Skip to content
AGJ, the AI governance job board
Menu

Executive job description template

Chief Risk Officer (CRO)

The Chief Risk Officer owns enterprise risk management, giving the organization a clear view of the risks it faces and the appetite it holds for them. This template reflects how the role is scoped at regulated enterprises today, including newer categories such as AI and model risk. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleChief Risk Officer (CRO)
DepartmentEnterprise Risk Management / Executive Leadership
Reports to[Chief Executive Officer / Board Risk Committee / Chief Financial Officer]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Chief Risk Officer (CRO) provides executive leadership for [Company]'s enterprise risk management program. This role owns the framework, appetite, and governance that identify, assess, monitor, and report the full range of risks the organization faces, from strategic and financial to operational, technology, and emerging risk.

The CRO partners closely with executive leadership, the Board, finance, compliance, internal audit, cybersecurity, privacy, and business units to embed risk-based decision making across the enterprise. The role maintains independence as a second-line function and provides objective challenge.

As organizations adopt AI and automated decision making, the Chief Risk Officer increasingly oversees AI and model risk as part of the enterprise risk portfolio, working with model risk, technology, and AI governance leaders to keep these risks within appetite.

Key responsibilities

Enterprise risk strategy

Risk identification and assessment

Lead identification and assessment across the enterprise risk portfolio, including:

Risk governance and committees

Monitoring and reporting

Develop enterprise reporting covering Key Risk Indicators (KRIs), limit monitoring, risk-appetite breaches, loss events, scenario analysis, stress testing, executive dashboards, and Board reporting.

Model and AI risk oversight

Oversee model risk management and, increasingly, AI risk, ensuring models and AI systems are inventoried, validated, monitored, and governed within enterprise risk appetite alongside model risk and AI governance leaders.

Capital, resilience, and continuity

Regulatory engagement and culture

Engage with regulators and examiners on risk matters, ensure the program meets supervisory expectations, and build a strong risk culture with clear accountability across the three lines.

Required qualifications

Preferred certifications

One or more of: FRM, PRM, CRISC, CIA, CRMA, CFA, and ISO 31000 training where the role requires framework depth.

Technical knowledge

Enterprise risk management, risk appetite and taxonomy design, quantitative and qualitative risk assessment, credit, market, liquidity, and operational risk, technology and cybersecurity risk, third-party risk, scenario analysis and stress testing, model risk management, AI and automated-decision risk, operational resilience, risk reporting and KRIs, and GRC platforms.

Essential competencies

Executive leadership, strategic and quantitative judgment, executive and Board communication, independent challenge, influence across the three lines, program management, regulatory interpretation, and composure under pressure.

Success measures: first 12 months

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in enterprise risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC leadership jobs

Stay close to the market

Frequently asked questions

What does a Chief Risk Officer (CRO) do?

The Chief Risk Officer owns enterprise risk management. They set the risk framework and appetite, identify and assess risks across the organization, monitor exposures and limits, and report the enterprise risk profile to executive leadership and the Board as an independent second-line function.

What qualifications and certifications does a Chief Risk Officer need?

Most CROs bring 15 to 20 or more years in risk, finance, audit, or a related second-line function, including at least 5 years leading programs, often with a Master's degree or MBA. Common certifications include FRM, PRM, CRISC, CIA, and CRMA.

Who does a Chief Risk Officer report to?

The CRO typically reports to the Chief Executive Officer, a Board Risk Committee, or in some structures the Chief Financial Officer. A direct line to the Board supports the independence the role requires.

How does AI affect the Chief Risk Officer role?

AI and automated decisions introduce new sources of risk, from model failure and bias to third-party and regulatory exposure. The CRO folds AI and model risk into the enterprise risk portfolio and keeps it within appetite, using frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 alongside model risk and AI governance leaders.