Insights · Risk Talent

Chief risk officer job description (SMF4): a UK template

A chief risk officer job description for a UK bank has to do two jobs: describe the role to candidates and match the statement of responsibilities that goes to the PRA with the SMF4 application. This template sets out both, with the Risk Control Part requirements and the prescribed responsibilities to consider for a CRO.

Illustration for the article Chief risk officer job description (SMF4): a UK template

The Word template follows the order of this page, with fields to complete for your firm and a prescribed responsibilities table to mark up. It carries no pay section: pay belongs in the offer.

What must a CRO job description cover in a UK bank?

The regulated function, the reporting line and the duties the PRA gives the risk management function. Take those from the rules, then write the rest for candidates.

The Senior Management Functions Part defines the Chief Risk function, SMF4, as “responsibility for overall management of the risk controls of a firm, including the setting and managing of its risk exposures, and reporting directly to the governing body of the firm in relation to its risk management arrangements” (rule 3.4). Use that sentence as the role’s purpose. The Risk Control Part then says what the function the CRO leads must be able to do.

RequirementRuleWhat the job description should say
Independent from the operational functions, with “sufficient authority, stature, resources and access to the management body”Risk Control 3.4(1)The CRO runs no business line or revenue function, and the grade, resources and board access of the role are stated
Ensures “all material risks are identified, measured and properly reported”Risk Control 3.4(2)The risk types the function covers and the reports the CRO owns
“Actively involved in elaborating the firm’s risk strategy and in all material risk management decisions”Risk Control 3.4(2)The committees the CRO sits on and the decisions the CRO can escalate
Able “to deliver a complete view of the whole range of risks of the firm”Risk Control 3.4(2)A firm-wide remit, including risks other senior managers own
Reports “directly to the management body in its supervisory function, independent from senior management”, and can “raise concerns and warn” itRisk Control 3.4(3)The line to the board and the risk committee, in writing
Head is “an independent senior manager with distinct responsibility for the risk management function” who “must not be removed without prior approval of the management body”Risk Control 3.5That appointment and removal need board approval

The Basel Committee adds detail worth writing in. The CRO “should not have management or financial responsibility related to any operational business lines or revenue-generating functions”, “should report and have direct access to the board or its risk committee without impediment”, and should be able to meet them “without executive directors being present” (Corporate governance principles for banks, paragraph 110).

Which prescribed responsibilities does a CRO usually hold?

SS28/15, the PRA’s guidance on the regime, names only one as typically held by the CRO: responsibility for financial information and regulatory reporting, often shared with the CFO. The rest go to “the Senior Manager it is most closely linked to” (SS28/15 paragraph 2.26), so the list depends on how your risk function is organised.

Prescribed responsibilityRuleWhen to consider it for the CRO
“The production and integrity of the firm’s financial information and its regulatory reporting”Allocation of Responsibilities 4.1(9)Often shared between the Chief Finance (SMF2) and Chief Risk (SMF4) functions (SS28/15 2.41)
“Managing the firm’s internal stress-tests” and the accuracy and timeliness of stress-testing information given to the PRA4.1(11)Where the risk function runs the stress testing programme
“Developing and maintaining the firm’s recovery plan, resolution pack” and, where relevant, resolution assessment4.1(10)Where the risk function owns the recovery plan and its indicators
“Managing the allocation and maintenance of the firm’s capital, funding and liquidity”4.1(7)Where the CRO, rather than finance or treasury, manages that allocation
“The firm’s performance of its obligations under Outsourcing”4.1(21)The PRA “generally expects but does not require” it to sit with the Chief Operations function, SMF24, where one exists (SS2/21 4.8)
“The compliance of the firm’s risk management systems, policies and procedures”4.2(2)Never: it applies only if the firm has no one performing the Chief Risk function
“Implementing and managing the firm’s risk management policies and procedures”5.2(3)In a small CRR firm, with gross total assets of £250 million or less

Where the financial reporting responsibility is shared, SS28/15 paragraph 2.41 expects it to be “recorded identically” in each holder’s statement, with free text listing “the financial and regulatory returns that each SMF is responsible for”. Agree that list with the CFO before the job description goes out, because those returns carry the CRO’s name. A small CRR firm allocates nine prescribed responsibilities in total (SS28/15 paragraph 2.26), so its CRO’s list is shorter.

How should it match the statement of responsibilities?

Word for word wherever they overlap. The statement goes to the PRA with the application (Allocation of Responsibilities rule 2.1), and the job description should describe the same role in the same terms.

The statement has to stand on its own. The FCA’s guidance says it should “be complete by itself” and “not refer to documents not forming part of it” (SUP 10C.11.24G), so it cannot point to the job description; the job description can quote it. SS28/15 says statements should be more than “a tick-box allocation of Prescribed Responsibilities” (paragraph 2.47B), expects free text that clarifies without diluting (paragraphs 2.48 and 2.48A), and treats 300 words of free text as a guide (paragraph 2.49).

  • Use the Rulebook wording for each prescribed responsibility in both documents.
  • Record a shared responsibility identically in each holder’s statement, and list the returns each one covers.
  • Make every responsibility in the statement appear in the job description, described the same way.
  • State the days for a part-time role: SS28/15 paragraph 2.46B measures “proposed time commitment” against the responsibilities allocated.
  • Check both against the management responsibilities map, which must describe “the reporting lines and the lines of responsibility” (Allocation of Responsibilities rule 7.1).

Who should the CRO report to?

To the board, directly. SMF4 includes “reporting directly to the governing body of the firm in relation to its risk management arrangements” (Senior Management Functions rule 3.4), and the risk function must be able to report to the board “independent from senior management” (Risk Control rule 3.4(3)).

The risk committee chair holds the other end of that line. Responsibility for “safeguarding the independence of, and overseeing of the performance of, the risk function”, the CRO included, goes to a non-executive senior manager (Allocation of Responsibilities rules 3.2 and 4.1(17)), and SS28/15 Table F gives the chair of the risk committee the job of “ensuring and overseeing the integrity and independence of the firm’s risk function (including the CRO)”. The Basel Committee adds that “appointment, dismissal and other changes to the CRO position should be approved by the board or its risk committee” (paragraph 111). If the CRO also has a day-to-day line to the chief executive, write both lines into the job description and say which one sets objectives.

What should the person specification test?

The headings of the firm’s own fitness and propriety assessment, then the judgement the role needs. Fitness and Propriety rule 2.6 requires the firm to be satisfied on personal characteristics (including good repute and integrity), competence, knowledge and experience, qualifications and training, so write the specification under those headings and the interview evidence maps straight onto the assessment.

  • Breadth. The function must give “a complete view of the whole range of risks”, so test the risk types the candidate has not led as well as those they have.
  • Challenge. Ask for a time the candidate raised a concern with a board or warned it, since Risk Control rule 3.4(3) expects the risk function to be able to do that.
  • Capital and liquidity. Basel 3.1 takes effect on 1 January 2027 (PS1/26 paragraph 1.23), so test the candidate on the capital and liquidity work it brings.
  • Approvals held. The PRA will take into account “whether the individual has been approved in another jurisdiction or similar accountability regime” and any previous experience as an SMF holder in another regulated firm (SS28/15 paragraph 4.6; PS12/26 paragraphs 2.16 and 2.21), so ask for the candidate’s full approvals history.
  • Time. For a part-time role, the days and availability between them.

Our chief risk officer search page sets out how we run the hire, and the white paper on hiring a chief risk officer covers it from brief to approval. The SMF4 approval timeline planner estimates when a new CRO could act, and what a chief risk officer does describes the role week to week. If the role will be part time or interim, see interim or fractional chief risk officer. Terms are defined in our glossary.

Questions readers ask

Is the statement of responsibilities the same as the job description?

No. The statement sets out “the aspects of the affairs of the firm which it is intended that the person will be responsible for managing” (SUP 10C.11.1G) and should only contain material that the FCA’s and the PRA’s requirements and FSMA say belongs in it (SUP 10C.11.24G). A job description also describes the firm and the role to candidates. Keep the parts that overlap identical.

Does a small bank need a different CRO job description?

A shorter one. A small CRR firm allocates nine prescribed responsibilities in total (SS28/15 paragraph 2.26), and SS28/15 Table B expects the Chief Risk function “where proportionate”. Where scale does not justify a specially appointed head of risk, another senior person may fulfil the function “provided there is no conflict of interest” (Risk Control rule 3.5).

Can the CRO also run compliance or operations?

The Basel Committee says a chief operating officer, CFO, chief auditor or other senior manager “should in principle not also serve as the CRO”, and that where dual hatting is unavoidable in smaller institutions, “these roles should be compatible” (paragraph 110 and footnote 26). For the combined role, see risk and compliance leadership search.

Who approves the CRO’s appointment inside the firm?

The board or its risk committee, on the Basel Committee’s principles (paragraph 111), and removal needs the management body’s prior approval under Risk Control rule 3.5. The PRA then decides whether to approve the person for SMF4.

Sources: PRA Rulebook, Senior Management Functions Part, rule 3.4; Risk Control Part, rules 3.4 and 3.5; Allocation of Responsibilities Part, rules 2.1, 3.2, 4.1, 4.2, 5.2(3) and 7.1; Fitness and Propriety Part, rule 2.6 (all as at 10 October 2026); PRA SS28/15 (April 2026 version), paragraphs 2.26, 2.41, 2.46B, 2.47B, 2.48, 2.48A, 2.49 and 4.6 and Tables B and F; PRA SS2/21 (November 2024 version), paragraph 4.8; PRA PS12/26 (22 April 2026), paragraphs 2.16 and 2.21; PRA PS1/26 (20 January 2026), paragraph 1.23; FCA SUP 10C.11, 10C.11.1G and 10C.11.24G; Basel Committee, Corporate governance principles for banks (8 July 2015), paragraphs 110 and 111 and footnote 26. Accessed 10 October 2026.

How we research and check our articles: our editorial policy.

Next step

Writing the brief for a new CRO?

Tell us about the role and send the draft job description if you have one. In 30 minutes a partner will go through the brief, the statement of responsibilities and the approval timetable.

Brief us on a role

Tell us about the role and a partner will come back to you. Treated in confidence.

For example Head of credit risk

What kind of hire?

PDF or Word, up to 2 MB

Prefer email? talent@risktae.com or +44 20 3996 9599. We use these details only to reply to you: privacy notice.