A chief risk officer runs a bank’s independent risk management function. In the UK the role is a regulated senior management function, SMF4, defined as “responsibility for overall management of the risk controls of a firm, including the setting and managing of its risk exposures”, with a direct reporting line to the board. The CRO proposes the risk appetite, makes sure every material risk is identified, measured and reported, and tells the board when the business is heading outside the limits it agreed.

What does the regulation say a CRO does?
Two parts of the PRA Rulebook define the job. The Senior Management Functions Part, rule 3.4, describes the Chief Risk function as responsibility for the firm’s risk controls and exposures, “reporting directly to the governing body”. The Risk Control Part sets out what the function the CRO leads must do and how independent it must be.
- The risk management function is “independent from the operational functions and has sufficient authority, stature, resources and access to the management body” (rule 3.4(1)).
- It makes sure material risks are identified, measured and reported, and it is involved in decisions on risk strategy (rule 3.4(2)).
- It can report directly to the board, “independent from senior management”, and “can raise concerns and warn the management body” (rule 3.4(3)).
- Its head is “an independent senior manager with distinct responsibility for the risk management function” who “must not be removed without prior approval of the management body” (rule 3.5).
That last protection matters more than it looks. A chief executive cannot dismiss the CRO without the board’s approval, and the risk committee chair is responsible for safeguarding the CRO’s independence (SS28/15 Table F; SS5/16 paragraph 4.3). The rules are designed so the person who says no to the business does not answer only to the business.
What does a CRO actually do week to week?
Less policing than most people assume, and more judgement. The work falls into six parts.
How the CRO role differs between a large group and a small bank
| Aspect | Large group | Small domestic deposit taker |
|---|---|---|
| Risk types | Led by specialist heads, each with a department | The CRO may carry every risk type |
| Team | The CRO leads specialist heads | The CRO works with a small team |
| ICAAP | Draws on the risk function's analysis | The CRO may write much of it personally |
| Committees | The CRO or a delegate may sit on key committees | The CRO may sit on every committee |
- Risk appetite. The FSB’s principles give the CRO the job of developing the firm’s risk appetite “in collaboration with the CEO and CFO”, for the board to approve. The CRO turns it into limits and early warning indicators the business can run to.
- Oversight of the first line. The business owns its risks; the CRO’s function challenges how they are measured and managed. The Basel Committee calls this the second line of defence.
- Capital and liquidity. The ICAAP, the ILAAP, stress testing and the recovery plan draw on the risk function’s analysis, and the prescribed responsibility for financial information and regulatory reporting is often shared between the chief finance and chief risk functions (SS28/15 paragraph 2.41).
- Reporting. The CRO gives the board and the risk committee a view of the firm’s risk profile against appetite, including the parts the executive would rather not discuss.
- Decisions. In many banks the CRO or a delegate sits on credit committee, new product approval and the asset and liability committee, with the right to escalate.
- The team. Heads of credit, market, liquidity, operational and model risk, and increasingly operational resilience and third-party risk, report into the function.
The balance shifts with the size of the bank. In a large group the CRO leads specialist heads, each with a department. In a small domestic deposit taker the CRO may carry every risk type with a small team, write much of the ICAAP personally and sit on every committee. We recruit for both, and they are different jobs.
Does every UK bank need a chief risk officer?
No. The mandatory senior management functions for a bank or building society are the chief executive, the chief finance officer and the chair (Senior Management Functions 2.2(1)). SS28/15 Table B lists the Chief Risk function for banks, building societies and PRA-designated investment firms “where proportionate”, and firms with gross total assets of £250 million or less “are not expected to have many Senior Managers in addition to the mandatory SMFs” (paragraph 2.7).
A bank without an SMF4 still needs someone accountable for its risk management. The prescribed responsibility for the compliance of its risk management systems, policies and procedures then goes to another senior manager (Allocation of Responsibilities 4.2(2)), and SS28/15 Table E allows another senior person to fulfil the function “provided there is no conflict of interest”. In practice, a bank of any complexity appoints one.
What is a CRO accountable for personally?
Everything inherent in the SMF4 role and anything allocated in their statement of responsibilities. Under the duty of responsibility in section 66B(5) of FSMA, the PRA can act against a senior manager where the firm breaches a requirement in an area they manage and they did not take the steps a person in their position could reasonably be expected to take (SS28/15 paragraphs 2.59 and 2.62). The PRA has to prove it (paragraph 2.68), and it says it will not judge with hindsight (paragraph 2.76). Its worked examples point at executives, “including Heads of the Key Business Areas and the Chief Risk Officer”, where capital requirements are breached after repeated limit breaches (Table G).
A new CRO also has a right to a proper handover. The FCA’s handover rule requires a firm to give an incoming senior manager the information they need, and says it “should include judgement and opinion, not just facts and figures” (SYSC 25.9.7G). A CRO who inherits a problem nobody mentioned has a strong reason to ask for the handover in writing.
What makes a strong chief risk officer?
Across more than two decades of risk searches, through Basel II, the financial crisis, Basel III and the Senior Managers Regime, the CROs who succeed share a few traits that no job description captures well.
- They are technical enough to find the weak assumption in a capital plan or a model, and plain-spoken enough to explain it to a board in two sentences.
- They can say no to a chief executive and keep the relationship.
- They know which risk types they are strongest in and hire deliberately for the rest.
- They read the regulator’s direction early. From 1 January 2027 that means Basel 3.1, and for many banks a CRO who can lead the first ICAAP on the new basis.
The routes into the role vary: credit risk, market and liquidity risk, treasury and prudential capital, internal audit and supervision all produce chief risk officers. Since April 2026 the PRA’s approval process also takes account of senior management experience and approvals held in other jurisdictions (PS12/26 paragraphs 2.16 and 2.21), which widens the field for international candidates.
If you are hiring, our chief risk officer search and interim CRO pages set out how we run it, and our white paper on hiring a chief risk officer covers the process from brief to approval. We also search for the heads who report to a CRO: credit risk, market and liquidity risk, operational risk, model risk, prudential risk and enterprise risk. If you are a risk professional thinking about the step up, our page for candidates is the place to start. Terms are defined in our glossary.
Questions readers ask
Who does a chief risk officer report to?
To the board, directly. SMF4 is defined as including “reporting directly to the governing body”, and the risk function must be able to report to the board independently of senior management (Risk Control 3.4(3)). The risk committee chair oversees the CRO’s independence and performance.
Can the chief executive fire the CRO?
Not alone. The head of the risk management function “must not be removed without prior approval of the management body” (Risk Control 3.5).
Does a CRO need regulatory approval?
Yes. SMF4 needs PRA approval before the person starts, apart from short interim cover where the previous holder left unexpectedly. The regulators have three months from a complete application; the PRA’s median was 28 days between December 2025 and February 2026 (PS12/26 paragraph 2.19).
Does a UK branch of an overseas bank need a CRO?
Where someone performs the role, yes. SS28/15 paragraph 2.18 says third country branches need the chief risk function approved, including “a UK Chief Risk Officer (CRO) with responsibility for risk management” across the UK business.
Sources: PRA Rulebook, Senior Management Functions Part, rules 2.2 and 3.4; PRA Rulebook, Risk Control Part, rules 3.4 and 3.5; PRA Rulebook, Allocation of Responsibilities Part, rule 4.2(2); PRA SS28/15 (April 2026 version), paragraphs 2.7, 2.18, 2.41, 2.59, 2.62, 2.68 and 2.76 and Tables B, E, F and G; PRA SS5/16, paragraph 4.3; PRA PS12/26 (22 April 2026), paragraphs 2.16, 2.19 and 2.21; FCA SYSC 25.9; FSB, Principles for an Effective Risk Appetite Framework (18 November 2013), principle 4.3; Basel Committee, Corporate governance principles for banks (July 2015), paragraph 13. Accessed 29 September 2026.
How we research and check our articles: our editorial policy.