| Title | Chief Risk Officer (CRO) |
|---|---|
| Department | Enterprise Risk Management / Executive Leadership |
| Reports to | [Chief Executive Officer / Board Risk Committee / Chief Financial Officer] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Chief Risk Officer (CRO) provides executive leadership for [Company]'s enterprise risk management program. This role owns the framework, appetite, and governance that identify, assess, monitor, and report the full range of risks the organization faces, from strategic and financial to operational, technology, and emerging risk.
The CRO partners closely with executive leadership, the Board, finance, compliance, internal audit, cybersecurity, privacy, and business units to embed risk-based decision making across the enterprise. The role maintains independence as a second-line function and provides objective challenge.
As organizations adopt AI and automated decision making, the Chief Risk Officer increasingly oversees AI and model risk as part of the enterprise risk portfolio, working with model risk, technology, and AI governance leaders to keep these risks within appetite.
Key responsibilities
Enterprise risk strategy
- Design and own the Enterprise Risk Management (ERM) framework.
- Define risk appetite, tolerance, and the enterprise risk taxonomy.
- Integrate risk into strategy, planning, and capital decisions.
- Establish risk governance, committees, and reporting lines.
- Present the enterprise risk profile to executive leadership and the Board.
Risk identification and assessment
Lead identification and assessment across the enterprise risk portfolio, including:
- Strategic, financial, credit, market, and liquidity risk where relevant
- Operational, technology, cybersecurity, and third-party risk
- Compliance, legal, and reputational risk, in partnership with those functions
- Emerging risk including AI, model, and automated-decision risk
Risk governance and committees
- Chair or co-chair enterprise risk committees.
- Maintain risk policies, standards, and delegated authorities.
- Oversee the risk and control self-assessment process.
- Ensure new initiatives receive appropriate risk review.
Monitoring and reporting
Develop enterprise reporting covering Key Risk Indicators (KRIs), limit monitoring, risk-appetite breaches, loss events, scenario analysis, stress testing, executive dashboards, and Board reporting.
Model and AI risk oversight
Oversee model risk management and, increasingly, AI risk, ensuring models and AI systems are inventoried, validated, monitored, and governed within enterprise risk appetite alongside model risk and AI governance leaders.
Capital, resilience, and continuity
- Support capital adequacy, insurance, and risk-transfer decisions.
- Oversee operational resilience and business continuity.
- Coordinate crisis management and incident escalation.
- Assess concentration and interconnected risk.
Regulatory engagement and culture
Engage with regulators and examiners on risk matters, ensure the program meets supervisory expectations, and build a strong risk culture with clear accountability across the three lines.
Required qualifications
- Bachelor's degree in Finance, Economics, Business, Risk Management, Mathematics, or a related discipline. Master's degree or MBA preferred.
- 15 to 20+ years of progressive experience in risk management, finance, audit, or a related second-line function.
- 5+ years leading an enterprise or major business-line risk program.
- Experience briefing executive leadership and Boards of Directors.
- Deep knowledge of enterprise risk frameworks and the regulatory environment for the industry.
- Experience overseeing quantitative risk, and familiarity with model and AI risk.
Preferred certifications
One or more of: FRM, PRM, CRISC, CIA, CRMA, CFA, and ISO 31000 training where the role requires framework depth.
Technical knowledge
Enterprise risk management, risk appetite and taxonomy design, quantitative and qualitative risk assessment, credit, market, liquidity, and operational risk, technology and cybersecurity risk, third-party risk, scenario analysis and stress testing, model risk management, AI and automated-decision risk, operational resilience, risk reporting and KRIs, and GRC platforms.
Essential competencies
Executive leadership, strategic and quantitative judgment, executive and Board communication, independent challenge, influence across the three lines, program management, regulatory interpretation, and composure under pressure.
Success measures: first 12 months
- Assess and refresh the enterprise risk framework.
- Define or recalibrate risk appetite and taxonomy.
- Strengthen risk identification and assessment across units.
- Improve KRIs, limits, and risk reporting.
- Establish or refresh enterprise risk committees.
- Integrate model and AI risk into the risk portfolio.
- Advance operational resilience and continuity.
- Strengthen risk culture and Board reporting.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in enterprise risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC leadership jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Chief Risk Officer (CRO) do?
The Chief Risk Officer owns enterprise risk management. They set the risk framework and appetite, identify and assess risks across the organization, monitor exposures and limits, and report the enterprise risk profile to executive leadership and the Board as an independent second-line function.
What qualifications and certifications does a Chief Risk Officer need?
Most CROs bring 15 to 20 or more years in risk, finance, audit, or a related second-line function, including at least 5 years leading programs, often with a Master's degree or MBA. Common certifications include FRM, PRM, CRISC, CIA, and CRMA.
Who does a Chief Risk Officer report to?
The CRO typically reports to the Chief Executive Officer, a Board Risk Committee, or in some structures the Chief Financial Officer. A direct line to the Board supports the independence the role requires.
How does AI affect the Chief Risk Officer role?
AI and automated decisions introduce new sources of risk, from model failure and bias to third-party and regulatory exposure. The CRO folds AI and model risk into the enterprise risk portfolio and keeps it within appetite, using frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 alongside model risk and AI governance leaders.