Enterprise Risk Management (ERM)

For the management of risks,* LY Corporation (the “Company”) conducts risk management activities centered on Enterprise Risk Management (ERM), risk intelligence, incident tracking across the LY Corporation Group (the “Group”), and the development of a risk-conscious culture.

*Based on ISO 31000, risks are defined as uncertainties that could affect the achievement of organizational objectives. Such risks include not only “threats” that may cause adverse impacts, but also “opportunities” that may create revenue opportunities. LY Corporation believes that appropriately managing and utilizing these uncertainties is essential for the sustainable enhancement of its corporate value.

ERM Process and Process Infrastructure

In accordance with the regulations on ERM, LY Corporation comprehensively identifies and assesses risks related to the management and businesses of the Company and its Group companies, and promotes ERM activities that lead to the generation of corporate value. The Risk Management Committee convenes to make decisions related to risks.

(1) Risk management: The Company identifies risks and opportunities that could affect the achievement of the Group’s mission and business goals and then analyzes these from two angles: (i) how severe the impact would be if the risk materializes (i.e., how much it would affect the Company’s ability to achieve its goals), and (ii) the likelihood of the risk materializing (i.e., how likely and frequently it would occur). From this, the Company assesses the risk level based on impact × likelihood and prepares measures accordingly. At the end of the fiscal period, the Company reviews its responses and conducts a risk management maturity assessment with each division responsible for risk management and business division to understand the current situation and strive for improvements in the next fiscal year. Additionally, the Company analyzes both internal environments (self-analysis by each division responsible for risk management and business division) and external environments (information acquisition from external sources). Based on these analyses as well as insights from the top management and the persons in charge, the Company identifies particularly critical risks as the top risks of the LY Corporation Group. While bearing in mind the impact from the environment surrounding the Group, the Company reviews these top risks as needed, ranks them by priority level, and carries out and monitors the progress of measures.

(2) Crisis management: In the event of an incident, the Company takes prompt and appropriate initial actions to prevent the situation from escalating and to quickly bring it under control, and considers measures to prevent recurrence. Additionally, to ensure that users can continuously access essential services that serve as critical infrastructure for daily life and business, the Company has established a service continuity framework for emergencies.

(3) Establishment of basic rules, plans and systems: The Company establishes policies, rules, regulations, and others to support the operation of ERM processes.

(4) Risk intelligence activities: The Company collects and analyzes external information on matters such as the business environment and changes in social conditions, and shares the information with those engaged in risk management throughout the Group.

(5) Fostering risk conscious culture and education: The Company communicates the importance of risk management as a top message to all employees. Additionally, it uses all available channels to raise awareness on risk management throughout the Group so that all personnel can engage in their daily activities with risk management in mind.

(6) Information disclosure: The Company discloses the material risks of the LY Corporation Group and the status of its efforts to address them in a timely and appropriate manner through available channels.

Diagram of the  ERM Process. The company first takes on a risk management process to identify potential risks. The individual steps are written from left to right of the diagram, starting with the steps involved to perform a risk assessment. This includes an analysis of the internal environment, analysis of the external environment, identification of risks, and their evaluation. Risk assessment is followed by risk response, monitoring, and follow-ups.  While the aim of risk management is to visualize potential risks, the crisis management process is undertaken to identify risks that have already materialized. The steps involved in crisis management are listed from left to right of the diagram, starting with incident response. This is followed by the establishment of an incident response team, damage control, and recovery, which are all implemented based on the company’s business continuity plan. Then, information disclosures are made through the securities report, company website, and so on. The entire enterprise risk management process is based on the following foundations: establishment of plans, systems, and basic rules such as policies and regulations; risk intelligence activities; and the education and fostering of a risk-conscious culture within the company.

ERM Structure

LY Corporation establishes an ERM structure, designating the highest responsibilities to the President and Representative Director, and strives to reduce and prevent risks by smoothly implementing an ERM process. The ISO31000 framework is used as an external guiding standard.
The Board of Directors determines the basic policies on risk management applicable to the entire Group. Based on the basic policies determined by the Board, executive bodies such as the Risk Management Committee, the Supervisory Organization of Risk Management (overseen by the head of the governance division), divisions responsible for risk management, and business divisions, develop the ERM structure and promote Group-wide risk management activities in cooperation with the Group companies.
In order to promptly respond to risks in an ever-changing business environment, important matters are reported to and discussed in the Top Management Committee (a meeting body comprising the President and Representative Director, directors, and others) and other relevant bodies. In addition, RM (Risk Management) Senior General Managers are responsible for risks arising from the fields supervised by each business division head, and RM Promotion Managers are also appointed to ensure a prompt response to risks. The Audit and Supervisory Committee (composed entirely of independent outside directors) and the internal audit division (led by the head of the internal audit division) maintain an independent structure to provide assurance and advise on the effectiveness of the risk management function. Reports on particularly noteworthy issues are provided to the Audit and Supervisory Committee as needed. The internal audit division audits the overall risk management framework and its operational status from an independent standpoint. In addition, as part of external evaluations of its risk management practices, the Company undergoes assessments of its ERM framework by third-party organizations based on the requirements of ISO 31000, and strives to further improve the effectiveness of its risk management framework.
Furthermore, the function overseeing risk management is structurally separated from the business divisions to ensure independence. To further strengthen this independence, the positions of the head of the governance division, who is responsible for the Supervisory Organization of Risk Management, and the head of the internal audit division, who is responsible for the internal audit division, are each held by different officials.

Related Links

The Risk Management Committee supervises the entire Group’s risk management. It is chaired by the President and Representative Director who is also the Chief Executive of Risk Management. Members of the committee comprise non-outside directors, CFO, CTO, head of the Governance Division who is responsible for supervising risks, personnel appointed by the Chief Executive of Risk Management, and the corporate officer in charge of the Supervisory Organization of Risk Management. The committee works with the Supervisory Organization of Risk Management by way of providing instructions and receiving reports. The Supervisory Organization of Risk Management also collaborates and reports to business divisions and divisions responsible for risk management. The executive body, which includes the Risk Management Committee and Supervisory Organization of Risk Management, collaborates and reports to group companies through each of their Supervisory Organization of Risk Management.

*1 The Risk Management Committee is chaired by the President and Representative Director (the Chief Executive of Risk Management) and its members comprise directors (excluding outside directors), the CFO and CTO, and the head of the governance division (responsible for supervising risks,) who serve as Committee members, as well as personnel appointed by the Chief Executive of Risk Management, and the corporate officer in charge of the Supervisory Organization of Risk Management. The Committee supervises the risk management of the entire Group.

Risk Categories

LY Corporation defines risk categories to thoroughly understand the risks faced by the LY Corporation Group. The Company classifies risks within specific fields as risk categories and designates the divisions in charge of each risk category to conduct risk assessments. When a top risk is identified from among the risk categories, the division in charge of the risk category also becomes the risk owner.

Starting this fiscal year, the Company has made the following changes to its risk categories in response to the growing need to comprehensively capture recent changes in the business environment and associated risks.

- The previous classification method based on the two axes of “strategic risks” and “non-strategic risks” has been revised. To enable a more comprehensive understanding of risks, all categories are now presented side by side within a unified framework.

- The categories of “economic security risks,” “business continuity risks,” and “tangible asset risks” have been abolished because they can be encompassed within existing risk categories.

- A new category, “AI governance risks,” has been established due to its growing importance to the Group’s business strategy.

Classification Risk Categories Outline
Strategy Business strategy risks Risks affecting or arising from the organization's business strategy and strategic objectives
Finance Market risks Risks of financial impact from fluctuations in various market risk factors
Credit risks Risks of incurring financial losses due to the deterioration of financial conditions of credit recipients
Liquidity risks Risks of not being able to secure necessary funds, inhibiting cash management, or risks of being forced to raise funds at an interest rate significantly higher than usual
Investment Investment risks Risks of being affected by fluctuations in the value of assets associated with investments, financing activities, and M&A transactions by the Company and between companies
Information technology System operational risks Risks of incurring losses due to errors, system downtime, malfunctions, or inadequacies in operations necessary for the running and maintenance of services during both normal and emergency situations
Product quality risks Risks of affecting users due to lack of quality control in the services and products provided
Information security risks Risks of damage due to break down, corruption, or falsification of information systems or data, or information leakage, etc.
Legal/compliance Legal/contractual risks Risks of being affected by penalties and damage compensations resulting from non-compliance with or breach of contracts for various transactions, etc., and risks of the companies and employees of the LY Corporation Group violating laws and regulations
Compliance risks Risks of adverse impacts arising from actions that violate the LY Corporation Group Code of Conduct or internal regulations; risks of intentional or grossly negligent violations or involvement in bribery, corruption, or other corrupt practices committed by the LY Corporation Group or its employees
Money laundering and financing of terrorism risks Risks of the LY Corporation Group’s services being misused for money laundering or for financing terrorism, or risks of being warned by supervisory authorities for insufficiencies in anti-money laundering measures
Governance Corporate governance risks Risks that insufficiently established governance frameworks for important decision-making in the LY Corporation Group lead to inability of the Group to make timely and appropriate decisions
Data governance risks Risks associated with the management and use of retained data
AI governance risks Risks related to the possibility that the use and application of AI may undermine trust due to deficiencies in governance, or alternatively may enhance trust and value through appropriate management
Supply chain governance risks Risks of being affected by the inappropriate selection of subcontractors or inadequate management of subcontract work and subcontract employees
Social Regulatory/public policy risks Risks related to deficiencies in understanding regulations, policies, and stakeholder conditions in specific countries or regions relevant to the business, as well as insufficient response to various laws and regulations
Environmental/social risks Risks of businesses adversely affecting the environment or society, or risks of businesses being affected by external social environment
Reputation risks Risks of being affected by the spreading of bad reputations or rumors, or risks of failing to respond to the media
Business operation Human risks Risks related to human resources, or risks that threaten the life/health of employees
Business operations risks Risks of incurring losses due to clerical errors in business operations

Fostering Risk Conscious Culture within the LY Corporation Group

LY Corporation regularly conducts (one or more times a year) mandatory training for all employees to learn the basic knowledge and concepts of risk management necessary to perform their work and to raise their awareness. The Company also gathers risk-related proposals and information from internal and external experts in various fields and notifies all employees of these.

Furthermore, the Company provides outside directors with regular opportunities (one or more times a year) to gain a comprehensive understanding of the Company’s risk management by utilizing training materials and related information from the employee risk management education program. These opportunities support outside directors to exercise appropriate oversight of the risks surrounding the Group.

The Company also believes that building relationships that facilitate the sharing of important information and communication among the Group companies is an important aspect of risk management of the Group. The Company is therefore committed to communication with each Group company and regularly shares information with the risk management staff of each company.
Risk management activities are promoted through mutual sharing of information on matters such as the Company’s initiatives and other information from each Group company.

In addition, risk intelligence seminars and other activities open to all personnel from the Group are held to raise risk management awareness throughout the Group.

Risk Management in Service Planning and Development

LY Corporation examines risks during service planning and development in accordance with its business characteristics.
For example, the Company introduces guidelines that clearly define the process for developing and operating products. At PayPay Corporation, a Group company, each department conducts risk identification, risk assessment, and control evaluation, and the company has introduced a process in which the frontline itself develops a risk response plan if the residual risks are unacceptable.

Top Risks of the LY Corporation Group

From its risk management activities, the Company selects the top risks for the LY Corporation Group, which serve as a guideline for the risk management activities of the entire Group.

Top risks are identified one or more times a year after the Risk Management Committee discusses risks that could have significant impact on the LY Corporation Group. Important risks identified during the fiscal year are reported to the Top Management Committee and decisions are made as they arise. The Risk Management Committee also convenes as needed in addition to their regular meetings.

Risk owners are appointed for top risks in order to clarify the responsibilities over the response measures. The risk owners promote the matters decided by the Top Management Committee and other bodies regarding priorities and response policies, and report the status of their response to the Risk Management Committee once every six months.

After the reports on risk management are submitted to the Risk Management Committee, the details are also reported to the outside directors by the Supervisory Organization of Risk Management at the Board of Directors meetings.

A structure is in place and is implemented so that the Supervisory Organization of Risk Management can regularly monitor the implementation status of risk management.

FY2026 Top Risks of the LY Corporation Group

  • Business strategy risks
  • Information security risks
  • Regulatory/public policy risks
  • Human risks

Please refer to the Annual Securities Reports (currently available in Japanese only) for financial risks that may have material impacts on investors' investment decisions.

Top risk categories Representative risk contents Measures to mitigate risks
Business strategy risks
Erosion of user touchpoints and failure to establish monetization models in the era of generative AI
  • Changes in user behavior driven by the widespread adoption of generative AI are occurring rapidly. Failure to establish new user touchpoints adapted to these changes or to develop new monetization models, including advertising that leverages generative AI and monetization of AI-enabled features, in accordance with planned initiatives may adversely affect the achievement of future revenue and profit targets.
  • The Group is implementing measures to improve the profitability of existing advertising businesses through data utilization in order to protect its revenue base.
  • As for new revenue sources, in line with the development of new user touchpoints, the Group is working to establish monetization models through the early introduction of agent-based advertising and monetization of AI-powered features tailored to user needs.
Increased costs associated with the expansion of LLM usage
  • As the use of large language models (LLMs) expands, AI-related costs—including inference, training, and operational expenses—may increase. If the costs are not managed appropriately, there is a risk of declining profit margins and reduced capacity for future investments.
  • The Group seeks to maximize cost effectiveness by continuously optimizing contract terms with model providers and establishing a cost management framework.
  • Through a hybrid strategy that combines technological development with collaboration with external partners, as well as through the enhancement of governance frameworks, the Group aims to respond flexibly to changes in the business environment and ensure its medium- to long-term competitiveness.
Information security risks
Occurrence of large-scale cyber incident
  • The Group may face impacts on its performance and a potential loss of credibility if incidents such as business-related human error or intentional misconduct, system failures due to disasters, cyberattacks such as malware infections and advanced persistent threats, or vulnerabilities in systems and products lead to information leakage, data destruction or alteration, or service disruptions.
  • If sophisticated attacks capable of circumventing the measures implemented by the Group occur, they could damage the Group’s reputation and adversely affect its business performance.
  • Recent cyber threat trends indicate that damage caused by ransomware and other cyberattacks has become increasingly severe, posing a threat directly linked to business continuity.
  • Should threats such as cyberattacks exceed expectations, the Group may incur additional costs, potentially affecting its performance.
  • The Group is committed to enhancing information security from a medium- to long-term perspective across the entire organization to provide users with safe and reliable services.
  • Following the unauthorized access incident disclosed on November 27, 2023, the Company submitted periodic reports to the Ministry of Internal Affairs and Communications of Japan and the Personal Information Protection Commission. In addition, in response to the administrative guidance and recommendations received, the Group completed the implementation of key technical and organizational recurrence prevention measures by the end of March 2026. These measures included the separation of systems and networks from affiliated companies and other entities that shared the same system infrastructure, the overall deployment of multi-factor authentication across the Company’s environment, and enhanced management of outsourced service providers. The measures have since transitioned to a phase of routine and ongoing operation.
  • The Group continues to maintain a monitoring framework through the Security Governance Committee, chaired by the President and CEO, and strives to ensure the effectiveness of its governance framework.
  • The Company supports the information security efforts of its Group companies. Specifically, under frameworks such as the Group CISO Board, which consists of the Company’s CISO, the CISOs of its major Group companies, including those outside Japan, and the CISO of SoftBank Corp. serving as an observer, the Company shares information security frameworks and supports their implementation, shares security-related information such as vulnerability information, and provides consultation on information security measures in response to requests from Group companies. In addition, the Company supports Group companies by providing regulations designed to enable the implementation of information security measures equivalent to those of the Company, as well as assistance in obtaining third-party certifications.
  • In addition to its existing security initiatives, the Group is placing particular emphasis on coordinated measures against ransomware and other cyber threats, including data preservation in preparation for potential system outages and the validation of effective recovery procedures.
Regulatory/public policy risks
Risk of decline in corporate value due to strengthened regulations on the Company’s business
  • In Europe and across Asia, legislations that impose obligations related to the provision and preservation of user information, cooperation with law enforcement investigations, and the appointment of legal representatives, are being increasingly introduced. In countries where the Company's services are accessible, the Company may be required to establish additional frameworks and modify its business practices.
  • In Japan, the regulatory environment surrounding the Company's businesses also continues to tighten, including discussions regarding amendments to the Act on the Protection of Personal Information, the Consumer Contract Act, and the Act on Specified Commercial Transactions, as well as the consideration of regulatory measures addressing issues in the digital environment, such as youth protection and the use of social media during elections.
  • Failure to adequately address these issues could result in administrative or other regulatory actions under applicable domestic and international laws and regulations, deterioration in reputation, and additional modifications to services to ensure legal compliance. Such outcomes could lead to a decline in the user base, increased compliance and operational costs, and ultimately a decrease in corporate value.
  • To respond promptly and appropriately to overseas regulations, the Company is advancing initiatives including the monitoring of regulatory developments abroad, the establishment of operational frameworks for legal compliance, and the enhancement of relevant systems.
  • The Company also closely follows discussions conducted by government review panels and engages in dialogue with government authorities to help ensure that regulatory frameworks are appropriate, by submitting recommendations as a relevant business operator where necessary.
  • In some cases, the Company has voluntarily implemented measures addressing practices that may be prohibited under future laws and regulations.
Risks of impacts on business operations due to compliance with various laws and regulations and changes in the international environment
  • If prior reviews relating to the introduction, modification, or other changes to critical equipment are not conducted appropriately, the Company may be subject to administrative measures such as corrective recommendations or orders. In addition, they may result in delays in the deployment of critical equipment, additional capital expenditures and operating costs, reviews of supply chains, and constraints on technology selection.
  • Failure to establish an appropriate management framework may result in administrative actions, as well as increased compliance-related costs, a greater burden associated with information management, and others.
  • The materialization of geopolitical risks and the occurrence of unforeseen events could have material adverse effects on the Company's business operations.
  • Having been designated as a specified social infrastructure operator on November 16, 2023, under the Act on the Promotion of Ensuring National Security through Integrated Implementation of Economic Measures (the Economic Security Promotion Act), the Company is required to comply with obligations relating to prior reviews and reports on the introduction, modification, and other changes to critical equipment. In response, the Company is advancing the development of internal organizational structures and strengthening its management framework.
  • Pursuant to the Cyber Capability Enhancement Act and related legislation (Active Cyber Defense Act), enacted in May 2025, specified social infrastructure operators are expected to become subject to obligations including the registration of designated computer assets and the reporting of cyber incidents. The Company is progressing its preparations to comply with these regulatory requirements.
  • Led by the Economic Security Office, the Company manages risks by monitoring domestic and international political and economic developments and leveraging advice from external experts.
Human capital risks
Mismatch in human resource structure due to changes in the external environment
  • If a gap arises or persists between the Group’s business strategy and its talent resources, the execution of business strategies may be delayed, expected outcomes may not be fully achieved, or the efficiency and competitiveness of business operations may decline. As a result, the Group’s business activities, operating results, and financial condition could be adversely affected.
  • Depending on future changes in the external or business environment and the extent of their impact, human capital-related risks may materialize beyond the Group’s expectations. Should this occur, the Group’s business development, operating results, and financial condition could be adversely affected.
  • Led by the division in charge of human resources and general affairs, the Group continuously monitors and assesses the alignment between the business strategies of each business domain and the talent required to execute those strategies, as well as the status of workforce planning and personnel allocation, including from a Group-wide perspective.
  • The Group regularly assesses whether any gaps have emerged between its business strategies and talent resources and strives to prevent such risks from materializing.

Related Links

Emerging Risks

By regularly reviewing risks, the Company identifies and manages emerging risks that could significantly impact its business. The Company focuses on key risks identified annually and selects emerging risks for which it implements countermeasures.
The emerging risks that have been identified for FY2026 are the following:

Risks arising from the use of generative AI, particularly centered around AI agents

Representative risk contents If the Company fails to appropriately respond to the rapid advancement of generative AI technology, the competitiveness of its core businesses, such as search and advertising, may decline, making value creation challenging. However, effectively leveraging generative AI technology can enable the creation of new value not only in these core areas but also across various service domains.
Impact on business If the Company fails to achieve strategic outcomes from its engagement with generative AI technologies and becomes unilaterally dependent on external resources or specific corporations, it risks losing its competitive technological edge. However, successful strategic integration of generative AI can provide new user experiences in various service domains, elevate customer satisfaction, and secure a competitive advantage.
Countermeasures
  • Clarification of the necessary technologies to realize differentiated AI agents
  • Building and strengthening a technology development framework for securing an in-house development field
  • Enhancement of alliances in areas dependent on external resources
  • Monitoring external environments such as domestic and international laws and regulations related to AI governance decisions, and reflecting them in rules and processes.

Critical Incident Response

The criteria for critical incidents are defined in the Rules on Incident Management. A system is in place to promptly report incidents which fall under critical incidents to the management via the Supervisory Organization of Risk Management. A system is also in place to ensure that the reported incidents are also shared with the divisions responsible for risk management, so that the status of the incidents within the Group can be promptly identified. Additionally, the Company has implemented the LY Corporation Group Critical Incident Reporting Guidelines , ensuring that any critical incidents occurring within Group companies are reported to management according to the same standards.

Business Continuity Plan (BCP)

LY Corporation provides numerous services that serve as infrastructures essential for daily lives and businesses. Many of these services play important roles in the event of a sudden accident/natural disaster, and the social responsibilities of the Company are increasing. The Company implements systems to minimize damages in the event of a disaster and to ensure that users have stable access to its services.

Continuance of Services in Emergencies

Especially at the time of emergencies, such as large-scale earthquakes, one of LY Corporation’s missions is to provide services needed by users, such as Yahoo! JAPAN News, disaster information, and the LINE communication app, without interruption.
To ensure that users can continue to access the services with peace of mind, the Company establishes a system to ensure the continuous operation of services at multiple locations in emergencies.

Flexible Work Systems Taking Emergencies into Account

LY Corporation introduces a work system that allows employees to work from home in a VPN environment with appropriate security measures in place.
While providing diverse and flexible work styles, as part of the BCP, this work style is designed to ensure the safety of employees and the continuity of business operations in the event of natural disasters or other situations that make it difficult for employees to commute or leave the house.

Establishment of Crisis Response Headquarters and Periodic Drills

In the event of an emergency, a Crisis Response Headquarters, led by the President and Representative Director will be established to ensure the continuity and early recovery of services.
LY Corporation formulates the BCP Rules that form the basis for the Crisis Response Headquarters, clarifies the roles of management and each department in the event of an emergency, gathers relevant personnel to conduct drills on the assumption of an emergency situation and safety confirmation drills for all employees on a regular basis, and reviews the BCP as needed in response to drill results and changes in the environment.

Page top