Corporate Governance
The Board of Directors has established the “Good Corporate Governance Policy” and “Code of Business Conduct” in accordance with the Corporate Governance Code (CG Code) for Listed Companies 2017, issued by the Securities and Exchange Commission (SEC), Thailand. These documents serve as guidelines for directors, executives, and employees in conducting business operations.
The Board has also established a policy requiring an annual review of the Good Corporate Governance Policy and related practices to ensure their continued suitability in response to changes in business operations, the business environment, circumstances, and applicable laws.
In addition, the Board has assigned the Corporate Governance, Risk Management, and Sustainability Committee to regularly monitor compliance with the Good Corporate Governance Policy and related practices through standing agenda items. The Company also communicates these principles publicly through the corporate website under the section “Corporate Governance: Corporate Governance Policy.”
Good Corporate Governance Principles 8 Core Practices
- Recognize the roles and responsibilities of the Board as the leader in creating sustainable value for the business.
- Define the Company’s objectives and key goals with a focus on sustainability.
- Strengthen the effectiveness of the Board of Directors.
- Recruit and develop senior executives and manage human resources effectively.
- Promote innovation and responsible business practices.
- Ensure appropriate risk management and internal control systems.
- Maintain financial reliability and transparent disclosure of information.
- Encourage shareholder engagement and effective communication with shareholders.
The Company recognizes that effective risk management is an essential part of good corporate governance and supports the achievement of business objectives. Management and employees are aware of their responsibilities in implementing the risk management process to maintain risks at an acceptable level. The Company’s risk management framework consists of the following five key components:
1) Governance and Organizational Culture
The Board of Directors and the Corporate Governance, Risk Management, and Sustainability Committee are responsible for establishing risk management policies and plans in accordance with relevant standards. These efforts aim to control and reduce the impact of risks effectively while supporting transparent and sustainable business operations.
2) Strategy and Objectives
The Corporate Governance, Risk Management, and Sustainability Committee analyzes the business environment, establishes risk management approaches, and assesses significant risks affecting the Company’s operations. These approaches are submitted to the Board of Directors for approval before implementation.
3) Performance Objectives
The Corporate Governance, Risk Management, and Sustainability Committee monitors and reviews overall risk factors and material risk levels affecting business operations and reports the findings to the Board of Directors.
4) Review and Improvement
The Corporate Governance, Risk Management, and Sustainability Committee regularly reviews and updates risk management policies and measures on an annual basis to ensure continued effectiveness.
5) Information, Communication, and Reporting
The Corporate Governance, Risk Management, and Sustainability Committee oversees risk management activities on an ongoing basis and discloses performance results through the Company’s Annual Report.
The Company emphasizes enterprise-wide risk management and conducts comprehensive analysis and evaluation of information to identify and monitor significant risks. These risks are categorized into two main groups:
1. Business Risk
The Company recognizes both external and internal risk factors that may affect operating performance and competitiveness. Risk management practices are systematically implemented to respond to changes and support sustainable growth.
2. ESG Risk (Environmental, Social, and Governance)
The Company recognizes risks related to environmental, social, and governance factors, including resource and energy consumption, waste and packaging management, stakeholder expectations, and compliance with applicable laws and standards. These factors may impact stakeholder confidence and business continuity. Therefore, the Company places importance on systematic ESG risk management to support long-term sustainable growth.
The Board of Directors places importance on internal control systems covering operations, finance, and governance. Clear approval authorities and segregation of duties have been established, and the Internal Audit Department has been assigned to independently review operations and provide recommendations to improve effectiveness and ensure compliance with applicable laws and regulations.
The Board requires the Internal Audit Department to report audit results directly to the Audit Committee. The Audit Committee is responsible for reviewing the adequacy and effectiveness of internal control systems, evaluating risk mitigation measures, and paying close attention to early warning signs and significant irregularities.
The Company’s Internal Control System
- Internal Control Environment
- Risk Assessment
- Operational Control Activities
- Information and Communication Systems
- Monitoring Activities
The Board of Directors has established a policy requiring directors and executives to comply with anti-corruption laws and has developed an Anti-Corruption Policy, which is communicated to executives, employees at all levels, and external parties. Key practices include
1) Establishing a Written Anti-Corruption Policy
The Board of Directors has established a written Anti-Corruption Policy, which all directors, executives, and employees are required to follow. The Company also supports activities that promote awareness and encourage compliance with relevant laws, regulations, and internal policies.
2) Public Disclosure and Communication
The Company publicly communicates its Anti-Corruption Policy and provides channels for whistleblowing and complaints as follows
- Complaint Channels
By Mail (please mark as confidential)
Company Secretary Office
Sun Vending Technology Public Company Limited
34 Krungthep Kreetha Road, Huamark, Bang Kapi, Bangkok 10240, Thailand - By E-mail
Company Secretary Office : com.sec@sunvending.co.th
Chairman of the Audit Committee : Suvit.t@sunvending.co.th - Company Website
3) Business Ethics Guidelines
The Company’s Code of Business Conduct includes the following requirements:
- Directors, executives, and employees must not request, accept, or receive any property or other benefits for themselves or others that may influence or appear to influence the improper performance of duties or cause unfair disadvantage to the Company.
- Directors, executives, and employees must not offer or provide any property or other benefits to external parties to induce them to act or refrain from acting unlawfully or improperly in relation to their duties.
The Company works with suppliers under the principles of good governance, transparency, fairness, and accountability throughout the supply chain process — from product selection to distribution and service delivery across operational areas.
The Company manages its supply chain efficiently to strengthen business continuity, reduce risks, and create sustainable value.
In addition, the Company continuously conducts supplier assessments to verify operational capability and compliance with environmental, social, and governance (ESG) requirements. These assessments aim to encourage suppliers to operate responsibly and align with the Company’s Code of Business Conduct, as well as applicable regulations, laws, and international standards.
Key assessment areas include
- Fair labor practices
- Occupational health and safety
- Environmental management
- Good corporate governance
In 2025, suppliers achieved an overall “Very Good” sustainability assessment rating. The Company uses assessment results to continuously monitor and develop supplier capabilities, with the goal of creating a more transparent, ethical, and sustainable supply chain that supports long-term growth together.
The Information Technology Security Policy has been established in alignment with the Company’s objectives and business strategies. The policy provides a governance framework and clear guidelines for managing information security across Sun Vending Technology Public Company Limited (SVT) to ensure consistent implementation and compliance with applicable laws, policies, and regulations.
The policy consists of four key areas as follows
1. Organizational Controls
- Policy and Governance Structure: The Company establishes clear information security policies and reviews and updates them annually in accordance with applicable laws. Roles, responsibilities, and requirements are also defined for employees regarding the use of portable computing devices and remote working practices.
- Asset Management: Information assets are assigned to responsible owners, information is classified according to confidentiality levels, and data storage media are managed appropriately.
- Access Control: Access and editing rights are assigned to prevent unauthorized access to systems, applications, and information.
2. People Controls
- Employee Responsibilities: Security responsibilities are communicated to employees and external personnel throughout the employment lifecycle, including before employment, during employment, and upon termination.
- Disciplinary Measures: Clear disciplinary actions are established for violations of information security rules and regulations.
3. Physical Controls
- Protection of Facilities and Equipment: The Company implements physical security measures to prevent unauthorized access to areas where information technology equipment is installed in order to reduce risks of damage, interference, or theft of Company assets.
4. Technological Controls
- Data and System Protection: Cryptography is applied to maintain confidentiality and prevent data leakage. The Company also implements data backup processes and protection against malware and other malicious software.
- Vulnerability Assessment: Vulnerability Assessment (VA Scan) and Penetration Testing (Pentest) are conducted regularly to reduce cybersecurity risks.
- Communication and Third-Party Service Providers: Network security and information exchange are managed carefully, while external service providers and suppliers are required to comply with security requirements and agreements.
- Incident Response and Business Continuity: The Company has established response plans for security incidents to minimize service disruption and ensure continued availability of systems and equipment.
- Legal and Regulatory Compliance: Information security practices are regularly reviewed to ensure compliance with legal, regulatory, and contractual requirements.
- Reduce customer complaints and increase customer satisfaction with products and services by 20% by 2027.
- Expand and increase access channels for products and services.
- Improve complaint management processes to enhance service quality and customer experience.
The Company places importance on customer relationship management and customer responsibility by conducting business with transparency and delivering quality products and services through modern technology and recognized standards that meet customer expectations.
The Company continuously listens to customer opinions and feedback to improve and develop its operations while ensuring customer data protection and strict compliance with applicable laws and regulations. These efforts aim to build trust, customer satisfaction, and long-term relationships.
To support customer engagement, the Company provides channels for receiving complaints and suggestions directly through its vending machines. Customers can scan the QR Code to add LINE Official Account: @sunvending or contact the Call Center using the information displayed on the vending machine.
The Company has established tax transparency practices to build long-term trust with stakeholders. Key principles include:
- Compliance with Tax Laws and Regulations: Strictly comply with all applicable tax laws, regulations, and related requirements in a complete, accurate, and timely manner.
- Tax Governance and Control System: Maintain clear and effective tax management and review processes to ensure accuracy and transparency in tax operations.
- Tax Disclosure and Reporting: Provide sufficient, accurate, and complete tax-related information to relevant authorities in accordance with legal requirements.