Supporting the Sustainable Development Goals (SDGs)

Decent Work and Economic Growth
Decent Work and Economic Growth
Climate Action
Climate Action
Peace, Justice and Strong Institutions
Peace, Justice and Strong Institutions

Goals and Performance Highlights

Goals

%
of employees possess awareness of risk management
Conduct a review of Emerging Risks & ESG Risks at least once per year
Adopt COSO ERM 2017 covering enterprise-level risks

Performance

No severe risk incidents affecting business operations
Establish a Risk Management Committee, with at least
meetings per year
Develop BCP, DRP, and conduct Crisis Simulations
%
of all employees demonstrate risk management awareness
Organize activities to promote a risk management culture within the organization
Conduct a regular review of the Risk Management Manual

Commitment, Challenge and Opportunity

The Company has adopted the COSO ERM 2017 risk management framework, an international standard, as the core guideline for enterprise risk management. This ensures that the processes for identifying, assessing, controlling, and monitoring risks are systematic, comprehensive, and aligned with all dimensions of the Company’s business operations. The organization has established a Risk Appetite that is linked to its business strategy, serving as a guideline for decision-making by executives and related departments. This helps ensure that risks are managed efficiently and maintained within an acceptable level.

In addition, the Company has appointed a Risk Management Committee responsible for overseeing, monitoring, and reporting risk management performance to the Board of Directors at least twice a year. This is to ensure transparency and credibility in the governance process. The Company has also established a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) to ensure preparedness for potential emergency situations. These plans enable the Company to maintain uninterrupted business operations and strengthen the confidence of all stakeholders.

The Company’s real estate business faces challenges arising from a wide range of external and internal factors. In particular, economic conditions and fluctuating interest rates, which directly affect customers’ purchasing power as well as the Company’s capital costs. In addition, increasingly stringent and rapidly evolving regulations and requirements related to Environmental, Social, and Governance (ESG) exert pressure on the organization to continuously adapt both in operational practices and in data reporting. Another significant challenge is Climate Risk, including floods, earthquakes, severe storms, and air pollution, all of which directly impact construction activities and real estate project operations. At the same time, greater reliance on digital systems exposes the Company to heightened cybersecurity threats that could affect data integrity and service continuity. Furthermore, the Company also faces Emerging Risks, which are difficult to predict, For example, changes in demographic structure, climate change, and supply chain disruptions. These risks may affect the Company’s adaptability and long-term business sustainability.

The Company recognizes the potential risks and opportunities that may arise in the future. The Company integrates ESG considerations and Climate Risk into its enterprise risk management system to manage risks and create opportunities for developing new work processes and products that address those risks. This approach builds confidence among stakeholders and investors that the Company manages risks comprehensively and remains responsive to social and environmental changes. In addition, the Company incorporates resilience into project design, such as allocating green spaces, implementing rainwater retention systems, and developing internationally certified green buildings. These measures not only help reduce environmental impacts but also enhance the value of the projects in the eyes of customers and investors. Furthermore, collaborating with suppliers and partners across the supply chain to jointly manage environmental and social risks represents another opportunity to create shared value and raise the standard of sustainable business operations. Strengthening transparency and good corporate governance through proactive risk management also supports the Company’s reputation in the capital market, increases credibility, and reinforces long-term organizational sustainability.

Strategies and Management Approaches

The Company is committed to establishing a systematic, efficient, and internationally aligned risk management system. The Company adopts the COSO ERM 2017 Enterprise Risk Management Framework as its primary guideline to ensure that risks are identified, assessed, controlled, monitored, and responded to appropriately, enabling continuous business operations in a rapidly changing environment.

The Company also defines a Risk Appetite that aligns with its organizational strategy and uses it as a decision-making guideline for executives at all levels, from the Board of Directors to operational departments. A Risk Management Committee has been established to set and review the risk management policy, the Risk Management Committee Charter, the Enterprise Risk Management Framework, and the risk management processes. This ensures that the framework remains up to date with changing conditions and is suitable for business operations. The committee also provides recommendations on risk management approaches that align with the Company’s strategic direction and business plan, enabling Risk Owners to manage key risks within the acceptable level (Risk Appetite). This ensures that the Company maintains adequate and effective risk management in accordance with international standards (COSO ERM 2017), while continuously supporting the development of risk management practices at all levels to foster a strong risk management culture throughout the organization.

Assessing the risk level, determining risk appetite, and identifying key risk indicators (KRIs)

Upon identification of risk issues concerning corporate sustainability, the risk management unit will propose key risk issues to the Risk Management Committee for consideration, so as to assess risk level, determine risk appetite, and identify the KRIs.

The Company determined risk appetite, which is represented by green and blue zones. Risk appetite of each issue was determined by taking into account: 1) stakeholders’ needs; 2) corporate strategic objectives; 3) factors for creating corporate value; and 4) risks that may affect corporate objectives (such as mega trends).

Risk tolerance level is represented by the yellow zone. If any risk issue scores within the yellow zone, or any zone representing higher levels (orange and red zones), the risk management unit must find a way to mitigate that issue to an acceptable level (risk appetite).

Severity levels Table presenting severity levels of risks
Very high

Very high severity level - high

There should be high control with close monitoring and regular evaluation. Also, additional methods should be sought to reduce the likelihood and impact to be at acceptable level.

High
Moderate

Moderate level of severity

Risks with a control or management plan in place should take into consideration cumulative impact that may escalate.

Low

Low severity level - very low

Risks accepted by the organization that may not require managing action should be assessed periodically to prevent cumulative impact from escalating.

Very low
Table showing the assessment of likelihood and impacts of each sustainability issue
Dimensions Sustainability Risks
Economic 1. Supply Chain
  1. Disruptions in the supply chain and loss of bargaining power due to reliance on large or too small number of suppliers/distributors.
  2. Shortage of skilled labour.
2. Tax-related operations Incorrect or incomplete tax filings.
3. Business and Social Innovation Lack of monitoring and promotion for the actual implementation of award-winning innovations by relevant departments.
Environmental 4. Biodiversity and Ecosystem Conservation Ecosystems/environment may be affected by the construction in the project, leading to a loss of biodiversity.
5. Resource and Waste Disposal Management Employees may lack continuous and sustainable implementation of daily efficient resource use, energy-saving, and waste management practices.
6. Climate Action
  1. Guidelines or activities set by relevant agencies may not align with carbon footprint reduction goals.
  2. Insufficient knowledge and understanding among responsible agency representatives (Center) in gathering data, communicating with consultants, and educating their teams.
Social 7. Consumer Responsibility Product quality may not the Company’s meet standards.
8. Community and Social Development Inconsistent execution of community and social development initiatives.
9. Respect for Human Rights and Fair Treatment of labour
  1. The Company may treat employees unfairly, Discrimination, resulting in a decrease in their quality of life and safety, leading to litigation and affecting the Company’s reputation.
  2. Failure to consider rights, diversity, and inclusion in Company’s processes such as recruitment, selection, training and development), as well as compensation and benefits, leading to gender, age, religion, and nationality discrimination that could impact the Company's image.
10. Capacity Enhancement for Employees and Workers in Work and Daily Life.
  1. Employee development may not cover the development of required competencies for each job position, leading to a lack of essential skills and knowledge for work and for leading daily life.
  2. Supervisors may lack a structured approach to developing employees in alignment with competency requirements.
11. Safety, Occupational Health and working
  1. Employees failing to comply with safety regulations, rules, or manuals.
  2. Unsafe work environments, working procedures and supervision.
Governance 12. Corporate Governance Operations may not comply with stock exchange standards and external regulatory bodies.
13. Risk Management The organization's risk assessment may not cover key emerging risks.
14. Anti-Corruption Operations may not comply with the criteria of the Thai Private Sector Collective Action Coalition Against Corruption (CAC).
Risk Mitigation Plan

The Risk Management Committee may propose additional risk mitigation measures beyond those implemented by business unit executives. This includes providing recommendations and assigning relevant executives to take action within a specified timeframe to ensure that risks are managed to an acceptable level. Subsequently, the risk management team will monitor and review the implementation progress and report to the Risk Management Committee monthly via a Line Group. Additionally, the Committee shall hold meetings, including subcommittee meetings, at least four times a year to review and assess risk issues. This ensures that risk management is conducted swiftly and continuously within the established framework.

The Company regularly reviews and assesses risks that may have a significant impact on its business operations through meetings of the Risk Management Committee and the Risk Management Sub-committee. These committees comprise executives with relevant knowledge, expertise, and experience, including executives responsible for legal affairs and corporate governance and compliance, namely, Mr.Krid Chancharoensuk, Senior Director of Legal, and Ms. Toopthong Hirunyanulak, Director of Corporate Governance Compliance & Quality System. Their responsibilities include jointly reviewing and monitoring risk management activities and reporting performance results and key risk issues to the Board of Directors on an annual basis.

Key Sustainability Risks of the Company

The Company adopts the standards of the International Sustainability Standards Board (ISSB) as a framework for identifying and managing sustainability-related risks and opportunities, ensuring alignment with its enterprise risk management approach. Sustainability-related Risks and Opportunities (SROs) are integrated into the Company’s Enterprise Risk Management (ERM) process to support the assessment and monitoring of risks that may affect its business operations.

The assessment process begins with an analysis of the Company’s organizational context and external trends, including climate change, regulatory developments, geopolitical tensions, information technology and social media, and stakeholder expectations, alongside benchmarking against international standards and indices. The Company then identifies and assesses sustainability-related risks and opportunities across its value chain, considering both financial impacts and impacts on the environment and society in accordance with relevant international frameworks. The assessment results are subsequently integrated into the Company’s enterprise risk management system to facilitate the systematic monitoring and management of sustainability-related risks.

These issues reflect key risks that may affect the Company’s business operations across the economic, environmental, and social dimensions. The Company continuously monitors and manages these risks within its enterprise risk management framework.

In 2025, two meetings of the Risk Management Committee were held, utilizing various risk assessment tools such as the Risk Map and Risk Radar Chart to evaluate risks across different areas and present the results to the Committee. In addition, the Company monitored, assessed, reviewed, and approved of the Risk Management Plan, which covers all significant categories of risks, and reported the risk management outcomes to the Board of Directors. These risks include:

Strategic Risk
Operational Risk
Financial Risk
Compliance Risk
Corruption Risk
Market Risk
Cyber Risk
ESG and Climate Risk
Emerging Risk

The Company places great importance on strengthening a risk management culture throughout the organization. All employees are encouraged to recognize the significance of risks and actively report any identified risks through designated channels, such as riskmgt@supalai.com . Risk topics are integrated into discussions in all meetings. The Company has also established a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) to ensure operational continuity in the event of emergencies or disasters.

The Company's risk management policy and plan reflect its strategic readiness, the integration of risk management into its organizational structure, and its strong commitment to transparency and accountability. These practices help build trust among shareholders, investors, business partners, and all stakeholders.

Enterprise Risk Management Plan

The Company conducts annual reviews and assessments of significant business risks through meetings of the Risk Management Committee, which is composed of experienced and knowledgeable executives. The Company utilizes tools such as the Risk Map and Risk Radar Chart to analyze risk interrelationships and prioritize urgent risks, ensuring efficient resource allocation. Appropriate risk mitigation measures and management plans are then developed in alignment with the Company’s strategic goals and presented to the Board of Directors. Each business unit is assigned responsibility for managing and reducing its risk levels to within an acceptable threshold (Risk Level), thereby supporting the successful achievement of the Company’s strategic plan.

Risk Management Culture

The Company is committed to cultivating a strong risk management culture among employees at all levels across the organization. This is achieved through continuous mindset development to ensure that everyone recognizes the importance of the Company’s risk management processes and can naturally and consistently apply them effectively in their daily work.

The process begins with leadership, comprising the Board of Directors and executives at all levels, who serve as role models in reinforcing risk management practices. Their leadership helps instill shared responsibility and supports employees in applying risk management knowledge to risks related to their roles.

The creation of a risk management culture focuses on equipping employees with the knowledge, understanding, and capability to manage associated risks naturally. Executives at every level play a crucial supporting role in driving organizational change and promoting sound frameworks that enable rapid identification and effective management of risks. The objective is to support the Company’s goals, vision, and mission.

The Successful Factors of Creating a Risk Management Culture Consist of 3 Aspects

To serve as a tool for fostering a positive work environment alongside the effective management of risks that may impact the Company in a timely manner, thereby supporting long-term business sustainability, the Company places strong emphasis on promoting a risk management culture across the entire organization. This ensures that the Company achieves stable and sustainable growth through cultivating a risk-aware culture grounded in risk management policies and frameworks, risk management structures, governance mechanisms, and continuous monitoring of risk management progress at all levels.

The Company has established guidelines for strengthening its risk management culture and mandates their application to employees at all levels. Additionally, the Company communicates the objectives and benefits of organizational risk management to all employees. These guidelines consist of six key components, as follows;

Risk Management Culture Guidelines
1
Risk Governance
Risk governance begins with establishing a risk management policy that covers emerging risks that may arise both in the present and in the future. The Risk Management Committee holds at least two meetings per year and monitors the implementation of the risk management plan on a monthly basis. The Risk Management Department tracks and reports the performance of each risk-owning business unit to the Risk Management Committee in order to evaluate and review the risk management plan, ensuring that risks are quickly and appropriately reduced to an acceptable level.
2
Leadership
Executives and the Board of Directors should place strong emphasis on risk management by setting policies and practices for managing risks at every level of meeting. The Chairman of the Board stipulates that all meetings must include the following practices:
  • A risk review agenda must be included as one of the mandatory discussion items.
  • The meeting chair shall raise risk-related issues at every meeting to build awareness and maintain continuous importance of risk management.
  • Risk management actions must be closely monitored and implemented in a concrete manner, with ongoing agenda items for reporting follow-up on resolutions related to risk management.
  • The meeting chair must report the results of risk management actions to the next level of meeting.
3
Risk Management Structure
The Company establishes a unified risk management framework across the organization in accordance with international best practices (COSO ERM 2017). All risk management activities must comply with this standardized approach and be implemented consistently throughout the organization.
4
Risk Management

The Company applies risk management techniques in alignment with academic principles and integrates psychological approaches to enhance effectiveness, as follows:

  • The Company adopts the COSO ERM 2017 framework and ISO 9001:2015 standards as tools for risk identification, risk assessment, risk management, and monitoring and reporting. Key Risk Indicators (KRIs) are also used as early warning signals to support preparedness and proactive prevention measures in cases where there is an increasing likelihood or potential impact of risks
  • Conducting internal quality management system audits by employees appointed as Internal Quality Auditors (IQA), focusing on process-level assessments. The audit scope covers ESG-related risks (E = Environment, S = Social, G = Governance), including safety risks that may directly or indirectly affect stakeholders, along with identifying appropriate risk mitigation measures.
  • Promoting a risk management culture among supervisors by requiring them to perform self-assessment (Self-Declared) every two years.
  • Measuring the effectiveness of the risk management culture by having subordinates evaluate their supervisors every two years.

The objective of the activity is to raise risk management awareness among no less than 80% of employees. The results showed that 95% of employees demonstrated awareness of risk management. The top three areas in which employees rated their supervisors/managers the highest are as follows.

  • Supervisors prioritize risk management and effectively communicate risk management knowledge for practical application in daily work.
  • Employees are informed about organizational-level risks and receive detailed risk-related information from their supervisors and/or senior management.
  • Supervisors actively listen to employees’ input and use it for risk management in their work.
5
Risk Communication
Risk-related communication is carried out continuously, incorporating both internal and external factors. This helps raise employee awareness regarding the need to monitor and prepare for potential risks. Risk issues are widely discussed in meetings, and a positive meeting atmosphere is encouraged for example, allowing subordinates to express their opinions constructively and ensuring equal opportunity for everyone to provide input.
6
Dissemination of Risk Management Knowledge
Employees at all levels receive knowledge related to risk management through various resources, such as the Risk Management Manual, onboarding training for all new employees, mandatory online courses (E-Learning), risk-related communications via email and the Supalai Connect system, and an annual basic risk-management knowledge test. These efforts aim to broaden awareness and understanding of risk management across the organization. In addition, The Company promotes a strong risk management culture throughout the organization by supporting various related projects.

Agile Transformation and the Development of Risk Management Processes

The Company has adopted Agile principles within the organization to enhance and modernize its risk management processes. Key examples include:

360° Risk Management
Through Agile’s emphasis on communication and cross-functional collaboration, risk perspectives are shared among employees with diverse expertise. This leads to a more comprehensive and well-rounded approach to risk management.
Risk Management Throughout the Workflow
Continuous delivery and rapid feedback throughout the work process enable ongoing review of risks. This approach aligns with today’s fast-changing environment in terms of technology, regulations, and consumer behavior.
Risk Management In-Process
The rapid and continuous development and improvement of work based on stakeholder feedback enables automatic risk management throughout the workflow. This reduces reliance on complex risk management tools and techniques and encourages employees to naturally adopt a risk-aware mindset through real-world practice.
The Executive Committee
Encourages employees at all levels to express their opinions by providing a direct channel to communicate with the committee.

Stakeholders Directly Impacted

Shareholders / Investors
Shareholders / Investors
Positive Impacts
  • Gained confidence that the Company has a risk management system aligned with international standards, is transparent, and supports sustainable growth.
Expected Impacts / Risks
  • Expect consistent returns, require transparency in information disclosure, and the Company’s capability to manage economic and regulatory risks.
Customers
Customers
Positive Impacts
  • Confident in project quality designed to address environmental and disaster risks such as flooding and green buildings.
Expected Impacts / Risks
  • Expect safety, construction quality, and project continuity even during crisis.
Employees
Employees
Positive Impacts
  • Received training and a risk-aware culture, with BCP/DRP systems in place to ensure operational stability.
Expected Impacts / Risks
  • Expect job security, crisis-impact mitigation, and strong cybersecurity management.
Suppliers / Contractors
Suppliers / Contractors
Positive Impacts
  • Received support to jointly enhance risk management and ESG systems, raising standards across the supply chain.
Expected Impacts / Risks
  • Expect fair selection, responsible risk management without burden-shifting to suppliers, and timely payments.
Community / Society
Community / Society
Positive Impacts
  • Benefited from projects designed to reduce environmental impacts and include disaster-prevention measures.
Expected Impacts / Risks
  • Expect the Company to manage environmental risks such as dust, wastewater, flooding, and to communicate transparently.
Government Agencies and External Parties
Government Agencies and External Parties
Positive Impacts
  • Saw compliance with laws and regulations, reducing non-compliance risks.
Expected Impacts / Risks
  • Expects accurate reporting aligned with frameworks such as GRI, TCFD, environmental laws, and anti-corruption measures.