Supporting the SDGs
The Company integrates risk management with corporate governance and business operations to support business continuity and minimize potential impacts on the organization, customers, and stakeholders, with a focus on:
Goal 8 Decent Work and Economic Growth
By promoting a safe and fair workplace and developing workforce capabilities
Goal 9 Industry, Innovation and Infrastructure
By enhancing innovation and supporting customers through technology risk management
Goal 12 Responsible Consumption and Production
By promoting responsible supply chain management
Goal 13 Climate Action
By improving resource efficiency and managing climate-related risks
Goal 16 Peace, Justice and Strong Institutions
By ensuring transparency and managing corruption risks
Goal 17 Partnerships for the Goals
By strengthening collaboration with business partners and managing digital risks
Goals

Operational Risk
Control risks impacting project delivery, timelines, and service continuity

IT Security Risk
Minimize risks affecting IT systems and critical data

Vendor Dependency Risk
Manage risks associated with external partners and service providers

Compliance Risk
Ensure full compliance with applicable laws, regulations, and contractual requirements

Service Continuity Risk
Maintain uninterrupted service delivery

Workforce Risk
Ensure workforce readiness to support business operations

Foreign Exchange Risk
Mitigate impacts from exchange rate fluctuations

Environmental Risk
Reduce environmental impact and monitor climate-related risks

Human Rights Risk
Prevent human rights violations

Ethics and Corruption Risk
Prevent unethical conduct and corruption

Strategic Risk
Adapt to market changes and technological advancements

Emerging Risk
Monitor and respond to emerging risks
Performance Highlights
Operational Risk
IT Security Risk
IT security risks were effectively managed, ensuring system reliability and continuity with no major incidents
Vendor Dependency Risk
Compliance Risk
Operations and projects were conducted in full compliance with legal and regulatory requirements, with no significant compliance issues identified
Service Continuity Risk
Workforce Risk
Workforce capacity was effectively managed to support ongoing projects and service delivery
Foreign Exchange Risk
Environmental Risk
Environmental risks and related trends were continuously monitored to support informed decision-making and impact mitigation
Human Rights Risk
Ethics and Corruption Risk
No significant incidents of misconduct or corruption were identified
Strategic Risk
Emerging Risk
Emerging risks were continuously monitored and assessed to support proactive risk management

Challenges and Opportunities
Management Approach and Value Creation
Risk management policy and plan
Metro Systems Corporation Public Company Limited recognizes the importance of enterprise-wide risk management and is committed to risk management in line with business directions and goals by continuously promoting management and processes so that the Company can achieve its objectives and targets, encourage good governance, build confidence among all stakeholders, and enable the organization to grow sustainably. The Company has adhered to the Enterprise Risk Management Framework in accordance with international standards, the Committee of Sponsoring Organizations of Treadway Commission (COSO) or COSO ERM, including the principles of good corporate governance for for listed companies in 2017 and anti-corruption guidelines.
The Company integrates the enterprise risk management system consistent with business operations, policies, laws, and standards covering the GRC system, which is Good Governance, Risk Management and Internal Control, and Compliance so that the organization can adapt and manage risks to risk appetite or not affecting current and future business operations.

1. Risk Management Structure
The Company has established corporate risk management through the Risk Management Subcommittee. The Chairman of the Risk Management Subcommittee is an independent director. The subcommittee is responsible for overseeing the implementation of risk management policies and guidelines, as well as providing comments, suggestions, and support in the development of appropriate risk management processes, including monitoring risk management and presenting opinions to the Board of Directors. The Board of Directors and senior executives will support and drive the risk management process to be continuous and effective.

2. Risk Management Process
The Company oversees and encourages appropriate and timely risk management, including awareness of emerging risk factors and corporate sustainability risk factors related to environmental, social, and governance issues (ESG Risk). The Company also focuses on the study and application of various forms of risk management tools, such as assessment and sequencing of risk factors using a risk map, risk management monitoring through a mitigation plan, and key risk indicator (KRI), as well as trend analysis from the scenario and PESTEL to monitor changes in external factors and emerging risks that may have a positive or negative impact on the future business operations of the organization.

3. Corporate Culture in Risk Management
The Company promotes risk management for all employees, including raising awareness of good governance, risk management and internal control, and compliance, or GRC, so that everyone in the organization can participate and own risks. All employees are responsible for identifying risks, assessing, monitoring, and supporting effective risk management processes. In 2024, training was continuously conducted to improve risk management knowledge according to the COSO ERM standard and the GRC system for executives and employees at all levels on an e-Learning platform. In addition, senior executives support and drive continuous and effective risk management processes to become part of the corporate culture.
