Back to Insights
Board Advisory8 min readSeptember 2026

What a Board Risk Committee Should Look Like for a Singapore-Listed Company

RC

Raymond Cheung

Chartered Actuary · CRO · Board Adviser · Singapore

Most board risk committees I have sat in front of spend their time reviewing a risk register nobody outside the room has read. Here is what changes when a risk committee is actually built to influence decisions rather than to document them, drawn from years reporting into these committees as a statutory CRO.

Early in my time as a statutory Chief Risk Officer, I presented the same twelve-page risk register to the board risk committee for three consecutive quarters. The heat map colours shifted slightly each time. Nobody asked a different question. It took a new independent director joining the committee — someone with no prior exposure to the deck — to ask, in her first meeting, "which two of these fifteen risks would actually change what we do next quarter?" That single question did more to reshape how the committee worked than the previous eighteen months of reporting had.

I have since sat on the other side of that table, advising boards on how their risk committees are structured, and the pattern repeats across almost every Singapore-listed company I have worked with: a committee that meets its statutory obligations, reviews a comprehensive risk register, and has almost no measurable effect on how the business actually makes decisions. That gap — between a compliant committee and an influential one — is the real subject of this piece.

The three failure modes I see most often

The first is scope confusion with the audit committee. Many Singapore-listed companies, particularly outside the financial sector, still run a combined audit and risk committee. That is permitted under the Code of Corporate Governance, but it is workable only when the committee agenda genuinely splits time and mindset between the two. In practice I have watched risk items get fifteen minutes at the end of a two-hour audit committee meeting that has already run long, discussed by directors whose entire prior conversation was about controls testing and financial statement assurance — a completely different cognitive mode from forward-looking risk judgement.

The second is a register that reports risk instead of a committee that governs it. A comprehensive risk register with fifteen to twenty-five entries, each rated on likelihood and impact, is a management tool. It is not a board tool, and treating it as one is why so many risk committee meetings feel like a status update rather than a discussion. The committee's job is not to read the register — it is to decide which handful of risks are material enough to warrant board-level attention this quarter, and to interrogate management's judgement on exactly those.

“A risk committee that reviews everything influences nothing. A risk committee that interrogates three things thoroughly changes how the business is run.”

The third failure mode is committee composition that does not match the company's actual risk profile. I have reviewed risk committees at insurers and financial institutions where not a single member had underwriting, actuarial or treasury experience, and risk committees at technology and consumer businesses where cyber and data risk — arguably the company's largest single exposure — had no directorial expertise represented at all. Independence and financial literacy are necessary; they are not sufficient. A risk committee needs at least one member who can ask a genuinely informed follow-up question on the company's dominant risk category, not just a well-run process for the rest.

What changes the committee's effectiveness

For MAS-regulated insurers, this is not optional — MAS's own reviews of ORSA reports have repeatedly found that board minutes document discussion of capital adequacy and stress test results but are silent on whether the board actually debated the plausibility of scenarios or the connection between risk appetite and business strategy. The same gap shows up in listed non-financial companies, just without a regulator naming it in a public report.

  • Set a standing agenda structure of three to five material risks per meeting, chosen in advance by the CRO or risk owner in consultation with the committee chair — not the full register
  • Require every material risk item to state explicitly which decision, limit or business unit it connects to, not just its likelihood and impact score
  • Match at least one committee member's expertise to the company's single largest risk category, even if that means recruiting for it specifically
  • Separate risk from audit on the agenda even in a combined committee — a hard time allocation, not a courtesy at the end
  • Ask the CRO, at least once a year, to bring the committee a risk that was assessed and judged not material — the negative case is often more revealing of judgement quality than the positive one

The SGX Group board tenure changes I wrote about separately this month are a useful adjacent example — Lim Chin Hu retained his seat on SGX's Risk Management Committee even after losing independent status, because the board had already confirmed the committee's independence composition remained compliant without him counted as independent. That is forward planning applied to committee composition. The same discipline — knowing exactly what expertise and independence math a risk committee needs before a vacancy or reclassification forces the question — is what separates a risk committee built to survive an audit from one built to actually change outcomes.

If you are advising a board or sitting on one, the test I would apply is simple: pull the minutes from the last four risk committee meetings and count how many times a director's question changed a management recommendation. If the answer is zero, the committee is compliant. It is not yet doing its job.

Common Questions

What should a board risk committee in Singapore actually focus on each meeting?

Three to five material risks chosen in advance, each tied explicitly to a decision, limit or business unit — not a full walkthrough of the risk register. The committee's value comes from depth on a small number of items, not breadth across all of them.

Can a Singapore-listed company combine its audit and risk committees?

Yes, this is permitted under Singapore's Code of Corporate Governance and common outside the financial sector. It works only if risk is given a genuinely separate, protected block of agenda time rather than the last fifteen minutes of an audit committee meeting that has run long.

Who should sit on a board risk committee for an MAS-regulated insurer?

At minimum, members with the financial literacy to interrogate an ORSA report, plus at least one director with underwriting, actuarial or treasury depth relevant to the insurer's specific risk profile. MAS reviews have found that board minutes often show discussion of capital adequacy figures but little evidence of debate on scenario plausibility or the link between risk appetite and strategy — composition gaps are a common root cause.

About the author

Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.

All insights