Corporate Governance & Board Advisory · Governance & Risk Architecture Design

Enterprise Risk Governance Framework.

Risk oversight is a board function, not a register — and the difference shows the first time a known risk becomes a loss.

A promoter-led board that has approved a risk register discovers, after a loss, that the risk was on the register the whole time — identified, recorded, and never owned, escalated, or governed. The register existed; the oversight did not. This is the gap between documenting risk and governing it.

Enterprise risk governance is the part of the Operating System through which risk reaches the board early enough to be a decision rather than a post-mortem. It defines what the company is willing to bear, who owns each exposure, and how risk moves up to the board before it crystallises.

The Framework

How We Frame Risk as a Board Function.

The firm does not treat risk governance as a register to be maintained. Under Section 134(3)(n) of the Companies Act 2013 the board must report on the company’s risk management policy, and for the prescribed class of listed entities the SEBI LODR framework requires a Risk Management Committee — but the obligation is for a working oversight system, not a catalogue of named risks.

We frame the domain around four questions: what risk the company is willing to carry, who owns each exposure, how it is reported, and when it must reach the board. A risk that is identified but unowned and unescalated is not governed; it is merely recorded. The design objective is movement — risk that travels to the right decision-maker in time to be acted on.

  • Risk appetite The board’s explicit statement of what exposure the company will and will not carry, against which every risk decision is measured.
  • Ownership model Who owns each material risk in the business, so that an exposure has an accountable holder rather than sitting unattended on a register.
  • Reporting discipline The cadence and content through which the board receives a true risk position rather than a reassurance.
  • Escalation path The thresholds at which a risk must rise to the board early enough to be governed instead of reported after the event.
The Analysis

Where Risk Governance Begins and How It Holds.

Risk oversight is only as good as the discipline beneath it — the obligations the company already carries and must track before it can govern anything more sophisticated. The foundation most boards underestimate is set out below.

01

Post-Incorporation Compliance Calendar Setup

Before a board can govern strategic risk, it has to be confident it is not quietly accumulating regulatory risk — and that confidence rests on a compliance calendar few companies treat as a governance instrument. From incorporation, a company carries recurring obligations under the Companies Act 2013: board and general-meeting cadence, annual filings such as the financial statements and annual return, event-based filings on changes in capital or directors, and the maintenance of statutory registers. Each missed obligation is a default that attaches to the company and, in many cases, to its officers.

The compliance calendar is the mechanism that converts those obligations into a tracked, owned, board-visible position. The structural question is not whether a calendar exists but whether the board receives a true compliance status from it — what is due, what is owned, what has slipped — rather than an assurance that all is in order. The calendar is the raw signal; how that signal is consolidated and surfaced to the board is the work of a board-level compliance dashboard and reporting framework, which turns a tracking list into governed oversight.

For a multi-entity group the calendar becomes the only way a single board holds a consolidated view of obligations discharged entity by entity, each on its own clock. Designed as the base layer of the risk framework, it feeds the board the early, factual signal — a default is the most predictable risk a company carries, and the cheapest to govern out before it crystallises into penalty or personal exposure.

Structural Implications

What Risk Governance Sets in Motion.

A working risk framework is felt across the board’s wider oversight responsibilities.

01

Director Protection

A board that demonstrably identified, owned, and escalated a risk has discharged its oversight duty — the absence of that trail is what converts a loss into a question of director failure.

02

Investor Assurance

Institutional capital and lenders price the risk system a board can evidence, not the register it can produce, and weak oversight surfaces in diligence as a discount.

03

Decision Quality

Risk that reaches the board against a stated appetite, in time, turns oversight into a strategic input rather than a retrospective explanation.