Skip to main content
Category: Regulatory Disclosure

Item 105 Risk Factors

Also known as: Item 105, Regulation S-K Item 105, 17 CFR 229.105, Risk Factors (Item 105)
Simply put

Item 105 is a U.S. Securities and Exchange Commission (SEC) disclosure requirement that directs companies to describe the material factors that make investing in them, or in a particular securities offering, speculative or risky. It appears under a "Risk Factors" heading in registration statements and other filings so that investors can understand the significant risks before making a decision. Under amendments adopted by the SEC in 2020, filings whose risk factor sections run beyond a specified length must include a short summary of those risks.

Formal definition

Item 105 of Regulation S-K (codified at 17 CFR 229.105) requires registrants, where appropriate, to provide under the caption "Risk Factors" a discussion of the material factors that make an investment in the registrant or an offering speculative or risky. It governs the content and presentation of risk factor disclosure in SEC filings such as registration statements and is issued and enforced by the SEC. Under rule amendments the SEC adopted on August 26, 2020 to modernize these disclosures, the item was amended to, among other things, require a summary risk factor disclosure of no more than two pages where the risk factor section exceeds 15 pages. Item 105 is a securities disclosure obligation applicable to registrants subject to SEC reporting requirements in the United States; it does not itself prescribe internal risk management processes, controls, or how the underlying risks should be treated, and its applicability depends on the specific filing and registrant context.

Why it matters

Item 105 sits at the intersection of securities regulation and investor protection. By requiring registrants to describe, under a dedicated "Risk Factors" heading, the material factors that make an investment speculative or risky, the SEC gives investors a structured place to understand significant risks before committing capital. For compliance and legal teams, the quality of this disclosure carries consequences: inadequate, boilerplate, or misleading risk factors can attract SEC comment letters and, in some circumstances, form the basis of securities litigation alleging that material risks were not adequately disclosed.

The 2020 amendments the SEC adopted on August 26, 2020 were intended to modernize risk factor disclosure and address the tendency of these sections to grow long and generic. Among the changes, filings whose risk factor section exceeds 15 pages must include a summary of no more than two pages. This raises the practical stakes for how registrants curate and prioritize the risks they present, since overly lengthy or undifferentiated disclosure now triggers an additional summary obligation and signals to reviewers that the section may not be sufficiently tailored.

For GRC functions, Item 105 is where enterprise and offering-specific risk considerations become externally visible and legally consequential. The disclosure is not a substitute for internal risk management, but the two are related: the risks an organization identifies and monitors internally should inform, and be consistent with, what it tells investors. Divergence between internal risk assessments and public risk factor language can create both regulatory and reputational exposure.

Who it's relevant to

Securities and Disclosure Counsel
Legal specialists responsible for preparing registration statements and periodic filings drafting the Risk Factors section to meet Item 105, including the summary requirement that applies when the section exceeds 15 pages. Their focus is on tailoring risk language to the registrant and offering rather than relying on boilerplate.
Compliance Officers
Compliance professionals at SEC-reporting registrants who help ensure filings satisfy applicable disclosure obligations and who monitor for SEC comment letters or inquiries relating to risk factor adequacy. Note that Item 105 is a disclosure obligation and does not prescribe internal control processes.
Risk Managers
Enterprise and operational risk personnel whose internal risk identification and assessment work informs, and should be consistent with, the material factors disclosed under Item 105. Their input helps align externally disclosed risks with the organization's internal understanding of its risk profile.
Internal Auditors and Assurance Functions
Assurance professionals who may assess whether processes supporting disclosure are sound and whether public risk representations are consistent with internal records. Consistent with independence principles, their role is to provide assurance over the disclosure process rather than to manage or draft the disclosures themselves.
Governance Bodies and Boards
Directors and audit or disclosure committees who oversee the integrity of the organization's public disclosures, including whether risk factor disclosure reasonably reflects the risks the organization faces. Their oversight concerns decision rights and accountability rather than the operational drafting of filings.

Inside Item 105 Risk Factors

Material Risk Factor Disclosure
Item 105 requires registrants to provide a discussion of the material factors that make an investment in the registrant or offering speculative or risky. The emphasis is on materiality, meaning factors reasonably likely to affect the company, rather than a comprehensive list of every conceivable risk.
Company-Specific Tailoring
Disclosures are expected to be specific to the registrant's particular circumstances rather than generic boilerplate. The requirement contemplates that risk factors reflect the actual facts, operations, industry, and exposures of the reporting company.
Organized Presentation and Summary
Where the risk factor discussion exceeds a specified length, a concise summary of the principal risk factors is contemplated. Risk factors are also expected to be organized under relevant headings to aid readability and navigation.
Risk Categorization
Grouping risk factors under logical categories (for example, risks related to the business, industry, regulation, or the securities offered) supports clearer presentation and helps investors locate the risks most relevant to their decision.
Applicability Across Filings
Item 105 is a component of the U.S. SEC's Regulation S-K and applies to various registration statements and periodic reports that incorporate Regulation S-K disclosure requirements. Its scope is tied to filings made under the U.S. federal securities laws.

Common questions

Answers to the questions practitioners most commonly ask about Item 105 Risk Factors.

Does listing a risk factor under Item 105 mean the company must have a control or mitigation plan for it?
No. Item 105 is a disclosure requirement, not a risk management or control requirement. Its purpose is to inform investors of material factors that make an investment speculative or risky. Disclosing a risk factor is a compliance and reporting activity; it does not by itself constitute the identification, assessment, or treatment of that risk within the organization's risk management program. A company may disclose risks it has chosen to accept without describing any mitigation, and conversely may manage many risks that never rise to the disclosure threshold. Treat the two as distinct exercises that should inform, but not substitute for, one another.
Are Item 105 risk factors the same as an enterprise risk register or the output of the risk management function?
Not necessarily. A risk register is an internal risk management artifact used to identify, assess, and monitor risks against organizational objectives, and it typically includes internal detail such as ratings, owners, and control status. Item 105 risk factors are externally facing disclosures aimed at investors and are governed by disclosure standards of materiality and relevance rather than internal risk methodology. The two may draw on overlapping information, but they differ in audience, purpose, level of detail, and the criteria used to decide what is included. One should not be assumed to be a copy of the other.
How does an organization decide which risks are material enough to warrant disclosure under Item 105?
Materiality for disclosure purposes generally turns on whether a reasonable investor would consider the information important to an investment or voting decision. Determinations commonly involve coordination among legal, financial reporting, and risk personnel, and often draw on internal risk assessments, prior disclosures, and events during the reporting period. Because materiality is context-specific and can involve legal judgment, organizations typically involve securities counsel. This entry does not provide legal advice, and specific thresholds and application vary by facts, jurisdiction, and applicable interpretive guidance.
How can risk factor disclosures be kept current across successive filings?
Many organizations establish a periodic review process, tied to their reporting calendar, in which draft risk factors are revisited against changes in the business, operating environment, and prior disclosures. This commonly includes input from business units, legal, financial reporting, and risk functions. The aim is generally to avoid stale or purely generic language and to reflect developments during the period. The specific cadence and workflow depend on the organization and its filing obligations, and this entry does not prescribe a particular process or tooling.
What role do assurance functions play relative to Item 105 disclosures?
Assurance functions, such as internal audit, may provide independent evaluation of the processes used to gather, review, and approve disclosures, but they generally do not draft the disclosures themselves, since preparing disclosures is a management activity. Maintaining this separation preserves the independence and objectivity of the assurance function. The nature and extent of any assurance over disclosure processes vary by organization, and external auditor responsibilities regarding disclosures are defined by applicable auditing and securities requirements rather than by this entry.
How can generic or boilerplate risk factor language be avoided?
Disclosures that merely recite hypothetical or industry-wide risks without connecting them to the specific organization are often criticized as offering limited value to investors. In practice, organizations may seek to describe how a given risk applies to their particular circumstances, drawing on internal risk assessments and business knowledge. The appropriate level of specificity is a matter of judgment, commonly informed by legal counsel and applicable interpretive guidance, and it must be balanced against other considerations. This entry does not prescribe specific wording or legal conclusions.

Common misconceptions

Item 105 requires companies to disclose every risk they face.
The requirement focuses on material risk factors, those reasonably likely to be significant to an investment decision. Listing exhaustive or hypothetical risks that are not material is not the intent and can obscure the disclosures that matter.
Risk factor disclosure is a compliance formality that can rely on standard boilerplate language.
The disclosure is expected to be tailored to the registrant's specific circumstances. Generic language that could apply to any company is commonly viewed as inconsistent with the objective of informing investors about the registrant's particular risks.
Item 105 is a risk management or governance requirement about how a company controls its risks.
Item 105 is a securities disclosure obligation about informing investors of material risks; it does not itself prescribe how an organization identifies, assesses, or treats those risks. The underlying risk management activities fall under separate frameworks and are outside the scope of this disclosure item.

Best practices

Ground each disclosed risk factor in the registrant's specific facts and circumstances, avoiding generic language that could apply to any company.
Apply a materiality lens to select and prioritize risk factors, focusing on those reasonably likely to affect an investment decision rather than cataloging every conceivable risk.
Organize risk factors under clear, relevant headings and provide the contemplated concise summary when the discussion exceeds the applicable length threshold.
Coordinate the disclosure process with subject-matter owners across the business so that the risk factors reflect current operational, industry, and regulatory realities.
Review and update risk factors each reporting period to reflect changes in the registrant's circumstances rather than carrying forward prior-period text unchanged.
Confirm applicability to the specific filing type under Regulation S-K and consult qualified securities counsel for interpretation, as this guidance does not constitute legal advice.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide