Confidential mandate
Chief Risk Officer — Enterprise-Software Suite
Planned Replacement
CRO - Risk mandate in Chennai, India · Technology
Reset enterprise risk ownership as a Chennai software suite moves from licence economics to subscription obligations.
The mandate
A multinational-owned enterprise-software suite is changing from licences to subscriptions while its approach to enterprise risk remains organised around periodic approvals. Revenue recognition, service continuity, customer commitments, cyber exposure, third parties and product change now interact continuously. The board has therefore called for a reset of risk ownership and assurance before the commercial transition creates blind spots between functions.
The Chief Risk Officer will oversee risk across approximately ₹2,000 crore in annual recurring revenue and lead about 375 employees and material partners. The remit covers enterprise risk, compliance, product and operational risk, resilience, investigations, third-party assurance, policy, reporting and risk talent. The CRO reports to the Group Chief Executive and the relevant board committee, retaining direct escalation access when executive consensus is incomplete.
The first task is to rebuild the risk universe around the subscription lifecycle. Quoting, contracting, provisioning, access, usage, billing, renewal and exit each create different failure modes. A control catalogue assembled for perpetual licences will not automatically protect recurring commitments. The CRO must connect risks to customer, cash and service consequences, name a first-line owner and identify which evidence proves that exposure is changing.
Ownership needs precision. Product leaders should own product decisions; commercial leaders should own deal exceptions; technology should own service and security controls. Risk should frame appetite, challenge assumptions, aggregate exposure and test evidence without becoming the silent operator of controls it later assures. Matters that cross functions require one executive owner rather than a committee label.
The board requires early warning rather than a longer heat map. Indicators should capture leading conditions such as exception volume, access drift, renewal concessions, unresolved vulnerabilities, concentration, failed recovery tests and manual billing intervention. Thresholds need a defined consequence. Reports must distinguish inherent exposure, current control performance, accepted residual risk and the action necessary to remain inside appetite.
Subscription growth also changes third-party dependency. Cloud providers, payment systems, data processors, implementation partners and embedded software can affect every customer simultaneously. The CRO will establish concentration views, contractual rights, exit options, monitoring and tested contingencies. Supplier attestations alone are insufficient when a critical service has not been recovered under realistic conditions.
Assurance should follow decision importance. The role will align first-line testing, second-line thematic review, internal audit and external evidence so coverage is complementary. Repeated requests for similar documentation waste expert capacity without increasing confidence. Conversely, closure cannot be declared because an action is recorded as complete; a sustained operating test must show the intended risk reduction.
Culture is part of the control environment. The CRO will assess whether incentives reward unsupported bookings, hidden exceptions or delayed escalation. Speak-up channels, investigation quality and consequence management should be trusted across levels. Independent challenge must be candid enough to change a decision while remaining practical enough to preserve executive followership.
Why this seat is open
This planned succession provides four to six months for assessment, diligence and an orderly transfer from the incumbent. Confidentiality protects customer, employee and regulatory confidence while the subscription transition continues. The handover should transfer open issues and judgement, not create informal shadow authority.
What you will own
- Redefine enterprise risk around the full subscription customer lifecycle.
- Provide independent challenge across ₹2,000 crore of annual recurring revenue.
- Allocate clear first-line ownership for commercial, product and service exposure.
- Replace retrospective risk reporting with decision-linked early warning.
- Lead approximately 375 employees and partners across risk and compliance disciplines.
- Rationalise assurance while strengthening evidence for material issue closure.
- Govern critical third-party concentration, resilience and exit preparedness.
- Maintain direct, trusted access to the relevant board committee.
The first 12 months
The first 90 days should establish a common risk baseline, meet the 30 stakeholders central to the reset and test the most consequential subscription journeys. Review appetite, open exceptions, board reporting, resilience exercises and leadership capability. Agree immediate containment for any exposure lacking a credible owner or evidence trail.
Between months four and nine, implement the revised taxonomy, indicators and accountability model. Conduct selected thematic reviews across contracting, access, billing, renewal and critical suppliers. Close material gaps through tested changes, strengthen escalation and appoint leaders where independence or technical depth is insufficient.
By the end of year one, early-warning quality, control effectiveness and regulator-ready evidence should be observable. Delivery should remain within 10% of the approved case, and three consecutive forecasts must align operating exposure, cash, customers and people. A severe risk may not remain without a board-approved resolution path beyond 30 days.
What the board will measure
- Subscription risks assigned to accountable executives with explicit appetite decisions.
- Leading indicators that predict customer, cash or service consequence.
- Material control remediation proven through sustained independent testing.
- Critical suppliers covered by concentration analysis and exercised contingencies.
- Retention above 90% for pivotal risk talent and ready cover for 70% of direct roles.
- Absence of material surprises withheld from the forum authorised to decide them.
The person
You are a CRO, Deputy CRO or Chief Compliance and Risk Officer with 22–28 years in technology or an adjacent regulated setting. Your experience includes resetting risk ownership during a business-model change and presenting independent conclusions to a board or supervisory forum.
You have carried an accountable portfolio of at least ₹1,150 crore and led no fewer than 275 people. Your examples should explain a difficult challenge decision, the evidence used, the executive response and results sustained across at least two reporting periods.
Credibility may come from software, cloud services, digital platforms, IT services or technology-enabled business services. Pure policy stewardship is insufficient. The board needs an operator who understands subscriptions, resilience and control design, yet can preserve the independence necessary to oppose an optimistic case.
Compensation and terms
The package is ₹2.2–3.0 crore fixed plus performance variable. This permanent Chennai role is onsite; relocation is expected, with a structured weekly commute potentially available in the first quarter. A notice period as long as six months is acceptable.
Confidentiality
The client and incumbent are unnamed to protect the board, customers and candidate population. Rounded operating facts are intentionally composite, and further information will be released only within a mutually confidential process.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.