THE BOARD RISK COMMITTEE: GOOD GOVERNANCE FOR VOLATILE TIMES
Corporate boards bear joint responsibility for their assigned governance tasks, including the oversight and assessment of the corporation’s risk management process. When we refer to boards, we mean one-tier boards of listed companies, where non-executive directors sit together with the executives, and supervisory boards in a two-tier system, composed of non-executive directors only. In the latter system, the executives are organised in a separate management structure, usually referred to as the executive committee or executive board.
Most jurisdictions, including the US and the UK, have opted for a one-tier board system, whereas the two-tier board system is mandatory, for example, in Germany and Austria. Most boards have established committees to prepare decisions for the full board or, to the extent legally permissible, to delegate certain board tasks and decisions. Corporations frequently establish nomination and compensation committees. Some have combined or standalone strategy and sustainability committees, and we are observing an increasing number of technology committees, given the rise of artificial intelligence (AI) and its impact on companies’ resources and business models.
The one committee that is not discretionary for boards, however, is the audit committee. Ever since the Sarbanes-Oxley Act of 2002 was enacted, most jurisdictions have joined the US in making audit committees mandatory. The non-exhaustive list of topics to which the audit committee must devote attention is demanding. It includes oversight of the corporation’s financial reporting and disclosures, the appointment of and interaction with the external auditor, the performance and reporting of the internal audit function, the assessment of internal controls, and ongoing dialogue with management on key accounting policies and principles.
