Next dueCompany / ROC
14 OCTADT-1 · Auditor appointment (after AGM)in 7 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 23 days 31 OCTMSME-1 · Dues to MSMEs · Apr–Sep 2026in 24 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 45 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 53 days 30 JUNDPT-3 · Return of deposits · FY 2026-27in 266 days 7 OCTTDS / TCS deposit · Deducted in Sep 2026due today 11 OCTGSTR-1 · Outward supplies · Sep 2026in 4 days
All due dates

The Risk Management Committee

The newest of the mandatory committees, and the one whose remit has expanded fastest. When SEBI first required it, "risk" mostly meant credit, currency and commodity exposure...

Published
Updated
Reading time
6 min
Views
26
Questions
7 answered
  • Expert Reviewed
  • High Complexity
Topic
Company Law
Published
September 5, 2026
Last updated
Oct 6, 2026
Reading time
6 min
0:00
Last updated: October 2026Verified against: Government sources

The newest of the mandatory committees, and the one whose remit has expanded fastest. When SEBI first required it, "risk" mostly meant credit, currency and commodity exposure. Today the regulation names cyber security explicitly and Schedule II names ESG — two categories that didn't feature on most Indian board agendas five years ago.

For an independent director, this is the committee where the questions are hardest to fake.

Who must have one

Regulation 21 applies to the top 1,000 listed entities, determined by market capitalisation as at the end of the immediately preceding financial year. It also applies to a listed entity with outstanding superior voting rights (SR) equity shares.

The category is recomputed annually. An entity that enters the top 1,000 has to constitute the committee; one that leaves it doesn't automatically dissolve it, and most don't.

The Companies Act has no equivalent committee requirement. What it does have is Section 134(3)(n), requiring the Board's report to include a statement on the development and implementation of a risk management policy, identifying elements of risk that may threaten the company's existence. So an unlisted company still needs a policy — it just doesn't need a committee to own it.

Composition and meetings

RequirementPosition
Minimum membersThree, with a majority being members of the board
Independent directorsAt least one. For entities with outstanding SR equity shares, two-thirds must be independent
ChairpersonMust be a member of the board of directors
Senior executivesMay be members — the CRO, CFO, CISO and heads of business
MeetingsAt least twice a year
Gap between meetingsNot more than 180 days on a continuous basis
QuorumTwo members or one-third of the members, whichever is higher, including at least one board member

The composition is deliberately hybrid. Unlike the audit committee and the NRC — which are director-only bodies — the RMC is designed to put executives who actually run risk systems in the same room as directors who oversee them. A risk committee without the chief information security officer present is discussing cyber risk secondhand.

The 180-day rule is the constraint that matters operationally. Two meetings a year satisfies the count, but if you hold them in April and December you've breached the gap. Space them.

What the policy must cover

Schedule II requires the committee to formulate a detailed risk management policy covering:

  • a framework for identifying internal and external risks, specifically including financial, operational, sectoral, sustainability (particularly ESG-related), information and cyber security risks;
  • measures for risk mitigation, including systems and processes for internal control; and
  • a business continuity plan.

Beyond the policy, the committee must:

  • ensure appropriate methodology, processes and systems are in place to monitor and evaluate risks;
  • monitor and oversee implementation of the policy, including evaluating the adequacy of risk management systems;
  • review the policy periodically — at least once every two years — taking into account changing industry dynamics and evolving complexity;
  • keep the board informed about the nature and content of its discussions, recommendations and actions.

And one governance safeguard worth knowing: the appointment, removal and terms of remuneration of the Chief Risk Officer, where the entity has one, are subject to review by the RMC. That's the same structural protection the audit committee gives the internal auditor — the person whose job is to find problems shouldn't be employed entirely at the discretion of the people whose problems they find.

RMC or audit committee?

The remits overlap and boards handle the boundary badly.

The audit committee evaluates internal financial controls and risk management systems under Section 177(4). Its lens is assurance: are the controls designed and operating effectively, and does the financial reporting reflect reality?

The RMC owns the risk framework itself. Its lens is forward-looking: what could damage this business, how likely is it, what are we doing about it, and can we keep operating if it happens?

A workable split: the RMC decides what the risks are and what we're doing; the audit committee tests whether the controls we claim to have actually work. Where the same independent director sits on both — common, and sensible — they should be conscious of which hat they're wearing, because the questions are genuinely different.

Questions worth asking

  • When did the risk register last change materially? A register that looks the same year after year isn't being used.
  • What are the top five risks, and who owns each one by name?
  • What's our cyber incident history — including the ones that didn't become public?
  • When was the business continuity plan last tested, not just written?
  • What ESG risks are financially material to us, as opposed to reputationally interesting?
  • Does the CRO have a reporting line that doesn't run entirely through the CEO?
  • What did we decide to accept rather than mitigate, and why?

The last one is the most revealing. Every risk framework involves accepted risk. A committee that has never explicitly accepted a risk isn't making decisions — it's receiving presentations.

Key takeaways

  • Top 1,000 listed entities by market capitalisation, recomputed annually.
  • Three members minimum, board majority, at least one independent director, board-member chairperson.
  • Senior executives may be members — the design intends it.
  • Twice a year, and no more than 180 days apart.
  • Policy must cover financial, operational, sectoral, ESG, information and cyber security risks, plus business continuity.
  • Policy reviewed at least once every two years.
  • The CRO's appointment, removal and remuneration are subject to RMC review.
  • Unlisted companies still need a risk management policy under Section 134(3)(n) — just not a committee.

Read next

Law stated as on 5 September 2026. Market-capitalisation categories are recomputed each year — confirm your entity's current position before assuming the regulation does or doesn't apply.

Quick recapKey facts & short answers

Key Facts About Risk Management Committee

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Which companies need a risk management committee?

The top 1,000 listed entities by market capitalisation, and listed entities with outstanding SR equity shares.

Can senior executives be members?

Yes. A majority must be board members, but executives may sit on the committee — and generally should.

Keep your director KYC current; one lapsed DIN can hold up a whole board's filing.

— TaxClue Corporate Law Desk

Risk Management Committee: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 7 questions readers ask most on this topic.

The top 1,000 listed entities by market capitalisation, and listed entities with outstanding SR equity shares.

Yes. A majority must be board members, but executives may sit on the committee — and generally should.

At least one. Two-thirds where the entity has outstanding SR equity shares.

At least twice a year, with no more than 180 days between consecutive meetings.

Two members or one-third of the members, whichever is higher, including at least one board member.

Yes. Regulation 21 names cyber security specifically, and Schedule II adds ESG and information risk.

No committee is required, but Section 134(3)(n) requires a risk management policy and a statement about it in the Board's report.