Risk Management

Governance

Our Basic Principle

We are strengthening risk management to achieve a "resilient business foundation" which we have identified as part of our materiality (priority issues). Based on risk prevention, forecasting, and control, we are implementing risk management through five committees (Quality, Trade Management, BCM, Information Security, and Technology Asset Management) that establish and implement regulations. In addition, we are enhancing resilience by supporting business divisions in their risk activities based on specialized knowledge and expertise, preparing and training on BCPs (business continuity plans) during normal times, and establishing a governance system for emergency situations.

Strengthening of the Risk Management System

YKK AP’s risk management promotion structure is based on a three-line model. The five basic units (Sales, Development and technology, Manufacturing and supply, Administration, and Overseas) serve as the first line, taking the lead in risk management activities. Risk management departments and committees, which serve as the second line, support the first line with their specialized knowledge and expertise. The Internal Auditing Division, which serves as the third line, audits the effectiveness of the risk management activities of the first and second lines. Furthermore, by allowing self-checks of risk management activities based on the YKK Group’s compliance standards, the YKK Global Criteria of Compliance (YGCC), we are clarifying the roles and responsibilities of each person and division in charge of conducting these activities, thereby enhancing their effectiveness.

Identification and Countermeasures for Key Risks

In FY2024, we reviewed our process for identifying key risks and, in addition to consultations with risk management departments, conducted risk surveys of business divisions and interviews with senior management to identify and analyze risks. In evaluating risks, we determine the level of risk based on the likelihood of occurrence and impact, as well as reputational risks and internal and external factors. This is then used as a basis for discussion and decision-making by the Board of Directors to identify key risks.

For FY2025, we have identified 27 categories of key risks, including system failures, cybersecurity, major natural disasters, product defects, and recalls. We will prioritize the allocation of business resources to these areas and implement measures to develop systems and countermeasures.

Response to Main Key Risks

* Missing parts of the table can be viewed by sliding the cursor to the side.
Type of Risk Major Risk Countermeasures for FY2025
System Failures, Cybersecurity
  • IT-BCP development, implementation, and training
  • Implementation of backups, strengthening of vulnerability response
  • Implementation of employee training on information security
  • Compliance with conformity assessment systems (establishment of company-wide promotion system)
Major Natural Disasters
  • Tabulation of damage estimates in the event of a major earthquake and incorporation into evacuation plans at each location
  • Implementation of BCP drills and BCP training at each location
  • Implementation of BCP monitoring
Product Defect-Related Accidents and Recalls
  • Thorough quality compliance and defect reporting
  • Process audit and conformity verification for minister-certified products
  • Ongoing communication and enhancement of safety awareness information
Fires/Explosions
  • Implementation of global fire safety management standards and improvements based on self-checks
  • Consideration and implementation of dust control measures in the casting process
  • Emergency inspection of preventive measures against small fires caused by aging buildings and equipment
Violation of Laws and Regulations in the Course of Business
  • Thorough implementation of various regulations and guidelines
  • Implementation of audits as important audit items
  • Expansion of field-specific legal education and training
Health and Safety Risks (Occupational Accidents at Construction Sites etc.)
  • Promotion of safety measures and improvement of working environments (detection of unsafe behavior using AI cameras, etc.)
  • Enhanced training for installation contractors (using CG videos, etc.)
Governance Risks
  • Establishment of administration systems for affiliated companies in Japan and overseas, enhanced monitoring
  • Regular compliance awareness surveys and compliance training, activities to reinforce the Management Principle based on survey results
Compliance Risks
  • Implementation of harassment prevention education
  • Operation of internal whistleblowing desks and regular monitoring
  • Customer harassment countermeasures (preparation of manuals, operation of external consultation desk and response support)

BCM (Business Continuity Management) Initiatives

We are working to acquire the appropriate business continuity capabilities necessary to respond to major emergencies. To this end, we are enhancing our organizational strength through repeated training and preparation to enable rapid initial response and implementation of BCPs based on an all-hazards approach, covering large-scale natural disasters, supply chain disruptions, cyber incidents, and the spread of infectious diseases.

The first basic policy is "Prioritize human life, ensure safety, and prevent secondary disasters." In FY2024, based on the scenario of a major earthquake directly under Tokyo or a Nankai Trough earthquake, we conducted joint training exercises involving manufacturing and sales operations across different areas, briefings for sales managers, and training exercises with Kurobe, which will serve as a backup base for the local disaster response headquarters in the event of a disaster in the Tokyo metropolitan area. Measures will be considered for each location to address issues identified during the training, and these will be reflected in BCP revisions and future training. We are also conducting initiatives that involve external contractors such as truck drivers and cafeteria staff in evacuation drills.

Resilience Certification

To recognize our series of initiatives on risk management, YKK AP has been certified as a business operator that meets the "Resilience Certification" requirements for Business Continuity and Social Contributions from the Association For Resilience Japan.

About the Resilience Certification

This program certifies corporations and organizations that endorse the Cabinet Secretariat's National Resilience concept, and are actively engaged in business continuity initiatives, as organizations that are helping build national resilience. The Association For Resilience Japan reviews and certifies organizations according to requirements set by the Cabinet Secretariat's National Resilience Promotion Office. Its goal is to build a more resilient society as a whole by promoting and expanding proactive initiatives by corporations and organizations for business continuity (self-reliance) and social contribution (public assistance).

Association For Resilience Japan
OUR STORIES

Latest stories