Risk Management

The SUGI Pharmacy Group’s basic policy is to take a preventive and proactive approach to risks, which are expanding and becoming more complex as business strategies evolve. This will help the Group achieve a sustainable increase in corporate value and implement the new Medium-Term Management Plan (for FY2026 – FY2030). The new Medium-Term Management Plan outlines initiatives such as a full-scale implementation of strategic M&As, the strategic utilization of leverage, and a focus on overseas expansion and new business areas. This has resulted in a significant change in the scope and nature of the risks facing the Group.
The Group has established a comprehensive management system that aligns with the industry’s shared framework by categorizing the overall risk landscape into nine major areas: business strategies and the market environment, legal frameworks and systems, products and services, natural disasters and infectious diseases, information security, human resources and the organization, compliance and reputation, the supply chain, and investments and finance. Under our risk management system, the Board of Directors supervises the development and operation of internal control systems. The Sustainability Committee, the Risk Committee, the Investment and Loan Committee, the Information Security Committee, and the Disclosure Committee are overseen by the Representative Director & President. The Risk Committee consists of internal members, External Directors, and outside experts who manage the risks of each of the above categories in Japan and abroad. The Investment and Loan Committee has expanded to include members from specialized internal departments, thus strengthening the monitoring of due diligence and PMI status of investment and lending projects. Each committee prioritizes its findings and reports them to the Board of Directors. After the Board decides on a response policy, each committee works to achieve continuous improvement through the PDCA cycle. In the event of a crisis, we have a system in place to act quickly and appropriately by establishing a separate emergency task force.

Examples of the major risks to be managed

Risk Main examples of risks
1.
Risks related to business strategies and the market environment
Changes in the competitive environment
  • Intensified competition with industry peers or different industries (e.g., e-commerce, convenience stores, food supermarkets)
  • Progress of industrial consolidation and oligopoly through large-scale M&A
  • Homogenization of the drugstore format and intensifying price competition
Market and store opening environment
  • Shrinking trade areas due to an aging and declining population
  • Delays in opening new stores and difficulty acquiring locations for them
  • Decline in competitiveness of existing stores
M&A and investments
  • Failure of M&As and investments to yield results
  • Impairment of goodwill and other assets
2.
Risks related to legal frameworks and systems
Pharmaceutical and healthcare systems
  • Deterioration of profitability due to revisions of drug prices and dispensing fees
  • Increase in costs to address revisions to the Pharmaceuticals and Medical Devices Act (PMD Act)
Applicable laws and regulations
  • Revisions to the Food Sanitation Act, the Premiums and Representations Act, and the Personal Information Protection Act
  • Impact of revisions to tax systems and accounting standards on business performance
3.
Risks related to products and services
Product quality and safety
  • Recall of products we handle (including private brand products) caused by defects, mixing of foreign substance, or inappropriate labeling
  • Side effects or health risks from pharmaceuticals or health foods
  • Damages under product liability (PL)
Service quality and safety
  • Accidents related to dispensing error or the sale and management of pharmaceuticals
  • Complaints arising from customer service
4.
Risks related to natural disasters and infectious diseases
Large-scale natural disasters
  • Damage to stores, distribution, headquarter functions, and systems due to earthquake, tsunami, typhoon, or heavy rain
  • Suspension of operating activities due to asset impairment or supply chain disruption
Climate change
  • Fluctuation in product demand and impact on procurement of agricultural products and raw materials due to changes in weather patterns
  • Increase in costs to address the tightening of greenhouse gas emission regulations (disclosures based on TCFD recommendations)
Infectious diseases
  • Stagnation of economic activity or decrease in store visitors due to infectious disease epidemic
  • Difficulty continuing store operations or distribution due to an infection outbreak among employees
5.
Risks related to information security and systems
System failure
  • Business suspension due to failure of core system, in-store POS, e-commerce, or prescription dispensing system
Cyberattacks and information leakage
  • Cyberattacks such as unauthorized access from outside and ransomware
  • Leakage of customers’ personal information, prescription dispensing information, and employee information
6.
Risks relating to human resources and the organization
Securing human resources, quality of training services
  • Difficulty securing specialized human resources such as pharmacists and registered pharmaceutical distributors, surge in personnel costs
  • Shortage of managerial and DX personnel
Labor affairs and human rights
  • Labor issues such as long working hours and harassment
  • Occupational safety and health issues, delay in addressing diversity
7.
Risks related to compliance and reputation
Violation of law, misconduct
  • Violation of law or misconduct by officers or employees
  • Violation of the PMD Act, the Antimonopoly Act, the SME Transactions Act, or the Personal Information Protection Act
Reputation
  • Reputation damage caused by dissemination of inappropriate information and the emergence and spread of rumors triggered by social media
8.
Risks related to the supply chain
Procurement and logistics
  • Disruption to business continuity and supply from major suppliers and logistics outsourcing partners
  • Purchase cost increases due to raw material and energy prices and exchange rate fluctuations
Human rights and the environment
  • Emergence of human rights or environmental issues in supply chains (e.g., forced or child labor)
9.
Risks related to investments and finance
Asset value fluctuations
  • Impairment of real estate holdings (including stores and leased property), decline in valuation of fixed assets
  • Decline in value of securities held
Financing
  • Increase in financing costs due to fluctuations in the interest rate environment and financial markets

Internal reporting system

For the purpose of preventing and correcting violation of laws and regulations or misconduct by organizations or individuals, SUGI Pharmacy Group has established a compliance consultation channel, enabling employees to seek consultation anonymously. The internal reporting system is operated in accordance with the internal rules, and reporting channels are established within the Group and in external law offices. In order to prohibit disadvantageous treatment of informants and increase the recognition and understanding of the abovementioned system, we have ensured that contact information for the system is displayed at our stores and offices and have also distributed the Compliance and Disaster Countermeasure Pocket Book. By such promotional activities, we endeavor to establish a sound reporting system.
The Internal Reporting System was renamed “Anything 115 Consultation Call Service for All Workplace Concerns” in FY 2021 to create an environment where employees feel able to use it more freely.

Personal information protection and enhanced information security

The SUGI Pharmacy Group works to strengthen personal information protection and information security to protect and prevent the leakage of personal, customer, and confidential information.
By establishing the Information Security Basic Policy, the Group implements various measures to prevent unauthorized access from outside, virus infection, and data leakage. Training emails are sent to certain group companies on a regular basis. Going forward, we will work to further strengthen information security systems and educate employees by expanding this to all group companies as needed. We have established a provision requiring information security events to be reported to the Information Security Committee as soon as possible via the heads of each division, who are the persons in charge of management.

Reinforcement of information security systems and education
  • Establish the Information Security Basic Policy
  • Inform employees of the Information Security Basic Policy and provide relevant education
  • Obtain certification from an external organization (ISMS)
Prevention of unauthorized access from outside
  • Install firewalls
  • Implement defense against unauthorized intrusion from websites
  • Prevent the receipt of virus-infected emails
Prevention of virus infection
  • Introduce anti-virus software
  • Apply security patches
  • Restrict communications with and browsing of websites
Prevention of data leakage
  • Prohibit the connection of PCs with external devices
  • Restrict access to customer information
  • Install security rooms and security cameras
  • Preserve logs of PC operations and email sending to strengthen the ability to investigate in the case of leakage and secure tracking trails

Information Security Basic Policy

The SUGI Pharmacy Group has been engaging in management to contribute to society by effectively utilizing assets and resources borrowed from society (people, things, money, information, etc.) and continuing to provide profits to society. To realize this, we understand that it is our top priority management issue to strengthen the information security of the entire Group by protecting our customers’ personal information and other information assets owned by us from various threats, including unauthorized access and cyberattacks. Based on this concept, the Group established the “Information Security Basic Policy.”
Going forward, we will endeavor to maintain and improve information security through compliance with and proper handling of the aforementioned policy and the “Handling of Personal Information (Privacy Policy)” by our officers and employees.

Click the website below for the Information Security Basic Policy

Conformance of information security management systems to standard requirements

The Sugi Pharmacy Group complies with the requirements of the ISO27001 standard in the following operations.
The Group will endeavor to strengthen and upgrade its responses in the areas of personal information protection and information security by receiving examinations by external organizations appropriately.

(1) Health guidance-related work
(2) Information management of point card members, incoming call handling, and management of incoming record creation
(3) Customer information analysis, purchase data analysis and sales operations, sales promotion and advertising-related tasks
(4) Recruitment and temporary staffing business, human resource consulting services
(5)Comprehensive e-commerce and logistics operations, integrated with health counseling services including professional referrals and product sales
(6)Planning, development, sales, and consulting for healthcare products and services, as well as pharmacy operations and professional consulting for pharmacists

Conformance of information security management systems to standard requirements
  • JQA-IM1736
  • JQA-IM1863
  • JQA-IM1978
  • JQA-IM2081
  • JQA-IM2198

Certificate Number: JQA-IM1736

Organization:SUGIWELLNESS CO., LTD.

Scope of Registration:

  • Development and provision of health guidance service and information offering serviceand based on healthcare data
  • Development and provision of health guidance systems

Certificate Number: JQA-IM1863

Organization:Customer Support Center

Scope of Registration:

  • Incoming call handling and record preparation services
  • Managing the registration of and changes in point card members

Certificate Number: JQA-IM1978

Organization: Digital Sales Promotion Dept., Product Div., SUGI PHARMACY CO., LTD. Note: Registration amendment in progress. (Formerly: Merchandising Administration Dept. and Digital Marketing Dept.)

Scope of Registration:

  • CRM strategy utilizing proprietary media, analysis of sales performance data, and analysis and sales of ID-POS data
  • Operations concerning sales promotion, advertising, and planning and implementation management of various measures and campaigns in the digital domain

Certificate Number: JQA-IM2081

Organization:MCS CO., LTD.

Scope of Registration:

  • Fee-charging staffing and temporary staffing services
  • Consulting services such as issue studies, implementation of countermeasures, and follow-up services in human resources

Certificate Number:JQA-IM2198

Organization: Pilot Station Promotion Dept., Sugi-Kaku Net Promotion & Management Div. Note: Registration amendment in progress. (Formerly: Pilot Station Promotion Project, DX Strategy Div.,SUGI PHARMACY CO., LTD. )

Scope of Registration:

At Sugi Pharmacy Kawaguchi Totsuka Store
  • E-commerce site operations including customer support and order fulfillment
  • Logistics and shipping services for outsourced operations
  • Health counseling services, including referrals to specialized institutions and the proposal/sale of related products and services
IS 748534 認証マーク
  • IS 748534

Certificate Number:IS 748534

Organization:KNOCK ON THE DOOR Inc.

Scope of Registration:

  • Planning, development, manufacturing, sales and consulting of healthcare sector products and services
  • Operation of pharmacies and consulting services for pharmacists

Compliance with standard requirements for the appropriate management of personal information

The Sugi Pharmacy Group complies with the standard requirements for proper management of personal information in the following corporations or operations.
We are committed to ensuring the appropriate protection and management of personal information, while continuously strengthening and improving our systems.

個人情報の適切な管理における規格要求事項への適合

Certificate Number:19001530

Organization:SUGIWELLNESS CO., LTD.

個人情報の適切な管理における規格要求事項への適合

Certificate Number:19001673

Organization:SUGI PHARMA SYSTEMS CO., LTD.

ISO 27701 認証マーク
  • PM 806690

Certificate Number:PM 806690

Organization: KNOCK ON THE DOOR Inc.

Scope of Registration:

  • Planning, development, manufacturing, sales and consulting of healthcare sector products and services
  • Operation of pharmacies and consulting services for pharmacists