Role guide · ADGM and the UAE

Fractional Chief Risk Officer for ADGM and UAE-regulated firms

Regulators expect a documented, board-approved view of risk long before operations begin. A Chief Risk Officer, also called a Head of Risk, builds that view and keeps it honest.

AppetiteSet with the board
RegistersKept current
OngoingFractional cover
A Chief Risk Officer reviewing charts on a wall board by a bright window
At a glance

The Chief Risk Officer in brief

The senior leader who identifies and measures the risks the firm runs, agrees with the board how much risk it will take, and reports honestly against that limit.

Also searched as: Head of Risk, Risk Officer
Regulatory status
Depends on the firm and regulator: CBUAE no-objection at a bank, a Controlled Function for ADGM banks and insurers, and a CMA-approved job.
Reports to
The chief executive and the board or its risk committee.
Works closely with
The Head of Compliance, MLRO, finance and internal audit.
Where it sits
Second line: independent risk oversight and challenge.[1]
Typical commitment
Agreed days each month, weighted to risk committee cycles, licence submissions and major decisions.

What the rules say

  • The DFSA and the FSRA both require firms to have risk management systems and controls, and to appoint an individual to advise the board and senior management on the firm’s risks.[2],[3]
  • In ADGM, banks and insurers are expected to give that role to a senior manager other than the chief executive, which makes it a Controlled Function needing FSRA approval.[3],[4]
  • CBUAE-licensed banks must have an independent risk management function headed by a Chief Risk Officer who reports directly to the board or its risk committee, and need CBUAE no-objection to appoint them.[5],[6]
  • The CMA lists risk management officer as a job that needs its approval, and VARA requires an effective risk management function with a suitably qualified head.[7],[8]
What they do

The risk management process

ISO 31000 sets out a process most risk functions follow: identify risks, analyse and evaluate them, treat them, then monitor and report. The Financial Stability Board adds the piece boards care most about: an agreed risk appetite that limits how much risk the business takes.[9],[10]

What they own

  • EWRA and business risk assessment
  • Risk appetite statement
  • Risk registers
  • Ongoing client risk-rating
  • Board risk reporting
  • Input to onboarding decisions
01

Identify

Build and maintain risk registers across financial, operational, conduct, technology and financial crime risk.

02

Assess

Rate each risk for likelihood and impact, and lead the business risk and enterprise-wide risk assessments.

03

Set appetite

Draft the risk appetite statement the board signs off, with limits and early-warning indicators.

04

Treat

Agree controls and actions with the business, and challenge decisions that fall outside appetite, including new clients and products.

05

Monitor and report

Track risks and indicators, and give the board a clear, independent view of the firm’s risk profile.

Why it matters

Why a UAE firm needs a Chief Risk Officer

Not every firm needs a full-time one. Every regulated firm needs someone to own the risk framework.

  1. 01

    Every regulated firm needs a risk owner

    Free zone rules require an individual to advise the board on risk. Someone has to own the registers, the assessments and the reporting.[2],[3]

  2. 02

    The board has to set an appetite

    International good practice expects the board to agree how much risk the firm will take, and the risk function to hold the business to it.[10]

  3. 03

    Banks must have one

    CBUAE-licensed banks need an independent risk function headed by a Chief Risk Officer, reporting directly to the board.[5]

  4. 04

    Licence applications need a risk framework

    An application needs a credible business risk assessment and a framework the regulator can review. That is hard to write well without someone who has done it before.

How it works

How a fractional Chief Risk Officer works with us

One brief, one accountable appointment. The person you meet is the person named on the appointment and doing the work.

01

Brief

Tell us where you are regulated, what stage you are at and why the role is needed. We screen the firm and any open regulatory matters before recommending an appointment.

02

Shortlist

We put forward senior candidates with relevant tenure in your role, sector and jurisdiction. You meet the person who will do the work, not a sales lead.

03

Approval

Where the role needs regulatory approval, we help prepare the application and the candidate for the fit and proper assessment. The regulator holds final acceptance.

04

Ongoing

Your appointee works agreed days each month, reports to your board and steps up around licensing, inspections and remediation.

The first 90 days

Days 1 to 30

Map the risks

  • Review the business plan, existing risk registers and assessments
  • Interview the leadership team on the risks they see
  • Check what the regulator has been told about the risk framework

Days 31 to 60

Build the framework

  • Draft the risk appetite statement and key indicators
  • Refresh the risk registers and client risk-rating approach
  • Set up risk reporting to the board or committee

Days 61 to 90

Run it

  • Take the risk appetite statement to the board for approval
  • Deliver the first risk report
  • Agree the annual cycle of reviews and stress tests
Choosing the model

Fractional, full-time or outsourced?

All three can work. What matters to the regulator is that the person named on the appointment has the seniority, independence and time to hold it.

Fractional
Full-time hire
Outsourced provider
Who does the work
FractionalThe named senior individual you appointed
Full-time hireYour own employee
Outsourced providerA provider’s team, under a named lead
Time commitment
FractionalAgreed days each month, flexing with need
Full-time hireFull time, whatever the workload
Outsourced providerSet by the service contract
Cost basis
FractionalA share of a senior salary, for the time you use
Full-time hireFull salary, benefits, visa and hiring costs
Outsourced providerA service fee, often plus ad hoc charges
Getting started
FractionalNo full recruitment cycle
Full-time hireA full search and notice period
Outsourced providerQuick to contract
Continuity
FractionalStays as long as you need; handover planned
Full-time hireDepends on retention
Outsourced providerStaff may rotate across clients
Best when
FractionalYou need a senior risk leader to build and run the framework, not a full-time department.
Full-time hireThe balance sheet or business model carries risk every day, as at a bank.
Outsourced providerYou need a one-off risk assessment or model validation.
When to engage

Signs it is time

  • A licence submission needs a risk framework
  • Client risk-ratings are out of date
  • The board lacks independent risk reporting
  • You are launching a new product, market or business line
Who we place

What good looks like

Relevant tenure and experience leading risk in regulated firms.

  • Experience leading risk in a regulated firm
  • Hands-on work on risk appetite, registers and board reporting
  • Knowledge of your sector’s main risks, whether credit, market, operational or technology
  • The independence to challenge the business and the board
Related roles

Often appointed alongside

Most regulated firms need more than one of these roles. Each has its own guide.

  1. Head of ComplianceThe senior leader accountable for the whole compliance framework, who oversees the Compliance Officer and MLRO and represents the firm to the regulator.
  2. Compliance OfficerThe approved individual who makes sure the firm meets its regulatory obligations day to day, and tells senior management when it does not.
  3. Head of Financial CrimeThe senior specialist who owns the firm’s defences against money laundering, sanctions breaches, fraud and bribery, and proves they work.
All seven Risk and Compliance roles
Common questions

Chief Risk Officer, answered

Yes, in most firms. Chief Risk Officer is more common at banks and larger groups; Head of Risk at smaller firms. We write Chief Risk Officer in full because the short form is also used for Chief Revenue Officer.

Every DIFC and ADGM firm needs someone to advise the board on risk, but not necessarily a full-time Chief Risk Officer. Banks are different: CBUAE-licensed banks must have one, and ADGM expects banks and insurers to appoint a senior manager to the role.

Sometimes. VARA allows the Compliance Officer to head the risk function. Elsewhere it depends on size and risk: combining the two weakens independent challenge, so larger firms keep them apart.

It depends. It is a Controlled Function for ADGM banks and insurers, needs CBUAE no-objection at a bank, and is an approved job at the CMA. At many smaller firms it is not separately approved.

Brief a compliance search

Need a Chief Risk Officer? Tell us where you are regulated.

We screen why the role is needed, triage any regulatory action and recommend the appointment your risk profile requires.

Brief a search for this role

Sources

  1. [1]The Institute of Internal Auditors, Three Lines Model: Assurance and Advice in Support of Effective Governance (2026).
  2. [2]Dubai Financial Services Authority, DFSA Rulebook, General Module (GEN), GEN 5.3.4 to 5.3.6, risk management.
  3. [3]ADGM Financial Services Regulatory Authority, General Rulebook (GEN), GEN 3.3, risk management and compliance arrangements.
  4. [4]ADGM Financial Services Regulatory Authority, General Rulebook (GEN), GEN 5.3 and 5.5, Controlled Functions and Approved Persons.
  5. [5]Central Bank of the UAE, Risk Management Regulation (Circular 153/2018), Article 3.
  6. [6]Central Bank of the UAE, Corporate Governance Regulation for Banks (Circular 83/2019), Articles 1 and 5, senior management appointments.
  7. [7]Capital Market Authority, Rulebook, Section 2: Licensing of Financial Activities and Jobs Approval, Chapter 6, approved jobs.
  8. [8]Virtual Assets Regulatory Authority, Compliance and Risk Management Rulebook, Part I (Compliance Officer, risk management) and Part III (MLRO).
  9. [9]International Organization for Standardization, ISO 31000:2018 Risk management.
  10. [10]Financial Stability Board, Principles for an Effective Risk Appetite Framework (2013).

Plain-English summaries, reviewed September 2026. Rulebooks change, so always check the current text. Fractional places qualified executives into regulated appointments. We do not provide legal advice, and final acceptance of any appointment rests with the relevant regulator; we work alongside your appointed legal and compliance advisers. Appointments to roles requiring regulatory approval are subject to the relevant authority’s requirements.