Announcement of the Board of Directors of
RATCH Group Public Company Limited No. 1/2026
On Group Risk Management Policy

RATCH Group Public Company Limited (The Company) places great importance on effective risk management by integrating its goals, mission and vision in accordance with the principles of Enterprise Risk Management and COSO framework, Enterprise Risk Management—Integrating with Strategy and Performance. Risk management is used as a strategic tool to drive organizational performance, create, preserve, and enhance value, minimize losses and potential adverse impacts, and capitalize on opportunities. It also aims to strengthen the Company’s potential and capabilities to achieve its objectives and support sustainable growth.

Objectives
  1. To establish a framework and structure for risk management policy and process that can be effectively implemented throughout the organization and cover all functions, business processes, and operational activities, with clearly defined and appropriate roles and responsibilities for risk management at both the organizational and operational levels.
  2. To apply the risk management policy and governance framework to organizational management in order to achieve business objectives, create added value, enhance competitiveness and strengthen business stability. This is intended to deliver the greatest benefit of the Company’s stakeholders, in alignment with the principles of Good Corporate Governance and Sustainable Development.
Scope

This Policy shall apply to the Company, its subsidiaries and joint ventures.

Definitions

Event means an occurrence or circumstance that may result in either a negative outcome (Risk) or a positive outcome (Opportunity) affecting the achievement of the organization’s objectives.

Risk means the possibility that an event will occur and adversely affect the achievement of the organization’s strategies and operational objectives.

Enterprise Risk Management (ERM) means a process for identifying, assessing, and managing risks and opportunities in accordance with the established risk management framework to provide reasonable assurance that the organization can achieve its defined objectives or strategies.

Key Policy Guidelines
  1. Risk management shall be the duty and responsibility of all executives and employees, who shall be aware of the risks associated with the operations of their respective functions and the organization as a whole. The Company shall promote a risk management culture throughout the organization by enhancing knowledge and understanding, fostering awareness, and cultivating shared accountability for risks, controls, and the potential impacts of risks on the Company across all management activities, business processes, and operations.
  2. The Company shall establish an enterprise risk management framework and a systematic risk management process in accordance with internationally recognized standards. The framework shall cover risks arising from the Company’s operations that may affect Environmental, Social, and Governance (ESG) matters. The risk management approach shall be consistent and interconnected at both the enterprise and operational levels. Enterprise risk management shall also be integrated into decision-making processes relating to the formulation of strategies, business objectives, and operational plans throughout the organization.
  3. The Company shall establish appropriate, adequate, and internationally aligned risk management processes, approaches, and measures, covering risk identification, risk analysis, risk assessment, risk prioritization, risk response planning, risk treatment, risk control and monitoring, risk reporting and evaluation, and continuous risk communication and information sharing. Such processes shall cover material existing risks, new risks, and emerging risks. The Company shall place emphasis on managing risks to ensure that they remain within acceptable levels.
  4. The Company shall measure risks using both qualitative and quantitative approaches. Qualitative measures may include impacts on the Company’s reputation and corporate image, while quantitative measures may include potential losses, decreases in revenue, and increases in expenses. Risk assessment shall take into consideration both the likelihood of occurrence and the potential impact.
  5. The Company shall establish its Risk Appetite and define relevant risk events and/or Key Risk Indicators (KRIs) to serve as early warning signals indicating trends in risk exposure and whether risks are increasing or decreasing.
  6. The Company shall establish a Risk Management Manual to provide guidelines and requirements for executives and employees to follow, thereby supporting effective control of risks arising from the Company’s operations.
  7. The Company shall review its Risk Management Policy, guidelines, and Risk Management Manual at least once a year to ensure their continued appropriateness, effectiveness, and alignment with changes in the Company’s business, risk environment, and applicable standards.
Risk Management Framework

The Company’s risk management framework is based on internationally recognized practices, including the COSO (2017) Enterprise Risk Management Framework: Integrating with Strategy and Performance and COSO and WBCSD (2018) Enterprise Risk Management: Applying Enterprise Risk Management to Environmental, Social and Governance-Related Risks.

The framework consists of the following five components:

  1. Governance and Culture
  2. Strategy and Objective-Setting
  3. Performance
  4. Review and Revision
  5. Information, Communication, and Reporting
Roles and Responsibilities
  1. Board of Directors (BOD)
    • Oversee the Company’s enterprise risk management, covering risks arising from the Company’s operations that may affect Environmental, Social, and Governance (ESG) matters, as well as review the risk management practices and assess the effectiveness of the Company’s enterprise risk management processes.
    • Approve the Key Risk Indicators (KRIs) and Risk Appetite to establish appropriate thresholds for monitoring and managing the Company’s risk appetite.
  2. Risk Management Committee (RMC)
    • Review and recommend the Company’s Risk Management Policy, enterprise risk management framework, and overall risk management approach, including risks arising from the Company’s operations that may affect Environmental, Social, and Governance (ESG) matters, prior to submission to the Board of Directors for consideration and approval.
    • Oversee the risk identification, assessment of impacts and opportunities, risk prioritization, and development of risk response measures, as well as monitor compliance with the Company’s Risk Management Policy.
    • Review and recommend the Key Risk Indicators (KRIs) and Risk Appetite for consideration and approval by the Board of Directors.
    • Support the review and assessment of the adequacy of the Company’s Risk Management Policy and risk management system, including the effectiveness of the system and compliance with the established policy.
    • Regularly report the Company’s risk status and the implementation of risk response measures to the Board of Directors.
    • Promote and support risk management activities at all levels of the organization, from the enterprise and business-unit levels to the operational level.
  3. Risk Management Team (RMT)
    • Implement the Risk Management Policy, enterprise risk management framework, and overall risk management approach.
    • Monitor and keep abreast of risk management practices and requirements in accordance with internationally recognized standards and applicable regulatory requirements.
    • Study and analyze internal and external factors that may affect the Company’s operations, and identify the nature and key drivers of associated risks.
    • Propose risk management approaches and measures to the Risk Management Committee for consideration and approval.
    • Monitor and oversee the implementation of risk management activities to ensure alignment with the approaches and measures approved by the Risk Management Committee.
    • Prepare quarterly reports on the Company’s risk status and the implementation of risk response measures for submission to the Risk Management Committee.
  4. Corporate Planning and Risk Management Division
    • Develop and/or review the Risk Appetite, Risk Management Policy, enterprise risk management framework, and key risk management processes for the organization, and submit them to the Risk Management Team (RMT) and the Risk Management Committee (RMC) for consideration and approval.
    • Identify, analyze, assess, prioritize, and monitor and report on risks, including strategic, financial, operational, and legal and compliance risks, to support the Company in achieving its business objectives.
    • Identify the Company’s material corporate risks, covering short-term and long-term risks as well as emerging risks, and submit them to the Risk Management Team (RMT) and the Risk Management Committee (RMC) for consideration and approval.
    • Develop Corporate Key Risk Indicators (Corporate KRIs) to monitor risk trends and provide early warning signals, and submit them to the Risk Management Committee (RMC) for review and endorsement.
    • Prepare periodic enterprise risk management reports and submit them to the Risk Management Team (RMT) and the Risk Management Committee (RMC) for consideration and approval, and report the relevant risk management matters to the Board of Directors for acknowledgment.
    • Monitor and consolidate risk management reports from functions, business units, and Group companies to ensure that risk management processes are implemented consistently throughout the organization and appropriately linked to strategic plans.
    • Provide support, advice, and guidance on risk management processes to all functions and business units across the organization.
    • Monitor emerging risk trends and developments, as well as relevant standards, frameworks, and regulatory requirements, to facilitate the continuous improvement of the Company’s risk management processes.
  5. Business Units / Responsible Functions Identify, assess, manage, and monitor and report risks that may affect the operations and performance of the projects or functions under their respective responsibilities.
  6. Employees All employees are responsible for complying with established risk management procedures and for promptly reporting any identified risks to their supervisors or the Risk Management Team (RMT).

This Policy is hereby announced for acknowledgment and compliance by all concerned. The previous announcement of the Board of Directors No. 2/2019, Subject: Risk Management Policy, dated April 17, 2019, is hereby cancelled and superseded by this Policy.

Announcement Date: 23 April 2026

Chairman of the Board of Director
RATCH Group Public Company Limited