Goal and Performance Highlights

Performance

In 2025, the Company reviewed and monitored key risk management plans across all core business groups on a quarterly basis, with

  • The Risk Management Committee (RMC) and the Risk Policy Committee (RPC) meeting jointly four times during the year to assess and control risk exposure in line with changing circumstances.
  • In addition, the Company conducted its annual enterprise-level review of key risks by comprehensively considering internal and external environmental factors, including domestic and international economic conditions, competitive dynamics, consumer behavior, technological changes, laws and regulations, as well as environmental, social, and governance (ESG) issues, together with the Company's strategy and growth plans, in order to define, monitor, and establish appropriate risk management measures.
Target

By 2030

To elevate and fully integrate the risk management system in all business groups in accordance with the COSO Enterprise Risk Management (ERM) 2017 framework, while embedding environmental, social, and governance risk factors (ESG Risks) into strategic decision-making and investment processes to support the transition toward a low-carbon economy.

Long-term target by 2050

To foster a strong risk culture across the organization and enhance the business's resilience and recovery from emerging threats, supporting sustainable long-term growth and driving the organization toward its net zero greenhouse gas emissions goal in line with the roadmap.

Challenges and Business Opportunities

Amid uncertainty from macroeconomic and geopolitical factors, including global economic volatility, interest rates, inflation, energy costs, supply chain disruption, government regulations, trade tensions, and political uncertainty, which may affect investment, tourism, consumer confidence, and the growth of the Company's retail, hotel, office, and residential businesses.

To respond to these challenges, the Company manages risk systematically under the COSO ERM 2017 framework and integrates risk management into business strategy setting, while assessing material sustainability topics using the Double Materiality principle, considering both the impact of external factors on the value and financial resilience of the mixed-use asset portfolio (Outside-In) and the impact the organization has on society and the environment across the value chain (Inside-Out).

At the same time, the Company sees opportunities arising from changing consumer behavior, growth in the tourism sector, urban and infrastructure development, and increasing demand for quality of life, health, and sustainability, all of which are key drivers supporting mixed-use project development and the creation of customer experiences that meet long-term needs.

Key Challenges and Risks

  • Complex value chain structures in managing large mixed-use real estate projects with a high proportion of Tier-1 suppliers and a large network of tenants have led the Company to place strong emphasis on controlling and overseeing ESG standards consistently throughout the supply chain.

  • Climate crisis and transition risks covering both physical risks from volatile natural disasters that may affect business continuity and transition risks arising from the impending enforcement of new environmental laws and policy criteria, which may require the organization to improve energy efficiency to absorb potentially higher operating costs.

  • Cyber threats and emerging technologies pose risks as the organization accelerates digital transformation and the application of artificial intelligence (AI), which may increase exposure to new forms of cyber threats, as well as risks related to the protection of customers' and tenants' personal data (PDPA) across the Company's platforms.

Business Opportunities

  • Building resilience and business continuity by integrating the GRC (Governance, Risk, and Compliance) system with a robust business continuity plan (BCP) helps reduce losses and limit the impact of operational disruptions effectively.

  • Competitive advantage through trust proactively enhancing ESG risk management in line with international standards builds confidence and recognition in global and domestic sustainability indices, benefiting the corporate image and helping attract long-term institutional investment.

A strong risk management system improves operational efficiency, reduces the likelihood of losses, and enables the Company to conduct business continuously.

Management Approach and Value Creation

Central Pattana Public Company Limited is committed to operating under a systematic risk management framework that covers the entire organizational value chain, with the aim of strengthening its ability to cope with evolving challenges and creating long-term sustainability. The Company has adopted the COSO ERM 2017 framework as the primary guideline for risk governance, enabling it to identify, assess, and manage risks systematically while linking risk management to business strategy.

In addition, to keep pace with emerging challenges, the Company has expanded its management scope to cover environmental, social, and governance issues (ESG Risks), especially climate risk analysis under IFRS S2, to strengthen infrastructure resilience and support the net zero greenhouse gas emissions target. Integrating ESG dimensions into the Company's core risk management framework enables the Company to effectively limit potential financial impacts while supporting business adaptation to build resilience and sustainable growth in line with international standards.

Risk Governance

The Company establishes enterprise-wide risk management policies and promotes a risk culture throughout the organization. The Risk Policy Committee is responsible for reviewing and providing recommendations on the organization's risk policies, strategies, and framework, and regularly reports on risk management to the Board of Directors.

The Company assigns the Risk Management Committee to oversee key risks through risk owners at both the management and operational levels. Risk owners are responsible for identifying key risks, assessing their likelihood and impact, and defining measures to prevent, control, and manage risks affecting objectives and operations. The Risk Management Committee analyzes, monitors, and oversees both the overall risk profile and key risks at various levels, while monitoring changing conditions, major trends, and risk factors from both inside and outside the organization to ensure that important objectives, targets, and strategic plans can be achieved as intended.

Risk Governance Structure

Chaired by the Chairman of the Board, has ultimate responsibility for establishing and overseeing the Company’s risk management framework and ensuring alignment with the Company’s strategic objectives.

Chaired by an Independent Director, with Board Directors and the President & CEO serving as members. The Committee is responsible for reviewing and approving the Company's risk management policy, governance structure, and risk management approach to ensure risks remain within acceptable levels. The Committee reports to the Board of Directors on a quarterly basis.

Chaired by the President & CEO, with senior executives from key business functions serving as members. The Committee is responsible for implementing and overseeing compliance with the Company's risk management policies and guidelines, integrating risk management into day-to-day operations, and promoting enterprise-wide risk management. Significant risk management matters are reported to the Risk Policy Committee on a quarterly basis.

Operates under the supervision of the Chief Finance, Accounting and Risk Management Officer. The Department is responsible for monitoring, analyzing, and reporting key risks to the Risk Management Committee, as well as supporting risk owners in identifying, assessing, and managing risks to maintain appropriate risk levels.

Operates independently from business units and provides assurance on key organizational activities, taking into consideration the risk profile of business units and operational processes. The Office also coordinates the use of audit findings to support the identification and assessment of key risks, thereby strengthening the effectiveness of risk oversight and governance across the organization.

Enterprise-wide Risk Culture

The Company promotes risk management as part of the organizational culture and daily operations by linking it to the Company's values.

  • Create thoughtfully, do good
  • Never stop innovating
  • Customer as inspiration
  • Move forward together, sustain the bond
  • Executives and employees at all levels participate in risk management.
  • Use risk information to support decision-making and operations.
  • Link to performance evaluation.
  • Covering everyone from the Board and executives to employees at all levels
  • Provide continuous training and knowledge sharing on risk management
  • Use digital systems to support risk monitoring and reporting
  • Operate in line with the Integrated GRC (Governance, Risk and Compliance) approach
  • Build risk-aware people who can adapt to change, make prudent decisions, and help drive the organization toward sustainable long-term growth.
Risk Management Process

The Company has established a systematic and continuous risk management process to support the achievement of strategic goals, performance, and sustainable growth by integrating risk management into business planning, investment decisions, and the operations of every unit. The process comprises four key principles as follows.

The Company identifies risks and factors that may affect organizational objectives by considering both internal and external factors, such as economic conditions, changes in consumer behavior, competition, cost volatility, legal requirements, technology, cybersecurity, natural disasters, and operational risks. Relevant units jointly analyze causes, impacts, and early warning signs to ensure risks are identified comprehensively and in a timely manner.

The Company assesses the likelihood and impact of risks across financial, operational, customer, people, legal, reputation, and business continuity dimensions in order to prioritize risks and define appropriate management responses. It also considers residual risk levels after controls and compares them with the Company's risk appetite so that resource allocation and risk monitoring focus on issues that are material to the organization.

The Company establishes control measures and risk treatment plans based on the type and level of risk. Responses may include accepting risk within defined thresholds, reducing risk through process improvements or additional controls, discontinuing high-risk activities, or transferring risk through insurance and business agreements. Risk treatment plans define responsible parties, timelines, relevant resources, and monitoring indicators to ensure measures effectively reduce the likelihood or mitigate the impact of risks.

The Company regularly monitors risk status, progress against risk management plans, and key risk indicators (KRIs) to identify warning signs and enable timely response. Responsible units report progress, changing risk issues, and the results of control measures to management and relevant committees. Risks and treatment plans are also reviewed periodically to align with the business context, external environment, and the organization's strategic direction.

Enterprise Risk Management

The Company integrates risk management with strategy and performance under the COSO Enterprise Risk Management Framework (2017), based on five key components that support the creation and preservation of organizational value as follows:

The Company establishes the structure and desired culture, demonstrates commitment to core values, and builds human capital to achieve business strategy and objectives, with the Board of Directors providing governance and support to management.

The Company integrates risk management into strategic planning by analyzing the business context, evaluating strategic alternatives and their potential impacts, and setting business objectives in line with acceptable risk levels.

The Company identifies and assesses the severity of risks that may affect the success of strategy and the achievement of business objectives, prioritizes those risks, uses them as criteria for selecting appropriate risk responses, and executes those responses effectively, while also developing and evaluating the overall risk profile so that all levels and relevant units are informed.

The Company identifies and assesses significant changes, and regularly reviews risks and performance to drive continuous improvement in enterprise risk management.

The Company leverages information systems, technology, and communication channels to support enterprise risk management, and continuously and appropriately reports risk information, performance information, and risk management results to relevant stakeholders.

ESG Risk Management Tools
  • Forward-looking and Crisis Scenario Analysis

    The Company integrates statistical data with sensitivity analysis and stress testing to simulate environmental and social crisis scenarios that may materially affect the organization, such as volatility in energy and electricity costs, rising wage levels, and climate change causing droughts and floods. This is used to assess impacts on financial materiality and support the systematic planning of business continuity measures.

  • Internal Carbon Pricing: ICP

    To align with the climate-related financial disclosure standard (IFRS S2), the Company has adopted internal carbon pricing (ICP) as a financial tool to assess monetization of climate-related IROs, both in evaluating transition risk and assessing the business case for investment in low-carbon technologies in pursuit of its Net Zero target.

Existing Risk Assessment
Risk Topic Risk Trend Affected Dimension
1. Economic and Competition Risk
2. Safety Risk
3. Climate Change Risk
4. People and Human Right Risk
5. Cybersecurity Risk
6. Artificial Intelligence (AI) and Data Governance Risk
7. Trade Receivables Credit Risk
8. Legal and Compliance Risk

Risk Trend

Increasing

Stable

Decreasing

Affected Dimension

Environment

Social

Governance

Economic

More details are available in the Existing Risk Assessment

Emerging Risk Analysis

Through continuous monitoring of external developments and risk trends, the Company recognizes the importance of emerging risks, which are new or evolving risks with high uncertainty and potentially broad impacts. If such events occur, they may materially affect the business over the medium to long term. Therefore, the Company places importance on regularly assessing and monitoring these risks to strengthen the organization's resilience and adaptability.

More details are available in the Emerging Risk Assessment

Risk Management and Impacts on Stakeholders

The Company's risk management process covers the identification and management of risk issues that may affect stakeholders throughout the value chain as follows:

Tenants and retail operators

Focus on business continuity management (BCP), the integration of green agreements for the environment, and the use of applications to improve communication efficiency in crisis situations.

Customers and service users

Control occupational health and safety risks through air circulation systems by installing MERV 14 technology, alongside the protection of personal data security (PDPA).

Suppliers and business partners

Supplier selection and assessment based on ESG (environmental, social, and governance) principles, and supply chain risk oversight through the Supplier Code of Conduct, help ensure that suppliers operate ethically and transparently. In addition, the Company has conducted audits and assessments of suppliers in 100% of development projects and provided training to strengthen operating standards and reduce potential risks.

Employees

Managing workplace safety risks in accordance with ISO 45001, labor rights, and the control of harassment risks within the organization.

Shareholders, investors, and creditors

Reducing financial risk through transparent disclosure in line with international standards and maintaining the net debt-to-equity ratio (Net D/E Ratio) within the defined level.

Communities and regulators

Strict compliance with laws and regulations through environmental and social impact assessments (EIA/SIA) and mitigation of negative impacts on communities surrounding project locations.

Stakeholders Involved

Retail operators, building tenants, customers, residential projects
Employees
Customers
Suppliers and business partners
Communities / community representatives, including regulatory bodies, government, academia, and independent organizations
Shareholders
Creditors