Skip to Content
Home / Services / Audit & Assurance / Risk Advisory & Risk Management
Audit & Assurance

Risk Advisory & Risk Management

Identifying business risks and structuring frameworks to strengthen governance.

Overview

Every business faces financial, operational, compliance and strategic risks. Risk management is a structured way to identify these risks, assess their likelihood and impact, and put controls and responses in place.

The Companies Act, 2013 requires the board's report to include a statement on the development and implementation of a risk management policy, and larger listed entities must have a risk management committee.

Who needs this service

Companies setting up or updating a risk management framework
Businesses preparing for investment, listing or rapid growth
Listed entities covered by the risk management committee requirement
Boards and audit committees

Legal and regulatory framework

  • Companies Act, 2013: Section 134(3)(n) and Section 177(4)
  • SEBI (LODR) Regulations, 2015: Regulation 21 (top 1,000 listed entities)
  • ISO 31000 and COSO frameworks as reference

Scope of services

Risk Identification

  • Enterprise risk workshops with management
  • Risk registers by function
  • Fraud risk assessment

Controls

  • Risk and control matrices for key processes
  • Policies and SOPs
  • Delegation of authority frameworks

Monitoring

  • Key risk indicators
  • Periodic risk reports for the board

How the engagement works

  1. UnderstandBusiness model, objectives and existing controls.
  2. Identify and assessRisks rated by likelihood and impact.
  3. RespondControls, policies and owners for each key risk.
  4. MonitorReporting formats and periodic reviews.

Documents typically required

Organisation structure and policiesPast audit and incident reportsBusiness plans and budgets

Key forms and due dates

ItemTimeline
Board's reportAnnually, with the financial statements

Indicative; subject to amendments and extensions notified by the authorities.

Deliverables

The scope of each engagement is agreed in writing and depends on the nature, size and regulatory requirements of the entity.

Frequently asked questions

Is a risk management policy mandatory?

The board's report of every company must state how the risk management policy is developed and implemented. A formal committee is mandatory for the top 1,000 listed entities.

How often should risks be reviewed?

At least annually, and whenever the business changes significantly.

This page is for general information only and does not constitute professional advice or solicitation.