MENU

Risk Management

1. Overview 

  • We recognize the strict observance of laws and regulations, our Articles of Incorporation, and other internal rules as a top management priority. Accordingly, the fundamental matters relating to compliance are stipulated in our Compliance Rules and Code of Ethics. We post on our intranet a compilation of internal rules that officers and employees are required to follow and work to ensure thorough understanding through training and educational programs. In addition, in order to prevent and promptly detect misconduct and violations of laws and regulations, we strive to make effective use of our whistleblowing system. Through these and other initiatives, we are continuously working to enhance and reinforce the effectiveness of our compliance framework.
  • The fundamental matters and policies regarding risk management are stipulated in our Basic Rules on Risk Management, Business Continuity Plan (BCP), and other relevant regulations. In addition to ensuring the soundness of our management through capital adequacy management and other measures, we recognize the importance of the following as major risks associated with our operations: (1) market risk, (2) credit risk, (3) liquidity risk, (4) operational risk, and (5) natural disaster risk. We manage these risks using methods appropriate to the characteristics of each risk category. Furthermore, we have established frameworks to ensure the effectiveness and adequacy of our anti-money laundering and counter-terrorist financing measures, as well as our group governance.
  • The status of each risk is monitored by the Risk Management Office, the Operational Risk Management Office, and the Management Planning Department, all of which are independent from front-office divisions. In addition, risk conditions are reported to and deliberated by various committees, including the ALM Committee, under a framework whereby material matters are determined at the executive management level. Furthermore, the Internal Audit Office, in coordination with the Audit & Supervisory Board, audits the execution of duties by officers and employees, and reports its findings directly to executive management.

2. Management System by Category

(i) Capital Adequacy Management

We calculate a capital adequacy ratio in accordance with the methodology used by financial instruments business operators for the regulatory capital adequacy ratio, and maintain it above a specified level. From the perspective of integrated risk management, we also quantify market risk, credit risk, operational risk and other risks, allocate capital from our own funds to cover these risks, and regularly monitor utilization ratios and other relevant indicators.

(ii) Market Risk

We assess the impact of interest rate fluctuations on assets and liabilities on an economic value basis and regularly verify that such impact remains within the allocated capital even under stress events. In addition, by setting a loss limit for interest rate maturity mismatches, we ensure that excessive adverse effects on earnings are avoided.

(iii) Credit Risk

We set transaction limits for each counterparty, on both an individual and group basis, within a certain percentage of our capital, in accordance with the counterparty’s creditworthiness. We also statistically measure the total amount of credit risk across counterparties and products, and regularly verify that it remains within the range of allocated capital. The risk management department continuously monitors developments in counterparties’ creditworthiness and flexibly reviews credit limits in response to changing conditions.

(iv) Liquidity Risk 

We use an integrated liquidity management table that consolidates all transactions to conduct detailed and planned maturity gap management, ensuring that funds and collateral do not become insufficient even under severe stress conditions over a given period. In addition, we have established contingency plans tailored to different funding environments, and the liquidity management department and front-office divisions hold regular liquidity meetings to review and validate the applicable phase. The results of these reviews are reported to the ALM Committee.

(v) Operational Risk

We appropriately manage operational risks, including system risk, administrative risk, legal risk, human risk, tangible asset risk, and reputational risk, through measures such as developing rules and manuals tailored to the characteristics of each risk, assigning specialized personnel, establishing various committees, providing training, and conducting self-inspections. In addition, the supervisory department monitors the overall status of risk management and reports regularly to executive management, while also providing guidance for improvements as necessary.

(vi) Information Security

We have established an “Information Security Policy” as our basic policy and work to prevent unauthorized use and incidents through measures such as the proper assignment and management of access rights, strict administration of IDs and passwords, and various countermeasures against computer viruses and unauthorized access. In addition, to ensure the continuity of critical operations in the event of a system failure, we have implemented data backups, network redundancy, and recovery procedures, and conduct regular drills and reviews. The status of controls and other important matters are reported to and deliberated by the Security Committee, and we are continuously working to strengthen our information security framework.

(vii) Natural Disaster Risk (BCP)

Under our Business Continuity Plan (BCP), we have put in place measures to ensure that critical operations can be maintained or promptly restored in the event that normal business activities become difficult due to unforeseen disasters, accidents, system failures, outbreaks of infectious diseases, power shortages, or similar events. These measures include establishing alternative sites, developing telework arrangements, duplicating critical systems and terminals, off-site storage of data and programs, and conducting regular drills.

In an emergency, an Emergency Response Headquarters, headed by the President, is established, under whose direction response teams take action. The BCP Committee regularly reviews the content of the Business Continuity Plan, and any material revisions are approved by the Board of Directors.

(viii) AML/CFT Measures

To comply with the Act on Prevention of Transfer of Criminal Proceeds and related guidelines, we conduct stringent customer due diligence at the time of transaction and carry out ongoing monitoring based on a risk-based approach. Any suspicious transactions are reported to the authorities in accordance with applicable laws and regulations. In addition, we have established internal rules to maintain and enhance these frameworks, provide ongoing training to officers and employees, and implement necessary improvements through regular internal audits.

(ix) Group Governance

To ensure the proper execution of operations at group companies, the supervisory department, in accordance with the Affiliated Company Management Rules, regularly monitors the status of compliance at each group company with respect to laws and regulations, articles of incorporation, internal rules, as well as reporting, consultation, and approval procedures. Through these efforts, we ensure the effectiveness and appropriateness of group governance.