Chief Risk Officer, AI risk edition
Executive leadership, an executive role
What does Chief Risk Officer do?
The enterprise risk leader whose framework must now answer questions traditional risk programs never faced: how a model is evaluated before deployment, who owns AI risk, and how third-party AI is judged.
What it decides: The organization's AI risk appetite, and which residual risks are accepted at the top.
The competencies employers name
- AI risk and impact assessmentcore, depth expected
Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.
14 graded topics teach this
- AI risk register and treatment trackingcore, depth expected
Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.
12 graded topics teach this
- Model risk management and independent challengerequired, working knowledge
Classifies models by tier, sets validation requirements, challenges data, methodology and performance evidence, and reports aggregate exposure.
14 graded topics teach this
- AI vendor due diligence and third-party riskrequired, working knowledge
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- AI incident response and recoveryrequired, working knowledge
Classifies AI incidents by severity, runs containment, preserves evidence, manages notification, and closes the loop with lessons learned.
3 graded topics teach this
- AI resilience, continuity and exit planningrequired, working knowledge
Plans for a vendor failure, an unsafe model change or a suspended service: rollback, manual fallback, data export and safe decommissioning.
3 graded topics teach this
- Executive and board communication on AI riskcore, depth expected
Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.
10 graded topics teach this
- AI governance operating model designrequired, working knowledge
Designs decision rights, committees, intake, approval tiers and escalation so routine uses move and consequential uses get reviewed.
20 graded topics teach this
- US federal and state AI regulationpreferred, working knowledge
Tracks executive orders, OMB guidance, agency rules and the state patchwork, and knows which state laws reach hiring, insurance and consumer decisions.
17 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- EU AI Act Implementation Expert16 topics
- Certified AI Practitioner: Workplace Foundations13 topics
- The AI Lobbyist: Certified AI Policy Strategist13 topics
- Certified AI Governance Professional (CAIGP)11 topics
- Certified AI Transformation Professional (CATP)11 topics
- Certified Agentic AI Governance Professional (CAAGP)10 topics
Check your readiness for this role
Add what you already have (optional)
Roles that feed into it
- Enterprise Risk Director
- Internal Audit Director
- Operational Risk Manager
- Chief Compliance Officer
Where it leads
This is a destination role.
What postings tend to name
Frameworks: COSO ERM, ISO 31000, NIST AI RMF, ISO/IEC 42001.
Credentials often listed: CRISC, FRM, CIA, AIGP. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- Who owns AI risk in an organization?
- The business owner of each system owns its risk; the risk function owns the method and the register; the committee and the executive accept what remains. A CRO's first job is making that separation explicit.