Confidential mandate
Chief Risk Officer — Patient-Access Organisation
Urgent / New
CRO - Risk mandate in Zurich, Switzerland · Healthcare Services
Reset independent risk appetite for a Swiss patient-access organisation as payer diversification changes authorisation, continuity, conduct and data exposure.
The mandate
A patient-access organisation is diversifying from a concentrated institutional payer base into insurer, employer and direct-patient channels. Different authorisation, communication and data obligations now converge on the same intake teams. The board has created an urgent new Chief Risk Officer seat to define appetite and independent challenge before commercial pace hardens unmanaged practices.
Approximately 1,050 employees and material partners work across referrals, contact centres, scheduling, payer navigation, digital access, provider coordination and shared functions in Switzerland and the wider region. The CRO owns enterprise risk, compliance coordination, independent assurance, policy, incident oversight and board-committee reporting. The role reports to the Group Chief Executive and relevant board committee, with unrestricted escalation.
Risk appetite must become specific enough to guide a live access decision. Broad statements about low tolerance for patient harm or compliance breach are insufficient. The CRO will define thresholds for unreviewed urgent referral, identity ambiguity, authorisation delay, provider capacity, complaints, data use and third-party dependency, explaining which exposure requires immediate pause or board acceptance.
The payer reset introduces conduct risk. Staff may prioritise channels by revenue, simplify complex authorisation or communicate coverage as if it were clinical acceptance. The CRO will establish monitoring that tests patient cases and conversations. Commercial targets must include counter-metrics for appropriateness, fairness and unresolved obligations.
Direct-patient services change financial communication. Fees, cancellation, reimbursement uncertainty and alternatives should be clear before commitment. Vulnerable patients must not be pressured by urgency language. The risk function will sample journeys, review complaints and ensure debt or refund processes remain proportionate and distinguish financial from clinical decisions.
Identity and consent practices vary by channel. Employer programmes, insurer referrals and self-registration collect different information, but access rights and permitted use cannot be inferred from source. The CRO will require purpose, consent, minimum data and retention to be explicit, particularly where employers or payers seek programme reporting.
Authorisation risk is both economic and clinical. An unpaid service may create financial exposure, while waiting for approval may worsen a patient's position. The CRO will ensure clinical escalation operates independently of payer decision and that unresolved cases have ownership. Exceptions should be visible by age and consequence, not buried in accounts-receivable status.
Third parties include providers, platforms, payment services, translation and payer portals. Due diligence will consider patient journey, data, continuity and conduct. A critical provider's limited capacity or a portal outage can undermine access even where contractual compliance appears sound. Concentrations and practical alternatives need board visibility.
The incident framework will separate cause from consequence and protect prompt reporting. Near misses and patient complaints may reveal control weakness before financial loss. The CRO will require preservation, root-cause analysis and verified action, while clinical incidents remain under appropriate professional governance. Materiality judgements should consider recurrence and vulnerable populations.
Independent assurance will use samples and observation. First-line attestations are useful but cannot establish effectiveness alone. The CRO will build a risk team capable of tracing referrals, listening to consented contacts and examining exception queues. Findings will identify the control owner and decision required, not simply recommend more training.
Board reporting will show exposure by payer and pathway, appetite breach, control confidence, unresolved issue and emerging dependency. Aggregated heat maps that hide the scale or age of exceptions will be retired. The committee should see where management accepts residual risk and where the CRO disagrees.
The new function must avoid taking ownership away from operations. The CRO defines framework, challenges, tests and escalates; business leaders own controls. Where management lacks capability, risk may support design temporarily with a dated handback. Permanent reliance on second-line execution will be reported as a weakness.
The CRO will build relationships with regulators, clinical governance, privacy, finance and internal audit. Overlap must be resolved through coordinated assurance plans and clear information sharing. The board should not receive contradictory ratings because functions used different definitions without discussing them.
What you will own
- Enterprise risk appetite and independent challenge.
- Payer, conduct, identity, consent and access-risk oversight.
- Incident, complaint and issue-effectiveness assurance.
- Third-party concentration and continuity challenge.
- Risk monitoring, sampling and board reporting.
- Coordinated assurance with clinical and control functions.
- Regulatory relationships and unrestricted escalation.
- Risk-team capability and succession.
The first 12 months
In the first 45 days, map material exposure by payer journey, test priority exceptions and propose operational appetite thresholds. Escalate any channel where financial or commercial pressure compromises safe access.
By month six, implement case-based conduct monitoring, establish coordinated assurance and complete critical third-party concentration reviews. Ensure first-line leaders own remediation.
At twelve months, achieve 95% verified closure of high-risk actions by agreed dates, reduce aged authorisation cases with clinical consequence by 60% and complete independent sampling across every material payer channel. All appetite breaches should reach the committee within defined timelines, with no material patient-data use lacking documented purpose and authority.
What the committee will inspect
- Appetite thresholds changing actual access decisions.
- Commercial incentives monitored for patient conduct.
- Financial authorisation separated from clinical judgement.
- Payer data used within explicit permission.
- Assurance testing cases rather than relying on attestations.
- Risk maintaining independence from operating ownership.
The person
You bring 22–28 years in risk, compliance, insurance, healthcare or another regulated access service, including CRO or material second-line authority. Your record includes payer or channel change, conduct monitoring, patient or customer data and direct board-committee challenge.
Swiss and wider European regulatory experience is valued, along with the judgement to disagree openly with commercial leadership. You must show how appetite was translated into a stopped, limited or redesigned activity. The permanent role is onsite in Zurich with unrestricted committee access.
Compensation and terms
Base compensation is CHF 340,000–470,000 plus annual incentive and long-term participation linked to appetite discipline, conduct, assurance quality, issue closure, data governance and risk leadership. The permanent urgent appointment is onsite in Zurich, reporting to the Group Chief Executive and relevant board committee.
Confidentiality
The organisation, patients, payers, providers, incidents, controls, data and regulatory discussions remain confidential. Further material follows conflicts and signed confidentiality. Applicants must not contact possible organisations, regulators or board members to identify the client.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.