CORPORATEGOVERNANCE

Corporate Governance Initiatives

1. Effective Corporate Governance Materiality ⑤.

To ensure effective corporate governance, the Company has established a Basic Corporate Governance Policy. Please refer to this page for more information on our Basic Corporate Governance Policy.

In addition, we have submitted a report on corporate governance to the Tokyo Stock Exchange and disclosed it on TDnet and our website. Please refer to this page for the Corporate Governance Report.

From the General Meeting of Shareholders, the Board of Directors (chaired by the President), the Board of Statutory Auditors, and the Independent Auditor are connected. From the Board of Directors, the Nomination and Compensation Committee and the Representative Director are connected. From the Representative Director, the Internal Audit Department, the Management Committee, and TDC SOFT Inc. divisions and group companies are connected. From the Management Committee, the Sustainability Promotion Committee and the Risk Management Committee are connected.
Corporate Governance Structure Chart

Internal control system and risk management

The Group has established basic policies and operates an internal control system based on the Companies Act and other laws as a foundation for directors and employees to execute their duties appropriately and manage the risk of loss.

Please refer to this page for the basic policy of our group’s internal control system.

With regard to the management of risk of loss in particular, the Company has established a “Basic Risk Management Policy” to appropriately address various risks surrounding its business activities, and in accordance with the “Basic Management Risk Management Rules,” business risks are periodically identified each fiscal year and the Risk Management Committee, chaired by the Chief Risk Management Officer, identifies the risks that need to be managed (company-wide risks). The Risk Management Committee, chaired by the Chief Risk Management Officer, identifies risks that require management (company-wide risks).

Ensure information security Materiality 6)

In order to properly manage information, the Group has established a basic policy for information management, and has built and operates an information security management system based on the ISO27001 standard.

Please refer to this page for the Group’s Basic Policy on Information Management and ISO27001 certification.

In addition, we have established a basic policy for the protection of personal information, including customer information, as well as an effective protection system, and have obtained the Privacy Mark.

Please refer to this page for our basic policy on the protection of personal information.

TDC-CSIRT Activities

The Group has established TDC-CSIRT, a team dedicated to preventing and responding to security incidents, and has organized a systematic approach to emergency response in the event of a security incident.

Please refer to this page for specific information on TDC-CSIRT initiatives.

In addition, TDC-CSIRT joined the Japan CSIRT Council, a domestic CSIRT collaborative organization, in April 2015.

Quality Control

The TDC Group has established and operates the TDC Software Quality Management System (TQS). Please refer to this page for the TDC Group’s quality policy.

In addition, the Group’s quality management system is ISO 9001 certified.