← Back to MUFG filing summaryOriginal filing text · Part I
Item 11 — Quantitative and Qualitative Disclosures About Market Risk
Mitsubishi Ufj Financial Group Inc · 20-F · FY 2026 · Period ended Mar 31, 2026
View complete filing on SEC EDGAR ↗This is the extracted source text from the SEC filing. Formatting may differ from the original document.
In the current market and regulatory environment, financial groups such as us are expected to ensure increasingly more sophisticated and comprehensive risk management. Risk management plays an increasingly important role in our operations as a financial group operating globally through various subsidiaries.
We identify various risks arising from businesses based on group-wide uniform criteria and implement integrated risk management to ensure a stronger financial condition and to maximize shareholder value. Based on this approach, we identify, measure, control and monitor a wide variety of risks so as to achieve a stable balance between earnings and risks.
Not all risks, including certain climate-related risks, can be managed in a quantitative manner due either to the nature of the risk or the lack of quantitative inputs available to us. Where quantitative assessment is not feasible, we use a qualitative approach in an effort to manage the associated future risks.
We undertake risk management to create an appropriate capital structure and to achieve optimal allocation of resources. However, our risk management measures may not be fully effective in identifying all risks or mitigating the impact of any materialized risk on us.
Risk Classification
At the holding company level, we broadly classify and define risk categories faced by the Group, including those that are summarized below. Group companies perform more detailed risk management based on their respective operations.
129
Table of Contents
Type of Risk Definition
Credit Risk The risk of financial loss in credit assets (including off-balance sheet instruments) caused by deterioration in the credit condition of counterparties. This category includes country risk.
Market Risk The risk of financial loss where the value of our assets and liabilities could be adversely affected by changes in market variables such as interest rates, securities prices and foreign exchange rates. Market liquidity risk is the risk of financial loss caused by the inability to secure market transactions at the required volume or price levels as a result of market turbulence or lack of trading liquidity.
Funding Liquidity Risk The risk of incurring loss if a poor financial position at a group company hampers the ability to meet funding requirements or necessitates fund procurement at interest rates markedly higher than normal.
Operational Risk The risk of loss resulting from inadequate or failed internal processes, people or systems, or from external events.
•Operations Risk The risk of incurring losses arising from negligence of correct operational processing, incidents or misconduct involving officers or staff, as well as risks similar to this risk.
•Information Risk The risk of loss caused by loss, alteration, falsification or leakage of personal or other confidential information, as well as risks similar to such risk.
• IT Risk The risk of loss arising from destruction, suspension, malfunction or misuse of IT, or unauthorized alteration and leakage of electronic data caused by insufficient IT systems planning, development or operations or by vulnerabilities of or external threats to IT system security, including cybersecurity, as well as risks similar to such risk.
•Tangible Asset Risk The risk of loss due to damage to tangible assets or deterioration in the operational environment caused by disasters or inadequate asset maintenance, as well as risks similar to this risk. Tangible assets include movable and immovable property, including owned or leased land and buildings, facilities incidental to buildings, and fixtures and fittings.
• Personnel Risk The risk of loss due to an outflow or loss of human resources or deterioration in employee morale, as well as risks similar to this risk.
•Incompliance with Laws and Regulations Risk The risk of loss due to failure to comply with laws and regulations, as well as risks similar to such risk.
• Legal Risk The risk of loss due to failure to identify or address legal issues relating to contracts and other business operations or insufficient handling of lawsuits, as well as risks similar to such risk.
Reputation Risk The risk of harm to our corporate value arising from perceptions of our customers, shareholders, investors or other stakeholders and in the market or society that we deviate from their expectations or confidence.
Model Risk The risk of loss due to decision-making based on information provided by an inaccurate model or the misuse of a model.
Risk Management System
We have adopted an integrated risk management system to promote close cooperation among the holding company and group companies. The holding company and our banking and securities subsidiaries each have appointed a chief risk officer and established an independent risk management division. The board of directors of the holding company determines risk management policies for various types of risks based on the discussions at, and reports and recommendations from, committees established specially for risk management purposes. The holding company has established committees to oversee management in managing risks relevant to the Group. Following the fundamental risk management policies determined by the board of directors, each group company establishes its own systems and procedures for identifying, analyzing and managing various types of risks from both quantitative and qualitative perspectives. The holding company seeks to enhance group-wide risk identification, to integrate and improve the Group’s risk management system and related methods, to maintain asset quality, and to eliminate concentrations of specific risks.
The following diagram summarizes our integrated risk management framework:
130
Table of Contents
Risk Management System
Crisis Management Framework
In order to have a clear critical response rationale and associated decision-making criteria, we have developed systems designed to ensure that our operations are not interrupted or can be restored to normal quickly in the event of a crisis such as a natural disaster, cyber-attack, system failure or a pandemic of an infectious disease so as to minimize any disruption to customers and markets. A crisis management team within the holding company is the central coordinating body in the event of any emergency. Based on information collected from crisis management personnel at the major subsidiaries, this central body would assess the overall impact of a crisis on the Group’s business and establish task forces that could implement all countermeasures to restore full operations. We have business
131
Table of Contents
continuity plans to maintain continuous operational viability in the event of natural disasters, cyber-attacks, system failures and other types of emergencies. Regular training drills are conducted to upgrade the practical effectiveness of these systems.
We conduct a comprehensive review of our existing business continuity plan to more effectively respond to such extreme scenarios, and contemplate and implement measures to augment our current business continuity management framework, including enhancing our off-site back-up data storage and other information technology systems.
Implementation of Basel Standards
In determining capital ratios under the FSA guidelines implementing Basel III, we and our major banking subsidiaries have used the Advanced Internal Ratings-Based approach, or the AIRB approach, to calculate capital requirements for credit risk since March 31, 2024. Since the same date, we have reflected market risk in our risk-weighted assets by using the Standardized Approach and the Simplified Standardized Approach, and have reflected operational risk in our risk-weighted assets by using the Standardized Measurement Approach.
Based on the Basel III framework, the Japanese capital ratio framework has been revised to implement the more stringent requirements, which are being implemented in phases beginning on March 31, 2013. In addition, based on the final Basel III reforms, the Japanese capital ratio framework has been further revised to implement the reforms, which are being applied to Japanese banking institutions with international operations conducted through foreign offices, including us, in phases beginning on March 31, 2024, and are scheduled to be fully implemented from March 31, 2029. Likewise, local banking regulators outside of Japan have begun, or are expected, to revise the capital and liquidity requirements imposed on our subsidiaries and operations in those countries to implement the more stringent requirements of Basel III as adopted in those countries. We intend to carefully monitor further developments with an aim to enhance our corporate value and maximize shareholder value by integrating the various strengths within the Group. For more information on the Basel regulatory framework and requirements, see “Item 4.B. Information on the Company—Business Overview—Supervision and Regulation.”
Credit Risk Management
We have established risk management systems to maintain asset quality, manage credit risk exposure and achieve earnings commensurate with risk.
MUFG and its major banking subsidiaries apply a uniform credit rating system for asset evaluation and assessment, loan pricing, and quantitative measurement of credit risk. This system also underpins the calculation of capital requirements and the management of credit portfolios. We continually seek to upgrade our credit portfolio management, or CPM, expertise to achieve an improved risk-adjusted return based on the Group’s credit portfolio status and flexible response capability to economic and other external changes.
Credit Risk Management System
The credit portfolios of our banking and securities subsidiaries are monitored and assessed on a regular basis by the holding company to maintain and improve asset quality. A uniform credit rating and asset evaluation and assessment system is used to ensure timely and proper evaluation of all credit risks. Under our credit risk management system, each of our subsidiaries in the banking, securities, consumer finance, and leasing businesses, manages its respective credit risk on a consolidated basis based on the attributes of the risk, while the holding company oversees and manages credit risk on an overall group-wide basis. The holding company also convenes regular committee meetings to monitor credit risk management at banking subsidiaries and to issue guidance where necessary.
Each major banking subsidiary has in place a system of checks and balances in which a credit administration section that is independent of the business promotion sections screens individual transactions and manages the extension of credit. At the management level, regular meetings of the Credit & Investment Management Committee and related deliberative bodies ensure full discussion of important matters related to credit risk management. Besides such checks and balances and internal oversight systems, credit examination sections also undertake credit testing and evaluation to ensure appropriate credit risk management.
The following diagram summarizes the credit risk management framework for our major banking subsidiaries:
132
Table of Contents
Credit Rating System
MUFG and its major banking subsidiaries use an integrated credit rating system to evaluate credit risk. The credit rating system consists primarily of borrower rating, facility risk rating, structured finance rating and asset securitization rating. Beginning April 1, 2025, we introduced our new credit rating system with a new financial scoring model and a new framework for qualitative assessment of a borrower’s financial strength and debt service capacity in order to enhance our credit risk management. The changes to our credit rating system did not have a material impact on the consolidated financial statements.
Country risk is also rated on a uniform group-wide basis. Our country risk rating is reviewed periodically to take into account relevant political and economic factors, including foreign currency availability.
Risk exposure for small retail loans, such as residential mortgage loans, is managed by grouping loans into various pools and assigning ratings at the pool level.
Borrower rating
Our borrower rating classifies borrowers into 15 grades based on evaluations of their expected debt-service capability over the next three to five years.
133
Table of Contents
The following table sets forth our borrower grades:
Definition of MUFG Borrower Rating
MUFGBorrowerRating MUFG Borrower Rating Definition
1 The capacity to meet financial commitments is extremely certain, and the borrower has the highest level of creditworthiness.
2 The capacity to meet financial commitments is highly certain, but there are some elements that may result in lower creditworthiness in the future.
3 The capacity to meet financial commitments is sufficiently certain, but there is the possibility that creditworthiness may fall in the long run.
4 There are no problems concerning the capacity to meet financial commitments, but there is the possibility that creditworthiness may fall in the long run.
5 There are no problems concerning the capacity to meet financial commitments, and creditworthiness is in the middle range.
6 There are no problems concerning the capacity to meet financial commitments presently, but there are elements that require attention if the situation changes.
7 There are no problems concerning the capacity to meet financial commitments presently, but long-term stability is poor.
8 There are no problems concerning the capacity to meet financial commitments presently, but long-term stability is poor, and creditworthiness is relatively low.
9 The capacity to meet financial commitments is somewhat poor, and creditworthiness is the lowest among “Normal” customers.
Borrowers who must be closely monitored because of the following business performance and financial conditions:
10 through 12 (1)Borrowers who have problematic business performance, such as virtually delinquent principal repayment or interest payment;
(2)Borrowers whose business performance is unsteady, or who have unfavorable financial conditions;
(3) Borrowers who have problems with loan conditions and for whom interest rates have been reduced or shelved.
10 Although business problems are not serious or their improvement is seen to be remarkable, there are elements of potential concern with respect to the borrower’s management, and close monitoring is required.
11 Business problems are serious, or require long-term solutions. Serious elements concerning business administration of the borrower have emerged, and subsequent debt repayment needs to be monitored closely.
12 Borrowers who fall under the criteria of Rating 10 or 11 and have a loan concession granted. Borrowers who have “Loans contractually past due 90 days or more.” (As a rule, delinquent borrowers are categorized as “Likely to Become Bankrupt,” but the definition here applies to borrowers delinquent for 90 days or more because of inheritance and other special reasons.)
13 Borrowers who pose a serious risk with respect to debt repayment and with whom loss is likely to occur in the course of transactions. While still not bankrupt, these borrowers are in financial difficulty, with poor progress in achieving restructuring plans, and are likely to become bankrupt in the future.
14 While not legally bankrupt, borrowers who are considered to be virtually bankrupt because they are in serious financial difficulty and have no prospects for an improvement in their business operations.
15 Borrowers who are legally bankrupt (i.e., who have no prospects for continued business operations because of non-payment, suspension of business, voluntary liquidation, or filing for legal liquidation).
Japanese banks were historically required to use the following categories of borrowers under the then applicable FSA inspection manual, which was abolished in December 2019, and are currently expected to use them as a basis for their borrower categorization with appropriate adjustments under the FSA’s discussion paper:
•Normal borrowers (generally corresponding to borrowers in categories 1 through 9 in our ratings), which are borrowers that are performing well, with no significant financial concerns,
•Borrowers requiring close watch (generally corresponding to borrowers in categories 10 through 12 in our ratings), which include loans that have been amended to allow for delays or forgiveness of interest payments, borrowers experiencing difficulty in complying with loan terms and conditions and borrowers that are recording losses or performing badly,
•Borrowers likely to become bankrupt (generally corresponding to borrowers in category 13 in our ratings), which are borrowers who pose a serious risk with respect to debt repayment and with whom loss is likely to occur in the course of transactions. While still not bankrupt, these borrowers are in financial difficulty, with poor progress in achieving restructuring plans, and are likely to become bankrupt in the future,
•Virtually bankrupt borrowers (generally corresponding to borrowers in category 14 in our ratings), which are not legally bankrupt, but borrowers who are considered to be virtually bankrupt because they are in serious financial difficulty and have no prospects for an improvement in their business operations, and
134
Table of Contents
•Bankrupt borrowers or de facto bankrupt borrowers (generally corresponding to borrowers in category 15 in our ratings), which are borrowers who are legally bankrupt (i.e., who have no prospects for continued business operations because of non-payment, suspension of business, voluntary liquidation, or filing for legal liquidation proceedings).
The primary data utilized in our assessment of borrowers include the borrower’s financial statements and notes thereto as well as other public disclosure made by the borrower. In addition, when appropriate and possible, we obtain non-public financial and operating information from borrowers, such as the borrower’s business plan, borrower’s self-evaluation of its operating assets and other borrower information about its business and products.
Based on the borrower and industry information, we assign borrower ratings mainly by applying financial scoring models—either developed internally or by third-party vendors, depending on the borrower’s attributes, whether the borrower is domestic or foreign, and whether the borrower is a corporate entity or another type of legal entity (such as a school, hospital or fund).
For example, for general business corporations, which constitute the largest borrower attribute in our current loan portfolio in terms of number of borrowers, we have adopted an internally developed financial scoring model, exclusively designed and developed for such attribute. We have selected various financial ratios that we believe to be useful and meaningful to quantitatively measure and assess the borrowers’ financial standing and repayment capability. Such financial ratios represent, among other things, borrowers’ profitability, stability, company size, cash flow and liquidity. The model is periodically tested against historical results. The following is an illustration of some of the financial ratios we utilize as part of our financial scoring model:
•To measure profitability: Gross profit to sales, and profit before tax to sales,
•To measure stability: Debt to equity ratio, and debt to capital ratio, and
•To measure company size: Total asset and total equity.
The financial score obtained through the models is reviewed and, when necessary, adjusted to reflect our qualitative assessment of the borrower’s financial strength and other factors that could affect the borrower’s ability to service the debt. For example, we take into account: capability of turning around the business (in case of borrowers with losses) or recovering positive net worth (in case of borrowers with negative net worth), and factors relating to business volatility, capability of management and governance, funding availability and lack of liquidity, as well as our assessment of the probability of receiving support from parent companies (if the borrower is a subsidiary of a large listed company).
When adjusting the results of primary financial scoring assigned to borrowers with losses, we consider the severity of losses and the possibility of improving operating results. We analyze and assess whether the loss is temporary, the trend in operating results is improving, or the loss is expected to continue for an extended period. When adjusting the results of primary financial scoring assigned to borrowers with losses or borrowers with negative net worth, we also analyze whether the borrower can return to a positive net worth, and the time period needed to achieve such recovery (one to two years, three to five years, or five years or more).
In addition, adjustments based on business volatility take into account business volatility arising from industry factors and borrower specific factors, such as restrictions and entry barriers, market volatility, and portfolio diversification. Adjustments based on capability of management and governance reflect our assessment of management’s capability to formulate and execute business strategies that may significantly affect future business operations, as well as the borrower’s risk management capability and organizational management capability. Adjustments based on funding availability and lack of liquidity reflect the possibility that the borrower may face future liquidity constraints, taking into account factors such as its banking relationships, access to capital markets and diversity of funding sources.
When assessing the probability of receiving support from parent companies, various factors are examined, such as the parent company’s credit standing and support policy, the extent of management control exercised by the parent company, and the borrower’s strategic positioning within the corporate group.
In addition, we consider outside ratings, and our internal borrower ratings may be adjusted when deemed appropriate.
Facility risk rating
Facility risk rating is used to evaluate and classify the quality of individual credit facilities, including guarantees and collateral. Ratings are assigned by quantitatively measuring the estimated loss rate of a facility in the event of a default.
Structured finance rating and asset securitization rating
Structured finance rating and asset securitization rating are used to evaluate and classify the quality of individual credit facilities, including guarantees and collateral, and focus on the structure, including the applicable credit period, of each credit facility. In
135
Table of Contents
evaluating the debt service potential of a credit facility, we scrutinize its underlying structure to determine the likelihood of the planned future cash flows being achieved.
Pool assignment
Each major banking subsidiary has its own system for pooling and rating small retail loans designed to reflect the risk profile of its loan portfolios.
Asset evaluation and assessment system
The asset evaluation and assessment system is used to classify assets held by us according to the probability of collection and the risk of any impairment in value based on borrower classifications consistent with the borrower ratings and the status of collateral, guarantees, and other factors.
The system is used to conduct write-offs and allocate allowances against credit risk in a timely and adequate manner.
Quantitative Analysis of Credit Risk
MUFG and its major banking subsidiaries manage credit risk by monitoring credit amount and expected losses, and run simulations based on internal models to estimate the maximum amount of credit risk. These models are used for internal management purposes, including loan pricing and measuring economic capital.
When quantifying credit risk amounts using the internal models, MUFG and its major banking subsidiaries consider various parameters, including the probability of default, loss given default, and exposure at default used in their borrower ratings, facility risk ratings and pool assignments as well as any credit concentration risk in particular borrower groups or industry sectors. MUFG and its major banking subsidiaries also share credit portfolio data in appropriate cases.
Loan Portfolio Management
We aim to achieve and maintain levels of earnings commensurate with credit risk exposure. Products are priced to take into account expected losses, based on the internal credit ratings.
We assess and monitor loan amounts and credit exposure by credit rating, industry and region. Portfolios are managed to limit concentrations of risk in specific categories in accordance with our Large Credit Guidelines.
To manage country risk, we have established specific credit ceilings by country. These ceilings are reviewed when there is a material change in a country’s credit standing, in addition to being subject to a regular periodic review.
Continuous CPM Improvement
With the prevalence of securitized products and credit derivatives in global markets, we seek to supplement conventional CPM techniques with advanced methods based on the use of such market-based instruments.
Through credit risk quantification and portfolio management, we aim to improve the risk return profile of the Group’s credit portfolio, using financial markets to rebalance credit portfolios in a dynamic and active manner based on an accurate assessment of credit risk.
Risk Management of Strategic Equity Portfolio
We hold shares of various corporate clients for strategic purposes, in particular to maintain long-term relationships with these clients. These investments have the potential to increase business revenue and appreciate in value. At the same time, we are exposed to the risk of price fluctuations in the Japanese stock market. For that reason, in recent years, it has been a high priority for us to reduce our equity portfolio to limit the risks associated with holding a large equity portfolio, but also to respond to applicable regulatory requirements as well as increasing market expectations and demands for us to reduce our equity portfolio. We are required to comply with a regulatory framework that prohibits Japanese banks from holding an amount of shares in excess of their adjusted Tier 1 capital. See “Item 5.B. Operating and Financial Review and Prospects—Liquidity and Capital Resources—Financial Condition—Investment Portfolio.”
136
Table of Contents
We use quantitative analysis to manage the risks associated with the portfolio of equities held for strategic purposes. According to internal calculations, the market value of our strategically held (Tokyo Stock Exchange-listed) stocks (excluding foreign stock exchange-listed stocks) as of March 31, 2026 was subject to a variation of approximately ¥1.1 billion when TOPIX index moves one point in either direction.
We seek to manage and reduce strategic equity portfolio risk based on quantitative analysis such as the sensitivity analysis described above. The aim is to keep this risk at appropriate levels compared with Tier 1 capital while generating returns commensurate with the degree of risk exposure.
Market Risk Management
Management of market risk at MUFG aims to control our risk exposure to fluctuations in market variables across the Group while ensuring that earnings are commensurate with levels of risk.
Market Risk Management System
We have adopted an integrated system to manage market risk from our trading and non-trading activities. The holding company monitors group-wide market risk, while each of the major subsidiaries manages its market risks on a consolidated and global basis.
At each of the major subsidiaries, checks and balances are maintained through a system in which back and middle offices operate independently from front offices. In addition, separate Asset-Liability Management, or ALM, Committee and Risk Management Meetings are held at each of the major subsidiaries every month to deliberate important matters related to market risk and control.
The holding company and the major subsidiaries allocate economic capital commensurate with levels of market risk and determined within the scope of their capital bases. The major subsidiaries have established quantitative limits relating to market risk based on their allocated economic capital. In addition, in order to keep losses within predetermined limits, the major subsidiaries have also set limits for the maximum amount of losses arising from market activities. The following diagram summarizes the market risk management system of each major subsidiary:
Market Risk Management System of Our Major Subsidiaries
Market Risk Management and Control
At the holding company and the major subsidiaries, market risk exposure is reported to the Chief Risk Officers on a daily basis. At the holding company, the Chief Risk Officer monitors market risk exposure across the Group as well as the major subsidiaries’ control over their quantitative limits for market risk and losses. Meanwhile, the Chief Risk Officers at the major subsidiaries monitor their own market risk exposure and their control over their quantitative limits for market risk and losses. In addition, various analyses on risk profiles, including stress testing, are conducted and reported to the Executive Committees and the Corporate Risk Management Committees on a regular basis. At the business unit levels in the major subsidiaries, the market risks on their marketable assets and
137
Table of Contents
liabilities, such as interest rate risk and foreign exchange rate risk, are controlled by entering into various hedging transactions using marketable securities and derivatives.
As part of our market risk management activities, we use certain derivative financial instruments to manage our interest rate and currency exposures. We maintain an overall interest rate risk management strategy that incorporates the use of interest rate contracts to minimize significant unplanned fluctuations in earnings that are caused by interest rate volatility. We enter into interest rate swaps and other contracts as part of our interest rate risk management strategy primarily to alter the interest rate sensitivity of our loans, investment securities and deposit liabilities. Our principal objectives in risk management include asset and liability management. Asset and liability management is viewed as one of the methods for us to manage our interest rate exposures on interest-earning assets and interest-bearing liabilities. Interest rate contracts, which are generally non-leveraged generic interest rate and basis swaps, options and futures, allow us to effectively manage our interest rate risk position. Option contracts primarily consist of caps, floors, swaptions and options on index futures. Futures contracts used for asset and liability management activities are primarily index futures providing for cash payments based upon the movement of an underlying rate index. We enter into forward exchange contracts, currency swaps and other contracts in response to currency exposures resulting from on-balance sheet assets and liabilities denominated in foreign currencies in order to limit the net foreign exchange position by currency to an appropriate level.
These market risk management activities are performed in accordance with the predetermined rules and procedures. The internal auditors regularly verify the appropriateness of the management controls over these activities and the risk evaluation models adopted.
Market Risk Measurement Model
To measure market risks, MUFG uses the VaR method which estimates changes in the market value of portfolios within a certain period by statistically analyzing past market data. Since the daily variation in market risk is significantly greater than that in other types of risk, MUFG measures and manages market risk using VaR on a daily basis.
Market risk for trading and non-trading activities is measured using a market risk measurement model. The principal model used for these activities is a historical simulation, or HS, model (Trading activities: holding period, one business day; confidence interval, 95%; and observation period, 250 business days. Non-trading activities (which include available-for-sale debt securities as well as loans, deposits and held-to-maturity debt securities): holding period, 10 business days; confidence interval, 99%; and observation period, 701 business days). The HS model calculates VaR amounts by estimating the profit and loss on the current portfolio by applying actual fluctuations in market rates and prices over a fixed period in the past. This method is designed to capture certain statistically infrequent movements, such as a fat tail. Changes in the fair value of loans, deposits and held-to-maturity debt securities are considered in the Non-trading activities, while such changes are not reflected in our financial statements.
In calculating VaR using the HS method, we have implemented an integrated market risk measurement system throughout the Group. Our major subsidiaries calculate their VaR based on the risk and market data prepared by the information systems of their front offices and other departments. The major subsidiaries provide this risk data to the holding company, which calculates overall VaR, taking into account the diversification effect among all portfolios of the major subsidiaries.
For the purpose of internally evaluating capital adequacy on an economic capital basis in terms of market risk, we use this market risk measurement model to calculate risk amounts based on a holding period of one year and a confidence interval of 99.9%.
Monitoring and managing our sensitivity to interest rate fluctuations is key to managing market risk in MUFG’s non-trading activities. The major banking subsidiaries take the following approach to measuring risks concerning core deposits, loan prepayments and early deposit withdrawals.
To measure interest rate risk relating to deposits without contract-based fixed maturities, the amount of “core deposits” is calculated through a statistical analysis based on deposit balance trend data and the outlook for interest rates on deposits, business decisions, and other factors. The amount of “core deposits” is categorized into various groups of maturity terms of up to ten years to recognize interest rate risk. The calculation assumptions and methods to determine the amount of core deposits and maturity term categorization are regularly reviewed.
Meanwhile, deposits and loans with contract-based maturities are sometimes cancelled or repaid before their maturity dates. To measure interest rate risk for these deposits and loans, we reflect these early termination events mainly by applying early termination rates calculated based on a statistical analysis of historical repayment and cancellation data together with historical market interest rate data.
Summaries of Market Risks
Trading activities
138
Table of Contents
The aggregate VaR for our total trading activities as of March 31, 2026 was ¥2.72 billion, comprising interest rate risk exposure of ¥2.73 billion, foreign exchange risk exposure of ¥0.85 billion, and equity-related risk exposure of ¥0.33 billion. Our average daily VaR for the fiscal year ended March 31, 2026 was ¥2.46 billion.
Due to the nature of trading operations which involves frequent changes in trading positions, market risk may vary substantially during and between measurement periods, depending on our trading positions.
The following tables set forth the VaR related to our trading activities by risk category for the periods indicated:
April 1, 2024—March 31, 2025 Average Maximum(1) Minimum(1) March 31, 2025
(in billions)
MUFG ¥ 1.79 ¥ 3.66 ¥ 1.20 ¥ 1.53
Interest rate 1.53 1.87 1.19 1.56
Yen 0.79 1.23 0.54 0.98
U.S. Dollars 0.93 1.42 0.61 0.85
Foreign exchange 0.69 1.23 0.47 0.51
Equities 0.43 2.43 0.10 0.24
Commodities 0.00 0.00 0.00 0.00
Less diversification effect (0.86) — — (0.78)
April 1, 2025—March 31, 2026 Average Maximum(1) Minimum(1) March 31, 2026
(in billions)
MUFG ¥ 2.46 ¥ 3.64 ¥ 1.36 ¥ 2.72
Interest rate 2.20 3.26 1.41 2.73
Yen 1.43 2.40 0.80 1.57
U.S. Dollars 1.33 1.76 0.81 1.39
Foreign exchange 0.79 1.73 0.51 0.85
Equities 0.83 2.07 0.09 0.33
Commodities 0.00 0.00 0.00 0.00
Less diversification effect (1.36) — — (1.19)
Assumptions for VaR calculations:
Historical simulation method
Holding period: 1 business day
Confidence interval: 95%
Observation period: 250 business days
Note:
(1)The maximum and minimum VaR overall and for various risk categories were taken from different days. A simple summation of VaR by risk category is not equal to total VaR due to the effect of diversification.
The average daily VaR by quarter in the fiscal year ended March 31, 2026 was as follows:
Quarter Daily average VaR
(in billions)
April—June 2025 ¥ 2.36
July—September 2025 2.28
October—December 2025 2.46
January—March 2026 2.75
139
Table of Contents
Non-trading Activities
The aggregate VaR for our total non-trading activities as of March 31, 2026, excluding market risks related to our strategic equity portfolio, was ¥511.5 billion. Market risk related to interest rates equaled ¥418.2 billion and equities-related risk equaled ¥160.9 billion. Compared with the VaR as of March 31, 2025, market risk decreased in the fiscal year ended March 31, 2026, primarily due to a decrease in Japanese yen interest rate risk.
Based on a simple sum of figures across market risk categories, interest rate risks accounted for approximately 71% of our total non-trading activity market risks as of March 31, 2026. Looking at a breakdown of interest rate related risk by currency, as of March 31, 2026, the Japanese yen accounted for approximately 31% while the U.S. dollar accounted for approximately 67%, and the euro approximately 2%, with a 17 percentage point decrease in the Japanese yen, an 18 percentage point increase in the U.S. dollar and a one percentage point decrease in the euro compared to March 31, 2025.
For a description of our strategic equity investment risk management, see “—Risk Management of Strategic Equity Portfolio.”
The following tables set forth the VaR related to our non-trading activities by risk category for the periods indicated:
April 1, 2024—March 31, 2025 Average Maximum(1) Minimum(1) March 31, 2025
(in billions)
Interest rate ¥ 456.0 ¥ 519.8 ¥ 394.7 ¥ 498.2
Yen 328.3 440.0 253.2 359.6
U.S. Dollars 306.7 415.7 210.2 360.8
Foreign exchange 5.0 9.5 2.3 5.2
Equities(2) 103.1 120.7 81.6 105.6
Commodities 0.2 1.8 0.1 0.1
Less diversification effect (44.4) ― ― (49.1)
Total 519.9 578.8 450.3 560.0
April 1, 2025—March 31, 2026 Average Maximum(1) Minimum(1) March 31, 2026
(in billions)
Interest rate ¥ 435.0 ¥ 493.8 ¥ 370.9 ¥ 418.2
Yen 235.7 368.0 152.9 197.9
U.S. Dollars 365.8 423.3 287.7 421.3
Foreign exchange 7.2 14.9 4.2 7.2
Equities(2) 151.3 191.8 93.5 160.9
Commodities 0.1 0.2 0.0 0.0
Less diversification effect (81.2) ― ― (74.8)
Total 512.4 564.6 463.1 511.5
Assumptions for VaR calculations:
Historical simulation method
Holding period: 10 business days
Confidence interval: 99%
Observation period: 701 business days
Notes:
(1)The maximum and minimum VaR overall for each category and in total were taken from different days. A simple summation of VaR by risk category is not equal to total VaR due to the effect of diversification.
(2)The equities-related risk figures do not include market risk exposure from our strategic equity portfolio.
The average daily interest rate VaR by quarter in the fiscal year ended March 31, 2026 was as follows:
140
Table of Contents
Quarter Daily average VaR
(in billions)
April—June 2025 ¥ 452.05
July—September 2025 435.04
October—December 2025 428.65
January—March 2026 424.27
Limitations of the Market Risk Measurement Model and Related Measures
Actual losses may exceed the value at risk obtained by the application of an HS VaR model in the event, for example, that the market fluctuates to a degree not accounted for in the observation period, or that the correlations among various risk factors, including interest rates and foreign currency exchange rates, deviate from those assumed in the model. In order to complement these weaknesses of the HS-VaR model and measure potential losses that the model is not designed to capture, we conduct stress testing, as appropriate, on our HS-VaR model for our non-trading activities by applying various stress scenarios, including those which take into account estimates regarding future market volatility, in order to better identify risks and manage our portfolio in a more stable and appropriate manner. In addition, we utilize back-testing to verify the effectiveness of our VaR measurement model.
Funding Liquidity Risk Management
Our major subsidiaries seek to maintain appropriate liquidity in both Japanese yen and foreign currencies by managing their funding sources and mechanisms, such as deposits, short-term borrowings and long-term debt, liquidity gap, liquidity-supplying products such as commitment lines, and buffer assets, primarily government bonds.
We have established a group-wide system for managing liquidity risk by categorizing the risk in the following three stages: normal, concern and crisis. The front offices and risk management offices of the major subsidiaries and the holding company exchange information and data on liquidity risk even at the normal stage. At higher alert stages, we centralize information about liquidity risk and discuss issues relating to group-wide liquidity control actions, including formulating contingency plans, among Group companies, if necessary. We have also established a system for liaison and consultation on funding in preparation for contingency, such as natural disasters, wars and terrorist attacks. The holding company and the major subsidiaries conduct group-wide contingency preparedness drills on a regular basis to ensure smooth implementation in the event of an emergency.
In addition, we have established a group-wide system for ensuring compliance with the minimum regulatory LCR and NSFR requirements by categorizing the risk in the following three stages: sufficient, concern and insufficient. The holding company and the major subsidiaries exchange information and data on LCR and NSFR even at the sufficient stage. At higher alert stages, we hold group-wide LCR and NSFR liaison meetings to discuss issues relating to LCR and NSFR and, based on the discussion as well as the information and data that have been shared, take countermeasures to improve LCR and NSFR as necessary.
For more information, see “Item 5.B. Operating and Financial Review and Prospects—Liquidity and Capital Resources—Financial Condition—Sources of Funding and Liquidity.” See also “Item 3.D. Key Information—Risk Factors—Funding Liquidity Risk—Deterioration in market liquidity or other external circumstances or an actual or perceived decline in our creditworthiness could negatively affect our ability to access and maintain liquidity.”
Operational Risk Management
The holding company has established, based on its Executive Committee’s determination, the MUFG Operational Risk Management Policy as a group-wide policy for managing operational risk. This policy sets forth the core principles regarding operational risk management, including the definition of operational risk, and the risk management system and processes. Pursuant to the policy, under the oversight of the board of directors, the Executive Committee formulates fundamental principles of operational risk management and establishes and maintains a risk management system as it considers appropriate. The Chief Risk Officer is responsible for recognizing, evaluating, and appropriately managing operational risk in accordance with the fundamental principles formulated by the board of directors and the Executive Committee. A division in charge of operational risk management has been established that is independent of business promotion sections to manage overall operational risk in a comprehensive manner. In addition, senior management receives regular reports on the status of our business operations from the perspective of managing operational risk in accordance with the fundamental principles. These fundamental principles have also been approved by the boards of directors of the major subsidiaries, providing a consistent framework for operational risk management of the Group. The diagram below sets forth the operational risk management system of each major banking subsidiary:
141
Table of Contents
Operational Risk Management System of Our Major Banking Subsidiaries
As set forth in the following diagram, we have established a risk management framework for loss data collection, control self-assessment, and measurement of operational risk in order to appropriately identify, recognize, evaluate, measure, control, monitor and report operational risk.
We have also established group-wide reporting guidelines with respect to loss data collection and its monitoring. We focus our efforts on ensuring accurate assessment of the status of operational risk losses and the implementation of appropriate countermeasures, while maintaining databases of internal and external loss events.
The following diagram summarizes our operational risk management framework:
142
Table of Contents
Operational Risk Management Framework
Operations Risk Management
The Group companies offer a wide range of financial services, ranging from commercial banking products such as deposits, exchange services and loans to trust and related services covering pensions, securities, real estate and securitization, as well as transfer agent services. Cognizant of the potentially significant impact that operations risk-related events could have in terms of both economic losses and damage to our reputation, our major subsidiaries continue to work on improving their management systems to create and apply appropriate operations risk-related controls.
Specific ongoing measures to reduce operations risk include the development of databases to manage, analyze and prevent the recurrence of related loss events; efforts to tighten controls over administrative procedures and related operating authority, while striving to improve human resources management, investments in systems to improve the efficiency of administrative operations, and programs to expand and upgrade internal auditing and operational guidance systems.
We work to promote the sharing within the Group of information and expertise concerning any operational incidents and the measures implemented to prevent any recurrence.
Efforts to upgrade the management of operations risk continue with the aim of providing our customers with a variety of high-quality services.
Information Risk Management
Complying with laws and regulations requiring proper handling of customer information, we implement information security management measures, including the establishment of an information risk management framework, enhancement of our internal operational procedures, and training courses mandatory for all officers and staff.
We have also formulated our Personal Information Protection Policy as the basis for our ongoing programs designed to protect the confidentiality of personal information.
With the aim of preventing any recurrence and minimizing risk or loss, we also work to promote sharing on a group-wide basis of experience, knowledge and expertise related to information risk incidents.
IT Risk Management
143
Table of Contents
IT risk refers to the following risks:
- Loss arising from destruction of, suspension of services reliant on, defects in, or misuse of IT,
- Unauthorized alteration, leakage or loss of electronic data caused by insufficient IT systems planning, development or operations, and
- External threats to or vulnerabilities in IT systems security, including cybersecurity.
Systems planning, development and operations include appropriate design and extensive testing phases to ensure that systems are designed to help prevent failures while providing sufficient safeguards for the security of electronic data including personal information. System development projects are managed and overseen by a team dedicated to performing such management and oversight functions, and the development status of any mission-critical IT systems is reported regularly to senior management.
Disaster countermeasure systems development and investments for redundancy of the Group’s IT infrastructure are designed to minimize damage in the event of any system failure. Emergency drills are conducted to help increase staff preparedness. Group-wide sharing of experience, knowledge and expertise related to system failures is promoted with the aim of preventing recurrence of, and minimizing, risk or loss. Contingency plans, including alternatives for both operations and systems, are designed to ensure operational resilience, enable quick recovery and reduce impact in the event of a system failure.
In addition, the risk of increasingly sophisticated cyber-attacks is a significant focus of the Board of Directors, and the Board regularly receives reports regarding our cybersecurity risk management program. We continue to work to strengthen measures designed to address and mitigate the risk, including the establishment of MUFG-CERT, our Computer Emergency Response Team, implementation of multi-layered defense and detection measures, enhancement of monitoring systems, and cooperation with global organizations with relevant expertise. MUFG-CERT is responsible for taking prompt action to coordinate and manage response to cyber security incidents to mitigate their impact. For more information, see "Item 16K. Cybersecurity."
We have established the “MUFG AI Policy” to ensure the safe, appropriate and secure use of AI. Under this policy, we are working to strengthen our AI risk management framework as a business entity engaged in AI utilization. See “Item 3.D. Key Information—Risk Factors—Operational Risk—We are exposed to risks related to the development and use of AI by us and others.”
Tangible Asset Risk Management
Tangible assets include movable physical properties and immovable properties, owned or leased, such as land, buildings, equipment attached to buildings, fixtures and furniture. We recognize the potentially significant impact tangible asset risk-related events can have on the management and execution of the Group’s businesses, which in turn can result in economic losses to, or diminished market confidence in, the Group. Accordingly, we continue to improve our risk control framework designed to appropriately manage such risk.
Personnel Risk Management
We recognize the potentially significant impact personnel risk-related events can have on the management and execution of the Group’s businesses, which in turn can result in economic losses to, or diminished market confidence in, the Group. Accordingly, we continue to work on improving our risk control framework designed to appropriately manage such risk.
Incompliance with Laws and Regulations Risk Management
We recognize the potentially significant impact compliance risk-related events can have on the management and execution of the Group’s businesses, which in turn can result in economic, reputation and other losses to, or diminished market confidence in, the Group. Accordingly, we continue to work on improving our compliance risk control framework designed to appropriately manage such risk.
Specifically, we have established our MUFG Group Code of Conduct as the basic guideline for the Group’s directors and employees. In addition, a compliance management division has been established at each of the holding company and the major subsidiaries. See “—Compliance” below.
Legal Risk Management
The legal division at each of the holding company and the major subsidiaries centrally and uniformly evaluates legal issues prior to entering into contracts or commencing new business operations, deals with legal disputes and manages other legal matters. With the
144
Table of Contents
aim of effectively managing our legal risk arising from our globally expanding business operations, we have established a global and group-wide legal risk management framework and promote sharing of experience, knowledge and practices relating to legal risk issues on a global and group-wide basis.
The Standardized Measurement Approach for Operational Risk
We adopted the Standardized Measurement Approach, or SMA, as of March 31, 2024, in place of the Advanced Measurement Approach that we had previously used, for calculation of the operational risk capital amount in measuring our capital adequacy ratios under applicable Japanese regulatory requirements based on the Basel III Standards. The SMA is intended to reduce complexity and variability in the calculation of operational risk capital amount and replace all previously permitted approaches.
Succinctly put, under the SMA, operational risk capital amount is calculated based on a bank’s income, expense items and historical loss amounts. Using a bank’s income and expense items as inputs, a financial statement-based proxy for the bank’s operational risk exposure, which is referred to as the Business Indicator, is calculated based on a prescribed formula. The Business Indicator is multiplied by an applicable coefficient or coefficients (between 12% and 18%) to arrive at the value referred to as the Business Indicator Component (BIC). The calculated BIC is then multiplied by a scaling factor referred to as the Internal Loss Multiplier (ILM), which is calculated based on a prescribed formula using the bank’s average historical operational risk losses over the last 10 years, or a conservative estimate value with a lower bound of 1, as an input.
Based on the foregoing, operational risk capital amount is calculated by multiplying the BIC and the ILM, and the risk weighted assets for operational risk are defined as the product of operational risk capital and 12.5.
Reputation Risk Management
Reputation risk refers to the risk of harm to our corporate value arising from perceptions of our customers, shareholders, investors or other stakeholders and in the market or society that we deviate from their expectations or confidence. We recognize that such risk, if materialized, can have a material negative impact on our business and continue to work on enhancing our framework designed to appropriately manage the risk based on MUFG Way, MUFG Group Code of Conduct, and other rules and codes of the Group.
Specifically, in order to manage our reputation risk effectively on a group-wide basis, we have established a risk management system designed to ensure mutual consultation and reporting if a reputation risk-related event occurs or is anticipated and, through this system, share relevant information within the Group.
Through the risk control framework and risk management system, we seek to prevent reputation risk-related events and minimize damage to the corporate value of the Group by promptly obtaining an accurate understanding of relevant facts relating to risk events and disclosing information concerning such events and the measures we take in response to such events in an appropriate and timely manner.
Model Risk Management
We recognize the potentially significant impact model risk-related events can have on the management and execution of the Group’s businesses, which in turn can result in economic losses to, or diminished market confidence in, the Group. Models are used for increasingly wider and more important purposes, including valuing exposures, instruments and positions, measuring risks, determining capital adequacy and compliance. Accordingly, we continue to work on improving our risk control framework. See “Item 3.D. Key Information—Risk Factors—Operational Risk—We are exposed to risks related to the development and use of AI by us and others.”
Compliance
Basic Policy
In April 2021, MUFG renamed its Corporate Vision as “MUFG Way” and newly defined its social purpose—the purpose of its existence, along with its shared values and medium- to long-term goal. MUFG Way serves as the group’s basic policy in conducting its business activities and provides guidelines for all group activities. Furthermore, we have established MUFG Group Code of Conduct as the guidelines for how the Group’s directors and employees act to realize the Corporate Vision, in which we have expressed our commitment to complying with laws and regulations, to acting with honesty and integrity, and to behaving in a manner that supports and strengthens the trust and confidence of society.
145
Table of Contents
In addition, as we expand the geographic scope of our business globally, we are committed to keeping abreast of developments in laws and regulations of the jurisdictions in which we operate including anti-money laundering and anti-bribery, as well as paying attention to trends in financial crimes.
See “Item 3.D. Key Information—Risk Factors—Operational Risk—Legal and regulatory changes could have a negative impact on our business, financial condition and results of operations.” and “Item 3.D. Key Information—Risk Factors—Operational Risk—We may become subject to regulatory actions or other legal proceedings relating to our transactions or other aspects of our operations, which could result in significant financial losses, restrictions on our operations and damage to our reputation.” See also “Item 4.B. Information on the Company—Business Overview—Supervision and Regulation.”
Compliance Framework
Management and coordination of compliance-related matters are the responsibility of separate compliance management divisions established at the holding company and the major subsidiaries. Each compliance management division formulates compliance programs and organizes training courses to promote compliance, and regularly reports to each company’s board of directors and Executive Committee on the status of compliance activities.
The holding company has established a Group Compliance Committee and each major subsidiary has established a Compliance Committee for deliberating key issues related to compliance. Additionally, the holding company has a Group Chief Compliance Officer, or CCO, Committee, which consists of the CCO of the holding company acting as committee chair and the CCOs of the major subsidiaries. The Group CCO Committee deliberates important matters related to compliance and compliance-related issues for which the Group should share a common understanding.
The following diagram summarizes our compliance framework:
Compliance Framework
Internal Reporting System and Accounting Auditing Hotline
The major subsidiaries have established internal reporting systems that aim to identify compliance issues early so that any problems can be quickly rectified. This system includes an independent external compliance hotline. Furthermore, the holding company has set up an MUFG Group Compliance Helpline that acts in parallel with group-company internal reporting systems and provides a reporting channel for directors and employees of Group companies. In the holding company, the contents of the reported cases as well as the results of surveys are reported to the audit committee on a regular basis or whenever necessary.
In addition to these internal reporting systems, the holding company has also established an accounting auditing hotline that provides a means to report any problems related to MUFG's accounting practices.
146
Table of Contents
MUFG Accounting Auditing Hotline
MUFG has set up an accounting auditing hotline to be used to make reports related to instances of improper practices (violations of laws and regulations) and inappropriate practices, or of practices raising questions about such impropriety or inappropriateness, regarding accounting and internal control or audits related to accounting in Group companies. The audit committee oversees the reporting process to ensure the appropriateness and effectiveness of the reporting process and monitors the reports received through the hotline. The reporting process works as follows, and may be carried out via letter or e-mail:
Hokusei Law Office, P.C.
Address: Sanshikaikan Bldg. 8th Floor 1-9-4 Yurakucho, Chiyoda-ku, Tokyo
e-mail:[email protected]
When reporting information please pay attention to the following:
•Matters subject to reporting are limited to instances regarding the Group companies.
•Please provide detailed information with respect to the matter. Without detailed factual information there is a limit to how much our investigations can achieve.
•Anonymous information will be accepted.
•No information regarding the identity of the informant will be passed on to third parties without the approval of the informant him- or herself. However, this excludes instances where disclosure is legally mandated, or to the extent that the information is necessary for surveys or reports, when data may be passed on following the removal of the informant’s name.
•Please submit reports in either Japanese or English.
•If the informant wishes, we will endeavor to report back to the informant on the response taken within a reasonable period of time following the receipt of specific information, but cannot promise to do so in all instances.
Internal Audit
Role of Internal Audit
Internal Audit aims to evaluate and assist in the improvement of the effectiveness of governance, risk management and control processes with high proficiency and independence, thereby contributing to the enhancement of the corporate value of the MUFG Group and to the achievement of MUFG Way. Internal Audit covers all aspects of the Group’s business activities and discusses and evaluates the management and operational frameworks and the implementation of business operations from legal compliance, rationality and efficiency perspectives, beyond checking compliance with defined procedures.
In addition, Internal Audit provides instructions and recommendations for operational improvement to audited divisions and reports to senior management on such instructions and recommendations, thereby contributing to safeguarding and development of the Group’s assets.
Three Lines of Defense Framework
Risk management is conducted at multiple levels within a business organization, including front-office divisions in charge of managing specific categories of risk, a compliance division, and an internal audit division.
As for financial institutions, including the MUFG Group, based on the experience of past financial crises, the traditional risk management structure that was heavily dependent on front-office divisions has been under close scrutiny. As a result, there is an increasing expectation for financial institutions to achieve more effective risk management through, for example, appropriate allocation of risk management roles and responsibilities among various divisions.
Cognizant of the importance of these developments, we have adopted the concept of “Three Lines of Defense” where the roles and responsibilities of each division in risk management are defined, classifying divisions within a financial institution into “the 1st Line of Defense”, “the 2nd Line of Defense” and “the 3rd Line of Defense”.
147
Table of Contents
Line Divisions Roles
The 1st Line of Defense Business divisions and client-facing divisions •Undertake risks within the extent of risk exposure assigned• Responsible and accountable for identifying, evaluating and controlling business risks
The 2nd Line of Defense Risk management division, compliance division, etc. •Ensure that risks are appropriately identified and managed by the 1st Line of Defense
The 3rd Line of Defense Internal audit division • Independently evaluate the effectiveness of the governance, risk management, and control processes implemented by the 1st and 2nd Lines of Defense
Internal Audit plays an essential role in the Group’s risk management through ongoing communications with the 1st and 2nd Lines of Defense, while maintaining independence.
Group Internal Audit Framework
The MUFG Group has internal audit functions at the holding company level as well as at the subsidiary level, which are designed to ensure proficiency and independence through effective collaboration.
The internal audit division of the holding company receives reports from the internal audit divisions of subsidiaries on the status and results of their internal audits and provides them with instructions and evaluations as needed.
Reports to the Audit Committee
The holding company has an audit committee within its board of directors as required by the Companies Act of Japan, and each of the major subsidiaries has established an audit and supervisory committee. Within each of the holding company and the major subsidiaries, the internal audit division reports to the committee on important matters, including governing principles for internal audit plans and the status and results of internal audits.
MUFG Internal Audit Activity Charter
We have adopted “MUFG Internal Audit Activity Charter”, which defines our basic policies for Internal Audit, including its purposes and roles and the organizational positioning of the internal audit function.
This charter is designed to encourage Internal Audit staff to conduct internal audits in accordance with the global standards set by the Institute of Internal Auditors, an international organization established for, among other purposes, formulating practical internal audit standards.