Risk and Crisis
Management

GRI 3-3
The current business environment is characterized by risk and uncertainty, stemming from geopolitical challenges and social polarization at both regional and global levels, economic vulnerabilities, and the constraints on economic, financial, trade, and investment activities, businesses face volatility in exchange rates, interest rates, and inflation. Additionally, emerging risks, stringent regulations, and societal measures in response to climate change and greenhouse gas emission reduction commitments are significant. These factors collectively impact business operations and necessitate companies to adapt to changing legal and regulatory frameworks aimed at reducing greenhouse gas emissions. Fluctuations in energy fuel prices under price control policies affect production operations, and exchange rate volatility impacts investment expansion, posing significant challenges to the company’s success factors and business goals in both the short and long term. Systematic, efficient, flexible, and timely risk management is crucial in supporting operations and mitigating potential impacts. Conversely, the company leverages these risks and uncertainties to create business opportunities, such as expanding into new energy businesses and related sectors, and adapting to new electricity production and distribution models in line with government policies, addressing evolving societal consumption behaviors. Based on the above principles and rationale, the company emphasizes and adheres to the Enterprise Risk Management (ERM) framework according to the international standards set by The Committee of Sponsoring Organizations of the Treadway Commission (COSO). This ensures that all business mechanisms and activities can appropriately apply risk management principles, ultimately benefiting the company. The company oversees enterprise risk management through the Risk Management Committee, assigned by the Board of Directors, and closely managed by the Risk Management and Internal Control Committee at the management level. The company’s risk and crisis management approach includes the following:

Risk Management
Culture

GRI 2-23, 2-24
Risk Culture 2025
With a business philosophy and culture aimed at creating shared value for all stakeholders, based on the fundamental principles of a positive corporate culture and clear operations, the company emphasizes fostering a robust risk management culture throughout the organization. This is achieved through development plans and operational strategies, both short-term and long-term, across various dimensions, including management systems and work processes, as well as personnel management. The enterprise-wide risk management framework encompasses key principles such as:

1. GPSC Risk Management Policy

GRI 3-3
The company, through its Risk Management Committee, has established a risk management policy to serve as a framework for overseeing and enhancing the efficiency of risk management operations. This policy integrates risk management at all levels across the organization and extends to the GPSC group level to align with the business strategies and goals, as well as adapt to changing conditions. It encompasses risk management in all dimensions, including strategic and investment risks, financial risks, business risks, technology and operational risks, legal and regulatory risks, personnel and organizational structure risks, environmental, social, and governance (ESG), corruption risks, and emerging risks such as information technology and cybersecurity. Moreover, risk management is designated as a responsibility of managers and employees at all levels throughout the organization. This ensures that the company's business operations are systematically managed under a comprehensive risk management framework that covers all business activities, linked with an effective internal control and audit system.

To ensure that the company's risk management policy remains relevant and aligned with current business contexts and goals, the policy is reviewed and subject to approval for any revisions annually.

Download Risk Management Policy Link

2. Risk Appetite

The Risk Appetite determines the acceptable level of risk in conducting business activities. This is based on principles of analysis and decision-making aligned with the company's environment, activities, and business goals. The company's acceptable risk level framework encompasses five key dimensions:
  • Financial Aspect: To maintain financial policy and structure levels, as well as an investment-grade credit rating.
  • Business and Operation Aspect: To ensure the stability and reliability of electricity production and distribution with zero incidents affecting workers and no negative impact on the environment or community.
  • Law and Regulation Aspect: To ensure compliance with laws, regulations, company policies, and to prohibit fraud and corruption, while adhering to human rights principles in employment under good corporate governance.
  • Strategy and Investment Aspect: To pursue investments aligned with the company's target portfolio, investment criteria, and financial policies, focusing on clean energy sources and the GPSC group's greenhouse gas reduction goals, ensuring value creation with careful consideration of impacts on stakeholders, communities, society, and the environment. Additionally, emphasis is placed on investment in research and development.
  • Human Resources and Organization Aspect: To develop the organization's and employees' capabilities in line with the company's strategy and business growth.

To ensure that the company's risk appetite framework remains relevant and aligned with current business contexts and goals, the policy is reviewed and subject to approval for any revisions annually.

3. Risk Criteria

The company has established risk criteria to align with the business operation framework, encompass dimensions of finance, business processes and operations, corporate reputation, customer aspects, and personnel. For analyzing the level of impact and the frequency of any risk events, a unified risk assessment criterion is applied across the entire organization, with specific sub-dimensions considered as shown in the picture.

To ensure that the company's acceptable risk level framework aligns with current business contexts and objectives, the company conducts an annual review and seeks approval for any necessary adjustments.

4. Enhancing Knowledge Management and Up-skilling for Executives and Employees Across Group Companies

through a blend of online (E-Learning) and hands-on workshop training. The training content will be comprehensive, in line with risk management policies and business contexts at both organizational and departmental levels, aimed at cultivating a unified organizational culture. Regular knowledge review sessions will ensure that employees receive relevant knowledge tailored to the current organizational and business landscape, empowering them to apply it effectively for enhanced operational efficiency.

5. Measuring Performance and Efficiency in Risk Management Operations

involves tracking the progress of organizational risk management quarterly through reports to the Risk Management Committee. Additionally, to drive performance efficiency towards the organization's predefined success objectives, the company also emphasizes the importance of driving key risk management through Key Performance Index (KPI) metrics for both management and employees. This serves as a mechanism to generate motivation and propel operational results towards the set goals effectively.

Enterprise Risk Management Structure and Framework

GRI 2-12, 2-13, 2-16, 3-3

The risk management of the company operates within the scope of authority, duties, and responsibilities of the specialized committee, which has the highest authority within the scope of risk management responsibilities of the organization, including:

Board Oversight
  • Board of Directors
    Responsible for considering significant risk factors that may arise, establishing comprehensive risk management guidelines, and overseeing management and executives to have an effective risk management system. They also address risk factors resulting from business opportunities and ensure that risk management aligns with current business context changes. They regularly approve the organization's risk management framework and review the company's performance, either annually or in case of significant impactful events.
  • Risk Management Committee (RMC)
    Operating under the charter approved by the Board of Directors to appoint certain members to perform specific duties. The RMC is tasked with defining and reviewing organizational risk management policies, overseeing, supporting, and monitoring the effectiveness and performance of organizational risk management aligned with strategies, business objectives, and changing scenarios. Additionally, they review current risk contexts to push for timely risk management strategies and actions concerning significant factors and events impacting company operations. Moreover, the RMC plays a significant role in supervising, supporting, and developing risk management at all levels throughout the organization to enhance operational efficiency aligned with strategies and business objectives, accommodating changing circumstances. They also ensure the acceptance of the company's acceptable risk framework, fostering widespread risk-awareness culture, and providing continuous efficiency-enhancing recommendations in risk management operations. The company mandates at least quarterly meetings to ensure ongoing effectiveness. (Further details regarding the scope, authority, duties, and responsibilities of the Risk Management Committee can be found in the Risk Management Committee charter.)

    Risk Management Committee Charter link

  • Audit Committee (AC)
    Reviews the effectiveness and adequacy of the Company's risk management system to ensure that it operates in accordance with the Audit Committee Charter.

    Audit Committee Charter link

Management Level
  • Management Committee (MC)
    Oversees and monitors risk management activities at the management level, considers significant risk issues, supports the RMCC’s operations, and promotes the integration of risk management into business management before reporting key matters to the Risk Management Committee (RMC), as appropriate.
  • First Line : Risk Owners/ Functions
    Every employee plays a role in managing various risks that may arise in their work to minimize the organization's exposure to damages under the most efficient business operations. This includes seeking business opportunities and executing risk management measures in various dimensions and activities. Their responsibilities involve assessing risks, uncertainties, and opportunities that may affect any goals or operations as set out to find management strategies. Moreover, they foster cooperation both internally within the organization and externally to support the organization's risk management culture and collective practices.
  • Second Line: Risk Management Function & Risk Management and Internal Control Committee (RMCC)
    The Risk Management Division serves as the Risk Management Function, responsible for developing the enterprise risk management framework, coordinating risk assessments, monitoring key risks, and supporting risk reporting across the organization. The Risk Management and Internal Control Committee (RMCC), comprising senior executives, drives the implementation of the Company's risk management policy and framework, oversees the effectiveness of the risk management and internal control systems, reviews significant risk issues, and reports the Company's risk management performance to the Risk Management Committee (RMC) at least quarterly.
  • Third Line : Internal Audit
    Provides independent assurance to the Audit Committee and the Board of Directors on the adequacy and effectiveness of the Company's risk management, internal control, and corporate governance processes, supporting the achievement of organizational objectives and the continuous improvement of operations.

ENTERPRISE RISK MANAGEMENT FRAMEWORK

GRI 2-16

In addition to the risk management committee structures mentioned above, the company also emphasizes the importance of personnel throughout the organization in both management and operational levels of various departments. This is to ensure that the context of business operations, governance, and performance enhancement can be cultivated from the employee/operator level all the way to the level of the highest-rank executive, through the responsibilities of each relevant position and committee, encompassing every activity across the Company’s business chain.

GPSC’s enterprise risk management framework and the connection between risk management components are as shown in the diagram.

RISK MANAGEMENT STRATEGIES

Under the enterprise risk management framework (ERM), GPSC has established guidelines for risk management operations at two levels: Corporate Level and Functional Level, ensuring comprehensive risk management across the organization and supporting the achievement of business objectives.

STRATEGIES FOR RISK MANAGEMENT

The risk management strategy, in addition to aiming to cultivate good knowledge throughout the organization for managers, employees, and stakeholders under the widely recognized Risk Culture, also encompasses efficient operational guidelines. These guidelines include appointing representatives from various units as Risk Agents, categorized according to the risks associated with all business activities of the company. Moreover, there is a central coordination and oversight for risk management, along with setting strategies and pushing for continuous improvement in the risk management system. All of this is aimed at ensuring comprehensive and integrated risk management in all dimensions, continuously developing the system, and driving it in the same direction as the organization's business strategy. Additionally, the company has fostered collaboration within the PTT Group to seek knowledge development in various risk management aspects, such as developing the Operational Excellence Management System (OEMS) and Sustainability Management.

CORPORATE RISK MANAGEMENT PROCESS

GPSC focuses on the importance of integrating participation in risk management at every level systematically. This includes assessing risk factors, analyzing and compiling risk issues that may impact the organizational context, aligning with the business strategy plan factors, which are internal, and risks from various changes occurring under the fluctuating business environment and emerging risks, which are external factors. It's supplemented with addressing problem issues and risks in operational activities at the unit level, which are significantly relevant to the business context. Furthermore, there's a push to elevate and enhance risk management operations at the unit level to integrate them into the organization's risk management processes in the short term (1 year), medium term (3-5 years) for consideration and approval. This serves as a framework for overseeing risk management and monitoring, as well as reporting operational results to align with organizational goals.

GPSC has set clear timeframes for reviewing risks and tracking operational results at least quarterly at both management and GPSC committee levels. Additionally, it considers reviewing and seeking approval for adjusting and adding organizational risk items significantly impacting GPSC (Emerging Risk) during the year to ensure the organization has processes in place to assess important changes and respond to new risks effectively throughout the year, whether they are short-term to medium-term risks, ensuring efficient handling. Overall, this is an important guideline that GPSC adheres to in using risk management systems as tools to drive strategic departments and operations to achieve strategic objectives. Furthermore, it promotes pushing for risk management to become part of the organizational work culture through various aforementioned operations.

In addition, the Company also emphasizes the integration of material issues into factors in the analysis of corporate risk management to the risk identification process to be considered comprehensively in all dimensions affecting stakeholders. The current risk assessment criteria for impact assessment have considered various dimensions comprehensively, from finance and operations including ESG. As a result, the assessment of the impacts of various material issues has enabled GPSC to effectively monitor the organization’s material risks, as well as determine corporate risk management strategies and implement adequate and appropriate impact mitigation measures.

RISK REGISTER

The assessment, analysis, review, and preparation of risk issues are carried out by relevant functions across various work processes, such as risk management in business operations; construction management; decision making in project investment development, project execution, including impact of occupational health, safety, and environment; and sustainability and human rights management. GPSC focuses on integrated operations and on putting in place adequate support measures in relation to risk assessment dimensions illustrated in the image below.

The assessment and preparation of the risk register are carried out in 7 steps as follows:

1. Objective Setting

This involves defining objectives/goals to clarify the scope of considering various trends of risks/uncertainties that may impact operational effectiveness. It aims to ensure that risk assessment and risk management planning are clear and efficient in terms of supervision, identifying plans and managers, as well as monitoring performance. The objective scope of risk consideration includes evaluating business activities and assessing risks at every level, such as:

  • Assessing the strategic level risk, which is the organizational business objectives, considered at the organizational level.
  • Evaluating the operational level risk of departmental business activities, considered at the departmental level.
  • Assessing specific tasks or projects, which are project-level risks under the supervision of related departments.
  • And other considerations, etc.
2. Risk Identification

This involves identifying all risks or events that may occur and potentially impact the achievement of set goals. These uncertainties can be either positive events (opportunities) or negative events (risks) that might arise. GPSC considers identifying risk factors through:

  1. 1) Assessing future scenarios by considering changes in both internal and external factors, encompassing emerging risks related to changes in business activities or contexts that may affect the organization's goal achievement, such as the stability of international economic and political conditions.
  2. 2) Evaluating situations arising from changes in normal business operations that may impact business conduct and/or current operational characteristics and potentially affect GPSC's business goals. Risk factors can be identified from various sources, such as personnel in relevant departments or through review, validation, and recommendations from committees and executives to manage risks in subsequent steps.

Under GPSC's risk management policy framework, identifying risk factors will be comprehensive in all dimensions, including financial and non-financial aspects, strategic and operational aspects, environmental, social, and governance (ESG) aspects, as well as emerging risks, classified by risk groups such as:

  • Strategic Risk This refers to risks arising from various factors that impact strategic objectives or goals, or risks from the chosen strategies that lead to strategic actions not meeting the business objectives. These risks affect the organization and stakeholders and stem from both external and internal factors. They include dimensions such as strategy, investment and business expansion, climate change, biodiversity, and changes in laws and regulations.
  • Business Risk This refers to risks arising from business operations with factors stemming from various uncertainties, such as increasing fuel prices, business competition, customer behavior, product prices, business competition, and unfavorable business laws.
  • Financial Risk This refers to risks that impose limitations on financial management, potentially affecting long-term business strategies. Examples include liquidity shortages, credit issues, capital management, and currency management. Financial risks may arise from income and capital structures, interest rate fluctuations, foreign exchange rate volatility, economic conditions, credit ratings, business strategy plans, and the current state of money and capital markets.
  • Operational risk This refers to risks that may cause damage to various operational areas, such as technology and operations, human resources, production, repair and maintenance of machinery and equipment, errors and inefficiencies in operations, compliance with legal and safety requirements, fraud, human rights, information technology and cybersecurity, supply chain issues, and project management not adhering to timelines.
  • Shareholder Investment Risk This refers to risks that may negatively affect shareholder equity, market prices of shares, or interest rates. These risks include uncertainties in shareholder investments, credit risks, and price risks.
3. Risk Assessment

GPSC conducts risk assessment and analysis in all dimensions of sub-risks according to the Risk Criteria in the main dimensions, which include financial, business process and operations, corporate reputation, customer, and personnel. These are the standard criteria used throughout the organization for considering enterprise-level risks, department-level risks, and investment risks in project/product development. The organization's standard risk assessment criteria are as follows:

  • Impact Assessment Criteria: The severity is divided into 4 levels: low, medium, high, and critical.
  • Likelihood Assessment Criteria: This is divided into 4 levels, ranging from :
    • Low likelihood (less than 10% chance, or never occurred or occurred once in 5 years)
    • Medium likelihood (between >10% and <20% chance, or occurred once in 3 years)
    • High likelihood (between >20% and <50% chance, or occurred once in 1 year)
    • Very high likelihood (critical) (more than 50% chance, or occurred more than once in 1 year)

GPSC presents the assessment results using a Risk Matrix to prioritize risks, with the following categories

  • Critical risk group (red): These are risks that require urgent management and mitigation to reduce potential impacts. They must be monitored and reviewed at least quarterly.
  • High-risk group (orange): These are risks that require proactive management and mitigation to reduce potential impacts. They must be monitored and reviewed at least quarterly.
  • Medium-risk group (yellow): These are acceptable risks but need to be monitored to prevent escalation. They must be reviewed at least once a year.
  • Low-risk group (green): These are acceptable risks that do not require additional monitoring measures. They must be reviewed at least once a year.

The risk dimensions outlined by GPSC include strategic risks, business operation risks, operational risks, and financial risks, with varying levels of risk management.

GPSC has divided the levels of management and governance into two levels:

  • Corporate Level: This considers significant impacts or damages that could prevent GPSC from achieving its objectives, strategies, and business plans as specified.
  • Functional Level: This considers impacts or damages that could prevent a department from fulfilling its objectives and responsibilities.

GPSC has conducted risk assessment, analysis, and prioritization through the risk matrix. The results are interpretated based on likelihood and magnitude of the potential impacts. Examples of GPSC key risks are presented in the table below:

Risk Area Risk Description Risk Area Risk Description
Strategic Risks Investment and Business Expansion Business growth of GPSC can be restricted by the external challenges e.g., fuel cost, fluctuation of exchange rate, and interests rate caused by macroeconomic. Financial Risks Over-reliance on Industrial Customer Income Risk associated with industrial customers that cause financially influences to GPSC revenue structure.
Organizational Capability The risk related to the organizational capability derived from work model and procedural transformation. Referenced Price to Power Generation & Distribution Volatility The price of fuel that is not aligned with the electricity cost can dramatically impact on GPSC’s profitability
Changed Rules and Regulations Changed Rules and Regulations can cause the business obstacles to GPSC and customer. Especially, the direct impact from changed regulations to strategies and business practices. Funding Management for Business Expansion The barrier on business growth of GPSC represented by funding management is related to the supporting of future investment plans, capital mobilization tools, the models aligned with economic and financial market conditions to optimize benefit to GPSC, credibility ratings.
Climate Change As of international goal in the GHG emission reduction, GPSC addressed climate change with the business commitment to tackle on the climate change by focusing on GPSC’s business operation. Interest Rate Volatility The volatility from loans is addressed as a financial risk with respect to the fixed and float rates that GPSC has to effectively manages proportions of fixed and float interest rates
Operational Risks Power Plant Reliability The risk represented by power plant reliability can impact to GPSC in delivering the products throughout supporting national economic growth and energy security. Exchange Rate Volatility An overseas investment come up with the fluctuation of exchange rate which can return to GPSC’ financial risk accordingly.
Quality, Security, Safety, Health, and Environment This risk is the potential thread to GPSC’s operation, especially business losses resulting e.g., disruption and discontinuity of operations together with impacts on communities, society, and the environment. Shareholder Investment Risks Credit Risks GPSC’s reliability can be risked provided that bond issuers performance falls short of expectations and the collateral is less than the overall debt.
Management of Projects under Construction The risk from the project under the construction can cause the negative impact on the reliable delivery of power and steam to customers and achieve financial performance aligned with the budget plan. Price Risks The price risks associated with GPSC can be occurred due to the general economic conditions, money market movements, interest rate changes, the interest rate policy fixed by the Bank of Thailand, inflation rates, remaining tenors, excessive demand, or bond supply shortages in the market.
Imbalanced Fuel Supply Portfolio Secure and maintain the energy source are the challenges to GPSC in preventing the risk of managing fuel supply and generation stability. Liquidity Risks Bond holders may not be able to dispose of bonds before maturity when there is no liquidity in the secondary or over-the-counter markets
Fraud and Corruption in Business Risk associated with employees to perform duties in conforming to good governance and Code of Conduct. Default Risks GPSC has no records of default on either principal or interest for bonds, mortgages, or loans from commercial banks, finance and securities firms, credit fonciers, and specialized financial institutions (SFIs).
4. Risk Response

GPSC ensures appropriate management to keep risks at an acceptable level by specifying a timeframe for risk management actions to reduce the likelihood and impact of risk events. Additionally, GPSC designates a Risk Owner responsible for developing and implementing the mitigation Plan.

For residual risks that remain at a high to critical level after control measures, it is necessary to seek risk response strategies. This involves selecting and implementing a Mitigation Plan to reduce the severity of these risks to an acceptable level.

The risk response strategies can be categorized into four types:

  1. Take/Accept/Pursue: No further action is taken because the residual risk is at an acceptable low level, or there is a desire to accept the risk associated with a certain action.
  2. Treat/Reduce: Additional actions are taken to reduce the likelihood or impact of the risk to an acceptable level.
  3. Transfer/Share: Some of the risk is transferred or shared with another person or entity to mitigate its severity.
  4. Terminate/Avoid: Actions are taken to cancel or avoid activities that generate the risk.

Examples of two key enterprise risks, together with their risk appetite levels, potential impacts, and mitigation measures, are presented below.

Risk Area Description Risk appetite level Likelihood Impact Level Mitigating Action
New Energy Transformation Management GPSC adoption of new S- Curve energy and related business i.e. Small Modular Reactors (SMR), CCS, Hydrogen, etc. are being prolonged in decision making and lead to the delay in the investment, resulted into the decarbonization target not achieved as plan and unable to incentivize business opportunities as expected
  • GPSC prioritizes the consideration and management of investments in clean/new energy/technology sources and related business that target to reduce greenhouse gas emissions of the GPSC Group and product to customers.
  • GPSC will invest towards a target portfolio that aligns with the company's investment strategy/criteria and policies
  • Analyze, develop & decision making of new business opportunity in GPSC’s business value chain such as Renewables, etc.
  • Study and explore pathway to develop new energy to solve business impact and capture opportunity corresponding to climate change in short - long term
  • Assign group of experts to conceptualized study on clean energy technologies that are suitable and/or beneficial to existing or future - to - be - company's business model
  • Seek strategic partnerships in global and local platform for knowledge transfer and opportunities for developing or being experienced in technology usage
  • Engage with related government authorities to support the relevant policy/regulation to push forward S-Curve study/development (CCUS/ Hydrogen/ Ammonia/ Biomass) to implementation phase
  • Govern the study of new s-curve energy in pipeline (i.e. H2, SMR CCS etc.) as plan in both short and long term to ensure the prompt response when worthwhile for investment and being granted the permission by regulators
Digital Transformation Management The possibility that digital transformation not implemented as roadmap or delayed to execute as plan
  • GPSC will develop its organizational capabilities to adapt to change and remain business competitive.
  • Develop knowledge and awareness of digital and AI application in company mindset to support of dynamic and more diverse business growth.
  • Identify all pain point/key gaps and prioritize to early execute as priority short term process improvement i.e. cross-functional process etc.
  • Review governing process and management of changes to ensure that new process can be practically implemented with effectiveness in term of compliance and time reduction with seamless operation
  • Enhance employee capabilities to groom from basic digital literacy to active technological adaptability through targeted upskilling i.e. AI fundamental & Usage, Data Analytics
  • Execute cyber security implementation in both IT/ OT to ensure the resilience of GPSC’s operational network and system

Low

Medium

High

Extream

5. Approval

After risk analysis and the creation of the risk register, verifying the completeness of the management plans/strategies and approving the implementation and risk closure is crucial for the thoroughness of the risk management process. GPSC divides risks into two levels:

  • Corporate Risk: This is prepared by the corporate risk management department in collaboration with relevant units and presented for review by the Risk Management and Internal Control Committee (RMCC) and the Risk Management Committee (RMC) before seeking approval from the GPSC Board of Directors.
  • Functional Risk: This is prepared by the risk-owning department in collaboration with relevant units and submitted for approval to the commandant accordingly.
6. Monitoring, Review & Reporting

Under the GPSC risk management policy, the charter of the Risk Management Committee, and the guidelines established by the Risk Management and Internal Control Committee (RMCC), GPSC continuously monitors, reviews, assesses, and reports on its enterprise risk exposure. The Risk Management Committee reviews the Company’s enterprise risk exposure at least once every quarter to ensure that identified risks remain responsive to current and future situations, events, and operational conditions. The following actions are taken

  1. Risk Monitoring, Review, and Reporting:

    GPSC designates clear responsibilities for monitoring, reviewing, verifying, and reporting risk items:

    • The RMCC at the management level is responsible for continuously monitoring departmental and corporate-level risks, as well as emerging risks. The results of monitoring significant corporate risks and new risks affecting GPSC’s business are reported to the Risk Management Committee (RMC) for ongoing management oversight to ensure an integrated view of risk management.
    • GPSC appoints a Risk Agent for each department to act as a central point for identifying risk factors and assessing risks using the Risk Register. The risk management department compiles the results and reports to the RMCC at the management level for continuous monitoring and review of risk management progress.
  2. Sensitivity Analysis and Stress Test

    GPSC recognizes the business challenges that have arisen and may arise in the future. Therefore, it places importance on managing uncertainties and their impacts by conducting Sensitivity Analysis and Stress Tests to predict these effects. This is done during the annual business planning period to address strategic management issues alongside creating a risk registry for both short-term and medium-term risks. This approach ensures that GPSC can face worst-case scenarios and has clear mitigation plans. Additionally, throughout the year, GPSC continues to review and assess the analysis and evaluations as situations change or new scenarios emerge during operations. This preparation aims to mitigate impacts and explore opportunities arising from changes that might affect business objectives, performance, and strategic direction.

    These activities are integrated into the quarterly risk assessment reviews or when new issues arise, such as fluctuating energy prices and policies that affect cost and revenue structures, impacting financial factors and performance. Geopolitical and geo-economic situations, coupled with global economic stability, money, and capital markets, also impact financial performance and growth targets, as well as strategic investment expansion plans. One of the tools GPSC uses to assess the severity of these impacts and plan appropriate preventive measures according to the risk level is Sensitivity Analysis and Stress Testing.

    GPSC focuses in the importance of regularly reviewing and adjusting risk management plans to align with the current situation. The objective is to comprehensively manage risks to maintain them at acceptable levels. In addition to the organizational risk issues approved by the GPSC board, if new risk issues arise during the year that could significantly impact GPSC, the risk management team, in collaboration with relevant units, will analyze and compile data for presentation to the Risk Management and Internal Control Committee (RMCC) for consideration before seeking approval from the Risk Management Committee (RMC). This is to include them as additional organizational risk items that require ongoing collaborative management.

7. Communication

GPSC emphasizes the importance of communicating risk-related issues to executives, employees, and stakeholders across all sectors. This is to raise awareness and promote participation in monitoring and pushing for prevention/remediation of existing and potential issues, in line with the practices that management prioritizes and consistently advocates for (Tone at the top). This is done through large and small group meetings within each department, dissemination of risk-related information via email, and integration into the content of internal training sessions, all in alignment with GPSC's advocated risk management culture. Moreover, GPSC stresses the importance of ensuring accurate and timely communication of significant risk-related information to external stakeholders in various situations.

The risk management overview is as shown in the diagram.

8. Risk Audit

For the purpose of assurance on overall risk management framework , which is one of the systems that support the success of an organization's mission and business objectives, auditing the effectiveness and operations of the system according to international standards is something that GPSC considers and emphasizes. The audit framework for GPSC's risk management system includes:

  • Internal Audit
    By GPSC's Audit Committee (AC), operating under the Audit Committee Charter, responsible for examining GPSC's risk management and internal control systems to ensure adequacy and effectiveness. The department overseeing and managing GPSC's overall risk management system proposes an annual risk management framework and guidelines for the committee's consideration at least once a year.
  • External Audit

    - Conducted by external auditors to certify compliance with international standards and best practices annually. Examples include certifications for ISO 9001:2015 Quality Management Systems, ISO 14001:2015 Environmental Management Systems, ISO 45001:2018 Occupational Health and Safety Management Systems, Integrated Management Systems (IMS) R-100 Rev.4, ISO 22301:2019 Business Continuity Management Systems, and ISO 27001:2013 Information Security Management Systems. Risk management is a crucial aspect evaluated for certification, from strategic considerations to operational practices, performance efficiency, and readiness to respond to emerging risks. GPSC is certified in all these areas.

    - PTT Public Company Limited, GPSC's major shareholder and a state enterprise, there are annual assessments of GPSC's overall risk management system's compliance with the PTT Group Way of Conduct, ranging from risk management policy to governance and implementation, based on the COSO ERM 2017 framework by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), an international standard. This includes principles and practices related to governance for state enterprises, as outlined by the State Enterprise Policy Office in 2019.

Correlation of risks

The risk issues classified as the most impactful on GPSC’s operations are the efficiency of investment, organizational capacity, compliance, power plant reliability, and project execution. Risk correlation is significant for GPSC’s risk management since it can cause a chain of effects which may increase or decrease the level of risk according to their relationship.

Chart of annual risk correlation analysis

Emerging Risks

GPSC recognizes emerging risks that may affect the Company's long-term business strategy and objectives. Emerging risks are regularly assessed to understand their potential impacts and identify appropriate mitigation measures. Examples of key emerging risks are presented below.

Emerging Risks Description Potential Business Impacts Mitigating Actions
Digital Transformation and AI Adaptation GPSC has integrated digital technology and Artificial Intelligence into core business, including production control, energy analytics, and strategic decision-making. The rapid advancement of AI—particularly Generative AI and Large Language Models—has introduced a new class of external risks that are unprecedented and not yet fully understood: AI-generated misinformation and disinformation that can distort operational decisions, adversarial manipulation of AI systems (data poisoning), and cyber threats targeting AI-integrated infrastructure. These risks differ from conventional IT risks they arise from the probabilistic and autonomous nature of AI systems. GPSC is in the early stages of building the governance, skills, and infrastructure required to manage these risks while their long-term impact on operational resilience, cybersecurity, decision-making reliability, and competitive position remains uncertain as AI adoption and regulatory expectations continue to evolve
  • Cyber threats targeting AI-integrated systems and digital infrastructure—including attacks on machine learning pipelines and OT-connected platforms—represent a new and expanding attack surface beyond conventional IT security, potentially causing system outages, data breaches, and reputational and financial damage.
  • AI-generated misinformation, disinformation, and data integrity failures from adversarial manipulation can directly compromise GPSC's production control decisions, energy forecasting accuracy, and analytical systems—leading to operational disruptions that are difficult to detect and attribute.
  • The rapid pace of AI adoption creates a workforce competency gap in AI model governance, data analytics, and digital system integration, risking slower technology implementation, reduced innovation capacity, and growing dependency on external vendors with limited internal oversight.
  • Prevent data leakage and strengthen cybersecurity through system design and testing, two-factor authentication, regular software updates, and prudent personal data management under oversight of the Board, management, and responsible functions.
  • Formulate and execute a long-term digital and AI roadmap compatible with GPSC's business context, including governance structures for AI model management, and build a digital & AI culture across GPSC Group to sustain capability in managing AI-related risks and opportunities.
  • Conduct routine phishing awareness programs and cybersecurity training for all personnel to build organizational resilience against social engineering and AI-enabled cyber threats, in compliance with GPSC's IT policies.
  • Develop upskilling and reskilling programs in AI, data analytics, and digital system integration to address workforce competency gaps and reduce dependency on external vendors.
Geopolitical Security Risk The escalating intensity of external risk derived from the international conflicts, together with the increasing geopolitical fragmentation through trade restrictions, sanctions, and regional realignment of global supply chains, has intensified geoeconomic uncertainty, energy security, and supply chain disruptions. These are increasing the volatility of fuel and energy prices, resulting inflationary pressures, higher transport and manufacturing costs, and global economic slowdown, creating long-term challenges for businesses to anticipate and manage emerging risks. These uncertain risks create long-term challenges in anticipating and managing emerging risks across GPSC, its customers, and stakeholders. For GPSC, risks may significantly affect fuel procurement, project investment costs, and electricity demand, requiring GPSC to strengthen energy security, diversify fuel and supplier portfolios, enhance supply chain resilience, and accelerate renewable and low-carbon energy investment
  • Impacts on energy and fuel stability, security, and price volatility of fuels, including natural gas and coal of GPSC’s business and feedstock/ raw material of customer/ supplier that resulted to return on business operation, power production and financial margins performance
  • Increase of supply chain impact from the surge of transportation, manufacturing & raw materials cost and supply shortage leads to the company business interruption
  • Decrease in customer demand and power consumption
  • The acceleration of energy transition into green and clean sources of energy for more self-resilience, compared to the dependency of conventional energy which may rely on imported fuel from external.
  • In short-term manage to maximize asset utilization and operate the business with optimum & reliable risk and opportunities to reducing uncertainty impact.
  • Seek investment opportunities in renewable energy supply chains and diversify portfolio of customers to support long-term business expansion and minimize risk of customer concentration in term of type and area.
  • Pursue investment opportunities to study and develop New S-Curve low-carbon technologies—SMR, hydrogen, ammonia, and CCS—to sustain long-term business growth beyond the present core power generation business and decarbonize GPSC Group and its customers in long term.
  • Study, develop, and drive the use of low-carbon fuels for power generation—including ammonia and hydrogen co-firing and SMR development—alongside CCS to stay prepared for GHG limitations and foster GPSC's emerging business opportunities.
  • Seek opportunities to secure sources of energy to decrease impact of supply chain volatility i.e. LNG shipper/importer
Economic Recession and Trade War Barrier International conflicts, geopolitical tensions, economic slowdowns, and expanding tariff and non-tariff barriers have evolved into increasingly interconnected and complex risks. These developments are reshaping global trade flows, industrial investment patterns, energy supply chains, and capital markets. While their impacts on GPSC are currently manageable, prolonged disruptions could significantly affect fuel procurement, industrial electricity demand, overseas investments, and long-term business growth, requiring continuous adaptation of the Company's strategy and risk management approach.
  • Increased volatility in energy security and fuel procurement costs.
  • Higher financing costs and capital allocation uncertainty arising from inflationary pressures and fragile international capital markets.
  • Changes in industrial production and export activities resulting from tariff and non-tariff barriers, potentially reducing electricity and steam demand from industrial customers.
  • Geopolitical developments affecting overseas investment execution, business partnerships, and long-term growth opportunities
  • Managing the impact on business performance through fuel price formulas used in electricity production and distribution contracts, along with plant optimization operations, production, and distribution improvements, and coordination with relevant external agencies.
  • Coordinating cooperation between customers/partners to maintain production and electricity delivery stability.
  • Risk management and impact mitigation through the Raw Material Price and Financial Hedging Committee, as well as monitoring interest rate situations and financial costs to find suitable financial instruments.
  • Managing risks and impacts from investment project selection, short and long-term evaluation, business partnership establishment, in-depth business environment study through GPSC personnel in the area, and considering Exit Strategy in appropriate situations.
Climate Regulation and Climate Action As international commitments, including those by Thailand, aim to address the reduction of greenhouse gas emissions, with Thailand setting a target to reduce emissions by 40% by the year 2030, it poses conditions affecting the current operations and business of GPSC. This necessitates seeking ways to reduce greenhouse gas emissions under the management of production from stable fossil fuels, essential for electricity generation to support industrial usage. This includes financial management and cost from policies supporting investments in clean fuel businesses, alongside maintaining business performance to respond to shareholders and stakeholders.
  • Measures to prevent trade barriers through taxes and additional expenses in products with higher greenhouse gas emissions than specified levels, affecting both customers and possibly leading to reduced product purchases and increased expenses for GPSC.
  • Accelerating production efficiency, energy fuel usage, investing in renewable energy, developing new business models for clean energy procurement, and certification of clean energy emissions.
  • Studying and developing new energy utilization technologies with low greenhouse gas emissions.
  • Exploring technologies for carbon capture and storage.
New Technology / Energy Advancement Risk The energy sector plays a vital role in the transition toward a low-carbon economy and sustainability. Conventional energy is being phased out and replaced by new advancements in energy technology. The accelerating pace of new energy, including solid-state batteries, SMR, H2–based energy, ammonia, and CCUS, poses a new and significant risk to the global energy sector including GPSC. These technologies have the potential to reshape the energy landscape, driving the transition from traditional centralized utilities to micro-decentralized, self-optimizing energy ecosystems. For GPSC, this could result in long-term shifts in the market and changes in customer expectations. This risk is still emerging as these technologies are in the early stages of development, and their impacts are yet to be fully realized. GPSC is preparing its business model called “S-Curve” to ensure the ability to adapt on these changes as a new pathway and integrate new energy solutions into its operations If GPSC delays implementing its S-Curve strategy and new energy solutions, the company may face penalties, fines, and rising compliance costs (e.g., carbon taxes) as stricter GHG emissions and sustainability regulations take effect. Failure to adapt could also expose the company to legal risks and greater financial pressures.
  • GPSC risks losing its market position if it fails to adapt to the shift toward new energy advancements. As competitors embrace emerging technologies and decentralization continues to disrupt traditional utility-based business models, GPSC could lose its competitive edge, leading to declining revenue and market share as customers increasingly demand more flexible, efficient, and sustainable solutions. To remain competitive, GPSC must proactively embrace platform-based, service-oriented, and data-driven approaches that align with evolving market expectations and sustainability goals.
  • If GPSC delays implementing its S-Curve strategy and new energy solutions, the company may face penalties, fines, and rising compliance costs (e.g., carbon taxes) as stricter GHG emissions and sustainability regulations take effect. Failure to adapt could also expose the company to legal risks and greater financial pressures.
  • Develop next-generation technologies such as solid-state batteries, hydrogen-based solutions, ammonia, CCUS, and nuclear microreactors (e.g., SMR), and secure strategic partnerships to accelerate integration and maintain competitiveness.
  • Evolve GPSC’s business model under S3 and S4 Strategies to be service-oriented and data-centric, integrating flexible energy solutions such as energy decentralization that combine renewable generation and energy storage for optimized, on-demand supply.
  • Govern the study to long-term R&D in emerging energy technologies and invest in infrastructure for decentralized energy systems to ensure GPSC is well-positioned for future energy solutions.
  • Collaborate with energy innovators and tech companies to adopt new technologies, reducing financial burdens while staying ahead in the evolving energy market.
  • Engage with related government authorities to support the relevant policy/ regulation/ to push forward new technologies to implementation phase.

Information Security / Cybersecurity Governance

GRI 3-3

Strategies for Success

Information security and cybersecurity have become vital components of corporate responsibility. As organizations increasingly adopt advanced digital infrastructure, the risks associated with cyber threats, data breaches, and system vulnerabilities continue to grow, therefore, posing significant operational, reputational, and stakeholder-related consequences. These risks impact not only business continuity but also the trust of customers, employees, and investors of the company.

In recognition of these challenges, GPSC has established a comprehensive policy and procedure to managing information security and cybersecurity with the highest level of responsibility, ensuring the protection of digital assets and the integrity of its operations. This includes continuously improving information security systems, ensuring integrity and protection of data, and monitoring and responding to information security threats. GPSC also promotes and establishes individual responsibilities for information security across its workforce and set up information security requirements for third parties (e.g. suppliers and contractors). These third-party requirements are outlined in the “Regulation on Information and Communication Technology Policy Standard Practice”, which specifies the security policies, protocols, and controls that external partners must comply with to conduct business with GPSC.

Through this framework, GPSC aims to mitigate potential risks/ threats arising from external relationships, safeguard shared systems and data, and ensure the continued integrity and confidentiality of GPSC’s digital assets.

Cybersecurity Policy

As digital technology and information systems are critical to business operation both the production system and the operating network that connect to the internet network which could lead to a risk of cyber threats. To productively and effectively facilitate the digital technology and information operation of GPSC group as well as be able to prevent threats and effectively manage the cyber and information risk in accordance with ISO / IEC 27001, NIST standard and relevant laws, the company has guidelines for information security and cybersecurity as follows:

Cybersecurity Policy
GPSC's Information Technology / Cybersecurity and AI governance structure
/storage/content/sustainability/governance-risk-compliance/risk-crisis-management/information-technology-cybersecurity-measure/gpsc-information-technology-and-cybersecurity-governance-en.webp

Board of Directors (BOD)

Board of Directors are responsible for reviewing and approving GPSC' s key strategies, policies, objectives, action plans, and financial goals as well as regularly overseeing and monitoring the executives so that such plans are carried out in accordance with the prescribed directions and strategies. Moreover, the roles and responsibilities of them are to consider potential risk factors, formulate comprehensive risk management guidelines, ensure that the executives operate with efficient risk management systems and processes in place and to ensure sufficient and effective internal control as well as regular assessment of the suitability of GPSC's internal control systems.

Risk Management Committee (RMC)

GPSC Risk Management Committee appointed by the Board, which has roles and responsibilities according to the charter consisting of determining and reviewing risk management policy and framework, monitoring and supporting the operation of risk management in accordance to the changing situations covering information technology and cybersecurity risk as well as providing recommendations for the Risk Management and Internal Control Committee (RMCC) (management level) and Management Committee (MC) to ensure that the company has an efficient risk management. The results of risk management operations will be reported to the Board.

Audit Committee (AC)

GPSC Audit Committee (AC) has duties to review to ensure that the internal audit systems, internal control systems and risk management of the company are appropriate and efficient as well as to guide and give any advice to management to improve processes effectively in order to reduce any risk factors.

Management Committee (MC)

GPSC Management Committee is responsible for monitoring and driving the business operations in accordance with the prescribed directions and strategies as well as managing any obstacles and risks which might affect business operations. In addition, the roles and responsibilities of them are to provide recommendations to President and Chief Executive Officer in order to make decisions on important issues to business operations and plans as well as to manage the working system with the same direction and to scrutinize the risk management of the company. The results of risk management and business operations will be reported to the Risk Management Committee and the Board, respectively.

Risk Management and Internal Control Committee (RMCC)

GPSC Risk Management and Internal Control Committee are responsible for governing risk management activities and internal control systems which cover all risks, including environmental, social, and governance risk (ESG risk) to ensure that the company can achieve organizational goals with reasonable confidence through supporting and monitoring the operation in accordance to the risk management policy and framework of GPSC Group as well as overseeing the operational risk management both corporate and functional risks. In addition, the roles and responsibilities of them are to scrutinize the risk management framework as well as to monitor and evaluate the results of risk management. They also have the responsibilities to support and provide recommendations to the management committee in risk management, according to their scope of duties as well as to develop enterprise risk management to align with international standard to ensure that the risk management system meets the requirements. The results of risk management will be reported to GPSC Risk Management Committee, Audit Committee, Management Committee and related functions. In case that there is a significant factor or situation which might affect the company significantly, the committee must report to the Board immediately.

Appointment of GPSC Corporate Services Management Meeting (CSMM)

Executive Vice President (EVP) Corporate Services holds executive-level responsibility for the company's information security and cybersecurity (Chief Information Security Officer ; CISO equivalent role), exercised through the chairmanship of the Corporate Services Management Meeting (CSMM), which oversees business process improvement, digital management and operations, cybersecurity, and the governance and application of artificial intelligence (AI) and enterprise data to support business performance, innovation, and sustainable growth across the GPSC Group. EVP – Corporate Services is the highest management level executive with dedicated responsibility for information security, with cybersecurity performance and risks reported to the Risk Management and Internal Control Committee and escalated to the Risk Management Committee.

In addition, senior executives from various departments join to perform the committee and be responsible for regulating and driving digital technology and cybersecurity operations to have the effective results and comply with the cybersecurity, ISO/IEC 27001, NIST standard, and relevant laws.

Digital technology and cybersecurity risk management and result of the operation will be reported to GPSC Management Committee as necessary. In case of emerging risk or high risk, the committee must report to the Risk Management and Internal Control Committee to consider and provide recommendations on the risk management as well as to concretely drive the efficient risk management.

Cybersecurity Working Team

Vice President (VP) Digital and AI Technology performs the chairman of Cybersecurity working team. The working team comprises representatives from key functions across the GPSC Group, including Corporate Services, Engineering and Plant Improvement, Internal Audit, Risk Management, Legal and Compliance, and Internal Control.

The Cybersecurity Working Team is responsible for implementing the Company's cybersecurity strategy and action plans in alignment with the Cybersecurity Policy, applicable laws, regulations, and relevant standards. The Working Team establishes the cybersecurity management framework, oversees cybersecurity risk management activities, coordinates cybersecurity implementation across business functions and operational sites, and monitors the effectiveness of cybersecurity controls. The Working Team also facilitates cross-functional collaboration, knowledge sharing, and progress monitoring, and regularly reports cybersecurity performance and key developments to the Corporate Services Management Meeting (CSMM).

ISO/IEC 27001 Information Security Management System (ISMS)

ISMS consists of 3 working groups as follows

Information Security Management Representative (ISMR)/ Information Security Management Assistance (ISMA) is the company's management representative which has responsibilities for supervising to establish, use and develop the information security management system in GPSC as well as for maintenance, continuously monitoring and improving to achieve the information security policy and to conform to ISO/IEC 27001 standard. In addition, ISMR/ISMA also has duties in providing recommendations and suggestions about information security and policy applying to all employees as well as supervising any changes that might occur in the company along with coordinating to assess, solve and appropriately control risks from those changes and in case of security breaches. ISMR/ISMA must report the result of the operation to CSMM.

ISMS Core Team (CT) consists of representatives from various departments. They have duties in coordinating with ISMR/ISMA to conduct risk assessments and manage risks for each segment as well as to measure the effectiveness of the process and control in the system. In addition, CT is responsible for coordinating with ISMR in the event of security breaches or any emergency cases to control and deal with these challenges that arise.

ISMS Document Controller (DC) is responsible for supervising and controlling the use of documents and records of the system to comply with the requirements of ISO/IEC 27001 standard, including coordinating with the GPSC central document controller team in order to operate the system to be in line with the company standard.

Information and Communication Technology (ICT) Standard Practice

GRI 3-3

To ensure that the governance, strategic direction, and management of Information and Communication Technology (ICT) across GPSC and GPSC Group companies are clearly defined, consistently implemented, and understood in accordance with recognized best practices—thereby enabling appropriate and secure operations, ensuring the continuity of business support, protecting the confidentiality of corporate and personal information, and complying with the applicable laws of the Kingdom of Thailand—GPSC hereby establishes the following Information and Communication Technology System Policy and related guidelines:

  • Section 1: General Provisions
  • Section 2: Information Security Management Policy
  • Section 3: Environmental Sustainability Policy for Information Systems
  • Section 4: Information and Communication Technology Governance Policy
Summary of ICT Standard Practice are following details :
  • Governance, Review and Endorsement

    ICT operations are conducted within the Company's enterprise risk management framework, with internal controls and process control points across all critical systems and regular review and monitoring. These regulations are reviewed and updated at least once a year

  • Purpose and Commitment

    GPSC and its affiliates recognize information and communication technology (ICT) as a vital enabler of business operations and performance. The Company maintains Group-wide regulations governing ICT oversight, direction, and management, aimed at ensuring information security, protecting the Company's confidential corporate information and personal data, and maintaining compliance with relevant laws of the Kingdom of Thailand, including the Personal Data Protection Act (PDPA).

  • Scope and Application

    The regulations cover the management, protection, and security of the Company's information and cyber systems, both inside and outside its premises, including procured cloud services. They apply to (1) all management, employees, and business units of GPSC; (2) external personnel authorized to access the Company's computer and information system properties or resources; and (3) affiliates over which GPSC has management control for the provision of ICT systems. Contractors, suppliers, and other relevant third parties form a user group required to comply with these regulations as a condition of their engagement with the Company.

  • Information Security

    The Company's security framework is founded on the principles of confidentiality, integrity, availability, accountability, authentication, authorization (least privilege / need-to-know), and non-repudiation.

    The Company manages information security through a management system aligned with the international standard ISO/IEC 27001 and externally certified, with continuous improvement. The information security program covers regular IT risk assessment; monitoring of and response to threats and incidents; business continuity management; access control; cryptography and encryption key management; physical and environmental security; change management; internal audit; and security awareness and training.

    Every employee and relevant external party carries defined responsibility for information security, and the Company establishes information security requirements for third parties and suppliers that access its systems.

    Compliance is monitored and inspected by management and independently evaluated. Employees who fail to comply are subject to disciplinary measures and may face criminal and civil liability; non-compliant external parties may face contract revocation or other legal measures. The Company applies a zero-tolerance approach to breaches.

  • Privacy and Data Protection

    The Company conducts its ICT operations under its privacy and personal-data protection commitments in accordance with the Personal Data Protection Act (PDPA). These privacy commitments apply across the Company's entire operations, including suppliers and data processors. Data protection is embedded within the Group-wide risk management and compliance framework, and breaches are subject to disciplinary measures under a zero-tolerance approach.

  • Responsible Artificial Intelligence

    The Company sets out principles for the safe and ethical use of artificial intelligence (AI), including generative AI, with the following commitments:

    • Respecting data privacy in the use and development of AI: personal and sensitive data must not be entered into, stored in, or analyzed by AI systems without authorization; privacy settings must prevent data being returned to AI providers, in line with PDPA/GDPR.
    • Protecting the cybersecurity of AI systems: only approved enterprise AI tools that have passed security controls may be used, and company accounts must not be used with public AI services without approval.
    • Keeping humans in the loop for critical decisions: AI must not be used for critical decisions without human review, and all AI outputs must be evaluated before actual use.
    • Defining clear boundaries for AI: permitted uses and explicit prohibitions are defined to prevent use beyond the intended scope.
    • Clear accountability: problems or risks must be reported to management through the chain of command, and use of AI tools requires approval by the responsible management.
    • Prohibited uses: AI must not be used to create disinformation, fake news, copyright-infringing content, or content that attacks or manipulates individuals.
  • Environmental Responsibility of ICT

    The Company applies environmentally responsible practices to its ICT operations, including the use of energy-efficient equipment certified by internationally recognized bodies (e.g., Energy Star, EPEAT), responsible device selection and disposal in accordance with accepted standards (e.g., Green Label, EU Eco-Label, ISO 14020), and reduction of ICT-related waste.

GRI 3-3

GPSC has organized training courses on information security and cybersecurity awareness, including compliance standards of the company's Information and Communication Technology Policy Standard Practice such as computers and software usage, internet usage, sending and receiving e-mails, and computer virus protection to employees at all levels, as well as new employees through online channels such as e-Learning and orientation, to raise awareness of cyber threats and know the policies and regulations for the use of information technology systems that employees at all levels must strictly adhere to as part of their performance evaluation. Employees with violations will be subject to disciplinary measures by the company.

GPSC Information Security Management Program 2025

In addition, GPSC has established business continuity and contingency plans as well as incident response procedures, which are implemented at least twice a year to ensure preparedness and responsiveness in the event of emergencies. Furthermore, GPSC assigns a third party to perform an annual vulnerability analysis of the organization's information technology systems. This assessment consists of four key activities: external penetration testing (targeting the organization's internet-facing systems), internal penetration testing (simulating attacks from within the network), vulnerability scanning to detect potential system weaknesses, and phishing mail testing. All activities are closely monitored and evaluated.

If any employee is found to have acted inappropriately or becomes a victim of the phishing test, GPSC will conduct targeted communication and organize training programs to raise awareness and enhance understanding of cyber threats among specific employee groups. In cases involving information security or cybersecurity incidents, employees are encouraged to contact the designated IT service channels, such as the IT Service Desk, system administrators, or PTT-Digital, to report the incident and initiate investigation and corrective actions.

GPSC has established channels for reporting emails received by employees that are suspected to be spam or Phishing Mail through the Report Phishing function. In the past year, GPSC has been certified in Information Security Management System – ISO/IEC 27001:2013 for data center, supporting infrastructure and cloud management (IaaS).

In order to ensure the effective, ethical, and secure use of Artificial Intelligence (AI) and Generative AI (GenAI) technologies across GPSC’s own operations and value chain, as well as compliance with relevant international standards and regulatory expectations, this Artificial Intelligence Policy is established. Responsible AI Policy was reviewed by the Corporate Governance and Sustainability Committee, a Board-level committee responsible for overseeing corporate governance and sustainability matters, in August 2026.

  • GPSC Responsible AI Policy
  • GPSC Responsible Artificial Intelligence Program
Updated as of July 2026

The content above is based on the sustainability reporting standards of the Global Reporting Initiative (GRI Standards) and externally validated and verified for data accuracy at the "Limited Assurance" level.