Nanto Bank Ltd.TSE: 8367

Risk Management System Enhancement

· MarketScreener

Governance

Upgrading risk management systems

Basic Policy

Nanto Bank is reinforcing its risk management in recognition of the importance of preventing assorted management risks and taking measures to mitigate or avoid others, while also responding to emergency situations that could exert a significant impact on its corporate activities.

Measures to combat money laundering and financing of terrorism, diffusion fi- nance, corruption, and bribery

Recent years have brought increasing demand from the international community for measures to combat money laundering and prevent financing of terrorism, diffusion finance, corruption, and bribery (money laundering, etc., hereafter). In this context, we have positioned money laundering prevention as one of our most important management issues. We have appointed the officer in charge of the department responsible for overseeing measures to prevent money laundering as the AML General Bank Manager. We also aim to improve the effectiveness and sophistication of our money laundering prevention by, for example, establishing the "Policy Against Money Laundering, Etc." as a fundamental Group policy.

In response to the emerging financial crimes that are becoming more complex and sneakier, meanwhile, we are also striving to maintain safe, highly convenient financial services by enhancing our preventive measures to prevent our customers from accidentally becoming involved in any financial crimes.

Policy Against Money Laundering

1. Organizational structure

  1. The Bank considers countermeasures against criminal activities such as money laundering to be one of the most important issues for management. It complies with all applicable laws and regulations concerning their prevention and establishes and implements the necessary administrative procedures. We also deploy our resources appropriately, including assignment of personnel with the requisite expertise and allocation of budgets.
  2. The Bank shall establish a centralized management system by designating a person responsible and a supervisory department for money laundering prevention and shall respond to the relevant issues in a cross-organizational manner through coordinated efforts of the departments involved.

2. Risk-based approach

The Bank shall employ a risk-based approach to appropriately identify and assess money laundering and other risks and shall implement mitigation measures commensurate with the risks.

3. Customer management policy

The Bank shall establish a system for conducting confirmation appropriately at the time of transactions and other customer management measures in accordance with the applicable legal and regulatory requirements. It shall also examine and analyze customer transaction records periodically and implement necessary customer management measures.

4. Reporting of suspicious transactions

The Bank shall confirm and determine whether transactions reported by its branch offices or detected through transaction monitoring are suspicious and shall notify the authorities immediately if it determines that a transaction is suspicious.

5. Correspondent bank management

The Bank shall collect information on correspondent banks, assess it adequately, and take proper measures in response to the risks associated with it. It shall eliminate any relationships with spurious banks that have no actual business operations as well as any business with correspondent banks that engage in transactions with fictitious banks with no business presence.

6. Management and employee training

The Bank shall conduct ongoing training programs to educate its officers and employees fully with respect to money laundering to raise their levels of expertise and assure proper responses.

7. Compliance auditing

The independent Internal Audit Department shall conduct regular audits of the Bank's money-laundering prevention and related systems, and the Bank shall draw on the results of the audits to improve its systems further.

8. Economic sanctions and asset freezing

The Bank shall take such appropriate measures in accordance with domestic and foreign laws and regulations as eliminating business relationships with parties subject to economic sanctions and freezing their assets.

9. Anti-bribery and anti-corruption actions

The Bank shall comply with the main objectives of laws and regulations related to the prohibition of bribery and the prevention of corruption. It shall refuse any requests to engage in bribery and avoid providing entertainment or gifts that exceed the socially acceptable value.

We shall endeavor, moreover, to ensure that our officers and employees are trained in the highest professional ethics. We have established guidelines regarding business entertainment and gifts, etc., with which our officers and employees are required to comply.

Strengthening credit risk management

Credit risk is the risk of incurring losses due to a decrease or loss of the value of assets stemming from deterioration of the financial condition of the creditor. We contribute to our customers' development through solutions based on our "know your customer" efforts, offering thorough financial and/or core business support to improve the quality of the Group's assets at the same time.

78 Nanto Report 2024, the integrated report of Nanto Bank

Administrative risk management (Thorough, accurate office work) System risk management
(Response to system failures/prevention of unauthorized use)
Legal risk management (Monitoring of legal compliance) Human risk management (Response to personnel and labor problems) Tangible asset risk management (Response to impairment of tangible assets) Rumor risk management
(Response to false assertions circulating in the market and among customers)
Liquidity risk management
Integrated risk management system
Operational risk
management
Market risk
management
Credit risk
management

About Nanto Bank

Nanto Group Corporate

Practicing Sustainable

Local Market

Strengthening

Control of Net Assets

Governance

Consolidated Financial

Value Enhancement

Management

Revitalization

Profitability

Statements

Governance

Risks and

Performance

opportunities

Risk management systems

Integrated risk management

To reinforce our ability to manage the risks we face in our banking business, Nanto Bank has assigned responsibility for each risk to an appropriate department and established the Risk Management Division to handle them in an integrated manner by determining the various risks' individual positioning and magnitude and responding to each promptly and accurately.

In our commitment to risk management, we have specified basic risk management policies through various directives, including our "Integrated Risk Management Regulations."

To realize integrated risk management in which risks are quantified on a unified scale and the amount of each is controlled to an appropriate level in relation to equity capital in consideration of management strength, we determine the risk capital allotment (capital allocation amount) for each type of risk semi-annually within the range of equity capital, and control each risk amount (value at risk = VaR, etc.) to ensure that it falls within the scope of

capital. The ALM Committee evaluates the status of each risk at its monthly meetings as part of efforts to achieve more efficient, effective risk / return management, and systems are in place

to exercise appropriate controls for ensuring management stability and improving profitability from the perspective of effective use of capital.

Risk management organization

(As of June 30, 2024)

Committees

System

Supervisory departments

Classification

(department

in charge)

Operations

departments

Audit and Supervisory Committee

Board of Directors

Emergency countermeasures meetings

Various management meetings

(Alert countermeasures meetings)

ALM Committee

Operational Risk Management Committee

Compliance Committee

(ALM Subcommittee)

(Operational Risk Management Subcommittee)

(Compliance Subcommittee)

Risk management system

Compliance structure

Risk Management Division

Compliance Control Department

Operational risk (Risk Management Division)

Compliance

Credit risk

Market risk

Liquidity risk

(Risk Management

(Risk Management

(Risk Management

Administrative risk

System risk

Legal risk

Human resources risk

Tangible asset risk

Reputation risk

(Compliance

Division)

Division)

Division)

(Personnel and

Control Department)

(Business Support

(IT Strategy

(Compliance Control

(Personnel and General

(Corporate Planning

Department)

Department)

Department)

General Affairs

Affairs Departments)

Department)

Departments)

Headquarters departments, sales branches, consolidated subsidiaries

Internal

Audit Division

Internal Audit Division

External audits and auditors

Crisis management system

The Bank's risk management systems discussed here are further augmented by its Crisis Management Plan, which is accompanied by a response manual for each type of crisis compiled to facilitate appropriate responses to crises that may impact our business, including natural disasters such as large-scale earthquakes, system failures, and epidemics of infectious diseases. In the event of a crisis, the Emergency Countermeasures Committee or Countermeasures Headquarters gathers information depending on the degree of the crisis, and issues centralized guidance and orders to minimize its impact on operations.

We also implement measures to ensure the Bank's ability to continue providing customer services as one of the service providers playing an essential role in maintaining social functions. These include such measures as enhancing our facilities to enable continued operation, even in the event of a disaster, and ensuring the effectiveness and continuous improvement of our Crisis Management System through crisis management drills and other measures.

Nanto Report 2024, the integrated report of Nanto Bank 79

Governance

Commitment to strict compliance

Compliance systems reinforcement

Compliance must always be ensured in observance of not only laws, government ordinances, and internal rules, but also of ethical and social norms. It is imperative that banks fulfill their social responsibilities and public missions in good faith. At Nanto Bank, we are implementing the following measures to ensure our full compliance with any and all applicable rules:

Being fully aware of our public mission and social responsibility as a financial institution, Nanto Bank seeks to gain the trust of its stakeholders, including its regional community and shareholders, by positioning compliance with laws and regulations as the most important issue for management. To this end, we have formulated "Basic Guidelines" and a "Code of Conduct" as corporate policies, with which all the Bank's officers and employees must comply.

The Bank formulates a Compliance Program including these policies each fiscal year and ensures that it is shared with and observed by all its Group member companies. The progress and status of achievement of the Compliance Program is verified semiannually and reported to the Compliance Committee and the Board of Directors.

In order to define a basic framework for our compliance systems, we have clarified our stance toward compliance with laws and regulations, not only by establishing compliance regulations but also by formulating disciplinary regulations that show the fairness and transparency of our disciplinary actions.

We have established a Compliance Committee chaired by the President to serve as a cross-sectional organization within the Bank that discusses and decides important matters related to compliance, as well as a supervisory department responsible for planning and supervising compliance.

Each fiscal year, we prepare a compliance program as a concrete, practical plan for achieving compliance, after which we investigate the program's implementation status and make appropriate revisions.

We are pursuing efforts to optimize operation of our compliance hotline, a whistle-blower system established for purposes of prevention and early detection and correction of violations of laws and regulations, harassment, and corrupt practices such as bribery. For the purpose of protecting whistleblowers, we accept anonymous or publicly known names and conduct investigations under strict information management, such as management ensuring that information concerning informants will be handled only by the informant's contact person to prevent identification of the whistleblower. We also ensure that whistleblowers are not searched or treated unfavorably in any way, including through personnel actions because of their reporting.

As concerns violations of laws and regulations and various types of harassment, the Bank provides guidance for managers through annual training of compliance officers and training at the time of promotion to managerial positions. It holds monthly compliance study sessions featuring lectures by personnel responsible for compliance in each department and branch office, moreover, in an effort to raise awareness among all its employees concerning prevention of legal violations and harassment.

We have compiled a "Compliance Handbook" to serve as a detailed guide to maintaining compliance, and we are following up with efforts to foster a compliance mindset by distributing the handbook to all our management and general personnel, and by holding regular group training and study sessions at every workplace.

In accordance with our resolute attitude toward antisocial forces that threaten the order and safety of civil society, we have formulated a set of "Regulations for Dealing with Antisocial Forces, Etc." to establish and maintain a system that eliminates any relationships with antisocial forces.

Whistleblower hotline

The Bank has established a compliance hotline to strengthen its compliance management by providing the officers and employees of the Bank and its Group companies with an enhanced ability to detect and correct violations of laws and ordinances at an early stage.

Reporting content

Any violation of laws or ordinances, or of compliance or ethics issues involving the Bank or its Group companies, its officers or employees

[Persons who have been retired from Nanto Bank or a Group company for less than one year] [Reporting contact]

(Internal contact)

(External contact)

Name: Compliance Management Department, The Nanto Bank, Ltd.

Name: Ohmine Law Office

Address: 16 Hashimoto-cho,Nara-shi630-8677

Address: 308, Nara Prefectural Keizai Club Kaikan, 3F, 6 Higashi Mukinaka-

Telephone: 0742-27-1530

machi, Nara City, Japan 630-8215

email: hot-line@nantobank.co.jp

Telephone: 0742-81-8500

[All officers and employees (including those who have retired within the past one year) of entities handling business outsourced by Nanto Bank and its Group companies]

[Reporting contact] Name: Ohmine Law Office

Address: 308, Nara Prefectural Keizai Club Kaikan, 3F, 6 Higashi Mukinaka-machi, Nara City, Japan 630-8215

Telephone: 0742-81-8500

80 Nanto Report 2024, the integrated report of Nanto Bank

About Nanto Bank

Nanto Group Corporate

Practicing Sustainable

Local Market

Strengthening

Control of Net Assets

Governance

Consolidated Financial

Value Enhancement

Management

Revitalization

Profitability

Statements

Governance

Risks and

Performance

opportunities

Cyber security initiatives

The Bank has compiled a policy on cyber security initiatives to reinforce its protection against cyber-attacks and other such threats.

Action Initiatives

With cyber-attacks threatening to become increasingly serious in the future, we recognize optimizing our cyber security to ensure the safety of our customers and assets as an important issue for management. Nanto Bank's CSIRT* plays a central role in ongoing Bank-wide efforts to implement effective cyber security related to the mid-term "road map" as well as to enhance our readiness to respond promptly to cyber-attacks.

*CSIRT: A security organization designed to respond to incidents related to computer security

Management involvement

Our Information Asset Management Regulations stipulate that the executive in charge of the IT Strategy Department shall be the general manager of CSIRT. We have been prioritizing development of a cyber security framework under the leadership of the Bank's management in a proactive manner. Participants in the Bank's CSIRT meetings discuss our progress in realizing our mid-term roadmap and annual plan for cyber security, as well as conditions in the surrounding environment and other issues. Among other precautions, the number of confirmed cyber-attacks and content of all internal and external trends are reported to the CSIRT General Manager and the Operational Risk Management Committee.

Outsourcing management

We use cloud services or external information systems that meet our information system security standards only after examining the security measures they employ. In addition, we routinely review such introduced services as a follow-up regimen.

Audit structure

The Audit Department and a major consulting firm conduct joint cyber security audits to facilitate advanced audits meeting recent trends in possible threats to financial institutions. Issues identified in such auditing processes will then be constantly dealt with in accordance with the Nanto Bank CSIRT's annual schedule, and the Audit Department monitors the status of efforts to strengthen cyber security management systems throughout the Bank's organizations.

Internal audit structure

Aims of the internal audits

The Internal Audit Department, the Nanto Bank Group's department responsible for internal audits, verifies and evaluates the effectiveness and appropriateness of internal management systems and controls, such as compliance and risk management, from a standpoint independent of the executive departments for the purpose of ensuring sound, appropriate business operations and contributing to achievement of the Group's management objectives as well as of making recommendations for correction and improvement of problematic issues.

Internal Audit Structure

The Internal Audit Department maintains its independence by reporting directly to the Board of Directors in order to ensure that there are sufficient checks and balances in place for the audited departments. It also evaluates and checks the company's operational procedures based on an internal audit plan and internal audit regulations approved by the Board of Directors for the fiscal year while at the same time observing the appropriateness and effectiveness of the Bank's internal control systems continuously as part of its monitoring function.

Corporate governance structure

General Meeting of Shareholders

Appointment/dismissal

Appointment/dismissal

Appointment/dismissal

Report

Board

of Directors Audit/supervision

Audit and

Supervisory Committee

Directors excluding Audit and

Directors

who are Audit and

Supervisory Committee members

Supervisory

Committee members

Findings

Inquiry

Appointment/dismissal/supervision

Report

Exchange of

Nomination and Compensation Advisory Committee

opinions

Auditor

Report

President and Representative Director

Instructions

Audit

Instructions

Collaboration

Report

Advisory Board

Advice

Accounting

Audit Department

ALM

Committee, Compliance Committee

Management Committee

Internal audit

Various committees

Instructions and supervision

Operational Risk Management Committee, etc.

Headquarters

Accounting audit

Intermediate holding company

Sales branches

Consolidated subsidiaries

Reporting and collaboration

Appointment, dismissal, non-reappointment/judgment of appropriateness of accounting audit

Assistance

Audit Committee Secretariat

Nanto Report 2024, the integrated report of Nanto Bank 81