KJRM Holdings, KJR Management and KJRM Private Solutions (KJRM) have established "Risk Management Rules" to ensure sound management through appropriate management and operation of risks.
KJRM believe that implementing risk management will ensure the continuity and stable development of our business. Being fully aware of our public mission and social responsibility in conducting asset management, we carry out necessary risk management, and we also conduct necessary risk management of the investment corporations to strive to protect investors and operate the investment management business appropriately. KJRM strive to conduct sound and appropriate business management, based on our management policy and strategic goals. With regard to the risks arising as part of that management, we have established an income and risk management system in line with the management policies of each of the investment corporations and based on the strategic goals, and we manage the system so that risk is appropriately controlled.
KJRM has established the Internal Audit Department, which is independent of any department. Audits are conducted by formulating and implementing an internal audit plan each year based on risk assessment result.
The Internal Audit Department conducts internal audit based on the established Internal Audit Rules. When the audited department receives any instruction or proposal for improvement through the internal audit, it prepares an improvement response plan as well as expected timeline, and reports the results to the Internal Audit Department.
After the completion of the internal audit, the Internal Audit Department directly reports to the President, in addition to reporting to the Board of Directors at least once a year, in principle.
The Company has established the Basic Rules on Information Security to ensure the appropriate and rigorous protection of all assets held by the Company.
Measures are taken for the following items based on the Basic Policies.
There is an increased risk of information leakage by "targeted (hoax) e-mail" attacks aimed at organizations such as corporations and government agencies. Since attack techniques are evolving day by day and the ultimate best defense to prevent damage is raising awareness and appropriate action of all employees as e-mail recipients, we implement training e-mail attack drills every month targeting all users. Additionally, between March and December 2024, we conducted special training on two occasions using videos on specific cases, etc.