Regulation 21: Risk Management Committee

The Risk Management Committee is the newest of the mandatory committees and the one with the most awkward meeting rule — a 210-day gap that does not line up with quarterly board...

Vikas Sharma Tax & Compliance Expert
5 min read 24 views Updated Sep 20, 2026 Expert Reviewed High Complexity
Regulation 21: Risk Management Committee
0:00
Last updated: September 2026Verified against: Government sources
Quick Answer

The Risk Management Committee is the newest of the mandatory committees and the one with the most awkward meeting rule — a 210-day gap that does not line up with quarterly board cycles, and therefore gets breached by companies that are otherwise meeting diligently.

The Risk Management Committee is the newest of the mandatory committees and the one with the most awkward meeting rule — a 210-day gap that does not line up with quarterly board cycles, and therefore gets breached by companies that are otherwise meeting diligently.

Who it applies to, and who is in it

RequirementPosition
ApplicabilityTop 1000 listed entities by market capitalisation as at the end of the previous financial year
Minimum membersThree
Board majorityA majority of members must be members of the board of directors
IndependenceAt least one independent director
SR equity share entitiesAt least two-thirds of the committee must be independent directors
ChairpersonA member of the board
MeetingsAt least twice a year, gap not more than 210 days
QuorumTwo members or one-third, whichever is higher, including at least one board member

The majority of board members requirement is the point that distinguishes this committee from the others: senior management may sit on it — and often should, because the chief risk officer and the head of technology are where the substance is — but they cannot outnumber the directors.

Why 210 days trips companies up

Two meetings a year sounds undemanding. The gap is what binds.

A committee that meets in May and then in December has met twice, and has a gap of roughly 214 days. It has breached the regulation while satisfying the meeting count.

The practical fix is to attach the RMC meetings to specific quarters — typically alongside the first and third quarter board meetings — rather than scheduling them as and when there is something to discuss. Risk agendas are elastic; the calendar is not.

Its mandate

Formulating a risk management policy. The policy must identify the internal and external risks faced by the entity — specifically including financial, operational, sectoral, sustainability (particularly ESG-related), information and cyber security risks, or any other risk the committee determines. It sets out the measures for risk mitigation, including systems and processes for internal control, and includes a business continuity plan.

Monitoring and evaluating the risk management systems of the entity.

Periodically reviewing the policy — at least once every two years, taking into account changing industry dynamics and the evolving complexity of the business.

Keeping the board informed about the nature and content of its discussions, recommendations and actions.

Appointment, removal and terms of remuneration of the chief risk officer, where such a role exists — subject to the board's review.

Where the RMC overlaps with the audit committee

The two committees look at adjacent things and the boundary is worth setting deliberately, because an item that neither committee owns is the item that gets missed.

The audit committee evaluates internal financial controls and risk management systems as part of its own mandate, from the perspective of financial reporting reliability. Audit committee →

The RMC owns the enterprise risk framework — including risks with no direct financial statement line, such as cyber, sustainability and business continuity.

The workable division is that the audit committee asks whether controls over reporting are effective, and the RMC asks whether the business has identified and is managing the risks that could damage it. Companies that leave the split undocumented usually find that cyber risk is discussed twice and business continuity not at all.

Where its output surfaces

The board's report carries a statement on the development and implementation of a risk management policy, including the elements of risk the board considers may threaten the existence of the company.

The BRSR, where applicable, requires disclosure of the entity's approach to identifying and managing ESG risks — which is the same material the RMC's policy is meant to address. Two documents drawing on one framework is the intended design; two documents describing different frameworks is a finding. The annual report and BRSR →

Key takeaways

  • Top 1000 by market capitalisation — check your rank each year.
  • A majority of the committee must be directors, though management may serve.
  • At least one independent director; two-thirds for entities with SR equity shares.
  • Twice a year and no more than 210 days apart — the gap, not the count, is what binds.
  • Cyber and ESG risk are named in the policy requirement, not optional additions.
  • Review the policy at least once in two years.
  • Set the boundary with the audit committee in writing.

Read next

Disclaimer: Positions stated as on 5 September 2026. Applicability is keyed to market capitalisation rank and has been widened more than once — verify the current position on sebi.gov.in before relying on it.

Key Facts About Regulation 21

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Which companies must constitute a Risk Management Committee?

The top 1000 listed entities by market capitalisation as at the end of the previous financial year.

What is the composition of the Risk Management Committee?

At least three members, with a majority being members of the board of directors, including at least one independent director, and chaired by a member of the board.

Over 90% of compliance penalties in India arise from missed due dates — timely handling can save businesses thousands of rupees each year.

— TaxClue Compliance Desk

Regulation 21: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Frequently Asked Questions
Which companies must constitute a Risk Management Committee?
The top 1000 listed entities by market capitalisation as at the end of the previous financial year.
What is the composition of the Risk Management Committee?
At least three members, with a majority being members of the board of directors, including at least one independent director, and chaired by a member of the board.
How many Risk Management Committee meetings are required?
At least two in a year, with a gap of not more than 210 days between two consecutive meetings.
Can senior management be on the Risk Management Committee?
Yes, but they cannot form a majority — a majority of members must be members of the board.
Does the risk management policy have to cover cyber security?
Yes. The policy must identify internal and external risks specifically including financial, operational, sectoral, sustainability including ESG-related, information and cyber security risks.
How often must the risk management policy be reviewed?
At least once every two years, taking into account changing industry dynamics and the evolving complexity of the business.

Was this article helpful?

Thank you for your feedback!
VS
Vikas Sharma VERIFIED EXPERT
7431 articles
Tax & Compliance Expert
Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.
Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

Related Guides

All guides →