Banking Risk

CRO priorities for banks: capital, liquidity, conduct and operational resilience

How a bank Chief Risk Officer should sequence capital, liquidity, conduct and operational resilience priorities across a single, coherent risk agenda.

By Jonas Osman AbdelfourPublished June 24, 2026

Summary The bank Chief Risk Officer sits at the intersection of prudential supervision, board oversight and day-to-day business decisions. The priorities that define the role are neither optional nor infinitely expandable: capital adequacy, liquidity resilience, conduct and financial crime, and operational resilience have to co-exist inside one operating rhythm. This article sets out how a CRO can sequence and integrate them without letting any single dimension dominate the agenda.

The four load-bearing priorities Capital is the primary constraint on strategy. Everything the bank underwrites, holds or promises consumes capital, and every capital decision is a statement about risk appetite. Liquidity is the primary constraint on survival. A solvent bank without funding is still a failed bank. Conduct — including financial crime — is the primary constraint on the licence to operate; a bank that fails its customers or its regulator on conduct forfeits the trust its business model depends on. Operational resilience is the newest formalised priority but the oldest lived reality: whether critical services keep running through disruption, cyber events and third-party failures.

Sequencing through the year A CRO agenda that treats these as competing bids for attention will lurch between them. A more disciplined pattern anchors each to a supervisory and internal cycle. ICAAP and the annual capital plan set the capital narrative. ILAAP, the funding plan and the contingency funding playbook set the liquidity narrative. The financial crime EWRA, conduct MI and complaints analysis set the conduct narrative. The operational resilience self-assessment, important business services mapping and severe-but-plausible scenario testing set the resilience narrative. When these cycles are timetabled coherently, the CRO office moves from reactive to deliberate.

The single integrated view The board is not helped by four separate stories. A credible CRO produces one integrated view that shows how the four priorities interact: how a downturn in credit affects capital headroom and liquidity outflows simultaneously; how a conduct issue drives operational cost and capital add-ons; how a third-party outage cascades into liquidity, customer harm and regulatory attention. The taxonomy, appetite metrics and reporting templates should support this integration rather than fragment it.

Second-line design that supports the agenda The second-line function has to be structured to deliver on all four priorities without being spread so thinly that none receive genuine oversight. That usually means a small number of deep specialisms (credit, treasury, financial crime, operational risk, model risk) supported by a horizontal framework, appetite and reporting team, with clear rules on which decisions require second-line challenge and which are informed only.

CRO and board implications Boards should expect the CRO to hold a defensible view on each priority individually, and on their interaction. Where the CRO cannot do so — because information is missing, models are stale or ownership is unclear — that itself is the issue to report, not a gap to conceal. A CRO who over-claims certainty is a CRO who will eventually be surprised.

Practical implementation Sequenced planning of ICAAP, ILAAP, EWRA and resilience cycles across the calendar; consolidated appetite dashboard that displays capital, liquidity, conduct and resilience metrics side-by-side; explicit escalation triggers where a movement in one dimension changes the risk profile of another; annual joint session with executive management on the integrated view.

Limitations No article can specify the correct capital, liquidity, conduct or resilience level for a specific institution — those are supervisory and board-level judgements calibrated to business model, complexity and jurisdiction. Legal and regulatory interpretations should be confirmed with qualified counsel.

Related reading See [Banking Risk](/expertise/banking-risk), [Enterprise Risk](/expertise/enterprise-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and [AML and Financial Crime](/expertise/aml). For the background of the practice, see [About](/about) and [Qualifications](/qualifications).

Frequently asked questions

What should risk leaders know about the four load-bearing priorities?

Capital is the primary constraint on strategy. Everything the bank underwrites, holds or promises consumes capital, and every capital decision is a statement about risk appetite. Liquidity is the primary constraint on survival. A solvent bank without funding is still a failed bank. Conduct — including financial crime — is the primary constraint on the licence to operate; a bank that fails its customers or its regulator on conduct forfeits the trust its business model depends on. Operational r...

What should risk leaders know about sequencing through the year?

A CRO agenda that treats these as competing bids for attention will lurch between them. A more disciplined pattern anchors each to a supervisory and internal cycle. ICAAP and the annual capital plan set the capital narrative. ILAAP, the funding plan and the contingency funding playbook set the liquidity narrative. The financial crime EWRA, conduct MI and complaints analysis set the conduct narrative. The operational resilience self-assessment, important business services mapping and severe-bu...

What should risk leaders know about the single integrated view?

The board is not helped by four separate stories. A credible CRO produces one integrated view that shows how the four priorities interact: how a downturn in credit affects capital headroom and liquidity outflows simultaneously; how a conduct issue drives operational cost and capital add-ons; how a third-party outage cascades into liquidity, customer harm and regulatory attention. The taxonomy, appetite metrics and reporting templates should support this integration rather than fragment it.

What should risk leaders know about second-line design that supports the agenda?

The second-line function has to be structured to deliver on all four priorities without being spread so thinly that none receive genuine oversight. That usually means a small number of deep specialisms (credit, treasury, financial crime, operational risk, model risk) supported by a horizontal framework, appetite and reporting team, with clear rules on which decisions require second-line challenge and which are informed only.

What should risk leaders know about cRO and board implications?

Boards should expect the CRO to hold a defensible view on each priority individually, and on their interaction. Where the CRO cannot do so — because information is missing, models are stale or ownership is unclear — that itself is the issue to report, not a gap to conceal. A CRO who over-claims certainty is a CRO who will eventually be surprised.