Skip to main content

Chief Risk Officer, AI risk edition

Executive leadership, an executive role

What does Chief Risk Officer do?

The enterprise risk leader whose framework must now answer questions traditional risk programs never faced: how a model is evaluated before deployment, who owns AI risk, and how third-party AI is judged.

What it decides: The organization's AI risk appetite, and which residual risks are accepted at the top.

The competencies employers name

  • AI risk and impact assessmentcore, depth expected

    Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.

    14 graded topics teach this

  • AI risk register and treatment trackingcore, depth expected

    Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.

    12 graded topics teach this

  • Model risk management and independent challengerequired, working knowledge

    Classifies models by tier, sets validation requirements, challenges data, methodology and performance evidence, and reports aggregate exposure.

    14 graded topics teach this

  • AI vendor due diligence and third-party riskrequired, working knowledge

    Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • AI incident response and recoveryrequired, working knowledge

    Classifies AI incidents by severity, runs containment, preserves evidence, manages notification, and closes the loop with lessons learned.

    3 graded topics teach this

  • AI resilience, continuity and exit planningrequired, working knowledge

    Plans for a vendor failure, an unsafe model change or a suspended service: rollback, manual fallback, data export and safe decommissioning.

    3 graded topics teach this

  • Executive and board communication on AI riskcore, depth expected

    Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.

    10 graded topics teach this

  • AI governance operating model designrequired, working knowledge

    Designs decision rights, committees, intake, approval tiers and escalation so routine uses move and consequential uses get reviewed.

    20 graded topics teach this

  • US federal and state AI regulationpreferred, working knowledge

    Tracks executive orders, OMB guidance, agency rules and the state patchwork, and knows which state laws reach hiring, insurance and consumer decisions.

    17 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

  • Enterprise Risk Director
  • Internal Audit Director
  • Operational Risk Manager
  • Chief Compliance Officer

Where it leads

This is a destination role.

What postings tend to name

Frameworks: COSO ERM, ISO 31000, NIST AI RMF, ISO/IEC 42001.

Credentials often listed: CRISC, FRM, CIA, AIGP. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

Who owns AI risk in an organization?
The business owner of each system owns its risk; the risk function owns the method and the register; the committee and the executive accept what remains. A CRO's first job is making that separation explicit.