Skip to content

Environmental, Social and Governance (ESG) - Principles and Practice · Risk Management

Risk Governance and Regulatory Requirements for Companies

Updated 11 October 2026 · Fact-checked

Risk governance is the structure that decides who owns risk in a company. The board is ultimately responsible. In listed companies, a Risk Management Committee under Regulation 21 of SEBI LODR oversees the risk policy. The Companies Act requires a risk statement in the Board's report. You answer by naming the body, the provision, the facts and the conclusion.

Understand Risk Governance and Regulatory Requirements

Risk governance means the people, committees and rules that make sure risk is identified, owned, monitored and reported. Risk management is the doing. Risk governance is the oversight of the doing. Examiners test the second.

The board sits at the top. It sets the risk appetite, approves the risk policy and checks that the systems work. The law backs this in several places. Section 134(3)(n) of the Companies Act, 2013 requires the Board's report to include a statement on the development and implementation of a risk management policy, including the elements of risk which, in the board's opinion, may threaten the company's existence. Section 177(4) lists evaluation of internal financial controls and risk management systems among the audit committee's terms of reference. Schedule IV (Code for Independent Directors) expects independent directors to satisfy themselves that systems of risk management are robust and defensible.

For listed entities, SEBI LODR adds more. Regulation 21 requires a Risk Management Committee (RMC) for the top 1000 listed entities by market capitalisation. Regulation 17(9) makes the board responsible for framing, implementing and monitoring the risk management plan, and for having procedures to inform board members about risk assessment and minimisation. Other listed entities may set up an RMC voluntarily.

Below the board, management runs the system. Many companies appoint a Chief Risk Officer (CRO), a senior executive who builds the framework, consolidates risk reports and reports to the RMC. Under Regulation 21, the appointment, removal and remuneration of the CRO (where there is one) are subject to review by the RMC.

The company secretary is not the risk owner. The CS is the governance adviser. The CS helps constitute the committee, drafts the charter and risk policy, schedules meetings so the gap rules are met, maintains minutes under the Secretarial Standards, and makes sure the disclosures in the Board's report, annual report and website are complete and consistent.

Key rules to remember

Board's report risk disclosure
Section 134(3)(n), Companies Act, 2013
Statement on development and implementation of the risk management policy, including elements of risk that may threaten the company's existence. Applies to the Board's report generally.
Audit committee and risk
Section 177(4), Companies Act, 2013
Terms of reference include evaluation of internal financial controls and risk management systems. The RMC does not replace this role under the Act.
Independent directors' duty
Schedule IV, Part II
Satisfy themselves that financial controls and systems of risk management are robust and defensible.
Who needs an RMC
Regulation 21, SEBI LODR: top 1000 listed entities by market capitalisation
Others may constitute it voluntarily. Check the current applicability criteria in the Regulations before answering.
RMC composition
Minimum 3 members; majority from the board; at least 1 independent director; chairperson a board member
Senior executives may also be members. A chairperson who is not a director breaches the rule.
RMC meetings
At least 2 meetings a year; gap between two consecutive meetings not more than 180 days
Both conditions must be met. Two meetings a year can still breach the 180-day gap.
RMC quorum
Higher of 2 members or one-third of members, including at least 1 board member
Example: 9 members gives one-third = 3, so quorum is 3.
RMC role
Risk policy + monitoring + review at least once in 2 years + reporting to board
Policy covers internal and external risks including financial, operational, sectoral, sustainability (ESG), information and cyber security risks, mitigation measures and a business continuity plan.
Board responsibility for risk
Regulation 17(9), SEBI LODR
Board frames, implements and monitors the risk management plan and ensures procedures to inform members about risk assessment and minimisation.

How to solve Risk Governance and Regulatory Requirements questions

Use this order for any case or theory question on risk governance. It keeps your answer in the provision, facts, conclusion format.

  1. 1Identify whether the company is listed, and if so whether it falls in the top 1000 by market capitalisation. This decides whether Regulation 21 applies.
  2. 2Name the body in question: board, audit committee, RMC, CRO or company secretary.
  3. 3State the rule in plain words with its source: Section 134(3)(n), Section 177(4), Schedule IV, Regulation 17(9) or Regulation 21.
  4. 4Test each fact against each condition: members, majority of directors, independent director, chairperson, quorum, meeting count and gap.
  5. 5Say clearly which condition is met and which is breached. Do not just say 'non-compliant'.
  6. 6Give the corrective action: reconstitute the committee, hold a meeting, amend the policy, fix the disclosure.
  7. 7Add the company secretary's practical role: drafting, notice, minutes, disclosure check.
  8. 8Close with a one-line conclusion that answers the question asked.

Quickest way: Four-point RMC check

When to use it: Use when a question gives facts about a listed company's risk committee and asks if it is compliant.

  1. Applicability: listed, top 1000 by market capitalisation?
  2. Composition: at least 3 members, majority directors, one independent director, chairperson a director.
  3. Meetings: at least twice a year and no gap above 180 days; check quorum.
  4. Work done: policy in place, reviewed at least once in 2 years, CRO changes reviewed, board informed, Board's report statement made.

Common mistakes in Risk Governance and Regulatory Requirements

  • Saying the Risk Management Committee is required for every company.

    Students mix the Companies Act disclosure with the LODR committee requirement.

    Fix: Section 134(3)(n) applies to the Board's report. The RMC under Regulation 21 applies to the top 1000 listed entities by market capitalisation. Others may set one up voluntarily.

  • Treating the chairperson of the RMC as any member, including a senior executive.

    Students remember that executives may be members and assume the chair can be one too.

    Fix: Executives can be members, but the chairperson must be a member of the board, and the majority of members must be directors, with at least one independent director.

  • Checking only that two meetings were held in the year.

    Students remember 'twice a year' and forget the second condition.

    Fix: Also check that no more than 180 days passed between any two consecutive meetings. Count the days from the dates given.

  • Making the company secretary the owner of risk.

    The CS is involved in every committee, so students assume risk ownership.

    Fix: Risk is owned by the board and managed by executives and the CRO. The CS advises, drafts, ensures compliance and checks disclosures.

  • Ignoring the audit committee and independent directors.

    Students focus on Regulation 21 and forget the Companies Act links.

    Fix: Mention Section 177(4) and Schedule IV in any full answer on risk governance. Say that the RMC does not remove these duties.

  • Writing that the RMC policy must be reviewed every year.

    Students assume annual review as a default.

    Fix: The review is required at least once in two years, considering changing industry dynamics. More frequent review is good practice.

Worked examples

Example 1

Sunrise Textiles Ltd, a listed company within the top 1000 by market capitalisation, has a four-member Risk Management Committee: two directors (one independent), the CFO and the Head of Operations. The CFO chairs it. It met on 10 February and 15 September in the same financial year. Examine compliance with SEBI LODR.

Show the solution
  1. Applicability: the company is listed and in the top 1000, so Regulation 21 applies and an RMC is mandatory.
  2. Composition rule: the majority of members must be board members, and the chairperson must be a board member. At least one independent director must be a member.
  3. Application: only 2 of 4 members are directors. That is half, not a majority, so the rule is breached. The CFO is not a director, so the chairperson condition is also breached. The independent director condition is met.
  4. Meetings: two meetings in the year meets the minimum. But 10 February to 15 September is over 200 days, which exceeds the 180-day limit between consecutive meetings, so this is breached.
  5. Corrective action: add at least one more director, for example another independent director, so directors are 3 of 5, and appoint a director as chairperson. Schedule meetings so no gap exceeds 180 days.
  6. Company secretary's role: draft the board resolution reconstituting the committee, prepare the annual meeting calendar, and record the changes in the minutes and disclosures.

Answer: The company complies on applicability and on having an independent director. It does not comply on majority of directors, chairperson being a director, and the 180-day gap. It should reconstitute the committee and fix the meeting schedule.

Example 2

Explain the board's responsibility for risk management in an unlisted public company and the role of the company secretary in meeting it.

Show the solution
  1. Source of duty: the Companies Act, 2013 does not require an RMC for an unlisted company, but the board remains responsible for risk oversight as part of directors' duties.
  2. Disclosure: Section 134(3)(n) requires the Board's report to include a statement on the development and implementation of a risk management policy, including elements of risk that may threaten the company's existence.
  3. Audit committee link: where the company has an audit committee, Section 177(4) includes evaluation of risk management systems in its terms of reference.
  4. Independent directors: if the company has them, Schedule IV expects them to satisfy themselves that the systems of risk management are robust and defensible.
  5. Company secretary: helps draft the risk policy for board approval, places risk on the board agenda, ensures the Board's report statement is accurate, and keeps minutes of risk discussions under the Secretarial Standards.
  6. Conclusion: the board owns risk oversight. The CS supports with drafting, process and disclosure but does not own the risk.

Answer: The board is responsible for the risk policy and oversight, and must make the Section 134(3)(n) statement in its report. The company secretary supports through drafting, agenda management, minutes and disclosure checks.

Exam tips

  • In case questions, always state whether the company is listed and in the top 1000 before applying Regulation 21. Marks are given for this first step.
  • Learn the RMC conditions as a list: minimum members, majority directors, independent director, chair, quorum, meeting count, 180-day gap. Tick them off one by one against the facts.
  • Pair every Companies Act point with its LODR counterpart: Section 134(3)(n) with Regulation 21, and Section 177(4) with the RMC's role.
  • In drafting-type questions, show the company secretary's practical steps: board resolution, charter, notice, minutes, disclosure.
  • Count days when meeting dates are given. Show the calculation in one line so the examiner sees the reasoning.

Practice questions from Risk Management

Risk Governance and Regulatory Requirements in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Governance and Regulatory Requirements: frequently asked questions

Is a Risk Management Committee mandatory for all listed companies?

No. Regulation 21 of SEBI LODR makes it mandatory for the top 1000 listed entities by market capitalisation. Other listed entities may constitute one voluntarily. Always check the current applicability criteria in the Regulations.

What does Section 134 say about risk management?

Section 134(3)(n) of the Companies Act, 2013 requires the Board's report to include a statement on the development and implementation of a risk management policy. It must cover the elements of risk that, in the board's opinion, may threaten the company's existence.

What is the role of the company secretary in risk management?

The company secretary is a governance adviser, not the risk owner. The CS helps constitute the committee, drafts the policy and charter, arranges compliant meetings, keeps minutes and checks that risk disclosures are complete and consistent.

Is the Chief Risk Officer a legal requirement?

The Companies Act does not require a CRO. Regulation 21 refers to a CRO where the company has one, and says the RMC reviews the appointment, removal and remuneration. So you should describe the CRO as a governance practice rather than a general mandate.