Risk management
Guidelines & structure
The Fujitsu Group aims to achieve business continuity, enhanced corporate value, and the sustainable development of corporate activities. Uncertainties that might affect the achievement of these objectives are considered to be risks. To address these risks, the Fujitsu Group established a Risk Management & Compliance Committee based on the Policy on the Internal Control System determined by the Board of Directors.
The Committee reports directly to the Board of Directors (including the Independent Directors and Auditors Council) and oversees risk management and compliance for the entire Fujitsu Group.
The Risk Management & Compliance Committee is chaired by the CEO and is composed of Board Members. Its primary function is to continually assess and verify risks that could potentially lead to losses for the Fujitsu Group. The Committee proactively implements measures to control risks identified during the course of business operations (potential risk management). Additionally, the Committee regularly analyzes realized risks to minimize losses, reporting them to the Board of Directors and working to prevent their recurrence (materialized risk management).
The Risk Management & Compliance Committee has established Regional Risk Management & Compliance Committees in each region that forms part of the global, region-based business execution structure. These regional committees operate as subcommittees. The Risk Management & Compliance Committee has deployed Risk Management & Compliance Officers to Business Units (First line), as well as to Group companies, both in Japan and overseas. Together, these entities collaborate to build a structure that promotes risk management and compliance throughout the Group.
To further strengthen the Group’s risk management capabilities, the company has established the Corporate Risk Management Office (Second line), a department which reports directly to the CEO and is independent of the business divisions. The Committee’s secretariat function is provided by the Corporate Risk Management Office and is supervised by the Chief Risk Management Officer (CRMO). The Secretariat monitors overall risk information, providing rapid and appropriate responses, and ensuring thorough risk management under the CEO’s direction. As well it convenes a monthly meeting of the Risk Management & Compliance Committee to ensure the swift and effective implementation of corporate policies.
To check that the risk management and compliance system is functioning properly, the company conducts annual audits by corporate auditors and internal audits by audit departments (Third line).
Processes
Potential Risk Management Process
-
Identification and review of significant risks of the Fujitsu Group
The Risk Management & Compliance Committee Secretariat (Corporate Risk Management Office, Second line) identifies and reviews the 16 significant risks considered important to the Fujitsu Group, taking into account environmental changes affecting the Group. Risk scenarios are defined for each significant risk, and they are classified into pure risk and management risk.
-
Assignment of risk management departments (Second line)
A risk management department is assigned to each significant risk, and is responsible for maintaining control over that specific risk.
-
Evaluation of risks to the Fujitsu Group
Each month, the risk management departments, Business Units, and Group companies evaluate the impact of each significant risk, the likelihood of its occurrence, and the status of mitigation measures.
-
Ranking and mapping of significant risks
Based on the evaluation results of the Group, we rank significant risks and create risk maps to visualize their significance. By plotting to four quadrants on a risk map, significant risks are evaluated across four levels (avoid, transfer, reduce, hold). From these evaluation results and status of materialized risks, their significance is evaluated and critical risks for that financial year are identified.
-
Reports to the Risk Management & Compliance Committee and Board of Directors
Analyses are conducted based on the evaluation findings, and mitigation policies are discussed and determined to address critical risks and significant risks to the Group.
-
Issues corrective guidance and improvement instructions to Business Units and Group companies
Based on the evaluation results for the Group, feedback is provided to Business Units and Group companies on an ongoing basis, advising them on improvements.
-
Risk monitoring within Business Units and Group companies
Monthly risk monitoring is conducted within Business Units and Group companies to assess the status of mitigation measures and reduce risk exposure.
Addressing materialized risks
- Risk management regulations mandate rules (such as prompt escalation to the Risk Management & Compliance Committee) and require employees to be informed accordingly.
- Establish escalation rules for Business Units and Group companies and apply those rules promptly when risks materialize, based on risk management standards and the rules for escalating risks to the Risk Management & Compliance Committee.
-
Analyze risks and deploy mitigation measures, while reporting to the Board of Directors as necessary, to prevent recurrence.
By cycling through this risk management process and having the risk management departments, Business Units and Group companies monitor it each month, we aim to reduce risks across the Fujitsu Group and to minimize the impact when risks materialize.
Critical risks
Considering the findings from evaluations conducted in the Potential Risk Management Process and the status of materialized risks, we have chosen to focus on critical risks based on their impact on achieving the Fujitsu Group's business strategies and goals. Consequently, we have identified the following two significant risks as critical risks for FY2026:
- Security risks
- Deficiencies or flaws in products and services
Significant risks to the Fujitsu Group (*1)
- 1. Security risks (Pure risk)
- 2. Deficiencies or flaws in products and services (Pure risk)
- 3. Risks of natural disasters and unforeseen incidents (Pure risk)
- 4. Human rights risks (Pure risk)
- 5. Compliance risks (Pure risk)
- 6. Financial risks (Management risk)
- 7. Risks related to the environment and climate change (Pure risk)
- 8. Risks related to Fujitsu Group facilities and systems (Pure risk)
- 9. Risks related to competitors and industries (Management risk)
- 10. Risks related to economic and financial market trends (Management risk)
- 11. Intellectual property risks (Management risk)
- 12. Customer risks (Management risk)
- 13. Risks related to suppliers, alliances, etc. (Management risk)
- 14. Risks related to investment decisions and business restructuring (Management risk)
- 15. Risks related to public regulations, public policies and tax matters (Management risk)
- 16. Risks related to human resources (Management risk)
- (*1) : These are just some examples of the risks associated with doing business. More detailed risk-related information can be found in our securities and other reports.
- https://global.fujitsu/ja-jp/ir/library/secreport
- Refer to the web page below for detailed risk information in accordance with our Task Force on Climate-related Financial Disclosures (TCFD) declaration.
Risk management education, etc.
To enforce risk management across the entire Fujitsu Group, we conduct education and training at every level.
These programs are targeted at newly appointed executives and managers, as well as others, to educate them on our basic approach to risk management and our rules for promptly escalating issues to the Risk Management & Compliance Committee. The programs present specific instances relating to products, services, and information security, with the aim of continually improving participants’ awareness of risk management and enhancing their capacity to respond to risks.
Furthermore, by incorporating risk management into employee evaluation indicators, the risk management departments aim to not only link evaluations to financial incentives, but also to enhance the organization’s risk responsiveness by improving its risk management skills.
Refer to the “FY2025 Performance” section for information on education outcomes for FY2025.
Group-wide disaster management
The basic policy of Fujitsu and its group companies inside and outside Japan is to ensure the safety of staff and facilities when disasters occur, to minimize harm, and to prevent secondary disasters. We also aim to ensure that business operations resume quickly, and that we can assist in disaster recovery for our customers and suppliers. To this end, we are building robust collaborative structures in our internal organizations and strengthening our business continuity capabilities.
In addition to supporting our customers through the management structure in each business unit and group company, the Fujitsu Group is building ‘area-based disaster management systems’ in each region for working in cooperation with and responding to customers.
To verify the efficacy of our disaster management systems and enhance our response capabilities, we conduct drills tailored to every level, from the entire company through to task forces, workplaces, and employees. We also implement voluntary inspections and verification activities to prevent accidents and minimize the level of harm in each of our facilities. These efforts enable us to accurately identify existing issues and review and implement measures to address those issues, thereby allowing us to work toward continually improving our capacity to prepare for disasters and sustain our business operations.
For more information on our Group-wide disaster management, joint disaster response drills and verification activities, please refer to the PDF listed below. For activity outcomes for FY2025 refer to the “FY2025 Performance” section.
Business continuity management
Recent years have seen a myriad of risks that threaten continued economic and social activity. These include events such as earthquakes, floods and other large-scale natural disasters, disruptive incidents and accidents, and pandemics involving infectious diseases. To ensure that Fujitsu and its group companies both in and outside Japan can continue to provide a stable supply of products and services offering the high levels of performance and quality that customers require, even when such unforeseen circumstances occur, we have formulated a Business Continuity Plan (BCP). We are also promoting Business Continuity Management (BCM) as a way of continually reviewing and improving our BCP.
In its response to disasters and infectious diseases, the Fujitsu Group placed the highest priority on maintaining the health and safety of its customers, suppliers and employees, and their families. It also promoted initiatives to sustain the supply of products and services to customers and to help resolve the many societal issues that arise due to disasters and infectious diseases.
For more information on our BCM activities and BCM in our supply chain, refer to the PDF listed below. For activity outcomes for FY2025, refer to the “FY2025 Performance” section.
FY2025 performance
Risk management education
Fujitsu Group new executive training: 44 people
Uses specific examples to illustrate management decision perspectives and key points that new executives need to take note of, including internal regulatory systems, compliance and issues relating to human rights.
Training for Board of directors: 9 (including 6 non-executive directors)
Providing e-Learning in various fields, including risk management, for non-executive and executive directors.
Fujitsu Group new manager training: 648 people
An e-Learning course that covers areas such as the basic approach to risk management and the role of managers regarding risk management.
Risk management education program: Fujitsu Group 110,000 people
Implemented e-Learning on risk management in general (information security, compliance, etc.)
Disaster Management Forum: 529 people
These forums are targeted at Fujitsu Group staff responsible for disaster management and business continuity, and all employees in Japan. They offer an opportunity for participants to share knowledge with the aim of improving our on-site responses to large-scale disasters.
Serious incident response training
Serious incident response exercise (December 2025, Organizational Training: 531 people; January 2026, Data Center Outage: 16 people): 547 people in total
To strengthen the response to a serious incident (including initial measures, cause investigation, cooperation between the site or region and head office, customer response, response to personal information leakage, and media response), we verified the incident response process through training run on two levels: to the site units, and to management in the form of an incident response meeting.
Incident response capabilities and inter-organizational cooperation globally will be enhanced by identifying issues through training and making continuous improvements.
Disaster management & BCM training
Fujitsu Group joint disaster response drills: FY2025 Drill - Eruption of Mt Fuji (widespread volcanic ash falls in the Greater Tokyo Metropolitan area)
These annual drills are used to ensure and to verify that Fujitsu and its group companies in Japan are fully versed in the essentials of dealing collaboratively with major disasters. (Proposed scenarios include the “Tokyo Metropolitan Area Earthquake”, “Nankai Trough Megaquake” and “Eruption of Mt Fuji”.)
BCP Awareness Week
An awareness training event centered on a hypothetical scenario involving the loss of resources in a crisis situation was implemented for all our employees around the globe. The objective was to raise the awareness of every employee involved in business continuity, and measure the business continuity capabilities of the organization as a whole. In addition, a simulation of operations and inter-organizational coordination as outlined in each organization’s BCP was used to identify issues and ensure continued improvement in the Fujitsu Group BCP.