Risk Managementimage

Risk Management

Risk Management Framework

The HOYA Group manages sustainability-related risks as well as business and financial risks arising from changes in the business environment through an integrated, Group-wide risk management framework.

Within the Group's risk management framework, Executive Officers and other members of management identify, assess, respond to, and improve risk management practices through each business division and functional department at Group headquarters. The Board of Directors is responsible for overseeing significant risks across the Group and the overall risk management system. In addition, the Audit Committee independently monitors the development, operation, and effectiveness of the risk management system through internal audit results and other relevant information.

To support this framework, the Group has established and operates a control framework based on the "Three Lines of Defense" model. Under this framework, the first line consists of business divisions responsible for identifying and managing risks; the second line comprises the Compliance function and other functional departments that provide oversight and support; and the third line is the Internal Audit function, which conducts independent audits. Through close coordination among these three lines, the effectiveness of risk management is maintained. The Internal Audit function reports to the Audit Committee and conducts audits in accordance with the Committee's policies and audit plans, reporting the results as appropriate. Through these activities, the Audit Committee independently monitors the effectiveness of the Group's risk management system.

Regarding business risks, the Group operates across a diverse range of products and markets. Accordingly, each business division takes primary responsibility for identifying, assessing, and responding to risks, including operational and geopolitical risks, based on market conditions, competitive dynamics, and the progress of business strategies. Significant matters are reported in a timely manner by division heads to the relevant departments at Group headquarters and Executive Officers, and are also regularly reported to the Board of Directors. The Board reviews these reports and oversees both the response to significant business risks and the effectiveness of the risk management system. In addition, for areas that are particularly important across multiple business divisions, the Group has appointed CXOs, including the Chief Information Officer, Chief Human Resources Officer, and Chief Compliance Officer, who report on risk status and response progress in their respective areas to Executive Officers and the Board of Directors to ensure effective risk management.

With respect to financial risks, in addition to treasury management, risks relating to financial reporting and internal controls are monitored and assessed through collaboration between the Finance and Accounting functions and the Internal Audit function. The results are reported to Executive Officers and the Audit Committee. Furthermore, the Group continuously carries out audits by the independent auditor and evaluation and improvement activities under the internal control reporting system (J-SOX) to ensure accurate and timely financial reporting.

In addition, the Internal Control team within the Finance Department at Group headquarters oversees the development and operation of internal controls across business divisions and monitors the execution of the PDCA cycle through regular reporting. When events that may significantly affect the effectiveness of internal controls occur, appropriate corrective and improvement measures are implemented. The status of these initiatives is reported to the Board of Directors through deliberations and audit results of the Audit Committee, enabling the Board to oversee the Group-wide risk management framework.

In the event of a major crisis, the Company establishes a Crisis Management Headquarters led by the CEO to enable prompt decision-making and response through a Group-wide cross-functional structure.

Related Topics

Risk Managememt Structure

image

Examples of Identified Business Risks and Countermeasures

1) Strengthening the Business Portfolio and Long-Term Growth Strategy
Risk
To achieve sustainable growth, the Company primarily operates businesses in the healthcare and information and communication sectors. In addition to expanding its core growth businesses, the Company is also working to create new business opportunities that will support long-term growth.

However, given the nature of its information and communication businesses, which primarily manufacture intermediate materials for semiconductors and electronic devices, performance is susceptible to fluctuations in end-market demand and customers' capital investment trends. As a result, deteriorating market conditions may significantly impact profitability. In addition, the Company operates under a divisional structure in which each business division is managed with the goal of maximizing its own business value. Consequently, there is a risk that collaboration and synergy creation across divisions may receive lower priority, resulting in missed opportunities for new businesses and future growth.

Furthermore, with respect to M&A, opportunities that meet the Company's standards for profitability and capital efficiency are limited, which may restrict investment opportunities. At the same time, investments in inappropriate targets could impair the Group's high level of profitability.

Response
To address market fluctuation risks in the information and communication sector, the Company seeks to optimize its business portfolio by maintaining a balanced mix of businesses with different characteristics, thereby enhancing the stability of the Group's overall performance.

Regarding M&A, the Company will continue to maintain strict financial discipline while carefully balancing growth investments and evaluating opportunities.

In addition, during FY2026, the Company plans to establish HOYA Incubation Laboratories (HILS), a cross-divisional initiative aimed at creating technology seeds for future growth by combining the core competencies of individual business divisions. Preparatory activities are currently underway.

Through these efforts, the Company aims not only to grow through M&A but also to strengthen the foundation for organic growth, thereby enhancing long-term competitive advantages and achieving sustainable growth in corporate value.

2) Geopolitics and Supply Chain
Risk
As a globally operated business, the Group relies on supply chains that span a wide range of regions, including procurement and logistics. Changes in geopolitical conditions, developments in trade regulations, and dependence on specific regions may affect the supply environment. As a result, any impact on procurement timing or sourcing conditions could affect product supply and revenue-generating opportunities.

Response
In addition to mitigating risk through the geographic diversification of its own operations, the Group is enhancing supply chain resilience by securing multiple sourcing options and diversifying supply networks. The Group also continuously monitors supply chain conditions and works to strengthen its ability to respond flexibly to changes in the external environment.

Information Security

The HOYA Group regards information security as one of the key management foundations supporting the stable operation of its global businesses and the trust of its stakeholders. As digitalization and business connectivity continue to expand, the Group strives to maintain an environment in which important information, including technological and personal information, is appropriately protected and securely utilized.

Because information assets and information systems can affect not only internal operations but also external stakeholders, including customers and business partners, information security is positioned as one of the critical areas within the Group's overall risk management framework.

Governance

The Company is strengthening its Group-wide governance structure for information security. Under the leadership of the Chief Executive Officer (CEO), the Chief Information Officer (CIO) leads Group Digital in establishing stronger common security policies and infrastructure across the Group and deploying them throughout the business divisions. The Company is also enhancing crisis response capabilities for cyberattacks and other information security incidents.

In addition, the Company is strengthening governance through the identification of key risk scenarios and prioritization of mitigation measures. The status of information security risks and related initiatives is reported by the CIO to the Board of Directors at least annually, and continuous improvements are implemented under the Board's oversight.

Furthermore, through audits conducted by the Internal Audit function, the Company evaluates the effectiveness of its information security management framework, identifies opportunities for improvement, and enhances the effectiveness of risk management and security measures.

Policy

To protect information assets, the Company has established an Information Security Policy and related guidelines covering areas such as access management, secure operation of information systems, incident response, and management of third parties, including suppliers. These policies apply across the Group and are continuously reviewed and strengthened in response to changes in the external environment.

For personal information protection, the Compliance function has appointed a Global Head of Privacy, who works closely with Group Digital to oversee access controls, appropriate handling of information consistent with intended purposes, and incident response. The Company also requires appropriate information management by suppliers and external service providers through contractual arrangements and the HOYA Supplier Code of Conduct.

In addition, the Company has established policies and guidelines governing the use of digital technologies, including generative AI (GenAI), to ensure responsible use and appropriate handling of sensitive information while balancing innovation and risk management.

Measures and Training

In strengthening information security, the Company recognizes that people are as important as technology. All employees who use PCs and other computing devices are required to complete annual security awareness training. The Company also conducts phishing simulations and ongoing awareness activities to enhance practical response capabilities. By sharing incident cases and near-miss experiences, the Company promotes the consistent adoption of appropriate security practices. In addition, information security incidents and suspicious activities are handled in accordance with established incident reporting and escalation procedures. Following prioritization based on severity, the Group manages and implements the full response process from containment through recovery.

From a technical perspective, the Company continuously enhances its security capabilities through measures such as updating security software, strengthening password management, conducting penetration testing, and performing vulnerability assessments.

Through the continuous improvement of people, processes, and technology, the HOYA Group enhances the resilience of its information systems, reduces risks, and supports the sustainable growth of its global business operations.