Blog

7 things Directors should know: FRC Risk Management responsibilities

GRC
7 things Directors should know: FRC Risk Management responsibilities
Richard Hunt
Written By Richard Hunt
written

5 Aug, 2016 — 2 min read

7 things Directors should know: FRC Risk Management responsibilities

Table of contents

7 things Directors should know: FRC Risk Management responsibilities
2:23

Every Director knows they need to ensure that their company is managing risk. But what does that mean in practice, and what does the law require of a company Director with respect to risk management and controls?

The main areas of statutory law applicable to risk management are the Financial Services and Markets Act 2000 and the Financial Reporting Council UK Corporate Governance code. The code states the following with regards to Risk Management and Internal Control:

'The Board is responsible for determining the nature and extent of the principal risks it is willing to take in achieving its strategic objectives. The Board should maintain sound risk management and internal control systems'.1

Under the Financial Services and Markets Act 2000 the Board of all publicly listed companies must disclose how they have complied with the code or explain any areas where they have not. Effectively, this makes risk management a legal obligation for Directors of a listed company.

So what are these obligations? In order to determine this, it is necessary to refer to both the code itself and the FRC guidance on risk management and internal controls.2 Here is a high level summary of the key responsibilities that a Director has under the code:

  1. Design and implement appropriate risk and control systems

  2. Perform a robust assessment of the principal risks to the business

  3. Agree on the approach for managing these principle risks

  4. Determine the risk appetite of the organisation

  5. Embed an appropriate culture and reward system for the management of risk

  6. Appraise and monitor risk management in the organisation, carrying out a review of the effectiveness of these systems at least annually

  7. Ensure the publication of risk management information in the annual report

It is evident that there is a lot left to the interpretation of individual Directors and their Boards with regards to the risk management systems they implement. However, it's also clear that there is an expectation that Directors will take the management of their business risks seriously and that legal consequences could follow if they don't.

1. Section C.2: Risk Management  and Internal Control

2.https://www.frc.org.uk/Our-Work/Publications/Corporate-Governance/Guidance-on-Risk-Management,-Internal-Control-and.pdf

Security insights, delivered.

Join 10,000+ risk professionals. Get the latest trends, guides, and case studies sent directly to your inbox.

By subscribing, you agree to our Privacy Policy and provide consent to receive updates.

Related posts

April 15, 2026

Five questions to guide your move to GRC for HANA 1.0

January 07, 2026

SAP Security, GRC, and IAM in 2026: What's coming and what does it mean for you?

December 22, 2025

SAP GRC 2026: Your questions answered