Risk Committee

لجنة المخاطر

Risk Committee

Risk Management Framework, Risk Appetite, and Oversight Reports

جدول المحتويات

First: Introduction

In an increasingly complex and uncertain world, the ability to manage risks has become as important as the ability to seize opportunities. Companies that succeed in the long term are not those that avoid risks but those that understand them, assess them carefully, and make conscious decisions about them. The risk committee is the body that brings this discipline to the highest level of corporate governance — translating strategic risk thinking into operational reality.

In the Saudi system, the risk committee is mandatory in banks (under SAMA regulations) and insurance companies (under Insurance Authority regulations). For other listed companies, it may be optional or its functions merged with the audit committee. This article reviews the risk committee in depth: composition, responsibilities, the risk management framework, risk appetite, control tools, and best practices.

💡  Key Insight

The risk committee is not the bearer of risks — that’s management’s job. The committee is the overseer of how risks are managed. Its role is to ensure the company has the right framework, the right people, the right tools, and the right culture to manage risks effectively. A strong risk committee transforms risk management from reactive firefighting to proactive strategic capability.

Second: Regulatory Framework

1. Banking Sector (SAMA)

SAMA mandates risk committee in every bank with detailed requirements:

  • Composition: 3-5 non-executive members.
  • Independence: Majority independent.
  • Expertise: At least one risk specialist.
  • Meeting Frequency: At least quarterly.
  • Reporting: Directly to board, with regulatory reports.

2. Insurance Sector

Insurance Authority requires:

  • Mandatory risk committee.
  • Solvency oversight.
  • Underwriting risk monitoring.
  • Investment risk oversight.

3. CMA Corporate Governance Regulations

For non-financial listed companies:

  • Risk committee recommended for large companies.
  • May be merged with audit committee in smaller companies.
  • Board has overall risk oversight responsibility.

4. International Standards

  • Basel III: For banks.
  • Solvency II: For insurance (referenced in some jurisdictions).
  • COSO ERM Framework: Comprehensive risk management.
  • ISO 31000: International risk management standard.

Third: Committee Composition

1. Member Count

  • Typical: 3-5 members.
  • Banks may have 5-7 due to complexity.
  • Smaller companies may have 3.

2. Independence Requirements

  • Majority must be independent.
  • No executive members.
  • Independent chair preferred.

3. Required Expertise

3.1 Risk Management Expert

At least one member with:

  • Risk management experience (CRO, risk consulting).
  • Knowledge of risk frameworks (COSO, ISO).
  • Industry-specific risk expertise.
  • Quantitative analysis capability.

3.2 Sector Expertise

Members with understanding of company’s risks:

  • Banking: Credit, market, operational, liquidity.
  • Insurance: Underwriting, claims, investment.
  • Non-Financial: Industry-specific risks.

3.3 Financial Expertise

  • Understanding of financial risks.
  • Capital adequacy.
  • Stress testing comprehension.

3.4 Technology Expertise

Increasingly important:

  • Cyber risks.
  • Technology disruption risks.
  • Data and privacy risks.

Fourth: Main Committee Responsibilities

1. Risk Management Framework

The committee oversees the enterprise risk management framework:

  • Recommending the framework to the board.
  • Reviewing framework effectiveness annually.
  • Updating in line with best practices.
  • Ensuring framework integration across the enterprise.
  • Coordination with audit committee on control aspects.

2. Risk Appetite

2.1 Defining Risk Appetite

  • Working with management to define appetite.
  • Aligning appetite with strategy.
  • Defining quantitative and qualitative limits.
  • Recommending to board for approval.

2.2 Monitoring Appetite Adherence

  • Regular reports on appetite vs. actual risk.
  • Investigating breaches.
  • Recommending corrective actions.
  • Periodic appetite review and update.

3. Risk Identification and Assessment

3.1 Risk Register Oversight

  • Reviewing comprehensive risk register.
  • Ensuring all material risks identified.
  • Reviewing risk assessments (probability and impact).
  • Identifying emerging risks.
  • Updating frequency.

3.2 Key Risk Categories

Committee oversight covers:

  • Strategic risks.
  • Financial risks (market, credit, liquidity).
  • Operational risks.
  • Compliance risks.
  • Reputational risks.
  • Cyber and technology risks.
  • ESG and climate risks.

4. Risk Mitigation and Controls

  • Reviewing mitigation strategies for major risks.
  • Assessing control effectiveness.
  • Approving insurance and hedging programs.
  • Overseeing business continuity planning.

5. Stress Testing and Scenario Analysis

  • Approving stress test scenarios.
  • Reviewing results.
  • Discussing implications.
  • Approving response plans.

6. Risk Function Oversight

6.1 Chief Risk Officer (CRO)

  • Recommending appointment to board.
  • Annual performance evaluation.
  • Approving compensation.
  • Independence and reporting lines.

6.2 Risk Function Resources

  • Reviewing function staffing.
  • Approving budget.
  • Ensuring technology adequacy.
  • Training programs.

7. Crisis Management

  • Approving crisis management plans.
  • Reviewing crisis preparedness.
  • Overseeing crisis response (in real crises).
  • Post-crisis lessons learned.

8. Regulatory Liaison

  • Communicating with regulators on risk matters.
  • Reviewing regulatory reports.
  • Implementing regulatory requirements.
  • Discussing emerging regulatory expectations.
📌  Note

Risk management is everyone’s job, but oversight is the committee’s. The committee should not get drawn into operational risk management — that’s the CRO’s role. Instead, the committee should focus on whether the right framework exists, whether it’s being followed, and whether it’s producing the right outcomes.

Fifth: Enterprise Risk Management (ERM) Framework

1. COSO ERM Framework

The most globally adopted framework, with components:

  • Governance and Culture.
  • Strategy and Objective-Setting.
  • Review and Revision.
  • Information, Communication, and Reporting.

2. ISO 31000

International standard providing:

  • Risk management principles.
  • Framework guidance.
  • Process description.
  • Applicable to all organization types.

3. Three Lines of Defense

LineOwnerRole
First LineOperational managementRisk owners and daily managers
Second LineRisk and compliance functionsOversight and guidance
Third LineInternal auditIndependent assurance

4. Risk Culture

Framework alone is insufficient without culture:

  • Tone from the top.
  • Risk awareness throughout organization.
  • Open communication about risks.
  • Willingness to escalate issues.
  • Learning from mistakes.
  • Risk-adjusted incentives.

Sixth: Risk Appetite Statement

1. Components of Risk Appetite

1.1 Qualitative Statements

High-level statements such as:

  • “We have zero tolerance for regulatory violations.”
  • “We will not engage in activities that harm our reputation.”
  • “We seek moderate financial risks for sustainable growth.”

1.2 Quantitative Limits

Specific measurable limits:

  • Maximum acceptable loss in adverse scenarios.
  • Capital adequacy ratios.
  • Liquidity ratios.
  • Concentration limits.
  • Operational loss thresholds.

2. Risk Tolerance vs. Risk Appetite

  • Risk Appetite: Broader strategic preferences.
  • Risk Tolerance: Specific operational limits.
  • Both needed for complete framework.

3. Cascading Risk Appetite

Translating appetite into operational limits:

  • Board approves overall appetite.
  • Management translates to division limits.
  • Divisions cascade to departments.
  • Individual transaction limits.

Seventh: Types of Risks

1. Strategic Risks

  • Industry disruption.
  • Competitive threats.
  • Strategic execution failures.
  • Market changes.
  • Technology obsolescence.

2. Financial Risks

2.1 Market Risk

  • Interest rate risk.
  • Foreign exchange risk.
  • Commodity price risk.
  • Equity price risk.

2.2 Credit Risk

  • Counterparty default.
  • Concentration risk.
  • Country risk.
  • Settlement risk.

2.3 Liquidity Risk

  • Funding liquidity.
  • Market liquidity.
  • Contingent liquidity needs.

3. Operational Risks

  • Process failures.
  • Human errors.
  • System failures.
  • Fraud (internal and external).
  • Third-party risks.
  • Natural disasters.

4. Compliance and Regulatory Risks

  • Regulatory violations.
  • Sanctions risks.
  • Anti-money laundering.
  • Data protection.
  • Tax compliance.

5. Cyber and Technology Risks

  • Data breaches.
  • System outages.
  • Technology obsolescence.
  • Third-party tech risks.

6. Reputational Risks

  • Media coverage.
  • Social media.
  • Customer complaints.
  • Stakeholder relations.
  • Executive conduct.

7. Emerging Risks

7.1 Climate and Environmental Risks

  • Physical risks (extreme weather).
  • Transition risks (regulatory, technology).
  • Reputational risks.
  • Investor pressure.

7.2 Geopolitical Risks

  • Trade tensions.
  • Political instability.
  • Currency controls.

7.3 Emerging Technology Risks

  • Artificial intelligence.
  • Quantum computing.

Eighth: Stress Testing

1. Purpose of Stress Testing

  • Testing resilience to adverse scenarios.
  • Identifying vulnerabilities.
  • Informing capital and liquidity planning.
  • Validating risk appetite.
  • Regulatory requirement (especially banks).

2. Types of Stress Tests

2.1 Scenario Analysis

  • Plausible adverse scenarios.
  • Multi-variable analysis.
  • Forward-looking.

2.2 Sensitivity Analysis

  • Single variable changes.
  • Identifying key sensitivities.
  • Limit testing.

2.3 Reverse Stress Testing

  • Starting from failure point.
  • Working backward to identify scenarios.
  • Identifying “break the bank” events.

3. Committee’s Role

  • Approving scenarios.
  • Reviewing assumptions.
  • Discussing results.
  • Approving response plans.
  • Communicating with regulators.

Ninth: Reporting

1. Reports to the Committee

1.1 Regular Reports

  • Risk dashboard (typically monthly).
  • Key Risk Indicators (KRIs) tracking.
  • Risk appetite adherence.
  • Emerging risks update.
  • Incident reports.

1.2 Periodic Deep-Dives

  • Annual risk assessment.
  • Stress test results.
  • Specific risk category reviews.
  • Business unit risk reviews.

2. Reports from the Committee

2.1 To the Board

  • After each meeting.
  • Annual comprehensive report.
  • Material risk events.
  • Recommendations for board action.

2.2 To Regulators

  • Required regulatory reports.
  • Stress test results.
  • Significant risk events.
  • Framework changes.

2.3 To Shareholders

  • Annual report disclosure.
  • Material risk factors.
  • Risk management approach.
  • Climate-related disclosures (increasingly).

Tenth: Coordination with Other Bodies

1. With Audit Committee

Significant overlap requiring coordination:

  • Financial risk oversight (shared).
  • Internal control assessment.
  • Joint meetings periodically.
  • Clear charter delineation.
  • Coordinated reporting.

2. With CRO and Risk Function

  • Regular direct communication.
  • Closed sessions for sensitive matters.
  • Approving CRO appointment and compensation.
  • Reviewing function resources.

3. With Internal Audit

  • Reviewing audit findings related to risk.
  • Joint risk assessment input.
  • Coordination on risk-based audit planning.

4. With External Parties

  • External auditors (on risk matters).
  • Rating agencies.
  • Risk consultants.

Eleventh: Common Challenges

1. Risk Volume and Complexity

Modern companies face countless risks:

  • Difficulty prioritizing.
  • Resource constraints.
  • Information overload.

Treatment:

  • Clear materiality thresholds.
  • Top risks focus.
  • Effective dashboards.
  • Strong risk function.

2. Emerging Risks

New risks emerge constantly:

  • Difficulty assessing unknown risks.
  • Lack of historical data.
  • Cross-cutting nature.

Treatment:

  • Horizon scanning.
  • Scenario thinking.
  • External expert engagement.
  • Industry monitoring.

3. Risk Culture

Building risk culture is challenging:

  • Tension with growth pressures.
  • Short-term performance focus.
  • Tone-from-top dependence.

Treatment:

  • Board commitment visible.
  • Risk in performance metrics.
  • Whistleblower protection.
  • Learning from failures.

4. Risk-Strategy Balance

Balancing risk avoidance with strategic ambition:

  • Over-cautious limits growth.
  • Under-cautious threatens sustainability.
  • Constant balancing act.

Twelfth: Best Practices

1. At Governance Level

  • Independent strong committee.
  • Clear charter and mandate.
  • Regular meetings (at least quarterly).
  • Direct access to CRO.
  • Annual evaluation.

2. At Framework Level

  • Integrated ERM framework.
  • Clear risk appetite.
  • Comprehensive risk register.
  • Robust stress testing.
  • Crisis management plans.

3. At Culture Level

  • Tone from the top.
  • Risk awareness training.
  • Open communication.
  • Whistleblower mechanisms.
  • Risk-adjusted incentives.

4. At Disclosure Level

  • Comprehensive annual reporting.
  • Climate-related disclosures.
  • Material risk factors.
  • Beyond minimum requirements.

Conclusion

The risk committee is the steward of corporate resilience. In a world of accelerating change and increasing complexity, the committee’s role becomes more critical with each passing year. New risks emerge from technology, climate, geopolitics, and society — and the committee must ensure the company is prepared. A strong risk committee builds capability before crises hit; a weak one finds the company reacting to events rather than shaping them.

Saudi companies, especially financial institutions, have built strong risk committee practices over the years, often exceeding regulatory requirements. The challenge now is keeping pace with emerging risks while maintaining excellence in traditional risk management. Investment in risk capabilities — frameworks, people, technology, and culture — pays back in resilience that enables companies to weather storms and seize opportunities others must decline.

🎯  Essential Points to Remember

(1) Mandatory in banks and insurance, recommended in large listed companies. (2) Composition: 3-5 non-executive members, majority independent. (3) Required expertise: risk management, sector knowledge, financial acumen. (4) Main responsibilities: framework, appetite, identification, mitigation, stress testing, function oversight. (5) ERM frameworks: COSO and ISO 31000 most common. (6) Three lines of defense: operational, risk function, internal audit. (7) Risk appetite combines qualitative statements and quantitative limits. (8) Risk types: strategic, financial, operational, compliance, cyber, reputational, emerging. (9) Stress testing essential for resilience and capital planning. (10) Coordination with audit committee critical given overlap.

Frequently Asked Questions

When is a risk committee mandatory in Saudi Arabia and what are its composition requirements?

The risk committee is mandatory under SAMA regulations in every bank and under Insurance Authority regulations in every insurance company, with detailed requirements: three to five non-executive members, a majority must be independent, an independent chair is preferred, and executive members are prohibited. For other listed companies, the CMA Corporate Governance Regulations recommend forming a risk committee in large companies while allowing its functions to be merged with the audit committee in smaller ones. Required expertise spans four dimensions that must be collectively present: at least one member with deep risk management experience in frameworks such as COSO and ISO 31000 with quantitative analysis capability and ideally FRM or PRM credentials; sector expertise covering the specific risk types relevant to the company such as credit, market, and liquidity risks for banks and underwriting and investment risks for insurance; financial expertise in capital adequacy and stress testing; and increasingly technology expertise given the growing importance of cyber risks, data and privacy risks, and technology disruption. Banks with higher complexity may have committees of five to seven members. The committee must have direct access to the Chief Risk Officer and must hold closed sessions without management for sensitive risk discussions.

What are the main responsibilities of the risk committee and how does it manage risk appetite?

The committee's responsibilities cover seven interconnected areas. Risk management framework oversight by recommending the ERM framework to the board, reviewing its effectiveness annually, and ensuring integration across the enterprise. Risk appetite definition and monitoring — the committee works with management to define both qualitative statements such as zero tolerance for regulatory violations and quantitative limits such as maximum acceptable losses, capital ratios, concentration limits, and liquidity ratios, recommends the appetite statement to the board for approval, then regularly monitors adherence and investigates breaches. Risk identification by reviewing the comprehensive risk register, ensuring all material risks including emerging risks are captured with appropriate probability and impact assessments. Risk mitigation and controls by reviewing mitigation strategies and assessing control effectiveness. Stress testing by approving scenarios, reviewing assumptions and results, and approving response plans. Risk function oversight including recommending the CRO appointment, annual performance evaluation, and approving compensation to protect the function's independence. Crisis management by approving crisis response plans and overseeing actual crisis responses. The risk appetite statement cascades from the board-approved overall appetite through management translation to division limits and then to individual transaction thresholds, creating an integrated hierarchy of risk constraints.

What risk types does the committee oversee and how does it coordinate with the audit committee?

The committee oversees seven categories of risk. Strategic risks including industry disruption, competitive threats, and technology obsolescence. Financial risks subdivided into market risk covering interest rates, foreign exchange, and commodity prices; credit risk covering counterparty default and concentration; and liquidity risk covering funding and market liquidity. Operational risks including process failures, human errors, system failures, fraud, and third-party risks. Compliance and regulatory risks including anti-money laundering, data protection, and sanctions risks. Cyber and technology risks including data breaches, ransomware, and system outages. Reputational risks across media, social media, and stakeholder relations. Emerging risks including climate physical and transition risks, geopolitical tensions, and artificial intelligence risks — the hardest to assess given limited historical data. Coordination with the audit committee is critical given significant overlap in financial risk oversight, internal control assessment, and compliance monitoring. Best practice involves periodic joint meetings between the two committees, clear charter delineation specifying which committee owns which overlapping topics, and coordinated reporting to the board to prevent gaps and duplication. The risk committee also coordinates with internal audit on risk-based audit planning and with external parties including SAMA, rating agencies, and risk consultants.

References and Sources

  • Saudi Central Bank (SAMA) Risk Management Regulations.
  • Insurance Authority Governance Regulations.
  • Corporate Governance Regulations issued by the Capital Market Authority.
  • COSO Enterprise Risk Management Framework.
  • ISO 31000 Risk Management Guidelines.
  • Basel III Standards — Banking Risk Management.
  • ICGN Global Governance Principles — Risk Oversight.
  • Three Lines of Defense Model — Institute of Internal Auditors.
  • Task Force on Climate-related Financial Disclosures (TCFD).
  • Deloitte / PwC / EY — Risk Committee Effectiveness Guides.

Related Posts

Quarterly and Annual Earnings Communications

Quarterly and Annual Earnings Communications

  Quarterly and Annual Earnings Communications Press Releases, Earnings Calls, Conferences, and Follow-Up First: Introduction Earnings announcements are the most important moments in the annual IR calendar. Four times a year (for Main Market companies), the company displays its financial

Read More»
Crisis Management in Investor Relations

Crisis Management in Investor Relations

  Crisis Management in Investor Relations Reputation, Activist Shareholders, Market Turbulence, and Crisis Communication First: Introduction Crises are a true test of investor relations. In normal times, IR is a routine communication function. In crises, it becomes the company’s first

Read More»
Digital Investor Relations (Digital IR)

Digital Investor Relations (Digital IR)

  Digital Investor Relations (Digital IR) Websites, Social Media, Live Streaming, and Digital Platforms First: Introduction Digitization has radically changed investor relations. What used to require printed reports and phone calls is now available through interactive websites, live streaming, and

Read More»