Suntory Group strives to understand and analyze the risks to the Group as a whole and take measures to resolve the issues so that we may continue our business operations and contribute to society.
Promoting Structure
In order to strengthen risk management across the entire Group, including our overseas Group companies, Suntory Group has established the Global Risk Management Committee (GRMC), chaired by the Chief Risk Officer at Suntory Holdings Limited and with a membership comprising the directors of each of the Group companies’ divisions and of key operating companies. In addition, we have established Risk Management Committees and Risk Management Teams at each of our operating companies.
The GRMC collaborates with the committees and teams at each of our business unites to assess risks, implement countermeasures, and establish crisis management frameworks within the Group. It regularly reports its findings and activities to the Board of Directors, which in turn monitors these activities and evaluates their effectiveness to ensure accountability to all stakeholders, including our customers.
To further enhance risk management, Suntory Group conducts internal audits on risks and countermeasures regularly.
For more information, see Corporate Governance
Enterprise Risk Management (ERM)
The risk surrounding companies is becoming more diverse and complex due to the globalization and informatization of the economy and growing public awareness of corporate social responsibility. Under the GRMC, Suntory Group conducts annual risk assessments for the entire Group. This assessment includes not only business risks but also environmental challenges, such as climate change, and social issues, such as human rights. The identified risks are assessed base on two axes: ”risk exposure” (probability of occurrence x magnitude of impact) and “preparedness level” degree of readiness) to identify significant risks to the Group as a whole. The GRMC designates personnel who will be responsible for risks identified as significant, then formulates, implements, and monitors countermeasures.
Our Initiatives
Establishing Infrastructure for Crises Response
The risks companies face are becoming ever more complex, diverse and significant, and the enhancement of risk management is a necessity in management. Therefore, it becomes especially important to establish Business Continuity Plan (BCP) based on the estimation of potential damage in case of crisis. Suntory Group has developed a risk and crisis initial response manual for all Group companies. . We aim to minimize impact and damage in case of disaster through timely information sharing and decision-making in event of a major crisis occurs to maintain the trust from society.
Business Continuity Plan (BCP) Formulation and Implementation
In recent years, the world has faced a spate of risks posing a threat to continued socioeconomic activity, including both natural disasters (such as major earthquakes, flooding and landslides caused by typhoons and torrential rainfall, heavy snow, and volcanic eruptions) and the spread of infectious diseases. Suntory Group has formulated a Business Continuity Plan (BCP) that will enable us to continue doing business as much as possible without interruption in the event of a disaster, to securely provide high quality products and services to customers, thus fulfilling our responsibilities to provide supplies. The plan we have formulated goes beyond manufacturing at Suntory Group plants to include raw ingredient procurement and distribution as well as sales activities. We have taken steps to be able to decentralize our head office functions and infrastructure in an emergency and continue to strengthen our response structure to cope with contingencies.
Large-scale Natural Disaster Measures
Disaster Response Systems
In the event of a large-scale disaster, we will provide a quick initial response by setting up a Disaster Response Headquarters, mainly consist of the General Affairs Department of Suntory Holdings Limited and Suntory Beverage & Food Limited, to oversee the entire Suntory Group, and placing emergency response teams for each department under its control. The Disaster Response Headquarters’ first response will begin with confirming the safety of employees and their families and collecting and organizing information on damage inflicted by the disaster. The task force will also oversee the restoration of office functions, restoration of information systems, and the arrangement of relief supplies, which will be carried out according to the response policies of each department involved. The Disaster Response Headquarters will also restore production operations and support customers and local communities. These systems and procedures are posted on the intranet so that employees can review them at any time. We have regularly reviewed our disaster response manuals, enhanced communication means and disaster supplies, and strengthened our disaster preparedness system, including that of our group companies. The Disaster Response Headquarters also has a remote response system in place to ensure a prompt and appropriate initial response in the event of an emergency.
Establishment of Safety Confirmation System and Emergency Drills
In preparation for natural disasters such as major earthquakes in Japan, we have in place a system that utilizes mobile phones, PCs, etc., to confirm the whereabouts and safety of employees.
We conduct safety confirmation drills twice a year and work to raise awareness to ensure that the system operates smoothly.
We conduct regular disaster prevention drills based on the scenario of a major earthquake and drills focusing on how to get home from work on foot. We also regularly disseminate information on disaster prevention and mitigation and conduct an annual e-learning program. In addition, we have implemented a safety confirmation system for expatriates and their accompanying families, enabling swift verification of their safety in the event of an emergency overseas.

Disaster Countermeasures Headquarters Training
Measures Against Infectious Diseases
Since the influenza pandemic in 2009, we have been taking measures to avoid the disruption of business operations by creating a manual on response process during a pandemic based on our Influenza Prevention Manual, disseminating information among employees, clarifying reporting system during pandemic, and strengthening measures to prevent the spread of infection. In addition, we created a course of action related to highly pathogenic diseases to handle all diseases. Furthermore, we have established a BCP that enables operations to continue even during a pandemic, highly-virulent influenza or other diseases.
Tightening Information Security
We are tightening information security systems in the entire Group to respond to information security risks, which are one of the most serious risks in operations. Global security policies were also formulated in an effort to enhance informational security at a global level.
Strengthening Information Security Systems
Suntory Group has established governance through preservation and systems for informational assets by defining the Suntory Group’s Basic Principles for Governance of Information Security based on the growing needs of society that demand even stricter management of corporate information security.
In response to the risk of information leaks on social media (including social networking services [SNS] such as Instagram, Facebook, X, and Line), we have formulated the Suntory Group’s Social Media Policy, which stipulates rules for using social media. We are reinforcing the awareness of each and every employee in the handling of information while advancing the information management of the entire Group based on these policies.
Suntory Group Information Security Basic Policy
Our information assets are a source of the Suntory Group’s competitiveness. During our strategic usage and application of such assets, we must be worthy of our customers’ trust in us and fulfil our corporate social responsibility. Thus, we have identified the appropriate safeguarding of information assets as being an important management challenge, and have instituted the following basic policy, which promotes information security governance.
-
・By maintaining a chain of responsibility for information security and by formulating and enforcing rules on the handling of information, we will strive for appropriate management as one group.
-
・By specifying how the information assets that we possess should be handled in accordance with their importance and any risks, we will strive for their secure and proper use and their appropriate safeguarding.
-
・We will conduct the ongoing education and training of our directors, all employees, and other personnel, and we will commit to awareness-raising regarding this issue and ensure full compliance with rules related to information security.
-
・We will strive to prevent information security incidents, and in the unlikely event that such an incident occurs, we will swiftly take action to recover and implement corrective measures.
-
・While complying with laws and regulations in every country we operate in related to information assets, we will continuously improve and enhance the abovementioned information security policies.
Enhancing Human Resource and Legal Management
We have established rules and regulations for the correct use of information systems and the management of confidential information, and we are raising awareness of that information via our intranet. Moreover, we are raising Group awareness to the fullest at each Group company in Japan through the following measure:
-
-Improve information management systems that are based on vulnerability analysis
-
-Introduce e-learning and study sessions to increase awareness of the importance of information security and the handling of information
-
-Establish rules related to using social media and introduce study sessions for employees
-
-Conduct training related to targeted email attacks that are growing year after year
-
-Work with members under the guidance of risk management control supervisors and leaders at each company to improve IT literacy
In 2016, Suntory put in place the Computer Security Incident Response Time (CSIRT) as a specialized organization to response to computer security incidents in an effort to prevent informational security incidents and strengthen its response in times of disasters as a Group.
Enhancing Physical and Technological Management
In preparation for the risks of information leaks, unauthorized access, and intrusions, we are working to prevent the occurrence and minimize the impact if an incident does occur through technological countermeasures at our offices and in our information systems, threat monitoring, and employee education and training.
Initiatives for Minimizing Social Media Risks
Individuals can now easily distribute information with the rise in popularity of social media. However, we see the instances when negative information spreads widely through social media and damages corporate value. The Suntory Group is conducting activities to make employees more sensitive to social media risks (awareness raising through e-learning, group seminars and promoting use of various education tool, etc.) by formulating various standards and guidelines for use of social media, discovering risks as early as possible, and launching response systems to lessen the social media risks.

Social media risk seminar framework
Response to the My Number System
We have put in place measures to properly manage personal information safely at each Group company as deemed necessary for identifiable personal information (My Number System) introduced in Japan in 2016. We have confirmed that our subcontractors have put these measures in place as well.
Protecting Customers’ Personal Information
Each company in Suntory Group stores personal information of many customers such as of those that applied for sales promotion campaigns and customers using mail-order of health and wellness foods, etc. The Suntory Group works to protect personal information of the entire Group according to the Act on the Protection of Personal Information and Guidelines to protect important customer information.
Employee Education on Personal Information Protection
We hold e-learning and study sessions for all employees in the Group to disseminate the importance of personal information protection. We conducted more focused information security education in departments that directly handle personal information.
Information Management of Mail-order Customers
Information of mail-order customers at Suntory Wellness Ltd. are centrally managed in a dedicated closed system at communication management center in which access is strictly managed using the Finger Vein Recognition system.

Finger Vein Recognition system
Initiatives on Intellectual Property Rights
The importance of intellectual property is increasing along with the rising social awareness on intellectual property rights and recent movement on Government’s measures and programs for the same. Suntory Group has established the Intellectual Property Department mainly focusing on patents as well as the Trademark Department focusing on trademarks and our corporate brand “SUNTORY,” as divisions supervising our intellectual property rights of Suntory Group.
Utilization of Intellectual Property
Suntory Group acquires and utilizes the outcome of research & development and design activities in connection with our product, service and technology as intellectual property and promotes our corporate activities to continuously provide highly value-added products unique to Suntory Group that embody our “Yatte Minahare” spirit. In addition, based on our founding spirit of “Giving back to society,” we proactively utilize such intellectual property in our sustainability activities and collaborative activities with various stakeholders for cohabitating in our society and solving social problems. Throughout such utilization of intellectual property, we strive to maximize the brand value of ”SUNTORY” as well as our product and service. We implement an incentive scheme based on Invention Regulation in the Group to promote and utilize employee inventions.
Respecting Intellectual Property of Others
While utilizing intellectual properties, we collect information upon working closely with the site of research & development, designing and marketing activities in order not to infringe intellectual property owned by others. For example, upon adopting new technology, we survey whether or not there is a patent owned by others in connection with such new technology. Furthermore, when adopting a new product name, we conduct whether or not it is registered as a trademark owned by others. We sometimes collaborate with the experts to judge whether our use of new technology and names are legally correct and appropriate.