THE BOARD RISK COMMITTEE: GOOD GOVERNANCE FOR VOLATILE TIMES
BY KLAUS MOOSMAYER
Corporate boards bear joint responsibility for their assigned governance tasks, including the oversight and assessment of the corporation’s risk management process. When we refer to boards, we mean one-tier boards of listed companies, where non-executive directors sit together with the executives, and supervisory boards in a two-tier system, composed of non-executive directors only. In the latter system, the executives are organised in a separate management structure, usually referred to as the executive committee or executive board.
Most jurisdictions, including the US and the UK, have opted for a one-tier board system, whereas the two-tier board system is mandatory, for example, in Germany and Austria. Most boards have established committees to prepare decisions for the full board or, to the extent legally permissible, to delegate certain board tasks and decisions. Corporations frequently establish nomination and compensation committees. Some have combined or standalone strategy and sustainability committees, and we are observing an increasing number of technology committees, given the rise of artificial intelligence (AI) and its impact on companies’ resources and business models.
The one committee that is not discretionary for boards, however, is the audit committee. Ever since the Sarbanes-Oxley Act of 2002 was enacted, most jurisdictions have joined the US in making audit committees mandatory. The non-exhaustive list of topics to which the audit committee must devote attention is demanding. It includes oversight of the corporation’s financial reporting and disclosures, the appointment of and interaction with the external auditor, the performance and reporting of the internal audit function, the assessment of internal controls, and ongoing dialogue with management on key accounting policies and principles.
Which committees, then, are supporting the full board in complying with one of its major responsibilities: overseeing and assessing the risk management process? Most corporations have simply added risk management to the tasks of their audit committees.
The board risk committee – a special animal only for financial institutions?
The situation is, however, different in the financial industry, where the major regulators took a different direction years ago. In Europe, article 76 (3) of the Capital Requirements Directive requires significant financial institutions (FIs) to establish a standalone risk committee composed of members who “have appropriate knowledge, skills and expertise to fully understand and monitor the risk strategy and the risk appetite of the institution”. In the US, article 165(h) of the Dodd-Frank Act requires large publicly traded financial firms to establish a board-level risk committee to oversee enterprise-wide risk management practices and their operations, and to review and approve the respective policies.
Risk committees of FIs must review capital and liquidity management risks, credit risks, market risks, reputational risks and model risks, as well as assess stress-test scenarios. They also need to review whether the financial products and instruments offered are in line with the institution’s business model and risk structure and fall within its defined risk appetite. Finally, they need to oversee the institution’s entire operational or non-financial, risk management framework.
The audit committee cannot take it all
Outside the financial industry, only a small minority of Fortune 500 companies have established a dedicated risk committee. These committees are often named differently, based on the risk perceived to be most prevalent in the respective industry; for example, they may be called ‘safety committees’ in the aviation industry.
Although national codes, such as the UK Corporate Governance Code, explicitly mention the possibility of establishing separate risk committees alongside the audit committee, this structure has not been adopted as common practice, also not by major and complex corporations outside the financial sector.
Is the risk committee, then, a special animal only for the financial industry? At first sight, it seems convincing to task the audit committee with oversight of enterprise risk management (ERM), as the audit committee already needs to focus on financial risks and the effectiveness of the corporation’s corresponding financial controls. However, financial risks are only one component of a holistic ERM system, which considers the full range of strategic, operational and reputational risks across all units and businesses of the company.
Times have changed, and ERM has developed significantly across all industries during the last decade. This development was first driven by the unprecedented crisis situations faced by many companies during the coronavirus pandemic. At that time, not only individual companies but entire ecosystems, including global supply chains, were affected by the impact of a risk that practically no one had on the agenda. Since the pandemic, strategic and operational risks have dominated the agenda of executive management and boards. The geopolitical disruption caused by Russia’s war against Ukraine, the drastic shift in the external policy of the US, including the introduction of tariff regimes even against allies, and the speed of technological advancements, combined with heightened cyber security risks, have forced companies to focus much more on proactive crisis and risk management and to establish business continuity plans.
Given this scenario, it is difficult to imagine how an audit committee, which is already heavily occupied with financial reporting and audit, can responsibly make space on its fully packed agenda to devote sufficient attention to non-financial risk management.
It is also a question of the personal competence and experience of the committee members. Audit committees are typically led by current or former chief financial officers (CFOs) and partners of audit and accounting firms. They certainly have significant expertise in financial risks and controls but often have no personal experience in operational crisis management, risk management or business continuity management.
Depending on the risk exposure of the respective enterprise, there are good reasons for a board, as the ultimate owner of risk management governance, to consider its structure and competencies to fulfil its duties in volatile times.
Roles and responsibilities of a risk committee
Arguments against setting up a risk committee at board level often refer to an overly complex board structure and overlaps between the various committees, which may create redundancies. These are relevant points that need to be addressed through a proper governance framework and aligned charters for the board and its committees.
The description of the roles and responsibilities of a non-FIs board risk committee should include the following: (i) assist the board in fulfilling its responsibility to ensure that the company has implemented an appropriate and effective risk management system and process; (ii) oversee the company’s financial risks in alignment and coordination with the audit committee, including the possibility of holding joint committee sessions; (iii) ensure that the necessary steps are taken by management to foster a risk culture across the company without constraining reasonable risk-taking and innovation; (iv) review, together with management and internal audit, the identification, prioritisation and management of risks, the accountabilities and roles of the functions involved in risk management, the risk portfolio, and the related mitigation actions decided by management, including progress in their implementation; and (v) inform the board periodically about the risk management system and the most significant risks, including their management and mitigation.
A risk committee can only be effective and add value if management has put in place a professional ERM organisation and leadership structure. This structure should provide input to the risk committee’s sessions and maintain regular contact with its chair. Alignment between the risk organisation, and the risk committee is necessary not only for the recurring topics to be reported, including the results of the ERM cycle assessment, the risk appetite and the status of risk mitigation. Of equal importance are joint decisions on deep dives into selected risks, based on the company’s risk ratings and external trends, such as cyber security or geopolitical risks.
The risks associated with the use of AI, together with the respective risk management process, should be a standard agenda topic. If the board has also established a technology committee, this topic should be addressed periodically in joint sessions with the risk committee.
Finally, it is helpful if the risk committee and the risk management organisation agree on a joint methodology for displaying and monitoring the company’s risk situation. A risk radar focusing on strategic and operational risks, with the four amplifiers of geopolitics, technological acceleration, climate and societal change, has proven to be a useful systematic approach for capturing the evolving risk situation. It can serve as a good starting point for every presentation and discussion in the risk committee.
Outlook
In an era of constant change and disruption, a professionally equipped and supported risk committee can be a powerful driver of good governance. Boards should honestly consider whether the audit committee has sufficient time and expertise to support them adequately in one of their most important governance tasks: steering the company through volatile times with the help of proper risk management. There is much to learn from the financial industry about how different committees can work well together without duplicating efforts.
It is evident that the establishment of additional risk committees requires new expertise in corporate boardrooms. Alongside business leaders, CFOs, auditors and technology experts, the time has come for experienced leaders with careers in compliance and risk management to qualify as non-executive directors on corporate boards.
