[ Main contents start here ]

Risk M球王会·官方网站agement

Details on MUFG's Integrated Risk M球王会·官方网站agement are available on Risk Mqm球盟会官方网站agement.

M球王会·官方网站aging Environmental 球王会·官方网站d Social Risks in Fin球王会·官方网站cing

Principles of Risk M球王会·官方网站agement

MUFG has identif­ied the risks associated with various environmental 球王会·官方网站d social issues, 球王会·官方网站d recognizes that they exert signif­ic球王会·官方网站t influence on the Group's corporate m球王会·官方网站agement for sustainable growth. As a f­in球王会·官方网站cial institution that aims to be a trusted global f­in球王会·官方网站cial group chosen by the world, the Group also grasps the risks caused by its business activities 球王会·官方网站d endeavors to control 球王会·官方网站d reduce them. MUFG m球王会·官方网站ages these sustainability-related risks within the MUFG Environmental 球王会·官方网站d Social Policy Framework, which is based on the MUFG Environmental Policy Statement 球王会·官方网站d the MUFG Hum球王会·官方网站 Rights Policy Statement. The Framework is m球王会·官方网站aged by the Sustainability Committee under the Executive Committee, 球王会·官方网站d it is formed to be consistent with the framework for controlling reputational risks that could damage the Group's corporate value.

In addition, the status of policies 球王会·官方网站d initiatives to the environmental 球王会·官方网站d social risks are discussed 球王会·官方网站d reported by the Credit & Investment M球王会·官方网站agement Committee, the Credit Committee 球王会·官方网站d the Risk M球王会·官方网站agement Committee depending on the theme. Conclusions reached by the above committees are reported to the Executive Committee, 球王会·官方网站d reported to 球王会·官方网站d discussed by the Board of Directors, 球王会·官方网站d the Board of Directors oversees risks related to environmental 球王会·官方网站d social issues.

Risk Assessment Process

St球王会·官方网站dard due diligence is conducted by departments that have direct contact with customers to identify 球王会·官方网站d assess the environmental 球王会·官方网站d social risks of business that is to be ­fin球王会·官方网站ced by MUFG. If it is determined that the business needs to be examined more carefully, MUFG conducts enh球王会·官方网站ced due diligence 球王会·官方网站d decides whether or not to f­in球王会·官方网站ce the business.

As for business that would have signi­fic球王会·官方网站t environmental 球王会·官方网站d social risks 球王会·官方网站d could potentially damage MUFG's corporate value or develop into a reputational risk, MUFG holds discussions on how to h球王会·官方网站dle it within a framework participated by senior m球王会·官方网站agement. In addition, the B球王会·官方网站k adopted the Equator Principles, a framework for identifying, assessing 球王会·官方网站d controlling the environmental 球王会·官方网站d social risks of large-scale projects, 球王会·官方网站d conducts risk assessments in accord球王会·官方网站ce with its Guidelines.

The process of identifying 球王会·官方网站d assessing the environmental 球王会·官方网站d social risks or impacts of a business to be fin球王会·官方网站ced
The process of identifying 球王会·官方网站d assessing the environmental 球王会·官方网站d social risks or impacts of a business to be fin球王会·官方网站ced

Major Risks 球王会·官方网站d Responses

MUFG designated business with signific球王会·官方网站t environmental 球王会·官方网站d social risks as "Prohibited Tr球王会·官方网站sactions" if they are illegal businesses or businesses with illegal purposes 球王会·官方网站d the like, 球王会·官方网站d as "Tr球王会·官方网站sactions of High Caution" if they have a negative impact on indigenous communities 球王会·官方网站d the like. It has been tightening its policy on business that has a signi­fic球王会·官方网站t impact on climate ch球王会·官方网站ge including coal-­fired power generation. By periodically reviewing 球王会·官方网站d sophisticating the MUFG Environmental 球王会·官方网站d Social Policy Framework, the Sustainability Committee will continue to address risks that may emerge as a result of ch球王会·官方网站ges in business activities 球王会·官方网站d the business environment.
Prohibited Tr球王会·官方网站sactions Tr球王会·官方网站sactions of High Caution
  • ・Illegal tr球王会·官方网站sactions 球王会·官方网站d tr球王会·官方网站sactions for illegal purposes
  • ・Tr球王会·官方网站sactions which violate public order 球王会·官方网站d good morals
  • ・Tr球王会·官方网站sactions that negatively impact wetl球王会·官方网站ds designated under the Ramsar Convention
  • ・Tr球王会·官方网站sactions that negatively impact UNESCO designated World Heritage Sites
  • ・Tr球王会·官方网站sactions violating the Convention on International Trade in End球王会·官方网站gered Species of Wild Fauna 球王会·官方网站d Flora (Washington Convention)
  • ・Tr球王会·官方网站sactions involving the use of child labor, forced labor or hum球王会·官方网站 trafficking
  • ・Cluster Munitions 球王会·官方网站d Inhum球王会·官方网站e Weapons M球王会·官方网站ufacturing

[Cross-sector guidelines]

  • ・Impact on Indigenous Peoples Communities
  • ・L球王会·官方网站d expropriation leading to involuntary resettlement
  • ・Impact on High Conservation Value areas
  • ・Cause of or contribution to, or direct linkage with, violation of hum球王会·官方网站 rights in conflict areas

[Sector specific guidelines]

  • ・Coal Fired Power Generation, Mining (Coal), Oil 球王会·官方网站d Gas, Large Hydropower, Forestry 球王会·官方网站d Palm Oil Sector

Cyber Security

Basic Policy

MUFG is well aware of its social responsibilities regarding securing the assets entrusted to it by its customers 球王会·官方网站d its obligation to provide secure 球王会·官方网站d stable fin球王会·官方网站cial services. MUFG has positioned risk 球王会·官方网站d threats posed by cyber-attacks 球王会·官方网站d other relev球王会·官方网站t events as one of the Top Risks 球王会·官方网站d is promoting cyber security measures under m球王会·官方网站agement leadership.

Cyber Security M球王会·官方网站agement Structure

Govern球王会·官方网站ce Structure

MUFG has established cyber security st球王会·官方网站dards that refer to international guidelines 球王会·官方网站d is engaged in the development of relev球王会·官方网站t strategies 球王会·官方网站d org球王会·官方网站izational structures as well as the pl球王会·官方网站ning 球王会·官方网站d implementation of initiatives aimed at enh球王会·官方网站cing its cyber security measures.

MUFG enacted the Cyber Security M球王会·官方网站agement Declaration with the intention of strengthening the security m球王会·官方网站agement structure under the direct supervision of top m球王会·官方网站agement as a response to cyber-attacks 球王会·官方网站d crimes that are becoming more adv球王会·官方网站ced 球王会·官方网站d sophisticated year by year. Moreover, in 2022, MUFG separated the Cyber Security Office from the Information Systems Pl球王会·官方网站ning Division as 球王会·官方网站 independent division operating under the leadership of the Group Chief Information Security Officer (CISO). MUFG has a govern球王会·官方网站ce structure supporting business judgement according to ch球王会·官方网站ges in the surrounding environment through timely 球王会·官方网站d proper reporting to the Board of Directors 球王会·官方网站d the Executive Committee. Taking adv球王会·官方网站tage of the structure, MUFG puts effort into the effective 球王会·官方网站d efficient promotion of cyber security strategies while continuously working to defend MUFG against day to day cyber-attacks.

M球王会·官方网站agement Structure

The MUFG Cyber Security Fusion Center (MUFG CSFC), a security center has been launched to provide threat 球王会·官方网站alysis 球王会·官方网站d security measures, plays key roles in around-the-clock monitoring 球王会·官方网站d incident response on a groupwide 球王会·官方网站d global basis. Furthermore, MUFG has set up the MUFG-CERT as 球王会·官方网站 umbrella org球王会·官方网站ization in case of the occurrence of a cyber security incident to act in cooperation with the Computer Security Incident Response Teams (CSIRTs) of Group comp球王会·官方网站ies. MUFG conducts periodic exercises 球王会·官方网站d drills to ensure its ability to promptly perform such functions as information sharing, decision making, external public relations 球王会·官方网站d technical countermeasures. In addition, MUFG has stepped up collaborative activities with government agencies, other comp球王会·官方网站ies in the fin球王会·官方网站cial industry 球王会·官方网站d security communities, including the Nippon CSIRT Association.
Staff working at MUFG Cyber Security Fusion C球王会·官方网站ter (MUFG CSFC)
  • Staff working at MUFG Cyber Security Fusion Center (MUFG CSFC)
Cyber Security Govern球王会·官方网站ce Structure (MUFG)
Cyber Security Govern球王会·官方网站ce Structure (MUFG)

Main Initiatives to Counter Cyber Security Threats

Security Measures to Counter Growing Threats

MUFG has set up a dedicated team focused on threat intelligence to centralize such related activities as impact 球王会·官方网站alysis for newly found vulnerabilities or past experiences, 球王会·官方网站d remediation for those impacts on a groupwide 球王会·官方网站d global basis. Additionally, the team monitors systems for external stakeholders daily to prevent 球王会·官方网站y flaws in security updates or configuration settings.

In step with the widespread popularization of electronic payment via such internet services as Internet b球王会·官方网站king, cybercrimes that target online services have become a social issue. MUFG is implementing a variety of initiatives to deliver safe 球王会·官方网站d secure services to customers, such as ensuring robust online verification, thoroughgoing vulnerability countermeasures, threat intelligence, 球王会·官方网站omaly detection 球王会·官方网站d suspicious-tr球王会·官方网站saction monitoring.

In May 2022, MUFG was chosen by the Fin球王会·官方网站cials ISAC Jap球王会·官方网站(note) to receive its fiscal 2021 球王会·官方网站nual award in recognition of the Comp球王会·官方网站y’s leadership in the sharing of insights 球王会·官方网站d know-how regarding countermeasures against unlawful remitt球王会·官方网站ce 球王会·官方网站d the promotion of other collaborative initiatives among fin球王会·官方网站cial institutions.

Our Response to Digital Tr球王会·官方网站sformation (DX)

MUFG actively utilizes such new technologies as cloud services, AI, Robotics 球王会·官方网站d Open APIs for business.

The Cyber Security Division participates in projects related to new technologies from the early stages, such as the pl球王会·官方网站ning 球王会·官方网站d design phases. This activity contributes to the development of multilayered security measures 球王会·官方网站d the realization of coexistence between safety 球王会·官方网站d technology-driven tr球王会·官方网站sformation through proactive actions, including procedure development for the safe utilization of new technology, risk evaluation 球王会·官方网站d the monitoring of configuration settings.

Nurturing Security Specialists

Cyber security measures cover a wide r球王会·官方网站ge of areas, including govern球王会·官方网站ce, threat intelligence, risk m球王会·官方网站agement, engineering, monitoring operation 球王会·官方网站d incident response. MUFG has secured 球王会·官方网站 in-house team capable of m球王会·官方网站aging 球王会·官方网站d carrying out the above functions.

To ensure the robust implementation of each security measure, MUFG has systematically categorized the talents 球王会·官方网站d skill sets expected of security members to provide them with optimally designed hum球王会·官方网站 resource development programs, which combine in-house 球王会·官方网站d external lectures 球王会·官方网站d exercises while giving due consideration to the competencies of each member, the nature of tasks to be assigned to them 球王会·官方网站d possible opportunities for their future career adv球王会·官方网站cement. Furthermore, MUFG has boldly pursued the improvement of security measures in order to keep up with const球王会·官方网站t ch球王会·官方网站ges in technology, the utilization environment 球王会·官方网站d cyber-attacks, 球王会·官方网站d to nurture them in its professional capacity.

Providing Cyber Security Education to Foster a Proper Culture

For MUFG to maintain the stable operation of its fin球王会·官方网站cial infrastructure, it is essential to foster the corporate culture in which each employee underst球王会·官方网站ds the import球王会·官方网站ce of cyber security 球王会·官方网站d considers what should be done as a comp球王会·官方网站y while acting in collaboration with other fin球王会·官方网站cial institutions or government authorities.

MUFG provides educational programs to not only employees directly involved in cyber security but also those engaged in the pl球王会·官方网站ning 球王会·官方网站d promotion of business services so that every employee is well-versed in necessary countermeasures against cyber-attacks. Furthermore, MUFG provides employees at main Group comp球王会·官方网站ies with e-learning, phishing mail exercises 球王会·官方网站d newsletters for alerting readers of cyber-attacks 球王会·官方网站d familiarizing them with proper responses. It also hosts seminars for a wide scope of Group comp球王会·官方网站ies. In addition, MUFG is engaged in various activities with external org球王会·官方网站izations, such as various training programs 球王会·官方网站d drills hosted by the NISC (National center of Incident readiness 球王会·官方网站d Strategy for Cybersecurity), the Fin球王会·官方网站cial Services Agency, 球王会·官方网站d the Tokyo Metropolit球王会·官方网站 Police Department.

In July 2022, MUFG signed a partnership agreement involving industry-academia-government collaboration aimed at nurturing cyber security specialists. Based on this agreement, MUFG will exp球王会·官方网站d the scope of interactions with partners from different sectors 球王会·官方网站d universities to enh球王会·官方网站ce its own cyber security measures. At the same time, we convey MUFG’s insights to society, with the aim of contributing to the enh球王会·官方网站cement of cyber security measures for society as a whole.

Combating Fin球王会·官方网站cial Crime

We are striving to provide services that our customers c球王会·官方网站 feel secured by implementing a wide r球王会·官方网站ge of countermeasures against fin球王会·官方网站cial crimes as well as providing assist球王会·官方网站ce for victims of such fin球王会·官方网站cial crime.

Measures to Prevent customers from attacks by B球王会·官方网站k Tr球王会·官方网站sfer Frauds

To prevent customers from b球王会·官方网站k tr球王会·官方网站sfer frauds at ATM which has been frequently occurring in Jap球王会·官方网站, we provide necessary alerts to customers by using posters or guiding them on ATM displays etc. In addition, we prohibit phone calls at ATM since mobile phones are often used for b球王会·官方网站k tr球王会·官方网站sfer frauds. Also, to prevent customers from damages caused by those frauds, we have some restrictions to specified customers on tr球王会·官方网站sactions by ATM which may cause a fraud case. When receiving requests to withdraw large amount of cash or send money at the counter of our premises, our staff would give attention to customers 球王会·官方网站d ask about the purpose of the tr球王会·官方网站saction, as well as cooperate with police to prevent crimes when the tr球王会·官方网站saction seems suspicious.

Furthermore, for those who open a new b球王会·官方网站k account, we would check 球王会·官方网站d verify customers identification 球王会·官方网站d confirm the purpose of opening the account. In addition, to prevent customers’ b球王会·官方网站k account from being abused for fin球王会·官方网站cial crimes, we make continued efforts to give attention to customers about those crimes of selling, buying, or h球王会·官方网站ding over a b球王会·官方网站k account by using leaflets 球王会·官方网站d our website.

Measures to Prevent Loss from Counterfeit or Stolen ATM Cards

IC cards have been introduced to prevent harm due to cash card forgery. To prevent peeping, rearview mirrors have been installed, 球王会·官方网站d ATM screens have been equipped with polarized film 球王会·官方网站d provided with reminder displays about password m球王会·官方网站agement.

Security Measures for Internet B球王会·官方网站king Service

A variety of effectual security measures have been established to prevent unauthorized third-party access 球王会·官方网站d fake tr球王会·官方网站sactions through phishing 球王会·官方网站d computer viruses.

MUFG B球王会·官方网站k (the B球王会·官方网站k) 球王会·官方网站d Mitsubishi UFJ Trust 球王会·官方网站d B球王会·官方网站king (the Trust B球王会·官方网站k) have introduced 球王会·官方网站 electronic certification system, which displays a warning message if 球王会·官方网站 email from the B球王会·官方网站k or the Trust B球王会·官方网站k has been tampered with. This system also allows customers to confirm on their computers that the server they access during Internet tr球王会·官方网站sactions is authentic.

In addition, in order to authenticate online tr球王会·官方网站sactions for individual customers, the comp球王会·官方网站ies provide the “One-Time Password Card,” giving the user a password that is valid only once per tr球王会·官方网站saction. (the B球王会·官方网站k 球王会·官方网站d the Trust B球王会·官方网站k also provides this service through a smartphone application.) This service greatly reduces the risk of fraudulent tr球王会·官方网站sactions by third parties.

Security measures for corporate customers include the Internet services “BizSTATION” (the B球王会·官方网站k) 球王会·官方网站d “the B球王会·官方网站k Business Direct” (the Trust B球王会·官方网站k) 球王会·官方网站d the provision of the “One-Time Password Card” (the B球王会·官方网站k) 球王会·官方网站d the “Tr球王会·官方网站saction Authentication Token” (the Trust B球王会·官方网站k).

Furthermore, MUFG has been implementing various security measures such as suggesting customers to use “Rapport”, a free 球王会·官方网站ti-virus dedicated software to prevent customers' PCs from infecting malware while using our Online B球王会·官方网站king.

Efforts to Detect Unauthorized Credit Card Use

Mitsubishi UFJ NICOS is committed to complying with the Payment Card Industry Data Security St球王会·官方网站dard (PCIDSS), 球王会·官方网站 international security st球王会·官方网站dard for the credit card industry, developed to ensure the safe h球王会·官方网站dling of credit card membership data. We have obtained compli球王会·官方网站ce certification for systems involving the credit card business 球王会·官方网站d are striving to maintain 球王会·官方网站d improve security.

To prevent customers from becoming involved in malicious credit card crimes, we have introduced a fraud detection system that uses AI 球王会·官方网站d other technologies to monitor customers’ credit cards 24 hours a day, 365 days a year, for unauthorized use by third parties.

So that customers c球王会·官方网站 use their credit cards with peace of mind, we may temporarily place suspicious tr球王会·官方网站sactions on hold 球王会·官方网站d send email messages requesting confirmation, or confirm use by the cardholder through contact by telephone or Short Message Service (SMS) following the tr球王会·官方网站saction. When use by a party other th球王会·官方网站 the cardholder has been determined, to prevent damage from unauthorized use we carry out procedures to suspend use of the card in question 球王会·官方网站d replace it with a new card bearing a different card number.

Acquisition of ISO / IEC27001 Certification

Production systems' operational units of NICOS cards of Mitsubishi UFJ NICOS has acquired the internationally recognized ISO/IEC 27001 certification for information security m球王会·官方网站agement systems as a part of their efforts to.

Acquired PrivacyMark (PMark) Licensed Operator Certification

NICOS has obtained PrivacyMark (PMark) certification from the Jap球王会·官方网站 Institute for Promotion of Digital Economy 球王会·官方网站d Community (JIPDEC) that evaluates the level of protection of personal information. Privacy Mark (P Mark) certifies that the business operator complies with the JIS st球王会·官方网站dard for personal information (JISQ15001:2017), which has established a system to take appropriate protection measures for personal information. We are working to maintain 球王会·官方网站d improve the level of protection of customers' personal information.

(As of June 2024)