Risk Management
Internal Control System and Risk Management
Internal Control Framework
In order to enhance the Tokyo Electron Group’s corporate value and remain accountable for our actions to our stakeholders, we continuously strengthen the effectiveness of our internal control system. Based on the Basic Policy on Internal Control Systems established by the Board of Directors. We annually evaluate the effectiveness of internal control over financial reporting in accordance with Japan's Financial Instruments and Exchange Act.
Approach to Risk Management
Our Group has built a risk management system to respond effectively and promptly to various risks, such as geopolitical and market changes in the semiconductor industry, and to ensure sustainable growth. We believe that it is crucial not only to make sufficient considerations in anticipation of the future and to minimize the impact of potential risks that may arise during business operations, but also to view these risks as potential business opportunities and address them in a manner that earns the trust of society.
Risk Management System and Implementation
We established the Corporate Project & Risk Management Office (CPRO) in the Corporate Planning Division at the head office to promote more effective enterprise risk management* in the Group as a whole.
(*) Enterprise Risk Management (ERM): An integrated framework and continuous process for managing risks across the Group.
As part of the Group's Enterprise Risk Management (ERM) activities, we analyze risks affecting the Group operations and support the monitoring and promotion of risk management activities for identified key risks. To identify and assess company-wide key risks, we apply five-level evaluation criteria for both impact and likelihood. Assessment results are visualized using a risk map to determine risk priorities and guide response actions.
Our Group conducts risk reviews on a company-wide basis. Specifically, we implement the following operating cycle to identify, assess, manage, and monitor risks across the organization.
- Risk owners assess key risks, which are subsequently reported to and discussed by the Risk Management Committee, which includes each risk owner.
- Risk assessments are performed in domestic and overseas group companies, and the results of those assessments are reported to group company management.
- Based on the overall risk assessment, high-priority risk areas are identified and reported by CPRO to top management. In addition, as necessary, the status of initiatives addressing key risk issues and related improvement measures are reported and discussed at quarterly review meetings and other management meetings attended by the CEO, Corporate Officers, and Division Officers.
The Group’s risk management activities are regularly reported to the Audit & Supervisory Board members and the Board of Directors, which oversees various initiatives implemented by each risk owner. In addition to oversight by the Board of Directors, the Group periodically undergoes audits by RBA-certified third-party organizations through the Validated Assessment Program (VAP) and receives external evaluation of its management and execution systems, including risk management.
To enhance employees’ awareness of risk management and strengthen their fundamental knowledge, the Group regularly provides risk management training programs, including web-based training for employees and specialized training for managers. Additionally, we are also continuing to revise and improve the operation of our BCPs for all Group companies, and we regularly conduct BCP drills and disaster drills to enhance our actual implementation capabilities so that we can maintain uninterrupted business operations in the event of an emergency.
Furthermore, we are actively promoting DX in our risk management activities and have introduced a dashboard that utilizes digital technology. This allows us to visualize the assessment of risks and response measures across the entire Group as well as to conduct global, cross-sectional information sharing between each owner and each responsible department.
Going forward, each owner will take the lead in implementing activities across the entire Group to further strengthen risk management for the major risk items with the aim of continuing to practice autonomous and highly effective risk management.
Key Risks and Initiatives
The Company continuously monitors the status of its risk management activities and identifies not only current and potential future risks that may affect its business, but also emerging risks from a medium- to long-term perspective. In response, the Company evaluates and implements appropriate mitigation measures.
The 16 key risks currently identified, together with the corresponding risk management initiatives, are summarized below.
16 Key Risk Categories
| Categories | Key Risk Scenarios | Key Initiatives |
|---|---|---|
|
1.Market Fluctuations
|
|
|
|
2.Research and Development |
|
|
|
3.Geopolitics
|
|
|
|
4.Procurement, Production, and Supply |
|
|
|
5.Safety |
|
|
|
6.Quality |
|
|
|
7.Environmental Issues |
|
|
|
8.Legal |
|
|
|
9.Intellectual Property Rights |
|
|
|
10.Information Security |
|
|
|
11.Human Resources |
|
|
|
12.Pandemics, Natural Disasters |
|
|
|
13.Finance |
|
|
|
14.M&A |
|
|
|
15.IT&Operations |
|
|
|
16.Business Locations |
|
|
Business Continuity Plans (BCPs)
The Tokyo Electron Group began formulating its business continuity plans (BCPs) in 2003. After the Great East Japan Earthquake, the Group rebuilt these plans to include more practical provisions for restoring operations at major business sites after a crisis. Specifically, the revised plan included disaster preparation measures such as stockpiling emergency supplies (including food and drinking water), the reinforcement of essential infrastructure, restructuring of the safety confirmation system, preparation of manuals, and the implementation of drills and employee training. To meet its responsibilities as an equipment manufacturer, the Group is constantly improving its BCPs to facilitate early disaster recovery and secure alternative production capabilities.
Drawing on our experience of previous earthquakes, reinforcement work is being conducted for our existing buildings in Japan to improve their seismic resistance, while techniques such as base isolation and seismic damping are being adopted for new buildings.
Internal Audit
To enhance our internal auditing functions, we have established the Global Audit Center, which is an organization under the direct purview of the Representative Director, President & CEO, responsible for conducting operational audits and evaluating our internal control over financial reporting prepared in accordance with the Financial Instruments and Exchange Act.
Based on our Internal Audit Policy, the Global Audit Center formulates the annual audit implementation plan, conducts audits of the Group’s business locations in Japan and overseas, evaluates the effectiveness of the Group’s internal audit system (i.e., the framework for ensuring that our business policies and various types of information are shared responsibly within the Group, and that risk evaluation and financial reporting are conducted properly and in a reliable manner) and the business operations under its control, and instructs audited organization to improve their practices if deemed necessary. The audit results and the status or outcome of evaluation are reported to our management team and also to Audit & Supervisory Board Members of the company and our Japanese subsidiaries every two months. Further, a process is in place to keep our board of directors and Audit & Supervisory Board informed.
In addition, the Global Audit Center and our independent auditors intend to exchange information and views with each other on a regular or ad hoc basis, so that our audits remain coordinated, efficient, and effective.