Risk Management
The current business environment is increasingly challenging and subject to uncertainties arising from both external and internal factors. These circumstances necessitate the continuous enhancement of the Company’s risk management framework to ensure effective risk identification, proactive response to change, and protection of core business operations. Such efforts support sustainable growth while enabling the Company to appropriately capture opportunities and generate long-term returns.
Risk Management Policy and Governance
The Company has developed risk management framework in alignment with the Committee of Sponsoring Organizations of the Treadway Commission Standard (COSO). This integrated approach covering the entire organization and all types of risks across business activities. To ensures that the Company's risk management processes are effective and efficient, capable of managing risks at risk appetite levels, and supporting sustainable business operations. The involved personel include:
Board Level
- Audit and Risk Management Committee appointed by the Board of Directors, is responsible for reviewing the adequacy and effectiveness of risk management, including compliance with risk management policies and strategies, as well as the level of risk appetite.
- Executive Committee oversees and monitors key risks status, risk management, and promotes a risk management culture.
Management Level
- Risk Management Sub-Committee is independently established, with the Chief Executive Officer serving as its Chair. The Committee plays a key role in driving the Company’s risk management practices by reviewing key risks, monitoring the implementation of risk mitigation measures, and evaluating Key Risk Indicators (KRIs).
- Risk Management Office is responsible for promoting and disseminating risk management knowledge, providing guidance and advisory support to relevant functions across the organization, and monitoring the progress of risk management implementation.
Operational Level
- Risk Champions act as key coordinators, serving as a liaison between business units and the Risk Management Office.
- All employees are expected to cooperate in risk management as an integral part of their responsibilities, act in alignment with the Company’s risk management culture, and report identified risks through the prescribed channels in a timely manner.
Central Function for Driving and Coordinating Collaboration
- Risk Management Office is responsible for promoting and disseminating risk management knowledge, providing guidance and advisory support to relevant functions across the organization, and monitoring the progress of risk management implementation.
- Internal Audit Office is responsible for evaluating the risk management process, providing recommendations for improvement, and utilizing risk assessment results in the preparation of the risk-based audit plan.
The Company requires risk assessments to be conducted at least twice a year, or whenever there are significant changes in the business environment. The Risk Management Sub-Committee reports the assessment results and progress of risk management actions to the Executive Committee and the Audit and Risk Management Committee, respectively.
Risk Management Framework and Tools
The Company has developed a “Risk Management Manual” to consolidate the procedures and tools used in risk management, with details as follows:
Establish the context
Assessing the business environment at the macroeconomic, industry, and company levels to gain an understanding of current conditions and trends that may affect future risks and opportunities.
Identify risk and opportunity
Identifying risks that may affect the achievement of the Company’s objectives, covering existing risks, emerging risks, and business opportunities, through the use of various tools and techniques such as the identification of internal and external issues, as well as cause-and-effect analysis under scenario-based assumptions.
Assessing and prioritizing risks, as well as defining risk mitigation measures and Key Risk Indicators
Assessing and prioritizing risks, as well as defining risk mitigation measures and Key Risk Indicators (KRIs).
-
Defining the risk appetite level as follows:
- CPF does not accept investments that yield returns lower than the cost of capital, affect financial liquidity, or hinder sustainable business growth.
- CPF does not accept business disruptions or operational interruptions that negatively impact customers, consumers, personel, society, the environment, or conflict with principles of good corporate governance.
- CPF does not accept risks that may affect the Company’s reputation, image, or brand.
- CPF does not accept risks arising from non-compliance with laws, regulatory requirements, applicable international standards, or any form of corruption in all countries where it operates.
- Conducting risk assessments through workshops and presenting the results on a Risk Heat Map. In addition, scenario analyses are performed for specific risks, such as climate change risks and risks arising from regulatory changes.
- Prioritizing risks, whereby risks exceeding the acceptable level are classified as key risks and require the identification of their underlying root causes.
- Defining risk mitigation measures and Key Risk Indicators (KRIs), with ensuring their efficiency and effectiveness prior to implementation.
Mrnitor and report risk
Reporting and monitoring the progress of risk mitigation actions and the status of Key Risk Indicators (KRIs) in accordance with the prescribed reporting cycle.
Emerging Risks
In 2025, the Company identified new emerging risks that may affect the Company's ability to achieve its objectives, as well as business opportunities. These are illustrated in the Risk Heat Map as follows:
Further details on the emerging risks and related risk management measures can be found here.
Risk Management Culture
The Company is committed to fostering a strong risk management culture across the entire organization through the following initiatives:
Environmental
- Integrating risk management into the formulation of the Company’s strategies, business plans, and budgeting process.
- Communicating the risk management policy, including clearly defined roles and responsibilities of personnel across the organization.
- Integrating risk management principles into the Company’s policies, rules, and operational procedures.
Awareness Building
- Communicating risk events together with preventive and mitigation measures, as well as risk management principles, through various communication channels such as posters and short videos, including knowledge-based games to enhance understanding and practical application.
- Enhancing risk management knowledge of directors, executives, and employees through structured training programs.
Implementation
- Assessing business risks and opportunities, establishing risk mitigation approaches, defining Key Risk Indicators (KRIs), and monitoring the progress of risk management activities.
- Assessing risks associated with various activities, including climate change, flooding, drought, human rights, mergers and acquisitions, investments in large-scale projects, occupational health and safety, and new product development.
- Applying risk assessment outcomes to drive continuous process improvement.
- Reporting risk incidents through the prescribed reporting channels.
- Promoting the inclusion of risk-related agenda items in business unit meetings and encouraging the sharing of risk management experiences across business units.