Summary The board risk committee's effectiveness depends on the quality of the questions its directors ask. This article sets out a working set of questions non-executive directors should ask the CRO across framework health, appetite adherence, emerging risk and cultural signals — questions that surface substance rather than reassurance.
Framework health Where is the framework weakest, and what is the plan? Which controls have never been tested? Where are we relying on manual controls that should be automated? Which risks are owned in name only?
Appetite adherence Which appetite metrics are closest to threshold, and what would trigger a breach? Where have we recalibrated appetite in the last year, and why? Which appetite statements do we not know how to measure?
Emerging risk What is on the horizon that could invalidate our current assumptions? What are we watching that we cannot yet quantify? Which of last year's emerging risks have crystallised, and what did we learn?
Cultural signals Where are people reluctant to escalate? What are near-miss and complaint patterns telling us? Where does the risk MI conflict with the anecdotal picture?
Governance and independence Which decisions this year did the CRO oppose or qualify? Where did the executive proceed nonetheless, and with what documented rationale? Is the risk function resourced to do independent work, or is it dependent on the first line?
Regulatory relationship What has the supervisor told us informally? Where are we in disagreement with the supervisor? What themes are they raising across peers?
CRO and board implications The CRO should welcome these questions, not deflect them. A CRO who cannot answer them substantively is a CRO whose function needs investment or whose role is being underutilised.
Practical implementation Standing question set for each committee cycle; rotating deep-dives on specific themes; executive session between the committee and the CRO with no executive management present; annual effectiveness review of the committee itself.
Limitations No question list guarantees good oversight. It supports directors who are prepared to challenge; it does not substitute for that preparedness.
Related reading See [Corporate Governance](/expertise/corporate-governance), [Governance](/governance) and [Effective CRO operating model](/insights/effective-cro-operating-model).
Frequently asked questions
What should risk leaders know about framework health?
Where is the framework weakest, and what is the plan? Which controls have never been tested? Where are we relying on manual controls that should be automated? Which risks are owned in name only?
What should risk leaders know about appetite adherence?
Which appetite metrics are closest to threshold, and what would trigger a breach? Where have we recalibrated appetite in the last year, and why? Which appetite statements do we not know how to measure?
What should risk leaders know about emerging risk?
What is on the horizon that could invalidate our current assumptions? What are we watching that we cannot yet quantify? Which of last year's emerging risks have crystallised, and what did we learn?
What should risk leaders know about cultural signals?
Where are people reluctant to escalate? What are near-miss and complaint patterns telling us? Where does the risk MI conflict with the anecdotal picture?
What should risk leaders know about governance and independence?
Which decisions this year did the CRO oppose or qualify? Where did the executive proceed nonetheless, and with what documented rationale? Is the risk function resourced to do independent work, or is it dependent on the first line?