Search suggestions

Risk Management

NSK’s Approach

NSK defines the purpose of enterprise risk management (ERM) as “effectively utilizing Group-wide resources and managing the impact of uncertainty related to the realization of the NSK Group Corporate Philosophy and the achievement of management goals.” ERM consists of two components: “risk management,” which aims to manage impacts due to uncertainty, and “incident management,” which aims to manage the response to incidents and accidents that have already occurred.

To achieve the purpose of ERM, based on the “Three Lines” model, NSK has established a management and governance framework that stretches from the Board of Directors to each site within the Group. Under this framework, risk management and incident management are conducted. The details are as follows.

ERM System

◆Management and Governance Framework

We have designated the companies, sites, and divisions that are actually exposed to risks or where incidents occur, such as plants and sales offices, as first-line risk response divisions. In addition, we have established second-line risk management divisions with responsibility for managing risks and incidents related to different types of risk. We have also created the Risk Management Oversight Division to oversee ERM as a whole and support the CEO and CFO in being able to supervise the status of risk and incident management by the risk response divisions and the risk management divisions. Finally, the Internal Audit Department serves as the third line, auditing the status of activities by the first- and second-line divisions and evaluating their effectiveness. 

We have positioned the Operating Committee, which is an advisory body to the CEO, at the center of executive decision-making in ERM. The Operating Committee determines the material risks to be managed, and the details of its deliberations are also reported to the Board of Directors. We have also built a framework for regularly reporting to the Board of Directors the details of the risks subject to management as determined by the Operating Committee, the status of the response to such risks, and the status of the response to incidents.

Determination of Group-Wide Level Risks (Risk Assessment)
Determination of Group-Wide Level Risks (Risk Assessment)
Enterprise Risk Management (ERM) System
Enterprise Risk Management (ERM) System

ERM Operational Status

◆Risk Management

We conduct risk assessments once a year covering each of our sites around the world. At the start of the risk assessment, we disseminate the risk recognition of the CEO and of the heads of each risk management division (the heads of the business division headquarters and the heads of the functional division headquarters). The assessments are carried out by the risk response divisions and risk management divisions in accordance with these risk recognitions. Risks are weighted according to likelihood of occurrence and impact of residual risk. For particularly material risks, risks subject to management are determined after deliberation by the Operating Committee. The Operating Committee meets to discuss not only risks identified through the bottom-up approach but also risks that are important for management strategy (including emerging risks), which are identified by corporate leadership. 

Risks subject to management are categorized into Group-wide level risk determined by the Operating Committee and risks to be managed by each headquarters and site (“headquarters-level risk” and “on-site level risk” respectively). Following this process, we carry out response activities and monitoring for these risks. The response status for Group-wide level risks is regularly reported to the CEO and CFO, as well as to the Board of Directors. When a material risk arises during the fiscal year, it is added as a new risk to be managed.

◆Incident Management

Whenever an incident meets certain reporting criteria, an initial report is made to the risk management division responsible for that risk area the incident falls under. Particularly serious incidents are also reported to the CEO and CFO. Following such reports, an action plan is formulated for each incident. As the plan is executed, the status of the response is reported regularly until the incident is resolved. 

◆ERM Training

We carry out regular ERM training to upgrade the level of ERM and foster a sound risk culture.

ERM Operational Status List

ActivitiesFrequencyNotes
Risk assessmentOnce a yearWhen new risks arise during the fiscal year, they are registered as risks subject to management.
Regular reporting of Group-wide level risks and serious incidents to the CEO and CFOOnce a monthGroup-wide level risks, the occurrence of incidents, and the status of responses are reported to the CEO and CFO by the risk management divisions or the Risk Management Oversight Division. Particularly material issues are also reported at meetings of various committees chaired by the CEO.
Reporting to the Board of DirectorsSeveral times a yearThe status of ERM is reported by the CEO or the head of the Risk Management Oversight Division.
ERM educational activitiesAs necessaryIn April 2026, we held a training session for officers including the CEO and CFO. We also hold e-learning programs for employees every year (approximately 400 employees at 28 Group companies participate).

In addition to ERM as described above, we manage individual risks in each business process. For example, we operate our original NSK Product Development System (NPDS) as a mechanism for managing quality risk in each process from product planning though development and mass production. In addition, when introducing equipment, we carry out a risk assessment related to safety aspects and work to reduce risks.

Material Risks in FY2026

Risk ItemDetails of Representative RisksCountermeasures
(1) Geopolitical risks
  • Risk of logistics disruptions, difficulties in procurement, production stoppages, and surging prices of raw materials and energy due to international conflict
  • Risk of the trade and economic security policies of various countries impacting NSK’s profit 
  • Visualize the supply chain and examine various alternative options 
  • Collect information in a timely manner and make subsequent adjustments to sales prices while considering changes to the location of production
(2) Risks associated with technological innovation
  • Risk of delayed development response to market changes and customer technology demands brought on by technological innovation
  • Ensure development plan management and operation based on mid- to long-term policies
  • Leverage open innovation and alliances
(3) Risks associated with safety, prevention of fire, and natural disasters
  • Risk of operations being impacted by an inadequate BCP response to events such as a natural disaster or pandemic
  • Risk of a major industrial accident occurring
  • Risk of a halt in operations due to a fire
  • Prioritize through impact analysis and specify and implement concrete countermeasures
  • Strengthen management systems and step up preventive activities at priority business sites
  • Enhance group-wide in-house training activities
(4) Risks associated with quality
  • Risk of occurrence of serious quality problems
  • Risk of decline in capability to deal with problems due to shortcoming in quality assurance system
  • Risk of quality data fraud and falsification
  • Strengthen countermeasures based on analysis of past incidents
  • Mitigate impact in the event of a problem through the introduction of a group-wide traceability system
  • Enhance information sharing and quality audit activities, and strengthen training
(5) Risks associated with the environment
  • Risk that delayed measures to reduce energy use in the long term will lead to lost business opportunities and damage to corporate value
  • Risk of a leak of environmentally harmful substances or overrun of emission standards
  • Implement investment plan based on cycle for achieving energy reduction targets
  • Strengthen management systems and step up preventive activities at priority business sites
(6) Risks associated with compliance
  • Risk of delayed response to changes in various laws and regulations
  • Risk of shortcomings in our responsiveness to global taxation issues
  • Information sharing, and education and training through the Group compliance system
  • Strengthen tax management system including increasing resources to deal with international taxation and sharing data and risks between parent company and subsidiaries
(7) Risks associated with human resources and labor
  • Risk of being unable to secure the globally competent human resources needed to expand business and implement strategies
  • Risk of being too slow to embrace diverse work styles and review personnel systems and measures accordingly
  • Risk of disruption to business operations as a result of failure to comply with each country’s labor laws and regulations
  • Strengthen recruitment process and enhance succession planning according to the status of businesses and capabilities under the condition of each country and region
  • Formulate and implement measures and action plans within the Group based on engagement surveys and step up awareness-raising activities
  • Engage in information exchange and monitoring with the Human Resource division of each region around the world on a regular basis and collaborate with external experts
(8) Risks associated with procurement
  • Risk of disruption to procurement due to overreliance on specific suppliers
  • Consider alternatives, have more than one supplier, and encourage local procurement
(9) Risks associated with DX and information security
  • Risk of delivery delays and rising costs in connection with the introduction of core systems
  • Information security risks such as cyber attacks and the leakage of confidential information
  • Tighten project management and establish a rigorous review process for additional development
  • Well scheduled system updates, and conduct vulnerability assessments on a regular basis
  • Improve ability of early detection and coping skills, and strengthen prompt recovery capability
(10) Risks associated with mid- to long-term improvement in corporate value
  • Risk that unexpected changes in the business environment prevent achievement of the mid-term management plan
  • Risk that inadequate dialogue with stakeholders, including shareholders, investors, employees, and others, impacts improvement in corporate value or external evaluations
  • Monitor achievement of the plan and formulate and implement new countermeasures in the event any negative changes occurred
  • Increase engagement activities with all stakeholders and improve disclosures and communication