Confidential mandate
Chief Risk Officer — Finance-Services Hub
Urgent / Replacement
CRO - Risk mandate in Chennai, India · Global Capability Centres
Establish independent product-risk governance as a Chennai finance hub replaces project delivery with persistent ownership of global finance services.
The mandate
A Chennai finance-services hub is converting recurring processes and enabling technology from temporary projects into owned products. The change promises clearer roadmaps and accountability, but it also blurs established control boundaries. Product owners can prioritise features yet do not hold legal-entity duties; local CFOs remain accountable but no longer direct every change. Risk assessments still occur at project approval and are poorly suited to continuous releases and persistent service ownership.
The Chief Risk Officer will hold independent second-line authority across approximately 1,200 employees and partners and a services perimeter near ₹3,300 crore. The remit includes operational, technology, third-party, conduct and change risk as they arise in the hub. Legal-entity risk and finance officers preserve their statutory responsibilities. The CRO must create an aggregate product-risk view, challenge first-line decisions and ensure material acceptance reaches the executive or board forum with authority to take it.
The role will succeed only if governance fits product cadence. Copying stage gates into monthly releases will generate paperwork without insight; removing gates without compensating controls will create blind spots. The appointee must define continuous evidence, release thresholds, control ownership and cumulative-change review while preserving independent escalation.
Data products add another layer of exposure. A finance service may consume models or reference data managed outside the hub, while its product owner remains accountable for downstream operation. The CRO must define assurance for lineage, model change, data quality and supplier dependence without pretending that the hub can directly control every upstream component.
Why this seat is open
The previous CRO left on short notice for personal reasons as the product model entered implementation. Interim risk coverage is split between technology and operations specialists, leaving no single independent view. This is an urgent replacement targeted within six to eight weeks. No unresolved conduct allegation is associated with the transition, and the board wants the search treated neutrally.
What you will own
- Define risk governance for finance products across design, release, operation, incident and retirement.
- Clarify first-line product ownership, control ownership, legal-entity accountability and second-line challenge in written service agreements.
- Set release and cumulative-change thresholds requiring independent review or formal risk acceptance.
- Create continuous evidence for access, reconciliation, data, vendor, resilience and model obligations without duplicating operational records.
- Build an aggregate view of dependencies and incidents across products that serve several legal entities.
- Challenge roadmaps and technical debt where product economics understate control or recovery obligations.
- Establish second-line capability in technology, operations and product risk with protected access to primary evidence.
- Report material exposures and overdue acceptance directly to the relevant board committee.
The first 12 months
Within 30 days, the CRO will identify releases and products proceeding under unclear authority. By day 90, the highest-risk products should have agreed owners, risk appetite, release thresholds and interim evidence. The board committee will receive a gap assessment that distinguishes immediate exposure from design immaturity.
During months four to nine, continuous controls will be piloted on two finance products with different legal-entity and technology profiles. The CRO will test cumulative-change review, run product-level resilience exercises and close or formally accept inherited high-risk exceptions. Second-line roles will be staffed independently of delivery teams.
At year-end, all critical products should have approved risk profiles, named control owners and current recovery evidence. Overdue high-risk exceptions should reduce by 70%, release-related severe incidents by 25% and unresolved ownership conflicts to zero. Independent review must operate within product cadence without delaying low-risk changes beyond agreed service levels.
What the board will measure
- Clear accountability accepted by product, control and legal-entity leaders.
- Risk information that changes roadmaps, releases or investment rather than documenting completed decisions.
- Reduction and timely acceptance of inherited high-risk exposure.
- Independent access, escalation and talent depth within the second line.
- No material control failure caused by ambiguity during the product transition.
The person
You are a CRO, operational-risk executive or senior technology-risk leader who has adapted governance to continuous product or platform delivery. You understand financial control and legal-entity accountability, but you do not require every decision to follow a traditional project gate. Relevant backgrounds include regulated finance, payments, global business services and technology-intensive operations.
You bring 22–28 years of experience and should have held independent risk authority over at least ₹1,900 crore and an operation of 850 people or more. You can discuss where you permitted faster low-risk change and where cumulative exposure required board acceptance. References must confirm independence under delivery pressure.
This onsite Chennai role carries direct access to the relevant board committee.
Compensation and terms
Fixed compensation is anticipated at ₹2.2–3.0 crore plus performance variable. Objectives will recognise exposure reduction, decision quality, product-cadence integration and independent team depth; speed without control integrity is not rewarded. Final terms depend on scope and current mix. Appointment remains subject to thorough diligence despite the urgent timetable.
Confidentiality
The finance products, legal entities, control exposures and parent identity are confidential. Qualified candidates will receive details only after reciprocal interest and a signed undertaking. The composite product transition and rounded scale must not be used to infer a named organisation.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.