Confidential mandate
Chief Risk Officer — Applied-AI Portfolio
Urgent / Replacement
CRO - Risk mandate in Mumbai, India · Artificial Intelligence
Reset enterprise risk ownership as an applied-AI portfolio crosses from promising solutions into scaled commercial deployment.
The mandate
An applied-AI portfolio is moving from controlled propositions into wider commercial use, increasing the number of customers, contexts and third parties exposed to its decisions. Risk ownership has not kept pace. Product, commercial, delivery and control teams each understand parts of the exposure, yet material acceptance can still become a negotiation after commitments are made. The new Chief Risk Officer will reset first-line accountability and give the board assurance grounded in operating evidence.
The perimeter covers approximately ₹1,050 crore in AI product and services revenue and around 240 employees and material partners across India, Mumbai and the wider operating region. It includes enterprise risk, compliance, model and data oversight, assurance, incident governance and third-party exposure. Commercialisation changes the scale of consequence: a control that worked through expert attention in a small deployment may fail when propositions are repeated across clients.
The CRO must enable informed commercial choices, not create a final approval queue. Risk appetite should translate into boundaries that product and account leaders can apply before pricing and contracting. Evidence must travel with the solution through design, release, customer configuration and monitoring. The board needs to know both whether controls exist and whether operating teams use them when trade-offs become difficult.
Why this seat is open
This is an urgent replacement after an accelerated leadership transition. Interim accountability protects critical matters, but a commercialisation inflection cannot be governed through divided ownership. The board expects to appoint within six to eight weeks and is treating predecessor circumstances neutrally and professionally. The permanent onsite position is based in Mumbai, reporting to the Group Chief Executive and relevant board committee.
What you will own
You will begin by defining the portfolio’s material risk universe through actual customer and product journeys. Model behaviour, data rights, security, regulatory exposure, customer dependency, conduct and resilience should be connected rather than assessed as isolated registers. Risk appetite must specify escalation and acceptance authority at useful thresholds, including conditions under which an opportunity should not proceed.
First-line leaders need practical obligations. You will agree control ownership with product, engineering, commercial and delivery executives, simplify overlapping attestations and ensure that evidence can be produced without emergency reconstruction. The independent risk function should challenge assumptions, test critical controls and identify concentration across customers, models and suppliers. It should not quietly perform controls that the business believes it owns.
Early warning is central to the brief. Incident, complaint, evaluation, service and commercial data need to reveal emerging patterns before loss or regulatory attention forces action. You will establish triggers that reach the correct forum with enough context for a decision. Remediation must address causes and confirm sustained closure, rather than count actions completed.
The 240-person employee and partner perimeter also requires clear standards. You will assess leadership, reduce fragmented specialist coverage and build succession for pivotal roles. Board papers should state exposure, appetite, control evidence and requested decision in plain language. Regulators and customers must receive consistent, substantiated accounts of how the portfolio is governed.
The first 12 months
In the first 90 days, validate the top exposures through representative deployments, loss and near-miss data, complaints, assurance findings and commercial commitments. Inspect how risk acceptance occurs in practice and stabilise any immediate gaps. Assess direct reports, clarify interim authorities and agree a board scorecard that separates inherent exposure, control performance and residual decisions.
Between months four and nine, implement the revised accountability model across priority propositions. Embed risk gates in product and commercial workflows, improve early-warning data and independently test the controls most important to scaled deployment. Resolve duplicated forums and fill leadership gaps. Demonstrate at least one issue detected and contained earlier because the new system connected relevant signals.
By month twelve, the board should receive regulator-ready evidence and a materially clearer view of control effectiveness. Enterprise risk ownership must be visible in first-line objectives, decisions and consequences. The following year’s plan should prioritise remaining exposure by commercial significance and include downside actions if control performance or portfolio growth diverges.
What the board will measure
The agreed risk programme and first-year value commitments should finish within 10% of approval, with deviations forecast early. Three quarterly outlooks must reconcile growth, customer exposure, control capacity, cash and people. A chosen operating constraint behind commercialisation risk needs demonstrable improvement from a controlled baseline and named data stewardship.
Priority findings should be closed by their authorised deadlines and retested for endurance. At least 90% of critical risk talent should be retained and ready-now succession should cover 70% of direct reports. Material incidents cannot be omitted from formal governance, while any severe escalation open for more than 30 days requires a documented acceptance or closure decision.
The person
You are a CRO, Deputy CRO or Chief Compliance and Risk Officer with 22–28 years in AI, enterprise software, data infrastructure, cloud, analytics, applied research or a comparable regulated technology environment. You have held accountability for at least ₹850 crore of P&L, budget, book or risk portfolio and led no fewer than 240 people.
Your track record shows enterprise risk ownership moving into the first line during commercial expansion. You can explain how appetite became operational, how weak controls were identified and how evidence changed a board or customer decision. The organisation values constructive independence: you can stop unsafe activity without making the risk function the owner of commercial judgement. References should confirm sustained results.
Compensation and terms
The anticipated package is ₹2.2–3.0 crore fixed plus performance variable, calibrated to the eventual portfolio scope and candidate mix. Standard vesting and performance terms apply to any long-term element. A notice period up to six months is workable. The role has frequent access to the chair, executive committee and principal capital sponsors.
Confidentiality
The company, predecessor and detailed control findings remain confidential pending mutual interest and an appropriate undertaking. Public scale and context have been deliberately rounded and combined to prevent identification.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.