Risk Management and Sustainability
Risk Management and Sustainability
Business Risk Management and Key Sustainability Risks
Risk Management Policy and Plan
The organization recognizes the intensifying pace of change and crises amid uncertainty and volatility across various dimensions, which may significantly impact the organization in economic, social, and environmental terms. The Company therefore prioritizes the establishment of systematic risk control measures to maintain risks within an acceptable and manageable level, enabling effective management through concrete monitoring, preparedness, and follow-up processes for relevant issues. This helps mitigate potential future impacts, ensures effective response when events occur, enables the achievement of organizational objectives, and supports sustainable management through the following sequential processes:
- The Risk Management Committee reviews and revises the policy annually to ensure alignment with appropriate risk management objectives and strategies. Significant policy updates are submitted to the Board of Directors for consideration and approval, with the most recent approval on July 25, 2025.
- Priority is given to risk management under the supervision of the Risk Management Committee in accordance with The Committee of Sponsoring Organization of the Treadway Commission (COSO) framework standards, encompassing Safety Due Diligence processes as part of strategic risk consideration for New Operations and Mergers & Acquisitions (M&A) to identify, prevent, and mitigate occupational health risks before commencing any new activities. The Company has also defined the structure and responsibilities of risk management oversight roles in accordance with The Three Lines Model, identifying three key roles as follows:
- Line 1 – Risk Owners: Comprises executives, employees of the Company, and various risk management working groups, who are representatives of operational units responsible for assessing risks that may occur in their areas and across the organization that could impact operations, and are accountable for managing those risks.
- Line 2 – Risk Management Committee: Appointed by the Board of Directors to establish a risk management policy covering the entire organization, oversee the implementation of risk management systems and processes to appropriately reduce business impacts, and monitor the progress of management by various working groups to ensure that the Company has adequate systematic risk management processes in accordance with established standards.
- Line 3 – Internal Audit: Responsible for evaluating and improving the effectiveness of risk management processes, controls, and governance, supporting management and the Board of Directors to reduce existing risk issues and minimize the probability of future occurrences.
- The Risk Management Committee holds meetings to review the policy and monitor progress in the assessment and management of key company risks. Executives and representatives of Key Risk Teams who are the primary risk owners report to the Risk Management Committee meetings to monitor and ensure systematic risk management processes that are adequate to established standards.
Integration of Climate Risk Management
Modernform focuses on elevating its risk management system to be more comprehensive and responsive to global circumstances. The Company has a climate risk management process as follows:
- Integration with the Core Risk Management System
The Company designates climate change risk as part of the enterprise-wide risk management system. Such risks are identified, assessed, and reported at the same level as strategic and other operational risks through the oversight of the Risk Management Committee, to ensure that business decisions at all levels thoroughly consider climate factors.
- Specific Risk Management Process
Beyond the normal ERM process, the Company has established specific procedures for climate risks in accordance with TCFD guidelines as follows:
- In-Depth Risk Classification: Specific procedures are in place to categorize risks into transition risks (e.g., changes in government policy and carbon taxes) and physical risks (e.g., impacts of flooding on production bases and supply chains).
- Scenario Analysis: The Company uses a climate scenario analysis process at global temperature increases of 2°C and above (referencing IEA and IPCC criteria) as a specific tool for assessing impacts on business strategy.
- KPI Monitoring: Greenhouse gas emissions are designated as one of the risk indicators that must be reported to management periodically to evaluate the effectiveness of ongoing adaptation and mitigation measures.
Section 1: New Initiatives and Key Issues for 2025
Enterprise-wide Risk Management Enhancement
The Company places great importance on the mechanisms driving serious risk management and has implemented plans through the activities of the Risk Management Committee and Internal Audit. The objective is to ensure that executives across all functions within the organization can understand and be aware of risks, identify and assess risks to a unified standard, and effectively manage them within acceptable risk parameters. In 2025, the following steps were implemented sequentially:
- The Risk Management Committee has prepared and distributed the Risk Management Manual of Modernform Group Public Company Limited to all members of the organization, comprising employees, executives, directors of the Company, and subsidiaries, to serve as a systematic tool and guideline for risk management. This will foster management processes that reduce risks and achieve performance targets, generating maximum benefit to the organization.
- The Company strengthens understanding and awareness of risk management and internal controls through the following activities:
- The Internal Audit function organized an In-house Training course on the topic of Internal Control Processes and Risk Management for executives and employees, to build understanding of risk management principles and practices that can be applied in real operations, enabling effective organizational risk management. The course format included lectures, case study examples, activities, and knowledge exchanges to facilitate easy understanding and learning. A continuous training plan has been developed for the following year to cover all employees, executives, and directors.
- The Human Capital Management function supports employees, executives, and directors in self-directed learning through the Modernform Online Self Learning program and designates this as an ESG MISSION Possible 2025 mandate, driving the development of learning capability through the ESG DNA course from the Stock Exchange of Thailand, to raise awareness and understanding of ESG risk management and sustainable business development.
- The Company has developed an online course on Business Ethics and Anti-Corruption, which is a key course that everyone must complete. The Company targets 100% employee participation and course completion to ensure that all employees share a common understanding and can apply it in practice in all situations, thereby reducing related risks that may arise.
- In accordance with the 2025 annual audit plan, the Internal Audit function presents topics on the significance of risk at every audit opening meeting to highlight the importance of driving organizational culture and risk awareness, and to incorporate risk assessment into the audit approach. Department executives and key personnel prepare risk checklists and assess risks according to the various components of COSO-ERM, producing risk level assessment results and prioritization based on the Risk Matrix for management of key functional areas, such as Sales Management – Project Sales, Supply Chain Management – Production Planning, Factory Operations Management – Production, and Corporate Excellence Management – Procurement, among others.
- The Company has incorporated risk topics into the Smart KPI Alignment Program development process, integrating risk management as part of the Performance Management System (PMS) evaluation to ensure that all relevant parties recognize its importance and manage it in a more concrete manner.
- In the preparation of the annual strategic plan, the Company incorporates risk assessment and management topics to analyze factors that may impact operational performance and future objectives across economic, social, and environmental dimensions, including major crises, into future action plans. This is to ensure that the Company can manage and achieve its objectives in both the short and long term, including sustainability risk assessment.
Section 2
- Factors Affecting the Company's Business Operations and Key Sustainability Risks
- Continuous Reporting of Risk Issues from 2024 through Management and Performance in 2025








Business Continuity Plan- Business Interruption
Unexpected events posing threats to the organization or its stakeholders — in order for the organization to continue conducting activities or business normally without disruption, the Company remains vigilant and systematically assesses factors that may cause business interruption, considering causes of disruption arising from the following factors:
- Risks from natural disasters and various accidents, such as floods, power outages, and fires.
- Risks from cyber threats and threats to critical data or operating systems, including vigilance regarding AI risks and its safe and effective use.
- Risks from the outbreak of new infectious diseases, and national or global situations causing business stagnation, including political and economic conflicts or impacts on continuous business operations.
Plans and Actions
The Company recognizes the importance of managing risks related to unexpected events that may occur and have severe impacts. Therefore, the Company prioritizes preparedness and the development of a Business Continuity Plan, according to the following key management processes:
- Continuous monitoring of the overall situation, encompassing economic, political, environmental, and other factors that may affect the Company's business continuity.
- Regular risk assessment and the development of risk management plans for new risk factors.
- Developing a Business Continuity Plan in the event of business stagnation.
- Establishing contingency measures for potential events, covering critical business data, operating systems, information systems, assets, and personnel involved, including necessary drills to ensure preparedness at appropriate intervals.
- Elevating the information security management system: The Company has obtained ISO 27001:2022 certification to enhance confidence in information security protection, prevent threats and potential damages, and reduce data breach risks. This enables the organization to continuously improve its information systems, protect its reputation from information security threats, ensure compliance with data protection requirements, and build trust and credibility with the organization and customers, while creating greater competitive advantage in the future.
Emerging Risk Management
- Emerging Risk Factors


Internal Controls and Anti-Corruption
- The Company has developed an online course on Business Ethics and Anti-Corruption, which is a key course that everyone must complete. The Company targets 100% employee participation and course completion to ensure that all employees share a common understanding and can apply it in practice in all situations, thereby reducing related risks that may arise.
- The Internal Audit function conducts audits in accordance with the plan and reviews internal controls across various processes, including an annual audit plan for anti-corruption and fraud prevention systems, with random transaction sampling processes related to various system audits. This also covers operational audits of all departments to ensure compliance with relevant requirements and regulations, with review and improvement processes for internal controls conducted with the responsible departments to ensure that operational systems are adequately effective.