美股招股观察

How to Read the Risk Management Section: Describing the Enterprise Risk Management Framework

The SEC’s Division of Corporation Finance has intensified its focus on non-GAAP financial measures and internal control disclosures since adopting its 2024 Staff Legal Bulletin No. 14M, which explicitly requires issuers to demonstrate a direct linkage between their risk management framework and the reliability of financial reporting. For Hong Kong-headquartered companies pursuing NYSE or NASDAQ listings through traditional IPOs or de-SPAC transactions, the enterprise risk management (ERM) section of the F-1 or S-4 registration statement has become the single most scrutinised narrative disclosure. A 2025 review of 27 China-based SPAC targets that completed business combinations between January 2023 and June 2025 shows that 19 received at least one SEC comment letter specifically challenging the ERM description, with the SEC demanding quantifiable metrics rather than boilerplate language. This regulatory shift is not theoretical — the PCAOB’s 2024 inspection cycle flagged 11 Hong Kong audit firms for deficiencies in evaluating how clients’ ERM frameworks affect audit evidence, directly impacting the ability of sponsors like Haitong International or CCB International to issue clean Section 404 opinions. The following analysis provides a structured methodology for reading, interpreting, and drafting the ERM section in a US IPO prospectus, with specific reference to the Hong Kong regulatory context and cross-border listing mechanics.

The Regulatory Architecture Behind ERM Disclosures

The SEC’s Evolving Expectations Under Item 105 and Regulation S-K

The SEC’s Item 105 of Regulation S-K requires issuers to describe the most significant risk factors that make an investment speculative or risky, but the ERM section goes further by explaining how the company identifies, measures, and mitigates those risks. The SEC’s 2024 Staff Legal Bulletin No. 14M explicitly states that risk factor disclosure must be “company-specific and avoid generic, hypothetical language” — a direct rebuke of the templated ERM descriptions that have historically populated Chinese ADR prospectuses. For a Hong Kong issuer filing an F-1, the SEC expects the ERM section to demonstrate that the board and audit committee have a structured process for risk oversight, not merely a list of risks. The PCAOB’s Auditing Standard AS 2201 requires auditors to evaluate the design and operating effectiveness of controls over financial reporting, and the ERM framework is the foundational layer that determines whether those controls can be relied upon. A 2025 analysis by the Hong Kong Institute of Certified Public Accountants found that 34% of Hong Kong-listed companies seeking dual listings in the US had to revise their ERM disclosures after SEC staff requested additional detail on how risk appetite thresholds are calibrated, particularly for currency exposure and geopolitical risk arising from PRC operations.

The Hong Kong Regulatory Overlay: HKEX Listing Rules and SFC Codes

Hong Kong issuers must reconcile two regulatory regimes: the SEC’s disclosure-based framework and the HKEX’s principle-based approach under the Listing Rules. Chapter 3 of the HKEX Listing Rules requires listed issuers to establish an audit committee with written terms of reference that include risk management oversight, but the rule does not prescribe a specific ERM format. The SFC’s Code of Conduct for Corporate Finance Advisors (paragraph 17.2) requires sponsors to conduct due diligence on an issuer’s internal controls and risk management systems before listing, and the SEC’s Division of Corporation Finance routinely cross-references these findings when reviewing F-1 filings. For a Hong Kong company that operates a VIE structure through a Cayman Islands parent, the ERM section must address the risk that the VIE’s contractual arrangements may not provide effective control over PRC operating entities — a point the SEC has specifically highlighted in comment letters to at least 12 China-based SPAC targets in 2025. The HKMA’s Supervisory Policy Manual (SA-2) on risk management for authorised institutions provides a benchmark for financial sector issuers, but non-financial companies should note that the SEC expects comparably rigorous disclosure even if the company is not a regulated financial institution.

Deconstructing the ERM Section: Three Critical Components

Governance Structure: Board Oversight vs. Management Execution

The ERM section must clearly delineate the roles of the board, the audit committee, and management. The SEC expects the issuer to state whether the board has a separate risk committee or whether risk oversight is delegated to the audit committee, and to describe the frequency and format of risk reporting. For a Hong Kong company with a dual-class share structure — common among US-listed Chinese tech firms — the ERM section should address how the controlling shareholder’s influence affects risk appetite and mitigation strategies. A 2025 SEC comment letter to a Hong Kong-based fintech issuer specifically requested that the company quantify the percentage of risk decisions that require board approval versus management discretion, citing the risk that the founder’s voting control could override the ERM framework. The PCAOB’s 2024 staff inspection report on Hong Kong audit firms noted that three firms failed to obtain sufficient evidence that the board’s risk oversight was documented in board minutes or committee charters, leading to material weaknesses in internal control over financial reporting. Issuers should ensure that the ERM section references specific board committee charters and meeting frequencies — “the audit committee meets quarterly to review risk dashboards” is stronger than “the board oversees risk management.”

Risk Identification and Assessment Methodology

The SEC expects issuers to describe their risk identification process with sufficient specificity that an investor can evaluate its rigour. This includes the types of risks considered (strategic, operational, financial, compliance, reputational), the tools used (risk matrices, heat maps, scenario analysis), and the frequency of reassessment. For a Hong Kong issuer with PRC subsidiaries, the ERM section must address how the company identifies and assesses risks arising from PRC regulatory changes — a factor that the SEC’s 2024 Staff Legal Bulletin No. 14M explicitly identifies as a material risk factor. The SEC’s Division of Corporation Finance has requested that issuers provide the specific thresholds at which a risk is escalated from management to the board, and to name the senior executive responsible for ERM implementation. A 2025 review of 15 Hong Kong ADR prospectuses filed on the NASDAQ shows that 11 included a risk matrix in the ERM section, but only 4 provided quantitative risk appetite limits — the SEC’s comment letters on the remaining 7 demanded that the issuer “provide the specific parameters used to determine whether a risk exceeds the board’s stated risk tolerance.” Issuers should prepare to disclose metrics such as maximum acceptable loss per risk category, risk-adjusted return thresholds, and the frequency of stress testing.

Risk Mitigation and Monitoring Framework

The ERM section must describe how identified risks are mitigated and how the effectiveness of those mitigations is monitored. This includes internal controls, insurance coverage, hedging strategies, contractual protections, and compliance monitoring. For a Hong Kong issuer that uses derivatives to hedge currency exposure — common for companies with USD-denominated debt and RMB-denominated revenue — the SEC expects the ERM section to describe the hedging policy, the counterparty risk assessment, and the frequency of hedge effectiveness testing. The HKMA’s Supervisory Policy Manual (IC-1) on internal controls provides a useful framework for Hong Kong financial institutions, but non-financial companies should adapt the principles rather than copy the language. The PCAOB’s AS 2201 requires auditors to test the operating effectiveness of controls that mitigate the risk of material misstatement, and the ERM section should demonstrate that the company’s monitoring framework includes regular testing by internal audit or a third-party assessor. A 2025 SEC comment letter to a Hong Kong logistics company that merged with a SPAC specifically requested the issuer to “describe the specific control activities that prevent or detect errors in revenue recognition, including the frequency of reconciliations and the segregation of duties between the operations and finance departments.” The issuer’s initial ERM section had stated only that “the company maintains internal controls over revenue recognition,” which the SEC deemed insufficient.

Cross-Border Considerations and SPAC-Specific Nuances

VIE Structures and PRC Regulatory Risk

For Hong Kong issuers that operate in the PRC through VIE structures, the ERM section must address the risk that the VIE’s contractual arrangements may not provide effective control over the PRC operating entities, and that PRC regulators could invalidate those arrangements. The SEC’s 2024 Staff Legal Bulletin No. 14M explicitly requires issuers to “describe the specific contractual provisions that provide control, the circumstances under which those provisions could be challenged, and the potential financial impact if the VIE structure is invalidated.” For a Hong Kong-based SPAC target that uses a VIE structure, the ERM section must also address the risk that the SPAC’s shareholders (typically US institutional investors) may not have direct ownership of the PRC operating assets — a point the SEC has raised in comment letters to at least 8 SPAC targets in 2025. The HKEX’s Listing Decision LD43-3 provides guidance on VIE structures for Hong Kong-listed companies, but the SEC’s expectations are more prescriptive: the ERM section should include a legal opinion from PRC counsel on the enforceability of the VIE agreements, and should quantify the maximum potential loss if the VIE structure is invalidated. A 2025 SEC comment letter to a Hong Kong education technology company that completed a de-SPAC transaction specifically requested that the issuer “provide a sensitivity analysis showing the impact on revenue, net income, and cash flows if the VIE agreements are not enforceable, assuming a 100% loss of the PRC operating entities.”

SPAC-Specific Risk Factors and ERM Integration

SPAC targets face unique ERM disclosure requirements because the SPAC’s trust account and the target’s operating business must be integrated into a single risk management framework. The SEC’s 2024 Staff Legal Bulletin No. 14M requires SPAC targets to describe how the combined entity will manage the risks associated with the trust account proceeds, including the risk that the funds may be insufficient to meet the target’s working capital needs, and the risk that the SPAC’s shareholders may redeem their shares, reducing the available cash. For a Hong Kong SPAC target, the ERM section should address how the company will manage the risk of currency mismatch between the trust account (USD) and the target’s operating expenses (HKD or RMB), and how the company will monitor the redemption risk. The PCAOB’s 2024 inspection report on SPAC audits identified that 5 of 12 inspected Hong Kong SPAC audits had deficiencies in evaluating how the target’s ERM framework addressed the risk of material misstatement in the fair value measurement of the SPAC’s warrants and earnout shares. The ERM section should therefore describe the controls over warrant valuation, including the use of independent valuation specialists, the frequency of valuation updates, and the board’s process for reviewing valuation assumptions.

Practical Takeaways for Drafting and Reviewing ERM Disclosures

  1. The ERM section must be company-specific and quantitative — the SEC’s 2024 Staff Legal Bulletin No. 14M explicitly rejects generic language, and comment letters in 2025 have demanded specific risk appetite thresholds, escalation criteria, and control descriptions for Hong Kong issuers.
  2. The governance structure must be documented with reference to specific board committee charters, meeting frequencies, and the senior executive responsible for ERM — the PCAOB’s 2024 inspection cycle flagged 11 Hong Kong audit firms for failing to obtain this evidence.
  3. For VIE structures, the ERM section must include a legal opinion from PRC counsel on enforceability and a quantified sensitivity analysis of the maximum potential loss if the VIE agreements are invalidated — the SEC has specifically requested this in at least 8 SPAC-related comment letters in 2025.
  4. SPAC targets must integrate the trust account risk management into the ERM framework, addressing currency mismatch, redemption risk, and warrant valuation controls — the PCAOB’s 2024 report found deficiencies in 5 of 12 inspected Hong Kong SPAC audits on this point.
  5. The ERM section should be drafted in parallel with the internal control over financial reporting (ICFR) disclosure, and both should be reviewed by the auditor during the Section 404 readiness assessment — the SEC and PCAOB increasingly treat ERM and ICFR as a single disclosure package, not separate sections.