Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
Audit committees in Singapore are facing a governance environment that is changing faster than most risk frameworks. These are the questions that reveal whether your risk function is fit for what is actually in front of you.
I spend a significant part of my advisory practice working with audit committees — helping them understand what they should be asking, how to interpret what they are being told, and where the gaps between the presentation and the reality tend to sit. What I find consistently is that the standard audit committee agenda — financial reporting, internal controls, external audit, compliance — has not kept pace with the risk environment that Singapore-listed companies are now operating in.
Climate risk is now financially material and must be disclosed. AI and algorithmic decision-making are moving into core business processes. Geopolitical fragmentation is reshaping supply chains and counterparty exposure. Regulatory expectations on ESG, data governance and operational resilience are tightening across Singapore, Hong Kong and the ASEAN region simultaneously.
Against that backdrop, here are the five questions I believe every SGX audit committee should be putting to the CRO — and what the answers should sound like.
1. What is the most material risk we are carrying that is not in our current risk register?
This question is more useful than asking whether the risk register is complete, because a competent risk function knows where its blind spots are. If the CRO cannot answer it — or answers with excessive confidence that everything material is captured — that tells you something important about the quality of the risk identification process.
2. Which of our top-ten risks has the weakest mitigant, and what would make it adequate?
Most risk presentations focus on what controls are in place. This question forces the conversation onto adequacy — whether the control is actually sufficient for the severity and likelihood of the risk, and what gap remains. It produces a much more useful conversation than the standard red-amber-green heat map.
3. How has our risk profile changed in the last twelve months — and why?
Risk reporting that does not explain change is not governance information — it is a status update. The audit committee should understand whether risks are moving because the external environment has changed, because management has made decisions that altered the profile, or because the risk assessment methodology has been adjusted. These are very different things.
4. Where is our climate risk currently sitting in the enterprise risk framework — and is that appropriate?
From FY2025, SGX-listed companies with a market cap above the threshold must disclose climate-related risks under the mandatory requirements. The question is not whether you are disclosing — it is whether the risk governance matches the disclosure. Climate risk that lives only in the sustainability report, and has not been integrated into the ERM framework, capital planning, or board reporting, is a governance gap with increasing liability implications.
5. Show me a decision made in the last six months where the risk function caused management to do something differently.
This is the question that separates a functioning risk function from a reporting function. If the CRO cannot name a specific example — a decision slowed, a proposal modified, a strategy adjusted because of risk challenge — then the risk function is producing paper rather than governance value. That is an important finding for an audit committee to hold.
“An audit committee that only asks whether risks are within limits is not governing risk. It is confirming that management says so.”
These questions are not adversarial. They are the questions that allow a board to govern with confidence rather than assurance. A CRO who can answer them clearly — with evidence, with appropriate uncertainty, with a view on what the board should worry about that management may be underweighting — is providing genuine value. If the answers are vague, deferential or focused on compliance outputs, the audit committee has something to address.
Common Questions
What should an SGX audit committee ask the CRO about climate risk?
The audit committee should ask whether climate risk is integrated into the enterprise risk framework (not just the sustainability report), what climate scenarios have been stress-tested against capital, and which physical and transition risks are currently material to the business.
How often should an SGX board review the risk register?
Best practice is quarterly review at the risk committee level, with material changes reported to the full board. However, the frequency matters less than the quality of the review — whether the board is challenging assumptions, asking about emerging risks, and receiving information in governance terms rather than technical terms.
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.