
The business case of adding Risk to Compliance responsibilities
Sometimes corporate compliance officers seek the extra responsibility, sometimes it’s thrust upon them from senior management, and in many cases it’s a very plausible idea: upgrading the chief compliance officer’s role to be chief compliance and risk officer.
So if that happens, how can the compliance (and now risk) officer ensure a smooth transition?
First let’s appreciate why, for many organizations, expanding the compliance officer’s role to include risk management isn’t far-fetched. You’re already responsible for compliance risks that affect many parts of the business: dealing with vendors and customer relationships, resolving conflicts of interest, protecting customer data, and more. The substantive work is quite similar to enterprise risk management, too: you perform risk assessments, set policies, test controls, study data, and monitor for when normal business activity drifts into a danger zone.
Meanwhile, management teams see more risks cropping up across the organization, and cropping up earlier in the organization’s natural lifecycle. New technologies like artificial intelligence do make it possible to manage those risks more centrally – the company just needs somebody to do it. So why not tap the chief compliance officer for the task?
Plenty of compliance officers might also seek out this promotion as a matter of career growth. CCOs with law degrees can move into legal roles such as deputy general counsel or general counsel, but those who don’t have a law degree cannot. If they want to take on more responsibility within the business, moving into the chief risk officer role is one natural path upward.
So how can the company and the compliance officer alike ensure that such a transition succeeds?
First, define the role clearly
The single biggest mistake would be simply to declare, “We’re consolidating risk into compliance” without a clear definition of the role and what the chief risk and compliance officer is or isn’t expected to do. That sets you up for frustration and failure, and squanders corporate resources while doing so.
One important step is to spell out exactly what managing the risk means, so that you don’t end up owning the risk without your awareness or consent.
For example, you would want to clarify that the chief risk and compliance officer advises the business units on risk management strategies, but the CRCO shouldn’t be responsible for selecting and implementing those strategies; the business units decide which steps to take in consultation with you.
Or you could be responsible for monitoring enterprise risks, such as critical suppliers who are taking longer and longer to deliver goods. However, you shouldn’t be the one to decide, “Supplier A isn’t good enough anymore, so we’re shifting to Supplier B starting next month.” That would be you owning the risk, especially if Supplier B then turns out to be a poor choice.
Push for clarity and formality. The chief risk and compliance officer role should have a job description, and ideally a charter for the whole risk and compliance function. Any substantive changes to your role, especially adding new risks to your portfolio or new oversight duties, should require board approval.
Otherwise, the risk is that management and business operating units turn your compliance and risk function into a catch-all, “make sure nothing bad happens” function.
Think about the tools you’ll need
Some technology capabilities you’ll need will be the same ones you’d need as a chief compliance officer:
- Policy management
- Third-party due diligence
- Internal reporting and escalation
- Investigations
- Testing and auditing
- Remediation
- Monitoring and reporting
The good news is that artificial intelligence can make lots of this work much easier and more automated. For example, AI will be able to test the effectiveness of many controls, generate reports on which ones aren’t meeting expectations, and recommend prudent remediation measures. It can also draft policies and other documentation and help you put together reports for senior management. Compliance teams already use AI and other tools for these capabilities now, so the learning curve won’t be steep.
The real learning curve will be risk monitoring and analysis – that is, pulling together disparate sources of data to assemble the larger picture of risks challenging the whole enterprise.
That can be new for compliance officers, because you need to interpret more risk information in a larger context. As a compliance officer, you primarily needed to worry, “Is this activity a compliance risk that needs attention?” A chief risk officer must wonder, “Is this a business risk that needs attention?” (Recall our post from earlier this year about how compliance officers need to “speak the language of business.” For risk officers, that’s even more true.)
Certain risks could be dire threats to the business – a key supplier going bankrupt or a crippling cybersecurity attack, for example – that aren’t significant compliance risks at all. A chief risk officer would need to understand the threats to the business, the types of information that would help you monitor those potential threats, and the systems that can help you perform that monitoring so you can intercept business risks before they spiral into a crisis.

Understand the relationships
Even with clearly defined roles and proper tools, moving into the chief risk officer role still means you need to have new, different conversations with the board, senior management, and business operating team leaders.
For example, you’ll need to work with the board and CEO to define the company’s risk appetite; until that threshold is clear, you won’t be able to advise business units very well on prudent risk management strategies. You’ll need to have conversations about inherent risk (how much risk from a transaction or process with no controls in place) and residual risk (how much risk the organization will tolerate from those same things after controls are in place).
You’ll also need to engage with other risk assurance and business management functions: cybersecurity, HR, legal, procurement, accounting, and more. They may disagree with risk controls you want to see in place; be ready with some sort of risk acceptance certification so the ownership of that risk falls to them, rather than you.
Ultimately, compliance officers have many reasons to expand their role into risk management as well – and you can make that expanded role work; it’s an upward jump that can yield tremendous rewards for compliance officers and their employers. You just need clearly defined roles and tools that can be leveraged upward, too, as you make the leap.


