Compliance and Risk Management

The Chief Compliance Officer, who is also the corporate officer responsible for internal control, heads the Corporate Compliance & Integrity Department and Risk Management Department and promotes compliance and risk management.
     
   

Compliance Promotion

Eisai promotes its compliance program that consists of delivering the message of top management, developing the Code of Conduct and other relevant rules, conducting educational activities, establishing a training system as well as providing consultation services by defining compliance as “the observance of the highest legal and ethical standards” and positioning it at the core of management activities. Based on a lesson from the international vitamin E cartel, Eisai started to promote full-fledged compliance in FY 2000. These compliance promotion programs periodically undergo objective reviews by Compliance Committee that consists of outside experts such as lawyers and consultants from Japan and overseas.

1. Establishment of Code of Conduct and Other Relevant Rules and Conducting Educational Activities to Foster Compliance Awareness

Eisai has been publishing Compliance Handbook, which outlines Eisai Network Companies (ENW) Charter of Business Conduct and the Code of Conduct, to cultivate the compliance awareness. For all officers and employees in all Eisai network companies, this handbook is available in 16 languages.

All officers and employees not only participate in training to understand contents described in Compliance Handbook, but also swear to comply with it every year.

In addition, with the aim of raising compliance awareness and preventing incidents from happening , we continuously conduct various training programs utilizing different formats, such as compliance workshops for corporate officers, e-learning trainings for all corporate officers and employees, and workshop training materials for each department.
 

Messages from Management
Code of Conduct
Compliance Awareness Survey

In order to grasp the compliance and organizational culture and matters that we must tackle, we conduct an All-ENW Compliance Awareness Survey every other year. The survey analyzes and evaluates ENW officers and employees on their awareness and activities concerning compliance. We utilize the results of the survey to further improve our compliance programs and also share the results with the corporate officers and department managers, leading to their voluntary actions to resolve matters identified.


2. Use of Compliance Counter

The Compliance Counter serves as a point of contact for whistle-blowing in ENW. It has been set up regionally, including in Japan, the United States, Europe, China, and Asia, in addition to being a global contact point for consultation and whistle-blowing that allows parties around the world to contact Japan directly in their local languages. The Company has also established outside consultation desks staffed by independent outside attorneys and outside consultation desks operated by neutral ombudspersons to handle problems related to work and the workplace, fostering an environment that makes whistle-blowing easier.

The Compliance Counter accepts not only whistle-blowing reports but also provides all sorts of consultations such daily activities regarding compliance. In FY 2021, Compliances Counter at Eisai Headquarters received more than 320 inquiries.

             

3. Prevention of Bribery and Corruption

Based on its strong determination to undertake honest business activities, Eisai formulated the Corporate Anti-Bribery and Anti-Corruption (ABAC) Policy for Eisai network companies in January 2012 (revised on October 1, 2018). This policy provides common rules for Eisai network companies when dealing with external parties in line with efforts to carry out business activities without bribery or corruption across the Eisai network companies.

As one concrete initiative, Eisai introduced the ABAC due diligence system that uses a web-based system for receiving responses to a globally common questionnaire on the possibility of bribery and corruption that is sent out beforehand to companies with which we plan to newly undertake transactions. By using this system, we have already achieved certain results in reducing risk associated with new business transactions. Based on the thinking of a risk-based approach, this system is being operated in the Americas region that includes Mexico, Brazil and Canada; the EMEA region that encompasses Russia and Eastern Europe; China, India, and countries in Asia.

 Additionally, Eisai is moving ahead with the advanced introduction of a system at overseas subsidiaries that detects signs of potential fraud by monitoring accounting and financial data.

4. Compliance-based promotion

Eisai conducts ethical promotion globally in accordance with compliance requirements. We disclose information on payments to medical institutions and patient groups, in accordance with the Japan Pharmaceutical Manufacturers Association (JPMA) guidelines, and the regulations and guidelines of each country in order to have broad societal understanding that our corporate activities are undertaken based on the highest ethics.

■Setting Forth a Code of Conduct in the Compliance Handbook

Eisai has set forth a code of conduct in the Compliance Handbook that is distributed to all employees to ensure compliance-based promotion. The following is an excerpt from the handbook.

  • Eisai markets and promotes its pharmaceutical products worldwide. We provide accurate and balanced scientific information, and promote our products only for the uses for which they have been approved by the applicable regulatory authorities.

  • “Promotion” means any activity undertaken, organized, or sponsored by a pharmaceutical company which is directed at Healthcare Providers (HCPs) to promote the prescription, recommendation, supply, administration, or consumption of its pharmaceutical products through all methods of communication, including the Internet.

  • When engaging in promotional activities with HCPs, we are expected to be familiar with local laws and regulations for such engagements in our home country.

  • Promotion in a manner not consistent with the approved label is prohibited and promotion of drugs prior to approval is also prohibited. All promotional materials must be reviewed and approved in accordance with local processes and may be used only for the approved purpose.

■Formulation of Eisai Co., Ltd. Code of Practice

In March 2012, the International Federation of Pharmaceutical Manufacturers & Associations (IFPMA) announced the “IFPMA Code of Practice” (“IFPMA Code”) as a code covering not only marketing activities but also interactions with healthcare professionals, medical institutions and patient organizations, as well as the promotion of medicines. In line with the intent of the IFPMA Code, the “JPMA Code of Practice” was established and implemented by the JPMA. Then Eisai, as a member of JPMA, established the “Eisai Co., Ltd. Code of Practice” in line with the aforementioned Code. All the executives and employees at Eisai engage in corporate activities with the aim of earning the trust from society by ensuring high level of transparency, ethics and corporate accountability in corporate activities involving researchers, healthcare professionals and patient organizations.

■Compliance Test

This is a set of questions that Eisai Group officers and employees ask themselves when they are unsure of a decision.

1. Could you openly tell your family what you have done?
2. Do you think it’s acceptable to be non-compliant as long as you are not found out?
3. How would it feel to read a report of your activities in the news or on social media?

Promoting Risk Management

1. Risk Management System

Eisai’s Board of Directors has established the "Rules on the Development of Systems Necessary to Ensure the Proper Execution of Duties by Corporate Officers etc." in accordance with the Companies Act. These Rules require all corporate officers to identify risks within their areas of responsibility and to establish, develop, and implement appropriate internal control systems.

 

The Representative Corporate Officer & CEO appoints a Corporate Officer responsible for Internal Control, who leads and promotes the development, maintenance, and effective operation of internal controls across the Group.

 

The Corporate Risk Management Department works collaboratively with Regional Risk Management Promoters to support the development, maintenance, and effective operation of internal controls across the Group.

To ensure effective risk management across the organization, Eisai conducts an annual global CSA (Control Self-Assessment) to identify and assess risks throughout the company. Out of the risks identified through this CSA, the Risk Management Committee, etc., discusses those risks that are shared Company-wide, and strives to prevent those risks from materializing.

 

Risk management structure

2. Eisai Network (ENW) Internal Control Policy

The Corporate Officer responsible for Internal Control has established a globally standardized “ENW Internal Control Policy”, and promotes the establishment, development, and implementation of internal controls across the Group.

Eisai Network (ENW) Internal Control Policy

Under the human health care (hhc) concept, we aim to effectively achieve social good in the form of relieving anxiety over health and reducing health disparities.

In order for us to achieve this goal, it is essential to establish internal controls, and continuously develop, implement, and improve them in compliance with laws and the Articles of Incorporation. For this reason, we hereby establish our internal control policy based on the "Corporate Governance Principles" and "Rules on the Development of Systems Necessary to Ensure the Proper Execution of Duties by Corporate Officers etc." established by the Board of Directors.

Therefore, we, as the officers, managers, and employees of ENW Entity, will commit ourselves to establishing internal controls and to their continuous development, implementation, and improvement in accordance with the following principles:

  • 1.
    We will identify and assess risks that may impact our business activities and operational processes, and fraud risks that may affect the corporate value, and take countermeasures.
  • 2.
    We will develop a control environment to include elements such as a business code of conduct, decision-making procedures for important matters, committees, job descriptions and the organizational culture to ensure the necessary ownership and treatment of risks.
  • 3.
    To mitigate and manage risks, we will develop and implement control mechanisms to include policies, internal rules, operating processes, systems, training, etc.
  • 4.
    We will develop and implement a structure for the appropriate storage and management of information related to business activities, appropriately recording and retaining the information, as well as communicating the information in a responsible and timely manner.
  • 5.
    We will develop and implement a system that shares and/or reports information with the relevant Eisai companies and organizations regarding the status of internal control development and implementation.
  • 6.
    We will enhance the effectiveness of our internal controls through regular self-assessments and third-party reviews.

February 16, 2026

Shin Kato

Vice President, Internal Control

Eisai Co., Ltd.

3. CSA (Control Self-Assessment)

CSA (Control Self-Assessment) is implemented as a tool to ensure effective risk management across the Group. CSA is a method for self-assessing risks and the status of their controls, and for using the results to lead to improvements. Eisai conducts CSA for all Corporate Officers. Eisai identifies critical risks across the company through identifying and assessing risks within their areas of responsibility by all Corporate Officers, and enhances the effectiveness of its risk management by following up on the status of responses to those risks.

 

Risk assessments by Corporate Officers are conducted twice a year—at the beginning of the fiscal year (prior to implementing countermeasures) and at the end of the fiscal year (after implementation)—to verify the effectiveness of these measures. The results are reported to the Board of Directors and the Audit Committee.

4. Risk Assessment Process

In the aforementioned CSA, the importance of risks identified by each Corporate Officer is assessed based on their impact and likelihood of occurrence of the risks, taking into account the status of the development and implementation of internal controls.

 

Risk assessment

5. The Risk Management Committee

The Risk Management Committee holds regular meetings (in principle, five times per year), either in Japan or globally depending on the matters to be considered), with the Corporate Officer responsible for Internal Control serving as the chair and receiving advice from the Board of Directors, to obtain comprehensive view of company-wide risks.

 

Based on this, the Committee conducts risk assessments, selects important risks from an enterprise-wide perspective, and supports risk owners in establishing, developing, implementing, and improving internal controls related to those risks.

 

In addition, to identify new risks and respond to them quickly and efficiently, the Committee reviews potential risks by referring to external corporate scandals and other incidents, and strives to prevent those risks from materializing.

     

● Overview of the methods to determine important risks to be followed by the Risk Management Committee

1)       The Secretariat of the Risk Management Committee (the “Secretariat”) comprehensively assesses all important risks identified by Corporate Officers through CSA, Materiality, Risk Factors, and selects candidates for important risks, taking into account internal controls spanning multiple Corporate Officers and departments.

2)       In determining candidates for important risks, the Secretariat considers the status of development and implementation of internal controls, the progress of countermeasures, the medium- to long-term impact, and the scope of Corporate Officers and departments involved.

3)       Risks identified as candidates for important risks are assessed from a comprehensive perspective, including the use of risk maps, to determine the final set of important risks.

4)       Notwithstanding the above processes, if concerns arise regarding new risks in the internal or external environment or in the advancement of business, the Committee will consider such risks based on the chairperson's instructions or suggestions from Committee members.

6. Training and related activities

The ENW Internal Control Policy states, 3. To mitigate and manage risks, we will develop and implement control mechanisms to include policies, internal rules, operating processes, systems, training, etc.” Based on this policy, we have developed and disseminated global guidelines for internal control and risk management.

 

We regularly conduct training on internal control and risk management through e-learning for executives and employees, as well as programs for newly appointed organizational leaders.

 

In 2026, we conducted training for newly appointed organizational leaders in April, training for overseas risk management promoters in May, and e-learning in June.

7. Audits related to risk management promotion activities, etc.

As part of confirming the implementation status of the "Rules on the Development of Systems Necessary to Ensure the Proper Execution of Duties by Corporate Officers etc." established by the Board of Directors, the Corporate Officer in charge of internal control reports the annual policy and results of risk management promotion activities to the Audit Committee.

 

This report covers all aspects of risk management promotion activities, including CSA (risk content and analysis results), training, the Risk Management Committee, as well as challenges and countermeasures related to these activities.