Based on the view that keeping risks that could affect the Group’s management and operations within acceptable limits contributes to the achievement of its business objectives, Monex Group implements integrated risk management based on the COSO ERM Framework.* Specifically, after appropriately identifying, analyzing, and evaluating the risks stipulated in “Rules of integrated risk control” and other internal rules, we have established risk management frameworks suited to the respective risks faced by Monex Group, Inc. and each Group company.
- The COSO ERM Framework is an international framework for enterprise risk management issued by the U.S.-based Committee of Sponsoring Organizations of the Treadway Commission (COSO).
As per the flow chart below, the CEO appoints a risk control manager, and this manager is responsible for ascertaining the development and operational status related to the risk control system and regularly reporting that status, including VaR management, to the Board of Directors.
- The executive officer overseeing a segment decides on the specific control method and control system of the subsidiaries developed appropriate control systems to counter unauthorized transfers. related to each risk
- When a risk develops or the risk’s probability is deemed high, the executive officer overseeing a segment reports this to the risk control manager and to the executive officer(s) responsible for that risk(s)
Monex Group combines quantitative and qualitative assessments to appropriately identify and assess risks across the Group, support the achievement of its business objectives, and sustainably enhance corporate value.
As part of its quantitative assessment, the Group monitors Group VaR, financial soundness and capacity for growth investment, and debt repayment capacity and emergency liquidity.
These indicators are regularly reported to the Board of Directors as internal management metrics for the Group and are used to inform management decisions.
|
Risk Areas Monitored |
Description |
|
Group VaR (quantitative assessment) |
Group VaR is calculated monthly to quantitatively monitor whether the Group’s aggregate market, credit, operational, and investment risk exposures remain within acceptable limits. |
|
Financial soundness and capacity for growth investment |
We monitor core cash flow, the net debt-to-equity ratio, and the net leverage ratio to maintain financial soundness while appropriately undertaking growth investments and providing returns to shareholders. |
|
Debt repayment capacity and emergency liquidity |
We assess the coverage ratio for borrowings and our ability to cover the maximum potential loss in the event of a crypto asset outflow in order to evaluate debt repayment capacity and emergency liquidity, including under extreme events that are difficult to predict. |
For risks that cannot be fully captured by quantitative indicators alone, we use the Group Risk Control Matrix (RCM) for qualitative assessment and evaluate residual risk based on the impact and likelihood of each risk and the status of related controls.
In particular, for cybersecurity risks that are highly material to online financial services and risks related to wallet management in crypto asset transactions, we work to reduce these risks through a Group-wide management framework and controls at each company.
The principal measures for each risk are described below (as of June 30, 2026).
In the Group’s main segments—the Online Brokerage Business Segment, the Digital Asset Business Segment, and the Asset & Wealth Management Business Segment—problems with the core systems underpinning services, insufficient processing capacity, telecommunications outages, or other issues could cause systems to malfunction and seriously disrupt business operations.
As a global business, the Group works to protect customers’ information and assets from increasingly serious cybersecurity threats and to provide a secure trading environment. To this end, it is strengthening comprehensive cybersecurity measures with reference to the Financial Services Agency’s Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc., and the Special Publication 800 series issued by the U.S. National Institute of Standards and Technology (NIST). In addition, the Group has established a global framework to respond to incidents caused by cyberattacks and mitigate damage. The Monex Group CSIRT (Computer Security Incident Response Team), established at Monex Group, Inc., serves as the central hub, with CSIRTs also established at major Group companies. Working in cooperation with the CSIRTs of Group companies, the Monex Group CSIRT strengthens Group-wide governance. Each company’s CSIRT protects its operations, information assets, and systems. Together, they advance cybersecurity measures across four pillars: organizational operations, system response, human response, and external collaboration.
However, deficiencies in these measures, delays in or failure to respond appropriately due to causes that cannot currently be foreseen, or leaks of personal information, confidential information, or other data resulting from external cyberattacks or other incidents could damage the Group’s credibility, give rise to claims for damages from affected parties, and adversely affect the Group’s business performance. In addition, Coincheck, which operates a crypto asset exchange, stores most crypto assets held in custody in highly secure cold wallets*1 to protect against unauthorized access and reduce the associated risk. However, if crypto assets held in hot wallets*2 or cold wallets are stolen through an external attack or other means and transferred without authorization, this could damage the Group’s credibility, give rise to claims for damages from affected parties, and adversely affect the Group’s business performance.
At Monex, Inc., a Group company, the risk of unauthorized access and transactions using credentials stolen through phishing or other means is also increasing. Monex, Inc. has experienced unauthorized access resulting from phishing scams. The costs of responding to customer harm, reputational damage, additional security measures, compensation and dispute resolution, and related matters could adversely affect the Group’s brand value, profit or loss from equity-method investments, and business strategy. Monex, Inc. is strengthening security by making the prevention of unauthorized access its highest priority, including by requiring passkey-based login.
- Cold wallets store the private keys used to manage crypto assets (similar to passwords) in an offline environment completely isolated from the internet.
- Hot wallets store and use the private keys used to manage crypto assets in an online environment that is continuously connected to the internet.
No material provisions for fines or settlement payments deemed highly likely to be incurred in the future have been recognized in the Company’s consolidated financial statements as of the end of the fiscal year ended March 2026.
In accordance with the audit firm’s internal rules, which are based on the Certified Public Accountants Act and other laws and regulations, rotation is subject to the following.
- Engagement partners may not be involved in the Company’s audit engagement for more than seven accounting periods, and the lead engagement partners for more than five accounting periods.
- After rotating off, engagement partners may not be involved in the Company’s audit engagement for two accounting periods, and the lead engagement partners for five accounting periods.