Governance

Risk Management

This is a image related to Governance

Policy

Policy (our fundamental view)

Recognizing the various risks surrounding the NOF Group, we promote risk management initiatives with the aim of preventing the occurrence of loss risks and minimizing their impact when they do occur, thereby contributing to the achievement of management strategy targets.

  1. The NOF Group comprehensively identifies various management risks surrounding its business, and conducts risk assessment based on the impact and frequency of each factor in order to identify risks that need to be addressed as a priority.
  2. According to the characteristics of the identified risks, We work to minimize the impact on management by taking appropriate measures to reduce the impact of risks that have materialized, as well as measures to reduce the probability of occurrence.
  3. We work to objectively verify the effectiveness of risk countermeasures by periodically conducting risk assessments, while working to recognize and evaluate new risks.
  4. Under the leadership of the Risk Management Committee, we promote the risk management of the NOF Group by implementing the above risk management cycle.

Organizational setup

The Risk Management Committee, the Compliance Committee, the RC Committee, and the Quality Management Committee analyze management risks, consider countermeasures, and report to the Board of Directors. The Board of Directors receives reports and deliberates as necessary on various business risks, including those related to compliance, information management, and environment and safety, as well as confirmation and evaluation of the comprehensiveness of risks. We manage and monitor Group companies in accordance with the rules on the management of Group companies, and offer advice, as necessary, while any important matters that are deemed to materially impact our subsidiaries’ assets or profit and loss are approved by the NOF Board of Directors or the Executive Committee.

This is the organizational chart for the Risk Management Committee. Risk assessment results are collected from manufacturing sites, sales offices, and affiliated companies. The Risk Management Committee reports to the Board of Directors and receives feedback in return. The committee meets regularly twice a year, with ad-hoc meetings held as necessary. The committee is chaired by an executive officer (appointed by the President) and includes members such as the General Managers of Corporate Planning, Technology, HR & General Affairs, Legal, Corporate Communications, Accounting, Information Systems, Procurement, and Intellectual Property. A full-time Audit & Supervisory Committee member and the Head of the Internal Control Office serve as observers; the Legal Department acts as the secretariat; and subcommittees cover Security Export Control, Information Security Management, Receivables Management, and Business Continuity Planning (BCP). The committee’s primary duties include determining risk management policies; verifying the comprehensiveness and assessment of risks; formulating risk management measures; reviewing risk mitigation strategies and monitoring their progress; conducting risk management training; following up on operational audits; and reviewing and evaluating the status of security export controls.

Diagram of Risk Management Committee organization

Risk Countermeasures

Risk assessment process

The Risk Management Committee takes the lead in preparing a list of risks in consideration of the business characteristics of each department and the environment surrounding the business, including global political, economic, and social conditions. Based on this list of risks, a questionnaire is sent to each NOF site and Group company to estimate the impact and frequency of each risk. Using the results of this questionnaire, the general managers of each division carry out risk evaluations. Based on the results, the Risk Management Committee identifies the risks whose response status should be recognized by management and consults with the Board of Directors to select the key risks for monitoring.
This process is conducted once every two years, and by reviewing risk items and worst-case scenarios each time, we constantly conduct risk assessments aligned with the latest
business environment.

This diagram outlines the risk assessment process, showing six steps from top to bottom alongside their respective details. First, every two years, the NOF Group identifies potential risks and compiles a risk list that includes a

Flow of risk assessment

Risk map (excerpt)

The risk map is prepared based on the results of a questionnaire estimating the impact and frequency of risks at each NOF site and Group company, as well as the results of risk evaluation by managers of each department. The risk map is regularly revised and key risks for monitoring are selected in order to implement activities aimed at enhancing the NOF Group’s resilience.

This diagram outlines the risk assessment process, showing six steps from top to bottom alongside their respective details. First, every two years, the NOF Group identifies potential risks and compiles a risk list that includes a

 

Overview and status of countermeasures of key risks for monitoring

 

Key risks for monitoring Overview Countermeasures
Harassment /
human rights violations
Possible decline in trust in the Company due to human rights abuse, such as violations of authority and sexual harassment at workplaces
  • Revise the NOF Group Corporate Code of Ethics and
    the Compliance Manual
  • Establish a consultation service with male and female employees as well as a contact point with attorneys
  • Implement a company-wide employee engagement survey and feed back results to employees
Cyberattacks and information system failures Possible information leaks and interruption of business activities, due to external attacks such as cyberattacks and information system failures
  • Establish the information security management rules and appoint a person responsible for information security management, etc.
  • Develop a defense system against illicit access and implement safety measures at appropriate, rational levels
  • Raise the overall level of security measures at each company and promote stronger incident response capabilities
Inadequate governance of overseas bases Possible decline in trust in the Company due to fraud, such as violations of laws and regulations, as a result of inadequate governance at
overseas bases
  • Develop a system for ensuring the appropriateness of
    business operations
  • Request a regular report on the state of business execution and financial conditions, etc.; conduct business audits
  • Strengthen communication through regular meetings with the NOF Head Office
Quality control Possible decline in trust in the Company due to quality fraud, falsification of quality inspection results, and other situations
Risk of a significant increase in workload due to rising customer quality demands
  • Ensure strict management of data related to quality control
  • Raise awareness and train employees
  • Conduct regular management audits

Overview of major risks and status of countermeasures

 

Major risk Overview Countermeasures
Technology leaks Possible decline in the NOF Group’s competitiveness, due to leakage of technology and technical information, which allows similar products/technologies to be provided by competitors
  • Establish rules for trade secrets
  • Develop a management system for trade secrets
  • Strengthen information security training for employees
Raw material procurement Risk of social credibility falling due to human rights violations such as forced labor and child labor, or procurement of raw materials suspected to damage the environment
  • Statement of compliance with the CSR Procurement Policy and CSR Procurement Guidelines in sales contracts
  • Ongoing supplier surveys through various questionnaires
Fires / explosions Possible casualties among employees and neighborhood residents, possible suspension of business activities, and possible compensation for damages as a result of large-scale fires and explosion accidents at plants
  • Continuously improve health and safety levels through Responsible Care activities
  • Strengthen the system for conducting safety assessments when installing new facilities
  • Formulate emergency response manuals and conduct training
  • Implement joint disaster prevention drills and dialogue activities with local municipalities
Intellectual property infringement, etc. Possible compensation for damages and possible orders to suspend manufacturing and shipment, due to infringements of intellectual property rights
  • Develop a check system for intellectual property management and patent infringement
  • Educate employees on intellectual property including patents and trademarks
Violations of laws and regulations Possible suspension of business activities and possible payments of surcharge, etc. following administrative dispositions taken in response to violations of laws and regulations, such as the Unfair Competition Prevention Act, Antimonopoly Act, Subcontract Act, Foreign Exchange and Foreign Trade Act, Chemical Substances Control Law, and Pharmaceutical and Medical Device Act
  • Prepare a Global Compliance Manual and country-specific compliance manuals based on the legal systems of each country
  • Establish compliance lecture and contact points for whistleblowing/consultation
  • Establish a system for disseminating information on revisions to laws and regulations
Earthquakes, tsunami, infectious diseases Possible interruption of production activities or business activities, including sales and distribution, due to earthquakes, tsunami, or other natural disasters
  • Formulate a business continuity plan (BCP)
  • Conduct BCP training and internal audits
  • Implement flood countermeasures for critical facilities
Delays in
talent development
Lack of development of core talent who will be responsible for business growth, due to a delay in implementing the human resource development plan, causing a possible stall in sustainable business growth and transformation
  • Build a system for deliberation and evaluation of company-wide talent development policy plans
  • Build a system to oversee indicators, targets, results, and countermeasures related to talent development
Inadequate disclosure of
non-financial information
Possible loss of trust from stakeholders due to uncertainty about economic and environmental impact as well as social reputation
  • Preparation of a roadmap for statutory disclosure
  • Introduction of a system to optimize the collection and aggregation of sustainability information

Security Trade Control

Basic policy on export control

The NOF Group implements appropriate security export controls to maintain the peace and security of Japan and the international community.
 

  1. Any exports of regulated goods or other items, intermediary trade transactions, or intermediary technology transactions that violate the Foreign Exchange and Foreign Trade Act or other applicable laws shall not be conducted.
  2. To comply with the Foreign Exchange and Foreign Trade Act and other applicable laws and implement appropriate export controls, a person responsible for security export control shall be designated to maintain and enhance the export control system.

Export control system

To appropriately implement security export controls in accordance with laws and regulations, the NOF Group designated the President as the chief officer and established the Security Trade Control Subcommittee under the Risk Management Committee. The Subcommittee operates under the internal Security Trade Control Subcommittee Rules and related Operating Rules. The Subcommittee is chaired and overseen by an Operating Officer appointed by the President who can make judgments independently of sales. Permanent members include the General Manager of the Corporate Planning & Strategy Department, General Manager of the Corporate Technical Division, General Manager of the Legal Department, General Manager of the Intellectual Property Department of the Corporate R&D Division, and General Manager of the Explosives & Propulsion Division.
Under the export review process, export applications issued by each business division’s Sales Department receive preliminary approval from the respective Planning Office, the Subcommittee Secretariat confirms the division’s review, and the Subcommittee Chairperson grants final export approval.
The Subcommittee Secretariat also conducts annual internal audits of export reviews at business divisions, R&D divisions, and affiliated companies. Audit results are reviewed by the Subcommittee and reported to the President after deliberation by the Risk Management Committee.

This is the organizational chart for the security export control system. It illustrates a reporting line extending from the President down to the Risk Management Committee, the Security Export Control Subcommittee, and the Division Managers. The Secretariat for the Security Export Control Subcommittee is positioned to the right of the Subcommittee itself. Reporting to the Division Managers are the Planning Office Manager and the Sales Department Manager; the latter oversees the Sales & Export Group Leader, followed by Sales & Export staff. Additionally, the structure entails the Division Managers managing affiliated companies, while the Secretariat for the Security Export Control Subcommittee conducts audits of those same affiliates.

Security trade control organizational chart

Security export control at domestic affiliated companies

In accordance with the Affiliated Company Management Rules, divisions supervising affiliated companies conduct necessary monitoring and guidance to ensure thorough security export control. To ensure proper export control operations, the NOF Security Export Control Operating Standards establish systems and procedures for guidance, training, and audits of operational structures and content for applicable affiliated companies, which are implemented regularly.

Awareness, education, and other initiatives

To ensure and sustain appropriate security export controls, we conduct internal awareness activities through information dissemination and educational activities such as seminars. In FY2025, we communicated information on changes in global affairs and legal revisions. We also held seminars for NOF and affiliated companies to raise awareness of legal revisions. We will continue responding promptly to external changes while conducting internal audits and considering improvements in operational efficiency.

Business Continuity Plan (BCP)

Basic BCP*policy and management system

To minimize damage to business assets and enable the continuation or early recovery of core businesses even during emergencies such as earthquakes, tsunamis, or infectious disease outbreaks, the NOF Group has developed a business continuity plan (BCP) centered on manuals governing emergency responses. Through annual internal audits and Company-wide drills involving top management, we promote “organizational learning” and improve the embedding and effectiveness of the BCP.
We have also prepared emergency manuals for initial responses to information incidents caused by cyberattacks and safety actions by overseas expatriates.

BCP training
 

Fiscal year 
implemented
Drill themes and assumed scenarios Key verification items and issues to address
FY2023 Cyberattacks and information leakage risks due to ransomware
  • Confirming the initial response flow when the above incident occurs and rapidly establishing the Emergency Response Headquarters
  • Reporting to relevant ministries and the Personal Information Protection Commission and verifying internal and external information disclosure processes
FY2024 Combined cyberattacks on overseas sites and geopolitical risks
(heightened tensions)
  • Initial response and securing alternative communication methods when communications with overseas sites are disrupted
  • Safety action process for expatriates and accompanying family members following an increase in the danger information level
FY2025 Tokyo metropolitan earthquake causing loss of Head Office functions, combined with a leak caused by torrential rain and the spread of misinformation on social media
  • Selecting an alternative Head Office site in Osaka or the Kanto region and verifying the process for safely and rapidly transferring authority
  • Early detection of misinformation through social media monitoring system (social listening), and emergency public relations responses to government authorities and local residents

 

BCP is an acronym for Business Continuity Plan. The plan illustrates policies, systems, and procedures designed to prevent important operations from being interrupted, or, if business is interrupted, that it is restored within the shortest possible timeframe even in the face of unforeseen events, such as a major earthquake or other natural disaster, the spread of infectious disease, a terror attack or other incident, a major accident, a disrupted supply chain, or a sudden change in the business environment.

Conducting practical drills in anticipation of diversifying risks

In recent years, threats surrounding companies have become increasingly diverse and complex due to more severe natural disasters, increasingly sophisticated cyberattacks, and heightened geopolitical risks. In light of these conditions, NOF’s recent BCP drills have practically simulated compound risks involving the simultaneous occurrence of multiple crises. In FY2025, we conducted a drill simulating the loss of Head Office functions due to a Tokyo metropolitan earthquake, combined with a chemical leak and the spread of misinformation on social media. The drill comprehensively verified processes for smoothly transferring authority from the affected area, initial public relations with government authorities and local residents, and risk communication.
As a result, we identified challenges such as transferring Head Office functions to a remote location, quickly detecting the spread of information on social media, and issuing timely communications. Reviewing alternative sites in the Kanto region and establishing a social listening system improved the effectiveness of our emergency BCP and our risk communication capabilities.

This is a photograph showing multiple executives and employees seated at a table with their laptops open, participating in a joint company-wide BCP drill in a conference room.

Company-wide joint BCP training

This is a monitor screen displaying the status of a BCP drill. Text such as

Information Security Management

Management of trade secrets and protection of personal information

The NOF Group considers information assets—including trade secrets and personal information entrusted to us by customers and business partners, or held by us, as well as systems for utilizing such information—to be important management resources in corporate activities. Based on the recognition that establishing robust information security for the information assets is essential for stable management, we have established an Information Security Policy as the basic policy for promoting the use and protection of information assets. At the same time, based on the recognition that protecting personal information is a fundamental social responsibility, we have established and published the Privacy Policy.
Under such policies, we have set forth specific measures for enhancing the levels of confidentiality, completeness, and availability of information and specific ways of handling personal information in our internal rules and manuals and are ensuring thorough dissemination and understanding within the company. Such internal rules and manuals include: Information Security Management Rules, Personal Information Protection Rules, Provisions Related to Information Systems, 
Confidential Information Handling Manual, and Information Equipment Handling Manual.

NOF Group Information Security Policy

The NOF Group considers information such as trade secrets and personal information entrusted to us by customers or business partners, or held by the Group, as well as systems, etc. for utilizing such information (below, “information assets”) as important management resources in corporate activities. Based on the recognition that establishing robust information security for information assets is essential for stable management, we have established the below Policy and ensure compliance therewith.

 

  1. The NOF Group shall develop the information security system to further strengthen the management function of information assets.
  2. In order to protect the information assets from leakage, falsification, and destruction, the NOF Group shall provide information security education for employees, develop regulations, and implement technical measures for information systems.
  3. The NOF Group shall comply with laws, regulations, codes, and contractual obligations related to information security.
  4. In the event of an information security incident, the NOF Group shall respond promptly and appropriately to each incident and prevent a recurrence.
  5. The NOF Group shall maintain and continually improve these efforts in this Policy.

Management system

In the internal organizational aspect, the Information Security Management Subcommittee is set up to deliberate and make decisions on important matters related to information security. Under the Information Security Management Supervisor, who is the chairperson of the Subcommittee, document information security management supervisors, electronic information and information system security management supervisors, personal information complaints handling supervisors, as well as a person responsible for management at each division, site, and department are appointed to manage the implementation of specific measures. Against threats such as unauthorized access from external, information leakage, falsification, and destruction, appropriate and reasonable security measures are implemented. In addition, NOF continually reviews and strives to improve the information security management and personal information protection systems and measures through internal audits.

This is the organizational chart for NOF Corporation's information security management system. Positioned directly under the President are the General Manager of Information Security Management and the Information Security Management Committee. Reporting to them are the Manager for Document Information Security, the Manager for Electronic Information and Information System Security, the Manager for Personal Information Complaint Handling, the Secretariat, and various divisions and offices. Within these divisions and offices, the structure proceeds from the Division/Office Information Management Manager down to the Department Information Management Manager, then to the Information System Manager, and finally to the end users.

Diagram of NOF’s information security management system

Risks and opportunities

The NOF Group recognizes the risks of business interruption and loss of trust due to cyberattacks and leaks of confidential or personal information, while viewing stronger information asset management as an opportunity to enhance competitiveness, earn customer trust, and improve employees’ security awareness. To both reduce risks and maximize opportunities, we implement risk-based measures and continuous monitoring and education.

Risks and opportunities in information security

 

Risks and opportunities Details Countermeasures
Risks
  • Long-term stoppage of production, sales, and R&D activities and loss of corporate credibility due to cyberattacks
    (illicit access, malware infection)
  • Loss of corporate trust and reduction in technological competitiveness due to leakage of confidential or personal information
  • Conduct self-inspections, and develop and implement
    improvement plans
  • Information sharing through meetings of IT managers at Domestic Group companies (once a year)
  • Conduct training on handling suspicious emails (once a year)
  • Respond by HDD encryption for computers taken outside the company and restrictions on the use of private storage media
  • Provide information security-related e-learning training for employees (once a year)
Opportunities
  • Improvement of corporate competitiveness through
    cybersecurity measures
  • Earning customer trust and enhancement of corporate brand value by strengthening information asset management
  • Increased employee awareness through strengthened
    information security
-

Number of information security incidents [Covered organizations:NOF] (Number)

 

FY2023 FY2024 FY2025
Number of incidents that occurred 0 0 0