Supporting the SDGs

The Company integrates risk management with corporate governance and business operations to support business continuity and minimize potential impacts on the organization, customers, and stakeholders, with a focus on:

Goal 8 Decent Work and Economic Growth

By promoting a safe and fair workplace and developing workforce capabilities

Goal 9 Industry, Innovation and Infrastructure

By enhancing innovation and supporting customers through technology risk management

Goal 12 Responsible Consumption and Production

By promoting responsible supply chain management

Goal 13 Climate Action

By improving resource efficiency and managing climate-related risks

Goal 16 Peace, Justice and Strong Institutions

By ensuring transparency and managing corruption risks

Goal 17 Partnerships for the Goals

By strengthening collaboration with business partners and managing digital risks

Impact 2025 Achievements

Goals and Performance Highlights

ESG Performance Data

Goals

Operational Risk

Control risks impacting project delivery, timelines, and service continuity


IT Security Risk

Minimize risks affecting IT systems and critical data


Vendor Dependency Risk

Manage risks associated with external partners and service providers


Compliance Risk

Ensure full compliance with applicable laws, regulations, and contractual requirements


Service Continuity Risk

Maintain uninterrupted service delivery


Workforce Risk

Ensure workforce readiness to support business operations


Foreign Exchange Risk

Mitigate impacts from exchange rate fluctuations


Environmental Risk

Reduce environmental impact and monitor climate-related risks


Human Rights Risk

Prevent human rights violations


Ethics and Corruption Risk

Prevent unethical conduct and corruption


Strategic Risk

Adapt to market changes and technological advancements


Emerging Risk

Monitor and respond to emerging risks


Performance Highlights

Operational Risk
The Company effectively managed project and operational risks within acceptable levels, with no significant impact on project delivery or service performance
IT Security Risk

IT security risks were effectively managed, ensuring system reliability and continuity with no major incidents

Vendor Dependency Risk
Risks related to vendors and partners were appropriately managed, with no disruption to project execution
Compliance Risk

Operations and projects were conducted in full compliance with legal and regulatory requirements, with no significant compliance issues identified

Service Continuity Risk
Service delivery risks were controlled within acceptable levels, with no significant service disruption reported
Workforce Risk

Workforce capacity was effectively managed to support ongoing projects and service delivery

Foreign Exchange Risk
Foreign exchange risks were managed within acceptable levels, with no material impact on financial performance
Environmental Risk

Environmental risks and related trends were continuously monitored to support informed decision-making and impact mitigation

Human Rights Risk
No incidents related to human rights violations were reported
Ethics and Corruption Risk

No significant incidents of misconduct or corruption were identified

Strategic Risk
The Company demonstrated the ability to adapt to evolving market conditions and technological trends
Emerging Risk

Emerging risks were continuously monitored and assessed to support proactive risk management

Challenges and Opportunities

Challenges
Shortage of AI, Data, and Cloud talent; difficulty retaining key employees amid rapid technological change
Opportunities
Workforce upskilling, stronger innovation capability, and improved employee engagement
Challenges
Revenue pressure from shifting from one-time sales to subscription-based models
Opportunities
Creation of recurring revenue streams and future-ready service offerings
Challenges
High competition and dependency on key customers may affect long-term growth
Opportunities
Use CRM and data analytics to improve retention, expand new customer segments, and enhance service quality
Challenges
Operational disruption from crises, system failures, or emergencies
Opportunities
Strengthen BCM, remote work capability, and resilient digital infrastructure
Challenges
Rapidly evolving regulations, especially AI and data privacy requirements
Opportunities
Enhance governance standards, improve compliance readiness, and build stakeholder trust
Challenges
Economic uncertainty, price competition, and rising costs pressure profitability
Opportunities
Shift to value-based competition, recurring revenue models, and operational efficiency improvements
Challenges
Currency fluctuations impact profit margins due to foreign procurement
Opportunities
Improve financial risk management through hedging and forward contracts
Challenges
Increasing cyber threats, ransomware, insider threats, and AI-enabled attacks
Opportunities
Strengthen cybersecurity standards (ISO 27001), improve data governance, and enhance stakeholder confidence
Challenges
Stricter climate regulations and potential carbon tax exposure
Opportunities
Achieve carbon reduction targets, enhance ESG reputation, and create green business opportunities
Challenges
Risk of human rights violations across operations and supply chain
Opportunities
Strengthen responsible business practices and align with global ESG expectations
Challenges
Corruption risks may damage reputation and lead to legal consequences
Opportunities
Enhance corporate governance, ethics culture, and stakeholder confidence
Challenges
High investment costs required for net-zero transition
Opportunities
Drive long-term sustainability, energy efficiency, and ESG-driven competitive advantage
Challenges
Reliance on major partners may impact competitiveness and revenue stability
Opportunities
Diversify partnerships and develop proprietary products and services
Challenges
Risk of disruption from competitors and emerging technologies
Opportunities
Foster innovation culture and create differentiated solutions for future growth
Challenges
Third-party failures may affect operations, compliance, and data security
Opportunities
Strengthen vendor governance, SLA management, and business continuity readiness
Challenges
AI-related threats such as deepfake, phishing, and Shadow AI causing data leakage
Opportunities
Develop AI Governance, improve cybersecurity capability, and leverage AI for operational transformation

Management Approach and Value Creation

Risk management policy and plan

Metro Systems Corporation Public Company Limited recognizes the importance of enterprise-wide risk management and is committed to risk management in line with business directions and goals by continuously promoting management and processes so that the Company can achieve its objectives and targets, encourage good governance, build confidence among all stakeholders, and enable the organization to grow sustainably. The Company has adhered to the Enterprise Risk Management Framework in accordance with international standards, the Committee of Sponsoring Organizations of Treadway Commission (COSO) or COSO ERM, including the principles of good corporate governance for for listed companies in 2017 and anti-corruption guidelines.

The Company integrates the enterprise risk management system consistent with business operations, policies, laws, and standards covering the GRC system, which is Good Governance, Risk Management and Internal Control, and Compliance so that the organization can adapt and manage risks to risk appetite or not affecting current and future business operations.

1
Risk Management Structure
2
Risk Management Process
3
Corporate Culture in Risk Management

1. Risk Management Structure

The Company has established corporate risk management through the Risk Management Subcommittee. The Chairman of the Risk Management Subcommittee is an independent director. The subcommittee is responsible for overseeing the implementation of risk management policies and guidelines, as well as providing comments, suggestions, and support in the development of appropriate risk management processes, including monitoring risk management and presenting opinions to the Board of Directors. The Board of Directors and senior executives will support and drive the risk management process to be continuous and effective.


2. Risk Management Process

The Company oversees and encourages appropriate and timely risk management, including awareness of emerging risk factors and corporate sustainability risk factors related to environmental, social, and governance issues (ESG Risk). The Company also focuses on the study and application of various forms of risk management tools, such as assessment and sequencing of risk factors using a risk map, risk management monitoring through a mitigation plan, and key risk indicator (KRI), as well as trend analysis from the scenario and PESTEL to monitor changes in external factors and emerging risks that may have a positive or negative impact on the future business operations of the organization.


3. Corporate Culture in Risk Management

The Company promotes risk management for all employees, including raising awareness of good governance, risk management and internal control, and compliance, or GRC, so that everyone in the organization can participate and own risks. All employees are responsible for identifying risks, assessing, monitoring, and supporting effective risk management processes. In 2024, training was continuously conducted to improve risk management knowledge according to the COSO ERM standard and the GRC system for executives and employees at all levels on an e-Learning platform. In addition, senior executives support and drive continuous and effective risk management processes to become part of the corporate culture.

Stakeholders Directly Impacted

Shareholders and investors
Affected by business risks and financial performance
Management and employees
Responsible for identifying, monitoring, and managing operational risks
Enterprise customers
Affected by service continuity and the quality of delivered solutions
Vendors and business partners
Involved in risks related to project execution and service delivery
Regulators
Oversee compliance with applicable laws and regulatory requirements