BUSINESS NEWS3 MIN READ

Why boards are considering a chief risk officer earlier.

Listed-company rules already push risk oversight to the board. For growth-stage companies, a risk lead before an IPO is a choice, not a mandate. What the rules require, and how a board can judge the timing.

Spectate Media cover: risk radar sweeping over detected points
SHARE

The chief risk officer, or CRO, has long been a fixture in banks and large listed groups. A pre-IPO habit of appointing one is now discussed as something growth-stage boards might do earlier, well before an IPO is on the calendar. We could not find published, measured data showing how many Indian boards have moved the appointment forward, so this piece treats it as a pattern to test, not a statistic.

What can be checked is the rulebook, and the questions it raises for a board deciding when a dedicated risk role earns its cost.

What the rules actually require

For listed companies, Regulation 21 of the SEBI LODR Regulations requires a Risk Management Committee for the top 1,000 listed entities by market capitalisation, and for high-value debt listed entities. SEBI's 2021 proposal extended the requirement from the top 500 to the top 1,000. As of September 2026, confirm the current applicability and any later amendment.

Per the regulation as summarised in current sources:

  • The committee has at least three members, a majority of them directors, with at least one independent director.
  • Its chairperson is a director.
  • It meets so that no more than 180 days pass between two meetings.
  • The appointment, removal and remuneration of the CRO, "if any", is subject to the committee's review.

The words "if any" matter. LODR does not require a listed company outside the regulated sectors to have a CRO. It requires board-level oversight of risk, and it assumes a CRO may exist.

The Companies Act 2013 adds general duties. Section 134(3)(n) requires the board's report to include a statement on developing and implementing a risk management policy. Section 177(4)(vii) has the audit committee evaluate internal financial controls and risk management systems. Schedule IV asks independent directors to satisfy themselves that risk management systems are robust and defensible. A 2022 Company Law Committee report recommended a separate risk committee for prescribed classes of companies, but we found no confirmation that this was legislated. Verify before relying on it.

Regulated financial entities such as banks and NBFCs have sector rules of their own, set by the RBI. We did not verify those, and they are outside this piece.

Why an earlier appointment is discussed

The reasoning is a matter of judgement, not evidence, and boards will weigh it differently.

  • Diligence readiness. Investors and, later, merchant bankers ask how risks are identified, owned and reported. A function that already produces a risk register and board reporting answers that without a scramble.
  • Control gaps show up late. Weak related-party processes, revenue recognition judgements and concentration in customers or suppliers are cheaper to fix before an offer document has to describe them.
  • Committee readiness. A company that lists must already run a risk committee that meets at least every six months and reviews risk policy. Having the first two cycles behind it is easier than starting cold.

Against that, a full-time CRO is a real cost for a company with a few hundred crore of revenue. Some boards use a senior finance or compliance executive with a formal risk mandate, or an outsourced internal audit firm, as a first step.

How a board can judge the timing

Some signs that risk may have outgrown the CFO's spare hours can show up in the board pack.

  1. Risks are discussed only when something goes wrong.
  2. No one owns a single risk register that the board sees at least twice a year.
  3. Material exposures, such as credit, currency, cyber, regulatory or key-person, are tracked in different places.
  4. An IPO, a large debt raise or a cross-border acquisition is likely within two to three years.

What to do with this

These are considerations, not advice.

  • Start with the mandate, not the title. Decide what the role should own: the register, reporting to the board, scenario work, or all three.
  • Decide the reporting line. One design to consider is reporting to the CEO with direct access to the board or its risk or audit committee. Independence from the functions being assessed matters more than the label.
  • Consider a shadow committee. A board-level risk discussion on a set calendar, even before it is compulsory, builds the record.
  • Check what applies to you. Listed status, sector regulator, debt structure and market capitalisation determine what is mandatory.
  • Revisit annually. The right answer at Rs 200 crore of revenue may not be the right one at Rs 1,000 crore.

Nothing here is legal or investment advice, and the facts of each company differ.

This article is journalism and commentary. It is not a recommendation to buy or sell any security, and it is not professional advice. Read the full disclaimer.

THE WEEKLY BRIEF

What moved this week, and what it means for your board.

One email every Friday. Unsubscribe in one click.