Management of ESG Risk

Business Ethics & Transparency

Societal

Economic

Environment

Risk Item

Human Capital Capability

Cybersecurity & Personal Data Protection

Climate Change

Risk Appetite

•  Commit to maintaining a sufficient leadership pipeline for all N-1 and critical N-2 positions.

•  Commit to maintaining and deploying a highly motivated, diverse, talented, and empowered workforce to ensure alignment with business direction

•  Strive to develop a global career track towards opportunities across countries

•  Commit to providing safe and reliable IT systems and processes, ensuring the protection of information, as well as compliance with applicable laws and regulations

•  Commit to ensuring adequate security controls following the international information security standard to ensure the confidence of interested parties

•   Commit to managing the transition and physical climate-related risks, both current and future scenarios, and managing the risks and opportunities associated with the strategic commitment to achieve the net-zero target as planned

Likelihood

Medium

Medium

Medium

Impact

High

High

High

Mitigation Action

•  Align organizational structure with business needs for agility and efficiency

•  Allocate 5% of the salary budget for training and development

•  Develop a corporate learning framework to address competency gaps

•  Implement the Banpu Global Leadership Program for cross-cultural collaboration

•  Strengthen key professional skills and cultivate a growth mindset with digital capabilities

•  Use the Success Factor system for succession planning in critical roles

•  Adopt ISO/IEC 27001 Standards by establishing cybersecurity policies to prevent threats

•  Appoint Global Information Security Officer (GISO) to oversee cybersecurity and ensure data protection compliance

•  Strengthen cyber oversight by conducting vulnerability assessments and enhancing Cyber-Physical Systems (CPS)

•  Conduct cyber drills by performing annual response and recovery exercises

•  Set up Security Operation Center (SOC) to monitor and respond to cyber threats in real time

•  Enforce Data Privacy Policies by safeguarding sensitive information to build trust

•   Set targets to achieve Net Zero by 2050, reduce emissions by 20%, and cut coal-related EBITDA to below 50% by 2030

•   Set up the Climate Change Committee to monitor changes in related policies and regulations

•   Embed climate change management as one of the KPIs for the CEO and senior management

•   Disclose Climate Change Report following the TCFD framework

•   Expand investments in renewable energy and related business (e.g., CCUS)

Feedback