PRTR is committed to operating its business stably and sustainably, thus recognizing the importance of organizational risk assessment. It regularly reviews and develops risk management plans under conditions of uncertainty, including rapidly changing social, economic, environmental, and technological aspects. For business operations to be sustainable and achieve organizational goals, risk management is a crucial foundation, encompassing risk identification, risk assessment, and the establishment of measures for regular control, monitoring, and review of risks. This ensures that if new risks arise, the Company can manage them within acceptable limits. To ensure that various departments within the Company have a consistent approach to risk management, PRTR has established guidelines in accordance with PRTR's risk management policy as follows:
The Company has developed its risk management in accordance with good corporate governance principles based on the Three Lines Model framework of the Institute of Internal Auditors (IIA) and international risk management standards such as COSO ERM 2017, by clearly defining the roles and responsibilities of the Board of Directors, management, and various departments as follows:
1. Board of Directors
The Board of Directors is responsible for the highest oversight of risk management, approving policies, frameworks, and acceptable risk levels, as well as monitoring risks that may significantly impact the Company, including strategic, operational, technological, data, and ESG risks, as well as risks from new projects or due diligence, to ensure that the Company has an appropriate risk management system that supports sustainable business operations.
2. Audit and Risk Management Committee
The Audit and Risk Management Committee is responsible for independently overseeing, monitoring, and reviewing risk management, and reviewing the adequacy of internal control systems. establish a working group, and appoint independent consultants with knowledge and expertise to provide advice, recommendations, and assistance to the Audit and Risk Management Committee in its operations. Assess information received from management ( First Line), Risk Management Department (Second Line), and Internal Audit (Third Line), and report to the Board of Directors at least twice a year to support a robust, reliable, and transparent risk management system.
3. Executive Committee
The Executive Committee is generally responsible for the organization's risk management, considering and approving risk management policies, and submitting them to the Audit and Risk Management Committee for approval before further submission to the Board of Directors for final approval. It also considers and approves the risk management framework and risk management plan, monitors the development of the risk management framework and the risk identification and assessment process, communicates and coordinates with the Audit and Risk Management Committee regarding significant risks, and reports to the Audit and Risk Management Committee on risks and risk management at least annually. 2 times
4. Chief Executive Officer
The Chief Executive Officer is responsible for overseeing and driving the organization's risk management in line with changing circumstances, monitoring significant risks, and ensuring adequate and appropriate risk management plans are in place. This includes supporting, promoting, and implementing risk management policies to ensure that risk management processes are continuously practiced throughout the Company, and reporting to the Executive Committee on risks and risk management at least annually. 2 times
5. Risk Management Working Group
The Risk Management Working Group is responsible for coordinating and supporting the organization's risk management, collecting, analyzing, and monitoring risks from all departments, preparing annual risk management plans, and supporting the integration of risks related to ESG, PDPA, technology, and security into the Company's risk management process to ensure systematic and consistent governance across the organization.
6. Departmental Risk Management Officer
The risk management officer of each department is responsible for establishing the framework, plans, and processes for the department's risk management, and submitting them to the Executive Committee for consideration and approval. They also support and monitor the risk management of their responsible department, as well as promote and motivate employees to recognize the importance of risk management.
7. Personnel at all levels and in all departments
All personnel are responsible for supporting the Company's risk management system by identifying and reporting risks encountered in operations, adhering to defined control measures, and continuously fostering an organizational risk culture, as well as complying with safety, quality, personal data, and relevant legal requirements.
8. Internal Auditor
Internal auditors are responsible for reviewing internal control systems and ensuring that the Company appropriately implements and practices risk management systems throughout the organization, that internal controls are sufficient and suitable for risk management, and that these internal controls are effectively followed. They also review risk management operations and communicate and clarify risks with management and auditees to plan risk-based audits ( Risk Based Auditing)
The Company places importance on managing risks that may affect business operations and customer services. Therefore, the Company has developed a Business Continuity Plan( BusinessContinuity Plan: BCP) to serve as a framework for preparedness, responding to incidents that may cause business disruption, and restoring operations to ensure continuous business activity withinan appropriate timeframe.
The plan aims to ensure that the Company's critical operations and services can continue at an acceptable level in the event of a disruption, building confidence among customers, shareholders, and stakeholders that the Company is prepared to handle B cope with incidents that may affect business operations, including defining guidelines for systematic coordination and restoration of organizational operations.
Business Impact Analysis (BIA)
The company has conducted a Business Impact Analysis (BIA) toidentifycritical business functions, processes, and services. This analysis assesses the potential impacts of business disruptions,determinesthe criticality levels of operational processes, andestablishesguidelines for system and operational recovery withinan appropriate timeframe. The results of this analysis serve as vital data for defining the company’s business continuity strategies and mitigation measures.
Scope of the Business Continuity Plan
The Business Continuity Plan covers incidents that may affect the Company's business operations, such as the inability to use the primary workplace, disaster events or emergencies at local, city, or national levels, disruption of information technology systems or critical operational systems, as well as a shortage of key personnel involved in business processes.
Business Continuity Process
The Company hasestablisheda business continuity process to address incidents that may affect operations, with the following key steps:
1. Situation Assessment (Incident Assessment)
The relevant department will assess the nature and severity of the incident, as well as its potential impact on operational processes, information systems, and company personnel.
2. Plan Activation BCP (BCP Activation)
Once it isdeterminedthat an incident may cause business disruption, the Company will activate the plan.BCP and appoint relevant working groups to manage the situation.
3. Response and Coordination (Response and Coordination)
The working group will implement defined measures to control the situation, mitigate impacts on business operations, and communicate necessary information to employees, customers, and stakeholders.
4. Business Continuity Operations (Business Continuity Operations)
The Company implements measures to ensure that critical operational processes can continue, such as remote work, the use of backup systems or locations, and the allocation of resources to support operations.
5. Operational Recovery (Recovery)
Once the situation is resolved, the Company willproceedto restore systems, business processes, and the working environment to normal conditions.
6. Plan Review and Improvement (Review and Improvement)
After an incident or plan testing, the Company will evaluate the results and gather lessons learned to further improve the effectiveness of its Business Continuity Plan.
Business Continuity Strategy
The Company has established measures to cope with situations that may affect business operations, such as supporting remote work through secure networks, preparing backup locations or systems for operations, data backup, and developing an information system recovery plan( DisasterRecovery Plan), as well as human resource management to continuously support critical operational processes.