Skip to content
BIZENIUS

When risk materialises: the CRO’s checklist for the crisis, the post-mortem and the rebuild

BIZENIUS Advisory Team · Last updated: 3 September 2026

Written and reviewed by the BIZENIUS advisory practice — senior practitioners from risk, treasury, finance and supervision.

The questions a chief risk officer should be able to answer before a risk crystallises, in the first hours, in front of the board and the regulator, in the post-mortem, and in the slower work of rebuilding the credibility of the models, the function and the seat.

In short

  • The seat is finally judged on the risk that materialises, and most of what decides that judgement is settled before the event: whether the information lines and escalation paths exist, and whether the CRO has thought about the week before it arrives.
  • In the first hours the CRO owns three things: the information the institution acts on, the escalation to the people who must decide, and the record that will be read afterwards.
  • The board and the regulator are briefed during the event, at their altitude, by the seat — not left to learn of it from the numbers or the press.
  • A post-mortem without scapegoats and with consequences is the only kind that improves the next event. One with scapegoats teaches the institution to hide; one without consequences teaches it nothing.
  • Credibility is rebuilt in three places — the models that missed it, the function that ran them, and the officer who signed the reports — and the CRO’s own standing afterwards depends on being seen to lead all three.
On this page
  1. Before: what exists
  2. The first hours: information, escalation, the record
  3. The board and the regulator during the event
  4. The post-mortem: without scapegoats, with consequences
  5. The rebuild: models, function, officer
  6. The CRO’s own standing afterwards
  7. How to use it

The chief risk officer’s seat is finally judged on the risk that materialises. Everything before it — the mandate, the rooms, the veto — is preparation for the week when a limit is breached, a model is wrong, a counterparty fails or an operation stops, and the institution turns to the second line for the information it will act on. Most of what decides that week is settled before it arrives.

The questions below follow the event in sequence: before it, in the first hours, in front of the board and the regulator, in the post-mortem, and in the rebuild. Each is a question a CRO should be able to answer for their own institution — not in the abstract, but with a name, a path or a decision. A question that cannot be answered now is the one that will be asked afterwards.

Before: what exists#

  • Which information lines reach the seat first when a limit is breached, a model output moves or a counterparty weakens — and have they been used, or only drawn?
  • Who can escalate to the CRO without asking permission from their own line, and does everyone in the second line know that they can?
  • What is the escalation path from the seat to the chief executive, the chair of the risk committee and the regulator, and has each of them been told what they will hear from the CRO and when?
  • Which risks has the seat already flagged as under-modelled, and where is that written down?
  • Has the CRO thought through the first hours of the most likely event, or only the last one?

The first hours: information, escalation, the record#

  • What does the seat actually know, what does it believe, and what does it not yet know — and is that distinction stated every time the CRO speaks?
  • Who has been told, in what order, and has anyone who must decide been told later than someone who merely wanted to know?
  • Is there a single record of what the seat knew and when, kept as the hours pass rather than reconstructed afterwards?
  • Which decisions belong to the CRO, which to the chief executive, and which only to the board — and is the CRO carrying only the first?
  • What is the CRO doing to keep the second line working on the rest of the book while the event absorbs attention?
The seat is finally judged on the risk that materialises, and most of what decides that judgement is settled before the event.

The seat is finally judged on the risk that materialises, and most of what decides that judgement is settled before the event. The first hours reveal whether it was.

The board and the regulator during the event#

  • Has the chair of the risk committee heard from the CRO directly, at the committee’s altitude — the exposure, the judgement, what is being done — rather than through management’s account?
  • Has the regulator heard from the seat before hearing from the numbers, the press or a counterparty?
  • Are the board and the regulator receiving the same truth, told to each as they can use it — judgement to one, evidence and record to the other?
  • What has the CRO said it does not yet know, and has that been said to both rooms in the same words?
  • Who is keeping the record of what each room was told and when?

The post-mortem: without scapegoats, with consequences#

  • Is the post-mortem asking what the institution did, or who did it — and does everyone in the room know which?
  • Which of the seat’s own assumptions failed, and has the CRO said so before anyone else did?
  • What did the models not know, and was that known before the event or discovered by it?
  • Which controls, limits or escalation paths existed on paper and did not operate — and what will be different next time, with a name and a date?
  • What consequence follows, and is it a change to the institution rather than a departure that changes nothing?

The rebuild: models, function, officer#

  • Which models missed it, what has been changed in them, and has the change been explained to the committee in its language rather than the modellers’?
  • What does the second line now do differently as a matter of routine, visible to the first line, rather than as a memorandum?
  • Has the CRO stated plainly what the seat got wrong, to the board and to the regulator, before defending what it got right?
  • Which reports signed before the event are now being re-read, and by whom?
  • What has the seat asked for — access, authority, resources — that the event showed it lacked, and has the answer been recorded?

The CRO’s own standing afterwards#

  • Was the seat seen to lead the response, the post-mortem and the rebuild — or only to attend them?
  • Does the chief executive treat the CRO differently now, and in which direction: closer as partner, or further as check?
  • Does the committee now hear more dissent from the seat, or less?
  • Has the regulator’s posture toward the institution moved, and does the CRO know why?
  • Would the CRO be heard earlier next time — and if not, what about the mandate’s architecture has to change?

How to use it#

Work the first section now, against the event the institution is most likely to face, and answer each question with a name, a path or a decision rather than a yes. Most of what is wrong will appear there, while it is still cheap to fix. Keep the remaining sections for the week itself and the period after it; a CRO who has read them before the event holds the seat differently during it. The CRO Mandate works the whole sequence with practitioners who have held the seat through a materialised risk.

Frequently asked

What should a CRO do when a risk materialises?

Own three things in the first hours: the information the institution acts on, stated as what is known, believed and not yet known; the escalation to the people who must decide, in the right order; and the record of what the seat knew and when, kept as the hours pass. Then brief the board and the regulator directly, at their altitude, before they learn of it from the numbers.

What makes a good post-mortem after a risk event?

It asks what the institution did rather than who did it, and it ends in a consequence that changes the institution rather than a departure that changes nothing. The CRO names the seat’s own failed assumptions before anyone else does, the controls that existed on paper and did not operate are listed with what will be different next time, and each change carries a name and a date.

How does a risk function rebuild credibility after a loss?

In three places at once: the models that missed it are changed and the change is explained to the committee in its language; the second line changes what it does as a visible routine rather than a memorandum; and the CRO states plainly what the seat got wrong, to the board and the regulator, before defending what it got right. Credibility returns to the officer last, and only if all three are led from the seat.

How should a CRO prepare for a crisis before it happens?

By making sure the information lines and escalation paths exist and have been used rather than only drawn; by telling the chief executive, the chair of the risk committee and the regulator in advance what they will hear from the seat and when; by writing down which risks the seat already regards as under-modelled; and by thinking through the first hours of the most likely event rather than the last one.

More where this came from

Browse the full resources hub, or subscribe in the footer for occasional substantial pieces.

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.