The Board of Directors of LY Corporation (the “Company”) has resolved on the "systems for ensuring the properness of business activities" as stipulated in the Companies Act and Regulation for Enforcement of the Companies Act, established this internal control system in its Basic Policy for Internal Control, and designated internal audit as a role to check various controls from within the company.
The Company has established the Internal Audit CBU as a dedicated organization reporting directly to the President and Representative Director, CEO. The organization audits and makes recommendations on the effectiveness and efficiency of operations such as compliance and information security in accordance with the Regulations for Internal Audits.
1. Organization, Personnel, and Expertise
The Company’s Internal Audit CBU comprises a total of 30 members (as of the end of March 2026). Its staff includes employees who are well acquainted with the Company’s services and systems, as well as qualified professionals such as Certified Internal Auditors (CIA), Certified Information Systems Auditors (CISA), and Certified Fraud Examiners (CFE).
In addition, subsidiary companies—including ZOZO, ASKUL, and PayPay—maintain their own independent internal audit functions.
2. Roles
Based on the three lines model, the Company’s Internal Audit CBU independently conducts internal audits of both business and administrative divisions. It also provides necessary advice, evaluations, and support (including personnel support via staff secondments) regarding the establishment and operation of internal audit systems at subsidiary companies. Furthermore, for subsidiaries that do not have an internal audit function, the Company conducts internal audits based on their risk profiles.
3. Status of Internal Audits
The Internal Audit CBU attends the Top Management Committee and other relevant meetings to collect information on controls in high-priority areas, which is utilized during the formulation of audit plans.
These audit plans primarily consist of “risk-based theme audits,” and “regular scheduled audits,” both of which are executed with due consideration to risk management and compliance.
Individual audit results are reported to the President and Representative Director as well as to the Full-time Audit and Supervisory Committee Member (Chairperson of the Audit and Supervisory Committee). Moreover, if there are significant audit findings or other matters that warrant reporting to the Board of Directors, a mechanism is in place to submit such matters for Board review.
Audit Achievements for FY2025
- Audits of personal information protection, information security, and system controls
- Audits of compliance with key laws and regulations and compliance management frameworks
- Audits of governance and risk management frameworks at Group companies in Japan and overseas
4. Coordination Among the Three Audit Functions
In addition to providing regular reports to the Audit and Supervisory Committee members, the Internal Audit CBU shares information with the Accounting Auditor and internal control division to promote coordination in internal audit activities.