The Risk Management Committee of a recognized exchange controller
The SFO requires a recognized exchange controller to establish a Risk Management Committee.
More key points
- It formulates risk-management policies for the controller and specified controlled exchange companies or clearing houses, then submits those policies to the controller for consideration.
On this page12 sections
- The statutory function
- Composition and independence
- What kinds of risk does it address?
- Avoid these exam mix-ups
- Committee purpose and coverage
- Policy formulation is not day-to-day operation
- Why the group perspective matters
- Governance and escalation
- A resilience example
- Exam distinction
- How policy oversight connects to resilience
- Document the route from proposal to action
A major exchange group operates connected markets and clearing systems. The Securities and Futures Ordinance therefore sets a governance structure for considering risks across the recognized exchange controller and the market infrastructure it controls.
The statutory function
Under section 65 of the SFO, a recognized exchange controller must establish and maintain a committee called the Risk Management Committee. Its statutory function is to formulate policies on risk-management matters relating to the controller's activities and those of any recognized exchange company or recognized clearing house that it controls. The committee submits those policies to the controller for consideration.
That wording matters. The committee develops and submits policy; it does not replace the controller's decision-making body or perform every operational risk task itself. Nor is its mandate limited to the risks of a single trading venue if the controller also controls a recognized clearing house.
Composition and independence
Section 65 specifies a mixed composition. The recognized exchange controller's chairman chairs the committee. The statutory membership also includes members drawn from the controller's board and persons appointed by the SFC, with the precise number and appointment details set out in the current Ordinance. The SFC-appointed members are intended to bring independent public-interest perspectives into the risk-policy process.
For exam purposes, distinguish this committee from an ordinary internal committee whose membership is chosen only under company policy. Its existence and framework are prescribed by legislation, and the SFC has a defined role in appointments.
What kinds of risk does it address?
The SFO describes a policy-formulation responsibility rather than an exhaustive list of risks in this section. Relevant matters can arise from operating trading systems, maintaining orderly markets, clearing and settlement, financial resources, business continuity, and connections among group entities. The controlling question is whether the risk relates to activities within the statutory scope.
Avoid these exam mix-ups
- The committee formulates risk-management policies; the recognized exchange controller considers them.
- The scope includes the controller and specified recognized exchange companies or clearing houses it controls.
- The SFC's appointment role does not make the committee a separate regulator or market operator.
- Do not substitute a licensed corporation's internal risk committee for the statutory committee required of a recognized exchange controller.
When reading a question, identify the legal entity first. ‘Recognized exchange controller,’ ‘recognized exchange company,’ and ‘recognized clearing house’ are different statuses, even when they sit within one corporate group. Then look for the verb: formulate, submit, consider, supervise, or operate. The allocation of responsibility is usually the tested point.
Committee purpose and coverage
SFO section 65 requires a recognized exchange controller to establish a Risk Management Committee. Its purpose is to formulate risk-management policies for the controller and specified exchange companies or clearing houses that it controls, and submit those policies to the controller for consideration. This statutory architecture places risk oversight at group and market-infrastructure level, where stress in one entity can affect trading, clearing or settlement elsewhere.
Policy formulation is not day-to-day operation
The committee’s policy role should be distinguished from the operating responsibilities of the exchange controller, exchange companies and clearing houses. It considers the risk framework and submits policies; the entities still need to implement controls, monitor exposures and respond to incidents under their own legal and operational responsibilities. Do not describe the committee as the SFC or as the body that directly supervises every broker or listed issuer.
Why the group perspective matters
Market infrastructure risks can travel across legal entities. A trading disruption may create unsettled trades; a clearing member default can affect liquidity and risk resources; a technology incident can impair several services at once. Policies should therefore address how exposures are identified, communicated and controlled across the relevant entities. The committee framework supports coordination, while the legal duties of each recognized entity remain important.
Governance and escalation
A robust committee process uses timely management information, clear terms of reference, documented policy reviews and a route for material concerns to reach the controller’s governing body. It should be possible to see how a proposed policy was considered, approved or amended, and how material weaknesses are reported. A committee that meets but receives incomplete risk information cannot perform meaningful oversight. Read section 65 with the controller’s applicable recognition conditions and rulebook.
A resilience example
Consider a clearing-system outage that delays settlement while market prices are moving. The risk committee’s policies should help the controller understand how the affected entities coordinate incident escalation, liquidity monitoring, recovery priorities and communications. The operational team handles the event, but the policy framework determines who reports, what thresholds matter and how interdependencies are addressed. A post-incident review can reveal whether assumptions about backup capacity or participant readiness were realistic and whether policy changes are needed.
Exam distinction
For questions on section 65, identify the regulated subject as the recognized exchange controller, the required body as the Risk Management Committee, and its policy-formulation and submission role. Then distinguish policy oversight from SFC statutory supervision, HKEX front-line functions and the operational risk duties of exchange companies and clearing houses.
How policy oversight connects to resilience
Risk policy should address how the controller and relevant entities identify interdependencies, monitor limits, manage defaults and restore critical services after disruption. Scenario analysis can test whether liquidity resources, settlement processes, communications and recovery arrangements remain adequate under stress. The committee’s policy role makes cross-entity questions visible to the controller, while the operating units provide the data and carry out approved measures. These arrangements are especially important where a disruption in one service can cascade to trading, clearing or settlement.
Document the route from proposal to action
Policy papers should state the risk being addressed, the entities covered, the control owner, reporting measure and escalation route. The committee’s consideration and the controller’s decision should be recorded so that a later reviewer can trace how a material issue was handled. If policies are not adopted as proposed, record the rationale and any alternative control. This makes oversight accountable and lets the group test whether policy is operating in practice.
Common questions
Who establishes the Risk Management Committee?
The recognized exchange controller must establish and maintain it under SFO section 65.
Does the committee itself approve its policies?
It formulates risk-management policies and submits them to the recognized exchange controller for consideration.
Does its scope include a controlled clearing house?
Yes. Section 65 includes activities of a recognized clearing house controlled by the recognized exchange controller.
Does the committee regulate individual brokers?
No. Its section 65 role concerns risk policies for the controller and specified controlled entities.
Does the committee implement every control?
Its statutory role is policy formulation and submission; operational responsibilities remain with the relevant entities.
Why are clearing houses included?
Clearing and settlement risks can interact with exchange operations and market stability.