Practice
Risk Governance
Aspect contributions
How this practice contributes to the green port aspects.
| Aspect | Role | Justification |
|---|---|---|
| Risk Management | Core | - |
| Regulatory Compliance | Secondary | Risk governance supports regulatory compliance oversight at board level |
| Financing (Green & Sustainable) | Secondary | Strong governance practices support investor confidence and access to capital |
| Social Licence and Community Engagement | Secondary | Board level oversight includes reputational and social licence risks |
Summary
Risk governance provides oversight and accountability for risk management at senior leadership and board levels. This may include, among others, board or audit and risk committee oversight, regular reporting on strategic and emerging risks, clear roles and responsibilities for risk management, integration of risk considerations into major decisions, and independent review or assurance of risk processes.
For DMC ports, strong risk governance can strengthen accountability for safety and environmental performance, improve transparency and stakeholder confidence, support compliance with governance leading practice, and enable timely responses to emerging threats. State owned and private port operators in the region are progressively strengthening risk governance structures in response to regulatory requirements and investor expectations.
Details
Risk governance refers to the structures, processes, and accountabilities through which an organization's highest levels of management oversee and direct risk management activities. Effective risk governance helps to ensure that risk considerations inform strategic decisions, that material risks receive appropriate senior attention, and that risk management processes are independently reviewed and challenged.
Typical elements of port risk governance include a board committee with explicit risk oversight responsibilities (such as an Audit and Risk Committee or Board Risk Committee), regular management reporting on the risk register and emerging risks, integration of risk assessments into capital allocation and major project decisions, and independent assurance of risk management processes through internal or external audit.
Risk appetite and tolerance statements approved by the board establish the boundaries within which management may accept risk in pursuit of strategic objectives. Escalation protocols support the elevation of risks exceeding tolerance thresholds to senior management or the board for decision. For ports operating in complex regulatory or stakeholder environments, risk governance may also include board level attention to reputational, social licence, and community engagement risks.
Integration of environmental, social, and governance (ESG) factors into risk governance is an emerging expectation from investors, lenders, and regulators. The IFRS S1 and IFRS S2 standards issued by the International Sustainability Standards Board (ISSB) require disclosure of how boards oversee sustainability related risks and opportunities, including specific climate related governance arrangements (IFRS Foundation, 2023). Port organizations subject to these standards, or to equivalent national requirements such as Australia's AASB S2 standard, mandatory for Group 1 entities for annual reporting periods beginning on or after 1 January 2025, must disclose their board level climate governance arrangements (AASB, 2024).
In the ASEAN region, state owned port operators including PT Pelabuhan Indonesia (Pelindo) and the Port Authority of Thailand apply risk governance frameworks; for example, Pelindo's 2024 risk assessment followed Indonesian state owned enterprise regulations (Pelindo, 2025b). Listed port operators are subject to corporate governance codes requiring board oversight of material risks. For smaller or government operated ports, risk governance structures may be more informal but should still include documented accountability for key risks and regular reporting to senior management.
Enabling factors
National corporate governance codes; state owned enterprise regulations; stock exchange listing requirements; IFRS S1 and IFRS S2 disclosure standards.
Board reporting platforms; governance, risk, and compliance (GRC) software; audit management systems.
Not directly applicable
External audit firms; industry associations for governance benchmarking; engagement with national regulatory bodies.