The Board Committee Series | Part 2: The Risk Committee

‍ ‍

This is Part 2 of a four-part series on core board committees. Part 1 covered the Audit Committee. The full series, along with our foundational article on Terms of Reference, is available here.

‍ ‍There is a question that cuts to the heart of how well a board is governing: not "what risks does this organization face?" but "how confident is the board that it actually knows?"

‍ ‍The Risk Committee exists to answer that second question and to hold management accountable for ensuring the answer is always yes.

‍ ‍In many organizations, risk oversight lives in the Audit Committee. That arrangement is understandable, especially in smaller boards where the committee structure is lean. But as organizations grow in complexity, combining audit and risk oversight in a single committee stretches both mandates thin. Audit focuses on what has happened, the accuracy of financial reporting, and the effectiveness of past controls. Risk on the other hand focuses on what could happen and what the organization is doing about it.

‍ ‍What the Risk Committee Oversees

The Risk Committee's mandate spans the full spectrum of material risks facing the organization. At a minimum, this includes:

‍ ‍ Strategic risk - whether the organization's strategic choices expose it to threats it has not adequately considered, including competitive disruption, market shifts, and reputational exposure.

‍ ‍ Financial risk - credit risk, liquidity risk, currency and interest rate exposure. In regulated financial institutions, this overlaps significantly with the regulatory capital and prudential frameworks enforced by the CBK, IRA, or other sector regulators.

‍ ‍ Operational risk - the risks arising from people, processes, systems, and external events. This includes cybersecurity risk, which has become a mandatory oversight priority across Kenya following the CBK's cybersecurity directives and the broader East Africa regulatory push on cyber resilience in 2025 and 2026.

‍ ‍ Compliance and regulatory risk - whether the organization is meeting its obligations under applicable law and regulation, and whether changes in the regulatory environment create new exposure.

‍ ‍ Emerging risks - climate risk, AI governance risk, geopolitical exposure, and supply chain fragility. These are the risks that do not fit neatly into existing categories but have become impossible for boards to ignore.

‍ ‍Risk Appetite: The Committee's Most Important Conversation

‍ The single most important concept in risk governance is risk appetite. This is the level and type of risk an organization is willing to accept in pursuit of its strategic objectives. It is the board's statement of where the boundaries are.

‍ ‍Without a defined and board-approved risk appetite, risk management becomes arbitrary. Management makes risk decisions based on individual judgment, without a shared framework for what is acceptable. The Risk Committee's role is to recommend a risk appetite statement to the full board, ensure it is translated into operational risk tolerances across the business, and review whether actual risk-taking is staying within the approved boundaries.

‍ In Kenya's current governance environment - where the Chambers and Partners 2026 Kenya Corporate Governance Guide describes the 2025–2026 period as a decisive shift toward governance excellence and long-term value creation - boards that cannot articulate their risk appetite are increasingly visible to regulators and investors as governance laggards.

Composition: Who Belongs on the Risk Committee

The Risk Committee should be formed of independent non-executive directors and apply relevant leading practice corporate governance guidance on composition, succession and performance evaluation criteria.

Members should collectively bring expertise across the risk domains most material to the organization. For a financial institution, this means directors with credit, treasury, and regulatory experience. For an NGO or development organization, it means directors who understand programme risk, donor compliance, and operational resilience in complex environments. Sector expertise matters enormously. A committee that cannot read the organization's risk profile intelligently cannot oversee it.

The Chief Risk Officer or equivalent typically attends Risk Committee meetings in a reporting capacity to ensure credible oversight.

‍ ‍Common Failures to Watch For

‍ ‍ Risk registers that are updated annually and filed away - rather than living documents reviewed regularly and connected to actual board deliberation

‍ ‍ Risk appetite statements that exist on paper but are not linked to operational limits - creating a gap between what the board has approved and what management is actually doing

‍ ‍ Committees that receive risk reports without challenging them - accepting management's assessment of risk likelihood and severity without independent scrutiny

‍ ‍Cybersecurity risk treated as an IT issue - rather than a board-level operational risk requiring the same governance rigor as financial and strategic risk

No escalation protocol - leaving management to decide unilaterally what risk information reaches the committee, rather than having a defined threshold for mandatory escalation

‍ ‍What a Risk Committee TOR Must Specifically Address

Beyond the standard TOR elements covered in last month's foundational article, a Risk Committee TOR should explicitly cover:

1.      The committee's authority to commission independent risk assessments

2.      The escalation protocol - what triggers mandatory reporting to the committee outside of scheduled meetings

3.      The committee's role in reviewing and recommending the risk appetite statement to the full board

4.      The frequency of risk register reviews - quarterly at minimum for most organizations

5.      The committee's oversight of cybersecurity and emerging risk categories

‍ ‍Risk Governance Is Not About Avoiding Risk. It Is About Owning It.

The board that governs risk well is the board that knows which risks it is taking, why it has chosen to take them, and what it will do if they materialize. That clarity - between the board, management, and external stakeholders - is what the Risk Committee exists to create and maintain.

‍ ‍Next week: The Board Committee Series | Part 3: The Nominations and Remuneration Committee

For support establishing or reviewing your Risk Committee's structure and Terms of Reference, Azali CPS provides governance advisory services across Africa.

‍ ‍admin@azali.co.ke | +254 707 456 140

‍ ‍

Next
Next

Chapter Zero Has Arrived in Kenya. Here Is What Every Board Needs to Know