Mitr Phol Group Sustainability

Edit Template
Key Stakeholders: Shareholders, Farmers, Employees, Suppliers, Customers and Consumers, Communities,
Government and Civil Society Sectors
Technology and Artificial Intelligence (AI) have been adopted to support business operations, improve data management, enhance organizational capabilities, and strengthen long-term competitiveness. Mitr Phol Group therefore places significant importance on data security and the responsible use of AI. Mitr Phol Group is committed to managing data prudently and securely, in compliance with applicable laws, while ensuring the transparent and accountable use of AI. These efforts aim to build stakeholder confidence and create long-term value for the organization.

Responsible Data Management

Mitr Phol recognizes the importance of the responsible and diligent use of data and technology. The Company has established clear data management processes and maintains readiness to respond to potential incidents. Through these practices, the Company is able to leverage data and technology effectively to enhance its competitive advantage while strengthening the trust and confidence of customers and stakeholders. 

2025 Target and Performance

Target
Performance
Cybersecurity Incident Response Time
Within 4 hours
No Cybersecurity Incident
Conduct a simulated cybersecurity incident response drill
in collaboration with the operations team.
1 time per year
1 time
Conduct cybersecurity incident response drills through tabletop exercises in collaboration with relevant business units.
1 time per year
1 time

Management Approach

Cybersecurity Management Structure

Recognizing that cybersecurity and data security are critical to business operations, the Board of Directors has assigned the Digital Transformation and Cybersecurity Committee to collaborate with the Risk Management Committee and the Audit Committee. The Company has also appointed a Data Protection Officer (DPO) and a Chief Information Security Officer (CISO). The Executive Committee is responsible for implementing the relevant policies into practice, while the Digital and Technology Transformation Group is directly responsible for overseeing cybersecurity and data security management. The roles and responsibilities of each relevant governance body and function are outlined below.

The Digital Transformation and Cybersecurity Committee

Responsible for establishing policies and management guidelines relating to information technology, cybersecurity, and data protection, as well as supporting their implementation across all business units.
Also oversees and drives the Company's digital transformation across the organization.

The Risk Management Committee

Responsible for establishing the Company's risk management policies, objectives, and guidelines, including those related to information technology, cybersecurity, and data security. Supports the implementation of risk management activities, monitors and evaluates performance, and provides recommendations to ensure effective risk management practices. These efforts aim to help Mitr Phol achieve its business objectives while maximizing value for stakeholders.

The Audit Committee

Responsible for independently monitoring and reviewing the Company's operations to ensure the effectiveness of risk management and internal control systems relating to information technology, cybersecurity, and data security, as well as compliance with applicable laws, rules, and regulations.
The Audit Office serves as the internal audit function, responsible for monitoring and auditing units
involved in cybersecurity and personal data protection. The Audit Office reports directly to the Audit Committee to ensure that operations are properly and comprehensively conducted in accordance with established policies.

The Chief Information Security Officer (CISO)

Responsible for defining information technology strategies in accordance with the policies established by the Digital Transformation and Cybersecurity Committee and for regularly reporting performance outcomes to the Committee. The role is held by the Executive Vice President of Digital and Technology Transformation. The CISO operates under the Digital and Technology Transformation Group, which is responsible for digital transformation, business systems development, IT infrastructure, IT security, cybersecurity, and data security to support business requirements and achieve organizational objectives.

The Data Protection Officer (DPO)

Responsible for providing advice, reviewing operations, and supporting business units to ensure compliance with personal data protection laws. This includes establishing security measures to safeguard personal data in accordance with legal requirements and elevating personal data protection practices to internationally recognized standards.

The Enterprise Security Management Unit and the Enterprise Infrastructure Solutions Unit, under the Digital and Technology Transformation Group

Responsible for planning, developing, and managing technology systems, information systems, and personal data securely, with due regard for confidentiality, integrity, and availability. Also responsible for assessing and controlling risks related to information technology, cybersecurity, and data security to ensure that risk levels remain within the Company's acceptable risk appetite. In addition, responsible for monitoring, responding to, and mitigating cybersecurity and data security incidents in a timely manner to minimize potential damage, as well as promoting cybersecurity and data protection awareness among employees and relevant stakeholders.

Risk Management Framework for Cyber Threats
and Information Security

Mitr Phol has established the Cybersecurity Policy, Personal Data Protection Policy, Data Governance Policy, and AI Governance Policy, which are applied across the Mitr Phol Group and reviewed annually to ensure their continued relevance and effectiveness. In addition, the Company has implemented a risk management framework for Digital Technology and Data Security Risk Management Framework to achieve the following key objectives:

Strengthening Cybersecurity Prevention Measures and Culture

The Company adopts a comprehensive cybersecurity measure focused on three domains: People, Process, and Technology to mitigate risks related to cybersecurity and personal data protection and to effectively respond to cyber threats. Key initiatives under each domain are outlined below:

People Domain

The Company enhances the capabilities of employees at all levels and raises cybersecurity awareness through learning programs delivered through multiple channels, ensuring comprehensive and accessible learning for all employee groups. These efforts prepare employees to respond to rapidly evolving cyber threats. The following activities were implemented:

Enhancing Knowledge and Skills and Fostering a Cybersecurity Culture

  • Conducted cybersecurity and Personal Data Protection Act (PDPA) training, covering phishing email detection, secure password practices, data subject rights, and the responsible use of data. More than 700 employees participated in 2025.
  • Communicated information on cybersecurity threats and response measures through Cyber News email communications to enhance employee awareness.
  • Provided dedicated channels through which employees can make inquiries and seek advice.

Preparation for Cyber Threats

  • Conducted simulated cybersecurity incident response drills involving various cyber threat scenarios.
  • Evaluated the drill results and used the findings to improve incident response procedures.

Process Domain

The Company develops standardized and effective processes to systematically manage cybersecurity
risks and respond to cybersecurity incidents through the following activities.

Policy Development and Review

  • Develops and reviews relevant policies and guidelines and communicates them to relevant parties.

Risk Oversight and Assessment

  • Conducted security assessments of IT infrastructure and information security management systems in alignment with the standards of the National Institute of Standards and Technology (NIST) through both internal and independent external audits.
  • Conducts PDPA compliance audits and provides recommendations on appropriate compliance practices.
  • Monitors regulatory developments and reviews litigation cases and data breach incidents in Thailand and other countries.

Incident Management

  • Maintains the Cyber Hotline incident-reporting channel, the Cyber Alert! notification system, and the Cyber Incident Response (Cyber IR) Procedure.
  • Conducts cybersecurity incident response drills regularly and records incident data through the Ticket Management System for incident analysis and continual improvement.

Technology Domain

The Company deploys advanced and effective technologies to strengthen cybersecurity and protect against cyber threats through the following measures:

  • Implemented access controls for critical systems and related devices.
  • Ensured secure data management
  • Enhanced threat detection and response capabilities through anomaly analysis, regular vulnerability assessments and penetration testing, and the deployment of tools that enable faster and more accurate responses to cyber threats.

Through the continuous enhancement of cybersecurity practices and the promotion of a strong cybersecurity and data security culture, the Company recorded no data security breaches or incidents that adversely affected business operations or stakeholders in 2025. The Company has also established channels for reporting cybersecurity and data security concerns. All reported cases are recorded in the Incident Management System and managed in accordance with the Cybersecurity and Privacy Incident Response Procedure. Incident reports and lessons learned are documented and reviewed to continuously strengthen preventive measures and enhance the Company's ability to respond to cybersecurity and data-related threats in a timely and effective manner. Employees and external parties can report incidents, vulnerabilities, or suspicious activities related to cybersecurity and data security through the following channels.

Cyber Hot Line - Cybersecurity Incident Reporting Channels

Cyber Drill Simulation

In 2025, Mitr Phol conducted an annual Cyber Drill Simulation to assess the readiness of relevant functions in responding to cybersecurity threats. The exercise involved realistic cyber incident scenarios, with participating units following the Cybersecurity and Privacy Incident Response Procedure follow, the Company's Cybersecurity and Privacy Incident Response Procedure and Business Continuity Plan (BCP). This exercise represented an important step in strengthening organizational confidence and professional response capabilities, while fostering a strong cybersecurity culture across the organization.

Responsible Artificial Intelligence

Mitr Phol recognizes the potential of Artificial Intelligence (AI) to enhance operational efficiency, support innovation, and strengthen business adaptability. At the same time, the Company acknowledges that the use of AI technologies carries important responsibilities. The performance, accuracy, and reliability of AI systems may vary depending on their intended applications and data environments, while inappropriate use of AI may result in unintended impacts on stakeholders. Accordingly, Mitr Phol places strong emphasis on responsible AI governance to ensure that AI is developed, deployed, and used in a safe, transparent, accountable, and ethical manner, creating value while safeguarding the interests of all stakeholder groups.

2025 Target and Performance

Target
Performance
Percentage of employees from operational staff to
executive management completing Responsible AI training
100%
88.31%

Management Approach

Responsible AI Governance and Management Measures

To ensure that the governance, strategic direction, and implementation of Data and AI initiatives across Mitr Phol Group are aligned with good corporate governance principles, corporate strategy, applicable laws, and relevant standards, the Company has appointed the Data and AI Steering Committee. The Committee is responsible for overseeing and determining strategic directions for the appropriate adoption of AI technologies. Furthermore, The Company has also established the AI Governance Policy for employees and executives to adhere to it. In addition, the Company is studying the adoption of ISO/IEC 42001:2023 Artificial Intelligence Management System standards (ISO/IEC 42001:2023) as a framework for developing its AI management system. This initiative aims to build trust, mitigate ethical risks, and enhance AI governance in line with international practices. The Company plans to pursue external certification in the future through the responsible functions.
In addition, the Company has established governance measures to strengthen trust and protect privacy through the implementation of Role-Based Access Control (RBAC), which limits access to sensitive information based on authorized roles and responsibilities. AI systems are not granted access to any sensitive data. Employees are assigned access rights according to their job responsibilities and defined scopes of authority, subject to approval by data owners and relevant functions, with ongoing monitoring and review in place. The Company also monitors and evaluates AI model performance to detect potential model drift or degradation over time. Monitoring frequency is determined based on the level of risk associated with each use case under a risk-based approach. Performance monitoring is conducted continuously throughout the model lifecycle until the model is decommissioned.
Bias testing in AI is conducted as part of the model validation process during model selection and development prior to deployment. This process includes reviewing training data, assessing the fairness of model outputs, and evaluating the established fairness criteria. These measures help identify and mitigate the risk of bias embedded in AI models, which could otherwise result in discriminatory outcomes or unfair treatment of certain groups of individuals.

Leveraging Cloud Services to Enhance Efficiency and
Reduce Energy Consumption

As data volumes continue to grow and AI applications require increasing computing capacity, the demand for data storage and processing resources has risen significantly. To address this, the Company has adopted cloud services provided by vendors selected based on cost-effectiveness, service reliability, and environmental considerations. This approach helps reduce reliance on internal infrastructure, lower energy consumption associated with AI computing and internal infrastructure as well as improve the stability and efficiency of data center operations, enabling continuous service availability.

AI-Related Complaint Channels

The Company recognizes the risks associated with the use of AI, particularly where adequate governance and human oversight may be lacking. To address these risks, the Company has established a Ticket System where employees or users can report concerns related to AI applications. Users may submit complaints, challenge AI-driven decisions or outcomes, and provide feedback regarding the use of AI systems. Dedicated responsible functions have been assigned to review and manage such cases. If a complaint is determined to have a significant impact, the responsible function will escalate the matter to the Data and AI Steering Committee for further consideration and appropriate corrective action. This mechanism helps ensure that all complaints and concerns are reviewed in a transparent and fair manner.

Building Employee Awareness and Capability
for Responsible AI Adoption

To enable employees to fully realize the benefits of AI while minimizing the risks of bias, privacy violations, and other unintended consequences, the Company provides AI training covering the ethical and secure use of AI technologies. In 2025, a total of 4,579 employees participated in AI-related training programs. In addition, the Company educates employees on the safe use of public AI websites through various internal communication channels. Warning messages are also displayed when employees access public AI websites to control employees using AI technologies appropriately. Furthermore, AI systems developed and deployed within the Company are configured to remind users that output generated by AI algorithms should be carefully reviewed and assessed. This is to ensure that AI-generated information remains subject to human review, oversight, and final decision-making. The Company also encourages employees to apply AI technologies to enhance business operations through the annual Mitr Beyond Innovation Awards. In 2025, the Digitech Champion – AI The Next Generation category was introduced to promote creative AI development and adoption across the organization.

Mitr Genie – the Company's internally developed AI platform, notifies users when content is generated by artificial intelligence and requires users to review and
verify the accuracy and appropriateness of the content before use.

Related Policy and Statements

Cybersecurity Policy

Personal Data Protection Policy

Data Governance Policy

AI Governance Policy