Skip to main content

Business and other risks

1. Management system and framework for major risks

(1) Overview of risk management system

Sompo Group operates an Enterprise Risk Management (ERM) framework to manage risk across the Group, serving as a sophisticated ‘compass’ that points the business towards the optimal direction. This embraces not just the avoidance of losses, but also the avoidance of opportunity losses for profitable risk-taking. These include, for example, potential new business investments in response to risks identified. The ERM system seeks to achieve these goals by providing and strengthening the following "three capabilities":

a.Correct understanding of the Group’s current position

b. Sensitive detection of potential risks

c.Clear indication of the routes the Group should take

ERM is effected through a series of business management processes that look to maximize corporate value by achieving a balance of capital, risk, and profit through management of the two objectives: "risk-taking for business strategies" and "risk control for a stable business foundation". In the risk-taking context, we make use of analyses on capital, risk, and profit within the Risk Appetite Framework for important management decisions, corresponding to (c) in the above diagram. For risk control, we use a framework – the Risk Control System – to identify, analyze, and assess various types of risks surrounding the Group, aiming to minimize unexpected losses and to increase the stability of profit. This corresponds to (a) and (b) in the diagram above.

<Overview of the Sompo Group's Enterprise Risk Management>

Overview of the SOMPO Group’s Enterprise Risk Management (ERM)

(2) Risk Management Governance Structure

In order to ensure the effectiveness of "ERM" based on the "Sompo Group Basic Policy on ERM" established by the Board of Directors, "Sompo Group’s Risk Appetite Statement" – consisting of the Risk Appetite Principles, the Medium-term Risk-taking Strategy, and the Risk Appetite Indicator – is used as a guideline for risk-taking, in alignment with the Group’s strategies and business management plans.

The Group Executive Committee, an advisory body to the Group CEO, regularly holds management discussions on matters related to risk management, including the Group's risk appetite statement, medium-term Group ERM promotion policy, and risk tolerance policies and measures.

The Group ERM Committee, chaired by the Group CRO, has been established as a subordinate body of the Group Executive Committee to conduct cross-sectional management discussions on important Group ERM issues, such as risk-taking strategies, and the status of control of material risks by the department with primary responsibility and risk management department.

The results are reported to the Board of Directors through the Group Executive Committee, and we have established a framework to continuously enhance governance pertaining to group risk management, incorporating advice and recommendations from the Board.

The Group CRO ensures that the "Sompo Group Basic Policy on ERM" and the "Medium-term Group ERM Promotion Policy" are known to all Group companies, and works to improve the effectiveness of ERM for the entire Group through regular monitoring and discussions with the CROs of each company.

Group companies have established risk management systems in line with Group policies and manage risk autonomously.
The Company and its major subsidiaries have adopted a “three lines” model:
First line: Each department or business unit responsible for developing and implementing policies and measures within our company and its key subsidiaries autonomously manages its own risks.
Second line: The risk management department, along with the department in charge of relevant duties businesses, oversees and supports first line’s risk management activities.
Third line: The internal audit section independently evaluates the validity and effectiveness of the overall risk governance framework.
These measures collectively ensure and enhance the effectiveness of the Group’s risk management system.

Risk Management Governance Structure

(3) The Risk Control System and the status of risk and capital

Under the Risk Control System, we conduct risk assessment using "the Material Risk Management" framework – firstly identifying all the material risks we face, then evaluating them from both a qualitative and quantitative perspective. For risks that can be quantified, their impacts on capital adequacy and liquidity are analyzed and assessed based on various quantitative indicators in "Capital adequacy management", "Stress testing", "Limit management", and "Liquidity risk management" frameworks. Based on these analyses, the management decides necessary risk control measures to secure and improve the Group’s financial soundness.

A.Material Risk Management

We define "risks that could have significant impacts on the business" as "material risks" and comprehensively capture and evaluate the risks faced by our business through bottom-up risk assessment and top-down confirmation and discussion by the Board of Directors and others. In conducting risk assessment, we have clarified the criteria so as to emphasize the reputational impact from the viewpoints of customers, society, and other stakeholders, in addition to economic loss and business continuity.

Material risks are comprehensively identified by the Group CRO based on risk assessments and the views of experts, etc., and risks are evaluated both qualitatively and quantitatively in terms of likelihood of occurrence and impact, based on specific scenarios of impact of risks on the Group, and the management status is discussed in the Group ERM Committee, then reported to the Group Executive Committee and the Board of Directors at least twice a year.

Risks for which the risk management structure should be reinforced are raised at the Group Executive Committee. Further, we have defined “emerging risks” as risks that, although it is difficult at this time to evaluate risks based on specific impact scenarios, have the potential to emerge or change due to changes in the environment and have a significant impact on our group in the future, and we manage them appropriately by associating them with individual material risks. In selecting emerging risks, the Group gathers information from various public and private sources, identifies potential candidates based on their possible future impact, and then designates them as emerging risks based on their materiality.

B.Capital Adequacy Management

We quantify the insurance underwriting risks, asset management risks, nursing risks, and operational risks we are exposed to maintain a sufficient level of capital relative to risks. A system has been established so that countermeasures are properly implemented if necessary.

C.Stress Testing

We conduct "scenario stress testing", "reverse stress testing", and "sensitivity analyses" on a Group-wide basis to accurately identify and manage events that could significantly affect its business management. We analyze the impact on both capital and risk and take countermeasures as required. As at the end of March 2026, we confirmed that the Group retains sufficient capital even under any of the assumed stress scenarios.

Scenario
Stress Testing
We evaluate how significantly large-scale natural catastrophes, financial market disruptions, and other stress scenarios could affect business, verifying capital adequacy and the effectiveness of risk mitigation measures. We regularly verify the validity of stress scenarios to ensure that we can respond appropriately to environmental changes.
Reverse Stress
Testing
We identify vulnerability by exploring specific events that breach risk tolerance levels and consider appropriate countermeasures for specific stress events in advance.
Sensitivity
Analyses
We identify the impact on capital and risk from fluctuations in key risk factors. Also, we validate in-house models by comparing theoretical figures calculated by the models with the figures of actual results.

D.Risk Limit Management

We have established the maximum limit for each risk on a Group-wide basis such as credit risk, reinsurance counterparty risk, and natural catastrophe risk to avoid outsize losses arising from the occurrence of specific events. The Group sets the limits within the maximum limits based on risk characteristics and has established a system to take appropriate measures when those limits are exceeded. As at the end of March 2026, we have confirmed that each risk was appropriately controlled.

E.Liquidity Risk Management

In addition to projecting cash requirements for day-to-day operations, we project the maximum cash outflows that could result from events such as a large-scale natural catastrophe. We then conduct management to ensure we have sufficient liquid assets to meet cash requirements in these scenarios. As at the end of March 2026, we have confirmed that the Group has adequate liquid assets to meet such outflows.

2. Major risks

(1) Material risks and the assessment of their likelihood and impact

Risks that management recognizes as having the potential to significantly impact the Group’s operating results and other factors are managed as ‘material risks’ in the Group. The risk scenarios for each material risk are reviewed from time to time in light of the latest business environment and other factors, and the impact and likelihood of occurrence are also reassessed in line with these scenario reviews.

Furthermore, from among the material risks, we identify ‘major risks’ which, based on management discussions, are considered to require a high priority for strengthening our management framework.

For these risks, we establish target states and action policies before implementing countermeasures; we discuss the status of risk management at the Group ERM Committee; and we report regularly to the Group Executive Committee and the Board of Directors, thereby striving to strengthen our management framework.

A summary of these risks is set out below. Furthermore, an overview of the major risks and the status of countermeasures is provided in section (2).

<List of Material Risks and Major Risks>
Significant change in macroeconomic environment
Geopolitical risk
Significant market deterioration
Reinsurance and investment credit risk
Changes in regulatory systems
Deterioration/transformation of competitive environment
Climate Change (Physical risk)
Mega earthquake in Japan
Huge wind and flood disaster in Japan
Mega natural disasters overseas
Sustainability risk
Conventional Terrorist Attack
Cyber aggregation risk
Business Interruption
Pandemic
Risks related to outsourcing
Liquidity in the event of a major disaster
IT failures
Cyber security breach
AI-related risks
Leakage of confidential and customer information (excluding cyber attacks)
Compliance risk
Serious misconduct in the nursing care business
Conduct risk
Reputational risk
Insufficient governance (Failure of internal controls)
Misjudgment of risks associated with new business
Misjudging the long-term nursing care business environment
IT Strategy risk
Risks related to Human Capital
  • ”○” indicates material risk and “●” indicates major risk

(2) Overview of Major Risks and Status of Countermeasures

Geopolitical risk

(Probability of occurrence: Large;
Impact: Medium)

<Risk Overview>

  • Ripple effects on the Group arising from a tit-for-tat exchange of sanctions or the occurrence of major incidents due to heightened geopolitical tensions (e.g. a decline in the value of financial assets, an increase in insurance payouts, business interruption, etc.)

<Status of Countermeasures>
Drawing on the expertise of external specialists, we are investigating scenarios that could have a significant impact on our Group, verifying the financial implications in light of market trends, and monitoring the situation closely to ensure we can identify management risks in a timely manner. Furthermore, we have established manuals setting out the actions to be taken by executives and staff in the event of a crisis, as well as business continuity plans, and we are striving to maintain an effective crisis response system through training and self-assessments.

Climate Change (Physical risk)

(Probability of occurrence: Medium;
Impact: Large)

<Risk Overview>

  • Impact on underwriting results arising from the occurrence of massive wind and flood damage (including snow and hail damage) exceeding expectations due to climate change, or from an increase in the frequency of such events
  • Accumulation of risk and reduced profit stability due to a tightening of the reinsurance market and a significant reduction in reinsurance capacity as wind and flood damage expands

<Status of Countermeasures>
We are conducting analyses to understand the long-term impacts, under a climate characterised by rising average temperatures, of changes in average trends—such as those affecting typhoons, floods and storm surges caused by changes in sea level—as well as trends in the occurrence of extreme disasters. In conducting these analyses, we are carrying out risk assessments utilising not only research findings from external organisations such as the IPCC (Intergovernmental Panel on Climate Change) and the NGFS (Network for Global Financial Stability on Climate Change Risks), as well as scientific insights obtained through collaboration with research institutions such as universities, but also meteorological and climate big data and the natural disaster risk model of the General Insurance Rating Organisation of Japan.
Furthermore, in order to manage the impact of massive wind and flood damage on our Group, we are revising our products and underwriting conditions.

Risks related to outsourcing

(Probability of occurrence: Large;
Impact: Large)

<Risk Overview>

  • A situation arising where the continuation of outsourced operations becomes difficult due to a lack of operational capability, financial collapse, breaches of laws and regulations, inappropriate conduct, or the withdrawal of services by key external contractors, including agencies, leading to the payment of compensation or damage to our reputation

<Status of Countermeasures>
We exercise appropriate management over general external contractors in accordance with our Basic Policy on External Contracting Management and other relevant guidelines; furthermore, with regard to agencies to which we outsource insurance sales, we provide guidance and supervision in accordance with separate relevant regulations and other guidelines.
In accordance with the administrative sanctions imposed on our Company and Sompo Japan Insurance Inc. (hereinafter referred to as ‘Sompo Japan’), our Group is implementing a business improvement plan. Under the Business Improvement Plan, we are implementing measures to establish an effective agency management framework, whilst fostering a sound corporate culture that prioritises compliance and customer protection, and working to instil the principles of conduct that must be observed in order to transform the awareness, mindset, values and behaviour of Group executives and employees.
Furthermore, we are striving to enhance the effectiveness of the Group-wide internal control system not only by establishing frameworks to ensure appropriate corporate activities in accordance with laws, regulations, social norms and corporate ethics, but also by analysing specific cases of misconduct occurring across Group companies and implementing measures to address common issues.

Cyber security breach

(Probability of occurrence: Large;
Impact: Large)

<Risk Overview>

  • The risk that a cyber attack could result in a security breach affecting our Group, our agents or contractors, leading to the shutdown or malfunction of information systems, unauthorised use, data destruction or tampering, a serious data breach, or disruption to the supply chain
  • In addition to the costs of investigation and recovery, lost opportunities due to service interruptions, and the impact on business transactions resulting from damage to reputation, there is a risk of non-compliance with national laws and regulations, such as the Personal Information Protection Act and the EU General Data Protection Regulation (GDPR)

<Status of Countermeasures>
Recognising that continuously improving our response capabilities is of paramount importance in the face of cyber attacks that are becoming increasingly sophisticated and intricate on a daily basis, the SOMPO Group has established the ‘SOMPO Group Basic Policy on Cyber Security’ and is striving to develop a cyber risk management framework across the entire Group.In addition to operating ‘CyberMetrics’—a system that quantitatively monitors and visualises the status of cybersecurity measures across Group companies—we have established a Cyber Centre of Excellence (CoE) within the Company. By working together as a unified Group, we are tackling cybersecurity measures and striving to continuously improve our response capabilities.

AI-related risks

(Probability of occurrence: Large;
Impact: Medium)

<Risk Overview>

  • The risk that, when developing systems incorporating generative AI, we may be unable to prevent infringements of intellectual property or privacy, or the generation of false information, resulting in erroneous decisions or the spread of rumours, etc.
  • The materialisation of the above risks due to deficiencies in rules such as regulations and guidelines governing the use of AI, or in their implementation, or due to a lack of AI literacy among executives and staff

<Status of Countermeasures>
We are establishing a governance framework through the formulation of the ‘SOMPO Group Basic Policy on AI Governance’, regulations concerning risk assessment when introducing AI tools, and user guidelines, whilst also working to enhance their effectiveness. Where a system under development is assessed as ‘high risk’, we commission third-party expert model testing and implement necessary measures based on the results.
We have made in-house training aimed at developing AI literacy compulsory, with a view to enhancing the knowledge of employees who utilise AI and ensuring that rules are firmly established.

Leakage of confidential and customer information
(excluding cyber attacks)

(Probability of occurrence: Large;
Impact: Large)

<Risk Overview>

  • Payment of compensation and damage to reputation at Group companies resulting from serious information leaks caused by directors and employees

<Status of Countermeasures>
We have established the ‘SOMPO Group Basic Policy on Customer Information Management’ and other guidelines. To safeguard and handle customer information appropriately, we have put in place a management framework comprising various security measures, with the aim of preventing serious information leaks before they occur.
Furthermore, we are working to strengthen preventive controls across the entire Group by analysing specific cases of information leaks and implementing measures to address issues common to the Group.

Compliance Risk

(Probability of occurrence: Large;
Impact: Very Large)

<Risk Overview>

  • Violations of laws and regulations applicable to each of the Group’s businesses, or those applicable in the countries and regions where we operate overseas, and the resulting payment of fines and other penalties; misconduct by directors, officers and employees; criminal acts by external parties; and the payment of compensation arising from litigation, etc.
  • Loss of social trust and credibility in the Group resulting from legal violations or scandals

<Status of Countermeasures>
We are striving to enhance the effectiveness of the Group-wide internal control system not only by establishing frameworks to ensure corporate activities are conducted appropriately in accordance with laws, regulations, social norms and corporate ethics, but also by analysing specific cases of misconduct occurring at Group companies and implementing measures to address common challenges across the Group. We are promoting the instilling and embedding of compliance awareness among our executives and employees by conducting training on the ‘SOMPO Group Compliance Code of Conduct’ and ‘SOMPO’s Yes’—a set of decision-making criteria designed to guide executives and employees towards correct judgements and actions in the course of their duties. Furthermore, to facilitate the early detection of misconduct and similar incidents, we have established a Group-wide consultation desk for the use of the internal reporting system, and we are operating this system whilst verifying its effectiveness.

Conduct Risk

(Probability of occurrence: Large;
Impact: Very Large)

<Risk Overview>

  • Damage to corporate value arising from a gap between the products, services and business practices provided by our Group and the expectations of society and stakeholders, including our customers
  • The possibility that our Group’s governance regarding products, services, the collection of personal data and the use of AI may fall short of stakeholder expectations and adversely affect market integrity

<Status of Countermeasures>
To foster a sound corporate culture that prioritises compliance and customer protection, we have formulated the ‘SOMPO Group Compliance Code of Conduct: Practical Guidelines’ and ‘SOMPO’s Yes’, which apply to all Group executives and employees, and will continue to carry out awareness-raising and training activities to ensure their widespread adoption.

Insufficient governance (Failure of internal controls)

(Probability of occurrence: Large;
Impact: Large)

<Risk Overview>

  • Risks arising from the inadequate functioning of Group governance functions (including the establishment and operation of internal control systems); for example, the failure of the Company’s supervisory functions due to a lack of communication and information sharing between the Company and Group companies; and the inability to achieve strategic objectives, non-compliance with regulations, or damage to reputation resulting from the malfunction of internal control systems relating to decision-making processes, etc.

<Status of Countermeasures>
To ensure that group governance functions appropriately, we are proceeding with the verification and strengthening of management and monitoring systems designed to assess the adequacy and effectiveness of group companies’ internal controls in a timely and appropriate manner, on a risk-based approach. Specifically, we are strengthening our supervisory framework through measures such as having the Company’s Representative Executive Officer concurrently serve as a director of Sompo Japan. Furthermore, we are working to enhance communication between the Company and Group companies—including the reporting of adverse information—as well as to promote the use of the internal whistleblowing system and foster a culture of speaking up.

Risks related to Human Capital

(Probability of occurrence: Large;
Impact: Large)

<Risk Overview>

  • The risk that, by failing to realise a ‘supportive working environment’, ‘the growth of employees and the organisation’, and ‘job satisfaction’, employees will be unable to take on challenges, learn and enhance their expertise, thereby preventing the creation of new value and the realisation of sustainable value creation.
  • The risk that it will become difficult to secure and retain high-calibre talent, making it impossible to implement strategic staffing, which will lead to a decline in productivity and corporate competitiveness

<Status of Countermeasures>
Based on ‘SOMPO’s Values (Integrity, Autonomy, Diversity)’, we are implementing a human resources strategy aimed at maximising ‘workplace comfort’, ‘the growth of employees and the organisation’, and ‘job satisfaction’.
To enhance ‘workplace comfort’, we are working to improve employee wellbeing through measures such as improving the office environment, promoting health management (including the prevention of excessive working hours) and eradicating harassment. Furthermore, we are fostering a culture in which diverse talent can thrive inclusively through measures such as strengthening support systems to help mid-career recruits become productive as soon as possible and implementing various DEI initiatives.
With regard to ‘the growth of employees and the organisation’, we are supporting employees in shaping their own careers by making large-scale investments in human resources to promote self-directed learning through the ‘SOMPO Human Resources Fund’, establishing and operating job-based HR systems and job challenge schemes, and creating an environment where employees can flexibly choose their working styles in line with their career aspirations and life events. Furthermore, to enhance our competitiveness in recruitment, we are working to diversify our recruitment channels and strengthen our employer branding.
Through these initiatives, with the aim of steadily improving ‘job satisfaction’, we conduct regular engagement surveys and have established an organisational PDCA cycle that utilises the results.

  • We also appropriately manage material risks not listed here by monitoring the status of risk controls and strengthening countermeasures where necessary.

(3) The status of Emerging Risks

The status of emerging risks is as follows.

Innovative medical technology Overview of risks and effect to business
  • The possibility of changes in insurance needs due to changes in treatment methods for diseases and injuries caused by innovative medical technologies.
  • Possibility of significant fluctuations in projected benefit payments due to the large portofolio of helth-related insurance products in the life insurance business and the spread of innovative diagnostic and treatment technologies in the market, leading to earlier detection of diseases, higher survival rates, and longer treatment periods.
Examples of countermeasures Investigating the landscape and impact of innovative medical technologies. Analyzing the implications of the research findings on future insurance businesses, and considering future responses, such as utilizing the findings for the development of products and services.
Biodiversity Overview of risks and effect to business
  • Stricter regulations and changes in government policy related to biodiversity loss.
  • Reputational risks and a decline in corporate value resulting from inadequate initiatives or information disclosure regarding products and services.
  • In terms of physical risks, the decline in disaster prevention and mitigation functions provided by ecosystems, resulting from the loss of biodiversity, leads to an increase in property damage, thereby driving up insurance payouts—such as those for fire insurance—and reinsurance costs.
  • In terms of transition risks, a decline in insurance premiums and investment returns resulting from the deteriorating performance of sectors heavily reliant on nature, due to the degradation of ecosystem services. Furthermore, there is a possibility of an increase in liability insurance payouts arising from nature-related litigation and similar cases.
Examples of countermeasures Continuously monitoring trends in biodiversity and natural capital disclosure standards and assessing their impact on our company. In addition, analyzing our insurance business value chains, both domestically and internationally, to understand our dependence on and impact on biodiversity and natural capital.
Critical infrastructure outages due to highly uncertain factors Overview of risks and effect to business
  • Interconnected global critical digital infrastructure (such as power grids, submarine cables and satellite communication networks) is relatively vulnerable to physical disruption and is highly susceptible to external shocks characterised by a high degree of uncertainty—such as severe space weather (including solar storms and geomagnetic storms) and the physical destruction of submarine cables—which go beyond conventional natural disasters.
  • External shocks such as those described above could lead to large-scale and prolonged infrastructure disruptions, resulting in substantial, unforeseen insurance payouts (such as claims for business interruption), whilst also posing a threat to the Group’s own business continuity, particularly the provision of its critical care services.
Examples of countermeasures Assessing the impact on the business through conducting research and analysis, etc. on the likelihood of disasters caused by various highly uncertain factors, including solar storms, and their potential impact on critical infrastructure.
Changes in societal expectations and standards related to business and human rights Overview of risks and effect to business
  • Rapid changes in global values have heightened society’s awareness of business and human rights, and these changes are outpacing the evolution of the relevant legal, regulatory and guideline frameworks.
  • Rapid changes in global values have heightened society’s awareness of business and human rights, and these changes are outpacing the evolution of the relevant legal, regulatory and guideline frameworks.
Examples of countermeasures Publishing policies aligned with the requirements of business and human rights regulations and guidelines, enhancing human rights risk assessments, and engaging in dialogue with stakeholders. Establishing a system for implementing human rights due diligence across the entire group.
  • linkedin
  • facebook
  • x
  • line