Hong Kong International Corporate Secretaries

Board risk management and internal control in Hong Kong: the board's oversight role

HKEX requires the board to oversee risk management and internal control systems. Learn the annual review and disclosure obligations.

Board Responsibility for Risk Management and Internal Control

The Hong Kong Corporate Governance Code (Appendix C1 to the Main Board Listing Rules) places responsibility for the issuer’s risk management and internal control systems squarely on the board. Board risk management Hong Kong is not a task that can be delegated away. The board must ensure that appropriate systems are designed, implemented and monitored. It must review their effectiveness at least annually. The corporate governance report filed with the Exchange must state that such a review has been conducted and describe its scope.

Board Oversight of Risk Management Systems

The board’s role is oversight, not operation. Day-to-day operation of risk management and internal control systems is management’s responsibility. The distinction matters. A non-executive director does not need to run controls, but must be satisfied that management has designed and maintained them properly.

The board should set the issuer’s risk appetite and risk tolerance, approve the overall risk management framework, and receive regular reports from management on the principal risks the issuer faces and the controls in place to mitigate them. The corporate governance report must describe how the board exercises this oversight, including how it satisfies itself that the systems are operating as intended.

Under Appendix C1, the board may discharge its review obligation through the audit committee or a separate risk committee. The code does not prescribe which body must do the work. It requires only that the review happen at least annually.

Hong Kong Internal Control Review Board

The phrase “hong kong internal control review board” captures what the board must do: conduct an internal control review that covers the issuer’s financial, operational and compliance controls. The review is not limited to financial reporting controls. It must assess whether the systems address the issuer’s material risks, whether they are designed effectively, and whether management has implemented them.

The board should document the scope of each review. Scope might cover:

  • The control environment, including the issuer’s culture and ethics
  • The risk assessment process
  • Control activities, including segregation of duties and authorisation limits
  • Information and communication channels
  • Monitoring activities, including internal audit or compliance functions

Where the issuer has an internal audit function, the board should consider its findings as part of the review. Where no such function exists, the board should evaluate whether that gap is justified and how it is addressed.

The corporate governance report must describe the scope of the review and confirm that it has been conducted. Issuers frequently include a statement that no material weaknesses were identified, or they disclose weaknesses and the remedial actions taken.

Risk Committee Hong Kong Listed Company

A “risk committee hong kong listed company” is a committee established by the board to oversee risk management specifically. Some issuers combine risk and audit oversight in the audit committee. Others maintain a separate risk committee, particularly where the issuer operates in a sector with complex risk profiles such as banking, insurance or commodities.

Code Provision D.2.1 of Appendix C1 states that the board should conduct the risk management and internal control review through the audit committee. Nothing prevents the board from forming a dedicated risk committee. Where a separate risk committee exists, its terms of reference should set out its duties. Those duties include:

  • Reviewing the issuer’s risk management framework and policies
  • Monitoring the principal risks facing the issuer
  • Reviewing reports from management on risk exposure and control effectiveness
  • Reporting to the board on any material issues identified

The committee should comprise a majority of independent non-executive directors, in line with the Listing Rules requirement that the audit committee consist solely of independent non-executive directors. The corporate governance report should disclose the committee’s composition, membership and work during the year.

Hong Kong Corporate Governance Internal Control

“Hong kong corporate governance internal control” refers to the requirement in Appendix C1 that the board establish and maintain sound internal control systems. The code does not prescribe a specific internal control framework. Many Hong Kong listed issuers adopt the COSO Internal Control - Integrated Framework, the Turnbull Guidance or the Hong Kong Institute of Certified Public Accountants’ guidance. Any recognised framework is acceptable as long as it is applied consistently and the board can demonstrate that it has been used.

The board should ensure that internal controls cover:

  • Financial controls, including authorisation of transactions, segregation of duties, reconciliation processes and safeguarding of assets
  • Operational controls, including policies on delegation of authority, procurement, and project management
  • Compliance controls, ensuring adherence to the Listing Rules, the Securities and Futures Ordinance, the Companies Ordinance and other applicable law

The corporate governance report should describe the issuer’s internal control framework and any changes made during the year.

Hong Kong Board Oversight Risk Management Systems

“Hong kong board oversight risk management systems” describes the board’s continuing duty to monitor the effectiveness of the systems between annual reviews. That oversight takes several forms. Management reports to each board meeting on current risk exposures and any control failures. The audit committee reviews internal audit reports and management’s responses. The board conducts its own review of emerging risks that may affect the issuer’s business.

The board should also satisfy itself that the issuer has a whistleblowing policy and an anti-corruption policy. These are separate systems that support the internal control environment. Code Provision D.2.3 requires a whistleblowing policy and system for employees and external parties such as customers and suppliers to raise concerns in confidence and anonymity with the audit committee or a designated committee comprising a majority of independent non-executive directors. Code Provision D.2.4 requires policies and systems that promote and support anti-corruption laws and regulations.

Both provisions were upgraded from Recommended Best Practice to Code Provision on 1 January 2022 and renumbered on 1 July 2025. An issuer that departs from them must explain the departure in the corporate governance report.

Annual Review and Effectiveness Review

The board must conduct an annual review of the effectiveness of the issuer’s risk management and internal control systems. The review covers systems in place for the financial year under report and up to the date of the annual report where relevant.

The review should consider:

  • Whether management has identified and assessed the principal risks
  • Whether controls are designed to manage those risks to an acceptable level
  • Whether controls have been operating effectively during the year
  • Whether any control weaknesses have been identified and remediated
  • Whether the internal audit function, if one exists, has operated effectively

The corporate governance report must include a statement that the board has conducted such a review and describe the scope. If the review identified any material weaknesses, the report should disclose them and state the actions taken or planned.

Where the board has not reviewed the systems during the year because of exceptional circumstances, it should explain why and state when the next review will occur.

Audit Committee Role in the Risk Review

The audit committee ordinarily carries out the annual effectiveness review on the board’s behalf. Listing Rules require the audit committee to review the issuer’s financial controls, internal control and risk management systems unless the board has established a separate risk committee.

The audit committee should receive management’s assessment of the adequacy and effectiveness of internal controls. It should review the internal audit function’s work plan and findings. It should discuss with the external auditor where relevant. It should report its conclusions to the board.

If the audit committee identifies significant control deficiencies, it should escalate them to the board promptly. The board must then decide whether to disclose the deficiency and what remedial action to take.

Management’s Operational Role

Management runs the controls day to day. The board relies on management to design and document the internal control framework, implement it consistently, and flag issues for escalation.

Management should maintain a risk register identifying principal risks and the controls in place. It should report to the board or audit committee regularly on risk exposure and control effectiveness. It should implement remedial actions when control weaknesses are identified. It should ensure compliance with the whistleblowing and anti-corruption policies.

The board should satisfy itself that management has the resources and expertise to operate the systems effectively. Where the issuer’s operations are complex, management may engage external advisers to assist with the risk assessment.

Whistleblowing and Anti-Corruption Policies

Whistleblowing and anti-corruption policies are separate internal control systems that the board must ensure exist. They are not optional for listed issuers. They are code provisions that must be complied with or explained.

The whistleblowing policy must provide a channel for employees, customers, suppliers and other stakeholders to raise concerns in confidence and anonymity. The channel should allow concerns to reach the audit committee or a designated committee comprising a majority of independent non-executive directors. The policy should state how concerns will be investigated and what protection the issuer offers to whistleblowers.

Hong Kong has no general statutory whistleblower protection for the private sector. The protection that exists is piecemeal. Section 72B(1) of the Employment Ordinance (Cap. 57) prohibits dismissal for giving evidence in proceedings concerning a work accident or a breach of work safety law. Section 381 of the Securities and Futures Ordinance gives civil immunity to auditors who communicate in good faith with the SFC. An issuer’s whistleblowing policy should address this gap by stating the issuer’s commitment not to retaliate against whistleblowers.

The anti-corruption policy should cover the Prevention of Bribery Ordinance (Cap. 201), section 9, which prohibits corrupt transactions with agents. An issuer should communicate the policy to all employees and agents, provide training, and establish procedures for reporting suspected corruption. Code Provision D.2.4 requires these policies and systems to promote and support anti-corruption laws.

Corporate Governance Report Disclosure

The corporate governance report must include the statements required by the Mandatory Disclosure Requirements of Appendix C1. For risk management and internal control, the report should contain:

  • A statement that the board has conducted an annual review of the effectiveness of the issuer’s risk management and internal control systems
  • A description of the scope of that review
  • Any material weaknesses identified and the actions taken
  • Confirmation that the issuer has established a whistleblowing policy under code provision D.2.3
  • Confirmation that the issuer has established anti-corruption policies and systems under code provision D.2.4

The report should also disclose how the board exercises its oversight, including the role of the audit committee or risk committee, the frequency of management reporting, and the issuer’s approach to internal audit.

Scope of Review

The scope of the annual review is a required disclosure item. It tells shareholders and the Exchange what the board examined and what it did not.

A comprehensive scope might include the issuer’s principal risks and the controls in place to manage them. It might cover the design and operating effectiveness of financial controls. It might address compliance with applicable laws and regulations. It might examine the operation of the whistleblowing and anti-corruption policies. It might review the work of the internal audit function and management’s responsiveness.

A limited scope might be justified where the issuer’s operations are simple or where the board has relied on management’s self-assessment. The corporate governance report should explain any limitations.

Relevant Appendix C1 Provisions

The following provisions in Appendix C1 of the Main Board Listing Rules are the primary sources for risk management and internal control requirements:

  • Mandatory Disclosure Requirement paragraph L: the board must state in the corporate governance report that it has reviewed the effectiveness of the issuer’s risk management and internal control systems and describe the scope of the review
  • Code Provision D.2.1: the board is responsible for risk management and internal control systems and must review their effectiveness at least annually through the audit committee or a separate risk committee
  • Code Provision D.2.3: the issuer should establish a whistleblowing policy and system for employees and external parties to raise concerns in confidence and anonymity with the audit committee or a designated committee
  • Code Provision D.2.4: the issuer should establish policies and systems that promote and support anti-corruption laws and regulations

These provisions apply to financial years commencing on or after 1 July 2025 following the December 2024 consultation conclusions. Issuers should check the effective date for their reporting year and apply the version in force at that time.

Sources

More on corporate governance.