Risk Management Policy

The Management Conference serves as the principal body for integrated management of risk across our Group, with the President as the supervising officer responsible for risk management. Our risk management framework is structured as follows:

1. Risk Management Structure

  1. The Management Conference serves as the principal body for integrated management of risk across our entire Group, with the President as the supervising officer.
  2. Executive officers, technical specialist officers, and representatives of Group companies, in their capacity as risk management officers, shall supervise risk management within their respective organizations in accordance with the Sustainability Basic Policy and Risk Management Regulations established by the Board of Directors.
  3. The Management Conference may establish advisory bodies or executive bodies related to risk management in order to realize risk management objectives across our Group.
  4. Representatives of Group companies shall establish internal rules necessary to operate the Risk Management Regulations in accordance with the business conditions and organizational circumstances of each Group company.
  5. Risk management for information assets shall be implemented through an Information Security Management System (ISMS) that complies with ISO/IEC 27001 (JIS Q 27001), ISMS Cloud Security Certification Requirements (JIP-ISMS 517), Code of Practice for Information Security Controls for Cloud Services (ISO/IEC 27017 (JIS Q 27017)), and Code of Practice for Protecting Personally Identifiable Information in Public Cloud Environments (ISO 27018). This shall be conducted in accordance with ISMS regulations as well as Risk Management Regulations, and shall be applied to Group companies as necessary.

2. Risk Management Committee

  1. From the perspective of internal control importance supporting our corporate governance, a Risk Management Committee shall be established to manage information security risks, legal and compliance risks, and reputational risks arising from daily operational matters such as business accidents, errors, system failures, fraud, and disaster response.
  2. The Risk Management Committee shall be chaired by the President, with detailed operational procedures to be determined by the Management Conference.

3. Response to Risk Incidents

  1. Officers and employees of the Company who become aware of a risk incident or have reason to believe one may occur shall immediately report it to their supervisor and the Risk Management Office and shall comply with their instructions, even outside business hours.
  2. Officers and employees of Group companies shall report to the Company's Risk Management Office through the reporting channels established by their respective Group company.
  3. Upon receiving such reports, the Risk Management Office shall respond as follows:
    1. When a report is determined to constitute an emergency (including cases where it is difficult to determine whether an emergency has occurred), the Risk Management Office shall immediately report to the Management Conference (or other advisory or executive bodies as specified in the Risk Management Regulations) and to the risk management officer. The Risk Management Office shall also request coordination with external specialists such as legal counsel and external organizations.
    2. For risk incidents not constituting an emergency, the Risk Management Office shall coordinate with the risk management officer to take necessary measures and shall report on progress to the Management Conference without delay. Departments and Group companies receiving instructions for necessary response measures shall report the progress and results of such measures to the Risk Management Office without delay.

4. Response to Emergencies

  1. Upon receiving a report of an incident constituting an emergency, the Management Conference shall respond as follows:
    1. In cases of particular severity and urgency, a Crisis Response Headquarters shall be established.
    2. When Crisis Response Headquarters is not established, the Management Conference shall take necessary measures.
  2. When a Crisis Response Headquarters is established, the Company's President shall serve as its Director. Should the President be unavailable, another Director shall assume this role in accordance with an order predetermined by the Board of Directors.
  3. The Crisis Response Headquarters or Management Conference shall coordinate with the Risk Management Office, relevant departments, external specialists such as legal counsel, and external organizations in addressing the emergency.

5. Reporting Following Risk Incident Resolution

  1. The head of the department responsible for managing and resolving the risk incident shall promptly report the progress and results of the resolution to the Risk Management Office.
  2. The Risk Management Office shall report to the Management Conference on information received from officers and employees.
  3. The Management Conference shall regularly report to the Board of Directors on the occurrence and resolution status of risk incidents and other risk management activities.

6. Audit of Risk Management

The implementation status of risk management measures shall be subject to audit by the internal audit function.