Overview
Every business faces financial, operational, compliance and strategic risks. Risk management is a structured way to identify these risks, assess their likelihood and impact, and put controls and responses in place.
The Companies Act, 2013 requires the board's report to include a statement on the development and implementation of a risk management policy, and larger listed entities must have a risk management committee.
Who needs this service
Legal and regulatory framework
- Companies Act, 2013: Section 134(3)(n) and Section 177(4)
- SEBI (LODR) Regulations, 2015: Regulation 21 (top 1,000 listed entities)
- ISO 31000 and COSO frameworks as reference
Scope of services
Risk Identification
- Enterprise risk workshops with management
- Risk registers by function
- Fraud risk assessment
Controls
- Risk and control matrices for key processes
- Policies and SOPs
- Delegation of authority frameworks
Monitoring
- Key risk indicators
- Periodic risk reports for the board
How the engagement works
- UnderstandBusiness model, objectives and existing controls.
- Identify and assessRisks rated by likelihood and impact.
- RespondControls, policies and owners for each key risk.
- MonitorReporting formats and periodic reviews.
Documents typically required
Key forms and due dates
| Item | Timeline |
|---|---|
| Board's report | Annually, with the financial statements |
Deliverables
- Risk register
- Risk management policy
- Risk and control matrices
- Board reporting template
The scope of each engagement is agreed in writing and depends on the nature, size and regulatory requirements of the entity.
Frequently asked questions
Is a risk management policy mandatory?
The board's report of every company must state how the risk management policy is developed and implemented. A formal committee is mandatory for the top 1,000 listed entities.
How often should risks be reviewed?
At least annually, and whenever the business changes significantly.