| Detail | For this role |
|---|---|
| Department | Leadership and Senior Management |
| Level | Leadership |
| Reports to | Chief Executive Officer |
| Direct reports | Credit Risk Head, Operational Risk Head, Market Risk Head |
| Experience | 15+ years in risk, with 5 years in a senior risk leadership role |
Chief Risk Officer job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: Chief Risk Officer
Department: Leadership and Senior Management
Reports to: Chief Executive Officer
Location: [City], [office, branch or site]
About the role
A Chief Risk Officer protects the company from the risks that could hurt it most. They build the risk framework, identify credit, operational, market and compliance risks, and make sure the business takes risk knowingly and within limits. The role is common in banks, NBFCs and large companies, and reports to both management and the board's risk committee. A good CRO spots risk early, sets sensible limits, keeps losses within appetite, and helps the business grow without taking on danger it cannot survive.
Key responsibilities
- Build the enterprise risk framework, and set the risk appetite with the board and management.
- Identify and assess credit, operational, market, liquidity and compliance risks across the business.
- Set risk limits and controls, and monitor exposures against them.
- Run credit policy and approvals for lending businesses, and watch portfolio quality.
- Track operational risk events and near misses, and drive fixes to the root causes.
- Stress-test the business against downturns and shocks, and plan the response.
- Report the risk profile, breaches and trends to the board's risk committee.
- Keep the company compliant with the risk and prudential rules of its regulators.
- Challenge business decisions that would breach appetite, and escalate when overruled.
- Build the risk team and embed risk ownership in the business lines.
Requirements
- Degree in finance, economics or a related field
- FRM, CA or MBA finance is an advantage
- Long experience in risk in banking, NBFC or a large company
- 15+ years in risk, with 5 years in a senior risk leadership role
KRAs and KPIs for a Chief Risk Officer
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Loss control | Credit and operational losses held within the approved risk appetite |
| Portfolio quality | Non-performing exposures held below the target for the year |
| Limit discipline | Risk limit breaches closed within the agreed timeline |
| Operational risk | High-severity risk events reduced to the target level |
| Regulatory compliance | Risk and prudential filings met on time with no major findings |
| Risk coverage | Key risks identified, assessed and mitigated on the agreed schedule |
Skills and tools
Tools used day to day: Risk management systems, Credit scoring models, MS Excel, BI dashboards, GRC tools.
Reporting line and career path
Next roles: Chief Executive Officer, Managing Director
Interview questions for a Chief Risk Officer
- How would you set a risk appetite that protects the company without blocking growth?
- The business wants to enter a segment you see as high risk. How do you handle it?
- Walk me through how you would stress-test our loan portfolio against a downturn.
- How do you get business lines to own risk instead of treating it as your problem?
- A limit breach keeps recurring. How do you find and fix the root cause?
- How do you report risk to the board so they act rather than just note it?
Managing a Chief Risk Officer in ZeniaHR
Hire and manage your leadership and senior management team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does a Chief Risk Officer do?
A Chief Risk Officer builds the risk framework and protects the company from credit, operational, market and compliance risks. They set the risk appetite and limits, monitor exposures, run credit policy for lenders, stress-test the business, and report the risk profile to the board's risk committee. They help the company grow within safe limits.
What is the difference between a CRO and a CISO?
A Chief Risk Officer covers the full range of business risk: credit, operational, market and compliance. A Chief Information Security Officer covers one type, information security risk. The CISO's work often feeds into the CRO's wider risk picture. In banks and NBFCs the two roles are distinct and both report risk to the board.
Who does a Chief Risk Officer report to?
A Chief Risk Officer usually reports to the Chief Executive Officer for day-to-day matters and to the board's risk committee for independence. In regulated firms like banks and NBFCs this dual line is expected, so risk decisions cannot be quietly overruled by the business. The reporting line protects the CRO's ability to challenge.