
Contribute to A Better World By Making Your Business Sustainable

Your Fractional Chief Risk Officer
Expert Governance, Embedded in Your Organisation
CRO-level risk frameworks, regulatory alignment, and ESG integration — proportionate to your institution's scale, without the fixed overhead of a full-time appointment.
What this delivers:
-
Regulatory-grade risk governance — Basel III/CRR3, IFRS 9, ERM — embedded directly into your decision-making process
-
Senior risk leadership for board, risk committee, and supervisory engagement — without a full-time CRO hire
-
Scoped to your regulatory environment, governance maturity, and strategic timeline — no fixed templates
Every Organisation Carries Risk
Few Have the Governance to See It Clearly
Every organisation carries risk — credit risk, operational risk, regulatory risk, ESG exposure. The question is whether your governance framework is strong enough to see it clearly, quantify it accurately, and act on it decisively.
When that framework is absent or underpowered, the consequences are concrete. They appear in supervisory findings. In capital penalties. In financing relationships that deteriorate not because the business is failing, but because the risk position was never properly documented or understood.
Three Situations Where the Gap Becomes Expensive
Scenario 1 — The Regulatory Deadline You Cannot Miss
A bank or fintech faces a CRR3 implementation deadline or an EBA supervisory review. The internal risk team is technically stretched, the documentation is incomplete, and the ICAAP narrative does not withstand challenge. What was a governance gap becomes a supervisory finding — and then a capital penalty.
Scenario 2 — The Covenant Breach No One Saw Coming
A company with EUR 20M in revenue secures a growth financing facility. Eighteen months later, leverage has shifted, ESG reporting obligations have emerged, and the lender is asking for an updated risk assessment the business cannot produce. The credit relationship deteriorates — not because the business is failing, but because risk was never properly instrumented.
Scenario 3 — The Scaling Organisation With No Risk Architecture
A fintech crosses the threshold where regulators expect a functioning Three Lines of Defence model. The board asks for a risk appetite statement. The CFO needs an IFRS 9 impairment methodology. There is no risk function to deliver any of it. Hiring a full-time CRO is premature. Leaving the gap open is not an option.

What a Fractional CRO Mandate Delivers
A Fractional CRO engagement provides an experienced Chief Risk Officer on a structured, part-time basis. This is not consultancy in the traditional sense — it is embedded advisory leadership. Amaranth Brose operates as a working member of your leadership team, with accountability for risk outcomes rather than the delivery of documents.
Typical engagements operate on a monthly retainer or defined project mandate, covering between one and three days of dedicated input per week. The structure is agreed at the outset and adapted as the mandate evolves. The objective is always the same: to ensure your organisation has the risk governance it needs — at the level of rigour its regulatory obligations, financing relationships, and board responsibilities require.
Engagement Formats
Retained Fractional CRO
-
Ongoing embedded leadership
-
Structured monthly retainer. Board and committee participation, regulatory dialogue, ICAAP/ILAAP oversight, risk reporting governance, and strategic risk leadership. Renewable and scalable.
Interim CRO Cover
-
Short-term leadership continuity
-
Senior risk leadership during recruitment, regulatory review, or organisational transition. Maintains governance continuity without the risk of a leadership gap reaching the regulator's attention.
Project-Based Mandate
-
Time-bound, outcome-defined delivery
-
Defined scope and timeline. Specific outputs: ICAAP/ILAAP narrative, ERM framework design, risk appetite statement, IFRS 9 ECL methodology, CRR3 gap analysis. Clear deliverables and completion criteria.
Advisory Board Participation
-
Board-level risk intelligence
-
Strategic risk input at board or risk committee level. Risk appetite challenge, model governance oversight, ESG risk positioning, and regulatory readiness review — without an operational mandate.
Three Steps - No Overhead
Every mandate begins with a clear conversation and ends with a defined outcome.
The process is structured to minimise friction and maximise decision quality from the first engagement.
Every mandate begins with a clear conversation and ends with a defined outcome. The process moves through three structured stages — Diagnostic Conversation, Mandate Scoping, and Embedded Advisory — each designed to generate decision-quality insight rather than procedural output. Nothing is templated. Every stage is calibrated to your organisation's specific regulatory position, governance maturity, and operational context. The sequence is deliberate.
The Diagnostic Conversation establishes a shared understanding of where you are and what the right next step looks like — before any engagement is proposed.
Mandate Scoping translates that understanding into a precisely defined scope: format, capability areas, reporting lines, and intended outcomes.
Embedded Advisory then delivers that scope inside your organisation — working with your teams, attending your committees, and producing outputs that hold up to regulatory and board scrutiny.
A 45-minute structured conversation about your organisation's risk governance position, regulatory obligations, and the specific gap you are trying to close. This is not a sales call. It is a working session that produces a clear shared understanding of what the right next step is — whether that is an engagement with Amaranth Brose or not.
Based on the diagnostic, a mandate scope is defined — covering engagement format, capability areas, time commitment, and intended outputs. For retained mandates, governance protocols are established: reporting lines, committee participation, communication cadence. For project mandates, milestones and deliverables are agreed. Typically completed within five working days of the diagnostic.
The mandate runs as agreed. Amaranth Brose operates as an internal leadership resource — attending board and committee meetings, producing and reviewing risk documentation, engaging with regulators where required, and integrating with your existing governance structure. Output is reviewed at defined intervals and the scope adapted as the organisation's needs evolve.

Not a Consultancy - A Risk Leadership Partner
Most risk advisory firms deliver documents. Amaranth Brose delivers decisions. The distinction matters: a risk governance framework that sits in a shared drive does not protect capital, satisfy a regulator, or inform a board. What changes outcomes is when the right risk logic is embedded in the decisions your organisation actually makes.
Every Amaranth Brose engagement is built around your organisation's real governance architecture, your specific regulatory obligations, and the decisions your leadership team will need to defend — not a pre-packaged methodology or a junior team's interpretation of what your risk function should look like.
The founder, Hüseyin Karagül, brings over two decades of institutional risk experience built at the most technically demanding intersection of model development, supervisory engagement, and capital governance — not in an advisory capacity removed from the work, but as the person responsible for the methodology, the submission, and the regulatory justification.
Critically, this career has operated on both sides of the work: model developer and independent model reviewer; methodology designer and regulatory challenger; delivery lead and quality assurance authority. That dual formation is the foundation of the advisory judgement Amaranth Brose brings to every mandate.
Capability Area | What It Covers |
|---|---|
Capital & Regulatory Risk | Basel III/CRR3 implementation, ICAAP and ILAAP production, SA/IRB transition planning, capital adequacy assessment, and Pillar 2 challenge readiness. |
ERM Framework Design | Risk taxonomy, risk register architecture, risk appetite statement, KRI development, Three Lines of Defence structuring, and ALCO governance. |
ESG & Climate Risk | ESG risk materiality assessment, climate scenario analysis (NGFS), CSRD/ESRS alignment, integration into regulatory capital and credit frameworks. |
Governance & Board Reporting | Risk committee charters, first-to-second-line interaction protocols, board risk reporting, model governance oversight, and supervisory letter management. |
IFRS 9 & Credit Risk | ECL model design and validation, PD/LGD/EAD mechanics, macroeconomic overlay frameworks, staging logic, and model risk governance for credit portfolios. |
Market & Liquidity Risk | Interest rate risk in the banking book (IRRBB), NII/EVE modelling, liquidity coverage ratio governance, funding risk frameworks. |
Regulatory Transformation | EBA, ECB, and NCA engagement readiness, supervisory examination preparation, CRD VI/CRR3 gap analysis, and regulatory documentation review. |
SME Risk Advisory | Proportionate ERM design, bank credit assessment preparation, ESG disclosure requirements (CSRD, lender covenants), and risk culture development. |