Is it time we stopped asking CCOs and CROs to “stay in their lane” — and instead re-draw the map?

Are Pre-Conceived Notions About the CCO and CRO Roles Holding Back Better Governance?

I came across a social media post recently that listed the regulatory fines paid by a large Canadian bank in 2025. Included were supervisory failures, compliance breakdowns and anti-money laundering deficiencies. The total dollar amount was staggering — not because fines are new, but because many of these issues were entirely preventable.

That post stuck with me, particularly when read alongside several recent articles and papers on the evolving role of the Chief Compliance Officer (CCO) and Chief Risk Officer (CRO). While most of this research focuses on the U.S. and Europe, the themes have very clear Canadian overtones and are highly relevant given the regulatory and operational environment financial services firms are facing as we head into 2026.

One recurring question keeps surfacing for me:
Are our pre-conceived notions of what the CCO and CRO “should be” actually limiting better governance outcomes?

In most organizations, the CCO and CRO roles are treated as distinct, but in practice they are often interchangeable — particularly when it comes to second-line oversight, escalation, and board engagement. The problem isn’t the mandate itself; it’s the expectations wrapped around it.

Take the traditional “zero tolerance” approach to policy breaches. Many oversight structures are designed with the assumption that strict enforcement, rigid controls, and absolute adherence will reduce risk. Yet evidence increasingly shows the opposite. These environments often discourage early escalation, create defensive behavior, and push issues underground — resulting in larger, more costly compliance failures over time.

In other words, we may be designing governance frameworks that look strong on paper but weaken risk management in practice.

Another area where expectations are clearly shifting is DEI. Historically, DEI has been viewed as a human resources function. However, recent lawsuits against large organizations that altered or rolled back DEI programs due to political or financial pressure tell a different story. In several cases, boards were asked why they were not informed of the changes or the associated legal, reputational, and conduct risks.

That question is telling.

If changes to DEI strategy can create material legal and reputational exposure, should DEI remain solely within HR? Or is it now firmly within the oversight scope of the CCO and CRO? If boards are holding compliance and risk leaders accountable for not flagging these risks, then the expectation has already shifted — whether organizations have acknowledged it or not.

The same tension exists with technology and digital transformation. Cloud computing, data governance, cyber risk, and now AI are fundamentally reshaping financial services. Yet most CCOs and CROs did not come up through or have competent IT or data disciplines. That reality raises an uncomfortable but necessary question: how can compliance and risk leaders credibly oversee risks they were never expected to understand?

AI is a perfect example. What is the firm’s policy on AI usage? What supervisory controls exist? What level of risk tolerance has been defined — if any? Avoiding these questions because they feel “technical” is no longer defensible. Regulators and boards are already asking them.

All of this points to a broader conclusion: the CCO and CRO roles must evolve. Not incrementally, but deliberately.

Holding onto dated assumptions about what compliance and risk management should look like — narrow, reactive, enforcement-focused — may itself be a governance risk. Today’s environment requires CCOs and CROs to be translators, challengers, and strategic advisors who operate across silos, not within them.

The real question may not be whether these roles need to change, but whether organizations are willing to let go of the pre-conceived notions that are quietly holding them back.Is it time we stopped asking CCOs and CROs to “stay in their lane” — and instead re-draw the