Sony Homepage

Internal Control and Governance Framework

Corporate Governance

Introduction

At a Board meeting held on April 26, 2006, the Board reaffirmed the internal control and governance framework in effect as of the date of determination and determined to continue to evaluate and improve such framework going forward, as appropriate. At Board meetings held on May 13, 2009 and April 30, 2015, the Board amended and updated the internal control and governance framework, and as of May 8, 2026, the Board reaffirmed that such framework was in effect and determined to continue to evaluate and improve such framework going forward, as appropriate. These determinations were required by and met the requirements of the Companies Act of Japan. For the content of the reaffirmation and the status of its implementation determined by the resolution of the Board dated as of May 8, 2026, please refer to the page below.

As for the summary of the principal framework of the internal control and governance framework based on the Board determination above, please refer to the following.

Financial Reporting Framework

Sony’s internal control over financial reporting is designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with International Financial Reporting Standards (IFRS).
Sony formed a cross-functional steering committee comprised of management in charge of the principal Sony headquarters functions to monitor the actions necessary to maintain effective internal control over financial reporting, including documenting, testing and evaluating internal controls and overseeing and assessing the global evaluation. Based on the evaluation by Sony Group Corporation, CEO and CFO have concluded that Sony maintained effective internal control over financial reporting as of March 31,2026.

Disclosure Control Framework

The securities of Sony Group Corporation, are listed for trading on exchanges in Japan and the U.S. As a result, Sony is obligated to make various disclosures to the public in accordance with applicable securities laws, regulations and rules in those countries and listing standards of the stock exchanges on which Sony Group Corporation’s shares are listed. Sony is committed to full compliance with all requirements applicable to its public disclosures.
Sony Group Corporation’s policy on investor relations activities is to aim to disclose accurate information in a timely and fair manner, as well as to endeavor to promote constructive dialogue with shareholders and investors, with a view to maximizing corporate value by building a relationship of trust with shareholders and investors. Sony Group Corporation has established disclosure controls and procedures as an approach to implement this policy. All personnel responsible for the preparation of submissions to and filings with the Tokyo Stock Exchange, the U.S. Securities and Exchange Commission and other regulatory entities, or for other public communications made on behalf of Sony, or who provide information as part of that process, have a responsibility to ensure that such disclosures and information are full, fair, accurate, timely and understandable, and in compliance with the established disclosure controls and procedures. Sony Group Corporation has established “Disclosure Controls and Procedures” outlining the process through which potentially material information is reported from important business units, subsidiaries, affiliated companies and corporate divisions and is reviewed and considered for disclosure in light of its materiality to Sony. As a body to assist the CEO and the CFO of Sony Group Corporation, in designing, implementing and evaluating the Disclosure Controls and Procedures, Sony Group Corporation has established the “Disclosure Committee,” which is comprised of members of senior management who are in charge of a part of Sony’s headquarters functions. In order to ensure appropriate and timely disclosure, the Disclosure Committee shall evaluate events that are reported by the important business units, subsidiaries, affiliated companies and corporate divisions in accordance with Sony’s internal rules in light of their materiality to Sony. Based on such evaluation, the Disclosure Committee shall review the necessity of disclosure in accordance with applicable securities laws, regulations and rules, as well as the listing standards of the relevant stock exchanges, and report to the CEO and CFO for their determination.

Risk Management Framework

Each business unit, subsidiary/affiliated company and corporate division of Sony periodically reviews and assesses risks and establishes and maintains necessary risk management systems (such as detection, communication, evaluation and response) for the area for which they are responsible. In addition, Senior Executives, including the Corporate Executive Officers, of Sony Group Corporation have established and currently maintain a system to identify and control risks that may cause losses to Sony Group regarding the areas for which they are responsible. The Corporate Executive Officer in charge of group risk control shall comprehensively promote and manage the establishment and maintenance of the systems stated above through the activities with related departments.
Examples of risks that may significantly impact investor judgements include reduced market relevance and profitability due to intensifying competition from competitors; newly incurred costs to comply with laws and regulations in countries and regions where Sony operates; impact on global operations due to trade restrictions and economic sanctions imposed by certain countries and retaliatory measures to them; impairment of long-lived assets; and changes in consumption behavior caused by the increasing prevalence of new technologies and distribution platforms.

Crisis Management System Framework

One aspect of risk management is the proper handling of crises if and when they arise, and the proper preparation for such crises. Sony Group’s crisis management and business continuity activities predominately occur at the business and operational level closest to the events Sony Group may encounter. Since some events can have a significant impact on Sony as a whole, Sony Group Corporation has established a group crisis management procedure to enable a swift and organized group-wide response to crises as needed.

Framework on Business Continuity Planning

Sony has strengthened its business continuity planning (BCP) to enhance risk management throughout the supply chain. The group identifies, analyzes, and evaluates business risks to mitigate the risk of business disruptions due to such emergencies as earthquakes, natural disasters, and accidents.
Sony’s electronics business was significantly impacted by the Great East Japan Earthquake and severe flooding in Thailand in 2011, and by the earthquakes in Japan’s Kumamoto region in 2016. Nevertheless, Sony’s employees and top management rallied together, capitalizing on their experiences in implementing measures to ensure business continuity, and succeeded in minimizing the impact of production disruptions. Knowledge gained from recovery efforts after the Kumamoto earthquakes was shared with relevant companies and local firms through industry bodies, to enhance the competitiveness of Japanese industry and strengthen supply chains.
In response to COVID-19, Sony established a group crisis management system in fiscal year 2019, placing the highest priority on ensuring safety and preventing the spread of the virus, as well as taking swift action to minimize the impact on Sony businesses. At that time, Sony secured business continuity through its global coordination, including by establishing internal guidelines, implementing measures in accordance with those guidelines and preparing emergency supplies. Sony Group Corporation is committed to building and continuously enhancing a cross-functional crisis management framework to prepare for large-scale disasters, including a major earthquake directly beneath the Tokyo metropolitan area. The Group also reviews the crisis management and business continuity plans of its businesses to improve their effectiveness, while maintaining policies and governance structures designed to address major incidents and business disruptions. Through these initiatives, Sony Group continues to strengthen resilience across the organization. Sony also continues to strengthen rapid recovery potential by strengthening cooperation among relevant companies and organizations and conducting realistic exercises.
Sony regards its BCP as an important part of its business strategy. Sony will continue to implement effective, practical measures, such as enhancing risk management across its group-wide supply chains.

Main Initiatives for Reducing Business Disruption Risks for Building and Equipment

Countermeasures Against Earthquakes

Utilizing lessons learned from the Kumamoto earthquakes, Sony is establishing guidelines for seismic measures for Sony group companies in Japan. These measures, which are essential to the safety of employees, are established by determining the seismic wave activity at each business site and conducting simulations to assess risk. The seismic measures apply to building structures and utility facilities as well as non-structural materials such as ceiling materials, to enhance safety in an earthquake. Sony is implementing safety measures that are particularly high in priority.

Countermeasures Against Fire

The Sony Group has global guidelines to facilitate early fire detection and protection against the spread of fire in buildings and equipment. Under the guidelines, Sony’s manufacturing sites around the world implement annual self-checks and are regularly audited on-site by the responsible department in Headquarters to verify compliance with them. Manufacturing sites implement Plan-Do-Check-Act (PDCA) cycles to address any uncovered issues and establish improvement plans to effectively reduce risks.

Countermeasures Against Flood-Related Damage

Sony has completed a survey of climate change-related flood risks at vulnerable business sites. Preventative measures will be taken depending on the situation to mitigate damage in the event of a flood and ensure that operations can be rapidly restored.

Examples of Reducing Business Disruption Risks

Semiconductor Development Center: Building Waterproof Walls to Reduce Flood Risk

Sony Semiconductor Solutions Inc. Atsugi Technology Center installed 1.4 km of waterproofing walls in 2024 to prevent flooding. Atsugi Technology Center conducts research, development, and design of CMOS image sensors and other semiconductor-related products. Sagami River, a first-class river, flows to the east of the center. If heavy rainfall exceeds the expected amount of rainfall and the upstream embankment breaks, the Center may suffer flooding damage.
In addition, if rainfall exceeds the city's capacity for handling, flood damage is expected. To address these risks, waterproofing walls are installed to prevent flooding. Inland water is drained to the outside of the Center through common ditches, and these measures significantly reduce the risk of flood damage.

Photo: Waterproof walls of the main gates and south gates
Waterproof walls of the main gates and south gates

Semiconductor Manufacturing Site: Seismic Isolation Structure and Initiatives to Reduce Fire Risks

The Nagasaki Technology Center of Sony Semiconductor Manufacturing Corporation became the first manufacturing site of the Sony Group to adopt a seismic isolation structure. This is being incorporated in its expansion building, which was completed in 2023. The seismic isolation system employs a hybrid seismic isolation structure with multiple base isolation devices to mitigate earthquake motion, and micro-vibration control essential for a semiconductor plant.
The expansion building is compliant with the Sony Group’s global guidelines on building and equipment specifications, to reduce fire risk. For example, the building features an NFPA* compliant high-sensitivity smoke detection system and sprinklers, non-flammable exterior walls and exhaust ducts, and fire barrier walls between distribution transformers, for early fire detection and protection against the spread of fire.

  • *The National Fire Protection Association (NFPA) is a US-based organization that develops standards for fire prevention.
Photo: Hybrid seismic isolation structure
Hybrid seismic isolation structure

Cybersecurity

Like many companies, Sony faces increasingly sophisticated cybersecurity threats, so the importance of information security continues to grow. In recent years, malicious actors seeking to compromise the information systems of global companies continue to grow in number, and their attack methods are becoming more advanced. Sony recognizes the importance of cybersecurity, both in achieving financial success for the company and in maintaining the trust of its stakeholders, which include shareholders, customers, employees, suppliers, and business partners. To address this situation and ensure that Sony continues to earn customers’ trust, Sony maintains and enhances an information security program.

Risk Management & Strategy

As part of Sony’s risk management framework, Sony maintains and continuously strives to enhance its information security program. This program covers the entire Sony Group and is implemented in accordance with policies and standards, which include cybersecurity risk management and governance frameworks, and guidance, developed by Sony and based on globally recognized industry best practices and standards. The policies define information security responsibilities within Sony and outline certain actions and procedures that officers and employees are required to follow, including with respect to the assessment and management of cybersecurity risks to Sony, including its systems and information. The policies, standards, and guidance are structured to help Sony respond effectively to the dynamically changing environment of cybersecurity threats, cybersecurity risks, technologies, laws, and regulations. Sony modifies its policies, standards, and guidance as needed to adjust to this changing environment.
If Sony’s cybersecurity risk management controls are overcome by a cyber attacker, Sony follows an incident response plan and escalation process as defined in the information security program. The response process includes an assessment of whether an incident may be material, and this assessment is adjusted as necessary as additional facts become known during the incident response. Any incident that is assessed as potentially material is escalated to Sony’s senior management and is reported to the three outside Directors in charge of information security on Sony Group Corporation’s Board of Directors.
In the fiscal year ended March 31, 2026, Sony was the victim of several cyberattacks. None of these incidents was assessed to be material, nor did they materially affect Sony’s business strategy, the results of its operations, or its financial condition. However, there can be no guarantee that this will be the case with a future incident.
Sony has also established policies and processes to help identify and manage cybersecurity risks associated with third parties, including companies that provide services and products to Sony, and companies that hold Sony information or have electronic access to Sony systems or information. The policies and processes include assessment of the cybersecurity and privacy programs at certain third parties, the use of this risk information when making contracting decisions, and the use of contract language that includes cybersecurity and privacy requirements.
Most of the information security program is implemented by Sony employees. Sony also engages the services of external providers to enhance and support its information security program, including leading cyber response specialists as may be needed, and consultants to evaluate and help improve organization, policies, and other aspects of the program.

Structure and Governance of Sony’s Information Security Program

Sony’s information security program is under the responsibility of a Senior Executive, specifically, the Sony Group Chief Digital Officer (“CDO”), and the Sony Group Global Information Security Officer (“GISO”), who reports to the CDO.
Under the leadership of the CDO and the GISO, and supported by a global information security team that works across the entire Sony Group, Sony implements the cybersecurity risk management and governance frameworks that are described in its policies and standards. Each business segment of Sony has a senior information security leader, called an Executive Information Security Officer (“EISO”), who reports both to the GISO and to the senior management of the particular business unit. The EISOs and their associated teams are responsible for ensuring implementation and operation of the information security program in a way that is tailored to each specific business unit, including as it relates to the assessment and management of cybersecurity risks. The GISO coordinates with the EISOs to monitor the implementation of Sony’s cybersecurity policies and standards.
The current CDO has experience in launching and overseeing the development, technical operation, and business operations of large-scale network products and services at Sony, including overseeing implementation and operation of the information security program. The current GISO has more than 40 years of experience in cybersecurity. Before joining Sony, the GISO served as Deputy Chief Information Officer for Cybersecurity of the U.S. Department of Defense (the Department’s equivalent of a Chief Information Security Officer) and before that, as the Chief Information Assurance Executive at the Defense Information Systems Agency (DISA), an agency of the U.S. Department of Defense.
The Sony Group CEO receives regular reports from the CDO and/or the GISO, additional reports as needed during the response to a cyber incident, and briefings from the CDO and GISO at various times during the year. The head of each Sony business segment also receives regular briefings from the CDO and the GISO, as well as reports and briefings from the business segment EISO.
The Board of Directors oversees Sony’s information security risks, significant incidents, policies and key initiatives. The full Board of Directors receives reports from the outside Directors in charge of information security as well as briefings several times a year from the CDO and the GISO, and also engages in discussion of these matters.
The following three outside Directors oversee Sony’s information security efforts, via monthly meetings and ad-hoc incident response communications with the CDO and GISO.

  • Joseph A. Kraft Jr., outside Director, serves simultaneously as the Chair of the Audit Committee.
  • Neil Hunt, outside Director, has extensive experience in the development of large-scale information systems, including experience with the management of cybersecurity risks.
  • Nora Denzel, outside Director, has deep experience in information technology cultivated at several Silicon Valley-based companies, including experience with the management of cybersecurity risks.

Employee Training as a Key Component of Information Security

Every employee has a critical role to play in protecting Sony’s most sensitive information and information technology assets. To increase Sony employees’ awareness of information security threats, Sony requires all personnel to receive regular information security training, where they learn how to report incidents and study the types of behaviors they must avoid in order to reduce risk. Sony employees also regularly receive phishing awareness training, which tests employees’ knowledge of how to spot and avoid cyber-attacks delivered through fraudulent emails.

Structure of Audit by the Audit Committee, Internal Audit and Accounting Audit, and Status Thereof

Audit Structure and Status of the Audit Committee

The Audit Committee conducts audits of the performance of duties by Directors and Corporate Executive Officers pursuant to applicable laws and regulations and the Charter of the Audit Committee established by the Board, through deliberation at Audit Committee meetings (held seven times during the fiscal year ended March 31, 2026), activities of Audit Committee Members (for example, reviewing reports relating to the execution of duties by the Corporate Executive Officers and employees of Sony Group Corporation, or directors, statutory auditors and employees of major subsidiaries of Sony Group Corporation, and visiting audits at business sites), and activities of the Audit Committee Aide (including attendance at meetings relating to important management execution matters, review of meeting materials, and review of approval documents and other materials concerning the Senior Executives).
In addition, the Audit Committee conducts the “organizational audit” in cooperation with divisions in charge of internal audit and divisions in charge of internal control of Sony. Through the process, the Audit Committee receives periodical reports from these divisions at the Audit Committee meetings or other meetings to be held from time to time, requests that they conduct necessary investigations, and receives reports on the process and result of such investigations. Furthermore, the meetings with divisions in charge of internal control of Sony were held seven times and the meetings with and written reports from the independent auditor were held and received, in total, eight times during the fiscal year ended March 31, 2026.
During the fiscal year ended March 31, 2026, the Audit Committee convened seven times. The attendance records of respective Directors are as follows.

Name Meeting Records*1 Attendance Records*1

Joseph A. Kraft Jr.

7 times

7 times (100%)

Keiko Kishigami*2

7 times

7 times (100%)

Shingo Konomoto

7 times

7 times (100%)

Yoriko Goto*3

4 times

4 times (100%)

  • *1The numbers of the Meeting Records and the Attendance Records are those applicable to the fiscal year ended March 31, 2026.
  • *2Ms. Keiko Kishigami, who was a member of the Audit Committee during the fiscal year ended March 31, 2026, retired as a member of the Audit Committee at the conclusion of the Ordinary General Meeting of Shareholders on June 23, 2026.
  • *3Because Yoriko Goto was newly appointed as a member of the Audit Committee pursuant to the resolution at the meeting of the Board held on June 24, 2025, the numbers of her Meeting Records and Attendance Records differ from those of other members of the Audit Committee.

Specific considerations by the Audit Committee include review of audit plans in three-way audits, identification and audit of priority audit items for each fiscal year, review of financial results and disclosure documents related to financial results, review of development and operation of internal control systems, audit of financial reports and SOX 404-related activities, audit of internal audit activities, review of the content and process for determining the compensation of the independent auditors, audit of the appropriateness of audit by the independent auditors and evaluation of the independent auditors. In addition to these, the Audit Committee held interviews with the Senior Executives and other officers to receive reports on matters such as the recognition of issues and the status of risk management in the respective areas of responsibility of each business and headquarter function, and engaged in dialogue.
The priority audit items for the fiscal year ended March 31, 2026. were the focus areas and governance framework under the new management structure, responses to changes in the business portfolio, and responses to new accounting standards and disclosure standards not yet adopted. Through the organizational audit described above, the following audit activities were conducted.

ⅰ) Focus areas and governance under the new management structure
The Audit Committee engaged in dialogue with the newly appointed Chief Officers, whose roles were effective April 1, 2025, regarding their focus areas under the new management structure and the status of progress. In meetings with the Business CEOs, in light of the rapidly increasing uncertainty in the business environment, the Audit Committee discussed opportunities and risks identified as particularly significant within their respective areas of responsibility and confirmed that prompt responses to risks and initiatives to strengthen the profitability of each business were being advanced.
ⅱ) Responses to changes in the business portfolio
With respect to the Partial Spin-off of the Financial Services business, the Audit Committee held in-depth discussions with the internal control department and the independent auditor regarding the appropriateness and sufficiency of the phased accounting treatments and related disclosures. In addition, the Audit Committee reviewed the policies and details regarding accounting treatments and disclosures in connection with the establishment of a joint venture through a strategic partnership in the home entertainment field between Sony Corporation and TCL Electronics Holdings Limited and its subsidiaries
iii) Responses to new accounting standards and disclosure standards not yet adopted
The Audit Committee received reports on preparations for sustainability disclosures in accordance with the sustainability
disclosure standards published by the Sustainability Standards Board of Japan, which will be effective from the fiscal year ending March 31, 2027, and reviewed the disclosure policy options available to Sony, Sony’s status of collecting such information for disclosure, and related challenges.

Internal Audit Structure and Status

Sony Group Corporation established a department in charge of internal audit, the Risk & Control Department (which is composed of approximately thirty members), which coordinates closely with the internal audit departments of major subsidiaries around the world, and Sony Group Internal Audit Charter, and endeavors to maintain and enhance the internal audit structure of Sony in order to promote Sony’s internal audit activities on a global basis. The Risk & Control Department and each Internal Audit Department of major subsidiaries of Sony (“Internal Audit Department”) play an important function in maintaining Sony’s governance in order to strengthen Sony’s management structure, promote efficiency of management, and maintain and avoid any loss of material assets, including Sony’s brand image, by evaluating the effectiveness of the internal control system and risk management structure of Sony through independent and objective audit.
The Risk & Control Department and each Internal Audit Department conduct the internal audit of each department or subsidiary that they supervise, in accordance with the annual audit plan that is established based on the risk assessments conducted at the beginning of each fiscal year and any matters proposed by Sony’s management or the Audit Committee. Each internal audit is conducted under the planned audit procedure. Afterward, each Internal Audit Department follows up until the completion of any improvement plan developed based on the audit result.
In order to ensure its independence, fairness and objectiveness, the appointment and dismissal of the head of the Risk & Control Department is subject to the prior approval of the Audit Committee. The appointment and dismissal of the person in charge of each Internal Audit Department also require the prior approval of the head of the Risk & Control Department.
The Risk & Control Department makes periodic presentations on the result of internal audit to the Audit Committee, and the Senior Executive in charge of internal audit.
The Internal Audit Department also make periodic reports to the independent auditor on the status of the internal audit activities and the result of the audit. The audit report issued by the independent auditor is used for the planning of the internal audit and for conducting the internal audit.

Accounting Audit Status

Sony’s accounting audit has been conducted by PricewaterhouseCoopers Japan LLC under an agreement since 2007. The certified public accountants who conducted the accounting audit of Sony for the fiscal year ended March 31, 2026. are as follows: Takeaki Ishibashi,* Yuko Harada,* Hitoshi Kondo,* and Shizue Takashima.* The team at PricewaterhouseCoopers Japan LLC that conducted Sony’s accounting audit is composed of 37 certified public accountants and 136 other staff members.

  • *The number of years of continuous audit-related work is not stated because it is within 7 years.

Policy and Governance Framework on Tax Strategy

Tax Policy

Sony conducts its business, including managing its tax obligations, honestly, ethically and with integrity. The Sony Group Code of Conduct defines Sony’s policy as being to comply with all applicable tax laws and regulations of each country and region where Sony conducts business as well as the common rules and guidance regarding international taxation. Sony understands and complies with both the spirit and letter of the laws and regulations that apply to its businesses.

Governance Structure

Based on the above global tax policy, each Sony group company has the responsibility to understand and comply with tax laws and regulations applicable to its businesses, with support from Sony’s Global Tax Office (the GTO), which is in charge of Sony’s overall tax position. The global head of the GTO reports directly to Sony Group Corporation’s CFO based in Japan, who is a Corporate Executive Officer. Significant tax events are reported to the Audit Committee and are included in reports to the Board of Directors as necessary. The GTO has implemented a series of processes and controls to identify, manage and report tax risk appropriately. These include regular updates with finance teams, documented review processes, regular training for staff involved in tax return preparation and review, and regular updates with the global head of the GTO. Transactional taxes such as VAT and sales taxes, customs duty, employment taxes, and other taxes are the ultimate responsibility of the relevant divisional Finance Director for each business. The GTO has strong links with these divisional Finance Directors to ensure that, in the event of material risks being identified or errors made, the GTO provides support, including liaising with the relevant tax authority where necessary.

GTO Report Line

Diagram: The GTO reporting line (details in main text)

Approach to Tax Planning

Sony operates diverse businesses within a complex global environment, in which tax is an important factor. Sony believes in taking a principled and responsible approach to managing its tax affairs, in line with business objectives and operations. Sony does not engage in transactions where the sole aim is to achieve tax avoidance or profit shifting, which are against the spirit of tax laws. The tax function provides appropriate input as part of the approval process for business proposals to ensure the tax consequences are clearly understood. Sony is committed to fulfilling its obligation both to comply with applicable tax laws and to safeguard Sony’s reputation. The jurisdictions in which Sony does business may offer various tax incentives such as enhanced deductions, credits and exemptions for certain types of income and expense to meet local policy objectives such as encouraging inward investment. Sony Group Corporation believes it has a duty to its shareholders to take advantage of such incentives where they are generally available to all taxpayers who meet the relevant criteria and the requirements to claim the incentives do not conflict with broader business objectives.

Tax Risks

Sony employs diligent professional care and judgment in assessing tax risk, and may take advice from third-party specialists and, where appropriate, consult with or obtain rulings from relevant tax authorities to support the decision-making process. However, tax law is not always clear and unambiguous, and differences in interpretation can arise. Sony monitors its tax positions closely and will not record an accounting benefit unless it determines based on consideration of the facts and the law that it is more likely than not that the position will be sustained.

Dealings with Tax Authorities

Sony seeks to maintain good professional relationships with tax authorities. When providing responses to Tax Authority questions, all responses are based on an honest and accurate representation of the facts as Sony understands them.

Transparency

Sony Group Corporation prepares and files annually a country-by-country report in accordance with Japanese law and prepares and files a transfer pricing master file in accordance with the laws of the countries where Sony does business.