Insights · Risk Talent

What does a head of non-financial risk do in a UK bank?

A head of non-financial risk leads the second-line oversight of a bank's risks that do not arise from lending, trading or funding: operational risk, operational resilience, third-party and outsourcing risk, technology and cyber risk, and in some banks conduct and model risk. The role challenges the first line and reports on these risks to the CRO and the board.

Illustration for the article What does a head of non-financial risk do in a UK bank?

“Non-financial risk” is the label firms use for a group of disciplines the PRA regulates through separate documents, each with its own owner in the first line. The head of non-financial risk holds them together for the CRO.

What does the role cover?

The risks that come from how the bank runs rather than from what it lends, trades or funds, overseen from the second line. The business owns these risks; the head of non-financial risk sets the framework, challenges how they are measured and managed, and reports the overall picture.

The anchor is operational risk, which UK law defines as “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events, and includes legal risk” (UK CRR Article 4(1)(52)). Around it sit the newer disciplines, each with its own PRA text.

RiskWhat the second line overseesMain PRA text
Operational riskTaxonomy, risk and control assessments, loss data, scenario analysis for Pillar 2AOperational Risk Part; SS31/15 as updated by PS15/26
Operational resilienceImportant business services, impact tolerances, severe but plausible testing, the self-assessmentOperational Resilience Part; SS1/21
Third-party and outsourcing riskThe outsourcing policy, materiality assessments of all third parties and the register of arrangementsOutsourcing Part; SS2/21
Technology and cyber riskICT and cyber controls and incidents, as they bear on resilience and third partiesSS1/21; SS2/21
Model risk (where it sits here)Model identification and risk classification, governance and independent validationSS1/23
Conduct risk (where it sits here)Misconduct risk and the losses it could cause, alongside the FCA’s conduct regimeFCA Handbook; SoP5/15 for Pillar 2A

How does it differ from a head of operational risk?

By breadth. A head of operational risk runs the operational risk framework; a head of non-financial risk usually has that plus resilience, third-party and technology risk, and sometimes conduct and model risk, often through specialist heads who report in.

The wider remit brings a problem the narrower one does not: the same event feeding several regulatory frameworks. A cyber attack on a critical supplier is an operational risk scenario for Pillar 2A, a severe but plausible test for operational resilience and a question for continuity in resolution. In PS15/26 the PRA said these frameworks “serve distinct purposes” and that, while firms “may draw on common underlying risk events”, it does not consider it appropriate “for a single scenario to be relied upon to meet multiple regulatory requirements” (paragraph 3.8). Keeping one event library and separate, purpose-built scenarios is a core part of the job.

Which PRA rules shape it?

Four documents do most of the work: SS1/21 on operational resilience, SS2/21 on outsourcing and third parties, the operational risk scenario expectations confirmed in PS15/26, and SS1/23 on model risk where the bank uses internal models. Basel 3.1 adds a new Pillar 1 calculation from 1 January 2027.

  • Operational resilience (SS1/21, March 2022 version). Firms had to be able to remain within their impact tolerances “within a reasonable time, and no later than Monday 31 March 2025” (paragraph 4.14), test “in severe but plausible disruption scenarios” (paragraph 6.1) and document a self-assessment (paragraph 8.1). Boards “are specifically required to approve the important business services identified for their firm and the impact tolerances that have been set for each of these” (paragraph 7.1).
  • Outsourcing and third parties (SS2/21, November 2024 version). Boards “should approve, regularly review, and implement a written outsourcing policy” (paragraph 4.10), and the PRA expects firms to assess the materiality and risks of all third-party arrangements, “irrespective of whether they fall within the definition of outsourcing” (paragraph 2.5).
  • Operational risk scenarios (PS15/26, 28 May 2026). From 1 January 2027 the updated SS31/15 sets clearer expectations for ICAAP scenario analysis. Scenarios should, where relevant, “cover at least all the Basel event types” in Annex 2 of the Operational Risk Part (paragraph 3.14), and insurance is not recognised as a capital mitigant in Pillar 2A (paragraph 3.9).
  • Model risk (SS1/23, April 2026 version). It applies to banks with internal model approval for regulatory capital, and expects an accountable senior manager who is “the most senior individual with the responsibility for the risks resulting from models” (principle 2.2). Other firms “are welcome to consider” the principles (paragraph 1.2).
  • Pillar 1 operational risk capital. From 1 January 2027 firms calculate it under the standardised approach (Operational Risk Part rule 4.1), built on the Business Indicator.

The seven Basel event types are internal fraud; external fraud; employment practices and workplace safety; clients, products and business practices; damage to physical assets; business disruption and system failures; and execution, delivery and process management. A loss database and a scenario set that cannot be mapped to them falls short of both the PS15/26 expectation and Pillar 2 reporting, which PS15/26 also maps to those event types (paragraph 3.20).

Who does it report to?

To the chief risk officer. The role sits in the risk management function, which the CRO heads and which must be “independent from the operational functions” (Risk Control rule 3.4(1)).

The first-line owner of much of what it oversees is the Chief Operations function, SMF24, defined as “responsibility for the internal operations and technology of a firm” (Senior Management Functions rule 3.8). SS1/21 says the SMF24, where one exists, “should hold overall responsibility for implementing operational resilience policies” (paragraph 7.4), and SS2/21 says the PRA “generally expects but does not require” the prescribed responsibility for outsourcing to sit with SMF24 (paragraph 4.8). The head of non-financial risk challenges that work. Settle that boundary in the brief: who writes the resilience self-assessment and the outsourcing register, and who challenges them.

The role is not a senior management function: the PRA defines no function for operational or non-financial risk on its own, and overall management of the firm’s risk controls sits with the Chief Risk function (Senior Management Functions rule 3.4). It is a certification function where the holder is a significant risk taker, “an employee of a CRR firm whose professional activities have a material impact on the firm’s risk profile” (Certification rules 1.2 and 2.2). The firm then issues the certificate rather than the regulator approving the person (rule 2.1). The FCA has certification functions of its own, including significant management and material risk takers (SYSC 27.8).

What separates strong candidates?

Range across the disciplines and the confidence to challenge the people who run operations and technology. The remit is wide, so the brief should say which risk types matter most to your bank.

  • They can explain how the bank’s scenarios differ across Pillar 2A, operational resilience and continuity in resolution, and why PS15/26 paragraph 3.8 expects them to.
  • They have challenged a resilience self-assessment or an outsourcing materiality call that someone else wrote.
  • They treat non-outsourcing third parties as in scope, because SS2/21 paragraph 2.5 does.
  • They know where conduct sits. For significant firms the PRA’s Pillar 2A assessment of conduct risk focuses on misconduct events “that are currently unknown”, with known events generally captured under Pillar 2B (PS15/26 paragraph 3.6).
  • They can present a cyber or third-party exposure to a risk committee in plain terms, with a view on whether it is within appetite.

We search for the role and for the specialists who report into it: heads of operational and non-financial risk, heads of operational resilience, heads of third-party risk and heads of cyber and ICT risk, with heads of model risk where model risk sits in the same function. For the role above it, see what a chief risk officer does. Terms are defined in our glossary.

Questions readers ask

Does the head of non-financial risk need PRA approval?

No. The role is not one of the PRA’s senior management functions. Where the holder’s work has a material impact on the bank’s risk profile it is a certification function, and the firm issues the certificate itself (Certification rules 1.2, 2.1 and 2.2).

Does the head of non-financial risk own operational resilience?

No. The board approves the important business services and impact tolerances, and the SMF24, where one exists, “should hold overall responsibility for implementing operational resilience policies” (SS1/21 paragraphs 7.1 and 7.4). The second line challenges and reports.

Is model risk part of non-financial risk?

In some banks. SS1/23 does not say where it sits; it asks firms to identify “a relevant SMF(s) most appropriate within the firm’s organisational structure and risk profile” to hold overall responsibility for the model risk framework (principle 2.2).

Is a head of non-financial risk the same as a head of operational risk?

Sometimes the titles describe the same job. Where they differ, the non-financial risk role is the wider one, with operational resilience, third-party and technology risk alongside operational risk.

Sources: UK CRR Article 4(1)(52) (revised version as at 7 October 2026); PRA Rulebook, Operational Risk Part (version from 1 January 2027), rule 4.1 and Annex 2; Senior Management Functions Part, rules 3.4 and 3.8; Risk Control Part, rule 3.4; Certification Part, rules 1.2, 2.1 and 2.2 (all as at 10 October 2026); PRA SS1/21 (March 2022 version), paragraphs 4.14, 6.1, 7.1, 7.4 and 8.1; PRA SS2/21 (November 2024 version), paragraphs 2.5, 4.8, 4.10 and 4.15; PRA PS15/26 (28 May 2026), paragraphs 1.11, 3.6, 3.8, 3.9, 3.14 and 3.20; PRA SS1/23 (April 2026 version), paragraph 1.2 and principle 2.2; FCA SYSC 27.8. Accessed 10 October 2026.

How we research and check our articles: our editorial policy.

Next step

Hiring a head of non-financial risk?

Tell us which risk types the role covers and who it reports to. In 30 minutes a partner will set out the market, the search and a realistic start date.

Brief us on a role

Tell us about the role and a partner will come back to you. Treated in confidence.

For example Head of credit risk

What kind of hire?

PDF or Word, up to 2 MB

Prefer email? talent@risktae.com or +44 20 3996 9599. We use these details only to reply to you: privacy notice.