In short: Risk management is management’s operational job; risk governance is the board’s oversight of it. King V requires the governing body to govern risk in support of strategy, and section 76(3) of the Companies Act makes failing to oversee a breach of the duty of care. The board must retain four things it cannot delegate: setting risk appetite, approving the framework, overseeing effectiveness, and holding management accountable - and delegating to a risk or audit committee never transfers accountability. A board crosses the line in two ways: over-reach (directing how controls are built) and the more common abdication (noting the report and moving on). The correct position is to ask and verify, never to execute and never to rubber-stamp.
In December 2017, a South African company that had grown into one of the largest retailers on the JSE lost the overwhelming majority of its value in a matter of days. Steinhoff. The forensic reports that followed did not describe a board that lacked a risk function. There was a risk framework. There were committees. What the reports described was a board that did not effectively govern risk: it received information but did not interrogate it, it trusted but did not verify. Here is the uncomfortable truth for every non-executive director. The board is not expected to manage risk. But the board is absolutely accountable when risk governance fails. That is where directors get caught, and it is exactly the line this article draws.
Two different jobs
Risk management is what management does: the operational work of identifying risks, assessing them, putting controls in place, and running those controls day to day. It is executed by the chief executive, the executive team, the risk function and control owners. It is hands-on, continuous and operational. Risk governance is what the board does: the exercise of oversight over that management activity. The board does not run the controls. It makes sure there is a system, that the system is adequate and effective, that it aligns with the organisation’s risk appetite, and that management is held accountable for operating it. King V anchors this: the governing body should govern risk in a way that supports the organisation in setting and achieving its strategic objectives. Note the verb, govern, not manage. King IV framed the same duty before it, and King V carries that architecture forward. The Companies Act sharpens the personal stakes: under section 76(3) of the Companies Act 71 of 2008, a director must act in good faith and in the best interests of the company, and with the degree of care, skill and diligence that may reasonably be expected of a person carrying out those functions. Oversight of risk is one of those functions, and failing to oversee is a failure of the duty of care.
What the board must retain
If governance is oversight, what must the board keep? Four responsibilities that cannot be delegated away. First, setting the risk appetite: the board decides how much risk the organisation will accept in pursuit of its strategy, and management cannot set its own boundaries. Second, approving the risk management framework and policy: the board does not build it, but it approves it and satisfies itself that it is fit for purpose. Third, overseeing effectiveness: the board must receive assurance, from management, from internal audit and from external providers, that controls are actually working and not merely written down. This is where Steinhoff failed. Fourth, accountability: when management reports, the board’s job is to interrogate, not to absorb and execute. Most of this is discharged through a risk committee, or in smaller organisations an audit committee carrying the risk mandate, but delegation to a committee does not delegate accountability. A committee prepares and recommends; the full board owns, and remains responsible under section 76.
Two ways to cross the line
Now the heart of it. There are two ways a board crosses the line, and directors usually worry about only one. The first is over-reach: a well-meaning director starts directing how a specific control should be built, redesigns the operational risk process, or instructs a manager directly outside the reporting line. This is not diligence, it is interference. It undermines the executive, blurs accountability and, ironically, exposes directors more, because they can no longer say they oversaw an independent management function. They became management. The second failure, and the far more common one, is abdication: the board receives the risk report, notes it, and moves on. No challenge, no probing question, no request for independent assurance. This is the rubber stamp. It feels like respecting management’s domain, but it is a failure of governance, and it is precisely the failure courts and regulators punish. The line is drawn correctly when the board asks and verifies rather than executes or observes. Oversight asks and verifies; management designs and executes. The moment a director stops asking and starts executing, they have crossed the line. The moment a director stops asking altogether, they have abandoned it.
The wall of green
Put yourself in the room. You are a non-executive director on the risk committee of a mid-cap JSE-listed company. Management tables the quarterly risk report and the dashboard is a wall of green. The chief risk officer says all key controls are operating effectively, no material issues this quarter. The abdication response, tempting when the agenda is running long, is: “Thank you. Noted. Next item.” The over-reach response is: “Green? I don’t believe it. Show me the raw incident logs and I will tell your team how to fix the controls.” You have now taken over management’s job. The governance response sits on the line. You ask what assurance underpins the green rating, whether it is management’s self-assessment or whether internal audit independently tested the controls this quarter, which risks moved and why, and whether any risk is within tolerance today but trending toward the appetite limit. You are not managing the controls; you are testing the credibility of the assurance and holding management accountable for the honesty of the report. That is risk governance, and it is section 76 care, skill and diligence discharged in practice.
The habit to build
In your next board or risk committee meeting, when management reports that risk is “under control”, do not accept it and do not take it over. Ask what independent assurance proves it, and hold management accountable for the answer. Govern risk by asking and verifying, never by executing and never by rubber-stamping. That single discipline is the difference between a board that oversees and a board that, like Steinhoff’s, discovers too late that it received information it never interrogated.
Does your board sit on the line, or over it?
BoardEvaluator™ assesses how the board as a whole governs risk - whether it interrogates assurance, respects the boundary with management, and records the questions it asks - and produces a structured, evidence-based view of where oversight is strong and where it drifts into abdication or over-reach.
See the Board-as-a-Whole evaluation →Frequently asked questions
Risk management is what management does - identifying and assessing risks, designing controls and running them day to day. Risk governance is what the board does - setting risk appetite, approving the framework, overseeing effectiveness and holding management accountable. King V puts it precisely: the governing body should govern risk, not manage it. The board makes sure there is an adequate system; it does not operate the controls.
It can delegate the work of preparing and recommending, but not the accountability. Delegation to a committee does not delegate accountability - the full board remains responsible under section 76 of the Companies Act. A committee prepares and recommends; the board owns.
Over-reach and abdication. Over-reach is when a director starts directing how a control should be built or instructs staff outside the reporting line - that is interference, and it actually increases a director’s exposure. Abdication, the more common failure, is receiving the risk report, noting it, and moving on without challenge or independent assurance. That is the rubber stamp, and it is the failure courts and regulators punish.
Not by accepting it (abdication) and not by taking over the controls (over-reach). The governance response sits on the line: ask what assurance underpins the green rating - management’s self-assessment or independent internal-audit testing - which risks moved and why, and whether any risk is trending toward the appetite limit. You are testing the credibility of the assurance, not managing the controls.
It can. Section 76(3) of the Companies Act 71 of 2008 requires directors to act with the degree of care, skill and diligence reasonably expected. Oversight of risk is one of those functions, so failing to oversee - whether by interfering or by rubber-stamping - is a failure of the duty of care. Steinhoff is the cautionary example of a board that received information it did not interrogate.