Risk Governance Structure
In strengthening our enterprise-wide risk resilience rooted in ESG principles, we have implemented an expanded risk governance framework that incorporates frontline risk sensing and double materiality assessment as core elements preceding the traditional Three Lines of Defense model. This integrated approach allows us to proactively identify and address stakeholder-specific impact issues, establishing a comprehensive, impact-driven risk management system that reinforces the effectiveness of conventional defense structures. Under this model, the first line of defense consists of operational departments that manage specific risk categories through direct, business-centered response activities. The second line comprises the enterprise risk management departments and executive leadership, who are responsible for strategic oversight and supervisory functions. The third line is composed of the internal audit unit and independent assurance bodies, which carry out objective evaluations and performance assessments. Together, these lines form a layered, accountable system that ensures both the integrity and completeness of our organization-wide risk response. Stakeholder feedback is continuously integrated into our risk management processes. ESG-related risks and mitigation activities are transparently disclosed through our Annual Report and Sustainability Report, reinforcing trust and accountability with stakeholders. Through this advanced and integrated risk governance system, we continue to enhance our ability to manage risks in alignment with long-term sustainability objectives.
[Risk Management Governance Structure]
You can zoom in or out of an image with two fingers.
Enterprise Risk Response Process
In strengthening our enterprise-wide risk resilience rooted in ESG principles, we have implemented an expanded risk governance framework that incorporates frontline risk sensing and double materiality assessment as core elements preceding the traditional Three Lines of Defense model. This integrated approach allows us to identify and address stakeholder-specific impact issues proactively, establishing a comprehensive, impact-driven risk management system that reinforces the effectiveness of conventional defense structures. Under this model, the first line of defense consists of operational departments that manage specific risk categories through direct, business-centered response activities. The second line comprises the enterprise risk management departments and executive leadership who are responsible for strategic oversight and supervisory functions. The third line is composed of the internal audit unit and independent assurance bodies that carry out objective evaluations and performance assessments. Together, these lines form a layered, accountable system that ensures both the integrity and completeness of our organization-wide risk response. Stakeholder feedback is continuously integrated into our risk management processes. ESG-related risks and mitigation activities are transparently disclosed through our Annual Report and Sustainability Report, reinforcing trust and accountability with stakeholders. Through this advanced and integrated risk governance system, we continue to enhance our ability to manage risks in alignment with long-term sustainability objectives.
[Integrated Process for Risk Response]
You can zoom in or out of an image with two fingers.
Risk types and Factors
CJ Logistics is establishing an integrated Risk Management system to cope with company-wide risks that may occur during management activities. Risk Management includes management of operational risks, market risks, regulatory risks, labor-management problems, illegalities, safety environments, etc. And the company manage the risks of customer complaints and information leakage, collect stakeholder feedback to further manage non-financial risks identified in the criticality assessment. In addition, to systematically respond to risks by risk factor, the company categorizes risk into three stages (R1, R2, R3) and establish response guidelines including management processes and action guidelines for each response stage. CJ logistics is making efforts to effectively respond to risks by introducing a mobile reporting system that enables immediate reporting and response regardless of location and time.
Risk types and Factors
| Category |
Risk type |
Risks |
| Business |
Operational Risk |
Investments, business plans, internal processes |
| Financial Risk |
Interest rates, liquidity, non-performing loans (NPLs) |
| Regulatory Risk |
Changes in relevant systems and government policies |
| Compliance Risk |
Violations of applicable laws and regulations, including the Capital Markets Act and financial legislation |
| Employees and Partners |
Labor relations risk |
Strikes, work stoppages and slowdowns, labor-management conflicts |
| Supplier risk |
ESG risks of suppliers (environmental regulation violations, strikes, work stoppages and slowdowns) |
| Ethical misconduct risk |
Unfair trade practices, embezzlement, bribery, sexual harassment |
| Occupational health and safety risk |
Personnel incidents, equipment accidents, fires, infectious diseases |
| Environmental risk |
Climate change, biodiversity loss, environmental pollution, natural disasters, sea level rise |
| Customer |
Customer satisfaction risk |
Handling of complaints and grievances |
| Information security risk |
Data breaches and external cyberattacks |