| Licence required | None. No US state licenses enterprise risk managers and there is no mandatory exam for the title. Two adjacent exceptions: a risk seat inside a broker-dealer may require registration on Form U4 through FINRA, and a signing or attesting role in an insurer may need an actuarial qualification. For everyone else the gate is evidence of having run the cycle, not a certificate. |
|---|---|
| Credential most often named in postings | It depends on the sector, and getting this wrong wastes a year. Banking and capital markets: FRM from GARP or PRM from PRMIA. Insurance: CERA for actuarial paths, ARM or CPCU on the insurance and claims side. Technology and cyber risk: CRISC from ISACA. Corporate and industrial ERM: RIMS-CRMP, which is built around ISO 31000, with a federal variant for government roles. Coming from audit: CIA and CRMA from the IIA already carry weight. Postings usually say preferred, not required. |
| What the credentials require | Most gate on experience as well as an exam. FRM is two exam parts plus two years of relevant professional experience before certification. CRISC requires three years of real risk and information systems control work across at least two of its domains. RIMS-CRMP combines an education and experience threshold with an exam. CIA is three parts plus an experience requirement. Requirements get revised, so confirm the current ones with the issuing body before you plan around them. In practice you sit the exam while already in a risk-adjacent seat, not before. |
| How long it takes | If you are already inside a company in audit, compliance, operations, finance or insurance, a move into enterprise risk is usually a one-step internal move or a single external hire, and three to nine months of deliberate preparation is a realistic horizon. From outside a risk-adjacent function it is slower: expect to take a risk analyst or operational risk seat first. Exam study adds months but is rarely the bottleneck. The missing artefacts are. |
| Typical hiring timeline | Four to eight weeks in a corporate, often three to five stages. Longer in regulated financial institutions, where background screening, an independence check and sometimes a fit-and-proper style review extend it, and where panels run larger. Public sector and higher education can run three months or more on a fixed committee schedule. |
| Who you report to | A chief risk officer or head of risk in a regulated firm. In mid-size corporates it is more often the CFO, the general counsel or a chief compliance officer, and the enterprise risk manager is the entire function. Reporting into the chief audit executive still happens and is worth a question at interview, because it folds a second-line job into the third line and costs you independence. |
| Pay source to use, not a band | The BLS publishes no wage series for the title enterprise risk manager. The closest OES occupations are 13-2054 Financial Risk Specialists and 11-3031 Financial Managers for financial-sector roles, and 13-1041 Compliance Officers or 11-9199 Managers, All Other for corporate ERM. For live numbers use postings in states that require a pay range in the advert, including Colorado, California, Washington, New York and Illinois, and check whether your own state now does. RIMS runs a compensation survey of the risk profession, and for banks and insurers the sector salary surveys beat any general aggregator. |
| The part nobody prepares for | The board and committee calendar sets the year. Papers are due one to two weeks before an audit or risk committee meeting, the appetite refresh and the annual risk assessment land on fixed dates, and an incident can take over a month at no notice. In multi-site industries, site risk assessments mean travel, so ask how many sites and how often before you accept. |
What an enterprise risk manager actually does, and the five versions of the title
An enterprise risk manager owns the process by which an organisation decides which of its risks it is willing to carry, and then keeps that decision honest. You do not own the risks. The business owns the risks. You own the taxonomy, the assessment process, the appetite and tolerance structure, the escalation route, the indicators, the scenario work and the reporting into an executive risk committee and a board committee. If a candidate cannot say that distinction crisply, it is usually the first thing an interviewer notices.
In practice the week is made of three kinds of work. The first is interviewing the business: sitting with a head of supply chain, a VP of engineering, a treasurer or a plant manager and getting them to say out loud what actually worries them, then turning that into a risk statement with a cause, an event and a consequence rather than a one-word topic. The second is measurement: defining what impact and likelihood mean in units that survive challenge, building indicators with thresholds and named data owners, and running a scenario or a stress test that produces a number someone can argue with. The third is writing: a committee paper, a register entry, an appetite statement, an escalation memo. The written output is the product, and people underestimate how much of this job is drafting.
The title covers at least five jobs, hired by different managers with different vocabularies. Treat them as different applications.
What separates a good enterprise risk manager from a report factory is a bias toward decisions. A register that grows every quarter and changes nothing is a failure, however well formatted. The artefact that wins an interview is not a heat map, it is a sentence of the form: we assessed this, the appetite said no, and the business did X instead.
A related distinction that trips up candidates from audit: a risk is a possible future event, an issue is something already happening, and a control deficiency is a weakness in a mitigation. Registers that mix all three are the most common thing you will inherit, and saying you would separate them in week one is a credible, specific first answer.
- Corporate ERM, often a one-person or two-person function reporting to the CFO or general counsel. The work is the annual top-risk assessment, the appetite statement, the audit committee paper, insurance and total cost of risk, business continuity, and increasingly AI governance. Framework reference is usually COSO ERM 2017 or ISO 31000.
- Second-line risk in a bank or credit union, one layer inside a large risk organisation. The work is the risk and control self-assessment programme, operational risk loss event data, issue and action management, appetite metrics cascaded into limits, challenge of first-line assessments, model risk interaction, and surviving the examination cycle. Framework reference is the Basel operational risk framework, supervisory guidance on model risk management, and for large institutions the OCC heightened standards style risk governance framework.
- Insurance company risk, centred on the Own Risk and Solvency Assessment process under the NAIC model, which insurers above a premium threshold file with their lead state regulator. Add risk-based capital interaction, reinsurance and catastrophe exposure, and a far more quantitative relationship with the actuarial function. CERA and actuarial credentials carry real weight here.
- Technology and operational resilience risk: cyber, third-party and vendor risk, data and privacy, change and release risk, concentration on a small number of cloud and SaaS providers, and resilience testing. Framework reference is NIST CSF 2.0, ISO/IEC 27001 and 27005, and now NIST AI RMF and ISO/IEC 42001.
- Public sector, healthcare and higher education ERM. Federal agencies run ERM under OMB Circular A-123 and reference the GAO Green Book for internal control. Hospitals run it close to patient safety, clinical quality and professional liability. Universities run it close to research compliance, Title IX, athletics and the endowment. The frameworks are the same; the register contents are nothing like a bank's.
What gates the job, and what stands in for a licence
There is no licence. That sounds like good news and is actually the hard part, because when nothing is gated by an exam, hiring is gated by evidence, and evidence is exactly what people moving in from audit or operations cannot produce yet. The question behind every interview stage is: have you ever carried a full cycle, or have you only contributed to someone else's?
A full cycle means all of this, once, with your name on it. You identified risks by talking to owners rather than circulating a survey. You assessed them against defined scales. You got a risk owner to accept ownership in writing. You set an appetite or tolerance that could actually be breached. You built at least one indicator that would tell you before the event rather than after. You reported it to a committee. And something changed. People who have done that answer questions in a different register from people who have not, and panels hear it inside two minutes.
The secondary gates are real but smaller. Background screening is standard and stricter inside regulated financial institutions, where fingerprinting and credit checks are common. Federal law also bars an insured depository institution from employing someone convicted of certain offences involving dishonesty, breach of trust or money laundering without a formal waiver, which is why bank screening asks about matters you might think are ancient history. Disclose everything on the form: an undisclosed item ends a process faster than the item itself would have.
Independence matters too. If you have been the internal auditor of the function you are about to risk-manage, expect a conversation about cooling off and about which assessments you will recuse yourself from. In a broker-dealer, a risk seat may carry FINRA registration on Form U4, with its own disclosure questions.
Degrees are rarely the gate. Postings commonly ask for a bachelor's in business, finance, accounting, engineering or a quantitative field, and an MBA or a master's in risk management is a mild plus and never a substitute for the cycle. The one place education binds is the actuarial path in insurance, where the exam sequence is the entry route and there is no way around it.
What does function as a soft gate is sector fluency. A bank will not hire a corporate ERM manager who cannot say what an RCSA is, what a past-due issue action means in that building, or how operational risk loss data gets captured and used. A manufacturer will not hire a bank second-line manager who talks about appetite metrics but has never valued a business interruption exposure or looked at a single-source component list. The vocabulary is the credential.
One more honest point. The ERM function in a company that does not want it is a thankless seat, and candidates rarely diligence this. Ask who sponsored the role, what triggered it, whether the board asked for it, and what happened to your predecessor. A role created because an auditor or a regulator wrote a finding is survivable. A role created because an executive wanted a report produced, with no mandate to escalate, is the one people leave in a year.
- The real gate: one complete risk cycle you can describe end to end, with a decision at the end of it.
- Background screening, stricter in banks, credit unions and insurers, with federal employment bars for certain convictions. Disclose everything on the form.
- Independence and cooling off if you are moving from internal audit into risk at the same employer.
- Form U4 registration through FINRA for some risk seats inside broker-dealers.
- Sector vocabulary, which behaves like a licence even though it is not one: RCSA and issue management in banks, ORSA in insurers, total cost of risk and business interruption values in industrials, resilience and third-party concentration in technology.
The credentials worth having, and the order to take them
Pick the credential your target sector names, not the one with the broadest-sounding title. The generic ERM certificates sold by training companies carry very little weight because there is no barrier to getting one, and a resume whose strongest line is a two-day ISO 31000 awareness course reads as someone shopping for a shortcut.
If you are coming from internal audit, you very likely already hold the most useful thing. The CIA from the Institute of Internal Auditors plus the CRMA tells a risk hiring manager you understand control environments, committee reporting and issue tracking. A CPA does the same work on the financial reporting side. Neither proves you can set an appetite, which is why the artefacts matter more than the letters.
If you are targeting banking, the FRM from GARP is the one recruiters search by name, and it is a genuine commitment: two exam parts, a heavily quantitative syllabus, and two years of relevant professional experience before you are certified. The PRM from PRMIA is a credible alternative with on-demand exam scheduling. Be honest about fit: FRM is weighted toward market, credit and quantitative risk, so if your target is operational or enterprise risk governance in a mid-size bank, the marginal return is lower than the study hours suggest.
If you are targeting technology, cyber or third-party risk, CRISC from ISACA is the clear leader and requires three years of real experience across at least two of its domains. CISA helps if you came from IT audit. For resilience and continuity seats, the DRI International certifications, CBCP and above, are the recognised ones.
For corporate and industrial ERM, RIMS-CRMP is the credential built on ISO 31000 and is well recognised on the insurance and risk management side of the profession, with a federal variant for government roles. The ARM and CPCU from The Institutes are the right choices if the job includes insurance programme, claims and total cost of risk work, which many corporate risk manager roles do and which candidates from audit routinely overlook.
The sequencing that actually works: get into a risk-adjacent seat first, then take the exam your employer will pay for, then use the exam period to build the artefact you are missing. Studying for a credential while having nothing to show is the wrong order. A candidate with no certification and a real appetite statement, a working KRI set and a committee paper beats a candidate with three certifications and a maintained spreadsheet, and interviewers will tell you so.
- From audit: CIA plus CRMA, already strong. Add artefacts, not more letters.
- Banking and capital markets: FRM, or PRM. Two years of experience required before FRM certification.
- Technology, cyber and third-party risk: CRISC, three years of experience across two domains. CISA if you came from IT audit.
- Corporate and industrial ERM: RIMS-CRMP, built on ISO 31000. ARM or CPCU if the job carries the insurance programme.
- Insurance company risk: the actuarial route and CERA. There is no shortcut here.
- Low signal: generic ERM certificates with no experience requirement, GRC tool certificates listed without saying what you configured, and one-day framework awareness courses.
How hiring runs, and who is actually in the room
Enterprise risk hiring runs on referrals and networks more than on job boards, especially above analyst level. The reason is structural: the hiring manager is often a chief risk officer or a head of risk with one seat to fill and a low tolerance for a bad hire, because the person will be in front of an audit committee within two quarters. Postings exist, and many go through a recruiter screening for sector keywords rather than judgement. Expect the first filter to be crude.
Stage one is the recruiter screen, fifteen to thirty minutes, and it is pattern matching. They are checking sector, framework name, company scale, committee exposure and sometimes a credential. The way to pass is to open with the one-sentence version: the sector, the framework, the size of the enterprise you covered, the number of risk owners, the committee you reported to and the cadence. Vague seniority language fails here.
Stage two is the hiring manager, and this is the conversation that decides it. A CRO, head of risk, CFO or general counsel will spend most of the time on two things: how you think about a risk you have never seen before, and how you behave when the business disagrees with you. Framework knowledge is assumed and tested obliquely rather than quizzed.
Stage three is a panel, and this is the stage candidates misread. The panel usually contains first-line leaders: an operations director, a CIO or CISO, a treasurer, a head of HR, a plant or regional manager. They are not assessing your framework. They are assessing whether having you in the building makes their job easier or adds a meeting. Candidates who arrive in audit voice, talking about gaps and findings and non-compliance, lose this stage without knowing it happened. The move that works is to ask them what they already worry about, then describe how you would help them make a case for resources rather than how you would assess them.
Stage four is very often an exercise, and it is where the role differs most from an audit interview. The common formats are a presentation to a small panel on how you would stand up or improve the function, a critique of a real or sanitised risk register or heat map they hand you, a written appetite statement for one named risk, a case on a specific scenario such as the failure of a single-source supplier or a ransomware event at a key vendor, or a mock committee update under a strict time limit. Ask what format it is and ask who will be in the room, because a paper for a CRO and a paper for an audit committee chair are different documents.
Stage five, in larger or regulated organisations, is an executive or committee-facing conversation: a CFO, a general counsel, occasionally the chair of the audit or risk committee for a senior appointment. The question under this stage is whether you can be trusted in front of the board, which mostly means whether you can be brief, whether you flag bad news early, and whether you know the difference between informing a committee and asking it to decide.
Two patterns are worth naming. Internal moves are common and often faster: audit to risk inside the same company is a well-trodden path and the independence conversation is the main obstacle. And consulting hires get a specific challenge, because risk advisory work gives you exposure to many frameworks and rarely gives you a full cycle you owned through a committee. Name that gap yourself before the panel does, and say how you would close it in the first two quarters.
Timelines: four to eight weeks in a corporate, longer in a bank or insurer where screening and panel size extend it, and three months or more in public sector and university hiring that runs on fixed committee dates. Offers in this field often arrive with a title negotiation attached, because manager, senior manager and director mean different things in different buildings. Ask what the reporting line is, what the committee access is, and whether you have a standing agenda slot. Those three answers determine whether the job is doable.
- Recruiter screen: sector, framework, scale, committee cadence, credential. Open with the one-sentence version.
- Hiring manager, usually a CRO, head of risk, CFO or general counsel: judgement under ambiguity and behaviour under disagreement.
- Business panel of first-line leaders: are you useful or are you overhead. Do not arrive in audit voice.
- Exercise: a 180-day plan, a register or heat map critique, one appetite statement, a scenario case, or a mock committee update. Ask the format and the audience.
- Executive or committee-facing round for senior seats: brevity, early bad news, and knowing when you are informing versus asking for a decision.
- Negotiate reporting line, committee access and a standing agenda slot alongside pay. They decide whether the role can work.
How risk frameworks are actually tested in the interview
This is the part people prepare for wrongly. Candidates memorise the five components and twenty principles of COSO ERM 2017, or the principles, framework and process structure of ISO 31000:2018, and arrive ready to recite. Almost nobody is asked to recite. Interviewers hand you a messy situation and watch whether the framework shows up in how you organise the answer. It is tested as a habit of thought, not as a list.
Know the difference between the documents, because mixing them up is a tell. COSO ERM 2017, Integrating with Strategy and Performance, ties risk to strategy and performance and is the common reference in US corporates. It is not the same document as the COSO Internal Control Integrated Framework, the internal control framework used for financial reporting and SOX work, with its five components and seventeen principles. Candidates from audit confuse these two constantly, and the confusion reveals which world you came from. ISO 31000:2018 is the international risk management standard: process-oriented, guidance rather than requirements, and not certifiable for an organisation. Its companion catalogue of assessment techniques is published as IEC 31010, still widely cited as ISO 31010, and naming it is a clean answer when someone asks what method you would use. NIST CSF 2.0 is the cyber reference and notably added a Govern function alongside Identify, Protect, Detect, Respond and Recover. For AI, NIST AI RMF organises around Govern, Map, Measure and Manage, and ISO/IEC 42001 is the management system standard. In banks, add supervisory guidance on model risk management (SR 11-7, issued as OCC Bulletin 2011-12), the operational risk framework, and the interagency guidance on third-party relationships. In insurers, add the Own Risk and Solvency Assessment process under the NAIC model.
The highest-frequency framework question is some version of stand it up. You have 180 days, the board asked for ERM, nothing exists. The weak answer is the framework in order, starting with governance documents, or worse, selecting a GRC tool. The strong answer starts with reading what already exists, because every organisation already has risk information scattered across internal audit findings, incident and outage records, insurance claims and renewal submissions, legal matters and litigation reserves, quality and safety data, customer complaints, the 10-K risk factors and the last regulator or external auditor letter. You synthesise that first, interview twenty to thirty people second, produce a shortlist of ten to fifteen risks third, get named owners fourth, and only then build appetite, indicators and a reporting cadence. Tool selection comes last and often not at all in year one.
The second highest-frequency question is appetite, and it separates candidates fastest. Asked to write a risk appetite statement, most people produce an adjective: we have a low appetite for reputational risk. That is not a statement, it is a mood. A usable appetite statement names the risk, the measure, the appetite level, the tolerance at which it is breached, the escalation route and the owner. In shape: for unplanned unavailability of the customer-facing platform, we accept no more than a stated number of minutes per quarter, tolerance is breached at a higher stated number, a breach escalates to the operational risk committee within one business day, and the owner is the VP of engineering. Bring one real example in that shape, for a risk a company like theirs would actually carry. Very few candidates do.
The third is the heat map, and it is a trap with a correct answer. If you present a five by five likelihood and impact matrix as your proudest artefact and cannot critique it, you look junior. The critique is well established: Tony Cox's paper What's Wrong with Risk Matrices? in the journal Risk Analysis, and Douglas Hubbard's The Failure of Risk Management, are the two references to be able to name. The substance is that ordinal scores get treated as numbers and averaged, that two risks landing in the same cell can differ by orders of magnitude in expected loss, that no time horizon is specified so a once-a-decade event and a quarterly one share a cell, that the matrix hides the difference between inherent and residual exposure, and that it compresses the tail, which is where the risks that kill a company live. The right position in an interview is not that heat maps are useless. It is that a matrix is a communication device for a committee, and you back it with impact scales defined in currency and in non-financial units such as days of outage, injuries, records exposed or regulatory consequence, with frequency expressed as an annual probability or a return period, and with quantified work on the handful of risks that justify it.
Expect to be asked how you would quantify something. The credible answers are scenario-based estimation with explicit assumptions and ranges, calibrated estimates from named subject matter experts rather than a single point number, loss exceedance curves where you have enough data, Monte Carlo simulation for aggregation, and FAIR for cyber loss quantification. The credible admission is that quantification is expensive, so you do it for the top few risks and the ones with an insurance or capital decision attached, not for all 200 rows. A candidate who claims to have quantified everything is either exaggerating or was wasting money.
Expect an aggregation question, the hardest honest one in the discipline. How do you roll up to an enterprise view? The wrong answer is that you sum or average ratings, because ordinal ratings do not add. The right answer is that you aggregate along shared drivers and concentrations rather than along register rows: three separate risks that all depend on one cloud region, one contract manufacturer or one currency are one concentration, and you surface it as such. Then you aggregate financially only where you have distributions, and for everything else you aggregate by scenario, a single plausible event narrative that touches several risks at once.
Expect the three lines question, and know the vocabulary is current. The IIA updated its model and it is the Three Lines Model now, not the three lines of defence, and the shift is deliberate: less militaristic, and explicit that the governing body and management are part of the structure. The trap inside this question is ownership. If you say you own the risk register you have failed it. You steward the register and the process, the first line owns the risks and the controls, and the third line provides independent assurance over both, including over you. Being assessed by internal audit is part of the job, and saying so out loud reads as maturity.
Expect indicator questions. A key risk indicator is chosen because it moves before the risk event; a key performance indicator describes outcome performance. Most registers are full of lagging metrics mislabelled as KRIs. A good answer names a leading indicator with a data owner, a refresh frequency, a threshold and an agreed action when the threshold trips. If there is no action attached, it is a chart, not an indicator.
Expect at least one behavioural question that is really a framework question in disguise: tell me about a risk you escalated that the business did not want escalated, or tell me about a time you were wrong about a risk. Have both. The first needs to end with a specific escalation route used and a relationship that survived. The second is a credibility test, because a candidate who has never over-called a risk has either not been doing the job long or is not telling you the truth.
Sector-specific probes to prepare for. A bank will ask about the RCSA cycle and how you challenge a first-line self-assessment that is obviously too green, how operational risk loss events get captured and used, how issues and past-due actions get managed, and how appetite cascades into limits. An insurer will ask how the ORSA process connects to capital and to reinsurance decisions. A manufacturer will ask about single-source components, business interruption values and how you worked with the insurance broker. A technology company will ask about concentration on cloud and SaaS providers, resilience testing, and the vendor whose outage takes you down. Answer in their units.
The preparation nobody does. Read the employer's own public risk disclosures before you walk in. For a listed company that means Item 1A risk factors in the 10-K, the board risk oversight section of the proxy statement, the cybersecurity risk management and governance disclosure, and any recent 8-K about a material incident. For a bank, the Pillar 3 style disclosures and the risk factors. For an insurer, the public parts of the capital and risk filings. For a non-profit or university, the audited financials and the board committee charters. Then ask a question only a reader could ask: your risk factors name concentration with two contract manufacturers, and the proxy says the audit committee holds cyber oversight, so who is accountable for supplier concentration today? That is the question that makes a panel treat you as someone who read their business rather than someone bringing a process.
- Know the distinction: COSO ERM 2017 for enterprise risk and strategy, COSO Internal Control for financial reporting and SOX, ISO 31000 plus IEC 31010 for process and technique, NIST CSF 2.0 for cyber, NIST AI RMF and ISO/IEC 42001 for AI.
- Bring one real risk appetite statement with a measure, an appetite, a tolerance, an escalation route and an owner.
- Be able to critique a five by five matrix, name Cox and Hubbard, then say what you back it with.
- Have an aggregation answer built on shared drivers and concentrations, not on summing ordinal scores.
- Say three lines model, not three lines of defence, and never claim you own the risks.
- Distinguish a leading KRI with a threshold and an agreed action from a lagging chart.
- Read the employer's own risk disclosures and ask one question only a reader could ask.
The resume that gets read, and what gets ignored
The first two lines decide whether the rest is read, and they should establish scale, sector, framework and committee. In shape, with your own figures: enterprise risk for a 2.4 billion dollar revenue, 11,000 employee industrial manufacturer across nine countries; COSO ERM 2017; 14 named risk owners; quarterly reporting to the audit committee. Use the real numbers, because every one of them is a thing a panel can ask about and inflated scale falls apart in two questions.
Then lead with artefacts, because artefacts are the proxy for the licence that does not exist. Name the thing you built and the state it was in when you left. The risk taxonomy you wrote and how many categories it had. The appetite statement, and how many of its metrics had quantified tolerances rather than adjectives. The register, and whether you grew it or cut it. The indicator set, and how many had a named data owner. The scenario or stress test, and what the business did afterwards. The committee you stood up, its membership and its cadence. Each of those is a line, not a paragraph.
Write outcome lines, not activity lines, and the outcome is almost never a risk score. It is a decision. Dual-sourced a component after a concentration assessment. Raised a retained limit and reduced premium after cleaning five years of loss data. Reduced past-due audit actions by moving ownership from a central team to the function that could actually fix them. Cut a bloated register down to the risks that had named owners, and got the committee to agree the deletions. Stopped an AI deployment pending a documented human review step. Lines like these, with your own before and after numbers attached, are rare on risk resumes and they are the ones that get a call.
If you are coming from internal audit, the rewrite is the whole job. An audit resume says you tested controls, sampled populations, documented workpapers and raised findings. A risk resume has to say you formed a view where no control existed yet. Go through your audit history looking for engagements where you had to assess exposure before there was anything to test: the new product review, the acquisition integration, the new country entry, the vendor you flagged before anything went wrong, the control you recommended against building because the risk was within appetite. That last one is gold, because it demonstrates the thing audit does not train: proportionality.
If you are coming from operations, the rewrite runs the other way. You already have credibility with the first line and real decisions in your history, and what is missing is the vocabulary and the committee. Reframe what you did in risk terms, honestly: a capacity contingency plan is a tolerance and a mitigation, a supplier qualification programme is third-party risk management, a near-miss log is loss event data, a safety stand-down is an escalation. Then be explicit about the gap. You have not yet written for a board, and you are going to say so before they ask.
On tools, be specific and be honest. Name the platform and say what you did in it: configured a risk and control library in Archer, built RCSA workflows in AuditBoard, stood up a vendor risk intake in ServiceNow IRM or OneTrust, built reporting out of LogicGate, Resolver, MetricStream, Riskonnect, Origami Risk, Diligent or Workiva. If the truth is that your function ran on Excel and PowerPoint, say that, because it is true in a large share of mid-size companies and claiming a platform you only logged into is an easy thing to catch. Data skill is worth a line if it is real: SQL, Power BI or Tableau for indicator reporting, Python or R if you have actually built a simulation.
What gets ignored, and in some cases counts against you: a skills blob listing COSO, ISO 31000, NIST, SOX, GDPR and Basel with no evidence of having applied any of them; the word stakeholder more than twice; strong communicator and detail-oriented; a certification block at the top with no operating experience behind it; every training course you have attended; a six-line professional summary written in the third person; and a register row count presented as an achievement. Two pages for most people, three only at director level and above with genuinely distinct programmes to describe.
- Open with scale, sector, framework, number of risk owners and committee cadence, using real figures.
- Lead with artefacts: taxonomy, appetite statement, register, indicator set, scenario, committee.
- Make outcomes decisions, not scores. Dual-sourced, repriced, declined, stopped, cut.
- From audit: find the engagements where you assessed before there was a control to test, and the time you recommended not building a control.
- From operations: translate honestly into risk vocabulary, then name the board-writing gap yourself.
- Name GRC platforms with what you configured, or admit it was Excel. Do not list a tool you only read reports from.
Pay, the board calendar, hours and the ladder
Point yourself at sources rather than at a band, because enterprise risk pay varies more by sector and company size than by title. The BLS publishes no wage series for enterprise risk manager. The closest Occupational Employment and Wage Statistics codes are 13-2054 Financial Risk Specialists and 11-3031 Financial Managers for financial-sector risk roles, and 13-1041 Compliance Officers or 11-9199 Managers, All Other for corporate ERM, which is where a lot of these jobs actually get coded. Use those for a regional floor, then use live postings in states that require a pay range in the advert, including Colorado, California, Washington, New York and Illinois, and check whether your own state now requires one. RIMS publishes a compensation survey of the risk management profession, and for financial institutions the sector salary surveys are more useful than any general aggregator.
Three structural facts about the money. Bank and insurer second-line risk pays more than corporate ERM at the same nominal title, with a larger bonus component and a smaller individual mandate. Corporate ERM in a mid-size company pays less but hands you the whole function, which is the better experience if your target is a head of risk seat. And title inflation is severe: risk manager, senior risk manager, director of ERM and head of risk map to wildly different scopes across companies, so judge the role by reporting line, committee access and headcount, not by the word on the offer letter.
The hours are not shift work and they are not flat either. The board and committee calendar sets the rhythm: papers are due one to two weeks ahead of an audit or risk committee meeting, and those weeks are long. The annual cycle adds its own peaks, with the enterprise risk assessment refresh, the appetite review, the insurance renewal submission if you own it, and in regulated firms the examination cycle and whatever the regulator decided to focus on this year. Then there is the unplanned work: if your remit includes crisis management or business continuity, you are on the call tree, and a real incident takes over a month at no notice. In multi-site industrials, site assessments mean travel, and the honest way to size it is to ask how many sites are in scope and how often each gets visited.
The ladder, honestly. Risk analyst, senior risk analyst, risk manager or enterprise risk manager, senior manager or director of ERM, head of risk or VP risk, chief risk officer. The move that is hard is manager to director, because it requires owning a committee relationship rather than feeding one. The hardest is into a CRO seat, which in regulated firms is effectively a different job with regulatory expectations attached to the individual. In a mid-size corporate where ERM is one person, the ceiling is the CFO or general counsel you report to, and the way up is out: a bigger company, or a regulated firm where the second line is a real organisation.
The lateral moves are good and worth knowing about before you need them. Enterprise risk goes cleanly to chief audit executive, to chief compliance officer, to head of operational resilience or business continuity, to risk and insurance manager, and increasingly to AI governance lead, which several companies have carved out of ERM. It also goes to strategy and corporate development more often than people expect, because the scenario and concentration work is the same work with a different audience. What it does not usually lead to is a first-line operating role, because the function teaches you to assess rather than to run.
- Use BLS OES 13-2054 Financial Risk Specialists and 11-3031 Financial Managers, or 13-1041 and 11-9199 for corporate ERM, as a regional floor.
- Use pay-transparency postings in Colorado, California, Washington, New York and Illinois for live numbers, and check your own state.
- Bank and insurer second line pays more; corporate ERM gives you the whole function. Pick on purpose.
- The committee calendar sets the year. Papers due one to two weeks before each meeting.
- Crisis and continuity remits put you on a call tree. Ask whether that is in scope before you accept.
- Ladder: analyst, manager, director, head of risk, CRO. Laterals to chief audit executive, chief compliance officer, resilience, risk and insurance, AI governance.
Moving in from audit, compliance or operations: the next 90 days
The fastest route into enterprise risk is an internal move, and the second fastest is an external move by someone who built the artefacts before they needed them. Both are achievable in a quarter of deliberate effort, because the gap is almost never knowledge and almost always evidence.
Weeks one and two: find out who owns risk where you already work, and get a meeting. In most organisations this is a known person with an under-resourced process and a quarterly deadline they dread. Offer to help with the thing they are behind on. Volunteering to facilitate two risk workshops, clean a register or build a reporting pack is the cheapest way into the function, and it is how a large share of these moves actually happen. If your employer has no ERM function, the route in is the audit committee materials and the insurance renewal, both of which someone is doing badly.
Weeks three to six: build the two artefacts you cannot interview without. The first is one real appetite statement, in full, for a risk at your own employer, with a measure, an appetite level, a tolerance, an escalation route and a named owner. Get a real owner to look at it, because the useful part is the argument you have about the threshold. The second is a scenario write-up: pick a plausible event, a single-source supplier failing, a key vendor suffering a ransomware event, a licence suspension, a funding facility closing, and write two pages on the mechanism, the exposure with explicit assumptions and ranges, the existing mitigations and the three things you would do now. That document is what you take to interviews.
Weeks three to six, in parallel: learn your target sector's vocabulary properly rather than at awareness level. If it is banking, you need to talk fluently about the RCSA cycle, loss event capture, issue and action management, appetite cascaded into limits, and the examination cycle. If it is insurance, the ORSA process and how it touches capital. If it is technology, resilience testing and third-party concentration. Use the sources that cost nothing: NIST CSF 2.0 and NIST AI RMF are free downloads, supervisory and interagency guidance is free, and 10-K risk factors are free. The COSO and ISO documents are paid, though their executive summaries are public and your employer may already hold a licence. Three 10-K risk factor sections read closely teach more than most courses.
Weeks six to ten: fix the AI gap, because it is now in the job description and most candidates from audit and operations have nothing to say about it. Build a small AI use case inventory for your own team or function: what tools are in use, approved or not, what data goes into them, what decision they influence, who reviews the output. Write a one-page tiering rubric, read NIST AI RMF, and form a view on the shadow AI problem. This is the single most differentiating preparation available in 2026-27, because the work is new enough that nobody has ten years of it.
Weeks eight to twelve: apply with a rewritten resume and go where risk people actually are. RIMS chapters for corporate and insurance risk, IIA chapters if you are coming from audit, ISACA for technology risk, PRMIA and GARP chapters for financial services, and the regional risk roundtables most large cities have. The hiring is relationship-driven, and a chapter meeting is a cheaper introduction to a hiring manager than two hundred applications. Ask the people you meet what their register looks like and what their worst reporting problem is. Those conversations become your interview answers.
Two things to do in every interview you get, regardless of preparation. Read the employer's risk disclosures first and ask a question only a reader could ask. And ask them what triggered the role, who sponsors it, what the escalation route is when the business disagrees, and whether the function has a standing committee slot. Those answers tell you whether the job is the one you want, and asking them is itself evidence that you understand what makes an enterprise risk manager effective rather than merely employed.
- Weeks 1-2: find whoever owns risk where you work and volunteer for the thing they are behind on.
- Weeks 3-6: write one complete appetite statement with a tolerance and an owner, and one two-page scenario write-up with explicit assumptions.
- Weeks 3-6: learn the target sector's vocabulary from primary sources, including three 10-K risk factor sections.
- Weeks 6-10: build an AI use case inventory and a one-page tiering rubric, and form a view on shadow AI.
- Weeks 8-12: rewrite the resume around artefacts and decisions, and work RIMS, IIA, ISACA, PRMIA and GARP chapters.
- Every interview: read their disclosures, ask one question only a reader could ask, and diligence the mandate.
What an enterprise risk manager needs to know about AI in 2026-27
Start with the honest calibration, because this is a role where overclaiming is punished. Enterprise risk management has not been automated and is not close to it, for a structural reason: the output of the job is an accountable judgement. A model cannot be the person a board committee questions, cannot accept ownership of a risk, cannot say no to a business leader with a revenue target, and cannot carry the relationship that makes someone tell you about a problem early. What AI has done to this function is add work, not remove it. Treat anyone selling you the automated risk function with the same scepticism you would bring to any vendor claim.
What has genuinely changed, and it is the biggest change to this role in a decade, is that AI governance has landed on or next to the enterprise risk function. In many organisations ERM owns it; in others it sits with legal, privacy, security or a dedicated AI governance lead and ERM co-owns the risk view. Either way it now appears in enterprise risk manager job descriptions and in the interview, so ask where it sits in their building and have something to say about it. If you have nothing, you are competing against people who do.
Know the reference frameworks by name and by structure. The NIST AI Risk Management Framework organises around four functions, Govern, Map, Measure and Manage, and is the common US reference because it is voluntary, free and maps onto the way risk functions already work. ISO/IEC 42001 is the AI management system standard and the certifiable one, which matters if your employer sells to customers who ask for certification. In financial institutions the live argument is whether AI sits inside existing model risk management under the supervisory guidance on models or beside it: most banks extended their model risk programme to cover machine learning models and added a separate layer for generative uses that are not models in the traditional validation sense. In insurance, regulators have issued a model bulletin on insurers' use of AI systems that states have been adopting individually, so the applicable position depends on which states you write business in. Having a view on the banking question, with a reason, is a strong interview answer.
On the EU AI Act, be careful, and that care is itself a differentiator. The obligations are real: prohibited practices, transparency requirements, obligations on general purpose models, and for high-risk systems a set of requirements covering governance of training and validation data, technical documentation, logging, human oversight and conformity assessment. The timetable is what you must not state with confidence. Phase-in dates have been amended since the regulation was adopted and simplification proposals have been in play. The right answer in an interview is to describe which obligations attach to which use case, say that the applicable dates need checking against the current text with counsel, and move on. A candidate who confidently quotes a date that has since moved does real damage, because the executive who repeats it is wrong in front of a regulator. The same caution applies to US state AI and automated-decision laws, which have been arriving and being amended at speed, and to climate and sustainability disclosure rules, where both the US and EU positions have shifted. Name the obligation, name the authority, and check the status.
The practical work that has landed on the function, and that you should be able to describe in operational detail. An AI use case inventory, which is harder than it sounds because much of it is shadow usage nobody declared. An intake and approval gate with a tiering rubric, usually three or four tiers from prohibited through high risk to low risk, with control requirements scaling by tier. Documentation standards: purpose, data sources, known limitations, evaluation results, human review point, rollback plan. Monitoring after deployment, for drift, for output quality and for usage outside the approved purpose. And the one that consumes the most time in practice: third-party AI, because existing vendors have added AI features to products bought years ago, which means re-assessing and re-papering a vendor estate rather than just assessing new purchases. The questions are whether your data trains their model, which subprocessors are involved, what happens to output you rely on, and whether a contract signed before any of this existed says anything useful.
Shadow AI is the problem every interviewer has right now, so have an answer. The useful one is not a ban, because bans move usage to personal devices where you can see nothing. It is a short approved list, a genuinely fast intake path for anything else, visibility through whatever network and SaaS discovery the company already has, and a published rule about what categories of data may never be pasted anywhere. Then the risk statement is about the data and the decision, not about the tool, which is the framing that survives the next tool arriving.
AI inside the risk function itself is real, and being specific about it is how you show you are current. The work that compresses is text work: extracting obligations from a regulation or a contract, crosswalking one framework to another, summarising incident reports and audit findings into draft register entries, parsing vendor assurance reports, horizon scanning across news and filings, and drafting the first version of a committee paper. What does not compress is anything requiring accountability or a relationship: the rating, the appetite conversation, the escalation against someone's incentives, and the judgement about which of three plausible readings of an ambiguous situation to act on. Be equally specific about the GRC vendors, because the pitch is usually AI-powered risk identification and what is delivered is mapping and summarisation. Useful, worth paying for, not a substitute for an owner.
There is a specific new failure mode hiring managers have started probing, and it matters because it affects the craft of the job. A language model will cheerfully produce a complete, plausible, well-formatted risk register for any organisation, and it will be generic. The pre-existing weakness of this discipline was registers full of plausible-sounding risks that nobody owns and nothing happens to, and generated content makes producing those nearly free. So the question has become how you tell a real risk from a plausible-sounding one. The answer has a shape: a real risk has a named owner who agrees it is theirs, a mechanism you can describe from cause to event to consequence in the organisation's own operational terms, evidence it has happened here or somewhere comparable, and an indicator that would move. A generated risk has none of those and can be deleted. Say that, and you sound like someone who has maintained a register.
Quantifying AI risk deserves a plain statement: it is immature. There is no defensible loss distribution for most AI failure modes, and anyone presenting a precise probability for a model producing a harmful output is fabricating. The defensible method is scenario-based with explicit assumptions, ranges rather than points, and a clear statement of what you do not know, borrowing the discipline of FAIR for the cases where the loss is a privacy, legal, remediation or business interruption loss you can bound. Saying this in an interview is stronger than producing a number, because the person opposite has almost certainly seen a vendor produce a number and has already stopped believing it.
Finally, what to bring. The artefacts that differentiate an enterprise risk manager in 2026-27 are an AI use case inventory you built, a tiering rubric with control requirements written out per tier, a monitoring metric you defined and the threshold you set, a crosswalk you own between NIST AI RMF, ISO/IEC 42001 and internal policy, and best of all a decision: a use case you declined or constrained, and the reasoning that held up when the business pushed back. That last one is worth more than any certificate in this area, because it is the only one that proves you can do the job rather than document it.
NIST AI RMF and ISO/IEC 42001 fluency
AI governance now sits in or beside enterprise risk in a large share of organisations, and these two documents are the common reference points. NIST AI RMF gives you the Govern, Map, Measure, Manage structure that slots into an existing ERM process, and ISO/IEC 42001 is the certifiable management system standard your customers may start asking about.
Show it: Bring a one-page crosswalk you built between NIST AI RMF functions, ISO/IEC 42001 clauses and your own internal policy or control set, and be able to say which clause forced a real control to change.
AI use case inventory and tiering
You cannot govern what you cannot list, and much of the AI use in an organisation was never declared. The inventory plus a tiering rubric is the foundational artefact of AI governance, and it is the first thing a CRO will ask whether you have built.
Show it: Show an inventory with the fields that matter: purpose, data sources, whether personal or regulated data is involved, the decision it influences, the human review point, the owner, the tier. Then show the rubric that assigns the tier and the control requirements that attach to each one.
Third-party AI reassessment
Much of the AI exposure in a typical company arrives through vendors that were already under contract, not through new purchases. Re-assessing and re-papering an existing vendor estate is the largest piece of practical AI work in the function, and it is where interagency third-party risk expectations bite.
Show it: Describe a vendor review you ran on an existing supplier that added AI features: the questions you asked about training on your data, subprocessors and output reliance, what the contract did not cover, and what the remediation or contractual change was.
Telling a real risk from a generated one
Generated content makes producing a plausible risk register almost free, which worsens the discipline's oldest failure: rows nobody owns. Hiring managers have started testing for this directly, because they are receiving generated material.
Show it: Give the four-part test out loud: a named owner who agrees, a mechanism described in the organisation's own operational terms, evidence from here or a comparable place, and an indicator that would move. Then describe a register you cut and the criteria you cut it on.
Honest regulatory positioning on AI
AI regulatory timetables have been amended since adoption and are still contested, so confident dates are a liability. An enterprise risk manager who names the obligation, flags the date as needing verification with counsel, and separates what is law from what is guidance, is more useful than one who sounds certain.
Show it: Answer an EU AI Act question by describing which obligations attach to a specific use case, then saying explicitly that applicable dates need checking against the current text. Do the same for US state AI laws and for climate and sustainability disclosure, where positions have shifted on both sides of the Atlantic.
Scenario-based quantification under uncertainty
AI risk has no credible loss distribution yet, and the pressure to produce a number is high. The defensible method is scenario estimation with explicit assumptions and ranges, bounded by the loss types you can actually size: privacy, legal, business interruption, remediation cost.
Show it: Walk through one AI failure scenario end to end: the mechanism, the population affected, the assumption you made and why, the range rather than the point, and what you told the committee you did not know.
Using AI on the risk function's own workload
The text-heavy parts of enterprise risk (framework crosswalks, obligation extraction, incident summarisation, first-draft register entries, horizon scanning, vendor report parsing) take a fraction of the time they did. A candidate who has done this credibly covers more ground than one who has not, and it is a reasonable thing for a CRO to ask about.
Show it: Name a specific task you compressed, say what you checked before your name went on the output, and say what you deliberately did not delegate. The verification step is the part the interviewer is listening for.
Shadow AI handling that is not a ban
Every organisation has unapproved AI usage, and prohibition moves it onto personal devices where the risk function has no visibility at all. A workable answer trades a small amount of control for a large amount of visibility.
Show it: Describe the four parts: a short approved list, a genuinely fast intake for anything else, discovery through existing network and SaaS tooling, and a published rule about data categories that may never leave. Then frame the risk statement around the data and the decision rather than the tool.
What a screen is looking for
These are the terms that a resume screen, human or automated, is matching against for this role. Use the ones that are true of you, in the words the posting uses.
- enterprise risk manager
- enterprise risk management
- ERM framework
- COSO ERM 2017
- COSO internal control framework
- ISO 31000
- risk appetite statement
- risk tolerance
- risk register
- risk taxonomy
- risk and control self-assessment
- RCSA
- key risk indicators
- KRI
- scenario analysis
- stress testing
- reverse stress testing
- three lines model
- second line of defense
- risk governance
- operational risk
- emerging risk
- risk quantification
- FAIR cyber risk quantification
- Monte Carlo simulation
- loss exceedance
- GRC
- Archer
- AuditBoard
- LogicGate
- ServiceNow IRM
- MetricStream
- Resolver
- Riskonnect
- OneTrust
- model risk management
- third-party risk management
- vendor risk assessment
- business continuity
- operational resilience
- crisis management
- NIST CSF 2.0
- NIST AI RMF
- ISO/IEC 42001
- AI governance
- AI risk management
- ORSA
- ICAAP
- Basel operational risk
- internal audit
- SOX
- audit committee reporting
- board risk reporting
- risk committee
- risk owner
- issue and action management
- CIA
- CRMA
- FRM
- PRM
- CRISC
- RIMS-CRMP
- CERA
- ARM
- total cost of risk
- insurance program
Mistakes that cost people this job
Saying you own the risk register, or worse, that you own the risks.
Say you steward the process and the register, and that the first line owns the risks and the controls. It is a one-sentence difference and interviewers treat it as a direct signal of whether you have worked in a mature second line. Add that internal audit provides independent assurance over your programme too, and that you expect to be assessed.
Answering "how would you stand up ERM here" with the framework in order, or with a GRC tool selection.
Start with what already exists. Audit findings, incident and outage records, insurance claims and renewal submissions, legal matters, quality and safety data, complaints, the 10-K risk factors, the last regulator or auditor letter. Synthesise that, interview twenty to thirty people, produce a shortlist of ten to fifteen risks with named owners, then build appetite, indicators and cadence. Tool selection comes last and often not in year one.
Offering a risk appetite statement that is an adjective. "We have a low appetite for reputational risk."
Bring one complete statement: the risk, the measure, the appetite level, the tolerance at which it is breached, the escalation route and timeframe, and the named owner. Have it ready for a risk that a company like theirs would actually carry. This single artefact separates candidates faster than anything else in the interview.
Presenting a five by five heat map as the centrepiece artefact with no critique of it.
Treat the matrix as a communication device for a committee and say what you back it with: impact scales defined in currency and in non-financial units, frequency as an annual probability or return period, inherent and residual stated separately, and quantified work on the few risks that justify it. Be able to name Cox's "What's Wrong with Risk Matrices?" and Hubbard's critique.
Arriving in audit voice in front of the business panel: gaps, findings, non-compliance, testing.
Ask the operations director, CIO or treasurer what already worries them, then describe how you would help them make a case for resources or a decision. The first-line panel is deciding whether you reduce their work or add a meeting, and audit vocabulary answers that question the wrong way.
Confusing COSO ERM 2017 with the COSO Internal Control Integrated Framework.
Keep them separate out loud. COSO ERM 2017 integrates risk with strategy and performance. COSO Internal Control is the internal control framework used for financial reporting and SOX. Using the wrong one tells an interviewer which world you came from and that you have not read the one you need.
Quoting a regulatory date with confidence. An EU AI Act phase-in, a state AI law effective date, a climate disclosure deadline.
Name the obligation and the authority without the date, or name the date and say it needs checking against the current text with counsel. Timetables in this area have been amended after adoption. A candidate who gives an executive a wrong date causes real damage, and the caution reads as senior rather than evasive.
Treating a 400-row register as evidence of thoroughness.
Lead with the cut. Say you reduced the register to the risks that had named owners, a describable mechanism and an indicator that would move, and that you got the committee to agree the deletions. Volume is the easiest thing in this job to produce and the clearest sign nobody is using the output.
Having no example of a decision that changed because of risk work.
Prepare three: a dual-sourcing or contingency decision, an insurance or capital decision informed by better loss data, and a project, vendor or AI use case you declined or constrained. Each needs the before state, what you did, and what the business did differently. Reporting with no decision attached is the failure mode of this whole profession and interviewers know it.
Sending the same application to a bank second-line role and a corporate ERM role.
Rewrite for the vocabulary. Banks want RCSA, loss event data, issue and past-due action management, appetite cascaded into limits, model risk and the examination cycle. Corporates want top risks to strategy, appetite for the board, total cost of risk, business interruption values and supplier concentration. These are different jobs hired by different people.
Having nothing to say about AI governance.
Bring an AI use case inventory, a tiering rubric with control requirements per tier, and one decision where you declined or constrained a use case. AI governance has moved into enterprise risk job descriptions, and the candidates you are competing with have built these. If you have not, build a small version for your own team before you interview.
Walking in without having read the employer's own risk disclosures.
Read Item 1A risk factors in the 10-K, the board risk oversight section of the proxy, and any recent incident disclosure. Then ask one question only a reader could ask, such as who is accountable today for the supplier concentration their own risk factors name. It takes an hour and almost no candidate does it.
Questions people ask
Do I need a certification to become an enterprise risk manager?
No certification is required to work as an enterprise risk manager, because no US state licenses the role and there is no mandatory exam. What substitutes is evidence of a complete risk cycle: a taxonomy you built, a measurable appetite statement, a register you reduced, an indicator set with named data owners, a scenario you ran and a committee paper you authored. Credentials help a resume get read, and the useful one depends on sector: FRM or PRM in banking, CRISC in technology risk, RIMS-CRMP in corporate and industrial ERM, CERA in insurance, and CIA plus CRMA if you came from internal audit. The order that works is a risk-adjacent seat first, then the exam your employer funds, then the missing artefact.
How do I move from internal audit into enterprise risk?
Moving from internal audit into an enterprise risk manager role is the most common path in the profession, and the obstacle is rarely knowledge. It is that an audit history reads as testing controls that already exist, while enterprise risk requires forming a view where no control exists yet. Go back through your engagements for the ones where you assessed exposure before there was anything to test: a new product review, an acquisition integration, a country entry, a vendor you flagged early, or a control you recommended against building because the risk sat inside appetite. Rewrite those as risk work, add one real appetite statement and one scenario write-up, and expect a conversation about independence and cooling off if the move is internal at the same employer.
What interview questions does an enterprise risk manager get asked?
An enterprise risk manager is almost never asked to recite COSO ERM 2017's components or the structure of ISO 31000. Interviewers hand over a messy situation and watch whether the framework shows up in how the answer is organised. The recurring questions are: how would you stand up the function in 180 days, write one risk appetite statement with a measurable tolerance, critique this heat map, how would you aggregate to an enterprise view, what is the difference between a KRI and a KPI, how would you govern an AI use case, and tell me about a risk you escalated when the business did not want it escalated. Framework knowledge is assumed. What is graded is whether you use it to reach a decision or only to produce a document.
What should an enterprise risk manager say about heat maps and 5x5 risk matrices?
An enterprise risk manager should treat the five by five matrix as a communication device for a committee and never as the analysis. The critique to be able to give is that ordinal scores get averaged as if they were numbers, that two risks in the same cell can differ by orders of magnitude in expected loss, that no time horizon is specified, that inherent and residual exposure get blurred, and that the tail is compressed exactly where the company-ending risks live. Tony Cox's paper "What's Wrong with Risk Matrices?" and Douglas Hubbard's "The Failure of Risk Management" are the references to name. Then say what you back the matrix with: impact scales in currency and in non-financial units, frequency as an annual probability or return period, and quantified analysis for the handful of risks that justify the cost.
What does an enterprise risk manager resume need that an audit resume does not?
An enterprise risk manager resume needs scale, framework and committee in the first two lines, then artefacts rather than activities. Give the revenue and headcount of the enterprise covered, the framework used, the number of named risk owners and the reporting cadence to the audit or risk committee. Then name the taxonomy, the appetite statement and how many of its metrics had quantified tolerances, the register and whether you grew it or cut it, the indicator set, and the scenario you ran. Outcome lines should be decisions rather than scores: dual-sourced a component after a concentration assessment, repriced an insurance programme after cleaning loss data, cut the register to the risks that had named owners and got the committee to agree the deletions, stopped an AI deployment pending a documented human review step.
How much does an enterprise risk manager earn?
There is no reliable single band for an enterprise risk manager, and the honest move is to point at sources rather than quote a number. The BLS publishes no wage series for the title; the closest Occupational Employment and Wage Statistics codes are 13-2054 Financial Risk Specialists and 11-3031 Financial Managers for financial-sector roles, and 13-1041 Compliance Officers or 11-9199 Managers, All Other for corporate ERM. For live figures use postings in states that require a pay range in the advert, including Colorado, California, Washington, New York and Illinois, and check whether your own state now does. Two structural facts: bank and insurer second-line risk pays more than corporate ERM at the same nominal title, and the titles are inflated, so judge scope by reporting line and committee access rather than by the word on the offer.
Is AI replacing enterprise risk managers?
No, and an enterprise risk manager should be able to say why precisely rather than defensively: the output of the job is an accountable judgement, and a model cannot be the person a board committee questions, cannot accept ownership of a risk, and cannot say no to a leader with a revenue target. AI has added work to the function rather than removed it, because AI governance landed there. What has compressed is the text work: framework crosswalks, obligation extraction from regulation and contracts, incident summarisation, draft register entries, horizon scanning and vendor report parsing. The new risk to the profession is the opposite of automation, namely generated registers full of plausible risks nobody owns, which is why interviewers now ask how you tell a real risk from a plausible-sounding one.
What AI knowledge does an enterprise risk manager need in 2026-27?
An enterprise risk manager now needs working AI governance capability, because it appears in the job description and in the interview. Know the NIST AI Risk Management Framework by its Govern, Map, Measure and Manage structure, know that ISO/IEC 42001 is the certifiable AI management system standard, and in financial institutions have a view on whether AI sits inside existing model risk management or beside it. Be able to describe a use case inventory, a tiering rubric with control requirements per tier, post-deployment monitoring, and the third-party problem where existing vendors added AI to products already under contract. Do not quote AI regulation dates with confidence, because phase-in timetables have been amended since adoption and US state laws keep arriving: name the obligation and say the date needs checking with counsel.
Can I become an enterprise risk manager without working in financial services?
Yes. Enterprise risk manager roles exist across manufacturing, energy, healthcare, retail, technology, higher education, non-profits and government, and the non-financial versions are often a one-person or two-person function reporting to the CFO or general counsel with the whole programme in scope. The frameworks are the same, usually COSO ERM 2017 or ISO 31000, but the register contents are nothing like a bank's: supplier concentration, business interruption values, safety, capital projects, cyber and third-party dependency, talent and key person exposure. The trade is real, because corporate ERM typically pays less than bank or insurer second-line risk at the same nominal title and gives far broader ownership, which is better preparation for a head of risk seat.
What is the single best piece of preparation before an enterprise risk manager interview?
For an enterprise risk manager interview, read the employer's own public risk disclosures and arrive with a question only a reader could ask. For a listed company that means Item 1A risk factors in the 10-K, the board risk oversight section of the proxy statement, the cybersecurity risk management and governance disclosure and any recent material incident filing; for a bank or insurer, the public capital and risk filings; for a university or non-profit, the audited financials and the committee charters. Then ask something specific, such as who is accountable today for the supplier concentration their own risk factors name. It takes about an hour, it proves you treat risk as specific to that organisation rather than as a process you brought with you, and almost no candidate does it.
Put this on a resume in about a minute
Paste your history once and point it at the Enterprise Risk Manager posting you are looking at. No account, no card.
Build my resume free More roles