TOKYO ELECTRON LIMITED

Risk Management

Internal Control System and Risk Management

Internal Control Framework

In order to enhance the Tokyo Electron Group’s corporate value and remain accountable for our actions to our stakeholders, we continuously strengthen the effectiveness of our internal control system. Based on the Basic Policy on Internal Control Systems established by the Board of Directors. We annually evaluate the effectiveness of internal control over financial reporting in accordance with Japan's Financial Instruments and Exchange Act.

Approach to Risk Management

Our Group has built a risk management system to respond effectively and promptly to various risks, such as geopolitical and market changes in the semiconductor industry, and to ensure sustainable growth. We believe that it is crucial not only to make sufficient considerations in anticipation of the future and to minimize the impact of potential risks that may arise during business operations, but also to view these risks as potential business opportunities and address them in a manner that earns the trust of society.

Risk Management System and Implementation

We established the Corporate Project & Risk Management Office (CPRO) in the Corporate Planning Division at the head office to promote more effective enterprise risk management* in the Group as a whole.
(*) Enterprise Risk Management (ERM): An integrated framework and continuous process for managing risks across the Group.

As part of the Group's Enterprise Risk Management (ERM) activities, we analyze risks affecting the Group operations and support the monitoring and promotion of risk management activities for identified key risks. To identify and assess company-wide key risks, we apply five-level evaluation criteria for both impact and likelihood. Assessment results are visualized using a risk map to determine risk priorities and guide response actions.

Figure1: Risk Assessment Criteria

Our Group conducts risk reviews on a company-wide basis. Specifically, we implement the following operating cycle to identify, assess, manage, and monitor risks across the organization.

Figure 2: Enterprise Risk Management (ERM) Operating Cycle

  1. Risk owners assess key risks, which are subsequently reported to and discussed by the Risk Management Committee, which includes each risk owner.
  2. Risk assessments are performed in domestic and overseas group companies, and the results of those assessments are reported to group company management.
  3. Based on the overall risk assessment, high-priority risk areas are identified and reported by CPRO to top management. In addition, as necessary, the status of initiatives addressing key risk issues and related improvement measures are reported and discussed at quarterly review meetings and other management meetings attended by the CEO, Corporate Officers, and Division Officers.

The Group’s risk management activities are regularly reported to the Audit & Supervisory Board members and the Board of Directors, which oversees various initiatives implemented by each risk owner. In addition to oversight by the Board of Directors, the Group periodically undergoes audits by RBA-certified third-party organizations through the Validated Assessment Program (VAP) and receives external evaluation of its management and execution systems, including risk management.

To enhance employees’ awareness of risk management and strengthen their fundamental knowledge, the Group regularly provides risk management training programs, including web-based training for employees and specialized training for managers. Additionally, we are also continuing to revise and improve the operation of our BCPs for all Group companies, and we regularly conduct BCP drills and disaster drills to enhance our actual implementation capabilities so that we can maintain uninterrupted business operations in the event of an emergency.

Furthermore, we are actively promoting DX in our risk management activities and have introduced a dashboard that utilizes digital technology. This allows us to visualize the assessment of risks and response measures across the entire Group as well as to conduct global, cross-sectional information sharing between each owner and each responsible department.

Going forward, each owner will take the lead in implementing activities across the entire Group to further strengthen risk management for the major risk items with the aim of continuing to practice autonomous and highly effective risk management.

Key Risks and Initiatives

The Company continuously monitors the status of its risk management activities and identifies not only current and potential future risks that may affect its business, but also emerging risks from a medium- to long-term perspective. In response, the Company evaluates and implements appropriate mitigation measures.

The 16 key risks currently identified, together with the corresponding risk management initiatives, are summarized below.

16 Key Risk Categories
Categories Key Risk Scenarios Key Initiatives

1.Market Fluctuations

 

  • A rapid contraction of the semiconductor market could lead to overproduction or an increase in excess inventory
  • Lost sales opportunities due to the inability to handle sharp increases in demand
  • Periodically review market conditions and orders received at the Board of Directors and other important meetings, and appropriately adjust capital investments, personnel/inventory planning and other aspects of business
  • Establish a dedicated division to work closely with a wide range of customers around the world and to quickly identify their needs and capital spending trends. Through these efforts and others, we strive to strengthen our sales framework and further improve our customer responsiveness

2.Research and Development

  • Decline in the competitiveness of products due to delays in the launch of new products or the mismatch of such products with customer needs
  • Provide highly competitive next-generation products ahead of competitors by collaborating with research institutions and sharing a technology roadmap spanning multiple generations with leading-edge customers

3.Geopolitics

 

  • Geopolitical tensions and regional conflicts, and the national security or industrial policies of countries and regions, can lead to supply chain disruptions or deterioration of the macroeconomic environment, restricting the Company’s ability to operate business
  • Carefully monitor the international situation as well as the diplomatic and security measures and industrial policy trends in each country and region
  • Analyze the implications on our business of regulations concerning product exports and imports and technological development and changes in the macroeconomic environment while actively engaging in dialogues with the policy-making authorities, industry groups and experts in various fields, and consider countermeasures in advance

4.Procurement, Production, and Supply

  • Increased demand that exceeds suppliers’ capacities, delays in component procurement stemming from changes in laws and regulations and a shrinking working population, strains on domestic or international logistics and interruptions in production due to natural disasters can lead to delays in the supply of products to customers
  • To ensure business continuity and a stable supply of products, the Company has established business continuity plans (BCPs) and implemented various measures, including the development of alternative production capabilities, seismic reinforcement of production facilities, production leveling, the establishment of backup arrangements for critical information systems, multisourcing of key components, and the maintenance of appropriate inventory levels
  • In addition, the Company shares semiconductor demand forecasts with suppliers and works closely with suppliers to strengthen supply chain resilience and ensure the stable supply of products

5.Safety

  • Safety problems with the Company’s products or liability for damages and decline in public trust due to serious accidents resulting in workplace injuries

     

  • Based on the “Safety First” approach, we implement thorough safety design at the product development phase with risk reduction in mind
  • By conducting risk assessments such as frontline workers' hazard prediction meetings, we implement company-wide efforts such as identifying potential risks and implementing preventative or mitigation measures, promoting safety through in-house competency qualification and safety training programs that are designed according to job requirements for employees and subcontractor employees, and developing an incident reporting system

6.Quality

  • Liability for damages and increased costs for countermeasures due to product defects and decline in the credibility of the Group’s brand
  • Strengthen the quality assurance framework based on ISO 9001
  • Promote continuous improvement activities
  • Mitigate quality risks through design reviews and simulation-based validation
  • Enhance procurement quality through root cause analysis, preventive and corrective actions, and supplier audits

7.Environmental Issues

  • The inability to respond appropriately to each country’s climate change policies, environmental laws and regulations can lead to additional related costs, reduced product competitiveness and diminished public confidence, as well as fines and liability for damages
  • To achieve industry leading environmental goals that include the net zero target, implement measures such as reducing greenhouse emissions from the use of our products, increase the rate of renewable energy usage at plants and offices, reduce overall power consumption, review packaging materials, and promote a modal shift
  • Provide technologies, etc., that contribute to higher performance and energy efficiency of semiconductor devices through implementation of our E-COMPASS initiative

8.Legal

  • Violations of the laws and regulations of the countries and regions where the Company operates could lead to interruptions or restrictions on business activities, diminished public confidence and fines and liability for damages
  • Monitor compliance activities at major domestic and overseas locations under the leadership of the Chief Compliance Officer
  • Promote product compliance activities by comprehensively managing applicable standards, specifications, and regulatory requirements for the Company's products
  • Foster a speak-up culture and enable the early detection and remediation of misconduct through the operation of an internal whistleblowing system

9.Intellectual Property Rights

  • Decline in product competitiveness from the inability to obtain exclusive rights to proprietary technology as well as restrictions on the production and sale of products and liability for damages due to infringements of the intellectual property rights of third parties
  • Advance the intellectual property strategy, business strategy and R&D strategy in an integrated manner to build an appropriate intellectual property portfolio
  • Reduce the risk of infringement of other companies' patents by continuously monitoring other companies' patents and establishing a system to take appropriate measures in cooperation with the business and R&D departments

10.Information Security

  • Data breaches from cyberattacks or internal fraud against the Company or suppliers can lead to loss of technological superiority, interruptions of operations, diminished public confidence, and liability for damages
  • Implement cybersecurity solutions and strengthen the protection of information assets through security monitoring, insider threat measures, global security policies, and employee awareness programs
  • Strengthen information security governance across the Group through the Information Security Committee, internal audits, and external assessments
  • Maintain Group-wide monitoring and incident response capabilities through CSIRT and PSIRT for information security and product security risks and incidents

11.Human Resources

  • The inability to recruit and retain necessary human resources on an ongoing basis or the inability to create an environment where people with diverse values and expertise can play an active role could lead to diminished product development capability or customer support quality
  • Make continuous improvements to work environments and promote diverse work styles as well as health and productivity management (e.g., sharing our visions by management, establishing training plans for human resources who will lead the future, visualizing career paths for employees and offering attractive remuneration and benefits)
  • Fostering semiconductor talent through collaborative efforts between industry, government, and academia as well as strengthening our partnerships with academic institutions globally

12.Pandemics, Natural Disasters

  • Impact on business operations caused by travel restrictions between countries due to large scale infectious diseases, natural disasters or terrorism around the world or in particular regions that threaten the safety of executives, employees or their families
  • Based on the Business Continuity Plan (BCP), enhance disaster preparedness through initiatives such as employee and family safety confirmation systems and disaster response drills.

13.Finance

  • Impact on business performance due to sharp exchange rate fluctuations stemming from international situations or interest rate fluctuations. Also, additional taxes due to differences in interpretation from the authorities of each country concerning tax laws in each country or region
  • The Finance Division have established a global risk management system in collaboration with the Corporate Strategy Division and finance leaders at each Group company
  • As a rule, our products are transacted in yen, but for a portion of foreign currency-denominated sales, we implement risk hedging through foreign exchange forward contracts

14.MA

  • Inability to realize the intended results due to insufficient due diligence of acquisition target companies and their business or PMI (post-merger integration). Additionally, the impact on competitiveness stemming from competitors purchasing potential targets first
  • Make investment decisions that consider both synergy potential and associated risks through regular policy reviews involving the CEO and other management members, led by the Corporate Strategy Division.
  • Develop and execute post-investment and post-acquisition plans that incorporate both strategic objectives and risk considerations.

15.ITOperations

  • Impact of large-scale failures in enterprise systems on business and the lack of capability in growth areas and new regulations due to delayed digitalization efforts and operational process innovations
  • Formulate a Business Continuity Plan (BCP) for IT systems and utilize a Disaster Recovery (DR) data center to conduct operational training using backup systems
  • Launch a business reform DX promotion project to review company-wide business processes and systems from various perspectives, including productivity improvement, regulatory compliance, and strengthening, to manage risk

16.Business Locations

  • Inefficiencies in the development of new locations and in the strengthening and control of existing locations due to delays in the deliberations and plans for global location strategies despite increases in new business around the world
  • Formulate and execute location strategies aligned with our business strategies
  • Group companies overseeing each country and region promote smooth operations and risk management tailored to the characteristics of each business and each country or region

Business Continuity Plans (BCPs)

The Tokyo Electron Group began formulating its business continuity plans (BCPs) in 2003. After the Great East Japan Earthquake, the Group rebuilt these plans to include more practical provisions for restoring operations at major business sites after a crisis. Specifically, the revised plan included disaster preparation measures such as stockpiling emergency supplies (including food and drinking water), the reinforcement of essential infrastructure, restructuring of the safety confirmation system, preparation of manuals, and the implementation of drills and employee training. To meet its responsibilities as an equipment manufacturer, the Group is constantly improving its BCPs to facilitate early disaster recovery and secure alternative production capabilities.

Drawing on our experience of previous earthquakes, reinforcement work is being conducted for our existing buildings in Japan to improve their seismic resistance, while techniques such as base isolation and seismic damping are being adopted for new buildings.

Internal Audit

To enhance our internal auditing functions, we have established the Global Audit Center, which is an organization under the direct purview of the Representative Director, President & CEO, responsible for conducting operational audits and evaluating our internal control over financial reporting prepared in accordance with the Financial Instruments and Exchange Act.

Based on our Internal Audit Policy, the Global Audit Center formulates the annual audit implementation plan, conducts audits of the Group’s business locations in Japan and overseas, evaluates the effectiveness of the Group’s internal audit system (i.e., the framework for ensuring that our business policies and various types of information are shared responsibly within the Group, and that risk evaluation and financial reporting are conducted properly and in a reliable manner) and the business operations under its control, and instructs audited organization to improve their practices if deemed necessary. The audit results and the status or outcome of evaluation are reported to our management team and also to Audit & Supervisory Board Members of the company and our Japanese subsidiaries every two months. Further, a process is in place to keep our board of directors and Audit & Supervisory Board informed.

In addition, the Global Audit Center and our independent auditors intend to exchange information and views with each other on a regular or ad hoc basis, so that our audits remain coordinated, efficient, and effective.