The Evolving Role of the Contemporary Chief Risk Officer
On March 10, 2023, Silicon Valley Bank (SVB), the 16th largest bank in the U.S., and a key player in the start-up ecosystem, failed after a sudden bank run, marking the largest bank failure since the 2008 financial crisis.
The collapse sent shockwaves through the financial and tech industries and reverberated throughout boardrooms around the world as risk professionals scrambled to determine the systemic and broader impacts.
The collapse of SVB exposed vulnerabilities in risk assessment and management practices. This event underscored the importance of robust risk management strategies and the pivotal role of CROs in identifying, assessing, and mitigating potential threats.
The SVB incident serves as a wake-up call, emphasising that modern risk management requires dynamic, agile, and real-time intelligence. CROs must prioritise resiliency by stress-testing risk models, investing in training and development, ensuring robust crisis management plans, and modernising risk management practices with AI, machine learning, and data science.
In Australia and New Zealand, the role of the contemporary CRO is evolving amidst this complex landscape marked by technological advancements, regulatory scrutiny, and shifting economic conditions. As organisations face increasing pressures from various fronts, the CRO has transformed from a primarily compliance-focused role to a strategic advisor and key member of the executive leadership team. This elevation recognizes the critical importance of risk management in driving organisational performance and resilience.
By securing a seat at the executive table, CROs provide valuable insights that inform strategic decision-making and help align risk management with business objectives. Their involvement is essential not only for navigating the complexities of contemporary risks but also for fostering a culture of risk awareness that permeates the organisation.
Increasingly, regulators and banking officials have also emphasized the critical role of CROs in financial institutions. Michael Barr, the Federal Reserve’s vice chairman for supervision, criticized Silicon Valley Bank for its risk management practices, stating: “SVB’s failure is a textbook case of mismanagement. The bank’s management failed to effectively manage its interest rate and liquidity risk, and the bank operated without a chief risk officer for many months”.
“SVB's failure is a textbook case of mismanagement. The bank's management failed to effectively manage its interest rate and liquidity risk, and the bank operated without a chief risk officer for many months. ”
This highlights the importance regulators place on having a dedicated CRO to oversee risk management. The Australian Prudential Regulation Authority (APRA) has also stressed the significance of risk management and the CRO role. In a speech, APRA noted, “No one gets off lightly: not wall street bankers; not mortgage originators; not home loan borrowers; not ratings agencies; not prudential regulators; not governments; and especially not governance and risk management practices across the financial services industry as a whole”.
This underscores how regulators view risk management as a critical responsibility shared across the financial sector, with CROs playing a key part.
But what of the challenges and opportunities that face contemporary CRO’s today?
Challenges Facing Chief Risk Officers
1. Technological Disruption and AI
The rapid integration of technology and artificial intelligence (AI) into business processes presents both challenges and opportunities for CROs. The proliferation of digital tools enhances risk assessment capabilities, enabling more sophisticated data analysis and predictive modelling. However, this also introduces new risks, particularly in cybersecurity and data privacy. According to the 2023 KPMG Chief Risk Officer survey, “CROs cited artificial intelligence (AI) and machine learning (ML) as the most vital digital tools to accelerate risk management processes in the next five years”.
However, implementing these technologies effectively requires new skills and capabilities within risk management teams. The survey also revealed that cybersecurity remains a top concern for CROs, with 53% ranking it as a priority risk area to modernise in the next two years. As AI and other technologies become more prevalent, the potential for cyber threats and data breaches increases, adding another layer of complexity to the CRO’s responsibilities.
CROs must navigate these complexities while ensuring that their organisations remain compliant with evolving regulations surrounding technology use and data protection.
2. ESG and Sustainability
Environmental, social, and governance (ESG) considerations have become paramount for organisations worldwide, including in Australia and New Zealand. CROs are now tasked with integrating ESG factors into their risk management frameworks.
This shift necessitates a comprehensive understanding of how sustainability impacts business operations and reputations. Failure to adequately address ESG risks can lead to significant reputational damage and financial loss, emphasising the need for CROs to champion sustainable practices within their organizations. New Zealand was the first country to commit to standing up a Task Force on Climate-related Financial Disclosures (TCFD) reporting mandatory. This applies to “Climate Reporting Entities” (CREs), including large, listed companies, banks, insurers, and fund managers with significant assets under management. The Australian Government meanwhile has introduced the legislation to mandate standardised, internationally aligned climate-related financial disclosures for large entities and financial institutions.
3. Regulatory Landscape and the Royal Commission
The aftermath of the Australian Royal Commission into Misconduct in the Banking, Superannuation, and Financial Services Industry has heightened the focus on risk management across sectors. CROs must ensure that their organisations comply with stringent regulatory requirements while fostering a culture of accountability and transparency. The Financial Accountability Regime (FAR) in Australia, which implements recommendations from the Banking Royal Commission, further emphasises accountability for risk management.
The legislation allows regulators to disqualify an individual from being or acting as an accountable person if the regulators are satisfied that certain conditions are met. This accountability extends to senior executives including CROs, highlighting their importance in regulatory compliance.
In New Zealand, the Financial Markets (Conduct of Institutions) Amendment Act 2022 introduces a new regime regulating the conduct of financial institutions, which will come fully into force in March 2025. This new legislation will likely expand the role of CROs in New Zealand financial institutions, adding conduct risk and consumer protection to their areas of focus.
4. Macroeconomic Factors
The current macroeconomic environment, characterised by inflationary pressures, supply chain disruptions, and geopolitical tensions, poses significant challenges for risk management. CROs must develop agile strategies to respond to these uncertainties, balancing risk-taking with the need for resilience.
According to a survey conducted by the Risk Management Association and Oliver Wyman, recession readiness has become the top priority for 52% of CROs. This shift in focus reflects the growing concerns about economic instability and its potential impact on the banking sector. The ability to anticipate and mitigate risks associated with economic fluctuations is crucial for maintaining organisational stability and achieving long-term objectives.
“No one gets off lightly: not wall street bankers; not mortgage originators; not home loan borrowers; not ratings agencies; not prudential regulators; not governments; and especially not governance and risk management practices across the financial services industry as a whole.”
Opportunities for Chief Risk Officers
1. Strategic Leadership
CROs increasingly have the opportunity to play highly strategic and influential leadership roles. By having a seat at the table, CROs can:
1. Provide real-time risk insights during strategic discussions
2. Ensure risk management is proactively integrated into business planning
3. Foster a risk-aware culture throughout the organisation
4. Align risk management efforts with the company’s overall mission and objectives
5. Contribute to more resilient and sustainable business practices
This strategic alignment not only enhances risk awareness but also positions CROs as trusted advisors to senior leadership and boards. As David Koenig, founder of the Directors and Chief Risk Officers Group, aptly puts it, “A CRO with a seat at the executive table is not just a risk manager, but a strategic partner in driving organisational value. Their presence ensures that risk considerations are woven into the fabric of decision-making, rather than being an afterthought.”
2. Enhanced Collaboration
The evolving role of the CRO fosters greater collaboration across departments. By working closely with IT, compliance, and operational teams, CROs can promote a holistic approach to risk management. This collaboration is essential for identifying emerging risks and implementing effective mitigation strategies. Furthermore, fostering a culture of shared responsibility for risk management can enhance organizational resilience.
“A CRO with a seat at the executive table is not just a risk manager, but a strategic partner in driving organisational value. Their presence ensures that risk considerations are woven into the fabric of decision-making, rather than being an afterthought.”
3. Leveraging Data Analytics
The advent of advanced data analytics tools offers CROs unprecedented insights into risk profiles. By harnessing these tools, CROs can improve risk assessment accuracy and enhance decision-making capabilities. One of the primary advantages is the improved ability to analyse vast amounts of data quickly and accurately. AI-powered systems can process and interpret complex datasets, enabling CROs to identify emerging risks and trends that might otherwise go unnoticed. AI can also enhance predictive modelling and scenario analysis, allowing CROs to better anticipate potential risks and their impacts.
This proactive approach enables more effective risk mitigation strategies and improved decision-making. This data-driven approach enables organisations to proactively identify and address potential risks, transforming risk management from a reactive function to a proactive strategic asset.
Mark Rigotti, CEO of the Australian Institute of Company Directors (AICD), emphasises the importance of AI governance for Boards, “As stewards of organisational strategy and risk management, directors should seek to seize the opportunities and mitigate the risks of AI. This requires a robust governance framework that can adapt to the unique characteristics of AI systems”.
The Australian Banking Association (ABA) has also welcomed regulatory initiatives that allow banks to reduce compliance costs and invest more in areas such as innovation and new technology.
4. Building a Risk-Aware Culture
CROs have a pivotal role in cultivating a risk-aware culture within their organisations. By promoting open communication about risks and encouraging employees to engage in risk management practices, CROs can foster an environment where risk is viewed as an integral part of business operations. This cultural shift not only enhances risk management effectiveness but also supports innovation and agility.
Conclusion
The impact of CROs in Australia & New Zealand has grown exponentially over the last two decades shaped by technological advancements, regulatory change, and macroeconomic pressures.
While challenges abound, they also present unique opportunities for CROs to influence organisational strategy and foster a culture of risk awareness.
By embracing these challenges and leveraging their expertise, CROs can position their organisations for sustainable success in an increasingly complex risk landscape. Regulators and banking officials consistently emphasise the vital role of CROs in maintaining financial stability, managing risks, and ensuring compliance with regulatory standards. The absence or ineffectiveness of a CRO is seen as a significant failure in risk management practices.
Looking ahead, the CRO’s contributions will be essential in ensuring that organisations not only navigate challenges but also capitalise on opportunities, reinforcing their role as indispensable strategic partners in shaping the future of their organisations.