Skip to content

Risk Committee

What is Risk Committee?

A committee of the board of directors responsible for overseeing the organisation's risk management framework, policies, and risk appetite. Risk committees are required or recommended by banking regulations and corporate governance codes.

Governance

Each of these is named in at least one of the same controls as risk committee. The number is how many controls name both.

What the standards actually require on risk committee

Requirements naming risk committee across 6 standards, quoted from the control text.

The Chief Risk Officer must report directly to the Chief Executive Officer and must have regular and unfettered access to the Board and the Board Risk Committee.

CPS220-P40 · Chief Risk Officer Reporting Lines and Board Access
HKMA TM-G-13 controls

HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure;

HKMA-TMG1-Governance-Board-Framework-Roles · TM-G-1 Governance - Board + Senior Mgmt Oversight + Technology Risk Management Framework + Roles

HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training;

HKMA-CRAF-Domain1-2-Governance-Identification · HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment

Implement governance + ISMS + risk + HR + lifecycle per MTCS SS 584 covering Information Security Management System (ISO/IEC 27001 alignment) + Risk Management (ISO 31000 + ISO/IEC 27005) + Human Resource Security (employment screening + training + termination...

MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities · MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles

Risk posture is continuously monitored and reported to management, board, and risk committees through KRIs and dashboards.

IS-III.C.1 · Risk Monitoring and Reporting

Questions people ask about risk committee

What is Risk Committee?
A committee of the board of directors responsible for overseeing the organisation's risk management framework, policies, and risk appetite. Risk committees are required or recommended by banking regulations and corporate governance codes.
Why is Risk Committee important for compliance?
Risk Committee is a key concept in Governance. Understanding risk committee helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Committee?
Risk Committee appears in the requirement text of APRA CPS 220 Risk Management, HKMA TM-G-1, IRM Enterprise Risk Management Framework (Institute of Risk Management), HKMA Cyber Resilience Assessment Framework (C-RAF), MTCS (Singapore). Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Committee?
Explore our compliance framework pages to see how risk committee applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Committee applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.