Ask Veda

TaxClue AI · Active
Namaste! I'm Veda — TaxClue's AI compliance assistant. 🙏

Ask me anything about GST, ITR, Company registration, Trademark, FSSAI or any compliance topic. When you're ready, I'll connect you with our expert for a callback.
Share your details — our expert will call you
Powered by TaxClue · India's Trusted Compliance Platform

The Risk Management Committee

The newest of the mandatory committees, and the one whose remit has expanded fastest. When SEBI first required it, "risk" mostly meant credit, currency and commodity exposure...

Vikas Sharma Tax & Compliance Expert
6 min read 8 views Updated Sep 12, 2026 Expert Reviewed High Complexity
The Risk Management Committee
0:00
Last updated: September 2026Verified against: Government sources
Quick Answer

The newest of the mandatory committees, and the one whose remit has expanded fastest. When SEBI first required it, "risk" mostly meant credit, currency and commodity exposure. Today the regulation names cyber security explicitly and Schedule II names ESG — two categories that didn't feature on mo…

Need help with Company Law?Talk to a qualified CA / CS about your exact case — no obligation.
Talk to an Expert →

The newest of the mandatory committees, and the one whose remit has expanded fastest. When SEBI first required it, "risk" mostly meant credit, currency and commodity exposure. Today the regulation names cyber security explicitly and Schedule II names ESG — two categories that didn't feature on most Indian board agendas five years ago.

For an independent director, this is the committee where the questions are hardest to fake.

Who must have one

Regulation 21 applies to the top 1,000 listed entities, determined by market capitalisation as at the end of the immediately preceding financial year. It also applies to a listed entity with outstanding superior voting rights (SR) equity shares.

The category is recomputed annually. An entity that enters the top 1,000 has to constitute the committee; one that leaves it doesn't automatically dissolve it, and most don't.

The Companies Act has no equivalent committee requirement. What it does have is Section 134(3)(n), requiring the Board's report to include a statement on the development and implementation of a risk management policy, identifying elements of risk that may threaten the company's existence. So an unlisted company still needs a policy — it just doesn't need a committee to own it.

Composition and meetings

RequirementPosition
Minimum membersThree, with a majority being members of the board
Independent directorsAt least one. For entities with outstanding SR equity shares, two-thirds must be independent
ChairpersonMust be a member of the board of directors
Senior executivesMay be members — the CRO, CFO, CISO and heads of business
MeetingsAt least twice a year
Gap between meetingsNot more than 180 days on a continuous basis
QuorumTwo members or one-third of the members, whichever is higher, including at least one board member

The composition is deliberately hybrid. Unlike the audit committee and the NRC — which are director-only bodies — the RMC is designed to put executives who actually run risk systems in the same room as directors who oversee them. A risk committee without the chief information security officer present is discussing cyber risk secondhand.

The 180-day rule is the constraint that matters operationally. Two meetings a year satisfies the count, but if you hold them in April and December you've breached the gap. Space them.

What the policy must cover

Schedule II requires the committee to formulate a detailed risk management policy covering:

  • a framework for identifying internal and external risks, specifically including financial, operational, sectoral, sustainability (particularly ESG-related), information and cyber security risks;
  • measures for risk mitigation, including systems and processes for internal control; and
  • a business continuity plan.

Beyond the policy, the committee must:

  • ensure appropriate methodology, processes and systems are in place to monitor and evaluate risks;
  • monitor and oversee implementation of the policy, including evaluating the adequacy of risk management systems;
  • review the policy periodically — at least once every two years — taking into account changing industry dynamics and evolving complexity;
  • keep the board informed about the nature and content of its discussions, recommendations and actions.

And one governance safeguard worth knowing: the appointment, removal and terms of remuneration of the Chief Risk Officer, where the entity has one, are subject to review by the RMC. That's the same structural protection the audit committee gives the internal auditor — the person whose job is to find problems shouldn't be employed entirely at the discretion of the people whose problems they find.

RMC or audit committee?

The remits overlap and boards handle the boundary badly.

The audit committee evaluates internal financial controls and risk management systems under Section 177(4). Its lens is assurance: are the controls designed and operating effectively, and does the financial reporting reflect reality?

The RMC owns the risk framework itself. Its lens is forward-looking: what could damage this business, how likely is it, what are we doing about it, and can we keep operating if it happens?

A workable split: the RMC decides what the risks are and what we're doing; the audit committee tests whether the controls we claim to have actually work. Where the same independent director sits on both — common, and sensible — they should be conscious of which hat they're wearing, because the questions are genuinely different.

Questions worth asking

  • When did the risk register last change materially? A register that looks the same year after year isn't being used.
  • What are the top five risks, and who owns each one by name?
  • What's our cyber incident history — including the ones that didn't become public?
  • When was the business continuity plan last tested, not just written?
  • What ESG risks are financially material to us, as opposed to reputationally interesting?
  • Does the CRO have a reporting line that doesn't run entirely through the CEO?
  • What did we decide to accept rather than mitigate, and why?

The last one is the most revealing. Every risk framework involves accepted risk. A committee that has never explicitly accepted a risk isn't making decisions — it's receiving presentations.

Key takeaways

  • Top 1,000 listed entities by market capitalisation, recomputed annually.
  • Three members minimum, board majority, at least one independent director, board-member chairperson.
  • Senior executives may be members — the design intends it.
  • Twice a year, and no more than 180 days apart.
  • Policy must cover financial, operational, sectoral, ESG, information and cyber security risks, plus business continuity.
  • Policy reviewed at least once every two years.
  • The CRO's appointment, removal and remuneration are subject to RMC review.
  • Unlisted companies still need a risk management policy under Section 134(3)(n) — just not a committee.

Read next

Law stated as on 5 September 2026. Market-capitalisation categories are recomputed each year — confirm your entity's current position before assuming the regulation does or doesn't apply.

Key Facts About Risk Management Committee

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Which companies need a risk management committee?

The top 1,000 listed entities by market capitalisation, and listed entities with outstanding SR equity shares.

Can senior executives be members?

Yes. A majority must be board members, but executives may sit on the committee — and generally should.

Over 90% of compliance penalties in India arise from missed due dates — timely handling can save businesses thousands of rupees each year.

— TaxClue Compliance Desk

Risk Management Committee: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Need Help with Compliance?

Our CA experts guide you through the entire process — registration to filing.

Frequently Asked Questions
Which companies need a risk management committee?
The top 1,000 listed entities by market capitalisation, and listed entities with outstanding SR equity shares.
Can senior executives be members?
Yes. A majority must be board members, but executives may sit on the committee — and generally should.
How many independent directors are required?
At least one. Two-thirds where the entity has outstanding SR equity shares.
How often must it meet?
At least twice a year, with no more than 180 days between consecutive meetings.
What's the quorum?
Two members or one-third of the members, whichever is higher, including at least one board member.
Does the policy have to cover cyber security?
Yes. Regulation 21 names cyber security specifically, and Schedule II adds ESG and information risk.
Do unlisted companies need one?
No committee is required, but Section 134(3)(n) requires a risk management policy and a statement about it in the Board's report.
Let TaxClue handle your Company LawFrom documentation to government filing — get it done right the first time.
Get Started →

Was this article helpful?

Thank you for your feedback!
Need help with Company Law?
  • Pvt Ltd Registration
  • LLP Registration
  • OPC Registration
VS
Vikas Sharma VERIFIED EXPERT
7431 articles
Tax & Compliance Expert
Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.
Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

Related Guides

All guides →
Get Expert Help

Need help with your Company Law?

Our CA & CS professionals handle everything — from registration and filing to ongoing compliance. Talk to an expert about your exact case, no obligation.

4.9★ Google · CA & CS verified · ₹0 hidden charges · Confidential