Take a look inside the world’s largest discreet leadership platform for media and telecommunications107 open mandates22 countriesEverything media & telecom leaders need

Confidential mandate

Chief Risk Officer — Digital-Services Division

Urgent / New

CRO - Risk mandate in Sydney, Australia · Telecommunications

Establish independent customer-risk oversight in an Australian digital-services division serving enterprise and public-sector clients.

The mandate

This digital-services division provides managed cloud, cyber security, workplace and connectivity services to enterprise and public-sector customers. Risk indicators exist across service, account, finance and technology teams, but no executive owns the combined exposure.

The group is creating a Chief Risk Officer appointment to bring independent judgement to that customer lifecycle. The CRO will oversee enterprise risk, operational and technology risk, customer conduct, third-party exposure, continuity, contract-risk governance and major incident assurance for the division. Commercial and operational executives retain ownership of customers and services. The CRO must make cumulative risk visible, ensure material acceptance occurs at the right level and prevent a retention target from producing commitments the organisation cannot responsibly honour.

This is not a conventional policy role. The board wants a risk leader who can examine why a customer is leaving, distinguish a recoverable service relationship from an uneconomic or unsafe one and influence action before the renewal deadline. The CRO will sometimes support investment in remediation and sometimes recommend an orderly exit.

Scope and operating context

Based onsite in Sydney, the role influences approximately 1,850 employees and material partners across Australia and a wider international region. The perimeter includes risk, resilience, customer conduct, supplier assurance, incident governance and contract-risk review, with close interfaces into account management, service operations, cyber, technology, product, legal, finance, procurement and internal audit.

Customers have different critical services and risk tolerances. A managed workplace incident may be inconvenient for one client and disrupt regulated operations for another. Contracts describe service levels but do not always reveal the business dependency, accumulated workaround or political consequence of repeated failure. The CRO must create a materiality view that respects customer confidentiality and avoids treating every account as equally critical.

Retention practices need particular scrutiny. Credits, free upgrades, extended terms and bespoke support can preserve a relationship while creating hidden liability or control weakness. Frontline leaders may believe they are acting in the customer's interest, yet lack authority or full cost information. Risk oversight must improve decisions without requiring central approval for every commercial remedy.

First-year agenda

During the first ninety days, the CRO will review a representative set of lost, at-risk and recently renewed accounts. The work will reconstruct incidents, complaints, credits, exceptions, security findings, executive escalations, margin and promises from the customer's perspective. It should identify patterns that individual product or service reviews miss, including accounts whose apparent stability depends on extensive manual intervention.

The executive will then define customer-risk triggers and ownership. Indicators may include repeated severity incidents, unresolved root causes, unsupported configurations, overdue security actions, disputed credits, excessive exceptions, key-person dependence or service cost outside contract assumptions. Thresholds will determine when a cross-functional account review is required and who may accept the remaining exposure.

For priority accounts, risk and commercial leaders will create a concise relationship-risk statement. It will name the customer outcome at stake, evidence confidence, controllable causes, contractual position, remediation options, cost, delivery capacity and consequence of exit. The document must support a decision, not become another account plan. Sensitive customer information will be minimised and access restricted.

The CRO will redesign risk input to renewal and retention. Material proposals will be tested for deliverability, security, supplier dependency, liability and lifetime economics before the offer reaches the customer. Remediation promised in exchange for renewal will have funding, milestones and an accountable service owner. Exceptions will expire or return for a new decision; sales urgency cannot convert a temporary workaround into an indefinite operating model.

Service recovery governance will be strengthened around recurring failure. The CRO will ensure incidents are viewed across customers, platforms and suppliers so common causes receive enterprise action. Post-incident reviews must test whether restoration actually returned the customer to a stable state and whether communications were accurate. Repeated acceptance of the same control weakness will be escalated to the board committee.

Third-party exposure will be connected to customer consequence. Critical providers will be assessed for concentration, support, security, recovery, subcontracting and exit. Where several at-risk accounts depend on one vendor or specialist team, the aggregate exposure will influence remediation and contract negotiations. Supplier assurance will prioritise evidence needed for decisions rather than questionnaires of equal depth for every provider.

The risk function itself will become more operationally fluent. Team members will spend time in service reviews, customer escalation calls and technology operations. Training will cover contract economics, managed-service architecture and proportionate challenge. The CRO will recruit selectively where cyber, resilience or commercial-risk depth is missing and will clarify boundaries with legal, compliance and internal audit.

By year-end, the division should have earlier visibility of deteriorating relationships, fewer unowned remediation promises and better evidence for invest, retain or exit choices. Churn may not fall in every segment; success includes leaving relationships whose risks and economics cannot be repaired responsibly.

Leadership responsibilities

The CRO will report to the Group Chief Executive and relevant board committee, preserving independent access when commercial pressure is high. They will present customer risk by exposure, trajectory, evidence and decision rather than using a generic heat map. The executive must be willing to disagree with a major renewal while offering a practical route to make it acceptable.

They will chair material account-risk and resilience forums, coordinate risk input during severe incidents and ensure accountability returns to the line after escalation. The function will provide frameworks, testing and challenge; it will not become the operational owner of every corrective action.

The CRO will also shape risk culture. Leaders should escalate uncertainty before it becomes a crisis, record why exceptions are accepted and communicate honestly with customers. Individuals who surface inconvenient evidence should be protected, while repeated failure to own agreed action will carry consequence.

Measures of success

The board committee will review material accounts by risk trajectory, recurring incidents, overdue root causes, security and resilience exceptions, disputed credits, remediation delivery and concentration. It will examine whether renewal decisions were supported by credible delivery and whether accepted exposures were authorised and time-bound.

Customer measures include avoidable churn, complaint recurrence, executive escalations, service stability and resolution confidence. Economic measures include cost-to-serve, credit leakage, remediation spend and retained contribution. Risk-function health will cover decision timeliness, action closure, independent testing, talent and the reduction of duplicate assurance.

Candidate profile

Candidates should bring 22–28 years in risk, managed services, technology, cyber, resilience or regulated enterprise operations. They must have held independent executive authority and influenced high-value customer or contract decisions. Experience with complex service failures and enterprise retention is more relevant than consumer campaign risk.

The committee will seek examples of challenging a renewal, funding a remediation because aggregate customer risk justified it and recommending exit where continuing service was unsafe or uneconomic. Candidates should understand contracts, service levels, cloud and cyber dependencies, incident response, third-party risk and customer communication.

The successful CRO will be commercially literate without becoming a revenue advocate. They must recognise genuine relationship value, challenge optimistic delivery claims and explain risk in language that helps executives choose. Calm authority during a live customer incident is essential.

Compensation and appointment terms

The indicative base range is AUD 440,000–590,000, plus annual incentive and long-term participation. Reward will balance customer resilience, responsible relationship decisions, control improvement, sustainable economics and leadership quality. Final terms will reflect the scale of independent risk authority and treatment of verified forfeited awards.

Confidentiality

The division is withheld because at-risk accounts, service failures, security exceptions and contract remedies are sensitive. Detailed information will be provided only after identity, conflict and confidentiality checks. Applicants must not disclose customer names, vulnerabilities, incident evidence or proprietary risk assessments from current or former organisations.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.