Risk Management

Basic Approach

Basic Approach to Risk Management

With the aim of maintaining and enhancing corporate value, the Group manages risk by appropriately identifying various risks associated with our business activities and mitigating the damages and losses through appropriate crisis management if any risks materialize.

Policy

Risk Management Basic Policy

  1. 1.We manage risk while paying attention to trends in financial conditions and business environments.
  2. 2.We manage risk in accordance with the relevant laws and regulations and from the perspective of Nabtesco Group’s social responsibilities, while also striving to disclose information promptly to minimize the impact and losses attributable to incidents that have occurred.
  3. 3.We validate concrete risk management processes after the occurrence of incidents and strive to prevent their recurrence.

System

Risk Management Systems

We have systems in place to ensure that profits, losses, asset efficiency, quality and disasters, among other matters, are reported to the Board of Directors properly and in a timely manner with respect to the execution of duties. By leveraging these systems, we strive for the early identification of risks and the minimization of losses. Under the oversight of the Board of Directors, we have established the Risk Management Committee under the direct supervision of the CEO, who has ultimate responsibility for risks. The committee members are appointed by the CEO, and the chairperson is responsible for the structure and implementation of company-wide risk management. The Chairperson of the Risk Management Committee (Managing Executive Officer) consults and coordinates with the members of the Management Materiality Committee, Quality & PL Committee, Environment, and Safety and Health Committee, and Information Security Committee, as required, and provides reports at management meetings such as Executive Officers Committee attended by CEO and Board of Directors meetings regarding the risk management initiatives periodically (approximately twice a year).

Administrative organizations of the Committees

  • Management Materiality Committee (administrative organization: Corporate Planning Dept.)
  • Risk Management Committee (administrative organization: Legal & Compliance Dept.)
  • Quality & PL Committee (administrative organization: Quality Promotion Dept.)
  • Environment, Safety and Health Committee (administrative organization: Environment & Safety Dept.)
  • Information Security Committee (administrative organization: Information Systems Dept.)

Measures

Risk Management Methods

First line of defense

At each in-house company and Group company, the head of the organization is responsible for risk management. Under the supervision of the risk management manager, the department and personnel in charge are responsible for risk management related to their business activities. Once a year, in-house companies and Group companies identify and evaluate the risks that may be assumed in the execution of the businesses under their jurisdiction, and they formulate and implement countermeasures to prevent materialization of the identified risks.

Second line of defense

The Corporate Department, which is in charge of handling various risks, manages the risks under its control based on its expertise in the division's area of responsibility, and supports the risk management of in-house companies and Group companies.

In addition, the Risk Management Committee, which reports directly to the CEO and is chaired by the Managing Executive Officer, meets at least twice a year. As a cross-company organization, the Committee first identifies and reviews company-wide major risks based on the results of risk assessments conducted by corporate divisions and Management Materiality (Long-term issues in achieving long-term goals), in-house companies, and Group companies. Next, the Committee deliberates countermeasures for major risks and directs the implementation of countermeasures. After risk countermeasures have been implemented, the Committee evaluates them and conducts follow-ups appropriately.

In identifying major risks, each risk item affecting business activities is evaluated in terms of its occurrence frequency and impact, and the potential causes of its occurrence are analyzed. Then, after prioritizing risk responses and confirming the level of risk tolerance, we formulate risk response methods and implement them after deliberating the proposed countermeasures. Our risk assessment is conducted in the following order: (1) risk analysis, (2) risk assessment, and (3) risk judgment. In risk analysis, each risk is analyzed in terms of its severity with five levels of occurrence frequency and four levels of impact. Based on the results obtained from such risk analysis, a score is assigned to determine the risk level and countermeasure level from among four levels.

Third line of defense

Our internal audit department, the Business Audit Department, is independent and conducts first and second line internal audits annually. The Business Audit Department investigates and evaluates the statuses of operational risk management, overall business processes, and asset management to ensure that they are being conducted properly. The results are compiled into an audit report, and follow-ups are conducted on the improvement statuses of items that have been pointed out and items for which improvement has been requested. Audit reports and follow-up reports are submitted directly to regular operational audit report meetings attended by the representative director, full-time corporate auditors, and some executive officers, and the contents of each report are posted to the audit report database for dissemination to all directors and corporate auditors, including those outside the company. In addition, the Internal Audit Department regularly reports on operations at Board of Directors meetings.

As a company with a board of auditors, Nabtesco's board of auditors, which consists of internal auditors and external auditors, is responsible for auditing the operations of the board of directors. By monitoring and providing opinions on the execution of duties, including risk management, from an independent and objective standpoint, we ensure management transparency.

Risk Management Cycle

Risk Management Cycle

Principal Risks

The following lists principal risks that are deemed to have potential impacts on the Group’s business performance and financial position.

  1. 1.Risks relevant to the economy, markets and currency
  2. 2.Risks relevant to geopolitical factors
  3. 3.Risks relevant to large-scale disasters and climate change
  4. 4.Risks relevant to procurement
  5. 5.Risks relevant to product quality
  6. 6.Risks relevant to competition
  7. 7.Risks relevant to information security
  8. 8.Risks relevant to intellectual property
  9. 9.Risks relevant to company acquisitions
  10. 10.Risks relevant to recruiting human resources

Risk Appetite

Through the Group Regulations on Responsibility and Authority, Nabtesco clearly defines the processes and responsible persons involved in the decision-making and business execution of the Nabtesco Group.

Risk appetite (Risk tolerance) is included in the above process, and it is determined by the final responsible party based on the degree of impact on the company after consultation with the responsible department.

The following are some of the major risks that have been identified and the measures taken to address them:

Example of serious risk Frequency Impact Effects on the Group Risk
tolerance
*1
Measures Link
Risks relevant to large-scale disasters and climate change Low Large Natural disasters, including floods and storms associated with global climate change, major earthquakes, pandemics, and other disruptive events may cause social disruption, resulting in human and physical losses, delays in material procurement, and disruptions to logistics networks. Low to Medium
  • Establish long-term emissions reduction targets validated by SBTi
  • Increase the use of renewable energy across operations
  • Implement integrated measures for emergency response and business continuity during disasters, supported by ongoing employee education and training in normal times
  • Conduct seismic reinforcement work, disaster preparedness drills, and safety patrols, including ESH audits

Combating Climate Change

Management of Occupational Health and Safety

Risks relevant to procurement Medium Medium Disruptions in component supply and the inability to secure alternative sourcing options may result in deteriorating product profitability and lost business opportunities. Medium
  • Strengthen the governance framework for BCP activities
  • Regularly assess suppliers’ information security capabilities and support continuous improvement
  • Promote multi-sourcing

BCP Initiatives

Build a Robust Supply Chain

Risks relevant to product quality Low Large In the event of a serious defect that leads to a product recall or product liability (PL) claim, significant costs may be incurred as a result of litigation, recalls, and related corrective actions. Low
  • Obtain and maintain Quality Management System (QMS) certifications at each manufacturing site
  • Conduct rigorous quality and product safety reviews throughout the development and design process, continuously monitor manufacturing process stability, and perform appropriate pre-shipment inspections
  • Provide ongoing education and training programs for employees

Quality and PL Management

  • *1 Risk tolerance: The identified risks are categorized into the following risk tolerance levels.
    • Low: Should not be tolerated.
    • Medium: Should be tolerated as necessary, in consideration of the benefits and merits.
    • High: Should be tolerated proactively for the creation of opportunities, while implementing countermeasures as necessary.

Emerging Risks

For “emerging risks” caused by changes in the external environment and other factors, we conduct regular reviews to check and manage their impact on our business. Typical emerging risks include the following:

Emerging risks Risk Related to Talent Availability (Talent Shortages Driven by Technological Innovation and Changes in the Labor Market) Paradigm Shift in Quality Assurance and Functional Safety Driven by Advances in AI Technologies and Evolving AI Regulations
Description of risks Against the backdrop of rapid technological advancement and changes in industrial structures, younger generations are exhibiting evolving views on work and career development. At the same time, increased labor mobility has intensified competition for talent across both companies and industries.
In the manufacturing sector in particular, the aging of skilled personnel who support production operations and maintenance services is progressing, while shifts in younger workers’ career expectations and employment mobility have made traditional talent acquisition and retention models, which are based on long-term workforce development, increasingly difficult to sustain. Furthermore, because the development of skilled technical and service personnel requires a considerable period of time, workforce shortages cannot be readily addressed in the short term, increasing uncertainty regarding the recruitment and development of the talent necessary to support business operations.
These changes in the external environment may make it more difficult to secure and develop talent capable of sustaining skill transfer and driving technological innovation. Over the medium to long term, this could adversely affect the Company’s competitiveness and ability to capture future growth opportunities.
The realization of the Group’s “Smart Motion Control” vision, as outlined in its Medium-Term Management Plan, requires the integration of AI technologies into products used in high-reliability applications, including aircraft, railway systems, industrial robots, and automatic doors. However, AI-enabled products introduce new challenges that extend beyond the scope of conventional mechanical control systems, including the prevention of unintended behavior, the explainability of AI-driven decisions, the integration of AI with functional safety requirements, and compliance with emerging regulations and standards.
As AI technologies become increasingly embedded in safety-critical products and services, the Group must adapt to a new paradigm in quality assurance and functional safety management. Reliance on traditional quality assurance frameworks alone may limit the Group’s ability to respond effectively to these evolving technological requirements and regulatory expectations.
Potential impacts on business The Group maintains a strong market position in a number of niche machinery components and products. As these products require advanced quality standards and long-term operational reliability, an insufficient supply of qualified personnel could lead to delays or constraints in product development, the advancement of manufacturing processes, quality assurance activities, maintenance services, and customer support.
In addition to manufacturing and selling products, the Group operates an MRO (Maintenance, Repair and Overhaul) business that provides maintenance, inspection, and repair services throughout the product lifecycle. Looking ahead, the importance of the MRO business may increase further as machinery becomes more sophisticated and customer demand grows for higher equipment availability and preventive maintenance solutions.
If the Group is unable to secure a sufficient number of specialized personnel to support maintenance, inspection, and repair services during a period of market expansion, service delivery capacity could become constrained. This may result in delays in responding to customer needs and the loss of business opportunities, which could adversely affect the Group’s competitiveness and future growth prospects.
If the Group is unable to transform its quality assurance framework in a timely manner to keep pace with this new paradigm, it may face delays in executing its Smart Motion Control strategy. In addition, failure to obtain type certification for products used in sectors such as aerospace and railway transportation could restrict market access and limit future business opportunities.
The increasing integration of AI into high-reliability products may also elevate the risk of product liability incidents arising from AI-related malfunctions, as well as public safety incidents involving infrastructure-related products. Such events could adversely affect operational performance and increase legal, regulatory, and reputational risks.
Furthermore, these challenges could undermine the Group’s corporate philosophy of providing “Safety, Security and Comfort” and erode the trust associated with its high-reliability brand. As a result, the Group’s business performance and financial position may be adversely affected.
Risk reduction measures The Group recognizes the attraction, development, and retention of specialized talent as a key management priority that supports product quality, reliability, and service capabilities. To address this risk, the Group has implemented the following measures:
  • Securing Diverse Talent and Promoting Knowledge Transfer
    The Group is strengthening the recruitment of early-career employees while broadening its talent pool through the hiring of employees from diverse backgrounds, including international talent. In addition, the Group promotes the re-employment of retired employees to facilitate the transfer of technical expertise and critical skills. Through these initiatives, the Group seeks to maintain and expand the workforce base that supports its manufacturing and maintenance service operations.
  • Creating a Work Environment that Supports Employee Retention and Growth
    The Group provides employees with career development opportunities and continuously reviews compensation and reward systems to better reflect professional expertise and on-site contributions. These measures are designed to foster an inclusive work environment in which diverse talent can build long-term careers and maximize their potential.
  • Enhancing Maintenance and Service Operations through AI and Digital Technologies
    In addition to initiatives aimed at attracting, developing, and retaining specialized talent, the Group is improving operational efficiency so that employees can focus on higher value-added activities.
    Within its maintenance service operations, the Group is advancing the implementation of AI and digital technologies in its products to improve condition monitoring and predictive maintenance capabilities. These technologies enhance the accuracy of equipment status assessment and failure prediction, enabling more efficient maintenance, inspection, and repair activities. As a result, the Group can reduce workload pressures on specialized personnel, improve productivity, and allow employees to focus on advanced technical support and customer engagement. Through these efforts, the Group aims to strengthen the resilience and sustainability of its long-term service delivery capabilities.
The Group recognizes the transformation of its quality assurance and functional safety framework for AI-enabled products as a key management priority that supports the realization of its Smart Motion Control strategy, as well as product quality, reliability, and public safety. To address this emerging risk, the Group has implemented the following measures:
  • Transforming Quality Assurance and Functional Safety Processes and Enhancing Readiness for International Standards
    To support the deployment of AI-embedded products and address news challenges, the Group is advancing its quality assurance and functional safety processes, including measures to prevent the unintended behaviour and to ensure that the rationale behind AI-driven judgments can be reasonably explained.
  • Strengthening Technological Capabilities through Advanced Technologies and External Collaboration
    The Group is enhancing the design and validation of AI-enabled products through the integration of advanced technologies, including model-based development and digital twin technologies. In addition, the Group leverages its Corporate Venture Capital (CVC) activities to collaborate with AI- and sensor-related start-ups, enabling the acquisition of diverse emerging technologies and accelerating innovation beyond in-house development capabilities.
  • Establishing AI Governance and Promoting Organization-wide Adoption
    To ensure the appropriate and responsible use of AI across the Group, internal AI guidelines are reviewed and updated on an ongoing basis. In addition, the Group has established a cross-functional governance structure that promotes risk-aware product planning and development from the earliest stages of product design and concept formulation.
  • Securing and Developing Talent with Expertise in AI and Functional Safety
    As a foundation for the transformation of its quality assurance framework, the Group is investing in the recruitment and development of specialized talent with expertise in both AI technologies and functional safety, thereby strengthening its long-term capability to develop and manage AI-enabled products safely and reliably.

Activities to Reduce Risk

Our group offers various products such as aircraft flight control actuation systems, brake components for railroad vehicles, remote control systems for marine vessels, platform doors for railroad stations, and automatic doors for buildings. Due to the very nature of these products, they pose serious risks to human life in the event of a malfunction-related worst-case scenario. Therefore, we prioritize safety and take proactive measures to prevent product accidents, earning high recognition for the reliability of our products. This high level of risk awareness is not something that can be achieved overnight. Every day, our directors and employees hone their risk sensitivity and work to establish a culture of risk reduction through activities such as the following.

Training on risks throughout the organization

The Group utilizes group training, e-learning, and other methods divided by rank and theme to foster compliance awareness, including risk awareness, among directors and employees (including contract employees, temporary employees, part-time employees, and trainees). Each year, we conduct a variety of training programs for all employees, including compliance training that contains risk management and information security training.

Regular training for internal and external directors as well as internal and external auditors

Once a year, we conduct training about the organization, our business, and finances as well as rules related to roles and responsibilities, legal responsibilities, compliance, and general risk management.

Incorporation of risk criteria when developing products and services

At Nabtesco, the business side and the Technology Division consider various risk factors for products and widely solicit opinions from related departments beyond the business side regarding the approval process, input resources, schedules, and other matters pertinent to clarifying development specifications. Risk assessments are conducted at each development stage from both qualitative and quantitative perspectives, and risk criteria are set separately per product group. To eliminate various risks, we also conduct environmental assessments for environmental conservation and chemical substances.

Financial incentives which incorporate risk management metrics

Nabtesco has introduced ROIC as an indicator that incorporates a risk management perspective, and the degree of improvement in this indicator is reflected in the compensation of directors (excluding outside directors). Compensation is based on the degree of improvement. All directors are aware of the cost of capital and dividend payout ratio, and they are committed to reducing the Group's risk and promoting management based on an awareness of sustainable growth.

Crisis Management (In the Event of Emergency)

If a serious incident has a significant impact on the Group’s business activities, such as their termination or suspension, the department in charge of the risk reports to the CEO and related departments without delay. The CEO reports to the Board of Directors and Audit & Supervisory Board promptly, establishes an emergency response headquarters and takes command of risk management.
The emergency response headquarters, which will be headed by the CEO as the General Manager, deals with the incident quickly and works to solve it while at the same time reporting to the Board of Directors on the matter, including on countermeasures taken to address the issue.

The Emergency Response Division

Senior General Manager CEO
Deputy Senior General Manager President of a responsible In-house and Group company, Officer in charge of relevant corporate department or General Manager
Members Staff of responsible In-house and Group companies and of corporate departments
Administrative organization Departments in charge of relevant risks, and if necessary, relevant departments of responsible In-house and Group companies and relevant teams of responsible corporate departments.

Serious Incident Reporting Route

Figure

Specific matters that cause losses for the Group are defined as incidents. We seek to minimize the impact of incidents through the reporting and sharing of information on these incidents through a series of regular meetings.

Reports on the occurrence, details, and causes of incidents as well as measures to address them and the losses incurred, among other things, are provided to the administrative organizations, the Executive Officers Committee and the Board of Directors. By doing so, we share information on the measures to reduce the occurrence of incidents.

Incident Reporting Route

Figure