Strategic Performance Management and Business Valuation · Corporate Risk Management Performance
Risk Governance and Role of Risk Officers
Updated 11 October 2026
Risk governance is the system of structures, roles and policies through which a board sets risk appetite, oversees management and makes sure risks are identified, owned and reported. To answer questions, name the body, state its duty, link it to the rule or line of defence, and give a clear recommendation.
Understand Risk Governance and Role of Risk Officers
Risk governance answers one question: who is responsible for risk, and how does the board know it is under control? Management runs the business and takes risks. The board decides how much risk is acceptable and checks that management stays within it.
The board sets the risk appetite (how much risk the company is willing to accept to reach its goals) and approves the risk management policy. Many boards delegate detailed work to a Risk Management Committee (RMC). The audit committee also looks at internal financial controls and risk systems. The board remains responsible even when it delegates.
The three lines of defence model divides roles. The first line is business and operating managers, who own and manage risks daily. The second line is risk management and compliance functions, who set frameworks, advise and monitor. The third line is internal audit, which gives independent assurance to the board. Keep the lines separate: independence is the point of the third line.
The Chief Risk Officer (CRO) leads the second line. The CRO designs the risk framework, consolidates risk information across the company, reports to the board or RMC, and challenges business decisions that exceed appetite. The CRO does not own business risks. Line managers do.
Risk culture is the set of shared attitudes and behaviours towards risk. It is shaped by tone at the top, incentives, open escalation and consequences for ignoring limits. Good policies fail in a poor culture. In India, the Companies Act, 2013 and SEBI LODR Regulations place duties on boards and, for listed companies, require a risk management committee in specified cases.
Key rules to remember
- Three lines of defence
- 1st line = owns and manages risk; 2nd line = oversees and monitors (risk, compliance); 3rd line = independent assurance (internal audit)
- Use this to assign any role described in a case. Internal audit is never the first or second line.
- Board responsibility
- Board sets risk appetite and approves policy; management implements; RMC assists the board
- The board cannot delegate away its accountability.
- SEBI LODR: RMC applicability
- RMC is mandatory for the top 1,000 listed entities by market capitalisation (as per SEBI LODR, Regulation 21(5))
- Other listed entities may constitute one voluntarily. Check the latest SEBI amendment if the question gives a threshold.
- SEBI LODR: RMC composition
- RMC: minimum 3 members, majority board members, at least one independent director (Reg. 21(2)); chaired by a board member
- Senior executives may be members, but board members must form the majority.
- SEBI LODR: RMC meetings
- At least twice a year, with not more than 180 days between two consecutive meetings
- The 180-day limit applies to the gap between any two consecutive meetings, so two meetings a year is the minimum, not the only test.
- Companies Act, 2013: board report, audit committee and independent directors
- Section 134(3)(n): board report must include a statement on development and implementation of a risk management policy; Section 177(4): audit committee evaluates internal financial controls and risk management systems; Schedule IV (Code for Independent Directors): independent directors satisfy themselves that risk management systems are robust and defensible
- Match each duty to its source: the board report, the audit committee and the independent directors each have a separate provision.
How to solve Risk Governance and Role of Risk Officers questions
Use this method for any governance question, whether it is a short MCQ or a case-based descriptive answer.
- 1Read the scenario and list every person or body mentioned: board, RMC, audit committee, CRO, managers, internal audit.
- 2Mark what each one is doing in the case, such as setting appetite, monitoring, owning a risk or giving assurance.
- 3Assign each to a line of defence or to the board level. Note any gap, overlap or lost independence.
- 4Check the regulatory angle: is the company listed, is an RMC required, and are composition and meeting rules met?
- 5Identify the cultural or reporting weakness, such as weak tone at the top, no escalation or incentives that reward risk-taking.
- 6Write the answer in order: finding, rule or principle, consequence, recommendation.
- 7End with specific, practical actions with an owner, for example CRO reports directly to the RMC.
Quickest way: Role-to-line matching
When to use it: Use for MCQs and for the first minute of a case question, when you need to place roles quickly.
- Ask: does this person own the risk? If yes, first line.
- Ask: do they set policy or monitor others? If yes, second line, which includes the CRO.
- Ask: do they independently test and report to the board or audit committee? If yes, third line.
- For regulation, check three things only: is it required, who sits on the committee, and how often it meets.
- Eliminate options that make the CRO own business risk or make internal audit design controls.
Common mistakes in Risk Governance and Role of Risk Officers
Treating the CRO as the person who owns all risks.
The title suggests the CRO is responsible for every risk in the company.
Fix: Say that business managers own risks. The CRO frames, aggregates, monitors, challenges and reports.
Placing internal audit in the second line or merging it with risk management.
Both functions deal with controls and risk, so they look alike.
Fix: Internal audit is the third line and must be independent. It gives assurance and does not manage risk.
Saying the RMC replaces the board's responsibility.
Students read delegation as transfer of accountability.
Fix: State that the RMC assists the board and the board remains accountable.
Quoting SEBI LODR requirements with wrong numbers, such as the meeting frequency or the gap between meetings.
The numbers are similar to audit committee rules and get mixed up.
Fix: Learn the RMC set once, as per Reg. 21: minimum three members, majority board members, at least one independent director, at least two meetings a year, not more than 180 days between two consecutive meetings.
Ignoring risk culture and writing only about structures.
Structures are easier to list than behaviours.
Fix: Add tone at the top, incentives, open escalation and accountability whenever the question asks why governance failed.
Giving a generic recommendation with no owner or action.
Students run short of time at the end of the answer.
Fix: Write two or three concrete actions, each with who does it and what is reported to whom.
Worked examples
Example 1
Shreeram Auto Ltd, a listed company, has sales managers who approve large dealer credit limits and monitor the resulting bad debts themselves. The risk team prepares the credit policy and reviews limits monthly. The internal audit team independently tests whether limits are followed and reports to the audit committee. Identify the line of defence for each group and comment on the arrangement.
Show the solution
- Sales managers approve credit and live with the outcomes. They own the risk, so they are the first line.
- The risk team prepares the policy and reviews limits. It sets frameworks and monitors, so it is the second line.
- Internal audit tests compliance independently and reports to the audit committee. It is the third line.
- Assessment: each role fits its line and the independence of the third line is preserved. First-line managers monitoring their own bad debts is acceptable, because owning and managing the risk is the first line's job and the risk team independently reviews limits every month.
- The company is listed. If it falls within the top 1,000 listed entities by market capitalisation, it must have an RMC, and the second line should report to that committee. The case does not give its rank, so state this as a condition.
- Recommendation: the risk team should report limit exceptions to the RMC, and sales incentives should reflect credit quality, not volume alone.
Answer: Sales managers are the first line, the risk team the second line and internal audit the third line. The structure is adequate. Strengthen it by reporting limit exceptions to the RMC and linking sales incentives to credit quality.
Example 2
Bharat Infra Ltd is among the top 1,000 listed companies by market capitalisation. It has an RMC of three members, all senior executives, which met once in the year. The CRO reports only to the Managing Director. Evaluate compliance and suggest improvements.
Show the solution
- Applicability: the company is in the top 1,000, so an RMC is mandatory under SEBI LODR (Regulation 21(5)).
- Composition: the RMC needs a minimum of three members, with a majority being board members, and at least one independent director (Regulation 21(2)). All three members are executives and none is a director, so the majority-of-board-members requirement is clearly breached. There is also no independent director.
- Meetings: the RMC must meet at least twice a year, with not more than 180 days between two consecutive meetings. One meeting in the year breaches the minimum.
- Reporting: a CRO reporting only to the MD weakens independence and board oversight, since the board gets filtered information.
- Recommendation: reconstitute the RMC with a majority of directors and an independent director, hold at least two meetings with gaps within 180 days, and give the CRO direct access to the RMC.
Answer: The company has not complied on composition or meeting frequency. It should reconstitute the RMC with a majority of board members including an independent director, meet at least twice a year within 180 days, and give the CRO direct reporting to the RMC.
Exam tips
- In MCQs, the usual trap is role confusion. Check each option against the three lines of defence before choosing.
- In case questions, always tie the finding to a rule or principle and end with a named action. This earns the application marks.
- Learn the SEBI LODR RMC points as one short list and write only what you are sure of. State the applicability test, composition and meeting frequency.
- When asked why governance failed, cover structure, reporting lines and culture. Many students cover only the first.
- Use the company's name and figures from the case in your answer. Generic text earns fewer marks.
Practice questions from Corporate Risk Management Performance
- A firm's portfolio has a one-day 99% Value at Risk of ₹4 crore. Assuming returns are independent and identically distributed and the square-…
- Sundaram Textiles Ltd estimates that a currency movement could cause a loss of Rs 60 lakh with a probability of 0.25 in the coming year. It …
- In enterprise risk management, a firm's 'risk appetite' is best described as:
- Asha Textiles has a risk register entry with probability of occurrence 0.20 and estimated impact of ₹50 lakh. Management buys a control cost…
- Which of the following is a risk-transfer response, as opposed to risk avoidance, reduction or acceptance?
Risk Governance and Role of Risk Officers: frequently asked questions
Is a Risk Management Committee mandatory for all listed companies?
No. SEBI LODR makes it mandatory for the top 1,000 listed entities by market capitalisation. Other listed companies may set one up voluntarily. Check the latest SEBI amendment for the current threshold.
What is the main role of a Chief Risk Officer?
The CRO leads the risk function. The CRO builds the risk framework, aggregates risk information, monitors exposure against appetite and reports to the board or RMC. Business managers still own the risks.
What are the three lines of defence in risk governance?
The first line is operating management, which owns and manages risk. The second line is risk and compliance, which sets policy and monitors. The third line is internal audit, which gives independent assurance to the board.
How is risk culture different from risk policy?
A policy is a written rule. Culture is how people actually behave towards risk, shaped by tone at the top, incentives and willingness to escalate bad news. A strong policy fails in a weak culture.