Risk-Taking and Risk Control

Internal Control That Promotes the Undertaking of Bold Challenges

Basic Approach to Internal Control System

Based on the report compiled by the Expert Committee for Improving and Strengthening Group Governance, the JR East Group has updated its basic approach to internal control. In updating this approach, we have reaffirmed and emphasized that sound business operations achieved through ensuring compliance are the foundation of the trust that is the Group’s greatest asset and the basis for its growth. We have also positioned the three pillars of the improvement measures P. 114 as the foundation of our internal control initiatives.
We view the Group’s internal control as various initiatives to realize the Group Philosophy and Group Management Vision appropriately and efficiently. Specifically, in response to changes in the business and operating environment, we view internal control as undertaking broad-based risk management, including risk-taking, and supporting and encouraging employees to take on new challenges, based on the fundamental premises of ensuring compliance, ensuring safety and security, preventing financial losses, and ensuring the soundness of financial statements.
The foundation of all businesses across the Group is the trust that is built through stable and proper business operations based on ensuring compliance. Trust is built on a sound corporate culture, necessary structures and rules, and active communication, and through the sincere and conscientious daily conduct of Group employees.
Under Group governance established on the basis of this approach, we will advance our dual-axis management of Mobility and Lifestyle Solutions, continuously create security and excitement, and strive to realize enriched lifestyles for all people.

JR East Group’s Basic Approach to Its Internal Control System

Systems and Mechanisms to Support and Encourage the Taking On of Bold Challenges

We have established systems that proactively encourage employees to take on “bold challenges” to develop the JR East Group and increase its value, and we are constantly reviewing and improving them.
To encourage employees to take on new challenges in their daily work and foster a mindset of expanding their own potential, we are promoting the horizontal sharing of challenge initiatives across the Group through communication tools that enable employees to view and post examples of challenges undertaken by other departments. We also conduct employee engagement surveys. We understand and analyze the percentage of employees giving positive responses to the “employee creativity rate” question and are working to create an environment that further encourages employee initiative and motivation.

Percentage of employees who gave positive answers to relevant items in the engagement survey

84.2% in FY2023, 85.8% in FY2024, and 85.8% in FY2025.

Basic Approach to Risk Management

To improve profitability and undertake structural reforms, we recognize the importance of broad-view risk management that considers risk* not only from the perspective of reducing negative factors such as avoiding losses but also from the perspective of proactively increasing the value of the Group including risk taking.
We have established and operate internal controls, including the internal control system under the Companies Act and the Financial Instruments and Exchange Act to ensure stable and proper business operations, while also working to develop the Group and support and encourage the taking on of bold challenges aimed at enhancing value and growth.

  • *These include not only risks related to compliance, safety assurance, and natural disasters, among others, but also those related to market changes, trends of our competitors, social and economic conditions in Japan and overseas, and management decisions related to new businesses.

Risk Management Initiatives

Tax Transparency Initiative

We have established a Group Policy on Tax Transparency to ensure that we pay taxes appropriately, which is one of our responsibilities as a corporation, while also managing tax risks appropriately and aiming to enhance our corporate value. We will also comply with tax-related laws and regulations in all countries and regions in which we do business and build a highly transparent tax governance system.

Strengthening Collaboration with Group Companies through Part-time Officers

To improve governance across the entire Group and achieve consolidated cash flow management by business unit, we are working to strengthen communication with Group companies through part-time officers who are dispatched to Group companies. The officers are provided with “key points to bear in mind,” which summarize their roles and responsibilities.
Each part-time officer reports to the head office on the status and implementation of initiatives, and by acting with an awareness of key points, they stimulate communication throughout the Group, which leads to improved governance, the realization of consolidated cash flow management, and enhanced corporate value.

Basic Approach to Compliance

Based on the Policy on Legal and Regulatory Compliance and Corporate Ethics, we have established a Compliance Action Plan that outlines how we should behave as a corporation and as members of society. While building trust with all stakeholders, we comply with all related laws in our various business fields, such as Mobility services and Lifestyle Solutions services, and we have conducted business in accordance with our corporate ethics.
As an improvement measure based on the report compiled by the Expert Committee for Improving and Strengthening Group Governance, in June 2026 we revised the Policy on Legal and Regulatory Compliance and Corporate Ethics and the Compliance Action Plan, and established the JR East Group’s “Determination and Commitment” as the code of conduct that serves as a guiding principle for everyone working within the Group. Based on this “Determination and Commitment,” we will continue working to further strengthen compliance.

Key Compliance Initiatives

You can swipe horizontally.

What We Aspire To Specific Initiatives Status of Initiatives
  • Understanding the importance of compliance as the foundation of management
    ​
  • Strengthening our ability to respond to risks that may be present in our business
    ​
  • Compliance education for all employees
  • Implemented for all Group companies in FY2026.3, (including seconded employees, contract employees, dispatched employees, etc.)
  • In light of recent internal and external incidents, including fraudulent personnel cost claims related to commissioned projects and subsidies for central government ministries and similar matters, discussions were held to prevent the recurrence of similar incidents
  • Compliance training for managers
  • Compliance seminars for executives
  • Established individual education programs as part of “Compliance education for all employees”
  • In FY2026.3, these discussions were also conducted on topics including the internal reporting system and business and human rights
  • As part of our improvement measures, we distributed videos on psychological safety and harassment prevention
  • Compliance awareness survey
  • Used the results obtained to identify issues and consider improvement measures
  • Regular inspections to ensure proper business operations
  • Prevention and early detection of inappropriate events
  • Checklists for confirming basic matters
  • Compiled summaries of main inspection items related to laws and regulations, which are checked and inspected at least once a year
  • Compiled into a Companywide version and a system-specific version
  • JR East Group compliance consultation desk (officers, employees, and former employees of all Group companies, as well as executives and employees of business partners, can consult and report via this desk)
  • Handled about 330 consultations and reports in FY2026.3
  • Handled a wide range of consultations and reports, including those related to the handling of laws and regulations, interpersonal problems, and various types of harassment
  • Building sound relationships with business partners
  • Inclusion of anti-bribery clauses in Compliance Action Plan
  • Formulated and announced Basic Policy for Preventing Bribery of Foreign Public Officials, etc. in conjunction with our expansion of overseas business
  • Inclusion of a ban on profiteering in work regulations
  • Signed the United Nations Global Compact and joined the Anti- Corruption Subcommittee
  • Strengthened compliance with anti-corruption laws and regulations in various overseas countries

Systems and Mechanisms to Support and Encourage the Taking On of Bold Challenges

We have established systems and mechanisms that proactively support and encourage employees to take on bold challenges to develop the JR East Group and increase its value, and we are constantly reviewing and improving them.
To encourage employees to take on bold challenges in their daily work, we share best practices throughout the Group through communication tools that can be viewed and posted by all Group employees, and we also conduct employee engagement surveys. We are working to create an environment that fosters employee initiative and motivation by identifying the percentage of employees who responded positively to “employee creativity rate” in the survey.
We also actively communicate with frontline employees through opinion exchange meetings, discussions, and on-site visits, with the aim of spreading the management vision.

Percentage of employees who gave positive answers to relevant items in the engagement survey

FY2023: 84.2% FY2024: 85.8%

Basic Approach to Risk Management

For the Group to improve profitability and undertake structural reforms, we recognize the importance of broad-view risk management that considers risk*not only from the perspective of reducing negative factors such as avoiding losses but also from the perspective of proactively increasing the value of the Group.
We have established and operate internal controls in accordance with the Companies Act and the Financial Instruments and Exchange Act to ensure stable and proper business operations, while also working to develop the Group and support and encourage the taking on of bold challenges aimed at enhancing value and growth.

  • *These include not only risks related to compliance, safety assurance, and natural disasters, among others, but also those related to market changes, trends of our competitors, social and economic conditions in Japan and overseas, and management decisions related to new businesses.

Risk Management Initiatives

  • *1Challenge risks are risks that should be considered when implementing new measures or entering new businesses.
  • *2Environmental change risks are risks that increase in importance with changes in the business environment.

Tax Transparency Initiative

We have established a Group Policy on Tax Transparency to ensure that we pay taxes appropriately, which is one of our responsibilities as a corporation, while also managing tax risks appropriately and aiming to enhance our corporate value. We will also comply with tax-related laws and regulations in all countries and regions in which we do business and build a highly transparent tax governance system.

Strengthening Collaboration with Group Companies through Part-time Officers

To improve governance across the entire Group and achieve consolidated cash flow management by business unit, we are working to strengthen communication with Group companies through part-time officers who are dispatched to Group companies. The officers are provided with “key points to bear in mind,” which summarize their roles and responsibilities.
Each part-time officer reports to the head office on the status and implementation of initiatives, and by acting with an awareness of key points, they stimulate communication throughout the Group, which leads to improved governance, the realization of consolidated cash flow management, and enhanced corporate value.

Basic Approach to Compliance

Based on the Policy on Legal and Regulatory Compliance and Corporate Ethics, the JR East Group has established a Compliance Action Plan that outlines how we should behave as a corporation and as members of society. While building trust with all stakeholders, we comply with all related laws in our various business fields, such as Mobility services and Lifestyle Solutions services, and we conduct business in accordance with our corporate ethics.

Key Compliance Initiatives

You can swipe horizontally.

What We Aspire To Specific Initiatives Status of Initiatives
  • Understanding the importance of compliance as the foundation of management
    ​
  • Strengthening our ability to respond to risks that may be present in our business
    ​
  • Compliance education for all employees
  • Implemented for all Group companies in FY 2025.3, (including seconded employees, contract employees, dispatched employees, etc.)
  • In light of the discovery of data fraud in vehicle wheelset assembly operations, discussions were held to prevent the recurrence of similar incidents
  • Compliance training for managers
  • Compliance seminars for executives
  • Established individual education programs as part of “Compliance education for all employees”
  • Implemented in FY 2025.3, covering themes including harassment prevention and support for diverse human resources
  • Compliance awareness survey
  • Used the results obtained to identify issues and consider improvement measures
  • Regular inspections to ensure proper business operations
  • Prevention and early detection of inappropriate events
  • Checklists for confirming basic matters
  • Compiled summaries of main inspection items related to laws and regulations into a Companywide version and a system-specific version, which are checked at least once a year
  • Compiled into a Companywide version and a system-specific version
  • JR East Group compliance consultation desk (officers, employees, and former employees of all Group companies, as well as executives and employees of business partners, can consult and report via this desk)
  • Handled about 270 consultations and reports in FY 2025.3
  • Handled a wide range of consultations and reports, including those related to the handling of laws and regulations, interpersonal problems, and various types of harassment
  • Building sound relationships with business partners
  • Inclusion of anti-bribery clauses in Compliance Action Plan
  • Formulated and announced Basic Policy for Preventing Bribery of Foreign Public Officials, etc. in conjunction with our expansion of overseas business
  • Inclusion of a ban on profiteering in work regulations
  • Signed the United Nations Global Compact and joined the Anti- Corruption Subcommittee
  • Strengthened compliance with anti-corruption laws and regulations in various overseas countries

Basic Policy for Information Security

We have established the JR East Group’s Basic Policy for Information Security and are working to minimize security risks throughout the Group, with the Department Director of Innovation Strategy Department serving as the Chief Information Security Officer (CISO).
JR EAST Group Information Security Basic Policy

System to Promptly Detect and Respond to Cyberattacks

Security Operation Center (SOC)

  • Establishment of an SOC to monitor suspicious communications targeting the JR East Group
  • Configuration of a framework that can analyze suspicious communications and escalate them in a timely manner

JR East Endpoint Security Service

  • Deployment of integrated security products with malware detection and SOC coordination functions to each computer within the JR East Group
  • Addressing of the increasing security risks associated with the expansion of remote working

ASM (Attack Surface Management)

  • Introduced Attack Surface Management (ASM) in FY2026.3 as a means of identifying the Group’s IT assets exposed to the Internet and maintaining an up-to-date understanding of their status
  • Strengthened cyberattack risk management by detecting signs of risk at an early stage and linking them to countermeasures

Information Security Initiatives

Security Education and Training
  • Education for all employees to raise their awareness of cybersecurity
  • Training for employees in each position within the implementation framework
  • Ongoing response training at each Group company to prepare for a security incident
10 Principles of Information Security
  • Distributed to each JR East Group employee as a set of rules that every employee must observe
10 Principles of Information Security (multilingual support)

Personal Data Protection Initiatives

Pursuant to applicable laws and regulations, including personal information protection legislation both in Japan and overseas, we are working to reduce the risk of data breaches by strengthening our personal information management system and reviewing our rules.

  • Publication of Basic Policy for Personal Information Handling
  • Formulation of internal regulations such as personal information management regulations
  • Operational audits conducted at least once a year at all locations
  • Publication of privacy policies in response to legislation in the European Union, the United Kingdom, and California, among other jurisdictions
  • Regularly scheduled education and training through compliance and information security education and other such programs for all employees

Fundamental Approach to AI Governance

The JR EAST Group aims to enrich the lives of all people through a human-centric approach to Lifestyle Transformation (LX) by leveraging AI. Thus we will transform our ways of working and create new customer experience value. We will identify the risks associated with AI and work together as a group to promote AI governance to address them appropriately.
Digital governance of JR EAST Group (image)

AI Policy

As we promote the use of AI across the Group’s diverse business activities and customer touchpoints, including Mobility and Lifestyle Solutions, we have established the JR EAST Group AI Policy to maximize the benefits of AI under a governance framework that identifies AI-related risks and responds to them appropriately.
The AI Policy consists of three components: Growth strategy (value creation), Protection (safety and trust), and the Foundations (human resources and organization) that support them. These are expressed through a total of seven elements.

  • Growth strategy (value creation): By addressing social issues and customers’ latent needs through the proactive use of AI, we will transform our ways of working and create new customer experience value.
  • Protection (safety and trust): With people at the center, we will use AI safely by promoting a proper understanding of risks, respecting human rights, and ensuring compliance.
  • Foundations (human resources and organization): We will deepen understanding of AI through continuous human resource development, promote the use of AI in collaboration with our partners, and respond appropriately through measures such as reviewing our management framework.

In addition, when introducing generative AI, the entire Group follows a process similar to that used for information security measures, confirming matters such as the intended use, the AI to be used, human rights and personal information protection, and the risk of hallucinations before implementation.

AI Policy

AI Policy

To maximize the benefits of AI across our diverse business operations, including mobility and lifestyle services, and throughout our customer touchpoints, we have established the “JR EAST Group AI Policy.”
Our AI Policy consists of seven key elements and is structured around three components: value creation as a driver of growth, safety and reliability as a means of protection, and a foundation of people and organizational capabilities that support them.
AI Policy

Initiatives for Generative AI Governance

Establishing Guidelines for the Use of Generative AI

  • Establishment of two sets of guidelines tailored for users and for those involved in implementation and development.
  • Development of a checklist to verify risk mitigation measures.

Educational Content

  • Distribution of materials that clearly explain the guidelines.
  • Company-wide training to enhance knowledge of and raise awareness of generative AI risks.
Initiatives for Generative AI Governance

Links