Importance and Mission

Efficient risk management and internal control mechanisms serve as the primary engine supporting the strategic objectives and sustainable growth of the organization.

The Company highly prioritizes systematic enterprise risk management in tandem with appropriate internal control and auditing systems. These frameworks are designed to prevent, mitigate impacts, and enhance organizational resilience against long-term uncertainties. Furthermore, they foster preparedness for adapting to potential future transformations. The enterprise risk assessment comprehensively encompasses emerging risks to instill absolute confidence among all stakeholders that business operations and institutional activities can successfully achieve the objectives stipulated under the Company's Risk Management Policy1

Supporting the SDGs Goals

Goal 17:
Strengthen the means of implementation and revitalize the Global Partnership for Sustainable Development
SDGs Goals 17

Goal and Performance

Goal
Covers all risk aspects: 100 percent.
Performance
In 2025, Covered all risk aspects: 100%.

Management Approach

The Company establishes an Enterprise Risk Management (ERM) system under the oversight of the Risk Management Committee. Utilizing the Three Lines of Defense model, the Company integrates Environmental, Social, and Governance (ESG) factors into its internal control processes. This integration aims to prevent corruption in accordance with the Anti-Corruption Policy2, protect customer data pursuant to the Personal Data Protection Policy3, and manage climate-related risks that could potentially jeopardize the debt-servicing capacity of agricultural customer segments.

Specifically, the Company emphasizes risk management tailored to the unique characteristics of microfinance and agricultural credit businesses. This encompasses credit risks under Responsible Lending practices, climate change transition and physical risks impacting agrarian client portfolios, cybersecurity threats, and fraudulent activity prevention, thereby ensuring robust security for all stakeholder groups.

Operational Implementation

  1. Systematic ERM Framework: Formulating a systematic enterprise risk management process covering risk identification, assessment, prioritization, and the establishment of risk mitigation plans.
  2. Whistleblowing and Fraud Investigation: Executing rigid procedures for tracking, investigating, and diagnosing fraudulent grievances and tip-offs in strict compliance with the Whistleblowing Policy4.
  3. Independent Policy Review: Reviewing core corporate policies and auditing their practical implementation across all operational branches and business units. This is conducted with absolute structural independence and without external interference in auditing and evaluation functions. The scope covers assurance engagements, advisory services, and the provision of strategic recommendations to support personnel at all organizational echelons, ensuring operational alignment with relevant laws, rules, and regulations.
  4. Cybersecurity and Data Protection: Prescribing stringent cybersecurity measures and personal data protection protocols, including system access controls, cyber threat prevention, data backup architectures, and regulatory compliance.
  5. Climate Risk Assessment: Assessing and managing climate-related financial risks, encompassing both physical and transition risks, while factoring in direct consequences on corporate operations and stakeholders.
  6. Loan Portfolio Risk Auditing: Instituting regular risk assessments that directly impact the credit and loan portfolios.

Performance and Quantitative Results (2025)

  1. Quarterly Risk Governance: Organizing business-unit-level risk management meetings every quarter to cultivate internal risk awareness and decentralized risk ownership, with operational outcomes reported to the Risk Management Committee on a quarterly basis.
  2. Whistleblowing Resolution & Zero Tolerance: In 2025, the Company received grievances through its Whistleblowing channels and detected irregularities via the internal audit system. Prompt investigative actions were executed, resulting in disciplinary sanctions and concrete process optimizations regarding repossessed vehicle auctions and payment collection procedures. These incidents caused zero impact on the Company’s financial position. The whistleblowing summary reports were submitted to the Corporate Governance and Sustainability Committee quarterly, and additional stringencies were enforced under a strict Zero Tolerance policy to prevent recurrence.
  3. Independent Audit Scope: The Internal Audit Department successfully reviewed and verified 9 core corporate policies. Every audited policy was reported to the Corporate Governance and Sustainability Committee each quarter to evaluate the alignment between written policies and actual branch practices, the effectiveness of field implementation, and the functional design of internal controls.
  4. Cybersecurity Infrastructure & Awareness: Installed an advanced external cyber threat detection and monitoring system, and conducted a comprehensive "Security Awareness Training" seminar. This initiative aimed to reinforce the knowledge, understanding, and appropriate behavioral patterns required to safeguard organizational data, corporate assets, and information systems from cyber threats and other security risks. The curriculum specifically empowered employees to confidently counter threats embedded within social media platforms and diverse online channels. The training was hosted on April 9, 2025, at the Head Office of Saksiam Leasing Public Company Limited, conducted by experts from Fortinet Thailand.

    Data Privacy Compliance Protocols (PDPA Enforcement). For every transaction involving the collection of stakeholders' Personal Data—defined as data capable of directly or indirectly identifying an individual—the Company strictly executes consent acquisition protocols or issues processing notifications in full compliance with legal mandates. Collection, retention, usage, and processing are strictly confined to data that is necessary and relevant to the specific transaction, as exemplified below:

    1. Credit Extensions and Loan Provision: Branch personnel must request explicit permission from loan applicants prior to executing any transaction. This consent is formally obtained before the extension of credit and is documented as a legally binding written instrument bearing the applicant's signature.
    2. Corporate Premises and Branch Network: The Company has deployed Closed-Circuit Television (CCTV) systems within the perimeters of its office buildings and branch facilities as part of its physical security measures. This architecture serves to prevent hazards to facility users and mitigate potential property damage to the Company, with prominent warning signage displayed at all premises.
    3. Digital Touchpoints and Web Interface: The Company provides clear notifications to web visitors regarding personal data collection configurations via its official Privacy Notice5, which is hosted on the corporate website.

    Data Security Milestone: In 2025, the Company achieved Zero Incidents regarding information security breaches, data leaks across all information technology systems, or personal data protection violations.

  5. Climate Strategy and CFO Certification: Formulated a comprehensive climate risk management plan and successfully executed the Corporate Carbon Footprint (CFO) project, achieving official CFO certification from the Thailand Greenhouse Gas Management Organization (TGO).
  6. Anti-Corruption Institutionalization (Thai CAC): Successfully applied for and renewed its certification as a full member of the Thai Private Sector Collective Action Against Corruption (Thai CAC), cementing standardized operational transparency and verifiable business ethics within the Thai private sector.

Stakeholders Directly Impacted

Shareholders
Shareholders
Customers
Customers
Partners
Partners
Creditors
Creditors
Employees
Employees