Airports of Thailand PLCบริษัท ท่าอากาศยานไทย จำกัด (มหาชน)

Importance

AOT places strong emphasis on risk management as a key mechanism for supporting stable and sustainable airport business operations. The Company has implemented an integrated enterprise-wide risk management approach in line with internationally recognized practices, with the objective of achieving its strategic goals, enhancing business continuity, and strengthening confidence among all stakeholder groups.

Policy

AOT has established comprehensive policies on risk management, internal control, and business continuity management to ensure that executives and employees at all relevant levels adopt and implement consistent practices across the organization. These policies are aligned with AOT’s enterprise plan, operational plans, and project management framework, as well as applicable laws, regulations, and organizational policies relevant to the Company’s operations.

The policies related to risk management, internal control, and business continuity management include:

In fiscal year 2025, AOT continuously reviewed and enhanced its risk management policy, with a focus on implementing integrated enterprise-wide risk management in alignment with good corporate governance principles and the organization’s core values, while strengthening value creation and operational resilience.

The policy establishes key implementation approaches as follows:

See More Details

AOT Risk Management Policy

Ministry of Finance Criteria on Standards and Guidelines for Risk Management Practices for Government Agencies

Business Continuity Management Policy

Internal Control Policy

Ministry of Finance Criteria on Standards and Guidelines for Internal Control Practices for Government Agencies

Risk Management Committee Charter

AOT Integrated Governance, Risk Management, and Compliance (GRC) Policy

Management Approach

AOT adopts the Three Lines of Defense principle in governing and controlling enterprise risk management operations to ensure alignment with the Company’s risk management framework. The structure consists of operational units (First Line), oversight and compliance functions (Second Line), and internal audit functions (Third Line). Each line of defense contributes to reducing and preventing risks, enabling the organization to achieve its objectives effectively while strengthening confidence among all stakeholder groups. The structure comprises the following levels:

AOT’s risk management structure comprises the following levels:

Board Level

Senior Management Level

First Line: Operational Units

Second Line: Oversight and Compliance Functions

Third Line: Internal Audit Function

Key Operational Responsibilities

Risk Management Framework

AOT has developed the Risk Management Manual for Fiscal Year 2026 to serve as an integrated enterprise risk management guideline in alignment with the framework of the Committee of Sponsoring Organizations of the Treadway Commission – Enterprise Risk Management Integrating with Strategy and Performance (COSO-ERM 2017), the Ministry of Finance’s Criteria on Standards and Guidelines for Risk Management Practices for Government Agencies B.E. 2562 (2019), as well as guidelines issued by the Securities and Exchange Commission of Thailand (SEC).

The Company integrates risk management processes into the development of AOT’s enterprise plan and the management of significant projects to ensure timely and continuous management of risks and potential crises that may affect business operations. This approach also supports AOT in achieving its strategic objectives and organizational goals effectively.

Integrated enterprise risk management in accordance with the COSO-ERM 2017 framework consists of five components and twenty principles, as follows:

Risk Management Handbook 2025

Risk Management Plan

Governance, Risk Management and Compliance Handbook

Risk Management Processes

AOT has established a structured Risk Management Process to identify and analyze potential events, changes, or uncertainties—both internal and external—that may affect the organization’s operations. This process is conducted regularly twice a year as part of the Risk Exposure Review: one prior to the start of the fiscal year, and another as a mid-year review. Additional reviews are conducted immediately when significant changes that may impact AOT occur.

AOT has conducted an analysis of information derived from eight key areas of change, along with other relevant factors. The information obtained has been used to assess the severity of risk issues in terms of both Likelihood and Impact in order to determine appropriate risk management approaches and plans.

The results of this analysis are utilized in formulating risk management strategies, as well as enhancing the annual operational plan and organizational management guidelines to effectively respond to long-term changes. In addition, the analysis serves as an important foundation for supporting AOT’s future growth and risk management efforts.

AOT establishes and reviews Key Risk Indicators (KRIs) to identify and monitor significant risks that may affect the organization. The KRIs are designed to align with the organization’s strategic objectives and serve as tools for risk tracking, as well as early warning signs for potential significant risks in the future.

The KRIs are categorized into three levels to support analysis and decision-making for improving the risk management process. The establishment of KRIs enables AOT to effectively monitor and manage risks in alignment with the organization’s strategic objectives.

AOT has analyzed potential risks that the organization may encounter through the development of a Risk Universe as an input for preparing the Risk Management Plan. The analysis considered six key sources in accordance with the State Enterprise Assessment criteria on Core Business Enablers, Aspect 3: Risk Management & Internal Control (RM&IC), as follows:

1. Laws and government policies

2. Strategies

3. Board and management policies (Tone at the Top)

4. Supply Chain

5. Key Performance Areas (KPAs) / Performance Agreement (PA)

6. AOT’s enterprise risk factors from the previous fiscal year

Based on the Risk Universe information above, the identified risk issues will be assessed in terms of severity using the evaluation criteria for Likelihood (L) and Impact (I) in order to determine the level of risk severity should such events occur.

Risk issues assessed as having a high or very high level of severity will be subject to a review of the adequacy of control measures. The criteria for evaluating the effectiveness of control measures will be considered from three perspectives: (1) performance results compared with targets, (2) control measures, and (3) monitoring. If the evaluation result in any one of these perspectives scores below Level 3, the effectiveness of the control measures will be considered “inadequate.”

Since the severity level of the risk issue exceeds the organization’s acceptable risk threshold, regardless of whether the existing control measures are adequate, the risk issue will be further assessed for its organizational impact across four dimensions: (1) impact on strategic objectives or enterprise-level goals, (2) scope of impact propagation, (3) level of decision-making or governance required, and (4) impact on reputation and relationships with key stakeholders.

If the overall average assessment score is greater than or equal to 4, the risk issue will be selected as an enterprise risk factor. However, if the overall average score is below 4, the issue will be further considered as a Risk Universe issue at the division, department, office, or airport level.

To ensure effective enterprise risk management, Airports of Thailand Public Company Limited (AOT) has established goals and objectives as the starting point of its risk management process to provide reasonable assurance that risk management activities achieve the intended objectives. AOT defines its risk management objectives through the establishment of Risk Appetite (RA) and Risk Tolerance (RT) levels.

Furthermore, AOT has established Risk Appetite (RA) and Risk Tolerance (RT) separately for four categories of risk: Strategic Risk, Operational Risk, Financial Risk, and Compliance Risk.

In addition to establishing risk management goals and objectives, AOT has also conducted root cause analysis by considering factors or causes that may give rise to risks, including both internal organizational factors and limitations or uncertainties arising from external factors. In this regard, Risk Owners are assigned to identify and analyze the causes of relevant risk factors in order to determine appropriate and effective risk management approaches.

Following the completion of the root cause analysis, the Risk Management Department, together with the Risk Owners, identified the existing controls, which refer to plans or activities already implemented to help reduce the severity level of each risk cause. The severity level of each individual risk cause was then assessed to determine which risk causes still remained above the organization’s acceptable risk level despite the implementation of existing controls.

For risk causes that continue to exceed the acceptable risk level, additional risk mitigation plans must be developed. These mitigation plans consist of new plans or activities that have not previously been implemented and are intended to serve as supplementary measures to further reduce risk levels. This process is designed to ensure that the overall risk severity, after implementing both existing controls and additional mitigation plans, is reduced to a level acceptable to the organization.

AOT conducts risk analysis and prioritization by considering the likelihood and impact levels of risks through the use of a Risk Profile to assess the severity level of risks. This assessment is based on historical statistical data, operational performance data, as well as trend analysis and future forecasting to ensure that the assessment criteria are appropriate, aligned with the operational context, and reflective of the organization’s actual risk exposure.

In addition, the risk assessment criteria are established in alignment with organizational objectives, laws and regulations, Key Performance Indicators (KPIs), operational performance results, and other critical factors affecting operations, including the organization’s acceptable risk level (Risk Boundary). This ensures that the assessment results can be effectively utilized in preparing appropriate risk management actions or control measures for potential risks and in reducing impacts to an acceptable level.

In assessing risk severity levels, AOT has established three levels of risk assessment to support risk analysis, monitoring, and management in alignment with the organization’s acceptable risk level, as follows:

AOT has established four risk response approaches: (1) Risk Acceptance (Take/Acceptance), (2) Risk Reduction (Treat/Reduction), (3) Risk Transfer (Transfer/Sharing), and (4) Risk Avoidance (Terminate/Avoidance). These approaches serve as guidelines for managing risks appropriately in accordance with the context and severity level of each risk.

In cases where the Residual Risk level exceeds the organization’s acceptable risk level, particularly for risks classified as High (orange) and Very High (red), the Risk Owner is required to consider and select the most appropriate risk response approach by taking into account the cost-effectiveness and efficiency of the measures to be implemented for managing such risks.

The selection of risk response approaches is based on a Cost and Benefit Analysis (CBA), considering at least two alternative options in both monetary and non-monetary terms, in order to support decision-making and identify the most appropriate and cost-effective measures. The organization may choose to apply a single risk response approach or a combination of approaches to effectively reduce the likelihood and/or impact of risks to a level acceptable to the organization.

In addition, AOT requires the preparation of additional risk mitigation plans for cases where further measures beyond existing controls are necessary to reduce risk levels to within the organization’s acceptable range. Such plans must clearly demonstrate that, upon full implementation, they will effectively reduce the likelihood of occurrence and/or mitigate the impacts of the identified risk factors in a concrete and measurable manner, with outcomes that can be clearly monitored and evaluated.

AOT requires the monitoring and reporting of enterprise-level risks as well as risks at the division, department, office, and airport levels on a quarterly basis, or immediately upon the occurrence of any significant event that may materially affect AOT.

To support this process, AOT prepares an annual risk management reporting plan through the operational plan of the Risk Management Division under the Risk Management Department. The plan is communicated to Risk Owners and personnel responsible for risk management, internal control, and business continuity management functions (Risk Agents) during meetings of the AOT Risk Management Working Committee (AOT-RMC).

This reporting framework serves as the timeline and guideline for Risk Owners and Risk Agents to report risk management results to the AOT Risk Management Working Committee (AOT-RMC) and the Risk Management Committee (RMC), respectively.

AOT’s risk management system is aligned with the framework of The Committee of Sponsoring Organizations of the Treadway Commission – Enterprise Risk Management Integrating with Strategy and Performance (COSO-ERM 2017), as well as the Business Continuity Management System (BCMS) framework in accordance with the international standard ISO 22301:2019 – Security and Resilience – Business Continuity Management Systems Requirements.

Risk management processes are integrated into the preparation of AOT’s Enterprise Plan and the management of significant projects to ensure that risks and potential disasters that may affect AOT’s business operations can be managed in a timely and continuous manner. This also supports AOT in achieving its established objectives and targets.

AOT has established BCMS processes and operational procedures that are linked and aligned with the strategies set out in the AOT Enterprise Plan. These processes are developed with reference to the nature of the business, organizational context, vision, strategies, SWOT analysis results, and critical business processes in order to define the scope of the BCMS to comprehensively cover AOT Headquarters and all six AOT airports.

AOT conducts Business Impact Analysis (BIA), risk assessments, prepares Business Continuity Plans (BCP), and carries out annual plan exercises in collaboration with relevant external agencies. In addition, AOT places importance on promoting knowledge, understanding, and awareness of BCMS among executives and employees through regular training programs and communication campaigns. These efforts help reinforce stakeholder confidence that AOT is well prepared to respond to emergency situations and capable of restoring critical services to normal operations in a timely manner.

AOT has continuously improved and enhanced the Business Continuity Management System (BCMS) of AOT Headquarters and all six AOT airports. The organization has successfully undergone recertification audits for BCMS: ISO 22301:2019 conducted by an accredited Certification Body (CB), with the certification valid for a three-year period from fiscal years 2025 to 2028.

This certification provides assurance that AOT Headquarters and all six AOT airports have fully implemented the BCMS in compliance with all requirements specified under ISO 22301:2019.

See More Details

ISO 22301:2019 HQ

ISO 22301:2019 BKK

ISO 22301:2019 DMK

ISO 22301:2019 HKT

ISO 22301:2019 CNX

ISO 22301:2019 HDY

ISO 22301:2019 CEI

AOT Internal Audit

AOT Risk Internal Audit 2025

Operational Practices

In fiscal year 2025, AOT implemented a systematic enterprise risk management process by assessing and prioritizing risks identified by responsible business units in order to establish appropriate risk mitigation and control measures in line with acceptable risk levels.

Examples of significant risk issues and their management approaches are presented in the following table.

Emerging Risks

Emerging risks represent challenges arising from various changes that may pose risks to airport business operations and could significantly impact the airport business and society across different contexts depending on each risk issue. These risks encompass environmental, social, and governance factors, such as climate change, resource scarcity, regulatory changes, and technological disruptions, as well as international conflicts and political polarization.

Managing emerging risks requires proactive strategies to ensure resilience, mitigate potential adverse impacts, and capitalize on opportunities for sustainable growth. Identifying and addressing these risks enables the organization to better align with global sustainability goals and preserve long-term business value.

Risk Culture Promotion

AOT places importance on fostering an organizational environment and culture that supports systematic and continuous risk management in order to embed risk management into operational processes and decision-making at all levels of the organization. The Company adopts the Deloitte Risk Culture Framework as a guiding principle for cultivating risk culture, while also defining appropriate risk-related expected behaviors for the Board of Directors, executives, and employees within each target group. This approach aims to promote behaviors and work practices that align with AOT’s corporate values and operational objectives in an efficient and sustainable manner.

In addition, AOT has implemented activities to promote and strengthen a tangible risk management culture throughout the organization, including:

Strengthen Risk Awareness (Risk Management Education)

AOT has defined desired risk-related behaviors under the “3A” concept to promote organizational values and drive a comprehensive risk management culture across the organization. This initiative aims to ensure that the Board of Directors, executives, and employees at all levels demonstrate work behaviors that align with the organization’s risk management approach. The details are as follows:

Furthermore, AOT has integrated risk considerations into its service development processes and established risk-related performance indicators for relevant departments, which directly influence financial incentives. In fiscal year 2025, AOT also implemented various projects and initiatives to continuously and concretely promote risk awareness, enhance understanding, and encourage risk-conscious behaviors among executives and employees at all levels in accordance with the organization’s expectations. These initiatives were jointly carried out by the Strategy Division and the Human Resources and Administration Division. Key activities included the following:

1) Risk, Internal Control, and Business Continuity Exhibition Project (Risk Day 2025)

Objective: To enhance awareness among targeted AOT executives and employees regarding desired risk management behaviors, internal control, and business continuity management under the “3A” concept. The initiative aims to ensure that all target groups are able to communicate and apply these behaviors within their respective units, ultimately fostering a risk culture aligned with the organization’s Core Values.

2) AOT Core Values Day 2025: Embracing DEI&B Activity Project

Objective: To promote knowledge and understanding of the DEI&B concept in supporting organizational values and culture, as well as to facilitate the exchange of experiences related to AOT’s core values and organizational culture among AOT personnel. The initiative also aims to enhance awareness among executives, employees, and staff regarding the importance of organizational values and culture as a fundamental foundation for operational practices and organizational development in support of achieving AOT’s vision.

3) Dissemination of AOT Risk Management Communication Materials through the AOTStaff Application

Objective: To enable employees at all levels to access accurate, timely, and up-to-date information regarding risk issues, management approaches, and related measures. The initiative also aims to encourage employees to recognize the importance of risk management and continuously apply risk management principles in their daily work practices.

In addition, AOT conducts annual surveys on employees’ levels of awareness and understanding of risk management in order to assess the effectiveness of risk management communication and information dissemination through various channels, both internal and external to the organization. The survey results are also utilized to further develop and improve communication formats and channels, with the aim of continuously enhancing awareness, understanding, and an effective risk management culture throughout the organization.

Risk-Focused Training

AOT organized training programs and activities to enhance participants’ skills and expertise in risk management and compliance with prescribed operational guidelines. These initiatives aimed to prepare all six airports for international standard assessments, while also promoting understanding and raising awareness of risk management among personnel at all organizational levels.