Skip to main content
Category: Board Committees and Governance

Risk Committee

Also known as: Board Risk Committee
Simply put

A risk committee is a group formed by a company's board of directors to help the board oversee how the organization identifies and manages its risks. It supports the board's oversight role rather than running risk management day to day, which remains management's responsibility. The specific structure, powers, and responsibilities of a risk committee vary by company, sector, and jurisdiction.

Formal definition

A risk committee is typically a standing committee appointed by the board of directors to assist the board in its oversight of management's responsibility for implementing and maintaining an effective risk management framework, which at some institutions encompasses enterprise risk management (ERM). It generally functions as an oversight body and does not itself execute operational risk management activities, preserving the distinction between the board's oversight duty and management's operational accountability. Its composition, mandate, and authority are set out in a board-approved charter and vary by entity type, sector, and jurisdiction; in certain regulated sectors a risk committee may be a regulatory requirement, while in others it is adopted as a matter of governance practice. This entry is educational and not legal, audit, or compliance advice.

Why it matters

A risk committee helps close a critical gap in board oversight: while the full board carries ultimate responsibility for overseeing risk, the technical depth and time required to scrutinize an organization's risk exposures often exceed what a full board can devote in its regular meetings. By delegating focused attention to a dedicated committee, the board can more effectively oversee management's responsibility for implementing and maintaining a risk management framework, which at some institutions encompasses enterprise risk management (ERM). This structure reinforces a foundational governance principle, that oversight sits with the board and its committees while operational execution remains with management.

The distinction matters because a risk committee is an oversight body, not an operating one. It generally does not run risk management day to day, set individual controls, or make front-line risk decisions; those activities remain management's accountability. Confusing the two can weaken governance, either by drawing the committee into operational detail it is not positioned to own or by allowing management responsibilities to drift upward without clear accountability. A well-defined charter helps preserve this separation.

The relevance and required rigor of a risk committee vary considerably by entity type, sector, and jurisdiction. In certain regulated sectors, a board-level risk committee may be a regulatory requirement; in others, it is adopted as a matter of governance practice rather than legal obligation. Whether an organization needs one, and how it should be structured, depends on the specific facts, applicable rules, and the board's own judgment.

Who it's relevant to

Board members and non-executive directors
Directors who serve on or interact with a risk committee rely on it to give focused oversight to the organization's risk exposures on the board's behalf. Understanding that the committee's role is oversight, not operational execution, helps directors hold management accountable for the risk management framework without taking on management's responsibilities themselves.
Chief risk officers and risk management functions
Risk leaders in management typically report to or engage with the risk committee, presenting risk information and processes for the committee's review and challenge. Because operational risk management remains management's accountability, these functions benefit from a clear charter that delineates what the committee oversees versus what management executes.
General counsel and governance professionals
Those responsible for board structure and charters need to understand whether a risk committee is a regulatory requirement in the organization's sector and jurisdiction or an adopted governance practice, and to draft a charter that accurately sets the committee's composition, mandate, and authority.
Compliance and internal audit functions
Assurance and compliance professionals interact with a risk committee as part of the broader governance structure. Recognizing the committee's oversight role, distinct from management's operational duties and from assurance activities, helps these functions position their own reporting and coordinate appropriately with the committee.

Inside Risk Committee

Board-Level Mandate and Charter
A risk committee is typically established as a committee of the board, operating under a written charter that defines its purpose, authority, composition, and responsibilities. The charter generally clarifies that the committee performs an oversight function rather than day-to-day risk management, which remains with executive management.
Risk Appetite and Tolerance Oversight
The committee generally reviews and recommends the organization's risk appetite (the amount and type of risk the entity is willing to pursue) for board approval, and monitors whether the business is operating within articulated risk tolerances. It does not typically set operational risk limits itself, which is usually a management responsibility.
Enterprise Risk Management (ERM) Review
The committee often oversees the design and functioning of the ERM framework, which may draw on standards such as COSO ERM or ISO 31000. These frameworks are generally voluntary and adopted at the entity's discretion, subject to any sector-specific regulatory expectations.
Composition and Independence
Membership commonly includes independent non-executive directors, and in certain regulated sectors (for example, some banking and financial institutions in various jurisdictions) a separate board risk committee may be a supervisory expectation. Requirements for existence, composition, and independence vary by jurisdiction, sector, and entity type.
Relationship with Other Committees and Functions
The committee typically coordinates with the audit committee, which often focuses on financial reporting and internal control assurance, and interacts with second-line functions such as the risk management and compliance functions, and with third-line internal audit for independent assurance. The specific division of labor depends on the entity's governance structure.
Reporting and Escalation
The committee generally receives reports on the risk profile, emerging risks, and significant risk exposures, and reports its conclusions and recommendations to the full board. Escalation pathways are usually defined so that material matters reach the board in a timely manner.

Common questions

Answers to the questions practitioners most commonly ask about Risk Committee.

Is a risk committee the same thing as the audit committee?
No. Although some entities combine the two, they generally serve distinct purposes and, where separate, have different mandates. A risk committee typically focuses on overseeing the risk management framework, risk appetite, and the entity's principal and emerging risks on a forward-looking basis. An audit committee more commonly focuses on the integrity of financial reporting, external audit, and internal controls over financial reporting. Whether an entity must have a separate risk committee, and how the mandates are divided, varies by jurisdiction, sector (financial institutions are often subject to specific expectations), and entity type. Combining or separating these functions is often a matter of board judgment unless a specific requirement applies.
Does having a risk committee mean the board has delegated responsibility for managing risk to that committee?
Not in the operational sense. A board-level risk committee generally performs an oversight function; it reviews and challenges the risk management framework and monitors the risk profile. Day-to-day identification, assessment, and management of risk typically sits with management and operational functions. In many governance models, ultimate accountability for risk oversight remains with the full board, and a committee's existence does not discharge that accountability. Delegation to a committee generally concerns the depth of oversight work, not a transfer of the board's overall responsibility. The precise allocation depends on the entity's charter, applicable law, and any relevant governance code.
How should a risk committee's terms of reference typically be structured?
Terms of reference generally set out the committee's purpose, membership and quorum, meeting frequency, reporting lines to the board, and the scope of matters within its remit. Many charters clarify the boundary with other committees, particularly the audit committee, to avoid gaps or overlaps in oversight. They also often describe the committee's authority to access information and to obtain independent advice. The content should be tailored to the entity and reviewed periodically. Where sector-specific requirements apply, the terms of reference may need to reflect them; entities should confirm any applicable rules for their jurisdiction and sector. This is a governance design matter rather than a fixed template.
What information does a risk committee generally need from management to carry out its oversight role?
A committee typically relies on reporting that allows it to understand the entity's principal and emerging risks, the status of key controls, and how the current risk profile relates to the board's stated risk appetite and tolerances. Reporting often distinguishes inherent from residual risk and addresses both control design and operating effectiveness, though the format depends on the entity's framework. The committee generally exercises challenge over management's assessments rather than preparing them. The sufficiency and quality of information is a common area of committee focus, and the appropriate level of detail depends on the entity's size, complexity, and the judgment of those involved.
How does a risk committee typically interact with assurance functions such as internal audit?
In many governance models, a risk committee receives assurance from independent functions to support its oversight, while remaining distinct from those functions. Internal audit generally provides independent assurance over the effectiveness of risk management and controls, whereas risk management functions may support the design and operation of the framework. The committee typically considers whether it is receiving sufficient assurance and may consider the coordination of different assurance providers. Reporting lines and the independence of these functions vary by entity and framework, and the specific arrangements should reflect the entity's structure and any applicable requirements.
How can a risk committee assess whether the entity is operating within its risk appetite?
A committee generally reviews whether management has articulated risk appetite and translated it into more granular tolerances or limits, and whether reporting shows the current risk profile against those measures. Because risk appetite, risk tolerance, and risk capacity are distinct concepts, committees often look for clarity on how each is defined and used. Assessing operation within appetite typically involves reviewing both quantitative indicators and qualitative judgment, and considering breaches or near-breaches and management's response. The approach depends heavily on the entity's framework and facts, and monitoring within appetite is an ongoing exercise rather than a one-time determination. These observations are educational and not audit, legal, or compliance advice.

Common misconceptions

The risk committee manages the organization's risks.
The committee generally provides oversight of the risk management framework and the risk profile; the operational identification, assessment, and treatment of risks typically rests with management (the first and second lines), not the board committee. Attributing operational risk management to the committee conflates oversight with execution.
Every organization is legally required to have a separate board risk committee.
The requirement to establish a dedicated risk committee varies by jurisdiction, sector, and entity type. In some regulated sectors it may be expected or mandated, while in many other entities risk oversight can be handled by the audit committee or the full board. Codes and frameworks that discuss such committees are often non-binding best practice rather than universal legal requirements.
The risk committee and audit committee perform the same role and are interchangeable.
While their remits can overlap and coordination is common, the audit committee generally concentrates on financial reporting integrity and internal control assurance, whereas a risk committee typically has a broader focus on the enterprise risk framework and risk appetite. Some entities combine the functions; others separate them depending on complexity and regulatory context.

Best practices

Maintain a clear written charter that distinguishes the committee's oversight role from management's execution role, and confirm accountability across the three lines.
Recommend a risk appetite statement for board approval and periodically review whether the organization is operating within its stated tolerances, escalating breaches promptly.
Coordinate explicitly with the audit committee and internal audit to avoid gaps or duplication in assurance coverage, documenting how responsibilities are allocated.
Confirm the committee's composition and independence align with applicable jurisdictional and sector-specific expectations, seeking professional advice where requirements are uncertain.
Request regular reporting on the enterprise risk profile, emerging risks, and the operating effectiveness of key controls, rather than relying solely on point-in-time snapshots.
Periodically assess whether the entity's chosen risk framework and committee structure remain appropriate for its size, complexity, and regulatory environment, treating framework adoption as a deliberate governance decision.