Section 1 - Risk identification and evaluation
We define and classify risk categories based on Japanese and international technical standards and best practices (e.g., the US National Institute of Standards and Technology (NIST) Risk Management Framework, the OECD AI Principles, Japan's AI Guidelines for Business, and, where applicable, regulations like the EU AI Act), and we evaluate risks based on these categories.
The Rakuten Group has established a specialized department in charge of AI safety and security. There are systems in place to proactively develop safe services while eliminating vulnerabilities (information security flaws) and risks by ensuring thorough security and privacy education for developers, implementing security and privacy reviews during the software development process, and conducting inspections for vulnerabilities and risks. Our efforts to prevent AI safety and security incidents also include monitoring illegal access, and surveying and responding to information security and privacy flaws.
The department in charge of AI safety and security conducts general security and safety-related tests to evaluate the suitability of models and systems. In addition, the group's quality control department adds checks to reduce AI risks from the perspective of shipment checks and conducts the necessary verification.
Rakuten Group operates a wide range of businesses both domestically and internationally. As our business expands, we encounter numerous potential risks that could escalate into significant issues. We define risk as “uncertainty that may affect the achievement of management objectives” and we have implemented Enterprise Risk Management (ERM) to enhance the likelihood of achieving these objectives. We have also been operating a Vulnerability Disclosure Program since 2023.
The Rakuten Group has established a Groupwide Computer Security Incident Response Team (CSIRT) to cooperate with external stakeholders such as relevant ministries, organizations specialized in combatting cybercrime, and other security companies, and we are strengthening our cooperation with organizations such as the police and other administrative and investigative agencies, Forum for Incident Response and Security Teams (FIRST), and the Nippon CSIRT Association.
We are committed not only to maintaining our own security but also improving information security for society as a whole. We are also promoting information exchange with the AI Safety Institute (AISI) in Japan and the AI Governance Association in Japan regarding AI-specific risk events.
At Rakuten Group, we are committed to risk management to achieve sustainable development amidst rapid changes in the business and social environment. Our risk management system is built on three key pillars: Enterprise Risk Management (ERM), Incident Management, and Business Continuity Management (BCM).
Under our Group-wide regulations on risk management, we have developed a system that follows a plan–do–check–act (PDCA) cycle for identifying risks, formulating and implementing countermeasures based on their significance, and monitoring the results.
Rakuten Group is a member of the AI Governance Association and actively exchanges opinions with related stakeholders across sectors.
No answer provided


























