Risk Committee
What is Risk Committee?
A committee of the board of directors responsible for overseeing the organisation's risk management framework, policies, and risk appetite. Risk committees are required or recommended by banking regulations and corporate governance codes.
Terms that appear alongside risk committee
Each of these is named in at least one of the same controls as risk committee. The number is how many controls name both.
- governance 14 shared controls
- audit 13 shared controls
- risk appetite 10 shared controls
- ciso 9 shared controls
- risk assessment 9 shared controls
- board risk committee 9 shared controls
- security officer 8 shared controls
- information security 8 shared controls
Frameworks that govern risk committee
What the standards actually require on risk committee
Requirements naming risk committee across 6 standards, quoted from the control text.
The Chief Risk Officer must report directly to the Chief Executive Officer and must have regular and unfettered access to the Board and the Board Risk Committee.
CPS220-P40 · Chief Risk Officer Reporting Lines and Board Access →HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure;
HKMA-TMG1-Governance-Board-Framework-Roles · TM-G-1 Governance - Board + Senior Mgmt Oversight + Technology Risk Management Framework + Roles →Risk Reporting + KRIs + Performance + Horizon Scanning translate the risk management process into actionable management information.
IRM-Reporting-KRIs-Performance-HorizonScanning-Dashboard-Heatmap-RiskRegister-EmergingRisk · IRM Risk Reporting + Key Risk Indicators (KRIs) + Performance Measurement + Horizon Scanning + Dashboard + Heat Map + Risk Register + Emerging Risk Identification →HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training;
HKMA-CRAF-Domain1-2-Governance-Identification · HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment →Implement governance + ISMS + risk + HR + lifecycle per MTCS SS 584 covering Information Security Management System (ISO/IEC 27001 alignment) + Risk Management (ISO 31000 + ISO/IEC 27005) + Human Resource Security (employment screening + training + termination...
MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities · MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles →Risk posture is continuously monitored and reported to management, board, and risk committees through KRIs and dashboards.
IS-III.C.1 · Risk Monitoring and Reporting →Questions people ask about risk committee
What is Risk Committee?
Why is Risk Committee important for compliance?
Which compliance frameworks address Risk Committee?
Where can I learn more about Risk Committee?
See how Risk Committee applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.