Enterprise risk management and business continuity
Indian law says surprisingly little about how a company must manage risk, and rather more about who must be seen to be managing it. That gap is where most enterprise risk management programmes go wrong: they are built to satisfy a disclosure rather than to change a decision. This guide separates what is actually required from what is framework, and says plainly where there is no legal requirement at all.
What the board actually has to say about risk
Section 134(3)(n) requires the Board’s report to include a statement on the development and implementation of the company’s risk management policy, including identification of any elements of risk which, in the Board’s opinion, may threaten the company’s existence.
Read carefully, that is a disclosure obligation about a policy, not a requirement to hold any particular level of risk or to run any particular framework. It is nonetheless the most useful sentence in Indian risk regulation, because the clause about risks that may threaten the existence of the company forces a conversation most risk registers avoid. A register of eighty operational risks scored on a five point scale rarely contains the two or three things that could actually end the business, and boards that discover this do so at the worst possible moment.
One scope point. This disclosure applies to companies preparing the regular Board’s report. A one person company or small company preparing an abridged Board’s report under section 134(3A) read with Rule 8A of the Companies (Accounts) Rules 2014 is not required to include this statement as a separate prescribed item, because Rule 8A’s prescribed list does not carry it.
Separately, the audit committee’s terms of reference under section 177(4)(vii) include evaluation of risk management systems, which is covered in Guide 1. Where a company has both an audit committee and a risk management committee, the division of labour between them is worth settling explicitly rather than leaving to practice.
The Risk Management Committee, for listed entities
SEBI’s Listing Obligations and Disclosure Requirements Regulations require the board of the top 1,000 listed entities by market capitalisation to constitute a Risk Management Committee. The threshold was raised from the top 500 to the top 1,000 by an amendment of 5 May 2021.
How the top 1,000 is identified. Entities are ranked by the market capitalisation list prepared by the recognised stock exchanges as at 31 December, based on average market capitalisation from 1 July to 31 December of that calendar year. This is a six month average, not a single figure at a financial year end, and the basis changed with SEBI’s amendment of 17 May 2024. Where an entity enters the top 1,000 for the first time, the requirement generally becomes applicable from 1 April or the beginning of the immediately following financial year, whichever is later. Once applicable, it continues in accordance with the three year exit mechanism in Regulations 3(2A) and 3(2B).
The committee must have a minimum of three members with a majority being members of the board, including at least one independent director. Where the listed entity has outstanding superior-rights equity shares, at least two thirds of the committee must be independent directors. It must meet at least twice a year, with not more than 180 days between consecutive meetings. Quorum is either two members or one third of the members, whichever is higher, including at least one board member in attendance. The committee has express power to seek information from any employee, to obtain outside legal or other professional advice, and to secure the attendance of outsiders with relevant expertise.
Its mandatory functions sit in Part D of Schedule II, which requires a risk management policy covering financial, operational, sectoral, sustainability (particularly ESG related) risks, information and cyber security risks, or any other risk the committee determines. Two things follow from that list. Cyber security is expressly within the committee’s remit, which is why Guide 4 belongs here rather than as a separate technology topic. And sustainability risk is a board level risk question here, distinct from the reporting obligation. The policy must be reviewed at least once in two years.
The SEBI LODR Second Amendment Regulations 2026, published on 14 July 2026, do not amend Regulation 21. They concern transfer and transmission procedures under Regulations 40(7) and 61(4) and the omission of Clause C of Schedule VII. Regulation 21 should nevertheless be read alongside the current high value debt listed entity framework, under which the identification threshold is ₹5,000 crore.
Frameworks: what ISO 31000 and COSO actually are
Both get quoted as though they were compliance requirements. Neither is, and one of them is routinely described in a way that is simply wrong.
ISO 31000:2018, Risk management, is guidance and cannot be certified against. ISO says so on its own page for the standard, in terms. There is no such thing as an ISO 31000 certified organisation, and any provider offering one is selling something that does not exist. Alignment with ISO 31000, or an assessment of a risk framework against it, is a real and useful exercise; certification is not. The standard is currently under revision, with the committee draft having closed for comment on 1 March 2026 and no publication date announced.
COSO publishes two different things that get conflated. Enterprise Risk Management, Integrating with Strategy and Performance (2017) is the ERM framework. Internal Control, Integrated Framework (2013) is the internal control framework, and it remains current: COSO has not reissued it. What COSO has published since are supplements, on internal control over sustainability reporting (2023), robotic process automation (2024) and generative AI (2026). Those are supplements, not a new core framework, and describing them as updates to COSO 2013 is inaccurate.
Business continuity: what the law does and does not require
Indian company law does not impose a universal requirement on every unlisted, non-regulated company to maintain a formally documented plan specifically called a business continuity plan. That does not mean continuity planning is legally irrelevant. Depending on the company’s operations, technology, location and contractual commitments, continuity or disaster recovery obligations may arise under sectoral regulation, cyber security requirements, safety and environmental laws, licences, contracts, or the board’s broader risk management and governance responsibilities.
What does drive it is real enough: the Companies Act and LODR risk governance provisions above, customer and contractual requirements (increasingly the binding constraint for anyone in a supply chain), and voluntary standards. Do not be told otherwise. Two commonly cited sources are narrower than they are presented:
The Disaster Management Act 2005 places disaster management planning duties on government authorities, not on private companies.
The RBI Guidance Note on Operational Risk Management and Operational Resilience of 30 April 2024 is a genuinely substantial document on business continuity and resilience, and it applies only to commercial banks, co-operative banks, All-India Financial Institutions and NBFCs including housing finance companies. It does not apply to non-financial-sector companies, and citing it to a general corporate audience as an applicable obligation would be wrong. As sector-specific good practice for anyone else, it is worth reading.
ISO 22301:2019, security and resilience, business continuity management systems, is the standard that matters here, as amended by Amendment 1:2024 on climate action changes. Unlike ISO 31000 it is a requirements standard and organisations can be certified against it. It is also under revision, with the committee draft having closed for comment on 10 May 2026. Citing the bare 2019 edition without the 2024 amendment is incomplete.
The practical work is unchanged by any of that: a business impact analysis that establishes what actually cannot stop and for how long, recovery objectives that someone has tested rather than asserted, and a crisis response that names people rather than roles nobody currently fills. A continuity plan that has never been exercised is a document, not a capability.
Send an enquiry
Tell us what you are working with: a risk register nobody trusts, a risk management committee that needs a policy that would survive scrutiny, or a continuity plan that has never been tested. A partner replies within one business day.
This page is general information, not professional advice. Indian corporate law positions and SEBI regulations change frequently, and how any of this applies depends on your company’s specific facts. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else’s, without one.