Risk Management
Governance (G)
Customers, Suppliers and Other Trade Partners, Employees, Local Communities, Global Environment
Basic Approach and System of Risk Management
Related information
Risk Management Initiatives
We classify risks surrounding the company by category and implement an annual survey of domestic and overseas group companies to determine which risks have the greatest impact on management. The results of the survey are shared with the Risk Management Committee, and important risks that should be addressed by the entire group are selected and prioritized for action.
Risk Categories List
| Domain | Risk Categories |
|---|---|
| Transactions and legal | Violation of antitrust laws, unauthorized trade, bankruptcy of business partners, violation of proper transactions act, contract troubles, failure to comply with trade regulations, etc. |
| Society and economy | Soaring prices of raw materials and crude oil, changing customer needs, fluctuation of interest rate, exchange rate and stock price, etc. |
| Natural phenomenon | Earthquakes, wind and flood damage, lightning strikes, land subsidence, etc. |
| Politics | War, terrorism, and civil unrest; stricter regulations and tariffs, involvement with anti-social forces, etc. |
| Technology | Lagging behind in technological innovation, obsolescence (including AI and DX), etc. |
| Management and internal control | Insider trading; failure to disclose material facts, tax evasion or underreporting, business strategy failures, public relations failures, intellectual property infringement, improper entertainment or gift-giving, etc. |
| Finance | Fictitious accounting, insufficient funds, etc. |
| Products | Product accidents, data impersonation, delay of delivery, insufficient performance, use of prohibited materials, ethical violations in the supply chain, delay in responding to claims, etc. |
| Employment | Loss of personnel, staffing imbalances (shortages or surpluses), declining morale, harassment, illegal employment, scandals, labor-management disputes and strikes, soaring labor costs, etc. |
| Information | Prolonged system outages, cyber-attacks, information leaks, etc. |
| Environmental problems | Pollutant leakage, noise/vibration, illegal dumping, violation of environmental laws and regulations, etc. |
| Safety and health | Injury/disease/mental health of employees, traffic accidents, novel influenza, etc. |
| Facilities and equipment | Fire/explosion, equipment accident, theft/vandalism, trespassing, etc. |
| Human rights | Violation of human rights laws and regulations, etc. |
Related information
The following are the key risks we are aware of and the measures we are taking (excerpts).
Business Continuity
Large-Scale Disaster
We have established a Business Continuity Plan (BCP) to ensure a rapid return to normal business operations in the event of large-scale disasters, such as earthquakes. The initiative began with the Automotive Anti-Vibration Business Divisions in 2010, and we have since completed the formulation of BCPs for all domestic and overseas bases, including group companies. Currently, we are checking the effectiveness of the BCPs, evaluating the linkage of each BCPs and conducting drills for further spiral improvement.
In 2018, we also began creating a disaster initial response plan focusing on initial measures in the event of a large-scale disaster. We are conducting drills based on the prepared plan to improve the effectiveness of the plan. Furthermore, we are collaborating with the purchasing division to share information on the status of procurement in the event of a disaster or accident.
In 2018, we also began creating a disaster initial response plan focusing on initial measures in the event of a large-scale disaster. We are conducting drills based on the prepared plan to improve the effectiveness of the plan. Furthermore, we are collaborating with the purchasing division to share information on the status of procurement in the event of a disaster or accident.
Infectious Diseases
Based on the knowledge gained from the countermeasures against the new coronavirus infection, we have formulated the "Sumitomo Riko Group Action Plan for Countermeasures against New Infectious Diseases" by completely revising the existing "Sumitomo Riko Group Action Plan for Countermeasures against Highly Virulent New Influenza". Thus, we are working to expand our crisis management system to include the spread of new infectious diseases in addition to existing infectious diseases.
From now on, we will work to strengthen the Group's infectious disease countermeasures and business continuity by spreading the action plan throughout the Group, including overseas companies.
From now on, we will work to strengthen the Group's infectious disease countermeasures and business continuity by spreading the action plan throughout the Group, including overseas companies.
Protection of Personal Information
In accordance with the "Personal Information Protection Policy" and "Basic Rules for the Protection of Personal Information," we handle the personal information of our customers, business partners, and employees in an appropriate manner while complying with the laws and other regulations regarding the protection of personal information.
In response to the EU General Data Protection Regulation (GDPR) and other trends of strengthening regulations worldwide, we are working on measures to review legal systems in each country and region, and are strengthening personal information management systems throughout the Group.
In response to the EU General Data Protection Regulation (GDPR) and other trends of strengthening regulations worldwide, we are working on measures to review legal systems in each country and region, and are strengthening personal information management systems throughout the Group.
Related information
Information Security
Information Security Basic Policy
The Sumitomo Riko Group has established the Basic Policy on Information Security to maintain and improve information security, which is one of the most important issues in our business activities, in order to become a "Global Excellent Manufacturing Company" that is needed worldwide and to continue to be a company that is trusted by our customers and society.
1. Establishment of Rules for Information Security
The Group shall establish and comply with rules, guidelines, and other regulations in order to appropriately manage information assets in accordance with the risks they pose in the course of conducting business.
The Group shall establish and comply with rules, guidelines, and other regulations in order to appropriately manage information assets in accordance with the risks they pose in the course of conducting business.
2. Information Security Management Structure
The Group shall promote organizational, personnel, technical, and physical information security measures by establishing a company-wide information security management system led by a director who is responsible for information security.
The Group shall promote organizational, personnel, technical, and physical information security measures by establishing a company-wide information security management system led by a director who is responsible for information security.
3. Information Security Education
The Group shall provide education on information security to directors and employees to improve their information security literacy.
The Group shall provide education on information security to directors and employees to improve their information security literacy.
4. Continuous Information Security Management
The Group shall strive to continuously improve and enhance information security in response to changes in laws and regulations, changes in the social environment, and changes in information security risks, as well as to maintain and improve security measures.
The Group shall strive to continuously improve and enhance information security in response to changes in laws and regulations, changes in the social environment, and changes in information security risks, as well as to maintain and improve security measures.
Information Security Management System
To address information security measures on a company-wide basis, our Group has established a framework to prepare for cyber risks. This structure operates under the oversight of a Chief Information Security Officer (CISO) and includes a "Risk Management Committee" to assess and address management-level risks, as well as a "CSIRT*" to respond to information security incidents such as system outages or data breaches caused by cyberattacks.
Furthermore, we collaborate with the CSIRT of our parent company, Sumitomo Electric Industries (SEI-CSIRT), to strengthen information sharing and incident response capabilities.
*Computer Security Incident Response Team
Furthermore, we collaborate with the CSIRT of our parent company, Sumitomo Electric Industries (SEI-CSIRT), to strengthen information sharing and incident response capabilities.
*Computer Security Incident Response Team
Implementation of Information Security Measures
In response to the demand for reform of the IT utilization environment, such as DX, work style reforms, and the use of cloud services, we are striving to improve employee IT literacy and reduce security risks.
・Information Security/Factory Security Training (group education, e-learning, etc.) and targeted e-mail training
・Vulnerability assessment of critical systems
・Training on how to respond to security incidents
Main Activities:
・Establishment of rules and guidelines to maintain information security・Information Security/Factory Security Training (group education, e-learning, etc.) and targeted e-mail training
・Vulnerability assessment of critical systems
・Training on how to respond to security incidents
Confidential Information Management
In order to properly manage, protect, and utilize confidential information, as well as to prevent unauthorized acquisition, use, or leakage of confidential information from other companies, the Sumitomo Riko Group formulates management methods according to the level of importance and conducts ongoing internal educational activities.
We also strive to implement preventative measures and strengthen our response in the event of a leakage.
We also strive to implement preventative measures and strengthen our response in the event of a leakage.
Security Export Control
In order to comply with export regulations for the purpose of international security, we have established internal rules for export control and an export control system with the Director as the Chief Officer.
When exporting, etc., we conduct appropriate screening of individual business negotiations and obtain individual export permits before conducting export activities.
For employees involved in export operations, mainly in each division within the company, regular training based on the latest case studies is conducted to build awareness and acquire knowledge of security export control. In addition, we are constantly monitoring the appropriateness of activities by checking the management status within the company and at affiliates, and sharing information among internal departments and affiliates through the Risk Management Committee to reduce security export control risks for the entire Group.
When exporting, etc., we conduct appropriate screening of individual business negotiations and obtain individual export permits before conducting export activities.
For employees involved in export operations, mainly in each division within the company, regular training based on the latest case studies is conducted to build awareness and acquire knowledge of security export control. In addition, we are constantly monitoring the appropriateness of activities by checking the management status within the company and at affiliates, and sharing information among internal departments and affiliates through the Risk Management Committee to reduce security export control risks for the entire Group.
Export Control System
