Hello, this is Ryuta Hamamoto from TIMEWELL.
"We know we should be doing something about economic security. Honestly, we just don't know where to start." A corporate planning director at a manufacturer told me this a while back, and the sentence has stayed with me. The term is everywhere in the news, yet the moment you try to put it on a board agenda, the pen stops moving.
That paralysis is not a personal failing, and government data backs this up. In a survey cited by Japan's Ministry of Economy, Trade and Industry, only 22.9% of 3,007 manufacturers said they had a concrete grasp of what economic security means for them. Another 70.7% answered that they had heard the term but had no concrete image of it1. Seven in ten know the words and nothing else.
On January 23, 2026, METI's Trade and Economic Security Bureau published the Economic Security Management Guidelines (1st Edition)2. As the name suggests, the document is addressed to executives rather than to the compliance desk. If you want to see where your own company stands before reading further, run our free export control and economic security self-check first. The rest of this article will land very differently once you have your own answers in front of you.
A document with no legal force, and why it still belongs on the board agenda
Let me clear up the most common misreading right away. These guidelines compel nothing. The text says plainly that they are "not an obligation imposed on companies"3. They are recommendations, meant to help firms think through a management strategy that keeps an eye on corporate value.
There is a second sentence I would not want anyone to skip: the guidelines are "not premised on transactions with any specific country, company, or person"3. Economic security tends to get discussed as a story about shutting someone out. This document refuses that framing. What it actually asks you to do is map your own value chain, identify your own core technologies, write your own risk scenarios, and fix your own internal structures. I think that restraint deserves credit.
So why bring a non-binding document to the board? The answer sits on the same page. METI states that acting in line with the guidelines "generally serves as one form of evidence that executives are fulfilling their duty of care"3. Duty of care, in the sense of managing the company with the diligence of a prudent manager. A company that knew a government-published set of recommendations existed and examined none of it will have a hard time explaining itself when something goes wrong. A company that kept a record of its review has something to point to. Not required, but useful when it counts. For this genre of document, that is unusually candid drafting.
The intended reader is spelled out too: "executives, including executive officers and equivalent responsible persons"3. On company size, the guidelines say they are "not limited to any particular industry, business model, or business scale," which keeps this from being a large-cap conversation only. They also note the document can be used to build shared understanding with counterparties and shareholders. Expect the question "how does your company handle economic security?" to start arriving from customers and suppliers. The difference between answering off the cuff and handing over a completed checklist is not small.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The part they left out is the part that weighs the most
The single most important thing about these guidelines, to my mind, is what they decline to cover.
Under "content and scope," the document explains that it focuses on economic security risks that cannot be handled through domestic legal compliance alone, such as tightening export controls by other countries or the outflow of a company's own superior technology. A footnote then clarifies that compliance obligations under security export control and other domestic laws are "a natural duty of companies conducting business in Japan and therefore not addressed directly"3.
Read that again, because it sets a demanding baseline. Classification under the Foreign Exchange Act, counterparty screening, obtaining export licenses. None of it is up for discussion. It is assumed, set aside, and the conversation begins from there.
From what I see in the field, that assumption holds in fewer companies than you would hope. The distinction between a classification report and a non-applicability certificate is not shared across the organization. Parameter sheets are being filled in from an outdated edition. Counterparty checks depend on one person reading a list carefully. A company in that state can march into the guidelines' real subject matter of autonomy, indispensability, and governance, and end up building an upper storey on a floor that is not there. If any of this sounds familiar, I would sort out how to write a non-applicability certificate and how it differs from a classification report first. It looks like a detour and it is not.
Seen from the other side, the same passage is clarifying. Domestic compliance is the floor. What the guidelines actually test is whether management has prepared for events that obeying Japanese law will not prevent, such as another country changing its rules overnight or a core technology walking out the door. The bar moved up a level.
Three principles, translated into language a board can use
The guidelines set out three principles for executives: understand your own business accurately and draft risk scenarios; treat economic security as an investment rather than a pure cost; and never stop talking to your stakeholders2.
The first is unglamorous and by far the hardest. You are asked to grasp, as accurately as you can, which businesses and which countries or regions you trade with, in what goods and services, and in what volumes and amounts across your value chain. Alongside that, you identify the core technologies that are the source of your competitive advantage2. Only once both are done can you sensibly work through scenarios in which an external shock cuts off your products, or in which those core technologies are lost or leak, and then rank your countermeasures by importance and urgency. The order matters. Mapping comes first, scenarios come second. I have sat in too many meetings that opened with "our risk is dependence on a single region" and closed without anyone being able to name a tier-two supplier.
The second principle, cost versus investment, is really a question of how the CEO decides to see the world. The data METI attached does some work here. Asked whether the cost of economic security measures or the revenue lost by not taking them would be greater, 22.3% of manufacturers said the lost revenue would dominate when looking one to three years ahead. Over a four-to-ten-year horizon, that figure rose to 31.9%1. Stretch the time frame and more companies conclude that inaction is the expensive option. As for what the work actually delivers, 68.4% named business continuity, meaning stable procurement, production, and supply1. That tells you something. Economic security behaves less like a growth investment and more like insurance against your operations stopping.
The third principle, dialogue, has a wrinkle worth noticing: the counterparty is not only external. The guidelines list customers, financial institutions, shareholders, the government, and local authorities, but the governance chapter goes further. It flags the likelihood of an information asymmetry between executives and the front line, urges that communication not become one-directional, and asks executives to actively listen to what the field is telling them4. In my experience the front line always hears it first. The unusual questionnaire from an overseas customer, the abrupt price notice from a supplier, the inquiry from a regulator. The real exposure is the structure that keeps any of it from reaching the top.
The 44-item checklist: the column on the right is the actual work
The appended checklist is where this document earns its keep. Counting the rows: five items under the principles executives should keep in mind, and thirteen each under securing autonomy, securing indispensability, and strengthening economic security governance. Forty-four in total5. Eight of them are worded as "it is also useful to," which puts them a notch below the rest. Rather than trying to complete everything at once, working through the thirty-six core items first is the realistic path.
Look at how the table is built. Three columns: the check item, a Yes/No box, and "the structure (organization, internal rules, etc.) and track record on which the check is based"5. Writing Y does not get you out of it. You then have to name the rule, the clause, the team, or the evidence. That third column is the whole point. Anyone can say "yes, we do that." If the basis column is blank, what you have is a practice living inside one employee's head. The design borrows from audit thinking, and it is the better for it.
A couple of items are worth quoting in substance. Under securing autonomy, where procurement depends on a single source, the guidelines recommend qualifying materials from potential alternative suppliers in advance so that they can be designed into your products, and building the relationships and internal capability to switch quickly if supply is cut2. Listing alternatives is not enough; get them qualified. That is a stiff standard, and I respect the drafters for writing it down.
On the indispensability side, the guidelines argue that protecting technology should not be parked with the heads of R&D, production engineering, and business units. It belongs to management, and it should pull in the heads of indirect functions such as corporate planning, HR, and legal, as a company-wide effort2. As long as technology outflow is filed as an engineering problem, departing-employee arrangements and joint-research partner selection will keep slipping through. Putting HR and legal in the room from the start is exactly right.
The governance chapter suggests setting up a command-center function for economic security and appointing someone at executive-officer level or above to own it, then immediately adds that companies with limited resources need not create a new organization or hire additional staff, and should assume they will work through existing teams and people2. That sentence keeps smaller firms in the conversation instead of quietly excluding them, and I was glad to see it.
One practical caveat. The moment supply chain resilience work involves several companies, competition law enters the room. The guidelines acknowledge this and point readers to the Japan Fair Trade Commission's framework on antitrust considerations for economic security initiatives, along with the accompanying casebook3. That casebook was published on November 20, 2025 by the JFTC together with METI and the Ministry of Land, Infrastructure, Transport and Tourism, and it organizes the analysis into three categories: information exchange, joint conduct, and business combinations6. If you have ever hesitated before sharing inventory data with a competitor, it is worth an hour of your time.
When the work to be checked grows and headcount does not
By now the pattern should be visible. What the guidelines really demand is more things known. Trade mapped by country and region across the full value chain. Visibility into tier-two and tier-three suppliers. Core technologies identified, plus verification of how counterparties handle them. There is even a checklist row asking whether you factor a counterparty's own technology management posture into the decision to work with them5.
The headcount assigned to all this almost never grows in proportion. In the companies I advise, export control and counterparty review typically run on one or two dedicated people, often doing the job alongside something else. When the surface area expands and the team does not, something gets missed. And if the consequence of a miss now lands on management, the only durable answer is to move the load off individuals and into a system.
That is what TRAFEED is built for. It is an export control AI agent aligned with METI's standards, supporting classification, counterparty screening, and economic security work in a single flow. In a joint proof-of-concept with Okayama University using roughly 30,000 past review records, we confirmed AI judgment accuracy of 95% or higher, and it surfaces the level of concern while keeping pace with regulatory changes across jurisdictions. The final classification decision remains with your export control officer, as it should. What changes is the weight of the research and first-pass screening leading up to it. Practically speaking, it means the "basis" column of that checklist can name a system instead of naming a person's experience. For me, that is the realistic destination in the guidelines era.
If you want the wider statutory picture, the complete guide to Japan's Economic Security Promotion Act and the article on the 2026 amendment enacted as Act No. 38 cover it. To check whether your company sits inside the support framework, start with the 16 specified critical materials and their supervising ministries.
Wrapping up
Here is what matters about the Economic Security Management Guidelines (1st Edition).
- METI's Trade and Economic Security Bureau published them on January 23, 2026 as recommendations for executives. They are not an obligation, and they are not premised on transactions with any specific country, company, or person.
- METI's view is that acting in line with them serves as one form of evidence that executives are meeting their duty of care.
- The focus is risk that domestic legal compliance alone cannot address. Classification and screening under the Foreign Exchange Act are treated as a baseline duty and sit outside the discussion.
- Three principles: map your business accurately and write risk scenarios, treat the work as investment rather than cost, and keep talking to stakeholders inside and outside the company.
- The checklist runs to 44 items, and the column asking for the structure and track record behind each answer is the real test. It separates practices that are documented from practices that are merely spoken about.
Reading it through, what this document seems least willing to tolerate is a company that knows economic security as a phrase and leaves it there. METI put the 70.7% figure at the very end of its own summary deck, which reads to me like a deliberate choice. Turn it around, though, and there is good news in it: a company that can fill in even ten of the forty-four rows with real evidence is already ahead of most of the field.
Run the first pass without aiming for a perfect score. The blanks that remain are your work plan for the next twelve months. If you get stuck on how to fill them, or you would rather rebuild from the export control foundations up, reach out through TRAFEED's individual consultation. We do not hand over a checklist and walk away; we stay with you until the basis column has something real in it.
References
Footnotes
-
METI Trade and Economic Security Bureau, "Economic Security Management Guidelines, 1st Edition (Overview)" (February 2026), p. 9, "Reference: The reality of manufacturers working on economic security." Underlying survey: Accenture Japan Ltd., "FY2024 Survey on the Actual State of Manufacturing Base Technologies (Survey on Challenges Facing Japan's Manufacturing Industry and Directions for Response)" (March 2025) https://www.meti.go.jp/policy/economy/economic_security/260123_guidelinegaiyo.pdf ↩ ↩2 ↩3
-
METI, "Economic Security Management Guidelines (1st Edition) Compiled" (January 23, 2026) https://www.meti.go.jp/press/2025/01/20260123004/20260123004.html ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
METI Trade and Economic Security Bureau, "Economic Security Management Guidelines (1st Edition)" (January 23, 2026), Section 2, "Basic Policy" https://www.meti.go.jp/policy/economy/economic_security/260123_guideline.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Ibid., Section 4(3), "Strengthening governance in economic security responses," p. 15 ↩
-
Japan Fair Trade Commission, METI, and Ministry of Land, Infrastructure, Transport and Tourism, "Casebook on Economic Security and the Antimonopoly Act" (November 20, 2025) https://www.meti.go.jp/press/2025/11/20251120001/20251120001-2.pdf ↩






