Business Risks

stock information

The Company assesses the likelihood of occurrence of risk events related to the business of the Company and its group companies, as well as their potential impact on management, and identifies risks that are considered material on a comprehensive basis. The location of material risks and the corresponding response policies are deliberated by the Risk and Compliance Committee and subsequently reviewed and approved by the Board of Directors. The progress of the annual risk management implementation plan is reported to the Board of Directors.
Among the risks related to the business operations of the Company and its group companies, those considered particularly important for investors' investment decisions are described below as “Highly Important Risks” and “Important Risks.”
These risks are reported periodically to the Risk and Compliance Committee and the Board of Directors to ensure appropriate responses in the event that risks materialize or new risk events emerge. In addition, the Company continuously conducts employee education to foster a strong risk culture and strengthens its internal control framework centered on the Three Lines of Defense. For details of the Company’s risk management framework, please refer to “4. Corporate Governance, (1) Overview of Corporate Governance, ③ Other Matters Related to Corporate Governance, (ii) Development of the Risk Management System” in the Annual Securities Report, or the “Risk Management Framework” section under “Corporate Governance” on the Company’s website. Forward-looking statements in this section are based on judgments made as of the filing date of the Annual Securities Report (only available in Japanese). Furthermore, this section does not purport to provide an exhaustive description of all risks relating to the businesses of the Company and its group companies.

Highly Important Risks

Risk Overview Mitigation Measures
・Risks Related to Important IT Projects
The Group strives to establish competitive advantages and differentiate itself from competitors through initiatives such as digital transformation (DX), core system upgrades, and the provision of new products and services. If significant IT projects experience delays in release schedules, fail to deliver planned functionalities, or suffer from quality issues, the Group’s business performance and financial condition may be adversely affected through cost overruns and other consequences.
The Group promotes projects through a framework that includes multilayered monitoring of development plans, development processes, and quality assurance. To ensure design quality and comprehensive testing coverage, the Group works closely with vendors while maintaining mutual checks and balances. The progress of critical IT projects is reported monthly to the Company's Risk and Compliance Committee. Prior to system releases, extensive verification is conducted for all possible scenarios, and contingency frameworks are established to enable prompt responses in the event of system failures.
・Interruption or Malfunction of System Services
The stable operation of IT systems is essential for the various services provided by the Group. If IT systems are suspended, interrupted, or malfunction due to system defects, natural disasters, human error, or failures attributable to third parties, the Group's operating results and financial position may be adversely affected.
The Group implements physical, technical, and organizational measures to minimize damage and ensure prompt recovery from such incidents. These measures include establishing and strengthening monitoring systems to detect failures quickly, distributing and redundantly maintaining systems and data, standardizing operational procedures, providing regular employee training, and developing and rehearsing recovery plans for incident scenarios. For incidents that occur, root cause analyses are conducted, and recurrence prevention measures are implemented. With respect to outsourcing vendors, pre-engagement due diligence is conducted, and close communication is maintained with other third parties to facilitate smooth responses in the event of system failures.
・Cybersecurity Risk
With the rapid advancement of digital technologies, cyberattacks have become increasingly sophisticated and complex. Threats utilize AI-assisted attack techniques, social engineering methods that exploit human vulnerabilities through emails and phone calls, and attacks targeting third-party service providers as entry points. As a result, cybersecurity threats facing financial institutions continue to escalate. If the Group's systems or those of its third-party providers become subject to cyberattacks, resulting in service disruptions, data corruption, or information leakage, the Group's operating results and financial position may be adversely affected.
The Group has implemented countermeasures against cyber threats and established a Cybersecurity Policy to clarify response standards and responsibilities across the Group.
In addition, AFS has appointed a Chief Information Security Officer (CISO) and established a dedicated Cybersecurity Department, while major Group companies maintain Computer Security Incident Response Teams (CSIRTs). These structures enable centralized management of cybersecurity across the Group, establish clear decision-making processes involving senior management, and maintain robust defense and monitoring systems for critical systems. The Group also participates in industry-wide cybersecurity exercises and collaborates with external experts to enhance incident response capabilities and reduce emerging cybersecurity risks. Furthermore, awareness activities are conducted for customers and employees regarding cyber threats such as phishing emails and business email compromise (BEC) fraud.
・Risk Related to Anti-Money Laundering and Counter Financing Terrorism
As a financial institution, the Group is required to comply with laws and regulations relating to anti-money laundering and counter financing terrorism (AML/CFT). Although the Group has established appropriate governance frameworks and implemented various countermeasures, violations of applicable laws and regulations that result in legal sanctions or other actions could adversely affect the Group's operating results and financial position. In addition, deficiencies in AML/CFT controls may negatively impact the Group's brand image and customer trust.
The Group recognizes AML/CFT risk management as a critical management priority. Measures include customer due diligence at onboarding and on an ongoing basis, verification of customer identity and transaction purposes, daily transaction monitoring through automated detection systems, operational audits and effectiveness reviews by risk management departments, and internal audits. In light of the business improvement order issued by Japan's Financial Services Agency regarding AML/CFT controls in the banking business of a Group company during the previous fiscal year, the Group has reviewed business processes to accelerate suspicious transaction reporting, conducted comprehensive reviews with external specialists, and strengthened employee training programs to enhance compliance awareness.
・Regulatory Compliance Risk
Many of the Group's services require licenses, permits, or approvals under applicable laws and regulations. Failure to respond appropriately to regulatory changes or newly introduced regulations, or becoming subject to administrative actions due to non-compliance, could result in restrictions on business activities and adversely affect the Group's operating results and financial position.
Each Group company monitors relevant legal and regulatory developments in its operating jurisdictions and evaluates their potential impact on business activities and performance to identify compliance risks. Strict deadline management is maintained to ensure timely and accurate regulatory filings and reporting. In addition, employees receive regular compliance training to reinforce adherence to applicable laws and regulations.
・Credit Risk
The Group’s credit portfolio is diversified, consisting primarily of consumer finance products such as credit cards, installment financing, and housing loans.
Nevertheless, significant deterioration in economic conditions or disruption in financial markets could negatively affect customers’ creditworthiness and result in exceedingly high credit-related costs.
To strengthen credit risk management, the Group continuously monitors external economic conditions and changes in credit trends across products and regions and reflects such developments in its underwriting standards. The Group also monitors customers’ repayment performance after account origination and conducts appropriate receivables management, including revisions to credit limits when necessary.
・External Fraud Risks (Including Unauthorized Access through Phishing Websites and Similar Schemes)
In recent years, phishing fraud has become increasingly prevalent, making the rise in financial crime a critical challenge for financial institutions. Criminal methods targeting online services have become increasingly sophisticated. Failure to address such crimes appropriately may undermine the Group’s credibility and damage its reputation. In addition, the Group may incur additional expenses associated with responding to such incidents, including compensation costs for affected customers, which could adversely affect its operating results and financial condition.
To respond promptly to evolving fraud trends and emerging risks, the Group continues to strengthen both technical and organizational security measures and to enhance its fraud detection and prevention capabilities. These measures include continuous monitoring of phishing websites and unauthorized access attempts, as well as industry-wide initiatives to proactively disable fraudulent websites. Furthermore, upon identifying websites that imitate the Company's website, the Group takes measures such as redirecting users to warning screens (red screens) as part of its web risk and safe browsing initiatives to prevent harm and reduce risk.
The Group also enhances its security framework through specialized security teams that continuously refine fraud detection rules. In addition, the Group collaborates closely with external organizations, including the Japan Cybercrime Control Center (JC3), to obtain timely information regarding emerging threats and strengthen fraud prevention measures. Ongoing awareness campaigns and information-sharing activities are also conducted to help customers avoid becoming victims of fraud.
・Information Security Risk
The Group acquires and manages important information, including personal information of customers and business partners, to the extent necessary for its business operations. However, cyberattacks or inadequate management by officers, employees, contractors, or other third parties may result in the leakage, alteration, destruction, or loss of such information, which could adversely affect the Group’s operating results and financial condition.
The Group has implemented technical, physical, and organizational safeguards to protect information assets, including personal information. Measures relating to cyber threats are described under "Cybersecurity Risks." Officers and employees receive regular education and training to deepen their understanding of the importance of information management and protection. In cases where the handling of personal information and other sensitive data is outsourced, the Group establishes outsourcing standards and conducts periodic monitoring and oversight.

Important Risks

Risk Overview Mitigation Measures
・Tax Risk
Differences in interpretation or application of tax laws between the Group and tax authorities in jurisdictions where the Group operates may result in unexpected assessments of additional taxes, interest, or penalties, which could adversely affect the Group's financial position.
The Group utilizes reviews and advice from tax specialists in each jurisdiction, including Japan, and maintains a framework designed to calculate appropriate tax liabilities and minimize differences in interpretation with tax authorities. Where such differences arise, the Group seeks to obtain understanding of its interpretations with support from external experts.
・Operational Error and Internal Misconduct Risk
The Group conducts numerous types of administrative and operational processing in the course of its business. Failure by employees to perform required procedures appropriately, or the occurrence of accidents, misconduct, or fraud, may result in unexpected losses or regulatory sanctions, which could adversely affect the Group's operating results and financial position.
The Group has established internal regulations and procedures designed to maintain and improve operational quality. When operational errors occur, root causes are thoroughly analyzed and corrective measures are implemented. To prevent internal misconduct, the Group employs job rotation programs and compliance education based on the common fundamental principles of the AEON Group.
・Foreign Exchange Risk, Interest Rate Risk and Market Price Fluctuation Risk
In its domestic banking business, the Group handles financial products with relatively long investment horizons, including residential mortgage loans. As a result, interest rate repricing gaps arise between assets and liabilities. Significant fluctuations in interest rates due to market developments or other factors may adversely affect the Group's operating results and financial condition.
In addition, the domestic banking business invests in foreign securities and marketable securities, including bonds and equities. Significant fluctuations in foreign exchange rates, interest rates, and stock prices may adversely affect the Group's operating results and financial condition.
Furthermore, as the Group operates businesses throughout Asia, substantial fluctuations in foreign exchange rates may affect cross-border investments and financing from Japan, foreign currency-denominated funding by local subsidiaries, dividend remittances from overseas subsidiaries, and consolidated financial results, thereby adversely affecting the Group's operating results and financial condition.
In its domestic operations, the Group utilizes long-term funding sources such as corporate bonds in an effort to reduce interest rate repricing gaps between assets and liabilities
With respect to market price fluctuation risk associated with securities held in the domestic banking business, the Group measures risk primarily through Value-at-Risk (VaR), which estimates potential losses that may arise from financial instruments over a specified future period at a given confidence level based on historical data and other assumptions. Risks are controlled within limits approved by the Board of Directors and other management bodies.
Foreign exchange risk in the domestic banking business is managed through the risk-control framework described above. The Group also periodically monitors the potential impact of exchange rate fluctuations in the Asian countries where it operates.
・Liquidity Risk
The Group secures funding necessary for its business activities through deposits, borrowings from financial institutions, corporate bonds, commercial paper, securitization transactions, and other funding sources. A deterioration in the Group's creditworthiness resulting from significant changes in financial markets, economic conditions, or other factors, or a downgrade in credit ratings, could adversely affect the Group's ability to obtain funding.
The Group manages liquidity risk through continuous cash flow monitoring, timely funding management, diversification of funding sources, and optimization of the balance between short-term and long-term funding in consideration of market conditions.
In the banking business, liquidity risk is further managed through the establishment and monitoring of liquidity reserve ratios and funding gap limits to ensure exposures remain within prescribed thresholds.
・Talent Management Risk
The Group conducts business activities across a broad range of fields that require highly specialized expertise. Competition for skilled professionals continues to intensify. Failure to attract, develop, and retain personnel with the requisite expertise due to increased competition for talent or employee turnover could hinder the execution of business strategies and adversely affect the Group's performance.
The Group recognizes the development and retention of highly capable professionals as a key management priority to drive innovation and respond effectively to evolving customer needs and business growth.
Accordingly, the Group operates a performance- and competency-based human resources system and seeks to enhance employee capabilities through robust training and development programs.
The Group also develops future leaders through initiatives such as its Next-Generation Executive Development Program and other management development programs targeting senior and middle management personnel.
・Human Resources and Labor Risk
The Group conducts operations both in Japan and overseas and employs individuals with diverse backgrounds, nationalities, and cultures. Inadequate understanding of, or responsiveness to, human rights and diversity issues within Group companies could lead to employee turnover and social criticism. Such circumstances could damage the Group's reputation and adversely affect customer utilization of its services, thereby negatively impacting operating results and financial condition.
The Group not only complies with applicable laws and regulations in each country where it operates but also conducts ongoing awareness and education programs designed to help all officers and employees embody AEON's fundamental philosophy of "placing customers first, pursuing peace, respecting humanity, and contributing to local communities." The Group also seeks to prevent human rights violations, including harassment and inappropriate workplace conduct. Where discrimination or other inappropriate conduct occurs, affected individuals or those aware of such conduct may report concerns through the Group's reporting system. Each reported matter is investigated and addressed appropriately while ensuring the protection of any staff member that reports these issues.
・Natural Disaster Risks and Other Risks Due to Catastrophe
The Group conducts business throughout Japan and across various countries and regions in Asia. Earthquakes, tsunamis, typhoons, heavy rainfall, system failures, infectious disease outbreaks, civil unrest, terrorist activities, and other disasters may result in physical damage to stores, facilities, payment infrastructure, ATMs, and other assets, as well as personal injury to employees and customers. Such events could lead to prolonged business interruptions, substantial recovery costs, or business discontinuation, thereby adversely affecting the Group's operating results and financial condition.
The Company and its subsidiary AEON Bank have obtained certification under ISO 22301, the international standard for Business Continuity Management Systems (BCMS), and have established business continuity plans and conducted related training and simulation exercises. Group companies similarly implement business continuity planning (BCP), identify critical operations, conduct exercises and drills, and provide employee training to minimize damage and facilitate rapid recovery during emergencies.
・Reputational Risk
Rumors, misinformation, or inaccurate perceptions regarding the Group or the financial services industry may arise and spread through media coverage, word-of-mouth communication, internet message boards, social networking services (SNS), and other channels. Such developments could erode customer trust, reduce revenues through customer attrition, and give rise to costs associated with mitigating reputational damage, thereby adversely affecting the Group's operating results and financial condition.
The Group conducts ongoing monitoring of media coverage and social media platforms through keyword detection systems to identify rumors and reputational issues at an early stage. Appropriate measures are taken based on the scale and potential impact of information dissemination in order to minimize adverse effects.
・Geopolitical Risk
The Group's international operations are concentrated primarily in Asia. Rising geopolitical tensions, increasing fragmentation among nations, and broader uncertainty in international affairs heighten geopolitical risks. Should trade disruptions, financial crises, political instability, social unrest, military conflicts, or diplomatic tensions arise in countries where the Group operates or elsewhere, the business and economic environment of affected regions, as well as the Group's operations, could be adversely affected. This may negatively impact the Group's operating results and financial position.
The Group conducts market research and analysis at both macroeconomic and microeconomic levels before and after entering markets. It also gathers information regarding economic, political, and social developments through collaboration with AEON Group companies and Japanese businesses operating locally. When signs of material changes in conditions are identified, appropriate responses are considered by the Risk and Compliance Committee and other relevant bodies.
・Climate Change Risks
Increasing frequency and severity of extreme weather events, including typhoons and floods, as well as rising temperatures, could cause power outages, telecommunications disruptions, and other damage affecting stores, facilities, payment infrastructure, and ATMs, which may adversely affect the Group's operating results and financial condition.
The Group is also pursuing initiatives under the "AEON Decarbonization Vision 2050" and aims to achieve the targets described in "2. Sustainability: Approaches and Initiatives, (4) Metrics and Targets, ② Climate Change Matters," including energy conservation, expansion of renewable energy usage, and transition to renewable energy sources. The Group is advancing disclosures consistent with the recommendations of the Task Force on Climate-related Financial Disclosures (TCFD). However, strengthened environmental regulations and rising stakeholder expectations could result in higher-than-anticipated compliance costs. In addition, if the Group's initiatives or disclosures are perceived as inadequate, its social credibility and reputation could be adversely affected.
The Group undertakes initiatives to improve facilities and operations at stores and other sites and to ensure the stable operation of systems and infrastructure. The Group also promotes decarbonization through initiatives such as paperless and digital solutions for product information, service applications, and AEON Card statements. In addition, the Group monitors new and revised environmental regulations and seeks to provide sufficient disclosures to ensure appropriate fulfillment of its accountability to stakeholders.

Related Information