Skip to content
BIZENIUS

What does a chief risk officer actually do? The mandate, the rooms and the veto

BIZENIUS Advisory Team · Last updated: 3 September 2026

Written and reviewed by the BIZENIUS advisory practice — senior practitioners from risk, treasury, finance and supervision.

The chief risk officer role explained as it is actually held: what the mandate consists of, where the CRO reporting line should run, which rooms decide the seat’s effectiveness, and when the veto exists.

In short

  • A chief risk officer is the executive paid by the institution to stand apart from it: to know what risk the institution is actually carrying, to hold that inside the boundary the board agreed, and to be heard before a decision is taken rather than recorded after it.
  • The mandate has an architecture — independence, a reporting line that reaches the board, and a second line that operates under pressure — and it is tested by how those work in a bad week, not by how the organisation chart draws them.
  • Three rooms decide whether the seat works: the board risk committee, the regulator relationship, and the axis with the chief executive. A CRO who is effective in only one of them is not yet holding the mandate.
  • The veto is real in some institutions and notional in others. Where it exists it is spent rarely, in the open, and with the numbers; where it does not, the CRO’s instrument is being heard early enough that a veto is never needed.
  • The seat’s hardest test is the risk that materialises. What the CRO does in those hours — information, escalation, the record kept — and in the post-mortem afterwards decides the credibility of the function long afterwards.
On this page
  1. What a chief risk officer is
  2. The architecture of the mandate
  3. The rooms that decide the seat
  4. The veto
  5. Where the seat goes wrong
  6. The hardest test

What a chief risk officer is#

A chief risk officer is the executive paid by the institution to stand apart from it. The role exists so that someone at the top table knows what risk the institution is actually carrying, holds that inside the boundary the board agreed, and is heard before a decision is taken rather than recorded after it.

That last clause is the whole of the seat. A risk function that is consulted after the fact, that documents decisions it did not shape, that is respected in the way a compliance requirement is respected, has already failed — however well its models run. The CRO responsibilities that matter are the ones exercised before the decision.

The architecture of the mandate#

The mandate rests on three structural facts, and each of them is tested by pressure rather than by the organisation chart.

  • Independence: the CRO’s assessment of a risk cannot be overruled by the business that wants to take it. Independence that exists on paper and dissolves in the room is the most common failure of the seat.
  • The reporting line: a CRO reporting line that reaches the board — through the risk committee and its chair — rather than ending with the chief executive, so that the second line can be heard by the people who own the boundary.
  • The second line of defence as it operates under pressure: the limits, the escalation paths and the challenge that hold when a desk is profitable, a deal is late and the chief executive wants it done.

Risk appetite belongs here only as the boundary the CRO enforces. The document itself is the board’s; what the seat owns is whether the business feels it — whether a limit is something a desk can actually hit, and whether hitting it changes anything.

The rooms that decide the seat#

A CRO is effective, or not, in three rooms. The board risk committee is the first: the paper the CRO writes for it, the briefing given across the table, and the professional dissent the committee should be able to hear from the seat without drama. The regulator is the second, and the relationship is a standing discipline rather than an event — a supervisor who learns of a problem from the CRO before learning of it from the numbers treats the institution differently. The chief executive is the third: the CRO is partner and check at once, and the line between the two is the seat’s daily work.

A CRO who is effective in only one of the three rooms is not yet holding the mandate.

A CRO who is effective in only one of the three rooms is not yet holding the mandate. The committee that trusts a CRO the chief executive ignores has a report, not a risk function; the chief executive who relies on a CRO the regulator does not believe has an adviser, not a second line.

The veto#

In some institutions the CRO holds a formal veto over transactions or limits; in many the veto is notional, a right that exists until it is used. Either way the discipline is the same: a veto is spent rarely, in the open, and with the numbers, because a veto exercised in private or on instinct costs the seat more than the risk it stopped. Where no veto exists the CRO’s instrument is being heard early enough that one is never needed — which is the point of the reporting line and the rooms above.

Where the seat goes wrong#

The role fails in recognisable ways. The CRO becomes the office of no, respected and routed around. Or the CRO becomes the chief executive’s risk adviser, influential and no longer independent. Or the function produces reports written to be approved, and the board learns of the real exposure from a loss rather than from the seat. Each of these is a failure of the mandate’s architecture under pressure, not a failure of technique.

The hardest test#

The seat is finally judged on the risk that materialises. In those hours the CRO owns the information the institution acts on, the escalation to the people who must decide, and the record that will be read afterwards by the board, the regulator and possibly others. Then comes the post-mortem — without scapegoats, but with consequences — and the slower work of rebuilding credibility: of the models that missed it, of the function that ran them, and of the officer who signed the reports. A CRO who has thought about that week before it arrives holds the seat differently from one who has not, which is what The CRO Mandate is built to work through.

Frequently asked

What is the role of a chief risk officer?

The chief risk officer is the executive responsible for knowing what risk the institution actually carries, keeping it inside the boundary the board agreed, and being heard before decisions are taken. The role leads the second line of defence and answers to the board through its risk committee, while working daily alongside the chief executive as both partner and check.

Who should the CRO report to?

The CRO reporting line should reach the board, through the risk committee and its chair, rather than end with the chief executive. The CRO works with the chief executive every day, but independence depends on the second line being able to be heard by the people who own the risk boundary — and on that access holding in a bad week, not only on the organisation chart.

Does a chief risk officer have a veto?

In some institutions the CRO holds a formal veto over transactions or limits; in many it is notional. Where it exists it should be spent rarely, in the open and with the numbers, because a veto used in private or on instinct costs the seat more than the risk it stopped. Where it does not exist, the CRO’s instrument is being heard early enough that a veto is never needed.

What is the difference between the CRO and the head of risk?

A head of risk runs the risk function: models, limits, reporting, the second line’s daily work. The chief risk officer holds the mandate at the top table — independence with influence, the board risk committee and the regulator relationship, the axis with the chief executive, and the decisions that arrive under pressure. Many heads of risk have a confirmed path to the seat; the difference is the rooms, not the technique.

More where this came from

Browse the full resources hub, or subscribe in the footer for occasional substantial pieces.

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.