Goal and Performance Highlights

Performance
In 2025, the Company reviewed and monitored key risk management plans across all major business groups on a quarterly basis. The Risk Management Committee (RMC) and the Risk Policy Committee (RPC) held a total of four joint meetings during the year to assess and control risk exposure in line with changing conditions.
Goal

By 2030

Fully enhance and integrate the risk management system under the COSO Enterprise Risk Management (ERM) 2017 framework across all business groups, while incorporating environmental, social, and governance risks (ESG Risks) into strategic decision-making and investment processes to support the transition toward a low-carbon economy.

Long-Term Goal by 2050

Build a strong risk culture across the organization and strengthen business resilience and recovery from emerging threats to support long-term sustainable growth and help the organization achieve the Net Zero greenhouse gas emissions target according to plan.

Challenges and Opportunities

The Company identifies and assesses material sustainability topics based on the Double Materiality approach to analyze the risk context from external factors that affect the value and financial stability of the mixed-use asset portfolio (Outside-In), alongside managing impacts that the organization may create on society and the environment across the value chain (Inside-Out), as follows:

Key Challenges and Risks

  • Complex value chain structures in the management of large-scale mixed-use real estate projects, which involve a high proportion of Tier 1 suppliers and extensive tenant networks, make it important for the Company to control and oversee ESG standards consistently across the supply chain.

  • Climate crisis and transition risks cover both physical risks from volatile natural hazards that may affect business continuity and transition risks from upcoming laws and new environmental policy criteria, which require the organization to improve energy efficiency to manage potentially higher operating costs.

  • Cyber threats and emerging technologies are risks arising from the rapid digitalization of the organization and the application of artificial intelligence (AI). These developments may increase exposure to new forms of cyber threats, including risks related to the protection of personal data (PDPA) for customers and tenants across the Company's platforms.

Business Opportunities

  • Strengthening business resilience and continuity by integrating governance, risk, and compliance (GRC) systems with robust business continuity plans (BCP) helps reduce losses and effectively limit impacts from disruptions to frontline operations.

  • A competitive advantage from trust is created by proactively elevating ESG risk management in line with international standards. This helps build confidence and recognition in global and national sustainability indices, supports corporate reputation, and attracts long-term investment from institutional investors.

A strong risk management system improves operational efficiency, reduces potential losses, and supports business continuity.

Management Approach and Value Creation

Central Pattana Public Company Limited is committed to operating under a systematic risk management framework that covers the entire organizational value chain. The goal is to strengthen the ability to respond to evolving challenges and create long-term organizational sustainability. The Company applies the COSO ERM 2017 risk management framework as the main guideline for risk governance, enabling systematic risk identification, assessment, and management while linking risk management with business strategy.

To keep pace with emerging challenges, the Company has expanded management coverage to include environmental, social, and governance risks (ESG Risks), particularly climate risk analysis under IFRS S2. This strengthens infrastructure resilience and supports the Net Zero greenhouse gas emissions target. Integrating ESG dimensions into the Company's core risk management framework helps limit potential financial impacts effectively while supporting business adaptation for resilient and sustainable growth in line with international standards.

Risk Governance Structure

The Company manages risk through the Three Lines of Defense model to cover operations across all business groups. The structure clearly defines roles and responsibilities, from internal controls by operating units and reviews by the central risk management function to policy oversight by sub-committees, ensuring that enterprise risk management follows established practices and standards.

Risk Policy Committee

The Company oversees risk by establishing risk policies, defining risk appetite, and setting an appropriate risk management framework. Risk management and internal control functions operate independently. The Company oversees risk through the Board and executives as follows:

The committee is chaired by an independent director and includes directors and the President & Chief Executive Officer as members. The committee is responsible for acknowledging and providing recommendations on risk policies, risk management structures and frameworks, and key risks; considering and approving risk levels and acceptable risk tolerance ranges; overseeing the setting of performance targets and key risk indicators; assessing the suitability and effectiveness of management's risk responses; and regularly reporting risk management activities to the relevant governing body for acknowledgement.

The committee is chaired by the President & Chief Executive Officer and includes executives from key functions as members. The committee oversees compliance with risk policies and risk management guidelines; ensures that business units identify, assess, manage, and report risks related to the achievement of objectives; integrates risk management into business plans and performance reporting on an ongoing basis; promotes and supports enterprise-wide risk management activities; and regularly reports risk management results to the Risk Policy Committee and the relevant governing body.

The department serves as secretary to the Risk Management Committee and supports risk management work. Responsibilities include monitoring, analyzing, and reporting key risks to the Risk Management Committee, as well as supporting risk-owning units in identifying key risks, assessing risk levels, and preparing mitigation measures to keep risks within appropriate levels. The Risk Management Department operates under the supervision of the Deputy Chief Executive Officer, Finance, Accounting and Risk.

The Company requires the Risk Management Department to support the Internal Audit Office in reviewing key organizational activities based on the risk levels of each unit and activity. Internal audit assessment results are also used as inputs for identifying and analyzing key risks. In addition, the Risk Management Department reports risk management results to the Audit Committee at least twice a year.

Risk Management Process

Central Pattana Public Company Limited's risk management process covers risk identification, analysis, and assessment. Risk appetite is reviewed annually or when significant changes may affect the business. The Company uses a Risk Map to analyze and prioritize risks and monitors risk trends through Key Risk Indicators (KRIs), leading to the definition of appropriate risk mitigation measures.

The Company regularly reviews risks and risk appetite to define key risks, usually once a year or when significant changes affect competitiveness.

The Company identifies risk factors from across the organization, taking into account both internal and external factors in alignment with business direction and corporate strategy. The Company considers the likelihood and impact of events that may affect business operations directly and indirectly, assesses risks, prioritizes them based on likelihood and impact using a Risk Map, and defines appropriate risk management plans to govern and control risks within acceptable levels.

The Company monitors risks through Key Risk Indicators (KRIs) and the progress of defined risk management plans to assess risk levels every quarter for reporting to the Risk Management Committee and the Risk Policy Committee.

ESG Risk Management Tools
  • Predictive Data and Crisis Analysis

    The Company integrates statistical data with sensitivity analysis and stress testing to simulate environmental and social crisis scenarios that may have a significant impact on the organization, such as volatility in energy and electricity costs, rising labor costs, and climate change that causes droughts and floods. This supports assessment of financial materiality and provides inputs for systematic business continuity management measures.

  • Financial Tool for Assessing Climate Risks and Opportunities (Internal Carbon Pricing: ICP)

    To align with climate-related financial disclosure standards (IFRS S2), the Company uses internal carbon pricing (ICP) as a financial tool to assess the value of impacts, or monetization of climate-related IROs, both for transition risk assessment and for evaluating the cost-effectiveness of investments in low-carbon technologies toward the Net Zero target.

Emerging Risk Analysis

Central Pattana Public Company Limited monitors emerging risk trends that may affect the real estate industry, referencing information from recognized organizations such as the World Economic Forum (WEF). Climate change and the low-carbon economy are key risks that may affect the real estate development business. Natural hazards such as floods and storms may increase development and operating costs, while stricter environmental regulations may also affect the business. Technological advancement and cyber risks are also important factors, as the use of digital technology and intelligent systems in business operations may increase data and cybersecurity risks.

Risk Issues

Risk Type:

Environmental

Description:

Climate change is one of the most significant risks facing the Company, with impacts ranging from operational to strategic levels. More severe natural hazards, such as floods, storms, and heatwaves, may affect the infrastructure of the Company's shopping centers and real estate projects, leading to additional repair and maintenance costs. Stricter domestic and international environmental regulations may also increase operating and development costs for new projects. Without appropriate measures, the Company may face risks related to declining asset value, delays in project development, and loss of confidence among investors and consumers who prioritize sustainability. The Company therefore assesses environmental risks across all projects, designs infrastructure to withstand natural hazards, and applies clean energy systems and greenhouse gas reduction measures in alignment with sustainable development goals.

Impact:

Damage to assets and infrastructure may increase repair and maintenance costs. Disruptions to shopping center operations and development projects may occur. Compliance with stricter environmental regulations may increase costs and affect project timelines. The Company's reputation may be affected if environmental impact mitigation measures are insufficient.

Mitigation Plans:

To mitigate climate risk impacts, the Company assesses environmental risks across all projects and designs infrastructure to withstand natural hazards by using efficient drainage systems, selecting environmentally friendly construction materials, and using renewable energy, such as rooftop solar installation projects at shopping centers. The Company also adjusts greenhouse gas reduction targets in line with international standards to reduce future regulatory risks.

Risk Type:

Economic

Description:

Economic uncertainty and rising interest rates affect business investment decisions and consumer purchasing power. If the economy slows, consumer spending will decline, directly affecting shopping center footfall and the Company's occupancy rates. In addition, Thailand's high household debt level, at 89.6% of GDP in the second quarter of 2024, may affect tenant sales in shopping centers and require the Company to restructure rental terms to reduce impacts on business partners.

The Company may face liquidity risks if the economy enters a recession. Lower occupancy may affect revenue and net profit. The Company therefore focuses on prudent financial management by maintaining an appropriate debt-to-equity ratio, diversifying funding sources, and developing project strategies that respond to market demand to strengthen long-term revenue.

Impact:

Lower demand for rental space may affect rental income. Reduced consumption may affect tenant sales and could lead to rental reductions to support tenants. Operating costs may rise due to interest rates and inflation.

Mitigation Plans:

To address these risks, the Company implements prudent financial strategies by diversifying funding sources and managing the debt-to-equity ratio at an appropriate level. The Company also emphasizes cost control and cash flow management efficiency. At the same time, the Company develops projects that respond to market demand under changing economic conditions, focusing on projects that target high-potential customers and diversify risks across the asset portfolio.

Risk Type:

Technology

Description:

Increasing reliance on digital technology in business operations exposes the Company to cyberattack risks, which may lead to leakage of customer and business partner data, reputational damage, and fines from regulators. Cyberattacks may also disrupt the Company's digital systems, affecting customer service and business continuity.

Without appropriate response measures, the Company may face loss of trust from customers and business partners. The Company therefore implements ISO 27001:2013 and NIST SP800-53 standards to enhance data security, arranges cyber insurance, and trains employees to understand cyber threats.

Impact:

Data leakage may lead to regulatory fines. Cyberattacks may disrupt shopping center digital systems, affecting customer experience and causing reputational damage and loss of customer trust.

Mitigation Plans:

The Company prevents cyber risks by applying information security standards such as ISO 27001:2013 and NIST SP800-53, strengthening data security systems through investment in technologies that detect and prevent cyber threats. The Company also provides ongoing employee training on cyber threat prevention and response and maintains cyber insurance to help mitigate potential impacts from cyberattacks.

Risk Type:

Political

Description:

Thailand's uncertain political environment, including changes in economic policies, may affect business investment and investor confidence. Changes in taxes or laws related to the real estate sector may increase operating costs or affect the Company's ability to expand projects.

The Company may be affected if new laws are enforced without sufficient time for preparation, which could increase project costs and timelines. The Company therefore closely monitors legal and policy developments to adjust business strategies in line with changes in a timely manner.

Impact:

Delays in new project development; higher costs from compliance with new laws; policy uncertainty may reduce investor confidence.

Mitigation Plans:

The Company closely monitors changes in laws and policies and adjusts business strategies in line with changing regulations. The Company also strengthens relationships with government agencies to support efficient project implementation.

Risk Type:

Social

Description:

Rapidly changing consumer behavior, particularly increased use of online platforms, may affect visits to shopping centers and use of services within the Company's projects. If the Company cannot adapt to new consumer behavior, rental revenue may decline.

The Company has adjusted strategy by focusing on creating experience-based destinations that meet the lifestyles of modern consumers. The Company develops shopping centers that are more than shopping venues, positioning them as centers of life that include relaxation, wellness activities, and social connection. The Company also strengthens digital channels and develops online platforms that connect customers with tenant products and services.

Impact:

Lower shopping center footfall may affect rental income. Rental space structures may need to be adjusted to respond to new demand.

Mitigation Plans:

The Company has adjusted strategy by developing experience-based destinations that create distinctive experiences in shopping centers, combining lifestyle, wellness activities, and entertainment to attract customers. The Company also develops digital channels in line with changing consumer behavior and increases the use of technology to connect shopping centers with customers.

Risk Culture

Central Pattana Public Company Limited emphasizes promoting risk culture as part of the organization by encouraging employees at all levels to participate in risk management through training, communication, and performance evaluation. The Company provides employee training on risk management guidelines, cybersecurity, and corporate governance standards, and integrates risk management approaches into employee performance evaluation to strengthen accountability and understanding of appropriate risk management.

Central Pattana fosters a corporate risk culture through a range of methods, tools and channels including:

  • Raising Awareness of key risk management topics through various channels and formats, such as communications on cyber threats and violations of personal data protection laws through email, Workplace, and other channels.
  • Training Provide online training courses to all employees on topics including risk management and crisis management and organize workshops specifically tailored for key functions such as general managers.
  • Drills and Tests Conduct crisis management plans, such as fire, sabotage, and working at height, as well as regular business continuity plan drills, including database security drills at least once a year.
  • Linking risk management to compensation by making risk one criterion in employee performance evaluation, such as using incident and crisis management as an evaluation criterion for LP officers in shopping centers.
  • Communicating key risk issues, impacts, risk management actions, and emerging risks through the annual report (One Report) and the Company's website so that stakeholder groups are continuously informed of the Company's risk management.
Risk Management and Impacts on Stakeholders

The Company's risk management process covers the identification and management of risk issues that may affect stakeholders across the value chain, as follows:

Tenants and Lessees (Retail and Offices) and Residential Customers

Focus on business continuity management (BCP), integration of green agreements for the environment, and use of applications to improve crisis communication efficiency.

Customers

Control occupational health and safety risks through air circulation systems by installing MERV 14 technology together with personal data protection (PDPA).

Suppliers and Business Partners

Supplier selection and assessment based on ESG principles (environmental, social, and governance), together with supply chain risk governance through the Supplier Code of Conduct, ensures that suppliers conduct business ethically and transparently. The Company also audits and assesses 100% of suppliers in development projects and provides training to strengthen operating standards and reduce potential risks.

Employees

Manage workplace safety risks in accordance with ISO 45001, labor rights, and harassment risk controls within the organization.

Shareholders

Reduce financial risks through transparent disclosure in accordance with international standards and control the net debt-to-equity ratio (Net D/E Ratio) within the defined level.

Communities / Community representatives including regulators and government bodies, academia and independent organizations

Strictly comply with laws and regulations through environmental and social impact assessments (EIA/SIA) and reduce negative impacts on communities surrounding branches.

Stakeholders Directly Impacted

Tenants and Lessees (Retail and Offices) and Residential Customers
Employees
Customers
Suppliers and Business Partners
Communities / Community representatives including regulators and government bodies, academia and independent organizations
Shareholders
Creditors