Proactively Navigating Risks in a Dynamic Environment
At Cube InvIT, risk management is embedded at the core of decisionmaking. As the platform scales, our risk management approach evolves into a forward-looking system that identifies risks before they crystallize, continuously monitors emerging trends, and integrates mitigation strategies into operational and strategic planning
Enterprise Risk Management Framework
We have established a robust Enterprise Risk Management (ERM) framework aligned with the best global practices, including ISO 31000 and COSO principles. The framework is designed to systematically identify, assess, prioritize, and mitigate risks across the organization while ensuring alignment with business objectives.
The ERM framework acts as a strategic compass, helping to:
Align risk management with stakeholder expectations.
Integrate risk considerations into business planning
Enhance preparedness for emerging risks and opportunities.
Strengthen financial stability and operational continuity.
Structured Risk Management Approach
The risk management process is anchored in a structured and cyclical methodology:
- Risk Identification and Assessment
- Risk Appetite and Tolerance
- Risk Mitigation and Control
- Continuous Monitoring and Review
- Technology Enablement
Governance and Oversight
Risk governance at Cube InvIT is driven through a centralized yet adaptive model:
Strategic risk decisions are taken at the central level.
Standardized approaches are implemented across assets.
Asset-level customization is applied for operational risks.
A three lines of defense model ensures accountability:
1
Operational teams manage risks at the source.
2
Risk and compliance functions provide oversight.
3
Internal audit ensure independent assurance.
Enterprise Risk Management (ERM) Overview
In its pursuit of sustainable value creation and operational excellence, Cube InvIT has implemented a comprehensive Enterprise Risk Management (ERM) framework.
1
Tailored Framework and Strategic Alignment
Cube InvIT has developed a bespoke ERM framework tailored to its business requirements and aligned with global best practices. This framework serves as a strategic guide to systematically identify, assess, and manage risks across the organization.
2
Risk Identification and Prioritization
Through collaborative efforts and extensive experience, the organization has built a comprehensive inventory of risks impacting operational resilience, financial performance, and strategic objectives. Each risk is evaluated based on its likelihood and potential impact, enabling focused prioritization of mitigation actions.
3
Industry Benchmarking
Regular benchmarking against industry peers helps identify emerging and prevalent risks. These insights are integrated into the ERM framework, ensuring it remains relevant, robust, and aligned with evolving industry dynamics.
4
Risk Register
A centralized risk register forms the backbone of the ERM framework, capturing identified risks, their potential consequences, and corresponding mitigation strategies. This structured repository supports proactive risk management and informed strategic decision-making.
5
Governance and Board Oversight
A strong governance structure underpins the ERM framework, led by the Board and its Risk Management Committee, comprising amongst other independent directors. Supported by a ‘three lines of defense model’, covering operational management, risk and compliance functions, and internal audit, the governance structure enables effective identification, assessment, and mitigation of risks across the organization.
Risk Management across the Asset Lifecycle
During Acquisition
A rigorous, multi-layered due diligence process is conducted, covering:
- Legal and regulatory compliance
- Financial and tax exposures
- Traffic and operational assessments
- Anti-bribery and corruption (ABAC) checks
Identified risks are addressed through valuation adjustments, indemnities, or contractual protections.
Post-Acquisition
Risk management is integrated into asset operations through:
- Continuous monitoring of traffic and asset conditions
- Preventive maintenance planning
- Standardized operating procedures
Risk Management Responsibility Mapping
The Risk Management Committee functions in line with the roles and responsibilities prescribed under the Securities and Exchange Board of India (Listing Obligations And Disclosure Requirements) Regulations, 2015 (“SEBI Listing Regulations”), as amended from time to time. Its scope also includes ensuring compliance with other applicable SEBI laws and regulations, along with any additional responsibilities delegated by the Board of Directors.
The Committee is composed of:
Mr. Jayesh R. Desai
Chairman
Mr. Sandeep Lakhanpal
Non-Independent Director
Ms. Helly B. Ajmera
Non-Independent Director
Mr. Raviraj V. Acharya
Non-Independent Director
Risk Management Matrix
| Risk Type | Risk Description | Example Mitigation Strategies |
|---|---|---|
Traffic and Revenue Risk |
Variability in traffic volumes, arising from economic slowdown, competing routes, seasonal patterns, or changes in user behavior, may impact toll collections and cash flows |
|
Regulatory and Policy Risk |
Changes in government policies, toll regulations, concession frameworks, or taxation could adversely affect project revenues and returns |
|
Concession Agreement Risk |
Dependence on concession agreements exposes the Cube InvIT to risks related to termination, non-compliance, or unfavorable amendments |
|
Operational and Maintenance Risk |
Inefficient operations, poor maintenance, or disruptions (including accidents or natural calamities) may affect asset performance and user experiences |
|
Financial and Leverage Risk |
High leverage or adverse changes in interest rates could impact profitability and cash distributions to unitholders |
|
Counterparty Risk |
Dependence on government authorities for annuity payments, or on contractors and vendors for execution, may lead to delays or defaults |
|
Project Acquisition and Integration Risk |
Challenges in identifying, acquiring, or integrating new assets may affect growth strategies and returns |
|
Environmental and Social Risk |
Environmental regulations, land acquisition issues, or social opposition may impact operations or expansion plans |
|
Tax Risk |
Changes to tax regimes and interpretation of tax provisions |
|
Force Majeure Risk |
Events such as natural disasters, pandemics, or unforeseen disruptions can impact traffic and operations |
|
Dependence on Key Stakeholders |
Reliance on the sponsor, investment manager, and key personnel may impact strategic execution |
|
Powering Integrity through Scale and Culture
Our compliance framework operates through a hub-and-spoke model, wherein central oversight is anchored at the corporate level, while execution is driven across SPVs.
Digital Backbone for RealTime Compliance
A key pillar of our compliance architecture is a centralized compliance management system, which serves as the backbone of all compliance activities. The platform enables real-time tracking of statutory requirements, maintains a comprehensive repository of evidences, and supports proactive monitoring.
Structured Monitoring and Transparent Reporting
We have established robust reporting mechanisms to ensure accountability and transparency. Periodic compliance certifications and structured review processes allow us to track adherence levels across SPVs. Any instances of non-compliance are promptly escalated and shared with relevant stakeholders, including trustees, reinforcing trust and governance discipline.
Strengthening Ethical Practices and ABAC Framework
Our Anti-Bribery and Anti-Corruption (ABAC) framework is deeply embedded into day-to-day operations. We have standardized key processes such as vendor onboarding, supported by mandatory due diligence and integration with supply chain workflows. Additionally, registers for gifts, hospitality, and site visits are maintained to ensure transparency in all interactions, particularly those involving government interfaces.
Multilingual Policies for a Diverse Workforce
- DISPLAY OF TEASERS/POSTERS AT SITE - ETHICS (WHISTLE BLOWER) HELPLINE
- IMPARTING TRAININGS AT SITES
- HR HANDBOOK AVAILABILITY IN ALL 6 LOCAL LANGUAGES
- DISPLAY TEASERS/POSTERS OF MANUALS AT SITES
Ethical behavior at Workplace
If you are unsure, Before you act - ASK!
- Is this legal?
- Is this fair?
- Is this as per the company policies?
If you witness any Code of Conduct violations, please reach out to the Ethics Helpline at:
The Compliance team has translated the Whistleblower Policy into various languages for better understanding by native speakers. This aids in identifying malpractices and facilitates prompt action.
Site Training
- 1Hazaribagh Tollway Private Limited.
- 2Jhansi-Vigakhet Tollway Private Limited
- 3Srirangam Infra Private Limited
- 4Salaipudhur Madurai Tollway Private Limited.
- 5Madurai Kanyakumari Tollway Private Limited.
Celebrating Compliance and Ethics Month, October 2025
- Focused Departmental Training: Conducted targeted sessions across HR, SCM, IT, and Operations & Maintenance to strengthen awareness of ethical standards and compliance practices.
- Leadership Messages by CXOs: Thought-provoking messages shared from leadership, reinforcing the organization’s commitment to ethics and integrity.
- Q&A Sessions with Senior Management: Facilitated open forums to address employee queries and discuss practical compliance and ethical dilemmas.
- AI-Generated Case Study Video: Released an in-house video on procurement fraud, developed using Generative AI to drive engagement and learning.
ETHOS 2025
We hosted knowledge-sharing sessions with external experts and industry leaders to deepen awareness and reinforce our commitment to ethics and compliance under ETHOS 2025.
Future Focus
Going forward, we aim to further strengthen our compliance ecosystem by leveraging data analytics, automation, and real-time monitoring tools. Our focus will remain on proactive risk identification, enhanced transparency, and continuous engagement with stakeholders, ensuring a resilient and futureready compliance framework that supports sustainable growth.