internal control
Basic principles for establishing an internal control system
In establishing our internal control system, we will comply with laws and regulations and our articles of incorporation, ensure the proper conduct of our business, and guarantee the reliability of our financial reporting. To this end, we will establish and appropriately operate a system for establishing our internal control system based on the following principles, and strive for continuous improvement in response to changes in the environment.
- (1) The Board of Directors shall decide on policies and plans for the development of the internal control system and shall receive regular status reports.
- (2) By continuing to appoint External Director, we aim to maintain and further improve the supervisory function over the execution of duties by directors.
- (3) The President and Representative Director shall be responsible for establishing, operating, and improving the internal control system as the highest-ranking officer in charge of business operations.
- (4) Establish an internal control promotion department to build, operate, and improve the internal control system.
- (5) An Internal Audit Office shall be established as a department that conducts internal audits independently of business activities. The Internal Audit Office shall monitor the implementation status of the system for building the internal control system and point out areas where improvements are needed.
- (6) Take appropriate measures to ensure the reliability of internal controls over financial reporting based on the Financial Instruments and Exchange Act.
Individual structures related to internal control systems
The following is an overview of our individual internal control system structure.
-
1.
System to ensure that the execution of duties by our directors and employees complies with laws and regulations and the articles of incorporation.
- (1) Establish a department responsible for planning and managing compliance, and develop a compliance system.
- (2) The "DTS Group Compliance Handbook" will be established, and officers and employees will be instructed through training and other means to take compliance as their own responsibility and apply it to their business operations.
- (3) Based on the "DTS Group Code of Conduct," we will resolutely eliminate any ties with antisocial forces that threaten the order and safety of civil society.
- (4) We will establish a "Helpline" as a means for our employees to consult and report any actions that may be questionable under the law.
- (5) The Internal Audit Office shall prepare an annual audit plan and conduct internal audits independently of business activities.
- (6) Establish the necessary regulations and systems to ensure the reliability of financial reporting.
-
2.
System for the preservation and management of information related to the execution of duties by our directors
- (1) The handling of documents (including electronic records; the same applies hereinafter) and other important information related to the execution of duties by directors shall be stipulated in the "Information Asset Management Regulations," and such information shall be stored in a highly searchable state in accordance with the said regulations, and a system shall be put in place to allow relevant parties to access it.
- (2) An internal information system shall be established for the storage, management, and effective use of information necessary for officers and employees to perform their duties.
- (3) Regarding information management, a department will be established to plan and manage information security, and a system for information security will be put in place. In addition, basic policies and guidelines will be established to address the protection of personal information.
-
3.
Our company's regulations and other systems for managing the risk of loss
- (1) The Board of Directors shall establish "Risk Management Regulations" and "Crisis Management Regulations," and shall have the President and Representative Director and other directors responsible for business execution carry out business in accordance with these regulations.
- (2) After deliberation at the Management Council, a "Sustainability Committee" will be established, chaired by a person responsible for overseeing sustainability initiatives, designated by the President and Representative Director, to identify risks and opportunities related to sustainability issues, and to plan and evaluate initiatives.
- (3) After deliberation at the Management Council, a "Risk Management Committee" will be established, chaired by a person in charge of overseeing risk management designated by the President and Representative Director, to manage the company-wide risk management system and operational risks. In addition, the committee will continuously monitor whether or not risks have occurred.
- (4) In the event of a large-scale disaster, etc., emergency response procedures shall be established, and regulations and systems shall be put in place to ensure the continuity of business operations.
- (5) After deliberation at the Management Council, a "Project Promotion Meeting" will be established, chaired by the person in charge of overseeing project development, as designated by the President and Representative Director. For projects that meet the prescribed criteria, the meeting will deliberate on whether to accept the order and make decisions on when to start the service, thereby eliminating or reducing factors that hinder efficiency and increasing the likelihood of achieving the goals.
- (6) An "Information Security Committee" will be established, chaired by the President and Representative Director, to deliberate on and report on countermeasures policies, primarily concerning cybersecurity, as well as on the status of responses, and to deliberate on and report on information security in general, including the protection of personal information and disaster countermeasures.
-
4.
System to ensure that the duties of our directors are performed efficiently
- (1) The Board of Directors shall establish "Rules of Duties and Authority" and, based on these rules, shall have the President and Representative Director and other directors responsible for business execution carry out business operations.
- (2) In promoting company-wide business activities, specific measures to be implemented and efficient operations shall be carried out in accordance with job authority and decision-making rules based on internal regulations.
- (3) The company will establish company-wide goals that are shared by officers and employees, and will work to ensure that these goals are understood and implemented. Based on these goals, a medium-term management plan covering a three-year period will be formulated. Based on this medium-term management plan, business objectives and budgets for each business division will be set as short-term plans for each fiscal year.
- (4) A "Management Council" shall be established as a body to discuss policies and plans for business execution and other important matters. In addition, monthly performance shall be reported to the "Management Council" in order to manage performance against performance targets.
-
5.
System for ensuring the proper conduct of business within the corporate group consisting of our company and its subsidiaries
- (1) To ensure the proper conduct of business within the corporate group, a department responsible for the subsidiary will be established to provide guidance and advice to the subsidiary in developing an appropriate internal control system.
- (2) Persons appointed as part-time officers of subsidiaries shall, in cooperation with the departments of the Company responsible for the subsidiaries, provide guidance and advice to ensure compliance with laws and regulations and proper conduct of business at the subsidiaries.
- (3) By holding cross-group meetings, information sharing among groups will be promoted to ensure the proper conduct of operations.
-
6.
System for reporting to the Company matters concerning the execution of duties by directors, etc. of subsidiaries
- (1) Subsidiaries shall be required to establish "Regulations for the Management of Affiliated Companies" and to seek approval from the Company, or to submit or report certain matters to the Company before a resolution of the Board of Directors, and matters that meet the prescribed criteria shall be submitted to the Company's Board of Directors for approval.
-
7.
Regulations and other systems for managing the risk of loss in subsidiaries
- (1) Our Risk Management Committee will identify problems at subsidiaries and the corresponding response plans, and will receive regular reports on the progress of these plans. The committee will also continuously monitor for the occurrence of risks at subsidiaries.
- (2) For projects of subsidiaries that meet the prescribed criteria, our project management meeting will deliberate on whether to accept the order and make decisions on when to start the service, etc., in order to eliminate or reduce factors that hinder efficiency and increase the likelihood of achieving the goals.
-
8.
System to ensure that the duties of directors and other officers of subsidiaries are performed efficiently
- (1) In promoting the business of subsidiaries, the duties, authority, and decision-making rules based on each company's internal regulations shall be followed. However, certain matters shall be governed by the provisions of our "Regulations for the Management of Affiliated Companies."
- (2) The Company shall establish and promote shared goals among the Company and its subsidiaries. Subsidiaries shall formulate medium-term management plans covering a three-year period based on these goals, set short-term business plans and budgets based on these medium-term management plans, and report them to the Company on a regular basis.
-
9.
System to ensure that the execution of duties by directors and employees of subsidiaries complies with laws and regulations and the articles of incorporation.
- (1) The Company will distribute the "DTS Group Compliance Handbook" to its subsidiaries and provide guidance and advice to them.
- (2) A "group helpline" will be established as a means for employees of the subsidiary to consult and report any actions that may be questionable under the law.
-
10.
Matters concerning employees who should assist the Audit and Supervisory Committee in its duties.
- (1) The Audit and Supervisory Committee may direct and instruct employees assisting it in carrying out the audit on matters necessary for conducting the audit.
-
11.
Matters concerning the independence of employees from directors who are not audit and supervisory committee members, as mentioned in the previous issue.
- (1) The opinions of the Audit and Supervisory Committee shall be respected regarding personnel changes, performance evaluations, etc., of employees who are to assist the Audit and Supervisory Committee in its duties.
-
12.
Matters concerning ensuring the effectiveness of instructions given by the Audit and Supervisory Committee to employees assisting the Audit and Supervisory Committee.
- (1) An employee who has received instructions and orders from the Audit and Supervisory Committee regarding the conduct of an audit shall not be subject to instructions or orders from directors or other persons who are not members of the Audit and Supervisory Committee while performing those duties.
-
13.
Systems for directors and employees who are not members of the Audit and Supervisory Committee to report to the Audit and Supervisory Committee, and other systems related to reporting to the Audit and Supervisory Committee.
- (1) Audit and supervisory committee members selected by the Audit and Supervisory Committee (hereinafter referred to as "selected audit and supervisory committee members") may attend important meetings such as the Board of Directors, the Management Council, and the Risk Management Committee in order to understand the process of important decision-making and the status of business execution.
- (2) The selected audit committee members may review important approval documents and other documents and, if necessary, request explanations from directors and employees who are not audit committee members.
- (3) Any director who is not a member of the Audit and Supervisory Committee shall promptly report to the Audit and Supervisory Committee any matters specified below as soon as they are discovered.
① Matters that cause significant damage to the company or a significant decline in its reputation, or matters that are likely to cause such damage or decline.
② Matters that constitute a serious violation of laws, regulations, articles of incorporation, or internal company rules, or that may lead to such a violation.
③ Matters important for compliance
④ Other matters similar to those in ① to ③ above. - (4) If an employee discovers any material facts relating to items ① through ④ above, they may report them directly to the Audit and Supervisory Committee.
-
14.
System for directors and employees of subsidiaries, or persons who receive reports from them, to report to our Audit and Supervisory Committee
- (1) Our selected audit committee members may attend business plan hearings and other similar meetings with subsidiaries.
- (2) The audit committee members selected by our company may review documents of subsidiaries and, if necessary, request explanations from the directors, etc., of the subsidiaries.
- (3) Any director or employee of a subsidiary that discovers any of the matters specified below, or any person who has been reported by such persons, may report it directly to the Company's Audit and Supervisory Committee.
① Matters that cause significant damage to the company or a significant decline in its reputation, or matters that are likely to cause such damage or decline.
② Matters that constitute a serious violation of laws, regulations, articles of incorporation, or internal company rules, or that may lead to such a violation.
③ Matters important for compliance
④ Other matters similar to those in ① to ③ above.
-
15.
A system to ensure that those who report to the Audit and Supervisory Committee are not subjected to unfavorable treatment as a result of having made such a report.
- (1) Establish "Internal Whistleblowing System Operation Regulations" that clearly state the protection and confidentiality obligations of whistleblowers. Furthermore, make sure that an environment is provided where employees can access these regulations.
-
16.
Matters concerning the procedures for advance payment or reimbursement of expenses incurred in the performance of duties by audit and supervisory committee members (limited to those relating to the performance of duties of the audit and supervisory committee), and other policies regarding the handling of expenses or liabilities incurred in the performance of such duties.
- (1) Expenses anticipated in the audit plan established by the audit committee members shall be budgeted in advance, and expenses necessary to respond to unexpected events shall be paid in advance or reimbursed.
-
17.
Other systems to ensure that audits by the Audit and Supervisory Committee are conducted effectively
- (1) The Audit and Supervisory Committee may hold meetings with the Representative Director and the Accounting Auditor as needed to exchange opinions.
- (2) The Audit and Supervisory Committee may communicate and exchange information with the directors and Auditors of subsidiaries in order to properly perform its duties.
- (3) The Audit and Supervisory Committee may, at its own discretion and as needed, seek advice from external experts such as lawyers and certified public accountants regarding audit work.
Risk management
Establishment of a risk management system
To maintain and enhance corporate value, our company has established a "Risk Management Committee" to appropriately manage various internal and external risks related to our business and to formulate and promote company-wide risk management policies.
The committee deliberates on company-wide risk management systems and important risks that the entire company must address, and approves risk management reports from each department and division. It also receives reports on the risk management response status within the group and provides guidance and advice to group companies as needed. Furthermore, it approves the company's most critical risks and continuously monitors the response status.
The "Operational Risk Subcommittee" is established as a subordinate organization of the Risk Management Committee. It deliberates on the identification and assessment results of significant risks, approves significant risks, and monitors the status of responses. The results of these deliberations are reported to the Risk Management Committee and the Board of Directors.
Furthermore, under the Risk Management Committee, we have established a Risk Management Department and a Risk Responsibility Department. These departments monitor the development and operation of internal controls, promote risk assessment and countermeasures, and provide necessary support, advice, and supervision for each risk category classified according to the nature of the risk.

Risk Management Process
At our company, we comprehensively identify risks and have extracted 81 items categorized into 5 business risk categories and 94 items categorized into 8 operational risk categories, which we have defined as a "risk list." In particular, for operational risks, we determine their importance based on the "degree of loss" and "frequency of occurrence," identify risks that should be addressed as priority as "most important risks" and "important risks," and regularly monitor the countermeasures for these risks and their implementation status.

The process for selecting the most critical operational risk and potential critical risks.
Intrinsic Risk Assessment
For each operational risk defined in the "Risk List," we will assess the risks that would result if no countermeasures were taken for each risk.
Based on the degree of loss and the frequency of occurrence, the importance of the risk is determined in three stages, from highest to lowest: "A," "B," and "C."
Residual Risk Assessment
For risks that were determined to be "A" or "B" based on the inherent risk assessment, the residual risk after implementing countermeasures is evaluated.
Selection of the most critical risks and critical risks
Based on the risk assessment results from Step 2, we will select the most critical risks and important risks by comprehensively considering our company's situation, the external environment, and other factors.
Risks and countermeasures that could affect the DTS Group
Our group has identified seven "business risks," which are based on a comprehensive consideration of their impact on our business, and nine "operational risks," which are selected as the most important risks, as "business and other risks," which have the potential to affect our operating results and financial condition. Furthermore, for the identified "business and other risks," we are working to prevent them from occurring and to mitigate their impact by developing and strengthening our risk management system and implementing necessary countermeasures.
Risks that could affect our group's operating results and financial condition are listed in our securities report.
Building a BCP system

From the perspective of our BCP (Business Continuity Plan), we conduct disaster prevention drills assuming the occurrence of disasters such as large-scale earthquakes.We have also introduced a safety confirmation system, prepared a disaster response manual, and are building a system with the aim of securing human lives, minimizing damage, and quickly restoring operations in the event that they are forced to be suspended.