SMF4: The Chief Risk Officer the Board Needs to Hear From
Share
Subscribe
Welcome to the SMF Capital Podcast. Today we're looking at SMF4 — the Chief Risk function and why the Chief Risk Officer can play such an important role in the governance of a regulated financial services business. Risk management matters to every business, but in a regulated firm the board needs to understand its principal risks, how those risks are changing and whether the controls designed to manage them are working effectively. That's where the Chief Risk Officer can become particularly i...
Welcome to the SMF Capital Podcast.
Today we're looking at SMF4 — the Chief Risk function and why the Chief Risk Officer can play such an important role in the governance of a regulated financial services business.
Risk management matters to every business, but in a regulated firm the board needs to understand its principal risks, how those risks are changing and whether the controls designed to manage them are working effectively.
That's where the Chief Risk Officer can become particularly important.
What Is SMF4?
SMF4 is the Chief Risk function.
It forms part of the Senior Management Functions framework, although whether an SMF4 is required depends on the type and regulatory status of the firm.
Where the function applies, the individual isn't simply a conventional risk manager. They have specific senior management responsibilities within a regulated organisation.
That makes the appointment an important part of the firm's governance structure.
The CRO also needs to work effectively alongside other Senior Management Functions, including the CEO, CFO, Compliance Oversight and, where applicable, the MLRO.
The objective isn't simply to create a collection of senior job titles. It is to establish clear responsibility and accountability.
What Does a Chief Risk Officer Actually Do?
The Chief Risk Officer provides senior oversight of the risks facing the business.
Depending on the firm, this can include:
- Financial risk
- Operational risk
- Conduct risk
- Technology and cyber risk
- Liquidity risk
- Credit risk
- Regulatory risk
- Strategic risk
- Third-party and outsourcing risk
- Business continuity and resilience
The exact risk profile depends on the firm's activities.
A payments business may face very different risks from an investment firm or another type of financial services business.
That's why the right SMF4 candidate needs to understand the firm's particular risk environment.
The CRO Needs to Be Heard by the Board
One of the most important aspects of the role is the ability to communicate risk directly and clearly to the board.
A CRO shouldn't simply produce a monthly risk report.
They need sufficient standing to challenge management where appropriate.
Imagine a commercial team wants to launch a new product quickly. The opportunity looks attractive, but the CRO identifies significant operational, technology or regulatory risks.
The purpose of the risk function isn't necessarily to stop the business taking risks. Businesses need to take risks to grow.
The purpose is to ensure those risks are identified, understood and appropriately managed.
That requires a CRO who can provide constructive challenge while understanding the commercial objectives of the business.
Why Independence Matters
A CRO needs enough independence to raise concerns when necessary.
If the person responsible for risk feels unable to challenge the commercial leadership team, the value of the function can be significantly reduced.
The CRO therefore needs to be sufficiently close to the business to understand what is happening, while retaining the ability to challenge decisions.
This becomes particularly important in rapidly growing fintech and financial services businesses, where the risk profile can change quickly as new products, customers, markets and technology are introduced.
SMF4 and FCA Authorisation
For businesses seeking FCA authorisation, the question isn't simply whether the company has a risk policy.
The regulator also needs to understand the governance arrangements surrounding the business.
Who has responsibility for risk?
How are risks identified and monitored?
Who reports to the board?
How are material risks escalated?
Who can challenge senior management?
And how does risk management interact with compliance and finance?
These are governance questions as much as risk questions.
Where SMF4 applies, the appointment should therefore be considered as part of the wider authorisation and governance strategy.
What Makes a Good SMF4 Candidate?
When recruiting a Chief Risk Officer, businesses should consider several areas.
Relevant risk experience: Does the candidate understand the risks associated with the firm's activities?
Regulatory experience: Have they operated within a regulated financial services environment?
Board-level communication: Can they explain complex risks clearly to directors and senior management?
Independence and challenge: Are they comfortable questioning decisions and escalating concerns?
Commercial understanding: Can they balance effective risk management with an understanding of the firm's commercial objectives?
The balance will vary between businesses.
A rapidly growing fintech may require a very different CRO profile from a large established financial institution.
Risk Management and Compliance
Risk management and compliance are closely connected, but they aren't necessarily the same function.
Compliance focuses heavily on meeting applicable laws, regulations and regulatory expectations.
Risk management takes a broader view of the risks facing the organisation and how those risks are identified, assessed, controlled and monitored.
There can be areas of overlap, but a well-designed governance structure should establish clear responsibilities and effective communication between the functions.
The CRO and CFO
The relationship between the CRO and CFO can also be important.
Financial decisions can create risk, while risk decisions can have financial consequences.
Changes to capital allocation, liquidity management, lending strategy or investment strategy can affect both the firm's financial position and its risk profile.
The CFO and CRO therefore need to work together while retaining clarity around their respective responsibilities.
Statements of Responsibilities
The responsibilities of an SMF4 also need to be clearly defined.
A Statement of Responsibilities should reflect what the individual is actually responsible for within the organisation.
That means understanding:
- Who owns particular risks
- Who monitors them
- Who escalates them
- Who reports them to the board
- Who has authority to challenge management
The answers should make sense within the firm's overall governance structure.
Does Every Business Need an SMF4?
Not necessarily.
The applicable Senior Management Functions depend on the firm's regulatory status, activities and circumstances.
Businesses shouldn't simply copy another company's governance structure.
A structure appropriate for a large financial institution may be excessive for a smaller fintech, while a structure designed for a small start-up may become inadequate as the business grows.
The right approach is to understand the applicable requirements and design the governance structure around the actual business.
For an overview of the different Senior Management Functions, see our SMF Designations: A Complete Guide.
Recruiting an SMF4
Recruiting a Chief Risk Officer is about much more than finding somebody with "risk" on their CV.
The recruitment process should consider:
- The firm's regulatory status
- Its business model and principal risks
- The required governance structure
- The candidate's regulatory experience
- Technical risk expertise
- Board experience
- Ability to challenge senior management
- Ability to communicate complex issues clearly
The right balance depends on the individual firm's circumstances.
The CRO and Risk Culture
The CRO can also play an important role in developing the firm's risk culture.
Where to Find Out More
If you're considering an SMF4 appointment, we've produced a dedicated guide:
SMF4: The Chief Risk Officer the Board Needs to Hear From
It looks specifically at the SMF4 role and the considerations involved in appointing a Chief Risk Officer within a regulated financial services business.
For the wider picture, see our SMF Designations: A Complete Guide.
Closing
So, what makes an effective SMF4?
It's not simply someone who can produce a risk register.
The Chief Risk Officer needs to understand the firm's risks, communicate them effectively, provide appropriate challenge and have the credibility to ensure important risk issues reach the board.
For a regulated business, that makes the CRO an important part of the overall governance structure.
If you're researching SMF4, read The Chief Risk Officer the Board Needs to Hear From.
And for the wider framework, see our complete guide to SMF designations.
You can also visit SMF Capital to find out more about senior management recruitment and support for regulated businesses.
That's all for this episode of the SMF Capital Podcast.
Thanks for listening.
