How is the role of a CRO changing? The future of risk leadership in banking

Risk leaders are navigating an increasingly interconnected environment spanning operational resilience, technology, third parties, transformation and artificial intelligence. Yet the answer cannot simply be for the risk function to assume responsibility whenever a new risk emerges.

We recently hosted a group of Chief Risk Officers (CROs) from across the banking sector to discuss the evolving risk landscape, operational resilience, crisis management and the growing impact of artificial intelligence. Several common themes emerged, highlighting how the role of the CRO continues to expand in both scope and complexity

One question surfaced repeatedly: as the risk landscape expands, how is the role of a CRO changing? The discussion pointed to a deeper evolution in risk leadership.

The CRO as an integrator

Greater specialisation has strengthened technical risk expertise, but it has also increased the potential for risks to be managed in isolation. The CRO’s role is therefore becoming more about connecting risks, challenging across organisational boundaries and maintaining a clear view of their interdependencies.

Clear accountability remains essential. The first line must own and manage risk within defined parameters. However, where risks are new or developing rapidly, the risk function may need to play a more active role initially, building understanding, establishing guardrails and challenging assumptions before ownership can mature within the business.

The test is whether the organisation genuinely understands who owns the decisions that matter, not how many committees oversee them.

Resilience begins when prevention fails

Operational resilience illustrates this shift with particular clarity.

Firms have invested significantly in frameworks, service mapping and scenario testing. But compliance with resilience requirements does not necessarily mean that an organisation will respond effectively when disruption occurs.

Real resilience becomes visible after prevention has failed. It depends on whether services can be restored, reliable information remains available and leaders can make difficult decisions under pressure.

This raises a challenging question about testing. If firms mainly test scenarios they already understand and know they can manage, are they testing resilience or simply demonstrating compliance?

The most valuable exercises may be those that expose uncomfortable unknowns: simultaneous failures, hidden dependencies, unavailable data and difficult choices about which services, customers or markets to prioritise.

AI tests both control and ambition

AI intensifies these challenges. It can amplify operational, technology, conduct and model risks, but its significance extends beyond established risk categories. AI may reshape products, operating models, competitive dynamics and the economics of businesses themselves.

For CROs, this creates a difficult balance. Moving too quickly carries risk, but so does moving too slowly.

Risk functions should not simply constrain adoption. They can help organisations innovate responsibly by bringing expertise in data, controls, governance and challenge. To do so effectively, however, risk frameworks must become more agile, and risk functions must engage early enough to shape decisions.

Human judgement will remain critical. Knowing when not to rely on AI may become as important as understanding how it works.

The next generation of risk leadership

Tomorrow’s CRO will need more than technical expertise. Technology literacy, commercial understanding, sound judgement and the ability to influence across organisational boundaries will all be essential.

The fundamentals have not changed: clear accountability, effective challenge and strong leadership still matter. What has changed is the speed, complexity and uncertainty of the environment in which they must operate.

 

 

 

What to discuss more about how the role of the CRO is changing?

Speak to the team

 

Want to know more?