Risk Management

The GMO Internet Group always aims to prevent and reduce risks and is dedicated to strengthening its risk management to ensure the smooth continuation of business activities.

If a large risk does arise, we will respond in a swift and fitting manner based on the Venture Spirit Declaration and the GMO Internet Group Compliance Declaration to minimize the damage (loss) incurred by humanity, society, and the economy. In the unlikely event of a risk arising, we will strive to have an ever prepared and operational risk management system that can respond immediately.
By having an effective risk management system in place, our goal as a group is to protect our services, our customers, and our partners (employees) and create smiles and inspire everyone involved as we continue to grow.

Management system

GMO Internet Group has established a risk management system designed to assess uncertainties and potential impacts, or risks, arising from changes in the business environment that could affect the achievement of our management objectives, and to enable prompt responses to such risks.

To identify and analyze risks from multiple perspectives, the Group Risk Management Division coordinates and shares information with business divisions and Group companies. Identified risks and the status of risk responses are reported to the Risk Management Committee, which comprises assistants to the Group CEO and the heads of relevant divisions and departments.

The Risk Management Committee identifies and prioritizes material risks, designates the responsible persons or departments as risk owners, and deliberates on and instructs necessary countermeasures. The Committee also reports its activities to the Board of Directors on a regular basis. The Board of Directors receives reports on identified risks, matters of concern, and the status of ongoing monitoring, and reviews the effectiveness of the Group’s risk management system.

Risk Management Approach

GMO Internet Group identifies risks that could have a significant impact on the Group’s brand or management by referring to frameworks and standards such as COSO and GRI, taking into account the diverse characteristics of its businesses, and incorporating company-specific risk identification and assessment results from Group companies.

The Group Risk Management Division convenes the Business Risk Committee, a forum for dialogue with Group companies. Through this dialogue, the Division assesses the potential impact and likelihood of risks in each business, discusses risks that require priority management and the necessary response measures, and monitors the status of responses by each Group company.

By continuously operating this plan-do-check-act (PDCA) cycle and reviewing and improving risk areas, the Group implements enterprise-wide risk management.

In addition, the Group Risk Management Division oversees the Compliance Declaration and communicates it regularly to Partners across the Group. It has also established reporting protocols for material risk information, including incidents, misconduct, and other irregularities at Group companies. When such matters arise, the Division works to ensure a prompt initial response and early resolution, while supporting measures to prevent recurrence.

Internal reporting system

GMO Internet Group has established various helplines to respond properly to stakeholders' feedback, questions, and concerns.

  • GMO Helpline/Nadeshiko Helpline

    In order to discover, ameliorate, or prevent all compliance risks, including overall bribery and corruption prevention in business activities, and human rights infringements at an early stage, we have a system that enables partners to consult with the company or solve problems, without undue worry, if they become aware of fraudulent acts or illegal acts in work, or if they see or hear acts that may be illegal though it's uncertain whether the acts are clearly illegal. We also have female consultants in case the female partners are unlikely to consult with male consultants (available for use by male partners as well). Whistleblowing can also be anonymous.
    Personal information, comments, or details of the consultation of individuals who consult with us will be managed under strict guard and we will never leak them to third parties without their acceptance. Retaliation against partners who have reported violations of laws and regulations to the company is prohibited if the reason behind it is whistleblowing.

  • External helpline to report problems

    If the actions of our directors, partners, etc. are a possible violation of laws and regulations, we have an external helpline to report (or facilitate consultation on) those problems. This helpline is available for use by anyone outside the company, which includes customers and retired workers. Whistleblowing can also be anonymous.

Information security

The company has positively viewed the protection of information security as one of its key social responsibilities and formulated the Basic Information Security Policy and Twelve Commandments of Information Security Conduct Guidelines, and the management system has been established.

Furthermore, GMO Internet Group owns GMO Cybersecurity by Ierae, Inc., which is Japan's leading white hat hacker organization, and has been providing a high degree of security measures against cyberattacks that are increasing significantly in and outside of Japan. In addition to vulnerability diagnosis for web and smartphone applications (security diagnosis) and penetration tests within the Group, GMO Internet Group implements initiatives to continue a sustainable business operation through guidance and seminars on cyber defense for partners who belong to our group.

Privacy policy

At GMO Internet Group, in order to gain our customers' trust, we take care to maintain high moral standards and engage in fair business practices taking into account the specialized nature of GMO's operations. GMO Internet Group will comply with guidelines relating to personal information protection set forth by the government agencies or industry associations and the laws and regulations.

Related contents