CRO vs CCO: How the Two Functions Differ at FCA Firms

CRO vs CCO: How the Two Functions Differ at FCA Firms

CRO vs CCO: How the Two Functions Differ at FCA Firms

The Chief Risk Officer and the Chief Compliance Officer are often confused, sometimes combined, and frequently misunderstood — including by firms hiring for them. Both are second-line functions, both are senior, and at FCA-regulated firms both are typically controlled functions: the CRO usually holds SMF4 and the CCO holds SMF16. This article sets out how the two genuinely differ, where they overlap, and how they should work together.

The core distinction

The cleanest way to state the difference is by what each function is accountable for. The Chief Risk Officer owns the firm’s risk framework — identifying, measuring, monitoring and overseeing the full range of risks the firm faces, from credit and market risk to operational, technology and third-party risk. The Chief Compliance Officer owns the firm’s compliance with the regulatory system — making sure the firm meets its obligations under the rules that apply to it, advising the business, and overseeing the compliance framework.

Put simply: the CRO asks ‘what could harm the firm, and are we managing it?’; the CCO asks ‘are we complying with our regulatory obligations?’ Regulatory risk is one of the risks the CRO oversees, which is where the two most obviously connect — but they are distinct lenses on the firm.

How the SMF roles map

Under SM&CR the mapping is usually clear. SMF4, the Chief Risk function, is held by the senior individual responsible for the risk function — setting and overseeing risk exposures and reporting to the governing body on risk. SMF16, the Compliance Oversight function, is held by the individual responsible for the firm’s compliance with the regulatory system. Each carries its own Statement of Responsibilities, and each holder is personally accountable for their area under the Duty of Responsibility.

Both are second-line functions, distinct from the first line that owns risk day to day and from the third-line internal audit function that assures the board both are working.

Where they overlap

The overlap is real and needs managing. Regulatory and conduct risk sit in both worlds: they are risks to the firm (CRO territory) and they concern compliance with obligations (CCO territory). Operational resilience touches both. Financial crime risk is overseen within the risk framework but has its own accountable owner in the MLRO. The Consumer Duty’s outcomes focus draws compliance into territory that looks a lot like risk management.

Where the two functions are not clear about their respective ownership of these shared areas, things fall between them — which is exactly the gap a supervisor probes. Good firms set the boundary explicitly rather than leaving it to be worked out case by case.

Should the roles ever be combined?

At smaller firms the risk and compliance functions are sometimes held by the same person, or the roles sit close together with shared resource. This can work where the firm’s scale genuinely does not justify two senior functions — but it carries a tension. A combined holder is, in effect, both setting parts of the control framework and overseeing compliance with it, which compresses the independent perspectives the two functions are meant to provide. As a firm grows, separating them is usually one of the governance maturity steps, and the point at which to do so is a judgement the board should make deliberately rather than by drift.

What this means for hiring

The practical consequence for firms is that these are different roles requiring different people, even though the market sometimes treats them as interchangeable. A strong CRO is an enterprise-risk thinker comfortable with quantification, resilience and the full risk taxonomy. A strong CCO is a regulatory expert comfortable advising the business, engaging the regulator and owning the compliance framework. Some individuals can do both, particularly at smaller firms, but the skill sets are genuinely distinct, and hiring for one when you need the other is a common and costly error.

FD Capital recruits both Chief Risk Officers and Chief Compliance Officers into FCA-regulated firms, and advises firms on which the mandate actually requires.

A worked example of the boundary

Consider how the two functions handle the same event. Suppose a firm discovers that a product has been sold to customers for whom it was not appropriate. The compliance function’s concern is whether rules were breached — the conduct obligations, the Consumer Duty, the sales process — and what remediation and possibly notification the breach requires. The risk function’s concern is what this reveals about the firm’s control environment — how the failure happened, what it says about the adequacy of first-line controls, and what the residual risk is across the rest of the book.

Both are engaged; neither view is complete alone. The compliance lens fixes the specific breach; the risk lens asks whether the same weakness exists elsewhere. Firms that understand this run the two functions as complementary rather than competing, and the board gets a fuller picture as a result.

Reporting lines and independence

Both functions need genuine independence from the first line to be effective, and both typically have a reporting line to the board or a board committee — the CRO often to a Risk Committee, the CCO with access to the board on compliance matters. Where either function reports purely into the executive it oversees, its independence is compromised. A firm’s governance maturity often shows in how it protects the independence of these two roles.

What firms get wrong

The most common errors are treating the two as interchangeable in a hiring brief; combining them for too long as the firm grows, past the point where scale justifies separation; and leaving the overlap areas — conduct risk, resilience, financial crime — unallocated between them. Each is avoidable with a clear view of what each function is for, and each is the kind of gap a supervisor notices.

The skills that distinguish each

The two roles reward genuinely different profiles, which is why treating them as interchangeable in hiring goes wrong. A strong Chief Risk Officer is comfortable with the full risk taxonomy, with quantification and modelling, with operational resilience and scenario testing, and with giving a board an unwelcome view of the firm’s exposure. A strong Chief Compliance Officer is a regulatory interpreter — fluent in the rulebook, confident advising the business on how to meet its obligations, practised at engaging the regulator, and able to hold the compliance line commercially.

There is overlap in temperament — both need independence and the willingness to be unpopular — but the technical cores differ. Firms that write a single generic brief for ‘a risk and compliance leader’ often end up with someone strong in one half and stretched in the other.

How the functions evolve as a firm grows

The relationship between the two changes with scale. A small firm may combine them; a growing firm separates them; a large firm builds sizeable functions under each, with specialists beneath. Understanding where a firm sits on that curve is part of hiring well — a firm separating the roles for the first time needs a different kind of leader, someone who can build a function, from a large firm slotting a specialist into an established structure. Getting that stage-match right matters as much as the CRO-versus-CCO distinction itself.

What this means for firms hiring

The practical takeaway for a firm is to be honest about which function it is actually recruiting for, and at what stage of the firm’s development. A firm formalising its risk function for the first time needs a Chief Risk Officer who can build an enterprise-risk framework from a modest base. A firm strengthening its regulatory position needs a Chief Compliance Officer who can own the regulatory relationship and the compliance framework. Conflating the two in a single brief tends to produce a hire who is credible in one dimension and stretched in the other, and the cost of that mismatch at senior level is high. Getting the brief right — which function, at which stage — is where a specialist recruiter earns their place.

Call 020 3287 9501 or email recruitment@fdcapital.co.uk to discuss a CRO, CCO or wider risk and compliance leadership appointment.

FD Capital — Risk and Compliance Leadership Recruitment

Fellow of the ICAEW | Placing Chief Risk Officers and Chief Compliance Officers into FCA-regulated firms since 2018. 4,600+ network. 160+ placements. Shortlists in 3–7 working days.

Related reading and services

CRO Career Progression to SMF4

The route to the Chief Risk Officer function.

How to Become a Head of Compliance

The route to SMF16 Compliance Oversight.

Head of Internal Audit Career Path

The independent third-line assurance role.

Recruitment for FCA-Regulated Firms

Senior risk and compliance leaders for regulated firms.

About the author

Adrian Lawrence FCA is the founder and Managing Director of FD Capital. A Fellow of the Institute of Chartered Accountants in England and Wales and a former listed-company Finance Director, he leads every risk and compliance mandate FD Capital accepts personally. Verify his ICAEW membership.

Call 020 3287 9501 or email recruitment@fdcapital.co.uk.

This article is general information about UK financial services regulation and recruitment practice. It is not legal or regulatory advice. Firms and individuals should take their own professional advice on their specific circumstances.