Corporate governance in India now prioritises risk oversight as a key board responsibility. While the Companies Act 2013 provides the foundation, SEBI (LODR) Regulations establish a structured framework for listed entities through the Risk Management Committee (RMC). The RMC ensures proactive risk identification and management systems to safeguard businesses against uncertainties and disruptions.
Applicability of Risk Management Committee Provisions
The provisions of Regulation 21 apply to specific categories of entities. These include:
- The top 1,000 listed entities, determined based on market capitalisation as at the end of the immediately preceding financial year; and
- High Value Debt Listed Entities (entities with a listed value of outstanding non-convertible debt securities of ₹500 Crore and above).
Composition and Meeting Requirements
Regulation 21(2) sets clear requirements for how the committee should be formed to ensure both diversity and proper Board oversight.
The committee must have at least three members. And the majority of them should be the members of the Board of Directors. As per Regulation 21(2), in the case of a listed entity having outstanding SR (Superior Rights) equity shares, at least two-thirds of the Risk Management Committee shall comprise independent directors. Otherwise, it is necessary to include at least one Independent Director. The Chairperson, too, has to be a member of the Board.
The Companies Act does not specifically mandate a Risk Management Committee for all companies. However, risk management remains part of the Board's responsibilities under the Act (under Section 177, the Audit Committee also reviews risk management systems). SEBI fills this gap for the larger market by providing this structured framework.
To maintain active oversight, as per Regulation 21(3C), the committee must meet at least twice a year. The gap between two consecutive meetings shall not exceed 180 days. These meetings ensure a periodic review of risks and mitigation strategies.
Meetings must adhere to specific quorum requirements under Regulation 21(3B) to ensure the validity of proceedings. Either two members or one-third of the members, whichever is higher; and at least one member of the Board must be present.
Roles and Responsibilities of the Risk Management Committee
The Risk Management Committee plays a central role in identifying, assessing, and managing risks. Its responsibilities are structured and cover multiple areas as detailed in Part C of Schedule II of the SEBI LODR Regulations.
1. Formulation of Risk Management Policy
The RMC is responsible for developing a comprehensive risk management policy. This policy must include a Risk Identification Framework to spot internal and external risks. These risks include:
- Financial risks (liquidity, credit, and market risks).
- Operational and sectoral risks.
- Sustainability and ESG-related risks (specifically those impacting long-term growth and climate change).
- Information and Cyber Security risks (now a mandatory focus area for the RMC).
- Any other risks the Committee determines.
The policy must establish Risk Mitigation Measures, including internal controls and a Business Continuity Plan to prepare for unforeseen disruptions.
2. Risk Monitoring Framework
The committee must ensure that appropriate methodologies and systems are in place to monitor risks and evaluate their impact on business operations. This creates a continuous process of risk tracking rather than a one-time assessment.
3. Oversight of Risk Management Systems
The committee is required to monitor and oversee the implementation of the risk management policy and evaluate the adequacy and effectiveness of risk management systems.
4. Periodic Review of Risk Policy
Under Regulation 21(4) and Schedule II, the risk management policy must be reviewed at least once every two years. The review must consider changing industry dynamics and increasing business complexity.
5. Reporting to the Board
The committee must keep the Board of Directors informed about the Key discussions, recommendations, and Actions required on risk-related matters
6. Oversight of Chief Risk Officer (CRO)
The committee is responsible for reviewing the appointment, removal, and remuneration of the Chief Risk Officer if the company has one.
7. Coordination with Other Committees
The RMC coordinates with other committees, like the Audit Committee, when responsibilities overlap. This coordination is important for maintaining a holistic and integrated approach to risk governance. It prevents gaps in the company's oversight framework.
In Simple Words:
The Risk Management Committee ensures that the company identifies risks proactively. It makes sure the company has strong systems to manage them. The committee also ensures the company stays prepared for uncertainties and disruptions. Ultimately, the committee ensures the company is always prepared for uncertainties.
The Role of the Company Secretary
The Company Secretary (CS) ensures that the committee functions smoothly and that compliance requirements are met. Under Regulation 6, the CS acts as the Secretary to the Committee. Their role includes coordinating meetings and handling all documentation. They ensure compliance with SEBI LODR requirements, since the committee operates within strict legal standards. They also assist in drafting risk management policies and maintain minutes and records of all proceedings.
The Company Secretary also facilitates communication between management and the committee. They track the implementation of risk mitigation decisions to ensure the committee functions effectively. Their involvement ensures the company stays compliant and the committee operates smoothly.
In Essence
The Risk Management Committee helps companies identify, assess, and manage risks to protect their future. SEBI LODR mandates this structured approach for listed entities to ensure market transparency. The Company Secretary ensures the smooth functioning and compliance of the committee. By following these regulations, a company ensures it is prepared for uncertainties. The RMC acts as a safeguard so that the entity remains sustainable in a complex business environment.