Goal 8:
Decent Work and Economic Growth
Goal 11:
Sustainable Cities and Communities

Management Guidelines and Practices

Risk management helps BEM to recognize potential risks, enabling appropriate, immediate preparations and response to changes in business conditions.

To that end, the Company has established the Risk Management Policy and the Enterprise Risk Management (ERM) Framework in accordance with international standards as part of the Company's business planning, with involvement of all employees. In addition, the Company prepares an annual risk management plan and a risk management manual to ensure that significant risks are within acceptable risk appetite, and that business decision-making have considered the risks.

Impact on Business and Stakeholders

Shareholders
Suppliers or Contractors
Employees
Creditors
Regulatory Authorities and Public Sector

BEM is aware that uncertainties arising from internal and external factors, including emerging risks, may hinder or disrupt business operations and have negative effects on stakeholders' satisfaction. Therefore, effective risk management according to international standards is the key process to strengthen the confidence of stakeholders, which will influence investment decisions and cooperation of shareholders, suppliers or contractors, employees, creditors, and regulatory authorities and public sector, by providing stakeholders with the assurance that risks are being handled appropriately through the processes of planning, strategy formulation, monitoring, and control to mitigate and prevent negative impacts. These factors are crucial to the enhancement of competitiveness and value creation to support the Company's sustainable business operations.

Commitment, Challenges and Opportunities

Amidst constantly changing global situations, customer expectations and technological advancement,

BEM strives to comprehensively manage risks and crises along with good corporate governance, social and environmental responsibility, as well as taking into account the rights and impacts on all group of stakeholders to achieve corporate objectives and provide customers with quality and safe services. BEM systematically conducts risk management and regular risk reviews, defines policies and surveillance measures, and seeks new business opportunities from the changing landscape to develop technology and services in order to better respond to expectations of customer and other stakeholders. The Company allows employees at all levels to participate in identifying risk issues, which provide prompt response to any potential risks and increased competitive opportunities for the Company. In addition, communication with stakeholders to acknowledge the Company's practices or guild lines, is an important factor in building trustworthiness, adding value and sustainable long-term returns to the Company's shareholders.

Integrating sustainability risk criteria covering Environmental, Social, and Governance (ESG) dimensions into the continuous organizational risk assessment process.
Risk management training was provided for a total of
114
persons

Policy and Practices

Risk and crisis management enables BEM to anticipate potential risks, prepare, and respond appropriately and timely to changes in the business environment. Therefore, the Company has established a Risk Management Policy and an Enterprise Risk Management (ERM) framework according to COSO standards as part of its business planning. All employees at every level are responsible for risk management. Additionally, the Company prepares an annual risk management plan and a risk management manual to ensure that risk management processes are implemented systematically, aligned with business strategies and acceptable risk levels, and are responsive to rapidly changing global trends.

Risk Management Structure

The risk management structure defines the responsibilities of stakeholders at all levels. The Board of Directors has delegated the Corporate Governance, Risk Management, and Sustainability Committee, which is structurally independent from the Company's business lines, to oversee and approve the Company's risk management policy and framework. The Company has also delegated responsibility to executive management, including the Legal and Compliance Group, Internal Audit Office, and other relevant units, to implement the overall enterprise risk management process, monitor and evaluate risks, and report the results to the Board of Directors and relevant committees.

The highest operational responsibility for enterprise risk management and internal audit lies with the Assistant Managing Director of Legal and Compliance Group and the Director of the Internal Audit Office, respectively. BEM reports enterprise risks to the Corporate Governance, Risk Management, and Sustainability Committee and/or the Board of Directors on a quarterly basis.

In addition, BEM places importance on material sustainability risks and opportunities. Both internal and external factors are considered under current circumstances and future trends, covering environmental, social, governance, and economic aspects, with a particular focus on climate-related environmental issues. In this regard, the Company is preparing to integrate climate-related risks and opportunities into its core enterprise risk management processes. This ensures alignment with IFRS S2 (Climate-related Disclosures) and IFRS S1 (General Requirements for Disclosures of Sustainability-related Financial Information) standards. The Securities and Exchange Commission (SEC) has mandated these disclosures for SET 50 companies as the first pilot group, starting with the 2027 performance results (scheduled for reporting in 2028), with the aim of enhancing sustainability disclosures in accordance with ISSB Standards.


Enterprise Risk Management Process

To ensure that the Company manages risks effectively at an acceptable level, BEM has established the following enterprise risk management process:

1. Establishing the Context
Identification of the Company's overview, internal and external environment, core processes, and key changes, including future policies and operational plans.
2. Risk Assessment
Comprising Risk Identification and Risk Prioritization, utilizing a risk map that categorizes risks into four levels: Very High, High, Medium, and Low.
3. Risk Treatment
Definition of risk management measures and Key Risk Indicators (KRI) to reduce residual risk to an acceptable level (Risk Appetite).
4. Communication and Consultation
Engagement and consultation among relevant stakeholders on matters related to the business context and associated risks.
5. Monitoring and Reviewing
Monitor the implementation of risk management measures to ensure they remain within acceptable levels, with risk reviews conducted on an annual basis.

Enterprise Risk Management Process Framework

Enterprise Risk Management Process Framework

Corporate Enterprise Risks

Strategic and Business Risks
  • Risks from Business Operations under Concession Agreements with Government Agencies
  • Environmental, Social, and Governance (ESG) Risks
    • Biodiversity Risks
    • Human Rights Compliance Risks Across All Stakeholder Groups
    • Risks from Community Conflicts
    • Corruption and Bribery Risks
  • Risks from Major Accidents, Public Unrest, or Natural Disasters
  • Flood Risks from Climate Change
Operational and Management Risks
  • Risks related to Workforce Capacity and Insufficient Service Capacity for Business Expansion and Operations
  • Risks from Engagement of Outsource Experts as Main Contractors for Supply and Maintenance of the M&E Equipment
  • Risks relating to Structural Stability and Safety
  • Risks relating to Information System Security and Cyber Threats
  • Risks relating to Occupational Health and Safety
  • Risks from Severe Infectious Disease Outbreaks in Metro system
  • Technology-related Risks
Compliance Risks
  • Risks from Non-Compliance with Laws / Concession Agreements
  • Risks from the Enforcement of Climate Change-Related Laws
Financial Risks
  • Risks relating to Revenues not in line with Projections
  • Risks relating to Interest Rate and Foreign Exchange Rate Fluctuations
Investment Risks for Securities Holders
  • Risk relationg to from uncertainty of expected investment returns
  • Risk relationg to from the Company's ability to pay dividends not meeting investors expectations.

BEM implements risk management in accordance with the Enterprise Risk Management process. A comprehensive risk assessment for the year 2025 has been conducted, as shown in the table below.

Risk Matrix for the Year 2025

Risk Matrix for the Year 2025

From the overall risk assessment results in 2025, BEM has implemented risk management by establishing risk mitigation measures, Key Risk Indicators (KRI), and risk appetites as acceptable risk levels, as exemplified below.

2025 Risk Management

Impact to Business

Affect liquidity management and the ability to meet financial obligations to lenders or creditors within the agreed timeframe

Mitigation Measures

  • Establish a unit to monitor potential impacts and adjust strategies accordingly
  • Develop and expand businesses to increase revenue
  • Strictly manage costs and expenses

Key Risk Indicators (Risk Appetites)

Actual revenue compared with projected revenue (deviation must not exceeding 10%)

Impact to Business

  • Cause delays in service delivery and result in resource wastage during issue resolution
  • Exposes the Company to lawsuits for damages resulting from personal data breaches that cause harm to data owners

Mitigation Measures

  • BEM complies with ISO/IEC 27001: 2013 standards.
  • Develop emergency response plans and conduct staff training

Key Risk Indicators (Risk Appetites)

  • Number of information system attacks causing service disruptions (0 incidents)
  • Number of data breaches leading to lawsuits or regulatory actions (0 incidents)

Impact to Business

  • Affect the Company's reputation and corporate image
  • Employee adherence to human rights principles may be non-compliant with laws or adversely affect stakeholders

Mitigation Measures

  • Establish operational procedures for human rights due diligence processes
  • Communicate and raise awareness among all employees and relevant stakeholders to ensure strict compliance

Key Risk Indicators (Risk Appetites)

Number of human rights violations (0 incidents)


Emerging Risks

BEM monitors and evaluates potential emerging risks over the next 3-5 years to enhance its resilience to respond to future changes and to develop proactive and effective mitigation measures.

BEM applies digital technologies, including Artificial Intelligence (AI), automation, and Generative AI (GenAI), in its business operations to enhance efficiency and competitiveness. However, such adoption may give rise to risks, including algorithmic bias, inaccuracies, or a lack of transparency in automated decision-making, cybersecurity threats, and unforeseen impacts arising from AI systems. In addition, these technologies may be exploited as tools in cyberattacks, potentially affecting data integrity, business continuity, stakeholder confidence, and the Company’s reputation.

Impact to Business

  • Risks of cyberattacks, data breaches, or the misuse of artificial intelligence technologies, which could impact the confidentiality, integrity, and availability of the Company’s critical data and systems.
  • BEM may be subject to penalties, legal liabilities, or disputes with stakeholders arising from non-compliance with applicable laws, regulations, or requirments, as well as from a lack of appropriate governance over the utilization of technology and artificial intelligence (AI).

Mitigation Measures

  • Establish governance frameworks for the utilization of digital and artificial intelligence (AI) technologies in alignment with corporate strategies, relevant laws, and international standards.
  • Continuously enhance information security and cybersecurity measures across prevention, detection, and threat response, while regularly conducting risk assessments and readiness testing for systems associated with artificial intelligence (AI) and digital technologies.
  • Enhance knowledge, understanding, and awareness among personnel in the appropriate, safe, and responsible use of technology and artificial intelligence (AI), coupled with ongoing cybersecurity training.

Key Risk Indicators (Risk Appetites)

  • Number of cyberattacks causing service disruption (0 incidents)
  • Number of data breaches resulting in litigation or regulatory interventions (0 incidents)

As the severity of climate change impacts continues to intensify, the likelihood of natural disasters and extreme weather events is increasing. Rising sea levels remain a persistent concern. It is projected that by 2050, certain areas, particularly Bangkok and its metropolitan vicinity, as well as other low-lying regions may experience significant flooding. Such events could disrupt the operations of government agencies and private companies, requiring temporary suspension of services or the implementation of work-from-home measures.

Impact to Business

  • Maintaining the efficiency, convenience, and safety of expressway and metro services becomes increasingly challenging due to logistical difficulties in the delivery of essential goods/ services, or spare parts for maintenance, as well as temporary workforce shortages caused by employees and contractors travel disruptions to operational sites
  • Revenue may decline due to reduced expressway user and metro ridership.
  • Management costs increase in efforts to maintain service efficiency, convenience, and safety under adverse conditions.
  • Service and maintenance costs rise due to higher prices of goods, services, and transportation, as well as the temporary suspension or closure of business partners, requiring the Company to identify alternative suppliers and substitute products.
  • Operational costs increase due to the need to comply with government requirements, legal, mandates, and the Company-imposed measures for greenhouse gas management and flood mitigation.

Mitigation Measures

  • Enhance service delivery processes, systems, and equipment to ensure continued efficiency, convenience, and safety under all conditions
  • Strengthen the Company's logistics and access systems to improve operational reach in flood-affected areas
  • Establish alternative approaches for the management of goods and spare parts inventory to support timely maintenance operations
  • For new BEM projects infrastructure under concession agreements, ensure that the design of structural elements and protective systems addresses flood risks. This includes designing entrances/exits above historical flood levels and installing flood barriers (e.g., flood boards or stop logs) and flood doors at underground station access points to prevent water intrusion. These protective systems have already been implemented in current projects such as the MRT Blue Line and MRT Purple Line.
  • Develop efficient and environmentally friendly systems, equipment, and service processes across the value chain in compliance with government regulations and to support organizational efforts in reducing greenhouse gas emissions
  • Implement organizational greenhouse gas reduction initiatives

Key Risk Indicators (Risk Appetites)

Flood Warning Level (Flood Monitoring Level)

BEM is required to fulfil its obligations in accordance with current and future climate-related legislation. These obligations include activities such as measuring, reporting, and verifying data on greenhouse gas (GHG) emissions, sequestration, and absorption, as well as the proper storage and management of such data.

Impact to Business

  • BEM may incur additional expenses from enhancing or modifying operational processes to ensure compliance with climate change-related laws and regulations.
  • BEM may face legal penalties or sanctions if it fails to fulfil its obligations under applicable climate change-related legislation.

Mitigation Measures

  • Closely monitor the enforcement and development of climate change-related laws, both existing and upcoming. Summarize key legal requirements and communicate them directly to the responsible departments to ensure timely and effective compliance.

Key Risk Indicators (Risk Appetites)

Number of instances of non-compliance with climate change-related laws (0 incidents)


Crisis Management and Business Continuity

BEM has implemented a Business Continuity Management System (BCMS) to ensure the continuity and efficiency of its operations. The Company has established formal procedures for business continuity processes, including the determination of the Maximum Tolerable Period of Disruption (MTPD) and the Recovery Time Objective (RTO) for resuming full-service operations. To ensure preparedness, the Company conducts drills and simulations in line with its business continuity and emergency response plans. For example, drills are organized to address emergency scenarios such as disruptions to the automatic fare collection system. The business continuity plan is reviewed and updated annually to ensure that the Company is capable of responding and managing emergencies in a timely and effective manner. Additionally, the Company promotes awareness and understanding of its business continuity practices through various employee engagement activities, such as quizzes and role-playing contests during business continuity drills.

Business Continuity Management Process

Business Continuity Management Process