Professional who Measures and Manages Risk

Photo of author
Written By Chris Ekai

The professional who measures and manages risk is called a risk manager, with variants including risk analyst, credit or market risk manager, and chief risk officer. They quantify threats with models, matrices, and stress tests, then treat them through controls, insurance, or deliberate acceptance, earning a median $106,000 in the United States.

On October 14, 2025, JPMorgan Chase chief executive Jamie Dimon told analysts on the bank’s third-quarter earnings call that “when you see one cockroach, there’s probably more.” He was explaining a $170 million charge-off tied to Tricolor Holdings, a subprime auto lender that had collapsed weeks earlier.

Professional Who Measures and Manages Risk: Key Takeaways
The professional who measures and manages risk is the risk manager, on a ladder running from risk analyst to chief risk officer, tracked by BLS as financial risk specialists at a $106,000 median wage.
Tricolor’s September 2025 collapse cost Fifth Third $178 million, JPMorgan $170 million, and Barclays $150 million in one quarter, the clearest recent case for funding the role.
Risk managers measure with registers, five-by-five matrices, value at risk, KRIs, and stress tests, then manage through avoid, reduce, transfer, or accept decisions with named owners.
BLS projects 6% growth for financial analyst occupations from 2024 to 2034, faster than the all-occupation average, with about 29,900 openings a year.
FRM, PRM, CRISC, RIMS-CRMP, and ISO 31000 Lead Risk Manager are the credentials that move pay; match the badge to the specialty lane.
Structure decides success: the role needs board access and independence under the three lines model, with success measured by decision quality instead of zero incidents.

Fifth Third charged off $178 million on the same lender and Barclays booked a $150 million loss, roughly half a billion dollars across three banks in a single quarter. Dimon’s own verdict on the miss was blunt: it was not the firm’s finest hour.

Catching the next Tricolor before it reaches the income statement is a job title. The professional who measures and manages risk is the risk manager, a role with its own salary ladder, credential market, and reporting line, all of which reward getting the structure right before the loss.

What Is the Professional Who Measures and Manages Risk Called?

The umbrella title is risk manager, but the market splits the work into a ladder of roles. Analysts gather and score data, managers own frameworks and treatment decisions, and the chief risk officer answers to the board for the whole risk profile.

The US Bureau of Labor Statistics tracks the core role as financial risk specialists, with a median wage of $106,000 in May 2024. GARP’s career guidance splits practitioners into credit, market, and operational specialists, and the generalists who coordinate across all three.

Whatever the title, the mandate is the same: keep exposure inside the appetite the board approved. That is why the role now reports higher than it did a decade ago, and why the risk management process is a board agenda item at most regulated US firms.

Title What they own Typical US pay Reports to
Risk analyst Data gathering, scoring, register upkeep $87,951 (Indeed) Risk manager
Risk manager Framework, treatment decisions, KRI thresholds $105,930 (Indeed) CRO or CFO
Model risk specialist Validating the models other teams rely on $116,680 (Indeed) Head of model risk
Chief risk officer Whole risk profile, appetite, board reporting $132,947 (Indeed); more at banks CEO and risk committee

Where you sit on that ladder decides your day. Our guides to becoming a risk analyst with no experience and the chief risk officer salary by US state map both ends, and the GRC analyst versus risk analyst comparison covers the adjacent compliance track.

Industry placement follows the loss data. Banks and insurers hire the deepest benches because capital rules demand them, while healthcare systems, utilities, and manufacturers typically run leaner teams anchored to operational and compliance exposure, with one enterprise-level owner pulling the threads together.

Professional who Measures and Manages Risk

Figure 1. Average US pay by risk role. Source: Indeed career data.

Why Companies Pay Six Figures for This Work

The ladder exists because misses are expensive and getting more so. Tricolor’s collapse cost three banks roughly $498 million in a single quarter, before lawsuits from securitization investors even started; the suits ask why warnings from credit risk teams never bit.

Professional who Measures and Manages Risk

Figure 2. Losses disclosed in third-quarter 2025 earnings. Source: company disclosures reported by Banking Dive and CNN.

Regulation keeps widening the mandate. The Federal Reserve’s Dodd-Frank stress tests make large banks prove capital adequacy against severe scenarios every year, and SEC rules since December 2023 force public companies to disclose material cyber incidents within four business days and describe board risk oversight.

  • Annual Dodd-Frank stress tests for banks above $100 billion in assets
  • Four business days to disclose a material cyber incident under SEC rules
  • Annual 10-K risk factor and board oversight descriptions read by investors and plaintiffs alike
  • State ORSA filings for insurers, due each year with board sign-off

Demand tracks the same direction. BLS projects 6% growth for financial analyst occupations from 2024 to 2034, faster than the all-occupation average, with about 29,900 openings a year. Risk specialists occupy the best-paid slice of that pool, and the salary section below breaks the spread down.

We have sat on both sides of that hiring decision, and the pattern holds: firms that fund the role only after a loss pay for it twice. The cheaper sequence is building the risk function well before the cockroaches show up.

How the Work Actually Gets Done

Strip the job to its verbs and two remain: measure, then manage. Both follow the risk management lifecycle, and both leave artifacts an auditor can check, which is what separates the profession from educated guessing dressed up in a heat map.

Measuring: Models, Matrices, and Stress Tests

Measurement starts with a risk register scored for likelihood and impact, usually on a five-by-five matrix anchored to dollar bands. ISO 31000 sets the process expectations, and the key elements of a risk register guide shows the fields that make scores defensible.

  • Value at risk and expected shortfall for trading books, validated by an independent model risk team
  • Scenario analysis and tail-risk stress tests modeled on the Federal Reserve’s annual exercises
  • Key risk indicators with green, amber, and red thresholds, drawn from sets like our 150-KRI library
  • Monte Carlo simulation for project and investment decisions where single-point estimates mislead

Stress tests exist to ask the question registers cannot: what breaks when three assumptions fail together? The Federal Reserve publishes its severely adverse scenarios every February, and private firms borrow the discipline even when no regulator requires it of them.

External data keeps the scores honest. Credit teams track delinquency roll rates, market teams back-test value at risk against realized moves, and operational teams reconcile registers against actual loss events, because a register that never matches reality is a fiction with formatting.

Managing: Four Treatments and a Reporting Line

Every scored risk gets one of four treatments: avoid the activity, reduce it with controls, transfer it through insurance or contracts, or accept it with a documented review date. COSO’s ERM guidance ties those choices to strategy, and our COSO ERM framework guide walks the twenty principles behind them.

Transfer still does heavy lifting in corporate programs: property, liability, cyber, and crime policies convert tail losses into premium expense. The professional’s job is reading exclusions the way Tricolor’s lenders should have read collateral reports, because transferred risk that bounces back mid-crisis was never transferred at all.

Results flow upward through the IIA’s three lines model: operating teams own risks, the risk function challenges them, and internal audit checks both. The reporting artifact that survives contact with a board is a one-page dashboard against appetite, like the examples in our ERM dashboard collection.

Reporting: What the Board Actually Reads

Reporting is the third verb hiding inside the job. The dashboard formats in our KRI dashboard examples turn raw metrics into trend, exposure, and one requested decision, which is the entire vocabulary a board risk committee has time for between agenda items.

Cadence matters as much as format. Monthly packs go to management, quarterly summaries go to the committee, and event-driven escalations move within days, the same rhythm the SEC’s four-day disclosure clock now enforces on public companies from outside the building.

Specializations Across Credit, Market, Operational, and Enterprise Risk

The toolkit stays constant while the subject matter shifts. A credit risk manager watches borrower concentrations like the ones Tricolor’s lenders missed, a market risk manager watches positions, an operational risk manager watches processes and vendors, and an enterprise risk manager rolls all of it into one picture.

A worked example makes the lanes concrete. The credit seat at a regional bank would have tracked Tricolor-style exposure through concentration KRIs and covenant alerts, while the enterprise seat’s job was making sure the auto-lending line item ever reached the board’s one-page view.

Specialty Watches Signature tools Typical employer
Credit risk Default and concentration PD and LGD models, covenant tracking Banks, credit unions, lenders
Market risk Price and rate moves VaR, stress tests, position limits Trading desks, asset managers
Operational risk Process, people, system failures RCSAs, KRIs, loss event data Every regulated firm
Enterprise risk The aggregate picture vs appetite Registers, heat maps, appetite statements Corporates, public sector
IT and cyber risk Technology estate and vendors KEV patching, control frameworks All of the above

Moving lanes is normal and usually upward. Credit analysts become enterprise risk managers, operational risk leads take on vendor programs, and IT risk managers inherit AI governance, so treat the table as a map of adjacent seats with low fences between them.

Sector guides matter because the loss data differs. Our credit risk KRI guide, the IT risk management lifecycle, and the risk appetite statement guide each cover one specialty’s daily instruments in working detail, so pick the lane that matches your balance sheet.

The US Salary Ladder and the Credentials That Climb It

Specialty chosen, the next question is pay. BLS puts financial risk specialists at a $106,000 median for May 2024, with the bottom decile under $62,270 and the top decile above $182,310; bank CROs clear multiples of that, as our state-by-state CRO salary data shows.

Professional who Measures and Manages Risk

Figure 3. Wage percentiles for financial risk specialists. Source: US Bureau of Labor Statistics, May 2024.

  • FRM from GARP for market and credit quant roles; two exams plus two years of documented experience
  • PRM from PRMIA as the FRM’s main rival; weigh them in our FRM versus PRM breakdown
  • CRISC from ISACA for IT and cyber risk seats; our CRISC comparison covers fit
  • RIMS-CRMP from RIMS for insurance-led corporate risk programs
  • ISO 31000 Lead Risk Manager for ERM process roles; the certification guide walks the syllabus

Rank order depends on the lane you picked, and our ranked certification guide scores all of them on cost, difficulty, and salary lift. If you are choosing between governance and analysis tracks, the GRC certification value analysis settles whether the badge pays.

Credentials compound with reps, and employers weight the reps more. Two annual register cycles, one owned KRI set, and a defended board paper outrank a third certification on most shortlists, which is why our interview questions guide drills scenario answers over definitions.

Red Flags to Watch When Hiring (and Green Lights to Chase)

Hiring the role badly is more common than skipping it. These six patterns from job specs and org charts predict trouble before the first register review, and each row below pairs the pattern with a fix that costs less than one quarter of Tricolor losses.

Red flag Why it fails Green light
Risk manager reports into the function they challenge Independence dies quietly Direct line to CEO plus audit or risk committee access
Job spec is all compliance checklists Measurement skills never get used Spec names models, KRIs, and appetite work
One hire covers risk, compliance, and audit Three lines collapse into one Separate challenge and assurance roles, even part-time
No budget beyond the salary No tooling, no data, no training Line items for systems and certification upkeep
Success defined as zero incidents Encourages hiding, delays reporting Success defined as decision quality and disclosure speed
Risk register reviewed annually Stale by the second quarter Quarterly refresh plus event triggers

Fixing a red flag usually costs an org-chart line and a sentence in the charter. The expensive version is discovering the flaw the way Tricolor’s counterparties did, in the quarter it converts to a charge-off with a class-action lawsuit attached.

The Professional Who Measures and Manages Risk: Your Questions Answered

What is a professional who measures and manages risk called?

Risk manager is the standard title, with risk analyst below it and chief risk officer above it. Specialist variants name the risk type: credit risk manager, market risk manager, operational risk manager, and IT risk manager are the four most advertised in US postings.

How much does a professional who measures and manages risk earn?

BLS reports a $106,000 median for financial risk specialists as of May 2024, with the top 10% above $182,310. Indeed’s role data runs from about $88,000 for risk analysts to $133,000 for chief risk officers, and bank and state variation moves both ends.

What qualifications does a professional who measures and manages risk need?

A bachelor’s degree in finance, statistics, business, or engineering is the floor, and the FRM, PRM, CRISC, or ISO 31000 Lead Risk Manager credential is the accelerator. The three lines of defense model also demands enough independence to challenge the business, which is a posture, not a certificate.

Where does a professional who measures and manages risk usually work?

Banking, insurance, healthcare, energy, manufacturing, and government hire the most, because regulators in those sectors expect a named risk owner. Financial services pays the premium: stress testing, model validation, and credit portfolio roles cluster inside banks supervised by the Federal Reserve and OCC.

What does a professional who measures and manages risk do every day?

Mornings usually go to indicator dashboards and threshold breaches, afternoons to register updates, treatment follow-ups, and meetings where the business argues its scores. Quarter-ends add board reporting, and event days, a vendor breach or a market shock, reorder everything else on the calendar.

Is a professional who measures and manages risk the same as an actuary?

No. Actuaries price insurance liabilities and pensions under Society of Actuaries or Casualty Actuarial Society credentials, while risk managers cover an organization’s full register, from credit to cyber to reputation. The two share statistical methods, and actuaries who move into enterprise risk often make strong CRO candidates.

How do you become a professional who measures and manages risk?

Start in an adjacent seat, audit, credit operations, compliance, or data analysis, then take ownership of a register or KRI set and add a credential. Our guide to getting a job in risk management maps the transitions that work without a finance degree.

Can a professional who measures and manages risk work as a consultant?

Yes, and many do after a decade in-house. Consultants build registers, calibrate KRI thresholds, and coach committees across several clients at once, trading depth in one balance sheet for pattern recognition across many; independent practices also backstop firms too small for a full-time hire.

Where the Profession Is Heading

Private credit is the next proving ground. Dimon’s cockroach warning was aimed at lending that migrated outside supervised banks, and the analysts who can trace exposure through fund structures will be the ones boards ask for by name in 2027.

AI is entering both sides of the job description. Models now draft register entries and flag anomalies faster than analysts can review them, which shifts the scarce skill from producing scores to validating the machinery that produces them. Expect model risk specialists to stay the best-paid technical seat below the CRO.

Disclosure clocks will keep compressing. Four-day cyber disclosure is now routine SEC territory, California’s climate reporting and the EU AI Act are queued behind it, and each new clock converts risk measurement from an internal craft into a public deadline with a docket number.

If the job spec on your desk looks like the red-flag column, we can rewrite it before the hire, or benchmark the function you already have. Explore our advisory services and reach out through the contact page; the review starts with your register and ends with your board pack.