Risk management

Guidelines & structure

The Fujitsu Group aims to achieve business continuity, enhanced corporate value, and the sustainable development of corporate activities. Uncertainties that might affect the achievement of these objectives are considered to be risks. To address these risks, the Fujitsu Group established a Risk Management & Compliance Committee based on the Policy on the Internal Control System determined by the Board of Directors.
The Committee reports directly to the Board of Directors (including the Independent Directors and Auditors Council) and oversees risk management and compliance for the entire Fujitsu Group.
The Risk Management & Compliance Committee is chaired by the CEO and is composed of Board Members. Its primary function is to continually assess and verify risks that could potentially lead to losses for the Fujitsu Group. The Committee proactively implements measures to control risks identified during the course of business operations (potential risk management). Additionally, the Committee regularly analyzes realized risks to minimize losses, reporting them to the Board of Directors and working to prevent their recurrence (materialized risk management).
The Risk Management & Compliance Committee has established Regional Risk Management & Compliance Committees in each region that forms part of the global, region-based business execution structure. These regional committees operate as subcommittees. The Risk Management & Compliance Committee has deployed Risk Management & Compliance Officers to Business Units (First line), as well as to Group companies, both in Japan and overseas. Together, these entities collaborate to build a structure that promotes risk management and compliance throughout the Group.
To further strengthen the Group’s risk management capabilities, the company has established the Corporate Risk Management Office (Second line), a department which reports directly to the CEO and is independent of the business divisions. The Committee’s secretariat function is provided by the Corporate Risk Management Office and is supervised by the Chief Risk Management Officer (CRMO). The Secretariat monitors overall risk information, providing rapid and appropriate responses, and ensuring thorough risk management under the CEO’s direction. As well it convenes a monthly meeting of the Risk Management & Compliance Committee to ensure the swift and effective implementation of corporate policies.
To check that the risk management and compliance system is functioning properly, the company conducts annual audits by corporate auditors and internal audits by audit departments (Third line).

Positioning of the Risk Management & Compliance Committee in the Internal Control System
Positioning of the Risk Management & Compliance Committee in the Internal Control System

Processes

Potential Risk Management Process

  • Identification and review of significant risks of the Fujitsu Group

    The Risk Management & Compliance Committee Secretariat (Corporate Risk Management Office, Second line) identifies and reviews the 16 significant risks considered important to the Fujitsu Group, taking into account environmental changes affecting the Group. Risk scenarios are defined for each significant risk, and they are classified into pure risk and management risk.

  • Assignment of risk management departments (Second line)

    A risk management department is assigned to each significant risk, and is responsible for maintaining control over that specific risk.

  • Evaluation of risks to the Fujitsu Group

    Each month, the risk management departments, Business Units, and Group companies evaluate the impact of each significant risk, the likelihood of its occurrence, and the status of mitigation measures.

  • Ranking and mapping of significant risks

    Based on the evaluation results of the Group, we rank significant risks and create risk maps to visualize their significance. By plotting to four quadrants on a risk map, significant risks are evaluated across four levels (avoid, transfer, reduce, hold). From these evaluation results and status of materialized risks, their significance is evaluated and critical risks for that financial year are identified.

  • Reports to the Risk Management & Compliance Committee and Board of Directors

    Analyses are conducted based on the evaluation findings, and mitigation policies are discussed and determined to address critical risks and significant risks to the Group.

  • Issues corrective guidance and improvement instructions to Business Units and Group companies

    Based on the evaluation results for the Group, feedback is provided to Business Units and Group companies on an ongoing basis, advising them on improvements.

  • Risk monitoring within Business Units and Group companies

    Monthly risk monitoring is conducted within Business Units and Group companies to assess the status of mitigation measures and reduce risk exposure.

Addressing materialized risks

  • Risk management regulations mandate rules (such as prompt escalation to the Risk Management & Compliance Committee) and require employees to be informed accordingly.
  • Establish escalation rules for Business Units and Group companies and apply those rules promptly when risks materialize, based on risk management standards and the rules for escalating risks to the Risk Management & Compliance Committee.
  • Analyze risks and deploy mitigation measures, while reporting to the Board of Directors as necessary, to prevent recurrence.

By cycling through this risk management process and having the risk management departments, Business Units and Group companies monitor it each month, we aim to reduce risks across the Fujitsu Group and to minimize the impact when risks materialize.

Critical risks

Considering the findings from evaluations conducted in the Potential Risk Management Process and the status of materialized risks, we have chosen to focus on critical risks based on their impact on achieving the Fujitsu Group's business strategies and goals. Consequently, we have identified the following two significant risks as critical risks for FY2026:

  • Security risks
  • Deficiencies or flaws in products and services

Loading component...

Loading component...

Significant risks to the Fujitsu Group (*1)

Loading component...

Loading component...

  • (*1) : These are just some examples of the risks associated with doing business. More detailed risk-related information can be found in our securities and other reports.

Risk management education, etc.

Loading component...

Group-wide disaster management

Loading component...

Business continuity management

Loading component...

FY2025 performance

Risk management education

Loading component...

Serious incident response training

Loading component...

Disaster management & BCM training

Loading component...