Enterprise Risk Management (ERM)
Framework and Oversight
In 2025, Monde Nissin began reviewing and refining its Enterprise Risk Management documentation and reporting processes.
The initiative, led by the Risk Management Department, aims to standardize risk recording and enhance internal reporting and information sharing.
Our ERM Approach
Identify Risks
Assess & Prioritize
Manage & Mitigate
Monitor & Report
Strengthening our risk culture to support informed decision-making and long-term value creation.
Digital Innovation and Transformation
Digital systems support operational efficiency, transparency and decision-making across the Company. In 2025, digital tools were used for sustainability monitoring, quality and safety systems, learning platforms, and operational reporting—reducing manual processes and improving data accessibility.
Key Digital Enablers in 2025
Sustainability Monitoring
Quality and Safety Systems
Learning Platforms
Operational Reporting
Building on earlier digital initiatives, traceability and workflow platforms enhanced accumeroduct development, procurement, and supply chain processes.
New systems for product development and procurement are now used more broadly to support structured data sharing and supply chain coordination.
Digital Innovation and Transformation
Strong Privacy Foundation
Since 2021, the Company has maintained a General Data Privacy Policy supported by privacy notices, consent forms, and contractual data privacy clauses. Where applicable, data sharing agreements are executed with counterparties.
Strengthened Controls in 2025
Cybersecurity and data privacy controls were further strengthened through:
- Security performance monitoring
- Regular vulnerability assessments and penetration testing
- Enhancements to network segmentation and perimeter controls
Compliance and Registration
In compliance with NPC Circular No. 2022-04, Monde Nissin:
- Renewed the registration of our critical data processing systems
- Registered new personal data processing systems launched during the year
The NPC issued a certificate of renewal confirming the Company's continued registration.
Incident Preparedness and Assessments
The Data Breach Response Team remained operational, and privacy impact assessments were conducted for identified systems.
Capability Building
Capability-building continued through targeted data privacy sessions, onboarding orientations, and external training and certification for designated personnel.
These measures support the confidentiality, integrity, and availability of information assets and the trust of our stakeholders.
Artificial Intelligence (AI) Governance
Responsible AI Use
In 2025, Monde Nissin issued an updated AI Governance and Acceptable Use Policy outlining principles and operational controls for responsible AI use.
Training and Awareness
AI governance and acceptable use training was deployed to employees within designated roles via the Company's learning platform.
Approved AI tools are provided through official IT channels, with restrictions on the upload of confidential or personal data and requirements for human review prior to business use.
The Company continues to enhance awareness and refine controls as AI adoption evolves.
For more information on policies and governance disclosures, please refer to the Annex


