Regulation 21 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The Risk Management Committee is the newest of the mandatory committees and the one with the most awkward meeting rule — a 210-day gap that does not line up with quarterly board cycles, and therefore gets breached by companies that are otherwise meeting diligently.
Applies to the top 1000 listed entities by market capitalisation. At least three members, with a majority being members of the board, including at least one independent director. The chairperson is a member of the board. It meets at least twice a year, with not more than 210 days between two consecutive meetings, and quorum is two members or one-third, whichever is higher, including at least one board member.
Who it applies to, and who is in it
| Requirement | Position |
|---|---|
| Applicability | Top 1000 listed entities by market capitalisation as at the end of the previous financial year |
| Minimum members | Three |
| Board majority | A majority of members must be members of the board of directors |
| Independence | At least one independent director |
| SR equity share entities | At least two-thirds of the committee must be independent directors |
| Chairperson | A member of the board |
| Meetings | At least twice a year, gap not more than 210 days |
| Quorum | Two members or one-third, whichever is higher, including at least one board member |
The majority of board members requirement is the point that distinguishes this committee from the others: senior management may sit on it — and often should, because the chief risk officer and the head of technology are where the substance is — but they cannot outnumber the directors.
Why 210 days trips companies up
Two meetings a year sounds undemanding. The gap is what binds.
A committee that meets in May and then in December has met twice, and has a gap of roughly 214 days. It has breached the regulation while satisfying the meeting count.
The practical fix is to attach the RMC meetings to specific quarters — typically alongside the first and third quarter board meetings — rather than scheduling them as and when there is something to discuss. Risk agendas are elastic; the calendar is not.
Its mandate
Formulating a risk management policy. The policy must identify the internal and external risks faced by the entity — specifically including financial, operational, sectoral, sustainability (particularly ESG-related), information and cyber security risks, or any other risk the committee determines. It sets out the measures for risk mitigation, including systems and processes for internal control, and includes a business continuity plan.
Monitoring and evaluating the risk management systems of the entity.
Periodically reviewing the policy — at least once every two years, taking into account changing industry dynamics and the evolving complexity of the business.
Keeping the board informed about the nature and content of its discussions, recommendations and actions.
Appointment, removal and terms of remuneration of the chief risk officer, where such a role exists — subject to the board's review.
Where the RMC overlaps with the audit committee
The two committees look at adjacent things and the boundary is worth setting deliberately, because an item that neither committee owns is the item that gets missed.
The audit committee evaluates internal financial controls and risk management systems as part of its own mandate, from the perspective of financial reporting reliability. Audit committee →
The RMC owns the enterprise risk framework — including risks with no direct financial statement line, such as cyber, sustainability and business continuity.
The workable division is that the audit committee asks whether controls over reporting are effective, and the RMC asks whether the business has identified and is managing the risks that could damage it. Companies that leave the split undocumented usually find that cyber risk is discussed twice and business continuity not at all.
Where its output surfaces
The board's report carries a statement on the development and implementation of a risk management policy, including the elements of risk the board considers may threaten the existence of the company.
The BRSR, where applicable, requires disclosure of the entity's approach to identifying and managing ESG risks — which is the same material the RMC's policy is meant to address. Two documents drawing on one framework is the intended design; two documents describing different frameworks is a finding. The annual report and BRSR →
Key takeaways
- Top 1000 by market capitalisation — check your rank each year.
- A majority of the committee must be directors, though management may serve.
- At least one independent director; two-thirds for entities with SR equity shares.
- Twice a year and no more than 210 days apart — the gap, not the count, is what binds.
- Cyber and ESG risk are named in the policy requirement, not optional additions.
- Review the policy at least once in two years.
- Set the boundary with the audit committee in writing.
Read next
- Regulation 18: The Audit Committee of a Listed Entity
- Regulation 17: Board of Directors of a Listed Entity
- Regulation 34: The Annual Report and BRSR
- Regulation 22: Vigil Mechanism and Whistle-Blower Protection
Disclaimer: Positions stated as on 5 September 2026. Applicability is keyed to market capitalisation rank and has been widened more than once — verify the current position on sebi.gov.in before relying on it.
Key Facts About Regulation 21
- Applies in: All states across India, under the relevant central law.
- Mode: Mostly online via the official government portal.
- Typical timeline: Ranges from a few days to a few weeks depending on the case.
- Non-compliance: May attract penalties, interest or late fees.
- Expert help: TaxClue completes the entire process end to end for you.
Which companies must constitute a Risk Management Committee?
The top 1000 listed entities by market capitalisation as at the end of the previous financial year.
What is the composition of the Risk Management Committee?
At least three members, with a majority being members of the board of directors, including at least one independent director, and chaired by a member of the board.
Over 90% of compliance penalties in India arise from missed due dates — timely handling can save businesses thousands of rupees each year.
Regulation 21: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.