Human Rights Risk Assessment
Human rights risk assessment has been integrated into various risk assessment processes at key stages of the Company’s business operations. These include the identification and assessment of environmental risks, as well as occupational health and safety hazard identification and risk assessment in accordance with ISO standards across all operational areas.
Human rights considerations are also incorporated into the Company’s risk assessment and internal control processes across all organizational activities. The Company provides opportunities for stakeholders who may be affected by human rights issues to express their opinions and expectations, which are taken into consideration in human rights risk assessments and in evaluating the effectiveness of impact mitigation measures.
Stakeholder feedback is gathered through various channels, including supplier and customer audits, grievance and complaint channels, Voice of Customer (VOC), and engagement with suppliers and business partners.
All identified risks are managed by the Risk Management Working Group and the Human Rights and Labor Practices Committee, which are responsible for proposing the human rights risk assessment plan covering both the Company’s internal operations and its entire supply chain for approval.
Relevant departments are required to conduct human rights risk assessments at least once a year, as well as collect and analyze the results and establish appropriate measures and management approaches. These are then presented to the Risk Management Committee for consideration.
Progress is also reported periodically to the management of each business function to ensure effective monitoring and continuous management of human rights risks.
The Company has established five levels of likelihood for the occurrence of potential events, as follows:
Level
Likelihood
Description
1
Very Low
No occurrence within the past 1 year.
2
Low
Occurs once per year and is unlikely to recur.
3
Moderate
Has occurred at least once and may occur up to 2 times per year, but can be prevented.
4
High
Occurs frequently or is likely to occur up to 3 times per year and cannot be prevented.
5
Very High
Occurs repeatedly or more than 3 times per year and cannot be prevented.
The Company has also established five levels of impact severity resulting from identified risks: Very Low, Low, Moderate, High, and Very High.
The assessment considers relevant human rights issues relating to employee rights, customer/supplier/business partner rights, and community and environmental rights. Each level of impact severity is determined based on the nature of potential impacts associated with the Company’s key operational processes. An incident may involve one or multiple human rights issues.
Where multiple issues are involved, the highest level of impact severity identified under the assessment criteria will be applied, as follows:
Employee-Related Issues
โอกาสที่จะเกิด
คำอธิบาย
Level
Impact Level
Description
1
Very Low
2
Low
3
Moderate
4
High
5
Very High
Customer / Supplier / Business Partner-Related Issues
โอกาสที่จะเกิด
คำอธิบาย
Level
Impact Level
Description
1
Very Low
2
Low
3
Moderate
4
High
5
Very High
Community and Environmental Issues
โอกาสที่จะเกิด
คำอธิบาย
Level
Impact Level
Description
1
Very Low
2
Low
3
Moderate
4
High
5
Very High
The Company assesses human rights risk levels based on the Likelihood and Impact Level of potential human rights impacts. The assessment results are used to prioritize human rights risks into four levels, as follows:
Risk Level Classification
คำอธิบาย
Risk Score
Risk Level
17-25
High
10-16
Moderate
4-9
Acceptable
1-3
Low
Human Rights Risk Assessment Matrix
Column 2
Column 3
Column
Column
Column 4
Impact Severity
Likelihood / Frequency of Occurrence
Description
Description
Description
Description
Row
Very Low (1)
Low (2)
Moderate (3)
High (4)
Very High (5)
Very High (5)
5
10
15
20
25
High (4)
4
8
12
16
20
Moderate (3)
3
6
9
12
15
Low (2)
2
4
6
8
10
Very Low (1)
1
2
3
4
5
The Company determines the severity of risk impacts by ranking risk levels from low to high and establishing appropriate risk management approaches for each level, as follows:
The likelihood and severity of the event are very low and considered insignificant. No further action is required.
No additional control measures are required. However, opportunities for further improvement should be considered, and the risk should be continuously monitored to ensure that the severity of potential impacts does not increase.
Efforts must be made to reduce the risk level by implementing appropriate risk mitigation measures within a reasonable timeframe. The effectiveness of these measures should be periodically monitored to ensure that the severity of the risk is reduced. Preventive and control measures may include the preparation of relevant documentation, preventive measures, and remediation guidelines for affected individuals.
The risk must be reduced immediately, with appropriate resources and specific control measures allocated to manage the risk during the corrective and improvement process. Additional measures may also be considered to control or further reduce the risk.
The Company conducts human rights risk assessments and monitors its human rights performance, while also providing employees with training and awareness programs to prevent potential human rights issues and adverse impacts arising from the Company’s activities. In 2025, the Company’s human rights performance was as follows:
Target
Actions
Performance Results
Zero Human Rights Violations
In 2025, there were no reported incidents of or complaints regarding human rights violations, and no high-risk human rights issues were identified from the Company’s risk assessment across its business activities and value chain.
In addition, the Company has established systematic and effective human rights practices and management processes, supported by the following measures:
Issue
Human Rights Prevention and Mitigation Measures
Fair and Equal Labor Practices
Occupational Health and Safety of Employees, Customers, Suppliers and Business Partners
Protection of Personal Data of Employees, Customers, Suppliers and Business Partners
Non-Discrimination against Customers, Suppliers and Business Partners
Environmental Impacts from the Company’s Operations
Product & Solution
Investor Relations