The Ricoh Group implements risk management in order to accurately respond to risks that may give serious adverse impact on corporate activities of Ricoh. The basic purpose, when implementing risk management, is to realize effective and efficient total risk management (TRM), by grasping exhaustively and systematically, and organizing and responding to the risks surrounding the Ricoh Group, in order to increase stability, sustainable development and corporate value of the Ricoh Group.
Based on the Risk Management Principles stipulated in the Ricoh Group Corporate Management Principles, the GMC / Internal Control Committee has established a risk management area of responsibility for each managerial risk and implements thorough risk management in daily execution and business operations. In addition, the Group has established a Risk Management Support Division that provides comprehensive support for executives, division responsible for managerial risk, and all divisions within the Group.
To streamline risk management groupwide, the Group Standard (which defines the Basic Rules for Ricoh Group Total Risk Management) is explained to major affiliates through the Guidelines for Implementing Affiliated Company Risk Management.
We create risk management journals for specific risks relating to events, factors, preventive measures and advance preparations, and response measures. We accordingly rank implementation items each year, and plan, undertake, and report on them.
We undertake risk management PDCAs according to risk levels. We deem sectoral risks managed by Ricoh divisions and Group companies as managerial risks if the impact on human life or society or the monetary damage could be major if such risks materialize. We prioritize focus managerial risks where considering it important to undertake initiatives focusing on them in the relevant fiscal year.
The Group assigns a risk value based on frequency and degree of impact for external risks such as world trends, incidents and accidents, as well as for internal risks such as changes in the business structure, and creates a two-dimensional risk map to define managerial risk. This is reviewed annually at the time the business plan is being created.
The Ricoh Group pays particular attention to the following types of risk in the fiscal year ending March 31, 2018.
Setting down the Ricoh Group “Incident Management Standard” for all affiliate companies in Japan and overseas, the Ricoh Group has created a system to deal with incidents that may have a negative impact on corporate business activities and to prevent reoccurrence based on the president's policies. “TRM incidents” are to be reported from the division in which the incident occurred through the management division primarily responsible for each incident, to the Ricoh President, the Internal Control Directors, officers connected to the case, and Audit and Supervisory Board Members. A summary of TRM incidents that have occurred during the most recent six months, together with a description of how they were dealt with and the measures taken to prevent reoccurrence, as well as changes in the numbers of occurrences classified by incident, are reported to the GMC and Board of Directors every six months. The GMC and Board of Directors review the management risks every year with reference to the content of these reports. In the fiscal year ending March 31, 2018, software copyright infringement will be added as a management risk, and PDCA cycles will be implemented for the risk management.
Among the reported incidents, the number of compliance-related TRM incidents (corresponding to GRI G4 SO5 (a)) in the past three years were 19 in the fiscal year ended March 31, 2015, 16 in the fiscal year ended March 31, 2016, and 17 in the fiscal year ended March 31, 2017.
Of these compliance-related TRM incidents, there was one major incident that required disclosures to external organizations in the fiscal year ended March 31, 2016, which was an accounting violation occurred in India. However, there is no major incident in the fiscal year ended March 31, 2017. We will leverage our website and other vehicles to promptly share any information that should be disclosed regarding Ricoh India.
An independent auditor that Ricoh India appointed in 2015 raised concerns regarding reporting, and delayed the publication of the results until the matter could be concluded. Ricoh India's audit committee, together with its accountants and lawyers in India, undertook an internal investigation which revealed that some employees had falsified accounts. Ricoh India announced its fiscal 2016 results on November 18, 2016.
Note : We will leverage our website and other vehicles to promptly share any information that should be disclosed regarding Ricoh India.
Ricoh takes the above matter seriously, and will fully cooperate with any continuing oversight by India regulators and courts. Concerning its global systems, it will reflect external expert assessments of the effectiveness of governance and internal controls at overseas subsidiaries in formulating and deploying measures to reinforce internal audits at those subsidiaries and prevent similar incidents from recurring.
The Ricoh Group has created a Business Continuity Plan (BCP) to enable the business to quickly recover and continue and to minimize the degree of damage in the event of an unanticipated disaster or accident.
In addition to the business continuity plan itself, this document introduces BCM issues such as implementation, application, education, training, correction and reviews as the coverage of BCPs.
The Ricoh Group has been formulating its BCP by referring to the 2nd edition of “Business Continuity Guidelines” published by the Cabinet Office of the Government of Japan. The Risk Management Support Division, as the secretariat, organizes functional teams within the Ricoh Group, and formulates and promotes BCP.
Currently, the Ricoh Group has two BCPs, one being formulated on the assumption of “New Influenza epidemic” and the other being the “Widespread disaster in Japan, such as major earthquakes.”
The Ricoh Group establishes response systems and execute necessary actions against the risk of a new influenza epidemic, based on the following basic policy.
In order to facilitate Ricoh Group companies around the world to recognize the conditions of outbreak of new influenza, and to respond based on a prescribed action plan, in the event of an outbreak of new influenza the Ricoh Group has established and has been applying the original alert level and criteria of issue. Having experienced the new influenza (A/H1N1) epidemic around the world from 2009 to 2010, the Ricoh Group conducted a review of the alert level in order to enable appropriate responses according to the individual conditions, and has been adopting the current level since FY2011.
The 5-step decision levels are formulated, and each Ricoh Group company implements countermeasures according to each level.
By referring to the phases released by the WHO, the Headquarters of Ricoh conducts a comprehensive study of : (1) the spread of infection, (2) the severity level, and (3) the damage to the Ricoh Group in each region, etc., and make a specific assessment of the alert level in each region.
The following is the overview of the alert levels.
The Ricoh Group has established and is implementing the “Ricoh Group New Influenza Action Guideline.”
The Action Guideline provides operations and activities to be conducted by each department and employee, approved/prohibited actions under each alert level. It also provides necessary preparations and execution items for operations to be continued under the alert level 5.
Ricoh Group companies / Divisions decide the business operations with priority that should be continued even during the pandemic of alert level 5, ensuring that safety of Employees is secured.
As a rule, the Ricoh Group suspends its businesses under the pandemic of alert level 5 and its Employees shall stay at home. Nevertheless, there are business operations whose continuation is considered indispensable in order to meet the strong needs of the society or due to inevitable reasons from the management point of view.
Operations to continuously provide customers who are engaged in public works* with products and services in the following
Basic jobs that must be performed by the Ricoh Group so that it can be sustained as a corporation (Payments of salaries, Payments to its creditors, etc.).
Jobs whose continuation under alert level 5 is regarded to be indispensable by each division, which is registered as such by the approval of the division manager in advance, and for which Response Plan that stipulated has been prepared.
The Ricoh Group has prepared a Response Plan, to continue business under the alert level 5.
Each company and each department has conducted analysis of impacts on the Continuing businesses with the utmost priority and Continuing jobs with priority, and prepared response plans based on the “Ricoh Group New Influenza Action Guideline.”
In order to respond quickly and effectively to widespread natural disasters and accidental disasters in Japan, the Ricoh Group has established the Large Scale Disaster BCP in Japan based on the following basic policy.
For the purpose of facilitating quick, appropriate and wide-ranging response to various disasters likely to occur in widespread regions in Japan (e.g., earthquakes, large-scale flood disasters, volcanic eruptions, nuclear power plant accidents, etc), BCP assumes representative disasters, such as “Tokyo-Epicentered Major Earthquake” and “Nankai Trough Huge Quake” as a basis of its formulation.
After selecting the important functions which the Ricoh Group should address (e.g., disaster prevention, establishment of information infrastructure, sales, production & procurement, etc.) each of these functions establishes BCP according to the following steps.
The formulation of this BCP was started in 2007, assuming “Tokyo-Epicentered Major Earthquake” and the “Tokai earthquake.” It was completed in December, 2010, and the report was submitted to the top management of the Ricoh Group. By the lessons and reflections based on the experience of the Great East Japan Earthquake in March, 2011, the assumed risk was expanded and the reviews are conducted still now.
Message Board was developed as a means of transmitting all necessary information from the company to their respective employees even when it becomes difficult due to congested communication lines after an outbreak of a disaster.
In addition to the use of conventional safety confirmation systems and emergency contact networks, “Message Board” is applied as a way by which employees can read messages from their companies using their PCs and smartphones.