Business

The Biggest Enterprise Risk Trends Indian CFOs and Boards Should Watch in 2027

12 min read Expert verified

The audit committee meeting is three weeks away. The risk register covers the operational, financial and compliance risks the business has tracked for years but some of the risks now demanding attention are changing.

An ERP upgrade may have changed user access and segregation of duties. AI tools may now be handling parts of finance or operations. Customers may be asking for ESG and sustainability data. Critical vendors may have become dependencies for technology, operations or business continuity. At the same time, lenders, investors and boards are expecting stronger governance as companies grow.

This is the reality many enterprises face heading into 2027. Regulatory requirements are evolving, technology is changing the control environment, third parties are becoming part of the risk perimeter and stakeholder expectations are rising across industries.

CFOs and finance leaders understand that these can affect financial reporting, compliance, operations, customer relationships and access to capital. 

This PKC blog examines what is changing, what it means for your business and what you should address before year-end.

TL;DR ESG and sustainability data requests are increasingly reaching companies through customers and value chainsERP, automation and AI adoption are creating new access, data and control risksThird-party risks now include cybersecurity, business continuity, concentration and complianceGovernance expectations are rising as companies grow, raise capital and work with larger customersThe Income-tax Act, 2025 requires finance teams to review systems, processes and documentationBoards should use four practical questions to identify where existing controls may no longer be sufficient

Why Enterprise Risk Priorities Are Shifting Heading Into 2027

For many mid-sized and growing companies, risk management has traditionally focused on cost control, working capital, statutory compliance and the annual financial audit. These areas remain important, but they no longer capture the full range of risks created by technology, customers, suppliers, regulation and changing stakeholder expectations.

Three forces are changing what boards, CFOs, auditors, lenders and investors expect.

1. Internal Controls Are Facing Greater Scrutiny: 

The Companies Act, 2013 requires qualifying companies to maintain formal internal financial controls. Auditors now focus on whether these controls work in practice and whether the company has written policies.

For multi-location manufacturers, this means testing controls such as purchase approvals, inventory checks, segregation of duties and financial reporting across plants, not just at head office.

2. Technology Is Expanding The Control Environment: 

ERP upgrades, cloud migration, automation and AI tools can introduce risks involving user access, data integrity, system integrations and audit trails. 

A control framework designed for a two-plant business may no longer be adequate after expansion to four plants and multiple connected systems.

3. Stakeholder Expectations Are Broadening: 

Large customers, lenders and investors increasingly examine cybersecurity, supply-chain controls, ESG information, business continuity and governance practices. 

An unlisted supplier does not have to comply with BRSR automatically. However, listed customers may ask for ESG and value-chain information for their own reporting.

For CFOs and audit committees, the question to ask for 2027 is: Can our controls stand up to scrutiny from a major customer, lender, investor or auditor tomorrow?

That scrutiny may not come in the form of a traditional financial audit. A lender may ask for evidence supporting financial or operational information, a customer may review supplier controls and ESG data. 

An investor or potential acquirer may test whether reported numbers, processes and system controls can be relied upon during due diligence. An auditor may identify weaknesses that have existed for years but were never formally tested.

So, control readiness needs to be treated as an ongoing management responsibility. 

The solution starts with updating the risk register, testing controls across locations, reviewing system access and segregation of duties, and closing gaps before they surface during an audit, customer review or due diligence process.

ESG and BRSR Disclosure Moving Down-Market to Mid-Sized Companies

Business Responsibility and Sustainability Reporting (BRSR) is a SEBI reporting framework that applies directly to India’s top 1,000 listed entities by market capitalization. 

An unlisted mid-sized manufacturer does not have to file BRSR. However, BRSR requirements can still affect the business through its customers and commercial relationships.

SEBI’s framework allows qualifying listed companies to seek ESG information from significant upstream and downstream value-chain partners. 

The current framework identifies partners contributing 2% or more of the listed entity’s purchases or sales by value, with the listed entity able to limit coverage to 75% of purchases and sales. SEBI has also clarified that value-chain ESG disclosures are voluntary for listed entities from FY 2025-26, following the 2025 changes.

For Example: an auto-component, engineering, chemical or industrial supplier may receive customer questionnaires covering energy consumption, water use, waste management, emissions, workforce information, safety incidents or supply-chain practices. 

These requests can come from different customers, each using slightly different formats, definitions or reporting periods. If the underlying ESG information is not maintained consistently, the same data may be calculated differently across plants or reported differently from one customer to another. 

Over time, this can make it difficult to reconcile current figures with prior-year numbers or provide reliable supporting evidence when a customer asks for it.

The mistake is to treat each request as a one-off form. A better approach is to establish a basic process for collecting, reviewing and retaining the underlying ESG data, so that the same information can be used consistently across customer questionnaires, audits and reporting requirements.

You do not need to build a full BRSR reporting function. Start with basic ESG data governance. Assign ownership, define consistent measurement methods and maintain a simple record of energy, water, waste, safety and workforce metrics for each factory.

This creates a reliable baseline before a major customer asks for the information. It also reduces the scramble during customer audits, supplier assessments, financing discussions or future sustainability reporting requirements.

Data and IT-Control Risk as ERP and AI Adoption Accelerates

ERP consolidation and AI adoption are improving efficiency for enterprises, but they are also changing where control risks lie. This is especially important for businesses operating multiple plants on a single ERP instance.

An ERP migration or upgrade can reset user permissions, and temporary go-live access can sometimes remain in place long after implementation. This can create conflicts between roles that were previously kept separate, particularly when access is granted quickly to resolve implementation or operational issues.

Consider a plant user who can create a vendor, approve invoices and process payments. That combination gives one person control over multiple stages of the procure-to-pay process and can make inappropriate or fraudulent transactions harder to detect. 

The key question is whether the user has only the access required for their role and whether those permissions maintain proper segregation of duties.

That is a clear segregation-of-duties risk, regardless of how well the ERP is configured elsewhere. The same review should cover users who can post manual journal entries, modify master data or approve their own transactions.

The problem often comes from outdated controls around the ERP. 

A Risk Control Matrix created before an ERP migration may no longer match the company’s current system, user roles or transaction flows.

After a major system change, review whether existing controls still work as intended. This should include user access, segregation of duties and key IT general controls. 

These controls should also be reviewed regularly to ensure they continue to match the way the ERP is being used.

AI introduces a different set of questions. 

If finance or operations uses AI for invoice processing, anomaly detection, forecasting or management reporting, the company should know what data the tool receives, where that data goes, who can access it and who reviews the output. 

AI-generated information should not automatically be treated as reliable simply because it comes from an established software platform. Human review, data governance and an audit trail remain important.

GST processes also increasingly depend on technology. 

E-invoicing currently applies to taxpayers meeting the prescribed turnover threshold, with the mandate having expanded to businesses with aggregate annual turnover of ₹5 crore or more from August 2023. 

Businesses should ensure their ERP, invoicing and GST reconciliation processes are aligned with current requirements.

As a CFO or audit committee member, the practical priority must be : review ERP access across every plant, identify segregation-of-duties conflicts, update controls after system changes, and maintain an inventory of AI tools used in finance and operations.

The objective is to ensure that technology designed to improve efficiency does not quietly create new financial reporting, compliance or data governance risks.

Third-Party and Supply Chain Risk in Manufacturing Value Chains

Supply chain risk used to mean delivery delays, raw material shortages and price volatility. For a multi-location manufacturer, the exposure is broader.

A critical supplier can create production, cybersecurity, quality, compliance or business continuity problems that may not appear in a traditional financial audit.

Identify Critical Supplier Dependencies

Start with concentration risk. Identify the vendors whose failure could stop production at any plant within a week.

For each critical supplier, assess:

  • Single Source Dependency: Do we rely on one supplier for a critical material, component or service?
  • Alternative Sources: Is a qualified second source available?
  • Switching Time: How quickly could production move to another supplier?
  • Supplier Resilience: Does the supplier have basic cybersecurity, backup and business continuity measures?
  • Geographic Exposure: Does cross-border sourcing create additional currency, customs, trade or geopolitical risks?
  • Recovery Planning: What would happen if the supplier stopped operating for 30, 60 or 90 days?

The objective is to identify dependencies that could interrupt production before an actual disruption exposes them.

Compare Controls Across Plants

There is another issue that often receives less attention: process inconsistency across plants.

One factory may complete purchase approvals in three days while another takes eleven. Different locations may also use different vendor onboarding, inventory or approval procedures even though they operate under the same corporate policy.

These differences can:

  • delay purchasing and production decisions;
  • create inconsistent approval controls;
  • make inventory and financial reporting harder to reconcile;
  • increase the risk of duplicate or inactive vendors; and
  • create control gaps that remain hidden at head office.

A useful review is to compare how each plant handles vendor creation, purchase approvals, goods receipt, inventory adjustments, payments and exception approvals. The goal is to identify where differences create unnecessary risk.

Strengthen Supplier Due Diligence

Supplier governance is also becoming more relevant as large customers strengthen their own ESG and value-chain reporting.

An unlisted manufacturer does not automatically have to report under BRSR. However, listed customers may ask suppliers to provide data on energy use, waste, safety, labour standards and other ESG metrics.

That means supplier onboarding should cover more than price, quality and delivery. Depending on the supplier’s importance, it may also need to cover:

  • Ownership and basic compliance checks;
  • Cybersecurity requirements;
  • Business continuity arrangements;
  • Labour and workplace safety practices;
  • Environmental and ESG information; and
  • Evidence supporting information provided to customers.

Focus on Practical Controls

The response does not require an expensive third-party risk platform.

A practical approach is to:

  1. Map critical suppliers and single-source dependencies.
  2. Rank suppliers by operational and financial impact.
  3. Identify qualified alternatives for critical materials and services.
  4. Compare procurement and inventory processes across plants.
  5. Set minimum due-diligence requirements for critical suppliers.
  6. Review supplier cybersecurity and business continuity arrangements.
  7. Check whether business interruption insurance reflects current production capacity and critical supplier dependencies.
  8. Reassess the list when production volumes, plants, suppliers or sourcing geographies change.

For the audit committee, the key question is which supplier could disrupt our business and whether we are prepared if that happens.

Governance Expectations Rising for Promoter-Led Businesses

Many ₹100 crore to ₹500 crore manufacturers and enterprises are still promoter-led, with founders or family members controlling both ownership and day-to-day decisions. 

This structure can work extremely well for growth but as the business expands, lenders, investors, customers and potential partners increasingly expect greater transparency around how important decisions are made.

From Informal Oversight to Documented Governance

An unlisted promoter-led company does not need a listed-company governance structure. It needs clear, documented processes for the controls it currently manages informally.

During a loan renewal, investment round or major customer due diligence, management may be asked:

  • Who independently reviews major financial decisions?
  • How are related-party transactions identified and approved?
  • Who reviews the finance function’s work?
  • What happens when the promoter is involved in a transaction with the company?

These questions are harder to answer when people make decisions based on personal oversight and judgment. Clear processes make these decisions easier to track and explain.

Know Where the Law Applies

The Companies Act, 2013 requires an audit committee for listed companies and prescribed classes of public companies meeting specified thresholds, including ₹10 crore paid-up capital, ₹100 crore turnover, or more than ₹50 crore in aggregate outstanding loans, borrowings, debentures or deposits.

These provisions do not automatically apply to every private company simply because it crosses ₹100 crore in turnover. Section 138 also requires specified companies to appoint an internal auditor based on prescribed criteria.

Companies should therefore assess their obligations based on their legal structure, financial position and applicable thresholds, rather than assuming that turnover alone determines the requirement.

Build Governance Before You Need It

Even where a formal audit committee is not required, a lightweight governance framework can reduce risk. Start by:

  • Establishing clear approval thresholds for significant transactions
  • Maintaining a related-party transaction register
  • Documenting key financial controls
  • Giving the board appropriate visibility into major risks
  • Reviewing controls independently rather than relying entirely on promoter oversight

For a growing promoter-led manufacturer, the goal is to reduce dependence on individual oversight. Good governance ensures that the business can withstand scrutiny without requiring the promoter to personally supervise every important decision.

Regulatory Change Risk Under the New Income Tax Act, 2025

The Income-tax Act, 2025 came into force on 1 April 2026, replacing the Income-tax Act, 1961. A key change is the shift from the earlier “previous year” and “assessment year” terminology to a single “Tax Year” concept. 

Under the new law, each Tax Year is the 12‑month financial year from 1 April to 31 March; for example, Tax Year 2026‑27 covers 1 April 2026 to 31 March 2027. Income earned up to 31 March 2026 continues to be governed by the 1961 Act using the old terminology.

The immediate risk arises from systems, processes, and documentation built around the old tax law such as ERP configurations, tax provision logic, audit checklists, and internal templates that reference “previous year”, “assessment year” and legacy section numbers. 

These need to be reviewed and updated to align with the new Act’s terminology, section mapping, and compliance requirements for Tax Year 2026‑27 and onwards.

Where the Transition Can Create Risk

Section references have changed, provisions have been reorganised, and tax forms and rules have been updated. Finance teams should therefore review:

  • Tax compliance calendars and internal SOPs
  • ERP configurations for TDS and other tax processes
  • Tax position papers and standard templates
  • Internal checklists and audit documentation
  • Delegation and review procedures for tax filings

The transition also creates an important distinction between old and new tax years. Income earned during FY 2025-26 continues to be governed by the 1961 Act and will be filed as AY 2026-27, even though the filing may take place after 1 April 2026. 

Similarly, pending assessments, appeals, reassessments and other proceedings relating to tax years beginning before 1 April 2026 continue under the old Act under the transitional provisions.

This means a company may need to operate with two tax frameworks at the same time: the new Act for Tax Year 2026-27 onwards and the old Act for earlier years and related proceedings.

The practical response is creating a transition checklist, map old section references to the new provisions where necessary, update ERP and tax documentation, and separately track all open assessments and appeals.

For most companies, this is manageable internal work. Specialist advice becomes useful for complex tax positions, transfer pricing matters or proceedings that span the transition period. Using the wrong framework in these cases can lead to serious problems.

What Boards Should Ask Management in the Next Audit Committee Meeting

Boards do not need a new risk framework to act on any of this. The existing risk register, control framework and audit processes already provide a starting point. What matters now is using them to test whether the controls are working across the areas discussed above.

Four specific questions, put to management at the next audit committee meeting, cover the ground above without turning the meeting into a compliance seminar and they will tell you quickly whether your existing team can close the gap internally or whether the gap needs a specialist set of eyes.

1. Which customers, lenders or other stakeholders have asked us for ESG or sustainability data in the last twelve months, and who owns tracking and responding to those requests?

2. When was our ERP access list and Risk Control Matrix last reviewed for segregation-of-duties conflicts across all locations and business units, and which AI tools are currently in use across finance and operations?

3. Which of our vendors are critical to business continuity, and have we assessed their own cybersecurity and continuity practices?

4. Where do we stand against the audit committee, internal audit and related-party transaction requirements applicable to our company, and is our current ICFR framework keeping pace with the expectations of lenders and investors?

Most companies can answer the first and third questions with existing staff and a week of internal work. The second and fourth tend to be where a fragmented, factory-by-factory audit history creates blind spots that are harder to see from inside the organisation, since each factory’s finance lead may honestly believe their own controls are sound without visibility into how the other three are run. 

An independent Risk Control Matrix review or ICFR gap assessment can help identify these gaps. It gives your internal team a second set of eyes on how controls work across locations.

Regardless of who does the work, assign an owner and a deadline to each of the four questions in the meeting minutes. Do not leave them as discussion points. Without a clear owner, the same questions may come up again at the next meeting without any action being taken.

If your board’s next audit committee agenda does not currently include any of these four questions, that is the gap worth closing first. Schedule an appointment with PKC ‘s risk advisory and audit team to work through where your specific operations and turnover bracket create the most exposure, and where an internal fix is enough versus where an independent review would help.

FAQs

Which enterprise risks are becoming more prominent for Indian companies in 2027? 

For mid-sized manufacturers specifically, the fastest-growing areas are ESG and sustainability data requests flowing down from listed customers, segregation-of-duties and IT-control gaps from ERP and AI adoption, third-party and vendor cyber risk, and governance expectations from lenders and investors on promoter-led companies. The transition to the Income-tax Act, 2025 adds a procedural layer on top of all of these.

Do BRSR disclosure requirements apply to mid-sized, unlisted companies? 

BRSR and BRSR Core apply directly to listed companies, with the requirements phased in up to the top 1,000 companies by market capitalization through FY 2026–27. An unlisted mid-sized manufacturer does not file BRSR. However, a listed customer may ask the manufacturer for ESG data if it is a key supplier or buyer in the customer’s value chain.

How does AI adoption change IT-control and data risk for enterprises? 

AI tools used in finance and operations, for tasks like invoice processing, demand forecasting, or drafting communications, need the same scrutiny as any system that touches financial data: who has access, what human review sits over the output, and where the underlying data is stored. Most companies have more AI tools in active use than their Risk Control Matrix or internal audit plan currently accounts for.

What governance changes should promoter-led businesses expect as they professionalise? 

The legal requirement for an audit committee applies to listed companies and public companies that meet specific paid-up capital, turnover or borrowing thresholds. It does not apply to private limited companies, regardless of their size.

However, lenders and private equity investors increasingly expect promoter-led companies to put these controls in place earlier. They may ask for independent financial oversight, a documented related-party transaction process and a tested ICFR framework before providing funding or approving large customer contracts.

How should audit committees prepare for the transition to the Income Tax Act, 2025? 

Treat it as a cross-referencing and documentation exercise rather than a policy change. Review internal SOPs, tax memos, and ERP configurations that cite specific sections of the old 1961 Act, confirm which framework applies to any pending assessments or appeals from earlier tax years, and align the tax team and statutory auditor on the updated section numbering before year-end.

How does PKC help boards build a forward-looking risk agenda? 

PKC Management Consulting works with CFOs and audit committees to map which of these risk areas carry the most exposure for a company’s specific operations, turnover bracket, and multi-location structure, and to identify where an internal fix is sufficient versus where an independent Risk Control Matrix review, ICFR gap assessment, or internal audit engagement would help before the next funding round, customer audit, or bank review.

How PKC can help you

Your dream business is just a click away. Book a FREE 30-minute consultation.

Call us: +91 91761 00095

Got a question after reading?

Drop your details and one of our consultants will call you back — usually within a business day.

Want to talk? Get a call back today
+91 91761 00095

Fill out your details

Once submitted, a calendar will open to book your 30-minute meeting slot.

or call us: +91 91761 00095