Risk management is a systematic process for identifying, analyzing, implementing, and controlling risks that could impact the achievement of an organization's objectives. Its primary objective is to minimize the negative impact of these risks and maximize the opportunities that can be exploited.
(Reference: ISO 31000:2018)
Risk Management Architecture
ISO 31000:2018 provides a structured and universal framework for managing risk in any organization. The standard outlines the principles, framework, and processes for effective risk management.


PT. Gapura Angkasa integrates risk management into its business strategy to ensure the achievement of performance targets and maximize value for shareholders and stakeholders. This includes the effective identification, evaluation, and management of internal and external uncertainties that may impact the company's objectives.
The Company's risk management practices are guided by internal guidelines, which align with key regulatory and international standards, particularly Regulation of the Minister of State-Owned Enterprises No. PER-2/MBU/03/2023.
In its commitment to implementing Good Corporate Governance (GCG) practices, PT Gapura Angkasa adheres to Regulation of the Minister of State-Owned Enterprises Number PER-2/MBU/03/2023 concerning Guidelines for Governance and Significant Corporate Activities of State-Owned Enterprises. As a subsidiary of PT Integrasi Aviasi Solusi and PT Garuda Indonesia, the Company consistently prioritizes the principle of prudence in implementing corporate risk management and managing all types of risks.
The ultimate responsibility for the implementation of the Company's risk management rests with the Board of Commissioners, which serves as the supervisory body, and the Board of Directors, which holds operational responsibility. This responsibility is then cascaded down to all levels of the organization; all levels of management and employees at both the Head Office and Branch Offices act as risk owners for their respective units. They are required to regularly report and monitor their unit's Risk Profile to the Board of Directors.
As a manifestation of its commitment to GCG through a structured risk management framework and governance, PT Gapura Angkasa has adopted the Three Lines Model. This is also reflected in the Risk Management Charter.
The Three Lines of Defense (3LoD) principle is a framework applied to risk management and organizational relationships, which divides responsibilities into three distinct “lines of defense” within an organization.



Risk Taxonomy
PT Gapura Angkasa has 20 risk taxonomies or risk classifications sourced from the INJ Group and Ministerial Regulation 02/2023 and its derivatives concerning the classification of state-owned enterprises in general industry.
Risk Appetite Statement
The Risk Appetite Statement is determined in accordance with that applicable at PT Gapura Angkasa, as follows:
Determining Capacity, Appetite, Tolerance, and Risk Limits for 2025
Referring to PT Gapura Angkasa's 2025 Risk Strategy which was established on February 17, 2025, Risk Strategy (including risk capacity, risk appetite, risk tolerance, and risk limits).
Guidelines – Enterprise Risk Management (ERM)
PT Gapura Angkasa is a subsidiary of PT Integrasi Aviasi Solusi (IAS) and PT Garuda Indonesia which is engaged in the most comprehensive services in the aviation sector which includes Ground Handling, Cargo & Logistics, and Hospitality services, which was inaugurated on January 26, 1998. In carrying out these business activities or activities, PT Gapura Angkasa has the potential to face risks that can hinder the achievement of the Company's goals or targets that have been set, so the Company must be productive in implementing Risk Management efficiently and effectively in order to be able to adapt to business developments and maintain the Company's business continuity. The implementation of Risk Management at PT Gapura Angkasa uses the ISO31000:2018 standard framework
Risk Management – Guidelines that refer to international organizations for standardization, and consider the harmonization of regulations or provisions set by the group (IAS Group) so that it is expected to achieve optimal implementation of Risk Management. Risk management is a coordinated effort to direct and control the Company against the risks determined in carrying out business activities. With the implementation of Risk Management, it is expected that potential losses can be reduced as low as possible or even be able to utilize risks into opportunities that can increase profits and bring benefits to PT Gapura Angkasa. The elaboration of the implementation of Risk Management at PT Gapura Angkasa is set out in a Risk Management guideline that aims to provide clear direction and boundaries as well as responsibilities for the implementation of Risk Management at PT Gapura Angkasa. The purpose of implementing this Risk Management is intended as a guide for all levels in the Company in implementing Risk Management and is intended as a basis for:
Risk Management Policy
PT Gapura Angkasa has established a Risk Management Policy as a manifestation of the Company's commitment to implementing good corporate governance and the principle of prudence in all business activities. This policy adheres to the ISO 31000 standard and applicable regulations for State-Owned Enterprises.
Risk Management is implemented in an integrated manner through the Three Lines Model approach, with ultimate accountability resting with the Board of Commissioners and the Board of Directors, and supported by all levels of management and work units within the Company. Each work unit is responsible for managing risks within its authority and periodically reports its risk profile to management.
Through this Risk Management Policy, PT Gapura Angkasa aims to ensure effective risk management, support decision-making, improve Company performance, and ensure the achievement of objectives and sustainable business continuity.
Documentation
Stay informed about the latest activities.
Risk Management Unit
Risk Management Unit
Risk Management Unit