The Question Boards Have Not Yet Answered

The Edge Singapore featured my latest article "The Question Boards Have Not Yet Answered" on 14 August 2026.

Lee Ooi Keong

8/21/202611 min read

The Question Boards Have Not Yet Answered

MAS is reviewing the Code of Corporate Governance. The data reveals where companies are falling short.

184 of the 607 companies listed on the Singapore Exchange, or 30.3%, made a profit in their most recent reported financial year without earning enough to cover the cost of the capital they used. Their combined market capitalisation is S$360.1 billion, 27.9% of total market capitalisation as of June 30, 2026.

These are not weak businesses. Together, the 184 generate S$406.4 billion of revenue at a median net profit margin of 6.0%, and 72 of them earn a net margin above 10%.

What they do not do is earn an adequate return on the capital held inside them. Their median return on equity (ROE), meaning profit earned on shareholders' capital, is 3.75%, some 4.25 percentage points below the roughly 8.0% cost of equity (COE) for Singapore-listed companies. For every year the gap persists, the owners are worse off for having their money invested in these companies.

Investors have drawn the same conclusion. Of the 184 companies, 142 (77.2%) trade below book value. This group's median price-to-book (P/B) ratio is 0.69 times. In other words, the market pays less for these companies than the accounting value of the assets they own. See Chart 1.

The regulator is already responding

MAS announced a review of the Code of Corporate Governance in May 2025. The Corporate Governance Advisory Committee is conducting it through two sub-committees, one on more meaningful implementation of the Code, the other on corporate culture, board effectiveness, and risk management in emerging areas such as artificial intelligence.

Speaking in March 2026 to the Singapore Institute of Directors' Chairpersons Guild Forum, Chia Der Jiun, Managing Director of the Monetary Authority of Singapore (MAS), set out what that review will consider. He said that "strong boards are disciplined stewards of capital", and that the review will look at supplementing the Code with practical guidance on value creation, including how boards "provide strategic oversight, and challenge to management on issues such as capital efficiency, and whether market valuation adequately reflects a company's earnings potential and value". He cautioned that disclosure requirements alone risk becoming "a box ticking exercise, if there is no real ownership by company leadership".

The concern is not confined to the regulator. Writing in the Singapore Institute of Directors' Directors Bulletin for the third quarter of 2026, Piyush Gupta, chairman of Singapore Management University and formerly chief executive of DBS Group Holdings, asked whether today's boards are "truly prepared for the complexities of the future". His answer was no. Boards, he wrote, "are focused almost exclusively on compliance and risk mitigation".

The direction of travel is settled. How a board is meant to deliver value creation is not, and that is where the framework runs out.

Not a problem of smaller companies

The obvious explanation is that this belongs to the smaller listed companies: thin boards, a controlling shareholder, no analyst asking hard questions. On that interpretation, better governance would fix it.

The Straits Times Index (STI) says otherwise. Of its 30 constituents, 12 earn an ROE above 8%, at a median of 17.55%. The other 18 fall below, at a median of 4.79%. Those 18 carry a market capitalisation of S$213.9 billion (28.1% of the index), and their median P/B ratio is 0.93 times against 2.35 times for the other 12.

These are the largest, most liquid and most closely followed companies in Singapore. Every one has an audit committee, most have a board risk committee, and they carry the deepest analyst coverage in the market. The 18 earn roughly a quarter of what the other 12 earn on the same shareholder dollar.

Boards have done what the rules ask

SGX Mainboard Rule 719(1) requires an issuer to have a system of internal controls and risk management that is adequate and effective. Rule 1207(10) requires the board to state its opinion on that system in the annual report, say whether the audit committee agrees, and disclose any material weakness found.

Boards take this work seriously. However, a board can produce a clean statement under Rule 1207(10), mean every word of it, and still oversee a decade of returns below the cost of equity, because the exercise does not look for the problem.

Returns stay there only through years of accumulated decisions: a plant expanded, a subsidiary retained, an acquisition made, profits reinvested rather than returned. Each is a board decision, and the rules say very little about how boards should decide.

The Code asks two questions

Singapore's Code of Corporate Governance (the Code) makes two demands on a board about risk. Principle 9 makes the board responsible for the governance of risk. Beneath it, Provision 9.1 requires the board to determine what risk the company should take in achieving its strategic objectives and value creation, and Provision 9.2 requires the board to obtain assurance that the systems for controlling risk are sound. The exact wording matters. Table 1 sets it out.

The first question is about risk-taking: what risk should the company run to achieve its objectives and create value, given that value is created only when returns exceed the cost of equity. The second is about control: are the systems for finding and containing risk sound. Both are proper board questions.

Only one question has a method

Singapore has told boards how to answer the second question in detail. The Corporate Governance Council published Risk Governance Guidance for Listed Boards in May 2012, a manual containing model terms of reference for a board risk committee, the contents of a risk management policy, checklists, reporting templates, sample questions for reviewing the systems, and more.

The manual also supplies the test of success. It says a system of risk management and internal controls is adequate and effective if it provides reasonable assurance on four matters:

• That the company's risks are being managed;

• That its assets are safeguarded;

• That its financial information is reliable;

• That it complies with laws and regulations.

None of those four tests asks whether the company's capital is earning what it costs.

For the first question, on strategic objectives and value creation, there is nothing of comparable weight. No methodology, no tools, no test.

How risk management became a control discipline

Risk management as most directors have practised it was built for a particular purpose.

Enron collapsed in December 2001 and WorldCom followed in June 2002, both after accounting failures that internal controls should have caught. In response, the US Congress enacted the Sarbanes-Oxley Act in July 2002. Its section 404 required management to assess and report on the effectiveness of internal control over financial reporting, and the external auditor to attest to that assessment. The aim was to improve the integrity of reported numbers.

This is where compliance-based risk management, as it is practised today, took its shape. Methods built for the reliability of financial reporting were extended into risk management, promoted by the professional accounting firms. Risk management became something that had to be evidenced: documented, tested, and capable of being inspected afterwards. By 2012 this was the mature body of practice available, and Singapore's guidance drew on it.

This is what risk management has come to mean in practice, and it starts from what could go wrong. The 2012 manual sets out the method: identify the risks, assess each for likelihood and impact, evaluate the result against the tolerances the board has set, and treat any risk outside them by transferring, avoiding, reducing or accepting it. Success is an opinion that the system is adequate and effective. This is the practice Singapore's disclosure regime requires, and rests on.

It was not built to tell a board whether the plan in front of it will earn more than the capital costs.

The other kind of risk management

Before the accounting scandals and the reshaping of risk frameworks around auditability and control assurance, risk analysis existed to support decisions. Investors, insurers, engineers and project managers used it to establish whether a course of action was worth taking and on what terms. The latest thinking in the field proposes a return to that purpose, and calls it “performance-centric risk management”.

Its starting point is the definition of risk itself. ISO 31000, published in 2009 and listed among the international frameworks the 2012 manual drew on, defines risk as the effect of uncertainty on objectives. On that definition, risk analysis is the work of reducing uncertainty about whether an objective will be achieved, before the decision is approved.

The work runs in four steps.

1. Start from the company's strategic objective and establish what would have to be true for it to be achieved.

2. Separate fact from assumption. A plan promising a return rests on a few things that are known and many that are assumed, such as the rate at which the market grows, whether pricing holds, or whether a project finishes on schedule. Board papers rarely distinguish between the two.

3. Identify the key assumptions that decide the outcome. Most major decisions turn on a small number of assumptions. Establishing which they are, and whether they are realistic and achievable, is the essence of risk analysis. The question is simple: “What must be true for this to succeed?”

4. Reduce the uncertainty on those assumptions. Test them against evidence, conduct further due diligence, and establish how much margin exists before the expected return falls below what the capital costs.

The result is a board that knows the conditions for success and what margin it has, rather than a board assured that nothing will go wrong. At the most advanced end, firms model and simulate the full range of outcomes across tens of thousands of iterations. Few companies in Singapore do this, and most do not need to.

None of this is unfamiliar. It is close to what an investment committee does before taking a position, where a manager is expected to state the expected return and what would have to go right for it to succeed. Boards commit larger sums, far less reversibly, yet no part of the governance framework asks them for the same.

The type of risk management a company practises changes what the board discusses. Where risk is treated as a control matter, the board reviews exposures and confirms the systems are working. Where risk is anchored to objectives, the board debates whether the plan will deliver and what it depends on. Both conversations have value. Only performance-centric risk management answers Provision 9.1.

Where the framework stops

The 2012 manual is not silent on value creation. It states that risk governance guides sound decision-making and the effective allocation of resources, that risk should be weighed as a company allocates capital across competing priorities, and that the risk management process belongs in strategy setting and in investment decisions. Those passages describe performance-centric risk management.

The manual quotes the Code duty in full, as it stood in 2012, including the requirement to determine what risk the board is willing to take in achieving its strategic objectives, and places its own emphasis on those words. It then lists the five things it will explain: what risk governance is, who is responsible for it, what a sound system looks like, how to ensure it is adequate and effective, and what to disclose in the annual report. The duty it has just emphasised is not among the five. While the manual does address how to set risk tolerance, it treats it throughout as a boundary: the point beyond which the company will not go. What risk is worth taking to achieve an objective is a different question, and the manual does not address it.

The current guidance does the same. Practice Guidance 9, issued in 2018 to help boards apply Provision 9.1 and last reissued in December 2023, restates the duty as "determining the nature and extent of the significant risks which the company is willing to take", and goes no further. The words that give the duty its purpose, achieving strategic objectives and value creation, do not appear. What follows deals with the annual review of adequacy and effectiveness, and with disclosure.

A board can therefore follow the guidance in full, satisfy the four tests, publish an accurate statement, and never be asked what its capital is expected to earn.

The strongest objection

A common objection is that this analysis belongs elsewhere. Capital discipline sits with the investment approval process, with the chief financial officer and chief investment officer, and in strategy review. Risk governance, on that view, is a control function.

The answer is in the Code itself. Provision 9.1 sits under Principle 9, which governs risk, and it is the Code that ties the board's risk-taking to strategic objectives and value creation. Wherever the analysis is carried out inside the company, the board discharges this duty through its governance of risk. Either the guidance beneath Principle 9 is incomplete, or Provision 9.1 means less than it says.

Practice varies among companies. An investment paper sets out the expected return, as it should. What Provision 9.1 asks the board to determine is the risk it is prepared to accept in pursuit of that return, which means testing the assumptions the return rests on. Where a board already receives that, the discipline exists in substance whatever it is called. However, because nothing in the guidance tells a board what to ask for, whether a board gets it depends entirely on the company.

Governance by luck

Compliance-based risk management answers the Code's second question, and Singapore has equipped boards to answer it thoroughly. Performance-centric risk management can answer the first, but it has never been named in the Code, and never given a method in the guidance.

Three consequences follow.

First, the capability now depends on who is in the room. A director with operating or investment experience will ask what the expected return depends on, because that is how they have worked all their lives. A director whose experience is in audit and controls will ask what could go wrong. Both are doing their jobs properly. Because the framework specifies only the control question, whether the value question is asked at all is settled by appointment rather than by process, and the capability leaves when that director retires.

There is a question here for nominating committees. Where a board has only known compliance-based risk management, "risk experience" on a skills matrix means audit and control experience. The experience the first question calls for is different: the ability to test whether a decision will deliver the returns it promises.

Second, the review now under way can close the gap, but only if its risk work and its value creation work are brought together. In 2012, Singapore gave boards a manual explaining how to answer the control question: what to require, what a sound system looks like, how to test it, and what to disclose. The first question, on achieving strategic objectives and value creation, has never received the equivalent. Performance-centric risk management should be named in the Code and set out in guidance with the same practical detail, covering what a board should expect to see before approving a material commitment of capital: the expected return, the assumptions it rests on, and the margin before those assumptions stop supporting it. It need not prescribe a method, which the 2012 manual was right to avoid. It should say what good looks like, which the manual did for control and never did for performance.

Third, none of this needs to wait. The test fits into a single question, and any director can put it to the next paper that asks for capital: does this tell me what return we expect, what that number depends on, and how much margin we have before the return stops covering what the capital costs?

That question is the beginning of an answer to what the Code has asked boards since 2012. Until it is asked routinely, Singapore will keep producing companies that are profitable, well controlled, accurately reported, and worth less than the assets they own.

Written 1 August 2026. Company data extracted from www.sgx.com as at 30 June 2026.

Lee Ooi Keong is an Independent Director of an SGX Mainboard-listed company with 30 years of experience in corporate performance, investments and risk management. He is the founder and Managing Director of Clover Point Consultants, an independent Board and C-suite advisory firm, and was formerly Director of Risk Management at Temasek for over 16 years.

For Enquiries or Corporate Bookings

Please contact us.