Risk management responsibilities 93
The risk manager should be responsible for the corporate learning that has to take place so
that the organization can understand the benefi ts of risk management. As guardian of the risk
architecture, strategy and protocols (GRASP), the risk manager will be responsible for devel-
oping the strategy, systems and procedures by which the required risk management outcomes
for the organization are achieved.
Historically, the insurance risk manager has probably not been involved in the strategic man-
agement and development of the organization. The broader role now required of a risk
manager should lead to a greater involvement in project management and strategy formula-
tion and delivery. The risk manager who enjoys a broad range of responsibilities will have a
very challenging role within the organization. It will be a role that enables the risk manager to
obtain a better level of understanding and involvement than most other roles or functions
achieve.
Chief risk offi cer (CRO)
Perhaps, the title ‘Risk Manager’ has too many historical connections for it to be used as an
appropriate description of what is now required. There is a need to fi nd a new title and re-
defi ne the role of risk management at the same time.
Many organizations in the fi nance and energy sectors have identifi ed the benefi ts of bringing
the management of credit, market and operational risks together. It has been the case for some
time in the fi nance sector that risk management has been separate from the purchase of insur-
ance. The development of the role of chief risk offi cer (CRO) reporting directly to the CEO
refl ects this fact.
Given that one of the key principles of risk management is that the approach to risk should be
proportionate to the level of risk faced by the organization, it is unlikely that the majority of
organizations will need to appoint someone of the seniority of a CRO. Nevertheless, organiza-
tions should, when reviewing their risk management architecture, decide the appropriate
range of responsibilities and level of seniority of the risk manager.
The introduction of the job title Chief Risk Offi cer (CRO) is not universal, but it is becoming
common in the specialist fi nance and energy sectors. Guardian of the risk architecture, strat-
egy and protocols (GRASP) is a superior description of the role that must be fulfi lled.
The box below provides an overview of the developing role of the chief risk offi cer. For organ-
izations where it is proportionate for a CRO to be appointed, the contribution that can be
made by that individual will be substantial.