing environmental impacts (GRI 3-3).
Approach to Innovation Management for Developing a Learning Organization
- Digital Innovation and AI-Driven Operations
The Company has established an AI Transformation strategy to transition traditional work processes to AI-driven operations, with the primary objective of enhancing in-depth data analysis capabilities and resource management.
- AI Governance: The Company places importance on the ethical governance of artificial intelligence usage, assigning the Information Technology (IT) function as the primary unit for oversight and inspection to ensure that AI technology deployment complies with the AI policy framework and the organization's information security standards. An AI Use Case Evaluation Checklist is used as a standard tool for project assessment prior to implementation to prevent personal rights violations and processing bias. Furthermore, work processes and digital risk management are managed and monitored through regular functional meetings to ensure the AI Transformation strategy aligns with the business direction and internal control standards.
- Security Policy: The Company has established an Artificial Intelligence Security Policy (AI Security Policy) in the organization's information management system as a practical guideline for employees to use AI safely and in compliance with the organization's information security standards.
- Personnel Development: The Company implements Upskill and Reskill employee programs through AI Literacy courses to build awareness and usage skills. The Company's IT team also participated in Internal Control Process & Risk Management training to apply the SIPOC model (Supplier, Input, Process, Output, Customer) to analyze and improve work processes for greater transparency and reduced errors.
- Case Studies in Practical Application
- Procurement: Using AI to analyze Terms of Reference (TOR) specifications and quotations to compare conditions and pricing with greater accuracy.
- Logistics: Applying Generative AI in delivery route planning to reduce distances, energy consumption, and greenhouse gas emissions.
- Information Security
In 2025, Modernform achieved a significant milestone in elevating its security standards to international levels.
- ISO/IEC 27001:2022 Standard: On November 4, 2025, the Company received the Information Security Management System (ISMS) certification from BSI (British Standards Institution).
- Scope and Benefits: The certification covers critical data control processes and cyber risk management, building confidence for customers and stakeholders that personal data (PDPA) and business data will be protected under a system with continuous international standard monitoring over 3 years.
- System Development to Support Operations
Elevating digital infrastructure is central to supporting fast and secure operations.
- ERP Upgrade (MOS): The Company has migrated its system to Oracle 19 Cloud and is preparing to develop to Oracle Version 26ai, which specifically supports AI technology, enabling faster and more stable data processing in accounting, production, and procurement systems.
- Data-Driven Organization: Through a Power BI training program to build a data-driven decision-making culture. In 2026, real-time reporting Dashboard creation will be extended to both new and existing employees to ensure the project achieves sustainable practical outcomes.
- Data Security Governance (PDPA): The IT team collaborates with the Legal department in developing a personal data storage system and a digital consent management system. The project is currently over 70% complete, in the process of selecting the highest security standard solutions from external service providers, to ensure the system complies with the PDPA Committee's requirements and international security standards.
- Ongoing Progress and Development
The Company has tracked the performance of innovation projects initiated since 2024 to further develop in 2025 as follows:
Future Innovation Projects (Roadmap 2026)
- Data Platform: Develop an organizational data hub for strategic analysis.
- Automation/RPA: Elevate repetitive work processes to automation to reduce manual process errors.
- Project Management System: Build a real-time project status tracking platform to increase management transparency.
Cybersecurity and Personal Data Protection
Elevating Security Standards
- Cybersecurity Management Strategy
The Company focuses on building a secure digital ecosystem by integrating international standards into every step of work processes, to support the transition to Cloud systems and the adoption of AI within the organization.
- ISO/IEC 27001:2022 Standard: In 2025, the Company successfully elevated its Information Security Management System (ISMS) to receive ISO/IEC 27001:2022 international standard certification from BSI on November 4, 2025, covering control processes, risk management, and critical organizational data protection.
- DevSecOps Infrastructure: The Company has integrated Security as part of the system development lifecycle, particularly in the ERP upgrade to Oracle 26ai, to ensure that every newly developed feature is stable and protected from external attacks.
- AI Security Policy: Established the Artificial Intelligence Security Policy No. MIT/2025/001 to control risks from the use of AI and Generative AI technology within the organization.
Dashboard showing 3-layer customer data protection measures

Elevating Personal Data Protection
In 2025, Modernform elevated its personal data management to be more transparent and rigorous in protecting the rights of customers, suppliers, employees, and all stakeholder groups. The Data Protection Officer (DPO) announced and enforced 3 important policies and operational manuals as a single standard across the entire organization, as follows:
- Standard Operating Procedure for the Acquisition, Access, and Processing of Personal Data
The Company establishes data access control measures based on a 'Need-to-know basis' principle in both physical and digital formats, with defined data retention periods and secure data destruction, to prevent data from being used for purposes other than intended or from violating data subject rights.
- Privacy Notice
The Company transparently communicates the purposes of collecting, using, and disclosing data by preparing Privacy Notices covering customers, suppliers, job applicants, and employees, to ensure that data subjects are fully informed of their legal rights.
- Personal Data Breach Incident Notification Procedure Manual
The Company has prepared an incident response and emergency containment plan, defining clear operating procedures covering everything from severity screening through to the use of standardized incident report forms, to enable the team to systematically screen and manage incidents in a traceable manner.
- Digital Consent Management
The Company is in the process of developing a personal data storage and Digital Consent Management system to elevate data subject rights management effectiveness. The project is currently 70% complete, in the process of evaluating specialized software with external experts.
Emergency Response and Breach Incident Reporting
The Company has established cybersecurity incident response procedures, with relevant team training to enable timely analysis and incident containment. For personal data breach incidents, the Company has defined incident reporting pathways where the Data Protection Officer (DPO) will assess impacts and report to the Risk Management Committee or Audit Committee. In cases of high-risk breaches or those significantly impacting the Company, the Board of Directors will be notified immediately to report to the Personal Data Protection Committee (PDPC) and notify data subjects as required by law.
Performance Results in 2025
Following the implementation of strict measures, the Company found no complaints or cases of personal data breaches from either regulatory authorities or external parties (GRI 418-1).
Performance Summary for 2025
Future Outlook
Modernform is committed to elevating itself to become a digitally transparent organization, with plans in 2026 to integrate a more effective and accurate personal data management database system, to support data subjects' rights quickly in accordance with international standards. The Company also targets expanding cybersecurity and personal data protection awareness-building to cover all organizational personnel, to build a culture of data responsibility and sustainably maintain stakeholder trust.