Building a Compliance Framework and Fostering a Sound Risk Culture to Support Sustainable Value Creation
In light of changes in the internal and external environment and growing societal expectations regarding the management of non-financial risks, establishing an effective compliance framework and fostering a sound risk culture have become essential to maintaining the trust and confidence of our stakeholders. The Bank views compliance not merely as a matter of rules and controls, but as a foundation that enables sound challenge and supports sustainable value creation. To achieve this, it is essential to foster a culture in which each employee uses our Code of Conduct, centered on integrity and fairness, as the basis for decision-making and exercises autonomous judgment in an environment of psychological safety. In FY2026, under the theme of “Every employee protects, communicates and demonstrates integrity, fairness and psychological safety,” senior management will continue to communicate these values directly and promote initiatives to ensure that they are put into practice in employees' day-to-day work.

CHISHIRO Koji
Executive Officer (General Manager of Legal Affairs and Compliance Division)
Chief Compliance Officer (non-financial risk)
Initiatives for Compliance
Basic Compliance Policies
To fulfill its basic mission and social responsibilities and meet the expectations of its customers and members, the Bank manages its business in accordance with societal norms, for instance, by fully complying with laws and regulations based on the principle of total self-responsibility. We are also constantly working to achieve a higher degree of transparency by emphasizing proper disclosure and accountability.
As part of this effort, the Bank has defined its basic compliance policy in its Code of Ethics, Environmental Policy, and Human Rights Policy.
Compliance Framework
The Bank's compliance framework is centered on the Compliance Committee established under the Board of Directors, the department that supervises overall compliance (Legal Affairs and Compliance Division), and the compliance officers and other personnel assigned to each branch and division. The Compliance Committee is the body responsible for deliberating and determining important matters relating to the development of the Bank's compliance framework. Matters of particular importance discussed by the Committee are also submitted and reported to the Board of Directors (generally twice a year). In addition to compliance-related matters, the Committee also addresses matters relating to non-financial risks and discusses policies concerning the execution of these important business activities.
The Legal Affairs and Compliance Division, supervising overall compliance activities, is responsible for developing and maintaining the Bank-wide compliance framework. It also promotes the Compliance Program for each fiscal year and supports compliance activities across the Bank's branches and divisions. In addition, the compliance officer in each branch and division bears ultimate responsibility for compliance implementation within the branch or division and ensures the execution of initiatives based on the Compliance Program.
Compliance framework

Practical Compliance Initiatives
As the secretariat of the Compliance Committee, the Legal Affairs and Compliance Division works to strengthen the Bank's compliance framework through activities such as compliance reviews, responding to compliance-related inquiries from branches and divisions, and conducting compliance monitoring, including visits to branches and divisions to assess and provide guidance on compliance practices. The Division also promotes awareness among officers and employees through the planning and delivery of internal training, as well as the development of e-learning programs and training videos.
At the branch and division level, all employees participate in the compliance framework, centered on branch and division managers as “persons responsible for compliance,” together with “persons in charge of compliance” and “compliance leaders.” In particular, “persons in charge of compliance” are appointed directly by the General Manager of the Legal Affairs and Compliance Division and are responsible for overseeing compliance-related matters within their respective organizations. Their responsibilities include responding to compliance-related consultations and inquiries from employees, conducting internal training and guidance, and serving as a point of contact for reporting, consultation and communication with the Legal Affairs and Compliance Division and other relevant functions.
In addition, Legal Affairs and Compliance Officers are assigned to all Head Office units to provide compliance support for their respective operations. These officers respond to legal and compliance-related inquiries from the executive officer responsible for each unit and provide advice on such matters. They also plan and promote training and awareness-raising activities within their units and identify and assess compliance risks.
Compliance Program
Each fiscal year, the Bank formulates a Compliance Program incorporating its management frameworks for compliance and customer protection, as well as promotion of initiatives, education, and training plans for them.
The Legal Affairs and Compliance Division implements the Compliance Program and monitors its progress to further enhance the Bank’s compliance framework.
Cooperation with Group Companies
The Bank shares its recognition of compliance-related issues through the Group Compliance Meeting and other forums. In addition, it strives for the early identification and resolution of issues by measuring effectiveness through questionnaires regarding the progress of each Group company's Compliance Program, monitoring reports submitted to the Group's shared external consultation hotline, and conducting off-site monitoring (and on-site monitoring where necessary) of Group companies.
Whistleblowing System
The Bank has established a Compliance Hotline so that directors, employees and others can report compliance-related issues by telephone, e-mail or other means.
The Compliance Hotline offers multiple reporting channels, allowing reports to be made either to the Legal Affairs and Compliance Division or to external legal counsel. Employees and officers may choose to report either anonymously or by name. Upon receiving a report, the Bank conducts appropriate investigations and implements any necessary remedial or corrective measures. The Bank's system is operated with the protection of the whistleblowers as the highest priority, for example prohibiting any disadvantageous treatment of a whistleblower and maintaining the information of reported content secret, and the Bank strives to improve trust in the system.
In fiscal 2025, although 17 cases were reported, none resulted in a major impact on the management of the Bank.
In addition, overseas branches each have contacts, separate from those described above, in place to receive reports from employees, but no reports were made in fiscal 2025.
Measures to Prevent Money Laundering
The Bank has established policies to prevent money laundering as follows to ensure that the entire group complies with the relevant laws and regulations and fulfills its sound financial intermediary function.
Group-wide Basic Policy
The Bank and the Norinchukin Group comply with all applicable laws and regulations, take robust confirmation measures when accepting customers to exclude antisocial elements, terrorists, etc., and implement continuous customer management measures based on a risk-based approach. The Bank ensures the maintenance of its effective management system to prevent money laundering, in accordance with the characteristics of the Bank and the Norinchukin Group.
Customer Management Policy
With an appropriate internal system to prevent money laundering and other risks, the Bank takes the following measures according to the risk-based approach.
- Strict confirmation before each transaction using various information gathered when accepting customers initially, and the preservation of confirmation records
- Management measures to reduce money laundering and other risks, such as monitoring of transactions based on business characteristics, notification of suspicious transactions, and analysis and management thereof
- Control measures in accordance with the magnitude of money laundering and other risks for each customer, such as strict control of additional confirmation for customers with high money laundering and other risks
- Review of customer management measures based on the results of periodic investigation and analysis of all customer transactions
- Measures such as terminating transactions if appropriate customer management cannot be implemented or for other reasons
- Measures such as freezing assets of terrorists
- Prevention of economic sanctions violations
- Appropriate measures to prevent financial crime
- Confirmation of the anti-money laundering measures within foreign banks with which the Bank concludes correspondent agreements
- Continuous management and review of the above measures
Internal Management System Policy
The Bank takes the following measures to improve its internal management system to prevent money laundering and other risks.
- Establish and implement policies, procedures and plans for the prevention of money laundering and other risks; inspect and verify the status of compliance; and continually improve the system based on the results of such inspection and verification
- Promote all directors and employees awareness of the importance of their roles in preventing money laundering and other risks and foster a corporate culture of such awareness, through guidance and trainings
- Appoint managers in charge
- Clarify the roles of the divisions such as business divisions/branches that handle customers, operation management divisions, and audit divisions
- Report to the management on the status of measures to improve the management system over the entire Norinchukin Group, including its overseas offices; the status of customer management and other updates; and continue improvement measures
- Other necessary measures
Measures to Combat Bank Transfer Fraud
The Bank has established policies to prevent money laundering and other fraudulent activities and is strengthening preventive measures in this area as part of an increasingly necessary international cooperative effort.
Measures to Eliminate Antisocial Elements
Under the Code of Ethics, the Bank takes a strong and resolute stance against antisocial elements that pose a threat to social order and security, and in order to block all relationships with such antisocial elements, the Bank has established a systematic exclusionary system, in line with the following basic principles, and strives to ensure sound management.
1) Response as an organization
The Bank has established the foundation of express provisions under the Code of Ethics and will respond as an entire organization, from the top management downward, and not simply leave it to the personnel or department in charge.
In addition, the Bank will guarantee the safety of employees who are asked to respond to unjustified demands from antisocial elements.
2) Cooperation with outside agencies
In preparation for unjustified demands from antisocial elements, the Bank endeavors to establish continuing cooperation with outside agencies such as the police, the National Centers for Removal of Criminal Organizations and lawyers.
3) Blocking of relationships including business transactions
The Bank shall block all relationships with antisocial elements including business relationships. In addition, unjustified demands from antisocial elements will be rejected.
4) Civil and criminal legal responses in times of emergency
The Bank shall reject unjustified demands from antisocial elements and take legal action, if necessary, on both a civil and criminal basis.
5) Prohibition of secret deals and provision of funds
Even in cases where the unjustified demands from antisocial elements are based on misconduct related to business activity or involving an employee, the Bank will absolutely not engage in secret deals. Furthermore, the Bank shall absolutely not provide funds to antisocial elements.
Bribery and Corruption Prevention
The Bank’s “Rules on Gift and Hospitality,” which are set forth under the Code of Conduct, clearly state that the Bank is committed to preventing corruption in all its forms, including extortion and bribery. Bribery includes the act of providing or offering to provide goods or other things (including non-monetary benefits) with the intention of influencing the recipient, and the act of accepting or requesting goods or other things with the intention of offering benefits to the provider.
In accordance with the said rules, the Bank stipulates the necessary procedures to ensure the appropriateness of gifts and hospitality acts involving the Bank or its directors and employees and ensures that all directors and employees are fully aware of these procedures. When those acts are conducted, the Bank ensures that the personnel responsible for and in charge of compliance confirm in advance that there are no problems from such perspectives as appropriateness and legal compliance.
In addition, the Legal Affairs and Compliance Division periodically monitors the status of gifts and hospitality acts and reports to the Compliance Officer, the Compliance Committee and the Board of Directors. Moreover, the Compliance Hotline is in place to enable directors and employees to whistleblow on compliance issues, including corruption and bribery, by telephone or e-mail.
Information security management
The Bank utilizes a variety of information obtained through transactions with customers in its various business operations. At the same time, advancement in information technology have diversified both the environments in which information is handled and the purposes for which it is used. Against this backdrop, the Bank places particular emphasis on information security management among non-financial risks in order to appropriately protect and manage customer information, and has established a governance framework in which the Board of Directors bears ultimate responsibility for maintaining an information security management structure.
The Bank requires all employees to complete information security e-learning programs and provides training programs each year to enhance awareness.
With respect to the handling of personal information, the Bank has established its Personal Information Protection Declaration and maintains an appropriate management framework. The Bank has also established privacy policies applicable overseas, in Europe and the United States. In addition, with respect to suppliers (outsourcing contractors), the Bank has established processes and contractual arrangements designed to ensure risk management standards equivalent to those applied by the Bank itself, thereby promoting the appropriate handling of personal information.
Governance framework for information security

Responding to Customer Consultations and Complaints
The Bank takes consultations and complaints from customers seriously, responds to them promptly and systematically, and reflects them in its business operations in a positive manner to improve customer convenience.