What a risk committee actually does
Launch library · evergreen read

A risk committee is a board level group specifically responsible for overseeing how a company identifies, assesses and manages the significant risks it faces, ranging from financial and operational risk through to reputational and regulatory risk, including the risk of corruption or serious misconduct occurring somewhere within the organisation.
Its work typically involves reviewing management's own risk assessments, questioning whether the controls in place genuinely match the level of risk identified, and ensuring emerging risks, such as those tied to a new market or an unfamiliar business relationship, are properly considered rather than only addressed after a problem has already occurred.
A well functioning risk committee asks uncomfortable questions before a risk becomes an actual incident, rather than reviewing what happened only after the damage has already been done. That forward looking discipline is really what separates a genuinely useful risk committee from one that exists mainly as a governance formality.