Daiwa House REIT Investment Corporation

  1. HOME
  2. Governance
  3. Risk Management

Risk Management

Risk Management System

The Asset Manager has prescribed Risk Management Regulations and Risk Management Implementation Guidelines regarding various risks that arise in the course of managing DHR’s assets. It endeavors to manage risk based on a fundamental policy of comprehensively and accurately identifying risks, qualitatively and quantitatively measuring and appropriately assessing the identified risks’ impacts on operations, formulating risk prevention measures, monitoring risk management status on an ongoing basis and formulating procedures for responding to risks when they surface.

Risk Management System

Risk Management Process

The Asset Manager’s risk management is based on the identification, recognition, measurement, monitoring, and reporting of risks in each department, as well as the maintenance of a response system. The risk management process is as follows.

Each department will evaluate risk items, taking into account the likelihood of risk occurrence and the degree of impact. The risk evaluation criteria, which consider both the likelihood of occurrence and the degree of impact, are as shown on the right, with the impact weighted slightly higher.

Development Status of Risk Management System

The Asset Manager has prescribed Risk Management Regulations and Risk Management Implementation Guidelines regarding various risks that arise in the course of managing DHR’s assets. It endeavors to manage risk based on a fundamental policy of comprehensively and accurately identifying risks, qualitatively and quantitatively measuring and appropriately assessing the identified risks’ impacts on operations, formulating risk prevention measures, monitoring risk management status on an ongoing basis and formulating procedures for responding to risks when they surface. Additionally, the Asset Manager conducts annual internal audits to verify the appropriateness and effectiveness of the foregoing risk management system and implementation status of risk controls. The audit results are reported to the President and CEO. The Asset Manager is committed to ensuring that operations are conducted appropriately and soundly managed through such means as reporting to the Compliance Committee and Board of Directors as the occasion demands.
The risk management, improvements and other relevant matters are incorporated into the annual Plan of Compliance Programs and reported to the Boards of Directors of both the Asset Manager and DHR.

Internal Audits

To ensure the effective conduct of internal audits, the Board of Directors has set out Rules for Internal Audits, established an Internal Audit Department independent from other departments, and appointed the General Manager of the Internal Audit Department as the person in charge of internal auditing. Internal audits are conducted based on an internal audit plan formulated each fiscal year, which is approved by a resolution of the Board of Directors after assessing the risk management status and types of risks. These audits include verifying whether the operations of each department within the Asset Manager comply with laws, regulations, and internal rules, identifying any deficiencies in internal rules, and assessing the establishment and operational status of each department’s business management system that supports the achievement of the Asset Manager’s goals. The results of these audits are reported by the General Manager of the Internal Audit Department to the President and CEO and the Board of Directors. In the event of any findings, follow-up on the progress of recurrence prevention measures and improvement activities by the departments being audited is conducted, and the status is regularly reported to the Board of Directors. These findings are also reflected in subsequent internal audit plans.

Internal Audit Implementation Status

  • Internal audits are conducted annually for all departments, and an external review by outside experts is also carried out each year.
  • When formulating the annual audit plan and individual audit plans, we collect information such as findings from past internal and external reviews, risk assessment results from each department, and developments in external environmental factors, including regulatory guidance. Based on this information, we identify priority areas for focused verification. Additionally, decisions are made through the process of aligning risk awareness by exchanging information with the President and CEO and corporate auditors.
  • Audit results are reported to the Corporate Auditors prior to Board of Directors meetings, and the Corporate Auditors may raise questions or provide comments on the findings during the board meetings.
Item Results (FY2025)
Number of internal audits carried out 6 times
Number of external inspections of internal management systems 1 time

Business Continuity Planning

The Asset Manager establishes the necessary items for its disaster prevention and crisis management in relation to risks specified separately for natural disasters such as large-scale earthquakes, accidents, crimes, and other material facts. It has established an “Emergency Response Manual” in order to prevent and avoid risk, ensure people’s safety and reduce/mitigate damage in the event of a disaster, prevent secondary accidents, resume DHR’s asset management operations at an early point, and fulfill its corporate social responsibility. Furthermore, to ensure continuity of payment and disclosure operations from the standpoint of the business continuity requirements to which financial instrument business operators are subject, the Asset Manager plans to operate in accordance with a BCP Execution Plan it has formulated.
The Asset Manager has stockpiled supplies, including three days of emergency meals and drinking water for officers and employees, at its office, warehouse for general affairs and elsewhere.

Safety Confirmation System

As part of corporate crisis management, the Asset Manager has adopted an online safety confirmation system to ascertain its officers and employees’ safety and post-disaster status at the time of disaster swiftly.The Asset Manager conducts safety confirmation drills at least once annually. In the fiscal year ended March 2026, the participation rate was 100%.

Managing Personal Information

DHR recognizes the importance of personal information (here and hereinafter including specific personal information as defined in the Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (hereinafter referred to as the “Numbers Act”)), and in its handling of personal information complies with the Act on the Protection of Personal Information, the Numbers Act, and other laws and regulations on protecting personal information in addition to guidelines and other literature issued by the competent authorities.
Additionally, DHR engages in the proper handling, protection, and management of personal information based on the following policy (hereinafter referred to as the “Personal Information Protection Policy”).

Please refer to "Personal Information Protection Policy"
https://www.daiwahouse-reit.co.jp/en/privacy/index.html

Information Security

The Asset Manager recognizes the proper management of information as an important management challenge and has established an information security policy as a basic policy to ensure information security.

Information Security Policy

  • Appointment of an information security manager
  • Preparation of an information security management system
  • Implementation of information security measures
  • Establishment of internal regulations
  • Information security education
  • Compliance with laws and regulations
  • Reinforcement of management systems of outsourcing companies
  • Implementation of ongoing improvements

Additionally, the Asset Manager has established IT Management Regulations, which define specific procedures for handling information devices, etc. to safely and smoothly manage information devices, etc. and secure the confidentiality and completeness of data, with an aim to fully protect the information handled by the Asset Manager.

General IT Management System

Management related to IT (information devices and systems, etc.) is handled by the Asset Manager’s Wellbeing Department, Administration and Accounting Division, with the Head of Administration and Accounting Division as the person responsible for IT control.
The person responsible for IT control is responsible for the following matters.

  • Supervision of IT-related operations
  • Overall IT management and maintenance
  • Provide guidance and advice to each department on the introduction of IT and promote its use
  • Other matters related to the handling of IT

Governance on Information Security and Cyber Security

Risks related to information and cyber security are handled by the Wellbeing Department, Administration and Accounting Division, which assesses risks using the risk assessment sheet and reports on control measures and other matters to the Compliance Committee, of which the Head of Administration and Accounting Division is a member, as well as to the Board of Directors and the DHR Board of Directors.

Compliance with the Guidelines on Cybersecurity Established by the Financial Services Agency

Based on the need to comply with the Financial Services Agency’s Guidelines on Cybersecurity for the Financial Sector, which were established in October 2024, the Asset Manager conducted a security assessment based on these guidelines with the full cooperation of Daiwa House Industry. The assessment covered a total of 176 items (126 fundamental response measures and 50 recommended measures). Following a gap analysis, each item was evaluated based on two criteria: “Extent of damage from incident” and “Likelihood of incident occurring.” Based on the assessment results, we intend to successively implement the necessary measures going forward.

Internal Rules on Information Security

At the Asset Manager, the employment rules require that, depending on the circumstances, an employee be reprimanded, reduced in pay, barred from work, suspended, or demoted/reduced in rank, if any of the following applies to the employee.

  • Leaking or attempting to leak company secrets outside the company, or obtaining company or other company secrets through improper means
  • Using company computers in violation of company regulations or other instructions, infecting them with computer viruses or otherwise interfering with business operations, or using them for unauthorized purposes outside of work and similarly interfering with business operations
  • Unauthorized entry into the company’s network or hacking activities
  • Using the Internet or e-mail for inappropriate purposes with an account lent by the company

Conducting drills to respond to targeted email attacks

The Asset Manager draws attention to suspicious emails through information security training conducted annually. However, in an effort to improve awareness among all officers and employees in a more practical way, the Asset Manager conducts drills for responding to targeted email attacks. If an officer or employee opens the email, then opens an attachment or clicks on an embedded link and logs in, they are shown educational content about targeted email attacks in an effort to verify and improve their awareness of information security.

Item Fiscal year ended March 2023 Fiscal year ended March 2024 Fiscal year ended March 2025 Fiscal year ended March 2026
Information security training 2 times 2 times 2 times 2 times

Verification of the Status and Evaluation of IT Operation and Management by Outside Contractors

When the Asset Manager contracts its IT operation and management to an outside contractor, the person responsible for IT control checks the contractor’s operational status on a quarterly basis. Additionally, IT managers evaluate outside contractors once a year, and reports to the person responsible for IT control.

Information Security-related Problems

There were no serious problems related to information security at the Asset Manager that would influence stakeholders. (Fiscal year ended March 2026)

The number of incident reports related to information security submitted to regulatory authorities by the Asset Manager.

FY2022 FY2023 FY2024 FY2025
0 1 1 0