The audit committee was never designed to carry the full weight of enterprise risk oversight. A growing number of sophisticated Indian boards are recognising this — and acting on it.
The Audit Committee Is Carrying Too Much
Audit committees in India are overloaded. Regulatory requirements have expanded substantially over the past five years — broader related-party transaction oversight, cybersecurity risk review, ESG disclosure assurance, and detailed internal audit oversight — without any corresponding reduction in the committee's traditional financial reporting and compliance mandate. The result, as CXO India's governance advisory team observes repeatedly, is an audit committee doing too many things too superficially.
A Dedicated Risk Committee Gains Ground
The fix gaining traction among India's more governance-forward boards is to hive off risk oversight into a dedicated risk committee. Long established in financial services, where the RBI mandates it, the structure is now being adopted voluntarily by non-financial listed companies that recognise the limits of the current setup.
CXO India's 2025 governance survey found that 23% of NSE 100 non-financial companies now operate a risk committee separate from the audit committee, up from 14% three years ago.
Design It Deliberately, Not by Default
The risk committee model works best when it is built on purpose rather than by default. The most common mistake is treating it as an administrative separation — shuffling items from one committee agenda to another — instead of a substantive redesign of how the board engages with enterprise risk.
Effective risk committees do three things:
- Develop a risk appetite framework in genuine dialogue with management
- Maintain a dynamic risk register that is honest about uncertainty
- Set explicit protocols for escalating emerging risks to the full board before they reach crisis level
The Right People in the Room
The directors who serve on these committees most effectively are those who bring operational experience in managing enterprise risk — not just financial risk, but operational, reputational, and strategic risk in its full complexity.




