Risk Committee
A risk committee is a group formed by a company's board of directors to help the board oversee how the organization identifies and manages its risks. It supports the board's oversight role rather than running risk management day to day, which remains management's responsibility. The specific structure, powers, and responsibilities of a risk committee vary by company, sector, and jurisdiction.
A risk committee is typically a standing committee appointed by the board of directors to assist the board in its oversight of management's responsibility for implementing and maintaining an effective risk management framework, which at some institutions encompasses enterprise risk management (ERM). It generally functions as an oversight body and does not itself execute operational risk management activities, preserving the distinction between the board's oversight duty and management's operational accountability. Its composition, mandate, and authority are set out in a board-approved charter and vary by entity type, sector, and jurisdiction; in certain regulated sectors a risk committee may be a regulatory requirement, while in others it is adopted as a matter of governance practice. This entry is educational and not legal, audit, or compliance advice.
Why it matters
A risk committee helps close a critical gap in board oversight: while the full board carries ultimate responsibility for overseeing risk, the technical depth and time required to scrutinize an organization's risk exposures often exceed what a full board can devote in its regular meetings. By delegating focused attention to a dedicated committee, the board can more effectively oversee management's responsibility for implementing and maintaining a risk management framework, which at some institutions encompasses enterprise risk management (ERM). This structure reinforces a foundational governance principle, that oversight sits with the board and its committees while operational execution remains with management.
The distinction matters because a risk committee is an oversight body, not an operating one. It generally does not run risk management day to day, set individual controls, or make front-line risk decisions; those activities remain management's accountability. Confusing the two can weaken governance, either by drawing the committee into operational detail it is not positioned to own or by allowing management responsibilities to drift upward without clear accountability. A well-defined charter helps preserve this separation.
The relevance and required rigor of a risk committee vary considerably by entity type, sector, and jurisdiction. In certain regulated sectors, a board-level risk committee may be a regulatory requirement; in others, it is adopted as a matter of governance practice rather than legal obligation. Whether an organization needs one, and how it should be structured, depends on the specific facts, applicable rules, and the board's own judgment.
Who it's relevant to
Inside Risk Committee
Common questions
Answers to the questions practitioners most commonly ask about Risk Committee.