Risk Management
An introduction to the Yamaha Motor Group’s initiatives in the areas of risk management, crisis management, and business continuity
We are working to reduce risk through various mechanisms and activities. During normal times, we clarify the departments in charge of handling specific risks and conduct measures by implementing the PDCA cycle. In the event of a major crisis, we establish an emergency task force with the President and Chief Executive Officer as the chief general manager to minimize damage and impact.
Contents
Approach to Risk Management
The Yamaha Motor Group's Risk and Compliance management policy promotes a management structure based on three pillars: Global, Integrated, and Agile. Through this structure, we seeks to quickly identify changes in the business environment and promote management that globalization of responsibility and authority across the Yamaha Motor Group. Specifically, we are advancing initiatives for risk and compliance management that are more globally integrated with management plans and business strategies in response to the expanding business environment. At the same time, we are contributing to value creation by agilely identifying and controlling risks arising from regulatory and environmental changes in each region.

Risk Management Structure
The Yamaha Motor Group, as part of its risk and compliance management framework, has appointed a Chief Risk and Compliance Officer (CRCO) who, based on the Rules of Risk Management and the Compliance Management Rules, serves as the chair of the Global Risk and Compliance Management Committee (GRC Management Committee), which is composed of executive officers appointed by the CRCO. The GCR Management Committee monitors risks on a Groupwide basis, while also designating Group major risks to be tackled as priorities and checking on activities to address risks. In this way, we are working to reduce risks throughout the entire Group. Members of the GRC Management Committee are appointed from among the members of the Management Committee involved in management decision-making. In addition to matters related to critical-risk countermeasures for the Group, the Committee also handles strategic risk-related matters such as rare earths, U.S. tariffs, defense-related transactions, M&A governance, and subsidiary reorganizations, thereby promoting risk management integrated with management plans and business strategies.
In key business regions including North America, South America, Europe, Oceania, Indonesia, India, Thailand, Vietnam, the Philippines, China, and Taiwan, and in the Financial Services Business, the Group appoints Risk and Compliance Officers (RCOs) designated by the CRCO to establish a risk and compliance execution framework that spans regions and businesses and promotes Group governance. The Group has also established the Global Risk and Compliance Steering Committee (GRC Steering Committee), consisting of the RCOs as members, to deliberate on matters discussed by the GRC Management Committee as well as risk countermeasures and crisis incidents handled in each region and business. The CRCO manages part of the goal-setting and personnel evaluations for the RCOs, thereby strengthening reporting lines and ensuring the global effectiveness of risk management together with agile responses grounded in on-site operations.
The Group has established the Risk Compliance Promotion Committee, composed of heads of risk management departments at headquarters and other organizations. From a professional perspective, the Committee deliberates on risk management policies, plans, monitoring, and countermeasures, while also sharing matters discussed by the GRC Management Committee and GRC Steering Committee. Based on management-level risk perspectives and global on-site awareness, the Risk Compliance Promotion Committee establishes response policies and regulations for managed risks and promotes countermeasure activities and monitoring of those activities based on those policies across headquarters departments and Group companies. The results of these deliberations are reported by the CRCO to the Board of Directors as appropriate, thereby establishing a framework that ensures the effectiveness of risk and compliance management adapted to the expanding business environment of the Yamaha Motor Group.
Furthermore, to ensure the effectiveness of risk countermeasure activities, the integrated auditing division carries out audits of the management departments responsible for those activities.
Risk Management Activity Cycle
The Yamaha Motor Group has prepared a risk management ledger identifying risks related to the Group’s management and business operations and has deployed it Groupwide on a global basis. Based on this ledger, the Group systematically controls risks by conducting activities such as risk assessments, risk selection, countermeasures, and monitoring.
Starting in fiscal 2026, such activities would be managed through a cloud system, and in coordination with regional RCOs, the Group is promoting utilization of risk management data on global basis.
Conducting risk management activities is promoted by operating the following PDCA cycle.
Significant Risks at the Group Level
Each year, risks that need to be prevented and addressed as special priorities are determined to be significant risks at the Group level. Group material risks are comprehensively assessed and selected based on overall Group risk assessment results, Group business strategies, changes in laws and regulations inside and outside the Group, environmental changes, and information on incidents that have occurred, as well as discussions by the GRC Management Committee, RCOs, and heads of risk management departments.
2026 Group Major Risks
| Risk Items | Background | Measures |
|---|---|---|
| Cybersecurity | As cyber attacks become more sophisticated, in addition to the measures led by the IT department, it is necessary to take measures for the supply chain, including factory equipment and business partners, and to collaborate with other companies and departments. Even In the event of a cyber attack, it is crucial to implement company-wide actions, including establishing a response and recovery system that ensures business continuity. | Implement measures on both the hardware and software fronts based on a cyber security policy that complies with global standard cyber security frameworks. These measures will improve our ability to defend against and respond to increasingly sophisticated attacks. We will also incorporate measures to detect attacks as early as possible and minimize damage as well as recovery time in the event of an attack. |
| Violation of Human Rights | In recent years, conflicts and poverty have become more serious, and human rights violations and the opportunities for violations are on the rise. On the other hand, our business is involved in multiple industries, and the supply chain involved is wide, and globalization is expanding and the risk environment is increasing. | We will promote the incorporation of human rights provisions and the acquisition of memorandums of understanding for dealers and direct material suppliers, aiming for 100% by 2027. We promote human rights due diligence in the Group, identify negative impacts, and strive to reduce, correct, and prevent such risks. In particular, we will promote the expansion of the supply chain and support the promotion of improvement through on-site confirmation of business partners selected based on risk assessments, SAQs, etc. At the same time, we will develop secondary and tertiary business partners. |
| Confidential Information Leakage | We have conducted various activities to minimize the risks so far. However, considering the economic security as well as information security enhancement, it is necessary to promote our activities further across the Group. | - Implement the Group Guidelines globally, and promote confidential information management activities within the Group companies. - Expand the area for which the information management structure is verified. - Increase cooperation with regional Group companies. - Global measures to minimize the risks of information leakage. |
| Death or Serious Injury During Business Activities due to Equipment, Machinery, etc. | A fatal occupational accident occurred due to equipment and machinery at YMC factory in the first half of year 2023. We have selected this theme because many group companies also have similar equipment and machinery in conducting business activities and it is necessary to raise the level of occupational safety and health by entire group, so that such serious occupational accidents never occur again. | In order to foster a safety first culture throughout the Group and to continuously promote initiatives aimed at zero occupational accidents, we have established a Group policy and targets and developed a governance system, etc. in 2024. In this medium-term period, we will minimize the risks of occupational accidents by thoroughly eliminating and reducing risks through the development and operation of Occupational Health and Safety Management System, ISO45001, in major manufacturing companies. In addition, we will strengthen governance and efforts to prevent recurrence of occupational accidents by understanding and analyzing the occurrence status of all Group companies. |
| Violation of Laws and Regulations Concerning Product Quality | Compliance with laws and regulations related to product quality is directly linked to the trust of customers and local communities, and strict management is increasingly required. In addition, it is expected that new laws and regulations will be established in line with the spread and diversification of CASE-related products and services in the world and the realization of a recycling society, and that such laws and regulations will be expanded to each country. We have selected this system because it is necessary for the entire company to respond to these changes without delay. |
We will work to ensure that we comply with product quality-related regulations through means such as collecting and disseminating regulatory information, and confirming that regulatory requirements are incorporated. We will also conduct strategic regulatory activities for new businesses. At the same time, we will strengthen the foundations of the legal management processes of each business, with the Quality Assurance Center Corporate Quality Section, as the hub for company-wide activities, in conjunction with the development of the Yamaha Motor Group Quality Assurance Regulations, which are based on ISO 9001. |
| Factory Closedown Due to Interruption of Supply Chain | In the recent procurement environment, geopolitical risks have become apparent, and the risk of supply chain disruptions for rare earths and other materials has increased. Therefore, we will strengthen supply chain resilience while also taking geopolitical risks into account. | We will advance short-term measures to strengthen contract arrangements with suppliers for securing materials and components, as well as systems for maintaining raw material inventories, alongside medium- to long-term measures including the development of alternatives and specification changes. |
| AI Governance | We recognize the ethical, legal, and social risks associated with the use of AI technology and the associated security risks peculiar to AI use as a global management issue. Taking into account international trends, we will strive to establish and continuously strengthen our AI governance framework, aiming to achieve sustainable growth and fulfill our social responsibilities. | We evaluate AI-powered systems and services based on a risk-based approach. We implement appropriate countermeasures commensurate with the risks. Furthermore, we promote the appropriate use of AI through employee training and awareness activities. |
With regard to governance of acquired subsidiaries, including corporate acquisitions and post-merger integration (PMI) activities, the Group has newly designated such governance as a common risk separate from the above Group major risks in light of its importance to the Yamaha Motor Group’s management plans and business strategies. The strengthening of risk management processes is under the leadership of the headquarters.
Crisis Management Structure and Activities
The Yamaha Motor Group works to minimize the damage from and quickly resolve crisis situations as per the Rules for Initial Response to an Emergency.
In the event of a disaster, accident, or compliance-related incident at the Group, the division involved will report to the risk supervising section and the divisions in charge of risk management as per standards for determining the level of reporting, which are set in advance. Depending on the designated risk level, matters are reported in a timely manner to the CRCO and RCOs, and investigations into causes, corrective measures, and recurrence prevention are promoted through organizational decision-making. If a reported incident involves material matters affecting Group management or multiple departments or companies, the CRCO and the risk supervising section convene a predetermined response team and establish an emergency response headquarters led by the President. This makes it possible to understand the situation and implement temporary responses, while simultaneously promptly reporting to customers and relevant authorities as necessary.
Business Continuity Planning
To prepare against envisioned risks that could impact the continuity of our business, Yamaha Motor has formulated Rules of Business Continuity and responds as per those Rules.
Yamaha Motor's primary operations are concentrated in Shizuoka Prefecture, and could be affected if a major earthquake were to occur in the Nankai Trough.
To prepare for disasters, we have taken steps such as earthquake-proofing our buildings and facilities based on damage predictions from government bodies in order to prevent and mitigate disasters. We are prepared to respond to tsunamis and have stockpiled food, water and other necessities and prepared emergency means of communication. We regularly conduct company-wide disaster drills including nearby Group companies (including night drills for some departments), conduct periodic drills in safety confirmation and also hold initial response drills for individual locations. In addition to all this, we have formulated a BCP that seeks to ensure business continuity while prioritizing the lives and safety of our employees.
We have selected our priority businesses, and we implement continuous and comprehensive measures for both tangible and intangible aspects, including identifying and formulating countermeasures to bottlenecks to recovery, clarifying recovery procedures, selecting response personnel in advance and establishing a system for gathering information from the supply chain.
Furthermore, Group companies have developed infection prevention measures, identified issues that could affect the continuity of their operations, and are formulating response plans in case a pandemic should occur.
We responded to COVID-19 in accordance with our Procedure for Business Continuity (Pandemic Influenza Version), setting up a COVID-19 Task Force headed by the President which collected information, determined response policies, and communicated information. Furthermore, to prepare for the possibility of another pandemic occurring in the future, we are engaged in ongoing initiatives that use the experiences and knowledge we gained from dealing with COVID-19.
We have also established the “Procedure for Business Continuity (Cybersecurity Incident Version)” to address critical incidents caused by cyberattacks, setting out specific structures and procedures for initial response, business continuity, and recovery measures, and promoting initiatives on a global scale.
Group companies are also promoting initiatives based on the “Rules of Business Continuity” to identify critical incidents requiring countermeasures in their respective regions and businesses, including from perspectives such as geopolitical risks, and to establish business continuity plans and frameworks for such incidents.
Cybersecurity
To protect the products and services used by our customers, and also protect information assets such as personal and confidential information, the Yamaha Motor Group has established a Cybersecurity Policy and is taking steps to address this issue.
Specifically, in addition to the basic defensive measures already in place, such as anti-malware and anti-vulnerability measures, the Group has a Security Operation Center (SOC) that monitors for irregularities and a Computer Security Incident Response Team (CSIRT) that responds to incidents to prepare for contingencies. The Group also provides training to increase employees' cybersecurity literacy, conducts assessments to ascertain the situation at each Group company and develop improvement plans, and makes other ongoing efforts to reduce cyber risks.
To help ensure product security, we joined Auto-ISAC* in both Japan and the USA, and the company's Product Security Incident Response Team (PSIRT) uses an understanding of the latest security information and of incidents that have occurred, including in the supply chain, to assist in its responses.
*Auto-ISAC(Automotive Information Sharing & Analysis Center)
Initiatives for Confidential Information Management and Personal Information Protection
The Yamaha Motor Group established Group operational guidelines related to information management in 2013 and has since been actively promoting relevant activities. The Group has established a promotion framework, updated various regulations and guidelines, clarified the roles of related divisions, and worked to prevent confidential information leaks.
Confidential Information Management
Information leaks and damage pose serious risks that can cause harm to third parties and erode corporate trust. The Yamaha Motor Group has designated confidential information leakage as a Group major risk for 2026. The Group is reducing information leakage risks by deploying Group operational guidelines globally and promoting confidential information management activities at Group companies level.
To raise awareness regarding information leakage among all employees, including those at Group companies, the Group conducts internal training and e-learning programs to promote awareness of the importance of handling information from a compliance perspective. Furthermore, access rights are established for stored documents and shared only with necessary personnel. In principle, photography within the Group requires prior application, and only designated personnel are authorized to handle photography.
Personal Information Protection
With the development of information and communication technology and the expanding use of big data, laws and regulations concerning the protection of personal information are becoming increasingly stringent globally. In light of this situation and based on the above Group Business Policy, Yamaha Motor and its Group companies in each country and region are working together towards establishing a personal information protection framework and rules governing the handling of personal information (including notification and consent when acquiring personal information, security management measures, responses to requests related to individuals’ rights, and responses to data breaches), as well as to address cross-border transfers of personal information.
Furthermore, the Yamaha Motor Group Privacy Policy states compliance with the laws and regulations regarding personal information protection in each country. We conduct annual monitoring of the status of handling of information among Group companies. Recommendations are made based on the results. At the same time, we execute group training, e-learning, and other educational and awareness-building activities to thoroughly ensure the appropriate handling of personal information.
If the Yamaha Motor Group becomes aware of any leaks (or the possibility of a leak) of personal information, we will promptly conduct the necessary investigation and take the necessary measures such as reporting to the supervisory authority and notifying the individuals in accordance with applicable laws and regulations, as well as taking disciplinary action and other strict measures in accordance with applicable regulations.
In fiscal 2025, one case occurred in which a Group company received an administrative fine from a personal data protection authority in Turkey due to a personal information leakage incident caused by deficiencies in safety management measures. We take this matter very seriously and will continue strengthening our recurrence prevention measures and information management systems to ensure that similar incidents do not occur again.