Selling to a chief risk officer
How services firms sell to a chief risk officer. What the role owns, what keeps it up at night, the signals worth watching and an opener that gets read.
· 3 min read
A chief risk officer doesn't buy upside. They buy fewer surprises. If your message promises growth, speed or innovation, it lands in the wrong inbox.
What a CRO wants is a clearer view of exposure and a credible plan to close a gap before a regulator, an auditor or the board finds it first. Write to that and you'll get read.
What the chief risk officer owns and answers for
The CRO owns the framework for how a company identifies, measures and reports risk. Credit, market, operational, model, third-party, sometimes compliance and resilience. In banks and insurers the role is senior and well funded. In other industries it may sit under the CFO with a thinner budget.
Either way, the CRO answers to the board's risk committee. That relationship shapes everything. Their year is built around what the committee asked for last time and what it'll ask for next.
They rarely run large delivery teams. They set the standard and other functions do the work. That makes them a sponsor and a gatekeeper more than a hands-on buyer.
CROs are measured on things not going wrong, and on being able to prove it. Clean exam results. Closed findings. Risk appetite statements the board signs without a fight. Reporting that's accurate and on time.
The quiet measure is credibility. A CRO who surprises the board once spends the next two years rebuilding trust.
So their pain usually lives in the space between what the framework says and what the data shows. A model nobody can explain. A third-party inventory built from spreadsheets. An issue log that keeps growing.
What they ignore
They ignore fear. "Regulators are cracking down" is a line every vendor sends, and it insults someone who reads the regulators for a living.
They ignore tools pitched as the answer. A CRO has seen plenty of platforms that turned into another system to validate.
And they ignore anyone who hasn't done the reading. If you don't know the difference between a finding and an observation, they'll know in one sentence.
The signals that matter
Exam outcomes and enforcement actions are the loudest. A consent order or a matter requiring attention comes with a deadline, and the CRO owns the remediation story. The consent order post covers how to read one.
New risk factors in a 10-K matter. When language about model risk, cyber exposure or vendor concentration shows up for the first time, someone inside asked for it.
A new CRO is a strong signal. New risk leaders tend to commission a gap assessment in their first quarter.
Hiring tells you a lot. A cluster of roles for model validators, third-party risk analysts or risk data engineers means a program is funded and short of hands.
The CRO is rarely alone. A head of operational risk or model risk is often your champion. The CIO or CDO owns the data the risk reports depend on. Write a version for each.
An example opener
Say a regional bank with a fictional name, Harbor Ridge Bancorp, added a new risk factor about third-party concentration in its annual report. Two months later it posted three roles for third-party risk analysts.
Harbor Ridge's annual report added a new risk factor on vendor concentration this year, and the bank has three third-party risk roles open right now. When those two show up together, it usually means the inventory and the tiering are being rebuilt by hand ahead of an exam. My guess is the hardest part is getting contract and usage data out of procurement and IT in a shape your team can trust. Is that accurate, or is the bigger issue something else?
It names a filing they approved. It ties the hiring to the work. It guesses at a data problem, not a governance failure, so nobody feels accused.
How the conversation goes
When a CRO replies, they'll often reframe your guess in risk language. Take their words and use them back.
Keep the first meeting about the gap and the deadline. Who's asking, by when, and what the evidence has to look like. Method and staffing come after.
And respect the independence of the role. A CRO can't look like they're buying a conclusion. Your work has to make their own judgment sharper, not replace it.
The point
Selling to a chief risk officer is selling clarity under scrutiny. Read what they've already told the board, find the gap between the framework and the data, and offer a specific guess they can correct. For more on reading filings this way, see the risk factor that wasn't there last year and how to read a 10-K like a seller.