Risk management

Safeguarding operations

Operating across diverse business clusters brings exposure to a wide range of risks. Our Enterprise Risk Management (ERM) framework is aligned with strategy and business planning, enabling us to identify, assess and respond proactively to a fast-changing external environment.

Risk governance and management

Our risk management framework is built on a strong strategic foundation, guided by our Risk Management Policy and seamlessly integrated into day-to-day operations. Risks are proactively identified through diverse sources, including risk forecast reports, industry insights, insurance assessments, and internal audits, and captured in a central risk register.

Each identified risk is assigned to a management owner responsible for developing and periodically reviewing mitigation plans. Risks are prioritised based on impact and likelihood and quantified as inherent risk values. Residual risk is the value post mitigation. Mitigation actions are assigned to ensure timely execution, thereby lowering residual risk.

Scenario analysis is undertaken to evaluate options for significant risks, while sensitivity analysis assesses the impact of changes in external and operational variables, enabling more agile and resilient decision-making.

A formal Risk Appetite Statement defines threshold limits on critical parameters such as debt exposure and business value creation. These limits are continuously monitored and reviewed to ensure risk levels remain within acceptable bounds while optimising performance in a dynamic environment.

By aligning risk management with core strategy and business planning, we ensure a forward-looking, integrated approach focused on protecting value across existing operations and new projects. We also promote a strong risk culture across the organisation through:

  • Periodic awareness sessions for Non-Executive Directors on cybersecurity, regulatory, and sustainability topics
  • Monthly training for employees on risk management principles and business continuity
  • Integration of risk analysis and mitigation review into Board approval notes for new business lines and projects
  • Cascading risk mitigation goals into measurable individual KPIs, linked to performance appraisal to ensure accountability and achievement of risk targets

Structure of risk governance

At the management level, business segment–wise risk committees meet quarterly to review emerging and existing risks and track mitigation progress. Our fully automated Online Risk Management System, RMS 2.0, supports this governance with smart, cluster-wise dashboards for real-time reporting, monitoring Risk Velocity and the Risk Mitigation Completion Index (RMCI) against planned timelines.

To foster enterprise-wide risk awareness, periodic training covers areas such as cyber security, regulatory compliance, operations, HR, finance, and sustainability. The Internal Audit Plan aligns with the risk register, evaluating mitigation effectiveness and ensuring adherence to the risk process and the overall integrity of our Risk Management Strategy, including a review of action completion during process audits.

Tata Power’s Enterprise Risk Management framework follows ISO 31000 and COSO standards, and our renewal of ISO 22301:2019 certification in FY25 for a period of three years reinforces the robustness of our Business Continuity and Disaster Management Plans (BCDMP).

Risk management process

1

Risks are identified across sector specific, technology, regulatory, commercial, financial, business, climate change and business continuity parameters

2

We designate a risk owner and champion responsible for structuring mitigation plans against identified risks

3

The outcomes of the first two stages are collectively mapped into our internal system with designated responsibilities and timelines to achieve riskrelated targets

4

Our risk management system enables Cluster Risk Management Committees (CRMCs) to ensure seamless monitoring and review of current and future risk plans

5

A Risk Mitigation Completion Index (RMCI) is employed to determine and monitor the level of completion of mitigation actions within the target date

6

When the RMCI percentage is lower than the target, the deviation in mitigation action areas is reviewed for requisite management intervention

7

Insights from the risk mitigation process are further incorporated in the risk plan to enable crossfunctional learning across the organisation and enable efficacious risk management

8

Our risk register lays out concise and complete details of our identified risks and mitigation plans

Risk compliance

Our Compliance Management System (CMS) enables seamless monitoring of compliances across Tata Power and key domestic subsidiaries, with automated updates for new and obsolete legislations. Quarterly reports keep the Board informed, reinforcing governance.

Internal Financial Controls (IFC) are integrated into the Risk Control Matrix (RCM) in line with the requirements of the Companies Act, 2013. All process owners perform self-assessments of the effectiveness of internal controls within their respective processes.

Key risks and their mitigation

The Cluster Risk Management Committee (CRMC) oversees identified risks, new risks if any, risk trends, influencing factors, mitigation strategies, FY26 developments, and their alignment with our strategic objectives and capitals.

R1.Sector-specific risk (emerging risk)

Risks

  • Supply chain risk
    • Procurement for EPC/Manufacturing business has huge dependency on China as prices are very competitive compared to India and other global markets. Any restrictions on imports from China will result in incremental cost for procuring these materials from alternative sources

Risk influencing factors

  • Fluctuating dollar and silver prices
  • Policy changes both in China and India creating multiple roadblocks and putting pressures on costs

Key mitigation

  • Diversification of supplies to countries other than China – Malaysia/Vietnam leading to reduction in supply chain risk and costs

Developments during the year

  • LVA (Local Value Addition) achievement of over 50% has allowed domestic suppliers to contribute to reduction in risks
R2.Technology risk (emerging risk)

Risks

  • Cyber security risks with the potential to impede operational transactions
  • Information security risks including loss/misuse of operational and customer data, and cyberattacks affecting LAN, WAN, SCADA, DMS, and related systems
  • Exposure to cyber threats, ransomware, data breaches, system compromise, and operational disruptions arising from increasing digitalisation, IT-OT convergence, cloud adoption, evolving nation-state threats, and third-party dependencies
  • Inadequate cybersecurity controls impacting confidentiality, integrity, and availability of enterprise, grid, and operational systems, leading to financial, regulatory, reputational, and business continuity risks

Risk influencing factors

  • Threat evasion, delayed updates, SOC skill gaps, and incomplete attack coverage
  • Insider threats, weak access governance, privilege creep, and vulnerabilities in remote and private access
  • Policy gaps, low adherence, limited awareness, outdated practices, and inadequate guidance
  • Incomplete testing, delayed remediation, legacy systems, and new vulnerabilities
  • Delayed threat intelligence, false positives, limited automation, and analyst fatigue
  • Increased exposure from digitalisation, cloud adoption, IT-OT convergence, and external integrations
  • Human risks including phishing, weak passwords, and social engineering attacks
  • Ransomware, infrastructure attacks, supply chain vulnerabilities, regulatory requirements, and advanced persistent threats

Key mitigation

  • Cybersecurity
    • Shift Left Application Security deployment
    • DAST deployment to reduce vulnerabilities and improve response agility
    • Network behaviour analysis, UEBA, SOAR, and OT threat detection for early threat identification
    • Renewed ₹100 crore cyber insurance coverage
    • OT security upgrades across Mundra, O&M sites, Bengaluru Manufacturing Plant, 4-GW Plant, and T&D Mumbai through EDR, OT DMZ firewalls, SOC, secure remote access, CTD, and Data Diode
    • Completion of phishing simulation cycles
  • Information security
    • VAPT for websites, portals, networks, mobile apps, and IT/OT assets through CERT-In approved agencies
    • Strengthened network access, DMZ implementation, and action on NCIIPC/CERT-In advisories
    • 24x7 cybersecurity monitoring through cyber control room with enhanced automation
    • Cyber Resilience Framework based on Security by Design and Defence in Depth
    • ISO 27001:2022 and ISO 22301 governance with independent CISO oversight and Board monitoring
    • Zero Trust transformation, IT-OT segmentation, identity and privileged access controls
    • Endpoint, cloud, and data security with vendor risk governance
    • Business continuity planning focused on resilience
    • Continuous maturity enhancement through threat intelligence, red-team exercises, awareness programmes, regulatory alignment, and resilience investments

Developments during the year

  • Completed ISO 27000 certification for T&D OT systems; evaluation ongoing for DMS replacement
  • VAPT completed for 6,040 IT & OT assets, and 295 high-level vulnerabilities closed
  • Implemented PAM, SASE, and ZTNA solutions
  • Routed traffic through DMZ with CAPTCHA and strong password controls
  • Blocked 10,480 malicious URLs
  • Implemented Zabbix, Libre tools, and Grafana dashboards for IT observability and downtime monitoring
  • Deployed secure remote access, EDR, and OT DMZ firewalls for operational protection
  • Enhanced application security through DAST, SAST, and open-source/API vulnerability scanning
  • Implemented DLP controls for enterprise data protection
R3.Regulatory risk

Risks

  • Mundra coal under-recovery
  • Water securitisation of hydro plants: risk of reduced generation
  • Risk of violating environmental norms

Risk influencing factors

  • Mundra coal under-recovery is influenced by PPA tariff rigidity, imported coal and forex volatility, regulatory pass-through constraints, and dispatch conditions
  • Water securitisation risk for hydro plants is influenced by competing demand, allocation priorities, climate-driven inflow variability, and pressure on reservoir resources
  • Environmental non-compliance risk is influenced by tightening regulations, emission-control performance, operational variability, ash evacuation dependencies, and enforcement intensity

Key mitigation

  • Reduced fuel costs through coal blending, spot procurement, logistics optimisation, analytics-based monitoring, and regulatory engagement for cost pass-through and supplementary PPAs
  • Engagement with Water Resources Departments, basin authorities, and relevant stakeholders to mitigate hydro water securitisation risk
  • Implementation of FGD and De-NOx systems, emissions monitoring, 100% ash utilisation, and strengthened environmental governance to ensure regulatory compliance

Developments during the year

  • Regulatory engagement, value-based hydro operations, inflow planning, and pumped storage advocacy were progressed to mitigate water securitisation risk for hydro generation
  • Progressed commissioning of FGD and De-NOx systems, strengthened emissions monitoring, sustained 100% ash utilisation
  • Mundra SPPA signed with GUVNL; engagement in progress with other procurers
R4.Commercial risk

Risks

  • Operations and Maintenance Cost disallowance (Odisha DISCOMs)

Risk influencing factors

  • Non-Approval of OPEX schemes by the regulator due to either of the reasons:
    • Overestimation of costs
    • Lack of prudence justification
    • Change in wage policy

Key mitigation

  • Filing of truing up petition/advocacy with regulator
  • Review of expenditure for reduction
  • Reconciliation and submission of asset register, employee cost (on rolls & outsource)

Developments during the year

  • OERC has issued provisional order for True up for FY24 and FY25
  • Key regulatory matters relating to employee costs, mandatory welfare expenditures, special R&M expenses and asset-base considerations in tariff determination are being pursued with the OERC
  • OPEX optimisation initiatives were undertaken through operational best practices, technology deployment, consolidated procurement and dedicated cost-optimisation measures
  • Clarifications were sought from the OERC, with relevant matters to be addressed during the ARR and tariff determination process for FY28
  • Key regulatory and tariff-related issues continue to be highlighted during ARR submissions
R5.Financial risk

Risks

  • Availability of cost-effective capital (debt availability)
  • Forex risk

Risk influencing factors

  • Global and domestic inflation trends
  • Domestic and global GDP growth rates
  • Monetary policies of the RBI and global central banks
  • Global geopolitical developments
  • Risk of Rupee depreciation against the USD due to dependence on imported raw materials such as coal, wafers, and cells
  • Environmental compliance risk arising from tightening regulations, emission-control performance, operational variability, ash evacuation dependencies, and regulatory enforcement intensity

Key mitigation

  • Diversification of lender base through long-tenor loans, bond issuances, and fixed-rate financing or interest rate swaps (IRS)
  • Continuous monitoring and hedging of foreign currency exposures

Developments during the year

  • Interest rates declined following RBI policy rate cuts and global monetary easing by central banks, resulting in lower rates across major economies
  • Currency markets remained volatile due to global and domestic factors, leading to significant depreciation of the Rupee against the USD
R6.Business risk

Risks

  • Availability of fuel for thermal plant at optimal cost
  • Natural disasters like cyclones, flood, drought, storm, earthquake, and lightning (Odisha DISCOMs)

Risk influencing factors

  • Fuel availability at optimal cost is influenced by coal price and quality volatility, freight constraints, regulatory dependencies, and plant dispatch levels
  • Odisha DISCOMs are exposed to cyclone risk due to their east coast location. Long overhead lines and dense vegetation increase network vulnerability.

Key mitigation

  • Diversification of coal sourcing, fuel and logistics optimisation, price-sensitivity analysis, and strengthening of long-term supply arrangements to ensure fuel availability at optimal cost
  • Sensitivity and scenario analysis of coal prices, freight, and transportation costs integrated into business planning and periodic reviews for proactive decision-making
  • Formulation and review of Disaster Management Plans (DMP) and Business Continuity Plans (BCP), along with awareness programmes for employees and Business Associates
  • Resource and emergency-response planning, including contractor identification and inspection of transit stores for critical materials
  • Development of cyclone-resilient networks and ensuring power continuity for critical medical facilities
  • Maintenance of cyclone inventory in coordination with government authorities, supported by insurance coverage and government assistance

Developments during the year

  • Fuel sourcing diversification, logistics optimisation, cost monitoring, and strengthened supply arrangements to ensure fuel availability at optimal cost
  • Regular review of DMP and BCDMP, supported by quarterly awareness programmes for employees, contractors, and Business Associates
  • Three-layer emergency response structure and preparedness reviews with Business Associates for post-monsoon restoration readiness
  • Inspection and maintenance of transit stores and emergency material inventory
  • Collaboration with group companies, manufacturers, and academic institutions to develop cyclone-resilient infrastructure
  • Identification and prioritisation of critical feeders for early restoration during emergencies
  • Coordination with government authorities and Business Associates for disaster-relief material procurement
  • Evaluation of insurance and parametric risk cover, supported by government capex and post-disaster grants for resilient network development
R7.Climate change, water and Business Continuity Plan (BCP)

Risks

  • Climate change linked with transitional risk:
    • Possibility of capping carbon emissions
  • Climate change linked with physical risks:
    • For operations located in the coastal area
    • Rise in water temperature potentially affecting processes
    • Extreme weather events such as floods and droughts, fuel, and water scarcity
  • Risk of pandemic and other natural disasters
  • Reduced generation due to changing weather patterns

Risk influencing factors

  • Increasing environmental activism and evolving GHG emission regulations
  • Emergence of carbon markets and energy-transition policies
  • Rising sea and water temperatures
  • Increasing frequency of extreme weather and climate-induced disruptions
  • Water stress and competing urban and industrial demand
  • Pandemic, public health, infrastructure, and supply-chain risks
  • Variability in wind, solar, monsoon, and irradiance patterns impacting renewable generation predictability

Key mitigation

  • Accelerating renewable energy capacity addition to reduce portfolio GHG intensity
  • Adoption of technologies such as Coal Catalyst and CCU, and exploration of low-carbon fuels and thermal flexibilisation
  • Implementation of rainwater harvesting and exploration of alternate water sources, including STP water for cooling
  • Strengthening business continuity and disaster management frameworks, supported by ISO 22301:2019 recertification
  • Enhancing intraday and day-ahead forecasting through AI/ML-driven models, real-time weather analytics, and park-level scheduling aggregation to improve operational optimisation and reduce DSM exposure and revenue volatility

Developments during the year

  • Added 968 MW renewable capacity, increasing green portfolio share
  • Continued pilots and deployment of emissions reduction technologies, including CCUS and Coal Catalyst
  • Progressed initiatives in alternative power generation, including nuclear energy
  • Achieved Water Neutrality (Scope 1 – Aspiring Certificate) for Generation and RE divisions
  • T&D certification targeted by Q1 FY27 Scope 2 certification from CII under progress for all divisions
  • Finalisation of city STP water utilisation for three divisions
  • Recertified ISO 22301:2019 for Business Continuity Management System
  • Implemented AI/ML-based and skycam-enabled forecasting, along with pilot initiatives with research institutions and start-ups
R8.Project risk

Risks

  • If there is a delay in commissioning of project, LD is levied for the delayed period
  • Project execution timelines exceeding internal/Scheduled Commercial Operation Date (SCOD) target dates
  • Transmission projects: Risk of delay in execution and external environment in material delivery and costs

Risk influencing factors

  • Land acquisition delays due to title disputes, outdated records, legal delays, administrative dependencies, connectivity constraints, and compensation disagreements
  • Skilled manpower and resource shortages amid rapid renewable sector growth
  • Delays in power evacuation infrastructure
  • Project disruptions due to unseasonal rains, storms, and floods
  • Extended supply timelines for modules and equipment due to rising industry demand
  • TBCB transmission project delays, time overruns, and developer accountability risks
  • Cost overrun risks dependent on CERC/SERC approvals for recovery of escalations

Key mitigation

  • Creation of government and private land banks through dedicated acquisition teams and timely land securitisation
  • Inorganic land acquisition and turnkey project allocation to developers
  • Improved land and connectivity readiness aligned with pre-bid timelines
  • Tight project monitoring from pre-bid stage to SCOD, supported by dedicated project management teams
  • Streamlined execution through integrated contracting, regulatory clearances, and enhanced pre-bid diligence
  • Engagement with local authorities and specialised partners to address RoW, land, and forest-related issues
  • Strengthened supply chain management, execution capabilities, and project assessment
  • Complete EPC execution for wind projects through leading players

Developments during the year

  • Creation of government and private land banks, supported by dedicated project development teams, to ensure timely project execution
  • Inorganic land acquisition and turnkey project allocation to developers
  • Development of alternate vendors, long-term supplier tie-ups, and close supplier coordination for timely material availability
  • Early engagement for statutory, environmental, forest and other relevant clearances, supported by land and route experts to minimise rerouting and cost overruns
  • Dedicated RoW teams, local liaison support, land aggregators, and coordination with district authorities to address RoW and land-related issues
  • Engagement of consultants and forest authorities to assess clearance requirements and manage stakeholder and public concerns
  • Pre-qualified EPC vendor pools, contractor capability assessment, and exploration of long-term tie-ups with OEMs and service providers
  • Capability building through lateral hiring and use of modern project-monitoring tools for timely corrective action
  • Forex and LME price hedging, capped variation clauses, and contingency provisioning to mitigate cost escalation risks
Risk has intensified
Risk has diminished
Risk has remained stable
Back To Top