Home / Blog / Stakeholders Relationship Committee & Risk Management Committee: The Two Board Committees That Can Delay Your IPO (2026)

Stakeholders Relationship Committee & Risk Management Committee: The Two Board Committees That Can Delay Your IPO (2026)

Written by , a Practising Company Secretary based in Bengaluru — advising companies and startups on company incorporation, secretarial audit, ROC & FEMA compliance, and corporate governance.

By CS Sapna Malpani, Practising Company Secretary, Bangalore | Last updated 22 July 2026

In 2025 the National Stock Exchange sent penalty notices to roughly 250 listed companies for Listing Obligations and Disclosure Requirements lapses, and a recurring line item on those notices was a board committee that was either not constituted or wrongly composed. Under the SEBI Standard Operating Procedure the meter runs at Rs 2,000 a day until the entity fixes it. For an unlisted public company that crosses one thousand security holders, the parallel failure carries a fixed Rs 5 lakh penalty on the company and Rs 1 lakh on every officer in default under Section 178(8). Most founders preparing to list have sorted out the Audit Committee and the Nomination and Remuneration Committee. The two that get left to the last week before the DRHP are the Stakeholders Relationship Committee (Regulation 20 read with Section 178(5)) and the Risk Management Committee (Regulation 21).

TL;DR
Who must comply: Every listed entity (SRC under Reg 20); the top 1000 listed entities by market cap plus high value debt listed entities (RMC under Reg 21); and any company with more than 1,000 security holders in a financial year (SRC under Section 178(5)).
Deadline: Both committees must exist and be correctly composed before listing, because the DRHP discloses their composition and merchant bankers verify it in due diligence.
Penalty: Rs 2,000 per day under the SEBI SOP for a listed entity; Rs 5 lakh on the company and Rs 1 lakh per defaulting officer under Section 178(8) for the Companies Act route; plus promoter shareholding freeze for continued default.
Key action: Constitute both, put a non-executive director in the SRC chair and at least one independent director on each, and diarise the meeting cadence.
Time to act: Fix this 12 months before you file, not in the DRHP fortnight.

The problem: two committees that are neither Audit nor NRC

When a private company converts to public and heads towards a listing, its board committee obligations multiply. The Audit Committee under Section 177 and Regulation 18, and the Nomination and Remuneration Committee under Section 178(1) to (4) and Regulation 19, get the attention because their names come up first and their roles feel familiar. I covered both, and the Rs 39 lakh composition mistake that follows from getting them wrong, in an earlier guide on Audit Committee and NRC composition.

The Stakeholders Relationship Committee and the Risk Management Committee sit in the same Section 178 and the same LODR chapter, yet they run on different triggers, different composition rules and different meeting rhythms. A company can have a textbook Audit Committee and still fail its secretarial audit because the SRC chair is an executive director, or because the RMC was never constituted even though the company sits inside the top 1000 by market capitalisation. These are exactly the findings that surface in a Section 204 secretarial audit report and that a book-running lead manager flags during pre-issue due diligence. A qualified secretarial audit report is not the note you want a merchant banker reading three weeks before your DRHP goes in.

Diagram 1: The four board committees at a glance

Here is where the Stakeholders Relationship Committee and the Risk Management Committee sit relative to the two committees most companies already have.

Committee Trigger / who must have it Composition Chair Meeting cadence
Audit Committee
(Sec 177 / Reg 18)
Listed entities; prescribed public companies Min 3 directors, majority independent Independent director At least 4 times a year, gap ≤ 120 days
NRC
(Sec 178(1) / Reg 19)
Listed entities; prescribed public companies Min 3 non-executive directors, at least half independent Independent director At least once a year
Stakeholders Relationship Committee
(Sec 178(5) / Reg 20)
Every listed entity; any company with >1,000 security holders in a FY At least 3 directors, at least 1 independent (for a listed entity) Non-executive director At least once a year
Risk Management Committee
(Reg 21)
Top 1000 listed entities by market cap; high value debt listed entities Min 3 members, majority board directors, at least 1 independent Board member (senior executives may be members) At least twice a year, gap ≤ 180 days

Composition figures for the Audit Committee and NRC are summarised here for context; the two committees this guide focuses on are the SRC and the RMC.

Stakeholders Relationship Committee: the grievance committee with a non-executive chair rule

Regulation 20 requires every listed entity to constitute a Stakeholders Relationship Committee to look into the redressal of grievances of shareholders, debenture holders and other security holders. The composition rule is the one companies trip on: at least three directors, with at least one being an independent director, and the chairperson must be a non-executive director. If a listed entity has outstanding superior voting rights (SR) equity shares, at least two-thirds of the committee must be independent directors. The committee must meet at least once a year, and its chairperson has to be present at the annual general meeting to answer security holders’ questions directly.

The Companies Act sets its own, wider trigger. Section 178(5) says the board of a company with more than one thousand shareholders, debenture holders, deposit holders and any other security holders at any time during a financial year must constitute an SRC with a chairperson who is a non-executive director. This catches unlisted public companies that have raised money from a large base (a rights issue, an NCD programme or a deposit scheme) long before any listing. The role, under Section 178(6), is to consider and resolve the grievances of security holders: transfer and transmission of shares, non-receipt of the annual report, non-receipt of declared dividends, issue of duplicate certificates, and the reduction of unclaimed dividends.

There is one sensible carve-out. The proviso to Section 178(8) states that non-consideration of a grievance by the SRC in good faith does not, by itself, amount to a contravention. The committee is judged on whether it exists and functions in good faith, not on whether it resolves every complaint to the complainant’s satisfaction. Section 178 also does not apply to Section 8 companies (that are not in default) or to specified IFSC public companies.

Risk Management Committee: the top-1000 committee founders assume they are too small for

Regulation 21 requires the board to constitute a Risk Management Committee with a minimum of three members, the majority of whom are members of the board, including at least one independent director. Where the entity has outstanding SR equity shares, at least two-thirds of the RMC must be independent directors. The chairperson has to be a board member, though senior executives of the company may sit on the committee. The RMC must meet at least twice a year, and no more than 180 days may pass between two consecutive meetings. Quorum is two members or one-third of the committee, whichever is higher, with at least one board member present.

Applicability is the part that surprises people. Regulation 21 applies to the top 1000 listed entities determined by market capitalisation as at the end of the immediately preceding financial year, and to high value debt listed entities. When the rule first came in it applied only to the top 100, then the top 500; the Second Amendment of 2021 (notified 5 May 2021) widened it to the top 1000. A company that lists at a healthy valuation can find itself inside the top 1000 in its first year and inside Regulation 21 from that point, so the RMC is a going-concern obligation for a newly listed company, not a large-cap luxury.

The committee’s job is spelt out in Part D of Schedule II. It must formulate a risk management policy covering financial, operational, sectoral, sustainability (including ESG), information and cyber security risks, along with mitigation measures and a business continuity plan. That policy has to be reviewed at least once every two years. Where a company appoints a Chief Risk Officer, that appointment, removal and remuneration are subject to the RMC’s review.

Rs 2,000per day SEBI SOP fine for non-constitution (Reg 21/20)
Rs 5 lakhcompany penalty under Section 178(8)
Top 1000listed entities inside Regulation 21
>1,000security holders triggers SRC under Sec 178(5)

What non-compliance actually costs

There are two enforcement tracks, and an IPO-bound company can be exposed to both in sequence: the Companies Act penalty while it is an unlisted public company, and the SEBI SOP once it lists.

Route Provision Consequence
Companies Act (SRC / audit / NRC failure) Section 178(8) Rs 5,00,000 penalty on the company and Rs 1,00,000 on every officer in default
SEBI LODR (committee not constituted) SOP under the SEBI Master Circular on non-compliance Rs 2,000 per day of default, recovered by the stock exchange
Continued LODR default SEBI SOP Freezing of the entire promoter and promoter group shareholding until compliance and payment
Repetitive LODR default SEBI SOP Suspension of trading in the entity’s securities
Governance gap at listing Section 204 secretarial audit + BRLM due diligence Qualified secretarial audit report; DRHP query; timeline slip

The SEBI SOP fine looks small until you count the days. A committee that should have been constituted at the start of the financial year but is fixed only after the annual secretarial audit flags it, say 210 days later, attracts a fine of over Rs 4 lakh before a single show-cause reply is drafted, and the promoter shareholding freeze is the part that actually changes behaviour, because a frozen promoter block stalls pledges, transfers and follow-on plans.

Diagram 2: Getting both committees in place before you file

T minus 12 months, Map your security holder count and market-cap position. If you already have more than 1,000 security holders, the SRC is due now under Section 178(5), listing or not.
T minus 10 months, Fix board composition first. You need enough independent directors to populate the Audit Committee, NRC, SRC and, if applicable, the RMC without the same person carrying every seat. Board composition and independent director requirements is the prerequisite step.
T minus 9 months, Pass board resolutions constituting the SRC (non-executive chair) and the RMC (board-member chair, at least one independent director), and adopt terms of reference mirroring Part D of Schedule II.
T minus 8 months, Adopt the risk management policy (financial, operational, ESG, cyber, business continuity) and the grievance redressal framework, and appoint a Registrar and Share Transfer Agent if not already in place.
T minus 6 to 1 months, Run the meeting cadence: SRC at least once, RMC at least twice with no gap over 180 days, minutes filed, so there is a real track record in the DRHP, not a committee that exists only on paper.

What you must do now

A short, ordered checklist for a board and its company secretary preparing either for a large security holder base or for a listing.

  1. Count your security holders across the whole year. Section 178(5) is triggered by more than 1,000 holders at any time during a financial year, not on the last day. A rights issue or NCD allotment that briefly pushed you past 1,000 counts.
  2. Check your market-cap rank if listed. Regulation 21 keys off the top 1000 by market capitalisation at the end of the previous financial year. If you are close to the line, assume you are in and constitute the RMC.
  3. Put a non-executive director in the SRC chair. This is the single most common defect. An executive or managing director chairing the SRC is a straight Regulation 20 and Section 178(5) breach.
  4. Place at least one independent director on each committee. For a listed SRC, at least one independent director; for the RMC, majority board members with at least one independent director. Where SR equity shares exist, two-thirds must be independent.
  5. Adopt written terms of reference. Mirror Part D of Schedule II for both committees, and the risk policy must expressly cover ESG and cyber security risks and a business continuity plan.
  6. Diarise the cadence. SRC at least annually; RMC at least twice a year with no more than 180 days between meetings. Set the calendar for the year and hold to it.
  7. Have the SRC chair attend the AGM. Regulation 20 and Section 178(7) require the chair to be present to answer security holders. Record the attendance in the minutes.
  8. Review the risk policy every two years. Put the review date in the compliance calendar so it is not missed in year three.
  9. Reconcile against your secretarial audit. Ask your Section 204 auditor to confirm both committees pass on composition, quorum and cadence before the DRHP is drafted.

The deeper implication

According to CS Sapna Malpani, the pattern she sees in pre-IPO reviews is not companies ignoring committees, it is companies treating all committees as one task and copying the Audit Committee composition onto the others. The SRC and RMC have deliberately different rules. The non-executive chair on the SRC exists so grievance handling is not controlled by the same executives whose conduct might be complained about, and the board-heavy RMC exists so risk oversight is not delegated wholesale to management. Copy-pasting the Audit Committee template onto them defeats both purposes and produces a technically constituted but non-compliant committee.

The direction of travel is towards more, not fewer, committee obligations. SEBI has already widened Regulation 21 from the top 100 to the top 1000 and has been layering ESG and cyber risk into the RMC’s mandate. A company that builds a genuine committee track record a year before filing, rather than constituting on paper in the DRHP fortnight, will clear due diligence faster and carry a cleaner secretarial audit into the issue.

Three points of confusion are worth settling. First, the Audit Committee and NRC live in Section 177 and Section 178(1) to (4); the SRC lives in Section 178(5) to (7). Same section number, different sub-sections and different rules, do not assume that constituting an NRC discharges your SRC obligation. Second, the RMC is a creature of SEBI LODR (Regulation 21) and, unlike the SRC, has no direct Companies Act penalty; its enforcement runs entirely through the SEBI SOP and the stock exchange. Third, the SRC’s Companies Act trigger (Section 178(5), more than 1,000 security holders) reaches unlisted public companies that the LODR never touches, which is why a large private-to-public company can owe an SRC well before it owes anything under Regulation 20.

Key takeaways

  • ✓ SRC is mandatory for every listed entity (Reg 20) and for any company with more than 1,000 security holders in a financial year (Section 178(5)).
  • ✓ The SRC chairperson must be a non-executive director, the defect most often flagged in secretarial audit.
  • ✓ RMC is mandatory for the top 1000 listed entities by market cap and for high value debt listed entities under Regulation 21.
  • ✓ RMC must meet at least twice a year with no gap over 180 days; SRC at least once a year.
  • ✓ Section 178(8) penalty for SRC/audit/NRC failure: Rs 5 lakh on the company and Rs 1 lakh on every officer in default.
  • ✓ SEBI SOP fine for a listed entity failing to constitute a committee: Rs 2,000 per day, escalating to a promoter shareholding freeze.
  • ✓ The RMC risk policy must cover ESG and cyber security risks and a business continuity plan, reviewed at least once in two years.
  • ✓ Fix committee composition 12 months before filing, not in the DRHP fortnight.

Sources and references

Preparing for a listing or crossing 1,000 security holders?
Get your board committee composition reviewed before it reaches your secretarial auditor or a merchant banker. Start with the pre-IPO compliance checklist and 12-month countdown and the SEBI ICDR pre-IPO and DRHP readiness guide. For a committee-by-committee review, message CS Sapna Malpani directly on WhatsApp.

Frequently asked questions

What is the difference between the Stakeholders Relationship Committee and the Risk Management Committee?

The Stakeholders Relationship Committee handles security holder grievances (share transfers, non-receipt of dividends or annual reports, duplicate certificates) under Regulation 20 and Section 178(5), and its chairperson must be a non-executive director. The Risk Management Committee oversees the company’s risk framework, including financial, operational, ESG and cyber risks, under Regulation 21, and applies only to the top 1000 listed entities and high value debt listed entities. The SRC has a Companies Act trigger that also catches unlisted companies with more than 1,000 security holders; the RMC is purely a SEBI LODR obligation.

Which companies must constitute a Risk Management Committee under Regulation 21?

Regulation 21 applies to the top 1000 listed entities determined by market capitalisation as at the end of the immediately preceding financial year, and to high value debt listed entities. The committee needs a minimum of three members, the majority being board directors, including at least one independent director, and it must meet at least twice a year with no more than 180 days between two meetings. A newly listed company that enters the top 1000 in its first year comes within Regulation 21 from that point.

When does Section 178(5) require an unlisted company to form a Stakeholders Relationship Committee?

Section 178(5) requires the board of a company with more than one thousand shareholders, debenture holders, deposit holders or any other security holders at any time during a financial year to constitute a Stakeholders Relationship Committee, chaired by a non-executive director. The count is tested across the whole year, so a rights issue or NCD allotment that briefly pushes the holder base past 1,000 triggers the obligation even for an unlisted public company that is nowhere near a listing.

What is the penalty for not constituting a Stakeholders Relationship Committee?

Under Section 178(8) of the Companies Act, contravention of Section 177 or Section 178 makes the company liable to a penalty of Rs 5 lakh and every officer in default liable to Rs 1 lakh. For a listed entity, the SEBI Standard Operating Procedure imposes a fine of Rs 2,000 per day of default recovered by the stock exchange, and continued non-compliance can lead to freezing of the entire promoter and promoter group shareholding until the entity complies and pays.

Can the same person chair the Audit Committee and the Stakeholders Relationship Committee?

The rules do not bar overlap in membership, but the chair requirements differ and often force different people. The Audit Committee chair must be an independent director, while the Stakeholders Relationship Committee chair must be a non-executive director. An independent director is a non-executive director, so one person could technically chair both, but boards preparing for a listing usually separate them to spread committee load and demonstrate genuine oversight rather than one director wearing every hat.

How often must these committees meet, and does it matter for an IPO?

The Stakeholders Relationship Committee must meet at least once a year, and its chair must attend the AGM. The Risk Management Committee must meet at least twice a year with no more than 180 days between meetings. It matters for an IPO because the DRHP discloses committee composition and meeting history, and a book-running lead manager’s due diligence checks that the committees actually met rather than existing only on paper. A real meeting track record built a year ahead reads very differently from a committee constituted in the filing fortnight.

Need Board Governance Support?

Guidance on establishing and maintaining effective board procedures