Take a look inside the world’s largest discreet leadership platform for banking and financial services344 open mandates33 countriesEverything financial services leaders need

Confidential mandate

CRO – Enterprise Risk — Retail Bank

Urgent / New

CRO – Enterprise Risk mandate in New York, USA · Banking

Rebuild enterprise-risk governance for a complex New York retail bank and deliver supervisory remediation with sustainable evidence.

The mandate

An institutionally backed retail bank has expanded across markets, products and channels faster than its risk governance. Local taxonomies, thresholds and committees produce inconsistent escalation, and supervisory remediation now requires a single enterprise view. The next planning cycle cannot proceed with risk information that reconciles only after decisions are made.

The CRO – Enterprise Risk will steward approximately US$69,350 million in loans and deposits and lead around 1,475 employees and material partners. The remit covers enterprise risk, credit, operational and model risk, risk appetite, portfolio oversight, issues management, stress, data and supervisory engagement. It reports to the Group Chief Executive and relevant board committee.

The first requirement is a coherent risk architecture. Appetite, limits, taxonomies, events, issues and committee decisions need defined relationships. Regional or product differences require evidence and a clear aggregation route. The CRO will remove duplicative reporting that consumes teams while obscuring the exposure requiring action.

Risk appetite must operate before a breach. Metrics need leading indicators, reliable data, thresholds and pre-agreed responses. Business leaders should understand which decisions remain delegated and when escalation is mandatory. Repeated exceptions will trigger a portfolio, process or leadership choice rather than endless renewal.

Supervisory remediation will be managed as operating change. Each finding needs a clear obligation, root cause, accountable executive, milestones, testing and sustainability period. Document production cannot substitute for changed decisions and behaviour. Independent assurance should enter early enough to challenge closure evidence before formal submission.

Portfolio risk requires joined views. Origination cohort, product, geography, customer treatment, concentration, funding and operational performance should connect to credit outcomes. The CRO will distinguish market movement from underwriting or servicing action and ensure emerging weakness changes pricing, limits, collections or capital promptly.

Model and data governance need practical ownership. Critical data elements, lineage, transformations, limitations and adjustments should be traceable. Models require use, performance and change evidence, not only technical validation. Manual overlays must have authority, rationale and expiry.

Operational and technology risk will be prioritised by service consequence. Incidents, resilience, cyber, partners and change should connect to customers and obligations. Control volume is not assurance. The risk function will identify which controls reduce exposure and challenge duplicated checks that create false comfort.

Escalation culture depends on response. Employees will not surface concerns if forums delay decisions or punish bad news. The CRO will make severity, ownership and timing explicit and ensure material dissent reaches the board. Closure requires proof under normal operation, not a one-off test.

The risk organisation will strengthen independent judgement and business fluency. Leaders need clear lines between advice, challenge and approval. Succession should test executives through stressed portfolio and incident decisions, reducing reliance on a few people who hold supervisory context.

Why this seat is open

This urgent new role replaces distributed risk ownership during remediation. Interim governance protects immediate decisions, but the board seeks a permanent executive within six to eight weeks to shape planning and supervisory engagement.

What you will own

  • Establish enterprise risk appetite, taxonomy, aggregation and decision rights.
  • Steward risk across US$69,350 million of loans and deposits.
  • Deliver supervisory remediation through sustainable operating evidence.
  • Connect portfolio, model, operational and technology risk views.
  • Strengthen escalation, issue ownership and independent challenge.
  • Lead approximately 1,475 employees and partners with credible succession.
  • Build traceable risk data, model use and adjustment governance.
  • Give the board transparent exposure, uncertainty and intervention options.

The first 12 months

The initial 90 days should reconcile remediation obligations, risk appetite and priority exposures. Meet the 30 stakeholders most consequential to risk governance, including supervisors, directors, business leaders, auditors, data owners and customers affected by treatment. Assess leadership and agree closure gates.

Months four to nine should simplify governance, implement leading indicators and resolve priority data or issue weaknesses. Make portfolio actions where evidence requires them and test sustainability independently. Early value may be a risk contained, capital protected, an issue closed credibly or a duplicate process retired.

By year end, risk transparency, decisive escalation and sustainable remediation should form a consistent pattern. Delivery must remain within 10% of approval and forecasts should reconcile exposure, cash, customers and people for three quarters. No severe escalation may age beyond 30 days, and priority closure needs independent acceptance.

What the board will measure

  • Exposure and action visible before risk appetite thresholds are breached.
  • Supervisory findings closed with independently accepted sustainability evidence.
  • Portfolio movement explained by cohort, market and management action.
  • Issues, incidents and model limitations escalated and resolved on time.
  • Retain more than nine in ten pivotal risk leaders and ready cover across seven in ten direct roles.
  • Risk reporting reduced while decision usefulness and data ownership improve.

The person

You are a CRO, Risk Director or senior controls executive with 18–22 years in banking or adjacent regulated finance. You have held independent challenge authority and closed material issues with evidence accepted by a board or supervisor.

Your accountable P&L, book, budget or portfolio has been at least US$40,200 million, and you have led 1,025 or more people. You can demonstrate outcomes sustained across two reporting periods.

You understand retail credit, model, operational and enterprise risk. You can challenge commercial leaders without taking over first-line ownership and can explain complex exposure plainly when evidence is incomplete.

Compensation and terms

Base compensation is US$430,000–575,000 plus annual incentive and equity. The permanent New York role is onsite, supports international relocation and permits notice of up to six months.

Confidentiality

The bank, supervisory findings and risk profile remain confidential. Identifying information follows reciprocal interest under a mutual undertaking; published circumstances are blended.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.