Enterprise risk leadership search is RiskTAE’s retained executive search service for heads of enterprise risk and risk framework leaders in banks, building societies, investment firms, asset managers, insurers and payment firms, in the UK and for international clients. A partner runs the search from the written brief to the first day, and every candidate is interviewed on the technical substance of the role before you see a CV.
You meet people who can put numbers on the board’s risk appetite, report to the risk committee with authority and hold the first line to account.
SMF4The Chief Risk function the role usually reports to
The role
What does a head of enterprise risk do, and who do they report to?
The head of enterprise risk owns the framework through which a firm takes, measures and reports risk: the risk appetite statement and its limits, the taxonomy and policies, the reports to the executive and the board’s risk committee, and the stress testing behind the ICAAP. The PRA expects an effective board to articulate and oversee a clear and measurable statement of risk appetite, and says the risk control framework should flow from it; the head of enterprise risk makes that true.
In most banks the role reports to the chief risk officer, who holds the PRA’s Chief Risk function, SMF4. The Risk Control Part requires the risk function to be involved in decisions on risk strategy and able to warn the board, which a head of enterprise risk kept out of the room when strategy is set cannot do. We settle in the brief whether the role sits on the executive risk committee and presents to the board’s committee in person.
Whoever you appoint will need to re-base limits set against capital or risk-weighted assets when the PRA’s Basel 3.1 rules take effect on 1 January 2027; we ask each candidate which of their limits would move.
What does a strong head of enterprise risk look like, and where do they come from?
Strong candidates come from four places: heads of enterprise risk or risk frameworks at other regulated firms; deputies in larger risk functions who have run the risk appetite refresh; credit or operational risk specialists who want breadth and have written the risk chapters of an ICAAP; and, less often, consultants and former supervisors who know what good looks like but have not run it inside a firm.
We test three things hardest. Whether the person can hold the first line to account: someone who has never told a business head that a limit will be reported as breached is not yet the hire. Whether they can write, because the appetite statement and the committee papers are documents the supervisor reads. And scale: in a smaller firm the same person writes the policies, builds the reports and answers the committee’s questions with one or two analysts.
The interviewers have held these roles: former chief risk officers and heads of risk, former regulators and interim executives. In the technical screen we ask for the last risk report a candidate wrote for a board committee, then what the committee should have asked and did not.
Process
How does a head of enterprise risk search run?
Stages of the search
Stage
What happens
What is different for this role
Brief
A 30-minute call, then a written brief: the role, first-year success, terms and timetable.
We settle whether the role is a senior management function or a certification function, and who holds the pen on the ICAAP.
Market map
The people who fit, most not looking, approached in confidence without naming you.
Titles vary, so the map is built on what people have run, not what they are called.
Technical screen
Each candidate is interviewed on the substance before you see a CV.
On the framework, the appetite statement and the board papers.
Shortlist
A short list with our written view of each person, then interviews and feedback both ways.
The chief risk officer and the chair of the risk committee meet the final two and hear them present.
Offer, checks and start
We handle the offer, plan the checks and stay close through notice and the first months.
Regulatory references cover six years and every relevant former employer, apply to certification functions as well as senior managers, and carry a four-week reply window that binds all firms.
Does a head of enterprise risk need the regulator’s approval?
PS12/26 changes to senior manager approvals take effect
Usually not. Neither regulator’s list of senior management functions for a bank names enterprise risk, so in most firms the role is a certification function: the firm certifies each year that the person is fit and proper, rather than the regulator approving them. Regulatory references still apply, and the PRA expects a criminal record check, with the candidate’s consent.
Approval is needed where the head of enterprise risk performs the Chief Risk function, SMF4, or holds overall responsibility for an area under the FCA’s rules with no other approval (SMF18, other overall responsibility). The regulator then has a statutory three months from a properly completed application, and the clock stops whenever it asks for more information; the work before the application takes longer than the application.
Where an approved person has already left, our interim chief risk officer page explains how the role is covered while the permanent search runs.
What usually goes wrong when you hire a head of enterprise risk?
The brief asks for a framework builder when the firm has a framework nobody uses. What it needs is someone who can make the first line own its risks, a different person with a different CV. Start from what the last supervisory letter said.
The appetite statement is a page of adjectives. The PRA expects a clear and measurable one, and a good hire puts limits on it. Agree before the search whether the board is ready to see a limit reported as breached; candidates who have done this ask.
The role is defined as reporting. Producing the board pack is the smaller part of the job; the rest is arguing with the first line about limits, and a head of enterprise risk kept off the executive risk committee loses those arguments before they start.
Finance holds the ICAAP and risk holds the taxonomy, and the two do not match. The ICAAP’s risk identification is the taxonomy in another document; when they differ, the supervisor asks which one the board approved. Decide who holds the pen first.
The chief risk officer owns this hire; where the CRO role is open too we run the two searches together (see chief risk officer search). The chair of the risk committee, whom the PRA holds responsible for safeguarding the independence of the risk function, usually meets the final candidate.
HR, in-house talent acquisition and RPO teams own the process and the offer; we bring the senior risk market map and the technical screen, for one hard-to-fill role or a whole programme (see talent acquisition teams).
The same firm does advisory and consulting, training and the RisKIT models, so a search can be paired with interim advisory cover on the framework or the ICAAP through Risk Advisory, or with board risk training for the committee the new head reports to. A founding partner has recruited risk leaders since 2003; the rest of our searches are listed under Risk Talent.
Sources: PRA SS5/16, July 2018, paragraph 4.3; PRA SS28/15, April 2026, Table F.
FAQ
Questions about enterprise risk leadership search
Is enterprise risk management recruitment different from hiring a chief risk officer?
Yes. The chief risk officer holds the Chief Risk function, SMF4, with responsibility for the overall management of the firm’s risk controls and a direct line to the board; the head of enterprise risk runs the framework the CRO answers for. We search for both, and a CRO search runs to a different timetable because approval is always needed.
Do we need a head of enterprise risk or a chief risk officer?
The 30-minute call usually settles it. The test is who will answer to the board and the supervisor for risk; if that is the person you are hiring, the role is the Chief Risk function. Where nobody holds that function, the PRA’s Allocation of Responsibilities Part still requires responsibility for the firm’s risk management policies and procedures to be allocated to an approved senior manager.
I am a head of enterprise risk thinking about a move. What should I do?
A chief risk officer runs a bank’s independent risk management function. In the UK the role is a regulated senior management function, SMF4, defined as “responsibility for overall management of the risk controls of a firm,...
In a UK bank the chair of the risk committee holds a senior management function of their own, SMF10, and needs regulatory approval before taking up the role. The PRA requires a risk committee, and so...
From 1 January 2027 an ICAAP has to be written on a Basel 3.1 basis. The PRA set this out in PS15/26: ICAAPs signed off by boards in 2026 should include an impact assessment of Basel...
By Mark Dougherty · 8 min read
Next step
Tell us about the role
A 30-minute call is enough to agree the brief and whether we are the right firm to run the search.