Skip to main content

Overview of the Status of Internal Control System

The following is an overview of the status of implementation of the system to ensure the appropriate performance of the business operations.

1. Internal Control System as a Whole

  • In order to ensure the effective functioning of the Group’s internal control, the Company has established various basic policies to control the Group, and checks the development and implementation status of these policies in a timely manner by the Board of Directors, while analyzing events occurring both inside and outside of the Group and seeking continually to improve, enhance and strengthen the internal control system.
  • Guided by our Group purpose, "For a future of health wellbeing and financial protection," we are committed to building a strong corporate culture rooted in compliance and customer protection. This commitment is upheld by all executives and employees, who value "Integrity," "Self-Motivation" and "Diversity."
  • The Company has consolidated its business domains into "SOMPO P&C (Property & Casualty Insurance Business)" and "SOMPO Wellbeing," and has appointed a Business CEO to oversee each business domain. Additionally, under the supervision of the Business CEO, Executive Vice Presidents of business segments are assigned as the heads of each respective business. The Business CEO discusses management policies for each business segment at a committee (Management Board), which they chair, and after consultation with the Group CEO, implements important measures under their own authority. This establishes a system that enables swift, strategic, and critical decision-making for the Group, thereby promoting unified efforts across the Group. The Company also introduced a system supervised by Group CEO whereby Group Chief Officers are deployed as chief officers responsible for each functional area to exercise functions laterally across the Group including execution of strategies and important issues of the entire Group.
  • The Company has established a Group Executive Committee to discuss themes that significantly impact management, such as group-wide strategies and operational policies. By having the Group CEO, Business CEOs, Executive Vice Presidents of business segments, Group Chief Officers, and other relevant members participate, we have built a management structure that enables high-quality and swift decision-making, as well as deliberation on highly specialized areas.
  • Furthermore, a framework is being developed for promoting the initiatives for providing solutions to medium- to long-term social issues towards materializing SOMPO’s Purpose primarily by the Group Sustainable Management Committee. This committee is chaired by the Group Chief Sustainability Officer (CSuO) and its members include CSuOs from the Domestic P&C Insurance, Overseas Insurance and Reinsurance, Domestic Life Insurance and Nursing Care businesses, among others.

2. System to Control the Group Companies

  • The Company carries out management of Group companies in order to enhance the corporate value of the Group as a whole by way of approving important matters such as management plans for the Group companies, receiving reports from each company of the Group including the progress of the plan and occurrence of risk events, and taking effective measures as needed in accordance with the approval and reporting system.
  • We have established a specialized team dedicated to financial planning and analysis. This department monitors and analyzes the management performance of each company within the Group, going beyond quantitative aspects to assess and verify the probability and validity of their respective plans.
  • The Company strives to ensure appropriate business operations of the Group by verifying the status on the development and implementation of the systems for each of the Group companies that are established based on various basic policies of the Group, and providing guidance to each company of the Group as needed.
  • Some headquarter departments of our company and Sompo Japan operate as a single unit, allowing for continuous monitoring of performance and direct involvement in initiative development through mutual assignments.
  • As part of our efforts to strengthen the Group's audit framework, we have appointed an external specialist as Deputy Chief Audit Executive (CAE) to further enhance internal audit functions both domestically and internationally. Concurrently, to ensure the effectiveness of checks and balances and audit functions for business operations, we are continuously investing in improving the expertise of personnel responsible for risk management functions, including compliance, and internal audit.

3. Compliance System

  • The Company sets out policies for promoting the Group’s compliance annually, and makes each company of the Group to be thoroughly aware of such policies. Each company of the Group takes its own initiatives to enhance compliance in a systematic manner based on the established policies. The progress of compliance promotion is checked by the Group Executive Committee to verify the appropriateness of the measures being taken.
  • We have established the Group Compliance Code of Conduct, which defines the fundamental standards of conduct regarding compliance for all executives and employees of our Group. In addition, we are working to further instill understanding throughout the entire Group concerning the "Group Compliance Code of Conduct" and "SOMPO's Yes," which serves as the foundation for decision-making in daily operations.
  • The Company aims to prevent undesirable incidents by encouraging each Group company to more autonomously and thoroughly identify and assess risks, including those inherent in conventional operations and industry practices, and by establishing appropriate management systems tailored to those risks.
  • The Company and Group companies endeavor to detect legal violations and other inappropriate events at an early stage by developing structures such as the internal reporting system and internal audit system. We maintain internal and external whistleblowing hotlines and offer a Group-wide consultation service to address questions about the system. We actively promote the system, emphasizing how to use it and the protection against retaliation for whistleblowers, while also verifying its effectiveness. In addition, to enhance the reliability of our internal whistleblowing system, we are conducting a group-wide awareness survey and training for personnel involved in handling whistleblowing reports.
  • Our Chief Compliance Officer concurrently serves as the Chief Compliance Officer of Sompo Japan, leading the timely and appropriate sharing of information and enhanced coordination between the two companies. In addition, we promote timely and appropriate information sharing and collaboration with all Group companies. We are developing the necessary systems to ensure that our Group complies with laws and regulations and operates in the best interests of its customers, while also strengthening its monitoring functions for major compliance issues, etc., to identify potential issues within the Group and resolve them, and to further develop a sound internal control system.

4. System Regarding Strategic Risk Management (ERM)

  • The Company makes each company of the Group to be thoroughly aware of its management strategies and Group Basic Policy on ERM in order to facilitate progress of ERM and dissemination of its culture throughout the overall Group. Each company of the Group establishes strategic risk management systems suitable for the nature of its operation, corporate scale and characteristic, such as developing rules pursuant to the Group Basic Policy on ERM in order to facilitate progress of ERM and dissemination of its culture throughout the overall Group.
  • The Company formulates business plans that are consistent with the Sompo Group Risk Appetite Statement through deliberations by the Group Executive Committee and allocates its capital to each business unit based on the growth potential and profitability. Each business unit takes risks within the range of allocated capital in an attempt to achieve profit objectives established in the business plan. The Company carries out ERM based on the principle of the PDCA cycle, in which changes in the operating environment and progress in plans are periodically reviewed and the plans and capital allocations are revised as needed.
  • The Company comprehensively identifies significant risks surrounding the Group based upon the fundamental of risk assessment, builds and operates risk control processes which performs analysis, evaluation and control. For especially significant risks, the Group CRO gains insight into and examines such risks comprehensively. The Executive Vice President of the respective business segment, Group Chief Officers, etc. subsequently develop and implement response measures against risks that require a reinforced system to manage them through a discussion by the Group Executive Committee, etc. in order to improve the effectiveness of risk control. The Company also appropriately controls “emerging risks” that may materialize or transform in the wake of environmental and other changes, and thus possibly have a significant impact on the Group going forward, by keeping an eye on signs of evolving into serious risks. In addition, we are working to identify and address connected risks, such as those involving complex interdependencies, from a medium- to long-term perspective, and to proactively strengthen resilience.
  • The Company has established a function to ensure the appropriateness of the actuarial matters of the entire Group (the Group's actuarial functions) that oversees Group companies based on the Actuarial Basic Policy. Furthermore, in light of the introduction of new solvency regulations based on economic value, The Company revised related basic policies and regulations, and established a verification function for solvency margin ratios based on laws and regulations, as well as a system for reporting verification results to the Board of Directors.
  • The Company has established the Group ERM Committee as a subordinate organization of the Group Executive Committee. The Group ERM Committee discusses on a Group-wide basis the important issues concerning the strategic risk management as well as material risks surrounding the Group.

5. Structure for the Execution of Duties

  • The Company sets out mid-term management plans and fiscal year plans for the Group, which are shared by each company of the Group. Each company of the Group sets out its own mid-term management plans and fiscal year plans that are consistent with plans made on a Group basis, so as to ensure the Group-wide cohesiveness. In addition, the Group promotes enhancement in its IT governance, which is at the base, to develop and promote various measures that contribute to business operation with high reliability, convenience and efficiency for Group companies.
  • The Company is working to strengthen effective cybersecurity measures and resilience across the entire Group, in response to the recent intensification of cyberattacks. Specifically, The Company is reviewing its risk management framework, including the establishment of a "Group SOC" (Security Operation Center) that centrally monitors data from each company's security devices and the strengthening of the second line of defense (checking and monitoring functions) in accordance with the Financial Services Agency's guidelines, etc. Furthermore, The Company is striving to improve its ability to maintain business continuity and achieve early recovery in an emergency through practical cyber exercises.
  • The Company is advancing the sophistication of its business continuity management system (BCM system) aimed at continuing core operations and ensuring early recovery in the event of crises such as large-scale natural disasters. In fiscal year 2025, The Company particularly strengthened its measures against the Nankai Trough Earthquake by formulating a new group-wide response policy for when "emergency information" is issued, and by conducting group-wide drills based on this policy to improve the effectiveness of its response. Furthermore, to enhance its response capabilities for crises spanning both domestic and international fronts, The Company unified its domestic and international crisis response contact points and rules.
  • The Company, in promoting the introduction of AI technology for business automation and sophistication, has newly established the "SOMPO Group AI Governance Basic Policy" to appropriately manage AI-specific risks and ensure safe and responsible utilization. The Company is thereby working to build and operate an AI governance framework for the Group.
  • The Company has newly established the "Group Investment Committee” as a subordinate organization to the Group Executive Meeting, with the aim of strengthening management discussions regarding asset management challenges faced by the Group. Using what is best for the group as a decision criterion, the committee deliberates on asset management policies and risk-taking directions across the Group, and by promoting intra-Group collaboration, it aims to strengthen asset management governance.
  • Matters that may significantly affect the Group management, such as mid-term management plan and decisions on policies for M&A, are duly deliberated at the Group Executive Committee in order to enhance the efficiency and effectiveness of resolutions by the Board of Directors.

6. Audit System by the Audit Committee

  • In order to ensure the effectiveness of audit by the Audit Committee, the Company establishes an Audit Committee Office that is independent from commands and orders given by executive officers, and appoints exclusive staff.
  • The Company formulates rules concerning the reporting to the Audit Committee, who receive reports from executives and employees on primarily the status of their duty execution periodically. In addition, reports are made promptly on matters requested by the Audit Committee. In addition, the Audit Committee receive reports from the Group CRO and the officer in charge of compliance on a quarterly basis (and whenever necessary) on the overall internal control system, the status of responses to major risks in the Group, the status of the occurrence of misconduct and major incidents at subsidiaries, and the status of implementation of measures to prevent recurrence, etc., in order to improve the effectiveness of audits from an independent perspective from the execution of operations.
  • The Company ensures opportunities for the members of the Audit Committee selected by the Audit Committee to express opinions by attending important meetings.
  • The Company ensures opportunities for the members of the Audit Committee or the Audit Committee to exchange information with the independent accounting auditor and internal audit sections on the audit results, etc.
  • The Company convenes periodic meetings where the members of the Audit Committee meet with representative executive officers to exchange opinions regarding the recognition of the Group’s important issues. The members of the Audit Committee also perform onsite audit, etc. at the Group companies, and exchange information with the representative, etc. and the Audit & Supervisory Board members, etc. of the respective companies.
  • linkedin
  • facebook
  • x
  • line