Chief Risk Officer (CRO) Certificate
Risk is a fact of doing business. Be a CRO who can see the big picture.
"I can’t say enough about the amazing experience I had attending these programs and the value it has provided me over the past several years. I completed the CISO certificate program and it was so helpful that I went back for the CRO program. As many of us have seen over the past decade, cyber threats are an enterprise risk and the education, relationships, and insight I received from both programs at CMU has been invaluable."
Jim Trainor
Senior Vice President, Aon | Former Asst. Director, FBI Cyber Division
Chief Risk Officer Calendar and Curriculum Details
Applications are currently being accepted for Cohort 12, which begins December 2025.
Virtual Orientation: 12:00 - 5:00 p.m. EST
December 3-4, 2025
Virtual Modules: 4:00 - 9:00 p.m. EST
(Note: all virtual class dates are Tuesdays)
December 16 (2025)
January 6, 13, 27 (2026)
February 10, 17, 24 (2026)
Mid-Session: 9:00 - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
March 11-13, 2026
Virtual Modules: 4:00 - 9:00 p.m. EDT
(Note: all virtual class dates are Tuesdays)
March 24 (2026)
April 7, 21 (2026)
May 5, 19 (2026)
Practicum: 9:00 a.m. - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
June 3-4, 2026
Virtual Orientation: 12:00 - 5:00 p.m. EST
February 12-14, 2025
Virtual Modules: 4:00 - 9:00 p.m. EST/EDT
(Note: all virtual class dates are Tuesdays)
February 25 (2025)
March 18, 25 (2025)
April 8, 15 (2025)
May 6 (2025)
Mid-Session: 9:00 - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
May 13-15, 2025
Virtual Modules: 4:00 - 9:00 p.m. EDT
(Note: all virtual class dates are Tuesdays)
June 3, 10, 17 (2025)
July 15, 22 (2025)
Practicum: 9:00 a.m. - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
August 11-12, 2025
The program mid-session and practicum will be held in person at our main campus in Pittsburgh:
Heinz College of Information Systems and Public Policy
Carnegie Mellon University
4800 Forbes Avenue
Pittsburgh, PA 15213
A virtual option will be offered for the program mid-session and practicum; students will not be required to travel to complete the program.
Earning your executive education certificate is just the beginning of a lifelong relationship with CMU; we're here to help you advance your career throughout your professional life. The Heinz College Executive Advantage program is meant for people who always want to be ahead of the curve—those who want to lead the conversation, not just be a part of it.
Executive Advantage was designed with you—C-suite executives and lifelong learners—in mind. In addition to the valuable skills you gain through our executive certificate programs, you now have access to workshops, leadership summits, and conferences.
"The program covered a comprehensive range of risk management topics that provided sufficient breadth and depth to prepare me for the CRO role. The practicum was extremely beneficial as it pushed me to apply the knowledge and role play the CRO function for an organization. Working for a CRO for the last several years had given me a strong foundation for this program. However, after completing the program I feel that I am infinitely more knowledgeable, prepared and confident in assuming the role and function of the CRO."
Sukhinder Jaaj
SVP, Enterprise Risk Director | Comerica Bank
Chief Risk Officer Curriculum
Instructors:
Brian Schwartz | Lead Client Partner and Enterprise Risk Management Leader, PwC
Jonathan Schwartz | Vice President, Internal Audit, Compass
In today’s global business environment, risk management must be aligned to business strategy. The CRO role is an important catalyst in this process so that a company can realize its long-term strategic objectives. This module focuses on discussing CRO roles and responsibilities; how the CRO integrates effectively in organizational governance and operations; and leadership and management practices that enhance the ability of today’s CRO to succeed in any organization.
This session sets the stage for the overall CRO certificate program and the subsequent modules.
Instructor:
Brett Tucker | Technical Manager, Cyber Risk Management,SEI
This module will define the baseline components of an enterprise risk management program, develop a risk appetite statement, and work to establish the governance and policy framework for the organization. This module will also provide practical guidance on available models, standards, and frameworks that can be tailored to your organization’s needs. Students will also discuss how to implement a model within an organization.
Instructors:
Dr. Earl Crane | Risk Executive Strategic Advisor, Earl Crane, LLC
This module will discuss the importance of risk assessment to the ERM program and the Chief Risk Officer in risk governance and management and decision making. Risk assessments are critical to effective risk management, reporting issues, and designing internal controls.
This module will also focus on developing risk appetite statements (qualitative and quantitative). Students will be led through a design workshop to understand the details of this important tool for risk-informed decision making
Understanding how to identify, measure, and manage operational risk commensurate with one’s specific business, industry, or sector is a primary objective of any enterprise risk framework, and consequently, of any CRO. This module will provide a comprehensive overview of operational risk concepts, including common frameworks and activities, and provide practical guidance and techniques to implement and manage an operational risk management function.
Today’s businesses face an array of potential disruptions from digital-based threats, such as denial-of-service attacks or the proliferation of ransomware. To effectively manage risk-based operations, an organization must become adept at preventing disruptions whenever possible and ensuring continuity of operations when a disruption occurs. This module discusses the necessary steps to enhance existing cyber risk management processes, and examines the role that the CRO can play. The module will conclude with a guest lecture on Cyber Risk Insurance landscape.
Instructor:
James Quinn | Co-Founder, Q9 Capital
This module is focused on discussing a major component within the landscape of enterprise risks—financial risk. It will help to set the stage for an overall understanding of the components of financial risk including market and credit risk. This module will conclude with a lecture on Fraud Risk Management.
Instructor:
K.C. Turan | Executive Vice President, Chief Risk, Compliance & Ethics Officer, Commonwealth Care Alliance
Today’s businesses face an array of potential disruptions from digital-based threats, such as denial-of-service attacks or the proliferation of ransomware. To effectively manage risk-based operations, an organization must become adept at preventing disruptions whenever possible and ensuring continuity of operations when a disruption occurs.
This module discusses the necessary steps to enhance existing cyber risk management processes, and examines the role that the CRO can play.
Instructor:
James Lam | President, James Lam & Associates, Inc.
The intersection of ERM and strategy is arguably one of the most important areas where the CRO can add value. As such, strategic risk should be a key focus area in any ERM program. What is the role of the CRO in strategic risk management? How should the CRO support the CEO and the Board and collaborate with the CFO and head of strategy? What are best practice strategic risk frameworks that companies can consider? This module will address and explore these questions.
Instructor:
Paul Zikmund | Chief Resiliency Officer, Berkadia
In an era of constant disruption — from cyber incidents and geopolitical instability to supply chain shocks, pandemics, and climate-related events — resilience has become a defining capability of successful organizations. This module prepares Chief Risk Officers to anticipate, prepare for, and adapt to disruptive events while maintaining operational continuity and strategic agility. Participants will learn how to embed resilience into the organization’s DNA through structured business continuity and disaster recovery (BC/DR) planning, scenario-based exercises, and a proactive risk culture that supports agility under pressure.
Instructor:
Spyro Karetsos | Chief Risk and Compliance Officer, Remitly
This module is an overview of practical “day-to-day” operations. Students will learn how to properly plan, structure, finance, and obtain “buy-in” from the organization and report on your risk team. This clear outline of the risk team structure and operations will better enable CROs to demonstrate the charter and effectiveness of the team to their organizations.
Instructor:
David Lassman | Distinguished Service Professor, Carnegie Mellon University's Heinz College
Chris Labash | Assistant Teaching Professor, Carnegie Mellon University's Heinz College
This module is designed to improve your effectiveness as a leader by introducing you to frameworks for understanding organizations and organizational processes. This session will focus on how to effectively lead and inspire, foster teamwork, and create a culture that helps better manage risk. This module will also discuss effective ways to communicate risk related organizational goals to the board and senior management.
Instructor:
Dennis Allen | Director — Security Programs, Strategy & Risk, Stratascale
An effective Governance, Risk, and Compliance (GRC) program is at the heart of organizational resilience and integrity. This module equips participants with the frameworks, tools, and leadership skills needed to design, implement, and sustain a robust GRC infrastructure that aligns with strategic objectives and regulatory expectations.
The module emphasizes practical approaches to operationalizing GRC — from establishing governance structures and policies to leveraging technology platforms, dashboards, and analytics for continuous monitoring and reporting.
Instructor:
Summer Fowler | CISO, Torc Robotics
This module will discuss important tips on how to build useful meaningful, strategic metrics, communicate the effectiveness of the program, and establish effective communication links with the C-suite and Board. This module will also cover how to develop more effective risk visualizations to enhance reporting effectiveness.
Instructor:
Laurie Champion | Managing Director & Global Client Executive, Marsh & McLennan Companies
The CRO plays an important role in encouraging understanding of potential trade-offs between pre-event planning and post-event response, as well as how a combination of Risk Response techniques can offer the best solution.
This module discusses the key characteristics of an effective Risk Response capability, along with the role the CRO plays in building Risk Response capability across the organization. Discussion will provide practical insight into best practices, including risk control, supply chain and contract management, insurance, and related matters.
This module will also provide a guest lecture for understanding and managing physical security as a core component of enterprise risk management. Participants will explore best practices for protecting organizational assets - people, facilities, and critical infrastructure - from both internal and external threats.
Instructor:
John Houston, Principal and the National Data Science Practice Leader (Ret.) | Deloitte
Dr. Anand Rao, Distinguished Service Professor of Applied Analytics and AI | Carnegie Mellon University's Heinz College
This module explores how data, analytics, and artificial intelligence (AI) are transforming the risk management landscape—and how Chief Risk Officers can lead their organizations in harnessing these technologies responsibly. Participants will gain a strategic understanding of how advanced analytics, predictive modeling, and AI-driven tools can enhance risk identification, assessment, and decision-making across the enterprise. At the same time, they will learn to evaluate and mitigate the emerging risks that AI itself introduces, from model bias and ethical dilemmas to governance, compliance, and security challenges.
Instructor:
Ryan Zanin | Chief Risk Officer, Westpac
With the rise of new risks, the use of data analytics and other advanced technologies has become more important than ever. The risk management approach must embed these technologies across the entire risk management process, starting from identification to assessment to mitigation to monitoring. This module will discuss how an analytics-driven approach can be used to measure the risk characteristics of a unit, as well as define common metrics for measuring an enterprise-wide risk profile.
Benefits, Discounts, and the Fine Print
Future Modules Benefit
Graduates of the Chief Risk Officer Certificate Program will have access to new CRO Program modules created in the future, providing you with continuing education after the program ends. Approval is required.
Please note: This benefit does not extend to future CIO, CISO, CDAIO, or CDigitalO program modules, unless the student is also a graduate of those programs.
MSIT Program Discount
Students who complete the CRO Certificate Program and who subsequently apply for and are admitted into the Heinz College MSIT Degree Program are eligible for a tuition discount scholarship. Program costs that have been paid for completing any or all of the Heinz College Executive Education certificate programs (up to $40,000) by the individual student or their sponsor/employer will be matched with a tuition discount from the MSIT program—reducing the cost to complete the MSIT degree by up to $40,000.
In order to be considered, applicants to the MSIT program should indicate their enrollment status with the CIO, CISO, CRO, CDAIO, and/or CDigitalO program(s) on the Application for Admission.
Please note: The tuition discount is only available once a student has completed all of the certificate program’s requirements. Completion of a certificate program does not guarantee admission to the MSIT program.
Cancellation/Refund Policy
- Should a student withdraw from the program after the deposit has been paid but prior to the program start date, students may have 4/5 of the program costs either refunded to them or transferred to the following cohort of the program.
- After the program start date, no refunds will be issued. However, under extenuating circumstances and with program director approval, students may petition to postpone their attendance to a future cohort and have 4/5 of the program costs applied accordingly.
What Is a Chief Risk Officer?
A Chief Risk Officer serves as the senior leader charged with identifying, analyzing, and mitigating risk to ensure organizational success.
CROs must be equipped to understand the risk landscape at an enterprise level. Typical responsibilities include:
- Strategic planning: develop and implement strategies to mitigate risk.
- Risk management: oversee the organization's risk management operations, including financial, operational, strategic, cyber, and compliance risk.
- Compliance: ensure the operation complies with relevant regulation and laws.
- Communication: lead and inspire to create a culture that helps mitigate risk.
Not Sure If The Chief Risk Officer Certificate Program Is Right For You?
Explore our suite of executive education open-enrollment programs to find the one that best fits you:
- CDAIO Certificate (Chief Data And AI Officer)
- CIDO Certificate (Chief Information and Digital Officer)
- CISO Certificate (Chief Information Security Officer)
- LEAAID Certificate (Leading Enterprise Agentic AI Development Program)
Additionally, the Master of Science in Information Technology (MSIT) is our part-time online program for professionals seeking graduate degrees in IT; Heinz certificate program graduates are eligible for a MSIT tuition discount.
What's Next?
Have questions? Reach out to us to find out more:
- Email: heinzexeced@cmu.edu
- Phone: David Ulicne, Executive Director — 412-268-5543
- Phone: Emily Brown, Director — 412-268-6730
Check out our detailed program guide.
Ready to apply?
Contact Us
Heinz College Executive Education
Carnegie Mellon University
5000 Forbes Ave
Hamburg Hall
Pittsburgh, PA 15213-3890
heinzexeced@cmu.edu