Risk Management

Our Group has established a framework for risk management by referencing ISO 31000 and COSO-ERM, which are international standards for risk management.

Risk Management Policy

Our Group positions risk management not merely as the avoidance and reduction of losses, but as a management foundation integrated with management policies, management strategies, and management plans to ensure business continuity and maintain and improve corporate value. Under the Total Risk Management Policy (TRM Policy) determined by the Board of Directors, we promote enterprise risk management in accordance with the Total Risk Management Regulations.

TRM Policy

  1. Purpose
    The ANA Group aims to maintain and improve corporate value by pursuing the self-actualization of employees and the well-being of their families, while also meeting the expectations of stakeholders such as customers, shareholders, and investors. In aiming to achieve this, we will comprehensively, inclusively, and strategically identify and evaluate all factors that cause uncertainty in achieving management goals from the perspective of overall group management, and perform appropriate management of major risks.
  2. Our Actions to Promote TRM
    1. Safety takes priority over everything else.
    2. Ensure thorough compliance in fulfilling social responsibilities.
    3. Capture both threats and opportunities from diverse and global perspectives, and promote risk management integrated with management strategy.
    4. Surely perform prevention, recurrence prevention, and change management through the visualization of risks, factors, countermeasures, etc.
    5. Assert doubts and notices, and share information on a "bad news first" basis.
    6. Learn from the past and from other companies, and enhance resilience to changing risks based on multiple risk scenarios.

Risk Management Process

Our Group conducts risk management based on the TRM Policy and TRM Promotion Plan formulated in light of its corporate philosophy and policies. Risks of our Group are broadly classified into strategic risks and operational risks as described later, and the risk management process also differs for each risk as follows.
Regarding the management process for strategic risks, the Board of Directors and the Corporate Strategy Committee identify strategic risks based on the business environment etc. at the time of formulating medium-term and annual management plans, distinguish whether the strategic risk is a "risk to take" or a "risk not to take" (determination of risk appetite), and conduct impact analysis based on risk scenarios, while also considering countermeasures and conducting monitoring after ensuring consistency between KPIs (Key Performance Indicators) and KRIs (Key Risk Indicators).
Regarding the management process for operational risks, for each operational risk on the risk catalog that comprehensively lists the major risks of our Group, the responsible risk management department annually identifies (reviews) the risk items to be managed, including the status of group companies, and conducts risk analysis and evaluation based on their degree of impact on management plans and goals, likelihood of occurrence, and existing countermeasures. Along with this, they take countermeasures based on the risk occurrence mechanism (risk scenario), and conduct monitoring after setting KRIs based on our Group's risk tolerance limits as management indicators.
In the evaluation of each risk within operational risks, an inherent risk evaluation is first performed based on the impact and likelihood of occurrence, and then a residual risk evaluation, or identification of risk exposure, is performed taking risk countermeasures into account. Since the evaluation of each risk is quantified through quantitative evaluation, it becomes possible to prioritize risks of different natures based on a certain standard. However, as it is considered that there are factors that cannot be fully captured by quantitative evaluation, adjustments based on qualitative factors are performed as necessary in addition to the quantitative evaluation.
While running the management processes for strategic risks and operational risks in this manner, we undergo internal and external audits* on an annual basis, and also conduct reviews of the risk catalog, the risk management frameworks and methodologies, and the risk management process itself, aiming to improve the maturity of our Group's risk management.
In addition, internal audits assess effectiveness of risk management process and risk governance, and the result is reported to the management.

Total Risk Management (TRM) requires the establishment of a comprehensive PDCA process (TRM cycle) that goes beyond individual risk management processes as 'Risk Information Extraction' → 'Risk Assessment' → 'Risk Control (Mitigation/Avoidance/Transfer/Acceptance)' → 'Risk Review'. This TRM cycle aims to integrate and manage individual risk management activities across the entire organization in a systematic, effective, efficient, and continuous manner to improve the likelihood of achieving organizational goals and objectives. Here's an overview of the TRM cycle: [Plan] - to establishe risk management policies based on the company's philosophy and overall strategy - to develops business plans to achieve management objectives - to define clearly risk appetite policies, determining acceptable risk levels within the business plans [Do] - to execute the business plans - to monitors progress - to conducts individual risk management activities, focusing on predetermined key risk areas [Check] - to evaluate TRM performance through internal audits - to obtain assessments from external organizations to verify TRM effectiveness [Action] - to implement improvements to address vulnerabilities identified during the Check phase - to incorporates lessons learned into the next planning cycle [Foundation for TRM Cycle] The TRM cycle is built upon: - leadership from top management - "risk culture" supported by employee education and risk management metrics incorporated into incentive systems [Communication] The organization communicates its risk management efforts through: - Securities reports - Integrated reports - Shareholders' meetings etc These approaches ensure transparent communication with customers, investors, and other stakeholders regarding the company's risk management practices and performance.By implementing this comprehensive TRM cycle, organizations can more effectively manage risks across all levels and functions, ultimately increasing their chances of achieving their strategic objectives.

*External Audits

To ensure the effectiveness and consistent implementation of Total Risk Management (TRM), and to continuously enhance its maturity, the ANA Group undergoes an annual systematic third-party assessment by an independent external professional organization. The assessment covers the TRM framework and the full risk management process, including risk identification, assessment, response, monitoring and reporting.
The assessment uses more than 100 proprietary questions organized into the categories below. These questions are benchmarked against internationally recognized frameworks, standards and assessment criteria, including COSO ERM, ISO 31000, the Sustainability Standards Board of Japan (SSBJ) Standards and the S&P Corporate Sustainability Assessment (CSA). Results are evaluated in alignment with the Risk Maturity Model (RMM) developed by RIMS, the Risk and Insurance Management Society.
The findings are reported to officers and employees through the Management Committee and the Group intranet. They are used to identify strengths and improvement opportunities in the design and operation of TRM and are incorporated into improvement plans.

ASSESSMENT CATEGORIES
Framework Process
Risk Governance - Leadership Risk Governance - Design: Resources Risk Management Foundation
Risk Governance - Commitment Risk Governance - Implementation Enterprise Risk Management
Integration Risk Governance - Evaluation Emerging Risk Management
Risk Governance - Design: Foundation Risk Governance - Improvement Sustainability Management
Risk Governance - Design: Roles

TRM maturity is evaluated on a five-level scale, from ad hoc risk practices to a continuous improvement cycle informed by internal and external intelligence.

Risk Management Structure

Under the supervision of the Board of Directors, our Group has established a total risk management structure in which the Corporate Strategy Committee, risk owners, risk management departments, organizations of ANAHD, and group companies cooperate closely to manage strategic risks and operational risks in an integrated manner.
The Board of Directors bears the role and responsibility to supervise the execution of Total Risk Management (TRM) by management, and performs the formulation of the TRM Policy, selection of most important risks, appointment of risk owners (Executive Officers of ANAHD in principle) and risk management departments, evaluation of the effectiveness of total risk management, and instructions for improvement.
In the analysis and evaluation of risks, the risk management departments play an important role. Regarding the risks they are in charge of, the risk management departments perform management (risk analysis and evaluation, construction of countermeasures, setting of management indicators, monitoring, etc.), including the status of each organization of ANAHD and each group company, and report the status of Most Important Risks to the risk owners, and the status of general risks to the Risk Owner Council. At the Risk Owner Council, the status of each risk is reported, and mutual impacts with other risks etc. are also confirmed and discussed. The contents of discussions and examination results at the Risk Owner Council are summarized by the Officer in charge of Risk at ANAHD and reported to the Corporate Strategy Committee and the Board of Directors. Furthermore, the results of these reports and discussions are utilized for reviewing response policies for major risks, as well as for allocation of management resources, prioritization of important measures, and decision-making on business operations.

Three Lines of Defense

To effectively implement risk management, three lines of defense have been established, as shown in the diagram.

In order for effective risk management, we have established the three lines of defense. The first line of defense refers to business departments which own and manage risks. The second line of defense refers to administrative departments which monitor risk management of the first line of defense. The third line of defense refers to internal audit department which provides advices on risk management from an independent position.  Each of the three lines of defense plays its role in preventing risks.

Risks of the ANA Group

Risks that our Group considers could have a significant impact on investors' decisions are as follows. Note that the following contents include forecasts regarding the future, which may not match reality, and other risks not listed may also impact our Group (please see "Business and Other Risks" in the 76th Securities Report (FY2025)).
Our Group comprehensively identifies major risks that affect management goals and lists them as a risk catalog. Risks are broadly classified into strategic risks and operational risks based on their characteristics. Strategic risks are risks associated with important management decision-making such as management strategies, and are selected at the time of formulating management plans in the Board of Directors and the Corporate Strategy Committee. Operational risks are risks associated with the execution of daily operations, maintenance of the business foundation, etc., and periodic evaluations are performed based on the impact and likelihood of occurrence of the risk, also taking into account the management's views on risk and incorporating risk countermeasures. As a result of the evaluation, risks that are large and should be intensively supervised and monitored by management are selected by the Board of Directors as most important risks along with strategic risks. Risks other than most important risks are managed as general risks by ANAHD and each group company under the risk management departments.

Most Important Risks

  1. 1. Strategic Risks

Changes in Political and Social Situations

<Summary>
Our Group has expanded its international passenger services in search of further growth opportunities, but the international situation is increasing in opacity, such as the situations in Ukraine and the Middle East, US-China confrontation, and the rise of third-pole powers, and uncertainty exists toward the future. International air transport has expanded up to now against the background of the globalization of economic activities, but if that flow stagnates or reverses, or if a peaceful environment is damaged by wars, conflicts, etc., it may affect the revenue of our Group through sluggish business travel demand and a decrease in sightseeing travel demand, etc. Furthermore, the destabilization of the international situation may affect not only international passenger services but also domestic passenger services through a decrease in inbound (foreign visitors to Japan) demand, etc. In addition, its impact may extend widely, such as an increase in air transport costs and cases where aircraft are forced to stop flying over war/conflict zones and detour.
<Prospect>
Uncertainty is increasing regarding the international situation and the future of economic activity globalization, and we believe that the necessity to manage and deal with this as a risk is rising.
<Mitigating Actions>
In expanding international passenger services, our Group proceeds with development considering international situation risks, rather than judging solely by short-term profitability in aviation network construction, and will continue this response going forward. Also, when acquiring customers overseas, we deploy with consideration for balance so as not to lean excessively toward specific countries or regions. Regarding the international situation, we strive to collect information at each base of our Group, and if the need for emergency response arises due to deterioration of the international situation, we try to reduce the impact by flexibly and swiftly changing flight operation plans and flight routes.

  1. 2. Operational Risks
  1. (1) Aviation Safety: Occurrence of events with a high possibility of leading to accidents or serious incidents under the Civil Aeronautics Act
Inherent Risk Residual Risk
Magnitude of Impact: Medium Likelihood of Occurrence: Medium Risk Evaluation: Medium Risk Evaluation: Small

<Summary>
Our Group positions safety as the foundation of management and a responsibility to society. If an event occurs where safety is damaged or obstructed, it will have a major impact on our Group. Especially if human damage occurs, it may fundamentally shake social credit and trust in our Group. If human or material damage occurs due to an aircraft accident etc., liability for damages may arise, but the impact when safety is damaged or obstructed is not limited to that; the impact may be extensive and long-term, in forms such as customers refraining from using aircraft, causing a decrease in our Group's revenue, or choosing flights other than our Group when using aircraft. Furthermore, toward ensuring safety, if a manufacturing defect etc. occurs or is discovered in an aircraft, we may preventively suspend the operation of the aircraft, but in that case, flight cancellations or reductions may occur due to a shortage of aircraft, potentially affecting the business operations of our Group.
<Prospect>
We believe this risk continues to be the most important risk for our Group.
<Mitigating Actions>
Our Group has established specialized organizations to promote safety and conduct safety quality audits, and at the same time, has constructed a sustainable "mechanism" to uphold safety. We pursue further safety improvements through recurrence-preventive, preventive, and future-predictive safety risk management, utilization of good practices and examples from outside our Group, and "visualization" of safety and consideration/implementation of countermeasures using SPIs (Safety Performance Indicators). At the same time, we conduct initial and periodic education and training for employees directly engaged in aircraft operations, including flight crews and cabin crews, and also conduct constant awareness activities regarding safety targeting all employees of our Group, striving to actively foster and strengthen a safety and security culture through the utilization of the training facility "ANA Group Safety Education Center" etc. In addition, we work to realize high-quality operations including safety while conducting close information exchange and opinion exchange with aircraft manufacturers etc.

  1. (2) Environment
Inherent Risk Residual Risk
Magnitude of Impact: Large Likelihood of Occurrence: Medium Risk Evaluation: Medium Risk Evaluation: Medium

<Summary>
The aviation industry is a "hard to abate" industry where decarbonization is difficult, but the reduction of CO2 generated by aircraft operations is an important responsibility that our Group sets as a materiality. Currently, SAF, which is the core, remains at a high price and in short supply, with no prospect of resolution. If SAF cannot be secured stably in the future or remains expensive, expense increases due to increased purchases of emissions allowances will occur, and there is a risk that competitiveness against other means of transportation such as railways will decrease due to passing costs onto fares. In addition, we are also paying attention to risks of decreased evaluation from investors and customers due to delays in climate change countermeasures, and increased costs due to tightened environmental regulations such as carbon taxes.
<Prospect>
While responding to decarbonization is an internationally pressing issue, more sophisticated and swift responses are required against changes in the external environment and the complication of regulations. Our Group proactively pursues the sustainable growth of our Group, positioning environmental countermeasures as the cornerstone of growth while enhancing tolerance to market fluctuations. Recently, in line with the formulation of our Group's "FY2026-2028 Medium-Term Management Strategy," we updated the medium-term goal of substantially reducing CO2 emissions by 10% or more by FY2030 compared to FY2019, and the transition scenario toward net zero by FY2050. We will continue to advance our strategy flexibly and steadily in accordance with the "rolling type" value creation roadmap that dynamically optimizes resource allocation according to changes in the external environment.
<Mitigating Actions>
Toward achieving goals, we will tackle decarbonization by combining four strategic approaches while pursuing compatibility with economic rationality. Based on current issues regarding SAF, we will first continue to promote direct CO2 reduction through "operational improvements and technological innovations in aircraft, etc." as the highest priority. In parallel, we will diversely advance "public-private partnership and supply chain construction for stable supply of SAF," "appropriate utilization of emissions trading systems," and "utilization of negative emissions technologies." Furthermore, we will strengthen proactive risk management in cooperation with stakeholders, such as active proposals toward domestic and international regulations and related framework creation, acquisition of government support, and construction of mechanisms to appropriately reflect environmental costs in fares, etc. Information in line with the TCFD (Task Force on Climate-related Financial Disclosures) recommendations is disclosed on our Group's website.
(https://www.ana.co.jp/group/en/csr/environment/goal/)

  1. (3) Public Security and Crime: Human, material, and functional damage due to wars, conflicts, terrorism, and large-scale riots
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Low Risk Evaluation: Medium Risk Evaluation: Small

<Summary>
Our Group has expanded its international passenger services in search of further growth opportunities, operating scheduled flights to major overseas cities, and establishing offices mainly in each destination to station expatriates and locally hired employees. Due to the deterioration of the international situation, the risk of employees staying locally, flight/cabin crews, and business travelers, etc. being involved not only in general crime but also in wars, conflicts, civil wars, terrorism, and large-scale riots is relatively increasing, and there is a possibility that human, material, and functional damage to the company may occur, including supply chain impacts in terms of economic security.
<Prospect>
The international situation changes constantly, and amid increasing political and economic uncertainty, we believe that the necessity to manage and deal with this as a risk is rising further.
<Mitigating Actions>
As responses during normal times, our Group develops internal communication systems and manuals, and conducts various training and seminars. In addition, when a risk event occurs, we take measures toward avoiding or reducing damage, such as prompt information collection/sharing, safety confirmation, and issuing alerts.

  1. (4) Infectious Disease Pandemic
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Low Risk Evaluation: Medium Risk Evaluation: Medium

<Summary>
Our Group received enormous impact from the COVID-19 infectious disease, but if a large-scale infectious disease occurs again in the future, it may again cause a major impact on our Group, such as being unable to appropriately execute the transport of passengers and cargo due to a sharp drop in demand caused by restrictions / prohibitions on human movement and absences of executives and employees due to further spread of infection.
<Prospect>
Generally, climate change (global warming) is said to increase infectious disease risks, and we believe that dealing with this risk is gaining importance.
<Mitigating Actions>
So that the aviation business can be continued, our Group stockpiles masks, etc. for executives and employees during normal times, and by possessing freighter aircraft in addition to passenger aircraft, has constructed a structure that can actively respond to material movement even under situations where human movement decreases. Along with this, regarding human movement, we ensure that we can respond most appropriately to limited aviation demand.

  1. (5) System Failure
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: High Risk Evaluation: Very Large Risk Evaluation: Medium

<Summary>
Our Group actively promotes the systematization of business operations in order to provide air transport services with higher quality and higher efficiency. If a failure occurs in these systems, regardless of whether the reason is an internal factor (in-house factor) or an external factor such as a cyberattack, its impact to the business is increasing. If a failure occurs in aircraft operation-related systems, there is a possibility that aircraft operation becomes difficult. In addition, if a failure occurs in related systems such as reservation, settlement, and boarding management, acceptance of reservations, settlement, and boarding management at airports become impossible, which may make it substantially difficult to provide air transport services.
<Prospect>
Given the progress of shifting systems to the cloud, the connection and increasing linkage of business-related supply chains, geopolitical perspectives, and furthermore, the increase and sophistication of cyberattacks such as the attacker's utilization of AI, we believe that risks regarding system failures and cyberattacks are rising. Also, we believe that social demands regarding preventing and reducing this risk are rising as well.
<Mitigating Actions>
In our Group, we perform 24-hour, 365-day monitoring in order to swiftly respond to system failures. In addition, through the construction of our Group CSIRT (Computer Security Incident Response Team), which was launched in 2024, by responding from the point when it is unclear whether it is a system failure or a cybersecurity attack, we have constructed a comprehensive and multi-faceted system operation structure, and very fast responses have become possible for both cyber incidents and overseas stakeholders. Also, we are strengthening responses in soft aspects, such as establishing functions to supervise the architecture of the overall system, strengthening employee education, and conducting training for responding to system failure occurrences.

  1. (6) Information Security
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: High Risk Evaluation: Very Large Risk Evaluation: Medium

<Summary>
Our Group retains a lot of information, including personal information of members of the customer organization "ANA Mileage Club," but if this information leaks illegally, we may receive claims for damages, be ordered to pay fines or surcharges by governments of various countries, or competitiveness may decrease due to loss of credit and trust from customers and society.
<Prospect>
Recently, information leakage events due to cyberattacks occur frequently even domestically, and given the rising social awareness and norms regarding the handling of information in general and the strengthening of related laws and regulations specified by governments of various countries, we believe that the necessity to appropriately deal with this risk is rising further.
<Mitigating Actions>
Along with conducting appropriate information management in accordance with laws and regulations of each country, we perform computer virus countermeasures, email security checks, monitoring of unauthorized operations, restriction of employees who can access information, enhancement of authentication, and education / awareness activities regarding information management targeting all employees. Also, we conduct continuous inspections targeting the systems of the entire group, and implement responses to prevent cyberattacks and information leakages, such as early detection of and response to system aging and vulnerabilities.

  1. (7) Human Rights
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Low Risk Evaluation: Small Risk Evaluation: Small

<Summary>
If acts constituting human rights violations occur in the entire business area involved in our Group's business, including not only within our Group but also contractors, business partners, procurement partners, our Group may face social criticism or become the target of boycotts. Also, in some overseas countries and regions, legislation regarding human rights protection in supply chains is progressing. If acts constituting human rights violations occur, including outside the group such as contractors, our Group may be imposed penalties in such countries and regions. Furthermore, if problems occur at suppliers including subcontractors and lead to suspension of operations, constraints or restrictions may be imposed on our Group's business operations.
<Prospect>
Human resources involved in our Group's business are diversifying amid responding to the decline in the labor population within Japan or advancing the expansion of overseas businesses, and we believe there is a need to deal with this risk more multifacetedly.
<Mitigating Actions>
In line with the procedures detailed in the United Nations "Guiding Principles on Business and Human Rights," our Group has constructed a mechanism for human rights due diligence under the "ANA Group Human Rights Policy." We conduct human rights risk assessments in supply chains, and strive for appropriate management of this risk by performing direct confirmation / investigation through dialogue with external relations and workers themselves as necessary. Furthermore, we have also developed a mechanism for workers to raise their voices directly, promoting respect for human rights through grievance mechanisms. In addition, we conduct employee education regarding human rights internally, and periodic monitoring in management-level committee bodies, etc.

  1. (8) Natural Disasters
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Medium Risk Evaluation: Large Risk Evaluation: Medium

<Summary>
Due to its characteristic of connecting points by air, air transport has a relatively strong tolerance to natural disasters among transportation / shipping systems, having advantages such as being able to perform alternative transport utilizing nearby airports even if some airports fall into dysfunction. However, since our Group's business foundation is concentrated in the Tokyo metropolitan area, if Haneda Airport or Narita Airport receives a major impact from a natural disaster, constraints or obstacles may occur regarding our Group's business operations.
<Prospect>
There are concerns over the intensification and frequent occurrence of wind and flood damages due to climate change, and the occurrence of large-scale disasters where enormous damage is expected, and we believe that dealing with this risk is further increasing in importance.
<Mitigating Actions>
Even if a large-scale natural disaster including an earthquake directly beneath the Tokyo metropolitan area occurs, so that we can promptly restore flight functions and fulfill our mission as a public transportation institution, we have formulated an all-hazard type Business Continuity Plan (BCP) and promote Business Continuity Management (BCM). Also, regarding various core functions indispensable for business operations, we develop backup systems, prepare satellite phones, stockpiled goods, employee safety confirmation systems, and while also cooperating with stakeholders (airport companies, etc.), conduct responses such as implementing periodic disaster prevention training.

  1. (9) Human Resource Management: Shortage of Personnel, Decline in Skills
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Low Risk Evaluation: Medium Risk Evaluation: Small

<Summary>
Our Group sets the domestic market as its largest business foundation, but as Japan's population decline progresses in the future, it may exert an impact from the perspective of securing the labor force necessary for our Group's business operations. In that case, unit costs of personnel expenses may increase, or constraints may arise in business operations due to labor shortages as well as shortages of skills and knowledge of employees (crew, maintenance, airports (including general agents and contractors)).
<Prospect>
We believe this risk has a possibility of manifesting in the future.
<Mitigating Actions>
In formulating management strategies, we incorporate and reflect assumptions of various social changes such as population decline and labor markets, and regarding securing labor force and maintaining / improving skills, we confirm the status of turnover rates and recruitment fulfillment rates across the entire group, leading to appropriate and swift responses (implementation of engagement improvement measures, strengthening recruitment activities including year-round recruitment, mutual support between airports, etc.).

  1. (10) Compliance
  1. 1) Act on the Protection of Personnel Information
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Low Risk Evaluation: Small Risk Evaluation: Small

<Summary>
Our Group retains a lot of personal information, such as information of members of the customer organization "ANA Mileage Club," but if this personal information is handled illegally, such as leaking because necessary safety management measures were not taken, or being provided to third parties without obtaining necessary consent, we may be ordered to pay fines or surcharges by governments of various countries, receive claims for damages, or competitiveness may decrease due to loss of credit and trust from customers and society.
<Prospect>
Given the rising social awareness and norms regarding the handling of personal information in general and the strengthening of related laws and regulations specified by governments of various countries, we believe that the necessity to appropriately deal with this risk is rising further.
<Mitigating Actions>
In the handling of personal information, based on the "Basic Policy and Action Principles for Privacy Governance" in the ANA Group and the "Privacy Policy" of each ANA Group company, we pay closest attention and thoroughly protect and manage information in a form compliant with various countries' laws and regulations such as Japan's Act on the Protection of Personal Information. Also, when utilizing customers' personal data, incorporating perspectives of ethical appropriateness, we conduct privacy impact assessments, education / awareness for employees, inspections / audits, etc., continuously strengthening systems and mechanisms that protect privacy.

  1. 2) Competition Law
Inherent Risk Residual Risk
Magnitude of Impact: Very Large Likelihood of Occurrence: Low Risk Evaluation: Small Risk Evaluation: Small

<Summary>
In our Group, if we adjust flights, routes, airfares, fees, number of provided seats, with competing operators, it is considered that it may violate the competition laws of various countries. If we conflict with these, not only huge fines (surcharges) will be imposed, but it will also lead to corrective orders by authorities, restrictions on business approvals, and furthermore, claims for damages from large-scale user groups and significant loss of brand image, and depending on the case, it is considered that it may develop into a situation that shakes the management foundation.
<Prospect>
Fluctuations in fares and fees of the air transport business are under attention by regulatory authorities of each country. Particularly, while adjustments via algorithms due to digitization attract attention as "digital cartels," inter-corporate collaboration toward decarbonization (SAF introduction etc.) calls new discussions from the viewpoints of global environmental protection and maintenance of competition. In the future, alliances between air transport operators will progress further, and it is expected that wider and more complex business operations than before will be required.
<Mitigating Actions>
In ensuring thorough compliance in our Group, we operate the business along the group's Competition Law Compliance Manual. Specifically, we continuously conduct the operation of approval rules regarding contact with competitors and education related to competition law for executives and employees. Also, in alliances and joint businesses, we obtain necessary anti-trust immunity approvals in advance, and will appropriately execute business activities with partners within the approved scope.

  1. 3) Various Business Acts
Inherent Risk Residual Risk
Magnitude of Impact: Large Likelihood of Occurrence: Medium Risk Evaluation: Medium Risk Evaluation: Small

<Summary>
Our Group needs to comply with domestic and international related laws and regulations in each business field including the Civil Aeronautics Act (hereinafter "Business Acts"). In business activities, if by any chance we cannot comply with these Business Acts due to internal management problems or external factors, we may receive administrative dispositions such as business improvement orders or business suspension orders from regulatory authorities. If such a situation occurs, it may exert a significant impact on management and financial conditions due to the loss of social credit of our Group, restrictions on business activities, etc.
<Prospect>
In recent years, accompanying changes in social situations and technological innovations, the contents of Business Acts tend to become complex and strict both domestically and internationally, and the importance of appropriately dealing with this risk is rising.
<Mitigating Actions>
Our Group positions compliance with Business Acts as one of the highest priorities of management, striving for appropriate management of risks. As specific responses, we collect and analyze information on the enactment and revision of related laws and regulations, constructing a structure to swiftly reflect them into internal regulations and operational procedures manuals. Also, besides periodically checking the status of law compliance, we implement continuous education and awareness activities etc. regarding the applicable Business Acts for executives and employees, working on strengthening the law compliance structure and governance of the entire group.

Major Initiatives

Implementation of Education

ANA Group regularly provides education and training on risk management to all levels of the company (directors, managers and staff) in order to deepen their understanding of risk management and to foster an effective risk culture.

  • Conducting study sessions for directors (including independent outside directors) on total risk management.
  • Implementation of e-learning related to total risk management for directors and employees
pagetop