Risk Management

Mission

We accurately identify the diverse risks that could impede the sustainable growth and development of the Resonac Group and society, while visualizing in an integrated manner the risks and opportunities involved in formulating and executing management strategies. By incorporating these insights into management decision-making, we contribute to enhancing corporate value over the medium to long term through optimal resource allocation.

Policies

In addition to controlling operational and hazard risks, we promote company-wide, comprehensive risk management that takes into account changes in the external environment, including international affairs and climate change.
Sustainable corporate growth requires not only avoiding and reducing risks, but also strategic risk-taking that creates opportunities for growth and earnings. We seek the optimal balance between risk control and risk tolerance and reflect our risk recognition and assessment across the entire business portfolio.

Promotion system

Risk management system

Resonac has established a risk management system compliant with ISO 31000. The system has been approved by the Board of Directors as an important component of the internal control system.
For key risks in group management and other important matters concerning responses to those risks, the Company has established a Risk Management Committee chaired by the CEO, where top management conducts cross-organizational deliberations. Matters deliberated by the Committee are reported to the Board of Directors after deliberation and approval by the Management Committee, and the directors oversee the development and operation of the risk management system.
Business units, sites, and major Group companies appoint risk owners, risk officers, and risk managers who are responsible for identifying and assessing risks and implementing response measures, thereby clarifying accountability through frontline implementation. In addition, with the Corporate Strategy & Resilience Department playing a central role as the Company-wide risk oversight function, Resonac is strengthening risk governance across the Group by enhancing risk assessments, monitoring key risks, and reporting to management in a timely manner.

Crisis management system

In the event of an accident, disaster, compliance incident or other incident in which risk becomes apparent, the relevant business unit or site reports to the CXO organization responsible for that risk and the CSO/CRO, and they respond in coordination. Should the incident be capable of threatening the Group’s existence or developing into a situation that could seriously impede the Group’s normal business operations, a Crisis Response Headquarters headed by the CEO will be established to respond promptly and appropriately.

If a significant impact on business continuity is anticipated after the initial response, we will activate the BCP (Business Continuity Plan) in order to maintain and quickly restore business activities and fulfill our responsibility to customers, including the continued supply of products necessary for maintaining social infrastructure.

For overseas sites, we plan to progressively develop systems similar to those used in Japan.

Risk management system diagram

Strategy for Realizing the Long-Term Vision

Vision for 2030 and Progress

Vision for 2030 Issues to be addressed Results in 2025 Plans for 2026
  • All employees understand and practice the principles and concepts of risk management
  • Achieve world-class management by establishing and improving risk management structures and systems that support the three lines of defense
  • Realize ERM that refines risk intelligence through AI and supports business operations
  • Develop and operate an effective management system, including the formulation of BCM/BCP
  • Strengthen risk assessment and management systems amid high uncertainty
  • Refine top-down risk scenarios from a management perspective and establish an alert management system that quantitatively captures early warning signs
  • Achieve globally competitive risk management by using generative AI and external data to conduct advanced analysis and assessment of highly uncertain risks
  • Improve BCP effectiveness and establish higher-level standardization
  • Further enhanced the Company-wide risk inventory and identified and updated key risk themes through management discussions
  • Deployed scenario planning and early warning monitoring using generative AI
  • Rolled out Company-wide training to verify BCP effectiveness
  • Conducted BCP training for executives based on the scenario of a major earthquake directly beneath the Tokyo metropolitan area
  • Managed and reviewed the response to a cyber incident and prepared an initial-response flowchart for the Crisis Response Headquarters
  • Refine top-down risk scenarios and establish a quantitative alert management system
  • Promote global deployment across the four RHQ regions and through business units
  • Conduct advanced analysis and assessment by incorporating generative AI and external data
  • Develop and enhance BCPs at overseas pilot sites
  • Develop and strengthen IT-BCP
  • Introduce an emergency information-gathering system with multiple reporting lines, reflecting lessons learned from the cyber incident

KPI Targets and Results

Resonac positions sustainability at the core of its company-wide strategy and has identified key sustainability issues (materialities). In the area of risk management, we have established the KPIs below and are working to realize our long-term vision through the achievement of each materiality.

Key Items (KPIs) Results in 2025 2026 Targets
Progress rate of risk response measures / status of measures promoted by each lead organizationIndicators are managed separately for each theme
(Not disclosed)
Indicators are managed separately for each theme
(Not disclosed)
Top-review cycle / review implementation rate by Management Committee membersExecutive study session implementation rate / theme-specific review rate
(Not disclosed)
Executive study session implementation rate / theme-specific review rate
(Not disclosed)

Risk management processes

Our business environment is constantly changing significantly due to technological innovation, market shifts, and policy developments, and uncertainty and complexity are increasing. To maximize corporate value in this environment, we believe it is important to make two mutually complementary approaches function together: a bottom-up approach that uses frontline knowledge and experience to manage and reduce risks encountered in day-to-day operations, and a top-down approach that prioritizes Company-wide risks and optimizes resource allocation from an organizational perspective.

Company-wide risks identified through these two approaches are visualized systematically using heat maps and other tools. We are also enhancing our understanding of the materiality and interrelationships of risks through the verification and analysis of risk data using digital technologies, including generative AI. The Risk Management Committee then deliberates these risks as Company-wide key risks, and intensive management discussions help formulate response policies and incorporate them into management decisions.

Bottom-up risk approach

The process by which each department identifies and assesses risks is supported by a standardized Enterprise Risk Management (ERM) system that aggregates and centrally manages data. Managers and above across the Company continuously share information through the system, helping improve the effectiveness of day-to-day risk reduction activities at the frontline level.

In fiscal 2024, templates for risk events and assessment items were implemented in the system, facilitating the categorization and accumulation of risk data. Based on this progress, in fiscal 2025, we promoted consistent granularity in risk inventories across business units and departments, thereby improving the accuracy of risk assessments.

The control departments (CXO organizations) responsible for each risk area review the risk events and assessment results identified by departments, together with related data such as current response status and future response plans, and promote cross-departmental communication by providing support and advice as needed. Individual risk events assessed as highly significant in terms of likelihood and impact are identified as top risks, continuously shared and verified with each department, and discussed intensively by the Risk Management Committee. In 2025, 5,186 risks were registered in total, of which 16 top risks were discussed.

Top-down risk approach

The external environment is rapidly becoming more diverse and complex, further increasing uncertainty about the future. Based on discussions by the Risk Management Committee and taking into account risk megatrends, we identify external environmental factors and changes that the Resonac Group should monitor.

Based on these analyses and the top risks identified by each department, management identifies and prioritizes Company-wide key risk themes at executive study sessions. We further enhance risk awareness through a scenario-based approach that reflects changes in the external environment and incorporate the results into management strategies and business operations.
For each Company-wide key risk theme, the CXO responsible for the relevant area leads the Company-wide response. In fiscal 2026, we will further systematize the definition of individual risk scenarios derived from major risk themes, including compound risks. We will also implement management-level indicator tracking using Key Risk Indicators (KRIs) and threshold-based monitoring in the Enterprise Risk Management (ERM) system, thereby strengthening the operating framework that supports early risk detection and agile decision-making.

Identifying and prioritizing Company-wide key risk themes

Area Related themes Key discussion points
Growth driver area
(review of risk appetite)
  • AI and talent: restructuring the talent portfolio in response to the rise of AI
  • Risks arising from AI-driven technological innovation and market change
  • Delays in capital investment: delays in upgrading and automation
  • Automation of patent drafting and filing through AI could rapidly transform technology protection and the competitive environment, including the rapid expansion of patent portfolios and the risk of infringement
  • Advances in quantum and physical AI may change the speed from R&D through production, making the design of data and infrastructure a key issue

AI-related risks remain particularly uncertain and will continue to be monitored intensively as S-rank risks.

Economic security area
(setting directional parameters and variables)
  • Country risk and economic security
  • Focus scenarios and proceed primarily with issues on which action has not yet begun

As an S-rank theme, conduct scenario-based reviews assuming specific contingencies.

Foundation development area
(strengthening resilience)
  • Supply chain management issues
  • Information leakage and cyberattacks
  • Individual measures have progressed to some extent, and uncertainty is considered to have decreased relatively
  • However, information leakage remains an issue from a control perspective

Continue existing measures and maintain progress management.

Promotion of BCM

In line with the BCM/BCP guidelines formulated in 2023, our company sets target recovery times and target recovery levels through BIA (Business Impact Analysis) and creates BCPs accordingly. The products targeted for BCP development are reviewed annually based not only on sales and profits but also on whether they are products necessary for social infrastructure. As an example, the disaster assumptions for our BCP are created based on seismic intensity probability maps published by public institutions, estimating the impact on each of our company’s locations. In addition to the products traditionally subject to BCP formulation, since 2025, we have started BCP formulation activities for all business locations, including those without products subject to BCP development. Furthermore, not only BCPs that respond to conventional hazard risks and operational risks, but also considering the current situation where geopolitical risks and cyberattack risks are increasing, since 2026, we have begun discussions on BCP formulation for our corporate division.

We are also advancing training to verify BCP effectiveness. We will establish a support system to enable each site eventually to conduct training independently. To strengthen executives’ crisis response capabilities, we conducted BCP training based on a Taiwan contingency in 2024 and a major earthquake directly beneath the Tokyo metropolitan area in 2025. In 2026, while advancing overseas deployment of BCPs, we are enhancing BCPs at pilot sites as a foundation for that deployment. In addition, following the security incident that occurred last year, we are advancing the Company-wide deployment and testing of IT-BCP.