1. Importance
Risk management is essential to safeguarding long-term business resilience and sustainable value creation. It enables the Group to anticipate, assess, and respond effectively to uncertainties that may impact strategic objectives, operational continuity, financial stability, and ESG performance. Strong oversight ensures that material risks are considered at the highest level, supporting balanced and informed decision-making.
By embedding risk awareness into strategic planning and ongoing management, the Group strengthens its ability to manage volatility, respond to emerging and ESG-related risks, and prepare for potential crises. Effective risk management enhances organisational agility, protects stakeholder interests, and supports consistent performance in an increasingly complex and rapidly changing business environment.
2. Targets and Performance
To demonstrate its commitment to Risk Management, ACE has established clear goals and systematically monitors performance against these material topics, as outlined below:
| Goal | 2025 Performance |
|---|---|
| No number of cases of violation of Code of Conduct that have been reported | 0 case of violation of Code of Conduct that have been reported. |
3. Management Approach
The Group recognises risk management as a core component of good corporate governance, supporting stable growth, financial resilience, and long-term value creation. An enterprise-wide risk management approach aligned with international standards is embedded into strategy formulation, decision-making, and daily operations.
3.1 Risk Management Policy
The Group and its subsidiaries recognise the importance of adopting an internationally standardised risk management system as an integral part of effective management and organisational excellence. Risk management is a shared responsibility across all levels of the organisation, with personnel required to understand and manage risks within their respective functions under systematic internal controls.
The risk management process is established in line with international standards and embedded into strategic planning, decision-making, and operational activities to ensure consistency across the organisation. Clear guidelines are developed to prevent and mitigate operational risks, supported by regular monitoring and evaluation to minimise potential damage or loss. In addition, the Group promotes the use of modern information technology to enhance risk management processes, ensure broad access to risk-related information, and enable effective risk reporting to the Sustainability Development and Risk Management Committee and/or the Audit Committee.
3.2 Risk Governance and Management Structure

| Level | Roles and Responsibilities |
|---|---|
| Board of Directors |
The Board of Directors provides guidance, direction, control, and oversight of the Group’s operations and risk management. This includes approving risk management policies, processes, and supporting practices, and regularly reviewing the effectiveness of the risk management framework. The Board also oversees sustainability-related risks and opportunities, including environmental, social, and governance (ESG) and climate change matters, as part of its overall risk oversight responsibilities. |
| Sustainability Development and Risk Management Committee |
The Board delegates oversight of risk management to the Sustainability Development and Risk Management Committee. The Committee oversees the identification and assessment of current and emerging risks and opportunities, and reviews the Group’s risk management plans and processes across strategic, operational, financial, regulatory, ESG, climate-related, and catastrophic risk areas. The Committee also oversees the effectiveness of the Group’s risk management process by monitoring and evaluating the implementation of the risk management framework and risk management plans. The results of risk management oversight are reported to the Board of Directors for acknowledgment, as appropriate. |
| Audit Committee | The Audit Committee is responsible for matters relating to audit, internal controls, and assurance. Its responsibilities are distinct from risk management oversight, ensuring a clear separation between risk oversight and audit functions. |
| Chief Executive Officer | The Chief Executive Officer plays a key role in the risk management working group, working closely with department heads to ensure the effective implementation of the risk management framework. The CEO oversees the identification and management of material and emerging risks, supports the integration of risk management into business decisions, and promotes a strong risk-aware culture, with significant risk matters escalated to the Board as appropriate. |
| Senior Management |
The Group appoints a designated senior management member within the Risk Management Working Group responsible for risk management, reporting to the CEO, and independent from the Head of Internal Audit. Senior Management establishes and continuously improves risk management procedures, ensures compliance across all operational levels, and promotes a risk-aware culture. Senior Management defines clear roles and responsibilities for risk management, including key areas such as ESG, fraud and corruption, human rights, and health and safety, and supports the development of risk management capabilities. |
| Operational Level (Executives and General Employees) | Executives and employees are responsible for complying with risk management policies and managing risks within their roles and activities. They are expected to identify, report, and address risks, and support the effective implementation of controls. |
3.3 Risk Management Process
The Group has established a risk assessment methodology aligned with the principles of the COSO Enterprise Risk Management (COSO ERM) framework. The risk management process is conducted through a structured six-step approach as follows:

1. Objective Setting
The Group begins its risk management process by clearly defining operational objectives at both the organizational and departmental levels. These objectives are aligned with the Group’s vision, strategy, and business plans. Establishing objectives systematically enables the clear identification of events or factors that may hinder the achievement of goals and provides a fundamental basis for risk assessment and management in subsequent steps.
2. Risk Identification
Potential events or factors that may prevent the Group from achieving its defined objectives are identified by considering both internal and external factors, including changes in the business, economic, social, technological, and legal environments. This risk management framework also covers ESG (environmental, social, and governance) risks. The identified risks are recorded in a risk register for use in subsequent assessment steps.
3. Risk Assessment
The level of risk for each item is assessed by considering both the likelihood of occurrence and the potential impact. Assessments may be conducted both before and after the implementation of existing control measures to reflect the actual level of risk. The results of the assessment provide insight into the severity of each type of risk.
4. Risk Prioritization
Risks are prioritized by comparing them against the Group’s risk appetite to determine which risks should be addressed first. Risks that are high or exceed the acceptable level are designated as requiring urgent management action.
5. Risk Response
Appropriate risk response strategies are established, which may include risk avoidance, risk reduction or control, risk transfer, or risk acceptance within defined thresholds. Specific control measures, responsible parties, and implementation timelines are clearly assigned.
6. Risk Monitoring
Risks are regularly monitored and reviewed to assess the effectiveness of implemented measures, as well as to consider changes in risk levels or emerging risks. The results are reported to relevant management or committees, and the risk register is continuously updated to reflect current conditions.
Following risk identification at the organisational level, the Group classifies risks in line with its Risk Management Policy. Risks are categorised into four main types as follows:

3.4 Business Continuity and ESG Emergency Preparedness
The Company recognizes that ESG-related catastrophic events, including climate change impacts, natural disasters, and operational disruptions, may affect operations and stakeholder value. To address these risks, the Company has established a structured and organization-wide approach to emergency preparedness, embedded within its enterprise risk management framework. This approach includes systematic risk identification and assessment, together with consideration of ESG-related risk scenarios and potential disruption events, as well as the development of response plans to support timely crisis management.
The Company’s preparedness framework is supported by board-level oversight through the Sustainability and Risk Management Committee, which is responsible for overseeing risk management strategies, including climate and disaster-related risks. In parallel, operational readiness is reinforced through emergency response plans, regular drills, and the implementation of preventive and mitigation measures to minimize potential impacts and ensure continuity of operations under adverse conditions.
Cyber Threats and Data Privacy
Given the advancement of technology and online communication that have come to play a more vital role in business operations, the Group may face risks involving cyber threats and data privacy, which may lead to unauthorized alteration of information, information leakage, or data theft.
To prevent and reduce such impacts on business operations, management guidelines have been established. The guidelines include planning business operations to be flexible and supportive of changes in technology, and improving work processes to be responsive to technological developments. The Group also considers potential cyber threat scenarios as part of its planning to enhance preparedness.
In addition, the Group has assigned its Information Technology Team to monitor developments and patterns of cyberattacks and to regularly assess the performance of its cybersecurity systems. The Team is also responsible for providing data recovery systems in the event of cyber incidents to support business continuity, as part of its response to cybersecurity incidents, encouraging personnel to enhance their technological knowledge, and raising cybersecurity awareness across all levels of the organisation.
3.5 Code of Conduct
The Group has implemented a Code of Conduct that sets out the standards of ethical behavior and business practices expected of directors, executives, and employees. The Code covers key areas such as compliance with laws and regulations, conflicts of interest, confidentiality of information, fair treatment of stakeholders, workplace conduct, and responsible business practices.
The Code of Conduct is communicated across the organization, ensuring that all personnel understand and adhere to the Group’s ethical standards. Mechanisms are also in place to monitor compliance and address any violations in a timely and appropriate manner. The Board of Directors oversees the Company’s operations to ensure adherence to the Code of Conduct and promotes, supports, and drives management and employees at all levels, including subsidiaries, to strictly comply with the Company’s Code of Conduct.
The Code of Conduct is reviewed at least every two years to ensure its continued relevance in response to changing business and regulatory environments. Compliance is monitored annually, with results reported to the Board of Directors on a yearly basis (January–December).
3.6 Whistleblowing and Complaint Channel
The Group has established formal grievance and whistleblowing mechanisms that enable internal and external stakeholders to report concerns related to legal violations, unethical conduct, corruption, or weaknesses in internal controls.
Scope: This policy applies to all directors, executives, and employees, and covers breaches of laws, regulations, internal policies, or the Code of Conduct; actions that adversely affect the Group’s interests, reputation, or internal control systems; human rights violations such as harassment, abuse, or unsafe working conditions; and fraud, corruption, or misconduct undertaken for personal or third-party benefit.
Eligible Reporters: Reports may be anonymously submitted by both internal and external parties, including employees at all levels, contractors, joint venture partners, and other parties working with the Group, as well as external stakeholders and members of the public. This includes individuals who experience, witness, or are aware of misconduct, breaches of group policies, or legal violations, including those involved in investigations or legal proceedings.
Reporting Channel
Reports may be submitted either anonymously or with the reporter’s identity disclosed, provided that sufficient supporting information is included. Available reporting channels include:
- Email or direct reporting to the Audit Committee, Corporate Governance Committee, supervisors (manager level and above), the Human Resources function, Internal Audit, or the Company Secretary
- Written submissions to the Compliance Unit (designated Whistleblowing Recipient)
- Submission through the Group’s whistleblowing channel at Whistleblowing Channel, with the option for reporters to remain anonymous

Investigation to Find the Facts
- Review of allegation and investigation scope
- Collection and examination of relevant documents and evidence
- Interviews with relevant employees and parties involved
- Assessment against applicable laws, regulations, internal policies and the Code of Conduct
Follow-Up Actions
Remedial Measures
- Monetary compensation, as appropriate
- Non-monetary remediation such as apology, support, rehabilitation, or other assistance
Note: Remedial actions conducted through consultation and mutual agreement
Disciplinary and Legal Actions
For Responsible Parties
- Disciplinary actions in accordance with company rules
- Termination or removal from position where applicable
- Legal action if violations of laws or regulations are confirmed
Record Keeping and Ongoing Monitoring
Responsibilities
- Internal Audit Department
Key Actions
- Maintain register of complaints and non-compliance cases
- Track investigation status and outcomes
- Prepare periodic summary reports
Reporting
- Audit Committee and Corporate Governance Committee (Regular reporting at least quarterly)
Note: The Group shall monitor the implementation and effectiveness of corrective actions to ensure that identified non-compliance is adequately addressed and does not recur.
3.7 Auditor Rotation and Appointment
The Group is committed to maintaining the independence and objectivity of its external audit function. It complies with auditor rotation requirements prescribed by the Securities and Exchange Commission, ensuring audit partners are rotated within regulatory limits.
The appointment of external auditors is reviewed annually and proposed for shareholder approval at the AGM. The Group also conducted a tender process in 2022 to enhance competitiveness, independence, and audit quality, and will continue to periodically consider audit firm rotation and tendering in line with governance practices.
3.8 Provisions for ESG-Related Fines and Settlements
The Group adopts a prudent approach in assessing risks related to environmental, social, and governance (ESG) matters, including legal and regulatory compliance.
As at 31 December 2025, the Group has recognised provisions of THB 34,160,000 (based on legal counsel’s assessment and in accordance with applicable accounting standards) in relation to environmental-related litigation involving 2 indirect subsidiaries which the Group acquired their whole shares from previous shareholders in August 2020, but the incidents that caused this lawsuit had arisen before these 2 companies became indirect subsidiaries of the Group.
The Group is actively managing these matters through appropriate legal processes and continues to monitor developments and review provisions as necessary. Other ongoing cases do not involve monetary claims and are being addressed in the normal course of business.