Governance, risk and compliance

SmartSuite for the Chief Risk Officer

The Chief Risk Officer owns the enterprise risk framework: appetite, taxonomy, assessment method and the board's view of exposure. They integrate operational, cyber, third-party and resilience risk into one picture and make sure every top risk has an owner and a funded response.

What you own

  • Set and maintain the enterprise risk appetite, taxonomy and assessment methodology
  • Chair the risk committee and report risk posture to the board
  • Aggregate risk across operational, financial, cyber, third-party and resilience domains
  • Ensure every top risk has an accountable owner and a tracked treatment plan
  • Oversee key risk indicators and escalation thresholds
  • Coordinate the second line with internal audit and compliance
  • Approve the risk-based inputs to strategy, capital and continuity decisions

Where the role sits

Each name opens that role's page.

Reports to

Chief Executive Officer

Chief Executive Officer

See the role
Board Risk Committee Chair

Board Risk Committee Chair

See the role

Direct reports

Enterprise Risk Director

Enterprise Risk Director

See the role
Operational Risk Manager

Operational Risk Manager

See the role
IT Risk Manager

IT Risk Manager

See the role
Third-Party Risk Manager

Third-Party Risk Manager

See the role
Head of Operational Resilience

Head of Operational Resilience

See the role
Fraud Risk Manager

Fraud Risk Manager

See the role
Model Risk Manager

Model Risk Manager

See the role

Works closely with

Chief Compliance Officer

Chief Compliance Officer

See the role
Chief Audit Executive

Chief Audit Executive

See the role
Chief Information Security Officer

Chief Information Security Officer

See the role
Chief Financial Officer

Chief Financial Officer

See the role
Risk Committee Member

Risk Committee Member

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

risk, reporting

Touches

contributes or approves

resilience, third-party, compliance, issues-actions

Depends on

consumes its output

audit, privacy, esg, ai-governance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

How they use SmartSuite

How they use the Enterprise Risk Management suite

Enterprise risk oversight

Reviews enterprise-wide risk exposure, top risks, and mitigation status in real time.

Strategic exposure reports

Delivers executive and board reporting on risk posture and trends.

Mitigation governance

Ensures mitigation plans are owned, tracked, and executed on schedule.

Suites that serve this role

How SmartSuite supports this role

Risk management. Gives the CRO one live risk register with heat maps, KRIs and roll-ups from every business unit, so top-risk exposure and mitigation status are read in real time rather than compiled quarterly.

Operational resilience. Links important business services, BIAs and continuity plans to the risks they protect, so resilience readiness appears in the same exposure view.

Third-party risk. Rolls vendor risk tiers and open remediation into the enterprise register so supplier concentration and critical-vendor exposure are part of the risk picture.

Issues and actions. Tracks every mitigation plan with an owner, a due date and automated escalation, so the CRO can see which treatments are slipping before the committee meets.

Reporting. Produces executive and board risk reports from live data, including strategic exposure trends, without a manual deck-building cycle.

Industry reference

COSO ERM (2017) and ISO 31000:2018 describe the framework the Chief Risk Officer owns: a stated risk appetite, one taxonomy, a repeatable assessment method and risk reported alongside strategy. US federal agencies carry the same duty through OMB Circular A-123, which has required enterprise risk management since 2016.

In banking the role is prescribed. The Basel Committee's corporate governance principles (2015) expect an independent risk function led by a CRO with access to the board, and the Federal Reserve's enhanced prudential standards require large bank holding companies to appoint one. Insurers carry the equivalent duty through the Solvency II risk-management function and the ORSA, mirrored in the NAIC ORSA Model Act.

In their words

Related roles

Chief Executive Officer

Chief Executive Officer

See the role
Board Risk Committee Chair

Board Risk Committee Chair

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.