Risk Management

Global healthcare systems are facing increasing challenges driven by global interconnectedness, economic volatility, rapid technological advancement and environmental change. In a fast-evolving global landscape, medical and public health organizations must navigate highly complex and uncertain risks, including geopolitical instability, supply chain disruptions, the accelerated adoption of artificial intelligence, the energy transition, labor mobility and continuously evolving societal expectations.
In response to these dynamics, BDMS has adopted an Enterprise Risk Management (ERM) framework as a core mechanism to strengthen the resilience of its healthcare service system and to support the effective execution of its strategy and long-term sustainability across all ESG dimensions—environmental, social, and governance. This framework enables the organization to proactively identify and anticipate risks, mitigate potential impacts, ensure service continuity and reinforce confidence among investors and all stakeholder groups.
Enterprise Risk Management (ERM)
BDMS has adopted the principles of risk management in accordance with the internationally recognized COSO Enterprise Risk Management (COSO ERM) framework and strengthened their application to align with the nature of its business. This approach is designed to address the impacts of global megatrends and the evolving healthcare risk landscape, which affect operations, patient services, supply chains, technology, data governance and emergency preparedness across all dimensions. The overarching objective is to ensure patient safety while integrating considerations of environmental, social and governance (ESG) sustainability. In this regard, BDMS places emphasis on four key priorities.

Risk Governance

The Company acknowledges the significance of risk management as an essential element of good corporate governance. Accordingly, the Company has defined clear roles and responsibilities for Enterprise Risk Management at both board oversight and operational levels. The Board of Directors has appointed the Risk Management Committee to scrutinize the Company’s risk management policy and directions, as well as to monitor and follow up the compliance of risk management policy and procedures. At the operational level, the Company follows the 'Three Lines of Defense' principle for risk management roles and responsibilities, as follows
| Risk Governance Framework | Dedicated committee and roles | Roles and responsibilities |
|---|---|---|
|
Board Oversight |
Board of Director |
|
|
Risk Management Committee |
|
|
|
1st Line of Defense |
Front-line employees as risk owners such as Risk Manager, Patient Safety Coordinator |
|
|
2nd Line of Defense |
Chief Administrative Officer and Enterprise Risk Management Steering Committee |
|
|
3rd Line of Defense |
Internal Audit Director and Internal Audit Unit |
|
BDMS Risk Management Strategy
BDMS integrates key information and essential aspects of corporate risk management to identify critical business risks while assessing their short, medium, and long-term impact.

BDMS Categorization of 9 Major Corporate Risks
Emerging Risks

In addition to the nine core risk categories identified above, BDMS also monitors and assesses Emerging Risks arising from rapidly evolving external conditions — including technological, regulatory, and geopolitical developments — that may have a material impact on the business over the next three to five years. In 2025, BDMS identified two key emerging risks as follows
1. Accelerating Clinical-AI adoption and evolving AI regulation may create patient-safety and data-integrity risks
Artificial Intelligence (AI) is transitioning from traditional predictive analytics toward systems that support more complex workflows, including Generative AI and Agentic AI, one of the key factors shaping the future direction of healthcare services. However, accelerating Clinical-AI adoption worldwide, together with evolving AI regulation and regulatory expectations, is an external driver that may affect patient safety and data integrity. AI governance trends are moving toward risk-based frameworks, as reflected in the EU AI Act, Thailand’s AI Governance Guideline, and the ASEAN Guide on AI Governance and Ethics. In the hospital business context, AI is not merely a technology tool. It can advance healthcare from Digital Healthcare toward Intelligent Healthcare Systems by integrating data, workflows, and clinical decision-making across the Patient Journey. As AI becomes embedded in patient care, emerging risks extend beyond technology and cybersecurity to include clinical quality, output reliability, health-data integrity, model bias, and human accountability. Over the next three to five years, deeper AI integration into patient care and medical resource management may affect treatment quality, service continuity, the confidence of patients, regulators, and other stakeholders, and business effectiveness.
BDMS recognizes both the opportunities and risks associated with AI and is committed to using technology responsibly to support medical excellence. The Company has begun integrating AI to support clinical operations and healthcare management, including AI-assisted radiology for pulmonary disease screening alongside physician judgment; Automated Speech Recognition (ASR) for medical record documentation; Pharmacogenomics (PGx for All) for personalized medication therapy through genetic-data analysis; and BDMS Utilization Review Technology (BURT) to support appropriate medical resource utilization aligned with patients’ benefit entitlements. In 2025, BDMS manages AI- and digital technology-related risks through existing governance frameworks covering IT governance, information security management, personal data protection, cybersecurity, and business continuity. The Company upholds the principle that AI and digital systems support, but do not replace, physicians and clinical personnel. For data and information security, BDMS applies Confidentiality, Integrity, and Availability, covering access controls, data encryption, audit logging, security testing, incident management, and third-party vendor risk management. The Company also applies recognized standards and frameworks, including ISO/IEC 27001, ISO/IEC 27799, the NIST Cybersecurity Framework, and COBIT.
Going forward, BDMS plans to strengthen its risk governance framework for AI systems, making it clearer and more systematic, by linking it to Enterprise Risk Management, IT Governance, Information Security, Personal Data Protection, Cybersecurity, and Business Continuity Management. Metrics and monitoring mechanisms will be assigned to the units that deploy and oversee AI systems, covering AI system performance, data accuracy, information security, patient safety, stakeholder impact, and business effectiveness. This will support structured oversight, monitoring, and auditing of AI systems in routine clinical operations. In parallel, BDMS will continue to build AI literacy and role-based skills so AI systems are used in line with governance principles, standards, and professional ethics. BDMS has established an AI Governance Working Team, which meets monthly to oversee responsible AI deployment and reports to the BDMS Policy and Strategy Planning Working Team, comprising senior executives of all business groups. This enables senior-management consideration and operational cascading of AI governance matters.

2.Geopolitical uncertainty and cross-border disruptions affecting international-patient demand and revenue resilience
Global and regional geopolitical uncertainty, including border conflicts, international tensions, and cross-border travel restrictions is an external factor that may affect the continuity of healthcare demand from international patients and their ability to access healthcare in Thailand. For a healthcare business serving patients from multiple countries, this risk may affect demand continuity from source markets, patients' ability to access care in Thailand, international referral networks, confidence among patients and business partners, and volatility in international-patient revenue. BDMS classifies this issue as an Emerging Risk because observed impacts in selected markets demonstrate the exposure of the international-patient business to external geopolitical factors, while the broader impact remains highly uncertain over the next three to five years. If international healthcare demand is concentrated in selected countries or regions, a geopolitical event in one source market may affect international-patient revenue growth, hospital capacity planning, marketing plans, international referral channels, and stakeholder confidence.
In 2025, the hospital business revenue mix between Thai and international patients was 72:28, and international-patient revenue continued to grow. However, the Thailand – Cambodia border conflict , which began in mid-2025, made it more difficult for Cambodian patients to travel to Thailand for treatment, resulting in a decline in Cambodia patient revenue from approximately 3% of hospital revenue in 2024 to approximately 2% in 2025. This observed selected-market impact serves as an empirical proof point demonstrating the structural vulnerability of the international-patient business to external geopolitical factors, and does not represent full materialization of the broader risk. The first quarter of 2026 operating results continued to indicate revenue pressure in selected markets and therefore require close and ongoing monitoring. BDMS responded in 2025 by adjusting domestic and international marketing strategies, monitoring international-patient revenue by nationality and region, and using these insights to support business-plan adjustments. The Company also manages this risk through the following measures:
- Market Diversification - Diversifying patient source markets, payer groups, and referral channels.
- Service & Digital Innovation - Expanding wellness and preventive medicine, developing seamless Digital Patient Journeys (pre- and post-travel), and strengthening Centers of Excellence (CoEs) for complex care.
- International Partnerships - Establishing local follow-up networks and clinical alliances in source countries, such as BDMS Wellness Clinic’s partnership with Neem Hospital & Modawi Platform in Oman, which supports patient referrals and medical knowledge exchanges.
Overall, these three measures support continuity of care for international patients and enhance business resilience against external geopolitical factors. From 2026, the ERM Committee has formally incorporated the geopolitical risk dimension related to international-patient demand into its monitoring process. The committee meets every two months and reviews relevant financial and operational indicators, including revenue, growth and market distribution of international-patient business. This matter is also reported through the Company's governance mechanisms as part of the enterprise risk management process. Going forward, BDMS will continue to monitor international-patient revenue growth, the Thai-to-international patient revenue mix, revenue distribution by nationality and region, and the impact of geopolitical events or travel restrictions. These activities support business planning, marketing strategy adjustment, international partnership development and ongoing management of international-patient risks.
Risk Management Processes

BDMS established Core System Risk Assessment and Hazard Vulnerability Analysis as guideline for risk management on clinical risks and risks related to core systems in hospitals. Risk management procedures are briefly described as follows
- Risk Identification
The department head and the committee responsible for critical systems are responsible for reviewing the working process, risks and factors from the occurrence or incidence report in the passing years, statistical indicators and experience from the external parties to determine potential impacts.
Risk factors are identified based on internal and external past events occurred. The data sources are obtained from updated in law and regulations, Occurrence report and Peer review.
- Risk Assessment are considered covering 2 factors
- Likelihood assessment: assess potential and frequency of impact occurrence
- Impact assessment: assess on quantity impact and quality impact in various aspects such as compliance to laws and regulations, safety, financial, strategic and operational and reputation
- Risk Scoring and Risk Prioritization
Risk Scoring or Risk Prioritization are considered based on levels of likelihood and levels of impacts. Risk Scoring can be illustrated as 5 of risk levels with definitions with the maximum score at 25 points.
BDMS Occurrence Reporting
BDMS sets forth the occurrence reporting system for employees and related internal and external personnel in case of any risks or incidents in the business operations. All personnel have the responsibility to manage such incident in a timely manner and must report the incident through the specified channels, both online and regular, within 8 hours after such incident takes place, with the aim of investigation and data analysis on the impact level. The impacts can be categorized in clinical aspects, including other aspects as follows
| Level | Clinical Impact |
|---|---|
|
0 |
Near Miss |
|
1 |
No Harm |
|
2 |
Mild Adverse Event |
|
3 |
Moderate Adverse Event |
|
4 |
Serious Adverse Event |
|
5 |
Adverse Event and Reputation Harm |
|
SE |
Sentinel Event |
Each impact level results in different internal investigation methods. The occurrence will be reported to the executives on a monthly and quarterly basis.
The risk appetite is at level Low to Medium only (Risk score below and equal to 0 is acceptable and depends on hospitals aspects).



Audit of the Risk Management Process

Internal Audit
The Audit Committee has roles and responsibilities, including ensuring that the Company has established suitable risk management and control systems that encompass the entire organization and suggesting appropriate and efficient management of risks associated with the Company’s business operations. Audit Committee has assigned the internal auditor team to set plan for the Company's annual audit. BDMS’s internal audit process is in accordance with International Professional Practices Framework (IPPF) by Institute of Internal Auditors. The internal audit plan covers reviewing the effectiveness of control, including IT reliance processes and non-IT reliance processes of hospital in BDMS groups and its subsidiaries. The project-based internal audit includes reviewing the effectiveness of the risk management process to assess control effectiveness and mitigation measures. The internal audit is conducted to check alignment of regulatory compliance and external relevant standards, such as regulatory requirements and international standards, such as IT Risk Management under ISO 27001, and requirements based on the Personal Data Protection Act 2012.
In 2025, BDMS’s Internal Audit function, as part of the third line of defense, provided independent and objective assurance, insights, and advisory perspectives on the adequacy and effectiveness of the organization’s governance, risk management, and internal control processes. The 2025 Internal Audit Plan was developed using a risk-based approach, aligned with BDMS’s business objectives, regulatory requirements, and the evolving risk environment.
The audit scope encompassed significant operational and information technology-related processes. Operational reviews focused on doctor compensation, procurement-to-payment, human resource management, and product development. In the IT domain, the audit focused on two key areas: data privacy practices in compliance with the Personal Data Protection Act (PDPA), and identity and access management (IAM).
These engagements were designed to evaluate whether controls over key operational and technology-related risk areas were adequately designed, implemented, and operating effectively. Furthermore, Internal Audit performed follow-up activities on agreed management action plans to assess whether corrective actions were implemented in a timely manner, thereby supporting the enhancement of governance, risk management, and control processes.
The internal audit process which covers risk management process are demonstrated below
