Confidential mandate
CRO – Enterprise Risk — Foundation-Model Platform
Planned Hiring / New
CRO – Enterprise Risk mandate in Singapore, Singapore · Artificial Intelligence
Establish independent risk governance in Singapore for a foundation-model platform whose compute commitments and training experiments are outpacing economic controls.
The mandate
A foundation-model platform has increased training scale, inference demand and reserved compute faster than its risk framework has matured. Technical teams manage model hazards and finance tracks spend, but no independent executive connects experiment authority, capacity exposure, customer commitments and downside. The board has planned a new CRO seat to create risk discipline without converting research into a slow approval queue.
Approximately 500 employees and material partners span research, infrastructure, product, security, data, finance, commercial and operations from Singapore. Reporting to the Group Chief Executive and relevant board committee, the CRO owns enterprise risk, independent assurance, resilience, issue governance and board reporting. Model, security and financial authorities retain their specialist decisions.
Risk appetite must translate into live thresholds. Training runs, reserved capacity, inference subsidies, model access and customer service commitments each create different exposure. The CRO will define when teams may proceed, when additional evidence is required and which decision belongs to the executive or board.
Compute risk begins before consumption. Long-term reservations, take-or-pay terms, accelerator concentration, power availability and interconnect constraints can create substantial downside. Independent review will test demand, portability and exit assumptions, ensuring that optional experiments are not funded through inflexible capacity commitments.
Experiment governance should distinguish exploration from scale. Small tests can operate within delegated budgets and safety limits; larger runs need hypotheses, stop criteria, cost-at-completion and ownership of resulting assets. The risk function will challenge runs whose scientific question is vague or whose continuation depends on sunk cost.
Model-cost escalation also appears at inference. Context length, tool calls, retries, safety filters and customer usage patterns affect unit economics. Risk will examine whether price, quotas, architecture and controls keep exposure inside appetite. A growing customer cannot be treated as successful if every additional request deepens an uncapped loss.
Model hazards remain integral. Evaluation coverage, red-team findings, capability thresholds and deployment restrictions must reach governance alongside cost and schedule. The CRO will test whether commercial or compute pressure narrows evaluation, accelerates disposition or obscures uncertainty. Independent authorities must be able to stop release.
Third-party dependency extends beyond cloud vendors. Data licences, model components, observability platforms and specialised contractors may carry rights, security and continuity concerns. Critical dependencies require ownership, alternatives and tested recovery. Contractual service credits do not replace a viable technical fallback.
Financial exposure will be scenario-based. Demand, utilisation, model efficiency, supplier pricing and product mix should form coherent cases. The CRO will challenge false precision and show directors which assumptions move cash and solvency most. Leading indicators must trigger action before quarterly reforecasting confirms the problem.
Customer commitments require risk acceptance. Availability, latency, residency, model stability and indemnity can be difficult to sustain through rapid technical change. Commercial exceptions should include quantified exposure, technical feasibility and expiry. No salesperson or researcher can privately commit the platform to an unbounded obligation.
Incident governance will unite model, cyber, service and economic consequence. Teams need clear command, evidence preservation and customer communication. An event can be technically contained yet continue through reputational, contractual or regulatory impact. Closure requires effectiveness and lessons translated into controls.
Board reporting must distinguish measured fact, management estimate and unresolved uncertainty. Sensitive research details may be compartmented, but consequence and decision cannot be withheld. The CRO will state where independent risk judgement differs from first-line optimism.
The new function should remain small and technically credible. Risk partners will sit close to research and infrastructure while preserving escalation. Internal audit and specialist assurance will test controls rather than duplicate them. Leadership incentives will include disciplined cessation of low-value or excessive-risk work.
What you will own
- Enterprise and model-cost risk appetite.
- Compute commitment and experiment assurance.
- Inference economics and customer exposure.
- Independent model-release challenge.
- Critical suppliers, rights and resilience.
- Scenario analysis and leading indicators.
- Incident, issue and board governance.
- Risk organisation, culture and succession.
The first 12 months
Within 45 days, map compute commitments, high-cost runs and uncapped customer exposures; establish interim escalation thresholds; and bring any appetite breach directly to the committee. Recruit technically credible risk leads.
By month six, implement experiment tiers, capacity scenarios, customer-exception governance and integrated model-risk reporting. Exercise loss of a critical infrastructure dependency and test incident decision rights.
At twelve months, reduce unplanned model-cost variance by 50%, place 95% of material compute commitments through independent review and cap identified inference-loss exposures. All high-capability releases must carry complete disposition evidence, with no overdue appetite breach and at least S$180 million of downside actions ready for board activation.
What the committee will inspect
- Appetite thresholds changing live decisions.
- Research freedom preserved within explicit bounds.
- Capacity commitments tested for portability and exit.
- Model safety not traded against sunk compute cost.
- Customer obligations measured before acceptance.
- Independent disagreement visible to directors.
The person
You bring 18–22 years in enterprise, model, technology or financial risk across AI, cloud infrastructure, capital-intensive technology or regulated platforms. Your record includes CRO-scale authority, complex supplier commitments, scenario analysis, board challenge and technically sensitive incidents.
Candidates must explain a major capacity or technology commitment they changed after downside review, and a model or product decision they escalated against commercial pressure. This permanent role is onsite in Singapore with frequent infrastructure and regional stakeholder engagement.
Compensation and terms
Base compensation is S$500,000–680,000 plus annual incentive and LTI linked to exposure control, independent model assurance, resilience, board confidence and risk-team capability. The permanent onsite Singapore CRO reports to the Group Chief Executive and relevant board committee. This is a planned new role.
Confidentiality
The platform, models, training plans, compute suppliers, customers, contracts, exposures and board materials remain confidential. Detailed disclosure follows conflicts, suitability and signed confidentiality. Candidates must not approach cloud providers, AI laboratories, customers or investors to determine the organisation involved.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.