Risk Management
Among the matters described in the Japanese-language Securities Report (Yuka Shoken Hokokusho), major risks—specifically those concerning the status of operations and accounts—recognized as having the potential to materially affect consolidated operating results, financial position and cash flows (hereinafter, collectively “operating results, etc.”) are presented below.
Note that TISI defines “risk” as “any factor that may hinder realization of the management philosophy, goals and strategies of the Company and the Group by causing economic loss; the interruption, stagnation or suspension of business operations; and/or damage to the Company’s credit or brand image.” In addition, groupwide risks are classified into four categories—strategic risks, financial risks, hazard risks and operational risks—according to Rules for Risk Management.
We apply our own risk management evaluation methodology to comprehensively assess all risks in terms of occurrence frequency and loss impact level. However, the impacts that each risk could have on operating results, etc. will vary depending on the nature of each risk event, the likelihood that the risk will emerge, and the timing of that emergence. Since more specific explanations of each risk are difficult, detailed descriptions of the potential damage to operating results, etc. have been omitted.
Note that forward-looking statements presented here are based on information available to management as of the filing date for the annual securities report in Japanese.
TISI established Rules for Risk Management to facilitate an accurate understanding of the risks facing the Group and to prevent losses from occurring. In accordance with these rules, an executive is appointed to oversee risk management of the entire Group. We also maintain a dedicated risk management department tasked with continually improving the overall risk management framework. In addition, we routinely review groupwide risk management policies and assess the implementation status of risk mitigation efforts. If a significant risk event occurs at a Group company, a crisis response headquarters is quickly set up to ensure appropriate measures are taken to minimize damage.
Regarding the status of the risk management system, we promote various measures to maintain and improve groupwide internal controls, in accordance with basic policy and various associated regulations, and also monitor ongoing development and operation of the internal control system and support a process for reporting the outcome of discussions by the Group Internal Control Committee to the Board of Directors.
<Risk Management Process>
At TISI, we assess risk from two perspectives: first, risks within the Group, where the Group’s priority risks guide Group company presidents in setting risk policies—for top-down risk direction and material risks—which in turn enable individual divisions to pinpoint specific risks; and second, new risks that materialize due to changes in the business environment and require a response aligned with management strategy. The Group Internal Control Committee examines identified risks for the entire Group twice a year, confirming issues related to those risks and evaluating the status of improvement measures, and then reporting to the Board of Directors. In response, the Board of Directors issues instructions that will be reflected in efforts to strengthen and improve the groupwide internal control system.
1) Strategic risks
1. Human resources
Driven by technological innovations, such as AI, and the consequences of a shrinking workforce, securing and developing human capital—a key management resource—represents a high-priority challenge for the Group. A shortage of top-level engineering talent, management talent, global talent and AI-ready talent, and a delay in reskilling and new skill acquisition could have a significant negative impact on our businesses and operating results, etc. To address this risk, TISI analyzes the impact path related to human capital and pinpoints KPIs for human resource strategies that could affect future financial performance on a groupwide basis. We track the status of these KPIs and make the appropriate adjustments to enhance human capital for business growth. At the same time, we are keen to adopt new workstyles and realize a higher level of job satisfaction among employees, and toward this end, take steps to attract and keep skilled individuals by creating a corporate culture, human resources structure and office environment that enables a diverse group of people to thrive. We complement this approach with initiatives to reinforce investment in human capital and to increase the base component of compensation to retain talent at a level necessary to prevent business growth from turning sluggish due to employee turnover.. In addition, TISI emphasizes measures related to human resources development, including support for acquiring qualifications and defining a career path, access to AI education programs and reskilling opportunities, and standardized training programs.
2. Changes in the market and economy
Our competitive advantage could be sidelined if we fail to keep pace with advancements in IT, notably AI—especially generative AI—and rapid changes in the business environment and social structures, impairing our ability to align services to client needs, which in turn could adversely affect our businesses and financial results. To mitigate this risk, we are implementing measures, such as rebuilding our ERM framework to enhance market analysis and fine-tune the accuracy of our strategies, focusing on high-value-added services, and training AI talent across multiple departments. In addition, we regularly review our technology strategy to select core technologies while innovating service processes—from proposal through development and operation—to differentiate the Company and by extension, the Group, from industry rivals. In addition, there is a risk that economic shifts and foreign exchange losses during rapid weakening of the yen could hurt overall financial performance. To minimize this risk, we apply currency hedges, conscious of the need to balance volatility and hedging costs.
3. Investments
TISI pursues capital contribution and M&A opportunities targeting companies at home and abroad to achieve business growth and acquire cutting-edge technologies. We also invest in large IT facilities, such as data centers, software, and human capital. But these investments carry the risk of adversely impacting operating results if plans do not deliver anticipated results, projects fall short, or scandals arise.
Therefore, depending on the nature of the investment, the Board of Directors, the CVC Investment Committee, the Investment Committee or other senior management body will carefully consider the opportunity from a business plan perspective before any final decision. We routinely follow progress on the associated business plan even after the investment has been made. In addition, for companies brought under our umbrella through large-scale capital alliances or M&A agreements, we assess operational risks pre-investment and implement any corrective actions necessary on an ongoing basis. We also appoint executives to these companies to gain rapid visibility into operations.
4. Overseas business
Overseas business may be impacted by various factors, including global economic and foreign exchange trends, legal regulations on investment and competition, local business practices, and labor-management relations. The departure of key personnel at overseas subsidiaries or affiliates, a decline in local revenue, stalled collaborations, cash-flow shortfalls, shortages of management talent, and deficiencies in global group governance are particular issues that could impact our businesses and operating results, etc. on a groupwide basis.
In response, we establish credit limits (for major overseas subsidiaries), implement monthly monitoring and information sharing, strengthen local corporate controls, develop overseas management talent (through partnerships with universities and startups, rotation of branch managers, training of young employees and talent pooling), adjust the scope of controls following the merger with INTEC, and enhance our ability to pinpoint local risk conditions early and reinforce response mechanisms. We also maintain a dedicated structure for overseas governance, and we promote measures to reinforce governance at overseas subsidiaries and affiliates
5. Human rights
The Group’s business activities may have a direct or indirect negative impact on certain stakeholders. The occurrence and disclosure of such events could damage the reputation and credibility of TISI and/or the Group, and could affect businesses and operating results, etc.
The human rights policy set by TISI for the Group is based on the Guiding Principles on Business and Human Rights adopted by the United Nations Human Rights Council in June 2011. Furthermore, by promoting human rights due diligence in line with this policy, TISI demonstrates its commitment to taking appropriate measures to identify and correct at an early stage any negative impacts of the Group’s business activities on society. The progress of these efforts is appropriately disclosed on the Company’s website. In addition, we maintain a rigorous system that leverages specialized expertise to preemptively mitigate risks prior to launching new businesses or entering new markets.
6. Geopolitical risks
Our businesses and operating results, etc. could be adversely affected if events such as war, civil conflict, political upheaval, revolution, terrorism, or riots create new international pressures, exchange rate fluctuations, trade friction, or increased procurement costs.
We will promptly assess the groupwide impact of such events, should they occur, and take quick, proactive measures to prevent losses stemming from each type of risk. In addition, TISI’s Business Continuity Plan (BCP) incorporates crisis response measures for expatriate employees and protocols for handling disruptions to offshore transactions.
7. Reputational risk
If our failure to properly manage risks results in a negative impact on society—or if we are simply perceived to be linked to a negative impact caused by another company— the consequences could be significant. A tarnished reputation and damaged brand image has the potential to interrupt the flow of business, cause projects to stall, or lead to a complete shutdown of operations. Such events may jeopardize our relationships with valued clients and business partners. Issues related to corporate governance, business and human rights, environmental impact, compliance, quality, and information security are particularly relevant to reputational risk. Management believes that this risk increases in proportion to business expansion and enhanced corporate profile, and that if the Company fails to take quick action to contain risks, even an incident that occurs at a subsidiary could have widespread implications for the entire Group. Therefore, we have in place a cross-group escalation system and a response manual for use should a situation arise.
8. Technological innovation
If we fail to keep pace with technological innovations, such as AI, we risk losing our competitive advantage due to an inability to secure the necessary talent and establish required development methodologies to meet demand. This could adversely affect our businesses and operating results, etc.
We are steadily implementing initiatives to reinforce business transformation groupwide. These include formulating AI-driven system development methodologies for deployment groupwide, defining AI talent requirements, introducing training programs, fostering networking through architect community activities, and establishing a dedicated team to gather information on the latest technologies. In addition, we formulated the Basic Policy on the Use of AI to guide us in harnessing the power of AI, driving the development of a sustainable society and maximizing provided value for our clients. We will integrate the knowledge and technology assets of Group companies and build a collaborative ecosystem that extends the scope of value creation and fosters innovative solutions to social issues. At the same time, we will carefully address risks associated with AI utilization to cultivate a trusted environment where clients can choose services with confidence.
2) Financial risks
1. Securities held
Some companies under the TIS INTEC Group umbrella buy and hold equity in suppliers and other business partners but only in cases where such investments are seen to underpin stable alliances and cooperative relationships that could lead to new business opportunities and support sustainable growth of the Group and enhance its medium- and long-term corporate value. TISI also invests in bonds as part of its short-term surplus fund management operations. However, businesses and operating results, etc. may be impacted if sharp fluctuations in the market prices of these marketable securities or deterioration in the business status of the issuing entities requires TISI to book accounting losses or apply some other accounting treatment.
Accordingly, TISI carefully confirms the safety of these securities by thoroughly examining issuer-related financial status, performance trends, credit ratings and other relevant indicators. In addition, TISI regularly reviews the suitability of continuing to hold the securities and reduces them if continued holding presents little significance.
2. Exchange rates and tax risks
Currency volatility affecting loans and transactions with overseas subsidiaries carries the risk of financial losses, while donation and transfer pricing taxation could result in additional tax assessments. TISI hedges loans to overseas subsidiaries using currency swaps and forward exchange contracts, and regularly verifies and reviews the appropriateness of these operations in accordance with detailed rules for derivatives management. For donations and transfer pricing, we prepare documentation to demonstrate economic rationale, and we conduct comprehensive risk assessments and implement appropriate measures to comply with global tax reforms and BEPS 2.0 requirements.
3) Hazard risks
1. Pandemics (the global spread of infectious and communicable diseases)
A pandemic that restricts operations in domestic and overseas markets and significantly impacts production activities by employees within the Group and at business partner companies has the potential to adversely affect our businesses and operating results, etc.
For this reason, TISI has a BCP in place for use should a pandemic occur.
2. Natural disasters
As global warming increases the likelihood of floods and other natural disasters occurring with greater frequency and in areas historically unaffected by such events, we face heightened risks to our operations. A large-scale natural disaster—or any extended power outage resulting from such a disaster that lasts longer than anticipated—could disrupt outsourcing and cloud service businesses, which rely on data centers and other large-scale IT facilities operated by Group companies.
Accordingly, TISI conducted an assessment based on the Taskforce on Nature-related Financial Disclosures framework to better understand disaster risk from a data center perspective. With or without that assessment, Group companies operating data centers are already required under our business continuity plan to ensure that their facilities are properly equipped to handle various types of disaster scenarios. Moreover, legacy facilities are being phased out as operations are consolidated into state-of-the-art data centers featuring highly reliable electrical infrastructure underpinned by seismic-isolation structures, robust disaster-mitigation equipment, emergency backup generators, fuel reserves, and priority fuel-supply agreements. To round out risk-mitigation efforts, we introduced a dedicated data center business continuity plan (DC-BCP) and will continue to conduct operational inspections and implement measures to prevent recurrence of disruptions if such situations have occurred in the past.
3. Cyberattacks
TISI could see its reputation tarnished and public trust lost because of information leaks caused by cyberattacks, malware infections, client system vulnerabilities and security breaches at contracted service providers. To mitigate such risks, we defined a groupwide CSIRT (Computer Security Incident Response Team) framework and utilize the Group Security Promotion Meeting to share pertinent information security data. We also maintain our own CSIRT for early threat discovery and quick, accurate action as required. Within this framework, we collect, analyze and share an extensive range of information on the latest attack methods and incident trends while also emphasizing network monitoring, timely action in the event of a security breach, and reaching out to external sources for new insights. Going further still, we created an IT-BCP to underpin cybersecurity efforts, and we run drills on a regular basis.
4) Operational risks
1. System development
Outsourced development and maintenance of various information systems for client companies is one of the Group’s core businesses. As system development becomes more sophisticated, complex and subject to tighter time constraints, larger-than-expected costs may be incurred if additional work is required to secure the promised level of quality or if a project cannot be completed on schedule. These increased costs and the possibility of claims for damages from clients due to delays or other situations could impact our businesses and operating results, etc.
To mitigate system development risk, TISI relies on a dedicated team to carefully screen business proposals based on a proprietary, ISO9001-compliant quality management system and to execute a thorough review at each stage of a project. This process underpins ongoing efforts to enhance quality control and boost productivity. In addition, we utilize the Group Quality Executive Meeting to drive quality improvement measures and production innovation throughout the Group, while also enriching tiered training programs to reinforce managerial and technical capabilities. We constantly update this system to keep pace with the latest trends.
Certain system development operations are outsourced to domestic and overseas partners to secure production capacity, enhance efficiency and leverage external technical expertise. Any failure by a partner to meet productivity or quality expectations could jeopardize smooth project execution and impact our businesses and operating results, etc.
To reduce this risk, we seek to better understand the operating status of our business partners through regular communication and supplier assessments, which will lead to stronger relationships. This ongoing engagement enables us to secure top-tier partners in Japan and overseas.
2. System operation
TISI relies on data centers and other large IT facilities to provide outsourcing and cloud services. If system problems arise due to human error or equipment malfunctions during system operation, and facilities are unable to provide services at the level agreed upon with the client, businesses and operating results, etc. may be impacted.
To minimize this risk, TISI uses a system maintenance/operation framework based on ITIL (Information Technology Infrastructure Library) practices to constantly improve system operation quality and also establish and strengthen measures for real-time system monitoring, early fault detection, incident reduction and prevention.
3. Information security
In the course of executing wide-ranging business activities, from system development to operation, TISI and other members of the Group are privy to various types of confidential information, including personal information held by clients and information about the technologies used in their systems. If such confidential information is leaked or tampered with, our businesses and operating results, etc. could be impacted by claims for damages from client companies affected by the breach and by a loss of trust in our services. Meanwhile, with the Internet now a part of the social infrastructure and various forms of information easily and instantly accessible, the range of potential users has expanded and convenience has increased. Concurrently, the risk of accidents and system failures due to unauthorized external access is growing. Failure to respond appropriately to such situations could also lead to claims for damages from affected clients and by a loss of trust in the Group’s services, culminating in adverse impacts on our businesses and operating results, etc.
To mitigate such risks, we use an information management system based on our Group Information Security Policy to facilitate appropriate information management, and we strive to raise awareness among employees through targeted education and training. In addition, guided by Group Information Security Promotion Regulations, we assess, evaluate and improve groupwide information security standards. If an information security breach does occur, an investigative committee is established and, through a clear accountability process, we endeavor to determine the root cause, execute countermeasures and prevent recurrence.
Regarding personal information handled by Group companies, TISI established a group-level information management system based on Japan’s Act on the Protection of Personal Information, Individual Numbers, and Rules for Handling Specific Personal Information. We conduct regular compliance audits under the Act on the Protection of Personal Information to ensure adherence to all necessary data security safeguards. In addition, we strive to maintain appropriate operations by strengthening client information management, a process contingent upon education and training programs that instill in employees a deep awareness of the importance of protecting personal information. We also emphasize security measures using a zero-trust security model to address the diversification of workplaces paralleling full-scale adoption of remote work. Also of note, members of the Group have obtained Information Security Management System (ISMS) certification and JIPDEC‘s Privacy Mark.
4. Legal systems, compliance
The Group is engaged in various businesses, and activities are conducted in compliance with respective laws and regulations in Japan and other countries. If a member of the Group were to contravene a law or regulation, or a new law or regulation were introduced, our businesses and operating results, etc. could be affected. An instance of discrimination or harassment that causes a reduction in productivity, an increase in costs, and/or a decline in employee engagement, could also affect our businesses and operating results, etc.
To mitigate these risks, TISI established a groupwide compliance structure aligned with its Basic Direction on Corporate Sustainability and Group Compliance Declaration. We are committed to fair business practices, ensuring comprehensive compliance and training for all employees, regardless of their employment status. In accordance with compliance regulations, we review significant compliance issues affecting the entire Group, formulate recurrence prevention measures, and track their implementation status to ensure compliance is deeply ingrained in the corporate consciousness. One such measure is the tightening of regulations on contracted work and temporary staffing, an important issue from a groupwide perspective because of the transactional nature of the IT service industry. We have a dedicated risk management system in place as well as an Operation Manual for Proper Contracted Work and Temporary Staffing to ensure the system functions as intended. In addition, to prevent illegal activities and detect and correct them at an early stage should they arise, we maintain a whistle-blowing system and a reporting and consultation desk, which serve to instill greater awareness of legal compliance throughout the Group. Furthermore, to create an environment free of discrimination and harassment, we conduct educational and awareness-building programs that foster positive interpersonal relationships and smooth communication. Should an incident occur, we deal with the situation fairly but firmly.
5. Intellectual property rights
In regard to intellectual property rights, such as technologies, licenses, business models and various trademarks, TISI always takes great care to ensure that no member of the Group infringes on the intellectual property rights of third parties in the course of business activities. Nevertheless, if such a situation were to occur, it might result in an injunction and a claim for damages. Should this happen, our businesses and operating results, etc. could be impacted. To preclude this scenario, TISI maintains and continually strengthens its intellectual property framework and offers educational programs and training to keep employee awareness high. Obviously, we see our own intellectual property as a vital business asset and take all necessary steps to protect this resource.
6. Climate change
In addressing climate change, companies are increasingly required to implement initiatives and demonstrate greater accountability on two fronts: mitigation (reducing greenhouse gas emissions) and adaptation (minimizing the adverse effects of climate change), and as a result, there are growing calls to accelerate the transition to renewable energy in business and corporate activities. Therefore, if fluctuations in renewable energy demand significantly impact energy costs across the Group, or if our transition to renewable energy is delayed, our businesses and operating results, etc. could be materially and adversely affected.
In response, TISI has endorsed the recommendations of the Task Force on Climate-related Financial Disclosures (TCFD) and is committed to a sustained process of assessment aligned with this framework, fulfilling accountability regarding climate change mitigation initiatives through ongoing public disclosures.