Corporate Risk & Compliance • Board Governance • India • 2026

Corporate Risk Register in India: Board Risk Management Framework, Scoring, Owners & Reporting Guide 2026

A practical board-level system for converting scattered legal, regulatory, contract, fraud, workforce, data and operational risks into a single owned, scored and monitored risk register.

IdentifyWhat can go wrong and where?
ScoreLikelihood, impact and velocity
OwnNamed executive and control owner
ReportBoard dashboard, overdue action and residual risk

A corporate risk register is the management document that answers a deceptively simple question: what are the most important risks facing the company, who owns them, what controls currently exist, what remains exposed, and what is management doing about it?

For many Indian businesses, risks are tracked separately by finance, HR, IT, legal, operations, procurement and the company secretary. The result is fragmented governance. Tax notices may sit in finance, litigation in external counsel files, contract renewals in business teams, vendor conflicts in procurement, data incidents in IT and labour exposure in HR. A board therefore receives multiple partial pictures rather than one enterprise-level view.

A properly designed risk register does not replace specialist compliance systems. It integrates them. It creates a common language for risk, converts findings into owners and deadlines, and allows directors to distinguish routine operational issues from matters requiring immediate escalation.

Important distinction: there is no single universal statutory form called a “corporate risk register” that every Indian private company must maintain. Its legal relevance comes from the wider governance framework—Board responsibility, risk-management disclosure where applicable, internal controls, applicable-law compliance, audit oversight, sectoral requirements and listed-company obligations. The register is therefore a practical governance instrument whose scope must be tailored to the company.

1. Legal foundation for board-level risk management

The Companies Act, 2013 creates several governance anchors relevant to risk management. Section 134 includes Board-report and directors’ responsibility requirements. For companies to which the full Board-report framework applies, section 134(3)(n) addresses development and implementation of a risk-management policy, including risks that may threaten the company’s existence. Section 134(5) also places emphasis on proper systems to ensure compliance with applicable laws and on their adequacy and effectiveness.

Section 177 connects Audit Committee oversight, where applicable, with internal financial controls and risk-management systems. Section 166 requires directors to act in good faith and exercise due and reasonable care, skill, diligence and independent judgment. These provisions do not prescribe a universal spreadsheet format, but they make documented risk identification and monitoring a rational governance response.

For listed entities, the current SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, last amended 14 July 2026, add specific governance obligations. Regulation 21 applies the Risk Management Committee framework to the prescribed listed-entity universe, including the top 1000 listed entities by market capitalisation under the current framework.

For a broader legal-risk review before creating the register, see our Corporate Legal Risk Audit in India and Legal Compliance Audit for Private Limited Companies in India.

2. What belongs in a corporate risk register?

The register should capture risks that can materially affect money, continuity, legality, reputation, people, data, assets, contracts or management bandwidth. A practical private-company register will usually include the following risk families:

Risk family Illustrative exposure Typical owner
Corporate / secretarial ROC default, approval gap, beneficial ownership, charges Company Secretary / Legal
Contracts Unlimited liability, termination, auto-renewal, SLA penalties Legal / Business
Vendor / procurement Conflict, shell vendor, bank-detail fraud, price leakage Procurement / Finance
Workforce Wage, social security, contractor, POSH, termination HR / Legal
Tax / finance Demand, TDS, GST mismatch, covenant breach, cash leakage CFO / Tax
Data / cyber Unauthorised access, breach, weak retention, vendor processing IT / Security / Legal
Litigation / investigation Claims, injunctions, police matters, regulatory action Legal
Operational Asset loss, claims leakage, logistics exceptions, business interruption COO / Operations
Regulatory / licence Expiry, suspension, sector breach, reporting default Compliance / Business

3. The minimum fields every risk entry should contain

A risk register becomes useful only when every row is actionable. At minimum, each entry should include:

  1. Risk ID: a unique reference number.
  2. Risk statement: what can happen, why and with what consequence.
  3. Category: legal, tax, HR, cyber, vendor, etc.
  4. Source: audit, complaint, notice, incident, contract review, regulator or management.
  5. Likelihood: probability of occurrence or recurrence.
  6. Impact: financial, regulatory, operational and reputational severity.
  7. Inherent risk: exposure before controls.
  8. Existing controls: policies, approvals, systems and monitoring.
  9. Control effectiveness: whether controls actually operate.
  10. Residual risk: exposure after controls.
  11. Risk owner: executive accountable for the outcome.
  12. Action owner: person responsible for remediation.
  13. Deadline: target closure date.
  14. Status: open, in progress, accepted, transferred, closed or monitoring.
  15. Evidence: documents proving control or closure.
  16. Escalation level: management, committee or Board.

Risk entries should be written as complete cause-event-impact statements. “GST” is not a risk statement. “Input-tax-credit mismatches are not reconciled monthly, creating potential demand, interest and working-capital exposure” is.

4. Risk scoring: use more than red, amber and green

Colour coding is useful, but the logic behind the colour matters. A simple 5×5 model can score likelihood from 1 to 5 and impact from 1 to 5. The product gives a base score of 1–25. Management can then add risk velocity and control effectiveness where appropriate.

Score Suggested level Governance response
20–25 Critical Immediate executive action and Board / committee escalation
15–19 High Named remediation plan, short deadline, periodic reporting
8–14 Medium Management remediation and scheduled review
1–7 Low Routine control improvement / monitoring

A ₹10 lakh issue that can close a factory tomorrow may deserve higher escalation than a ₹50 lakh receivable dispute that will move through litigation over several years. This is why velocity and continuity impact matter.

5. Inherent risk vs residual risk

Inherent risk is the exposure before controls. Residual risk is what remains after controls are applied. The distinction prevents management from overstating comfort merely because a policy exists.

Example: a company has thousands of vendor payments. The inherent fraud risk may be high. If it operates verified vendor onboarding, maker-checker banking, bank-detail change callbacks, PO-GRN-invoice matching, conflict declarations and exception analytics, residual risk may fall materially. But if those controls exist only on paper, the residual score should remain high.

For vendor-specific controls, see our Third-Party Risk Management in India.

6. Risk ownership: do not assign everything to Legal

Legal can advise on exposure, but business risks should have business owners. A contract-renewal failure may be owned jointly by Sales and Legal; labour dues by HR and Finance; access-control risk by IT; vendor conflict by Procurement; statutory filings by the Company Secretary; tax demands by Finance/Tax; regulatory licences by the operating business with Compliance oversight.

A strong register therefore uses two accountability fields:

  • Risk owner: the executive accountable for managing the risk.
  • Action owner: the person completing a specific remediation task.

Without this separation, risk reports become legal-team inventories rather than management systems.

7. What should go to the Board?

The Board does not need 500 unfiltered risk rows. It needs decision-relevant information. A useful Board pack should show:

  • top 10–20 enterprise risks;
  • new critical/high risks since last meeting;
  • risks whose score increased;
  • overdue remediation actions;
  • material litigation and regulatory notices;
  • control failures that repeated after remediation;
  • major contract, vendor, cyber or workforce events;
  • accepted risks requiring Board acknowledgement;
  • trend charts by business unit and category; and
  • decisions or resources required from the Board.

The register should be detailed; the Board dashboard should be concise.

8. Risk acceptance must be explicit

Not every risk can or should be eliminated. A company may accept a low-probability contractual exposure because the commercial benefit is substantial. But “accepted” must not mean “ignored.” A proper risk-acceptance record should state:

  1. what risk is being accepted;
  2. estimated exposure;
  3. why mitigation is disproportionate or commercially undesirable;
  4. who has authority to accept it;
  5. review date; and
  6. trigger for reopening the decision.

Material risk acceptance should follow the company’s delegation and governance framework.

9. Link the risk register to the compliance calendar

A compliance calendar tracks what must be done and when. A risk register tracks what may go wrong and how serious it is. They should connect.

If a statutory filing becomes overdue, the compliance calendar should create an exception. If the exception remains unresolved or materially exposes the company, it should enter the risk register. Similarly, a repeated vendor KYC exception should move from process monitoring to enterprise risk if it reveals systemic control failure.

For an operational compliance framework, see our 2026 Private Company Compliance Audit Checklist.

10. Link the register to incidents and investigations

Every material incident should be tested against the existing risk register:

  • Was this risk already known?
  • Were controls identified?
  • Did the controls fail?
  • Was remediation overdue?
  • Did the risk score understate exposure?
  • Does the incident create a new risk category?

Where suspected fraud, misconduct or data leakage is involved, the risk register should record the issue without prejudging individual guilt. Evidence and findings should be managed through a separate investigation process. See our Board-Led Corporate Internal Investigations in India.

11. Data and cyber risk in the register

Data-risk entries should reflect the applicable legal and operational framework. MeitY notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025 with a staged commencement structure. Companies should therefore distinguish obligations already operative from those whose commencement is deferred, while using the transition period to close governance and technical gaps.

Typical register entries include excessive privileged access, weak employee offboarding, missing vendor processing terms, incomplete data inventory, incident-response gaps, customer-data exports and inadequate retention controls.

12. Risk-register review cycle

A practical cadence is:

Frequency Review
Continuous Critical incidents, regulator notices, fraud allegations, major litigation
Monthly Action-owner updates, overdue items, new high risks
Quarterly Executive / Board dashboard and trend analysis
Annually Full risk-universe refresh, scoring criteria and appetite review
Event-driven Acquisition, new geography, major system, restructuring, regulatory change

13. Sample board-ready risk register

Risk Inherent Controls Residual Owner Action Deadline
Critical customer contract expires without renewal 20 Renewal tracker; account review 15 Sales Head Negotiate renewal 30 days
Vendor bank-detail fraud 16 Callback + maker-checker 8 CFO Quarterly control test Ongoing
Employee exports customer database before exit 20 Role access + DLP + offboarding 12 CTO / HR Restrict bulk exports 15 days

14. Common failure modes

  • The register has hundreds of rows but no prioritisation.
  • Every risk is assigned to Legal or Compliance.
  • Risk scores never change even after incidents.
  • “Closed” items have no closure evidence.
  • Management removes uncomfortable risks from Board reporting.
  • No distinction exists between inherent and residual risk.
  • Accepted risks have no approval trail.
  • Repeated audit findings are treated as new surprises.
  • The register is updated only before the annual audit.
  • There is no link between the register, compliance calendar and incident process.

15. 30-day implementation plan

Days 1–7: define risk categories, owners, scoring criteria and escalation thresholds. Import open issues from litigation, tax, HR, compliance, cyber, vendor and contract trackers.

Days 8–15: conduct management workshops to write proper risk statements, identify controls and score inherent risk.

Days 16–23: test control effectiveness, calculate residual risk, define remediation and assign action owners.

Days 24–30: prepare the first executive dashboard, validate top risks with management and establish monthly/quarterly review cadence.

Frequently asked questions

Is a corporate risk register mandatory for every private company?

There is no single universal statutory register in a prescribed format for every private company. The appropriate system depends on the Companies Act reporting framework, company class, sector, scale, contractual commitments and governance needs.

Who should own the risk register?

One function may coordinate it, but individual risks should be owned by the relevant business executives. Legal or Compliance should not become the owner of every business risk.

How many risks should be shown to the Board?

The detailed register may contain many entries, but the Board pack should focus on material, changing and overdue risks and decisions required.

What is residual risk?

It is the exposure that remains after existing controls are considered and tested.

Should litigation be in the risk register?

Material litigation, regulatory proceedings and threatened claims should ordinarily feed the enterprise risk picture, while detailed case management can remain in a separate litigation tracker.

Related corporate-risk resources

Corporate Risk & Compliance Enquiry
Structured risk reviews, compliance audits and remediation frameworks

Organisations seeking a structured discussion on legal-risk identification, risk registers, compliance audits or remediation planning may use the corporate enquiry form for preliminary information exchange.

Corporate Enquiry Form

This information is provided for professional identification and correspondence only and is not intended as advertisement, solicitation or an invitation to engage legal services.
Disclaimer: This article is general legal and governance information as on 28 August 2026. Risk-management duties vary by company class, listing status, sector, thresholds, exemptions and facts. Specific statutory, SEBI, RBI, tax, labour, data or sectoral obligations should be independently verified for the entity concerned.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *