Risk-Taking and Risk Control
Internal Control That Promotes the Undertaking of Bold Challenges
Basic Approach to Internal Control System
Based on the report compiled by the Expert Committee for Improving and
Strengthening Group Governance, the JR East Group has updated its
basic approach to internal control.
In updating this approach, we have reaffirmed and emphasized that
sound business operations achieved through ensuring compliance are the
foundation of the trust that is the Group’s greatest asset and the basis for
its growth. We have also positioned the three pillars of the improvement
measures P. 114 as the foundation of our internal control initiatives.
We view the Group’s internal control as various initiatives to realize
the Group Philosophy and Group Management Vision appropriately
and efficiently. Specifically, in response to changes in the business
and operating environment, we view internal control as undertaking
broad-based risk management, including risk-taking, and supporting
and encouraging employees to take on new challenges, based on the
fundamental premises of ensuring compliance, ensuring safety and
security, preventing financial losses, and ensuring the soundness of
financial statements.
The foundation of all businesses across the Group is the trust that is built
through stable and proper business operations based on ensuring
compliance. Trust is built on a sound corporate culture, necessary
structures and rules, and active
communication, and through the
sincere and conscientious daily
conduct of Group employees.
Under Group governance established
on the basis of this approach, we will
advance our dual-axis management
of Mobility and Lifestyle Solutions,
continuously create security and
excitement, and strive to realize
enriched lifestyles for all people.
JR East Group’s Basic Approach to Its Internal Control System
Systems and Mechanisms to Support and Encourage the Taking On of Bold Challenges
We have established systems that proactively encourage employees to take on
“bold challenges” to develop the JR East Group and increase its value, and we
are constantly reviewing and improving them.
To encourage employees to take on new challenges in their daily work and foster
a mindset of expanding their own potential, we are promoting the horizontal
sharing of challenge initiatives across the Group through communication tools
that enable employees to view and post examples of challenges undertaken by
other departments. We also conduct employee engagement surveys. We
understand and analyze the percentage of employees giving positive responses
to the “employee creativity rate” question and are working to create an
environment that further encourages employee initiative and motivation.
Percentage of employees who gave positive answers to relevant items in the engagement survey
Basic Approach to Risk Management
To improve profitability and undertake structural reforms,
we recognize the importance of broad-view risk
management that considers risk* not only from the
perspective of reducing negative factors such as avoiding
losses but also from the perspective of proactively
increasing the value of the Group including risk taking.
We have established and operate internal controls,
including the internal control system under the
Companies Act and the Financial Instruments and
Exchange Act to ensure stable and proper business
operations, while also working to develop the Group
and support and encourage the taking on of bold
challenges aimed at enhancing value and growth.
- *These include not only risks related to compliance, safety assurance, and natural disasters, among others, but also those related to market changes, trends of our competitors, social and economic conditions in Japan and overseas, and management decisions related to new businesses.
Risk Management Initiatives
Tax Transparency Initiative
We have established a Group Policy on Tax Transparency to ensure that we pay taxes appropriately, which is one of our responsibilities as a corporation, while also managing tax risks appropriately and aiming to enhance our corporate value. We will also comply with tax-related laws and regulations in all countries and regions in which we do business and build a highly transparent tax governance system.
Strengthening Collaboration with Group Companies through Part-time Officers
To improve governance across the entire Group and achieve consolidated cash flow
management by business unit, we are working to strengthen communication with Group
companies through part-time officers who are dispatched to Group companies. The officers are
provided with “key points to bear in mind,” which summarize their roles and responsibilities.
Each part-time officer reports to the head office on the status and implementation of initiatives,
and by acting with an awareness of key points, they stimulate communication throughout the
Group, which leads to improved governance, the realization of consolidated cash flow
management, and enhanced corporate value.
Basic Approach to Compliance
Based on the Policy on Legal and Regulatory Compliance and
Corporate Ethics, we have established a Compliance Action Plan that
outlines how we should behave as a corporation and as members of
society. While building trust with all stakeholders, we comply with all
related laws in our various business fields, such as Mobility services and
Lifestyle Solutions services, and we have conducted business in
accordance with our corporate ethics.
As an improvement measure based on the report compiled by the
Expert Committee for Improving and Strengthening Group Governance,
in June 2026 we revised the Policy on Legal and Regulatory Compliance and Corporate Ethics and the Compliance Action Plan, and established
the JR East Group’s “Determination and Commitment” as the code of
conduct that serves as a guiding principle for everyone working within
the Group. Based on this “Determination and Commitment,” we will
continue working to further strengthen compliance.
Key Compliance Initiatives
You can swipe horizontally.
| What We Aspire To | Specific Initiatives | Status of Initiatives |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||
|
|
Systems and Mechanisms to Support and Encourage the Taking On of Bold Challenges
We have established systems and mechanisms that proactively
support and encourage employees to take on bold challenges
to develop the JR East Group and increase its value, and we are
constantly reviewing and improving them.
To encourage employees to take on bold challenges in their daily
work, we share best practices throughout the Group through
communication tools that can be viewed and posted by all
Group employees, and we also conduct employee engagement
surveys. We are working to create an environment that fosters
employee initiative and motivation by identifying the percentage of
employees who responded positively to “employee creativity rate”
in the survey.
We also actively communicate with frontline employees through
opinion exchange meetings, discussions, and on-site visits, with
the aim of spreading the management vision.
Percentage of employees who gave positive answers to relevant items in the engagement survey
Basic Approach to Risk Management
For the Group to improve profitability and undertake structural
reforms, we recognize the importance of broad-view risk
management that considers risk*not only from the perspective of
reducing negative factors such as avoiding losses but also from
the perspective of proactively increasing the value of the Group.
We have established and operate internal controls in accordance
with the Companies Act and the Financial Instruments and
Exchange Act to ensure stable and proper business operations,
while also working to develop the Group and support and
encourage the taking on of bold challenges aimed at enhancing
value and growth.
- *These include not only risks related to compliance, safety assurance, and natural disasters, among others, but also those related to market changes, trends of our competitors, social and economic conditions in Japan and overseas, and management decisions related to new businesses.
Risk Management Initiatives
- *1Challenge risks are risks that should be considered when implementing new measures or entering new businesses.
- *2Environmental change risks are risks that increase in importance with changes in the business environment.
Tax Transparency Initiative
We have established a Group Policy on Tax Transparency to ensure that we pay taxes appropriately, which is one of our responsibilities as a corporation, while also managing tax risks appropriately and aiming to enhance our corporate value. We will also comply with tax-related laws and regulations in all countries and regions in which we do business and build a highly transparent tax governance system.
Strengthening Collaboration with Group Companies through Part-time Officers
To improve governance across the entire Group and achieve
consolidated cash flow management by business unit, we are
working to strengthen communication with Group companies
through part-time officers who are dispatched to Group
companies. The officers are provided with “key points to bear in
mind,” which summarize their roles and responsibilities.
Each part-time officer reports to the head office on the status and
implementation of initiatives, and by acting with an awareness
of key points, they stimulate communication throughout the
Group, which leads to improved governance, the realization of
consolidated cash flow management, and enhanced corporate
value.
Basic Approach to Compliance
Based on the Policy on Legal and Regulatory Compliance and Corporate Ethics, the JR East Group has established a Compliance Action Plan that outlines how we should behave as a corporation and as members of society. While building trust with all stakeholders, we comply with all related laws in our various business fields, such as Mobility services and Lifestyle Solutions services, and we conduct business in accordance with our corporate ethics.
Key Compliance Initiatives
You can swipe horizontally.
| What We Aspire To | Specific Initiatives | Status of Initiatives |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||
|
|
Basic Policy for Information Security
System to Promptly Detect and Respond to Cyberattacks
Security Operation Center (SOC)
- Establishment of an SOC to monitor suspicious communications targeting the JR East Group
- Configuration of a framework that can analyze suspicious communications and escalate them in a timely manner
JR East Endpoint Security Service
- Deployment of integrated security products with malware detection and SOC coordination functions to each computer within the JR East Group
- Addressing of the increasing security risks associated with the expansion of remote working
ASM (Attack Surface Management)
- Introduced Attack Surface Management (ASM) in FY2026.3 as a means of identifying the Group’s IT assets exposed to the Internet and maintaining an up-to-date understanding of their status
- Strengthened cyberattack risk management by detecting signs of risk at an early stage and linking them to countermeasures
Information Security Initiatives
Security Education and Training
- Education for all employees to raise their awareness of cybersecurity
- Training for employees in each position within the implementation framework
- Ongoing response training at each Group company to prepare for a security incident
10 Principles of Information Security
- Distributed to each JR East Group employee as a set of rules that every employee must observe
Personal Data Protection Initiatives
Pursuant to applicable laws and regulations, including personal information protection legislation both in Japan and overseas, we are working to reduce the risk of data breaches by strengthening our personal information management system and reviewing our rules.
- Publication of Basic Policy for Personal Information Handling
- Formulation of internal regulations such as personal information management regulations
- Operational audits conducted at least once a year at all locations
- Publication of privacy policies in response to legislation in the European Union, the United Kingdom, and California, among other jurisdictions
- Regularly scheduled education and training through compliance and information security education and other such programs for all employees
Fundamental Approach to AI Governance
AI Policy
As we promote the use of AI across the Group’s diverse business
activities and customer touchpoints, including Mobility and Lifestyle
Solutions, we have established the JR EAST Group AI Policy to
maximize the benefits of AI under a governance framework that
identifies AI-related risks and responds to them appropriately.
The AI Policy consists of three components: Growth strategy
(value creation), Protection (safety and trust), and the
Foundations (human resources and organization) that support
them. These are expressed through a total of seven elements.
- Growth strategy (value creation): By addressing social issues and customers’ latent needs through the proactive use of AI, we will transform our ways of working and create new customer experience value.
- Protection (safety and trust): With people at the center, we will use AI safely by promoting a proper understanding of risks, respecting human rights, and ensuring compliance.
- Foundations (human resources and organization): We will deepen understanding of AI through continuous human resource development, promote the use of AI in collaboration with our partners, and respond appropriately through measures such as reviewing our management framework.
In addition, when introducing generative AI, the entire Group follows a process similar to that used for information security measures, confirming matters such as the intended use, the AI to be used, human rights and personal information protection, and the risk of hallucinations before implementation.
AI Policy
Our AI Policy consists of seven key elements and is structured around three components: value creation as a driver of growth, safety and reliability as a means of protection, and a foundation of people and organizational capabilities that support them.
Initiatives for Generative AI Governance
Establishing Guidelines for the Use of Generative AI
- Establishment of two sets of guidelines tailored for users and for those involved in implementation and development.
- Development of a checklist to verify risk mitigation measures.
Educational Content
- Distribution of materials that clearly explain the guidelines.
- Company-wide training to enhance knowledge of and raise awareness of generative AI risks.