MD, Protiviti
In the run-up to the Leaders in Finance CRO Risk Event on 29th of October in Amsterdam, we spoke with Owen Strijland, Managing Director at Protiviti. We discussed the changing risk landscape, technology and smart analytics, DORA and third-party risk, recent VU research on the CRO role, and what participants can expect from the event.
Can you briefly introduce yourself and tell us about Protiviti, the main partner of the CRO Risk Event?
I’m Owen Strijland. I have a technical background and have worked in risk and compliance within financial services for the past twenty years. In fourteen years at Protiviti, I’ve focused on growing the business and helping banks, payment providers, insurers and other financial services companies with security, privacy, risk, compliance and internal audit. What I enjoy the most is working closely with clients and delivering results when change is needed.
What attracted Protiviti to the CRO Risk Event?
About two years ago, a CRO at a Dutch bank told me there was no strong, regular network for CROs across banking, payments and insurance. That conversation planted the seed for a dedicated CRO event. I brought the idea to Leaders in Finance last year, and the first edition was a real success. This year the programme is broader, with more speakers and an active contribution from DNB. That matters because much of the CRO agenda is shaped by global regulation and translated into local supervision by DNB and the AFM.
From Protiviti’s perspective, what are the most important developments in the risk landscape?
Three connected developments stand out from my conversations with CROs, our interviews with the VU and our work with clients. Firstly, technology is changing how CROs work. GRC and financial-risk software have been around for years, but the real opportunity behind the current AI discussion is smart analytics: using data to look forward instead of relying mainly on backward-looking assessments and the administrative side of risk and control.
Second, geopolitical instability makes economic and operational risks harder to anticipate. Finally, DORA and other regulations are changing how institutions assess their vendors, including fourth- and fifth-party dependencies and concentration risk. Together, these developments make the CRO agenda much more interconnected. Risk management is no longer just about assessments, GRC implementation or compliance policies; it is also about anticipating what may happen and understanding how clients and third parties could be affected.
In reality the next step for risk management is not collecting more data, but turning signals into timely decisions.
Can you give a concrete example of how smart analytics is already helping organisations become more forward-looking?
Customer monitoring is a clear example. Data can reveal early warning signals, such as a change in ownership or adverse media involving a customer, vendor or partner. Teams can then investigate and act before the risk materialises. Similar approaches support DORA vendor analysis, financial risk and compliance. Traditional risk and control assessments tend to look backwards; continuous monitoring can make the organisation more predictive.
The same technology can also create information overload. AI may increase analytical capacity, but its economics and operating model still require careful management. The harder question is what the organisation does once a warning signal appears. Having more information only helps if you can identify what matters and act on it.
You mentioned DORA. What changes are you seeing as a result of its implementation?
DORA is already driving changes in third-party risk management. Across Protiviti’s offices, we work both with financial institutions assessing vendors and with vendors being assessed by their clients. Organisations can gather far more data about third parties, but turning it into actionable intelligence is harder. Major providers such as Microsoft or a large cloud provider cannot easily be replaced. DORA makes concentration risk and interdependence more visible and forces institutions to decide which practical measures are realistic.
At the event, you will moderate a technology panel with the CRO of MEWS and the CRCOs of Katanox and GoDutch. You will also present recent research conducted with the Vrije Universiteit Amsterdam. What did the research examine, and what can attendees expect from the panel?
Together with the VU, we asked a VU graduate, who has since started a master’s in risk management, to interview twenty CROs. We wanted to understand what keeps them busy, how they work within their organisations, what they would like to change and how the formal description of their role compares with their day-to-day experience.
The most striking finding is the variation. Unlike the CFO role, the CRO role does not have a standard career path. CROs come from compliance, legal, product and client-facing backgrounds, and their responsibilities differ considerably between organisations. That flexibility can also be a strength: the role brings together strategy, compliance and risk-taking. But does it make the CRO adaptable, or does the lack of a standard mandate weaken the function?
We will share more of the findings at the event.
The technology panel will bring that diversity into practice. The CROs and CRCOs represent highly technology-driven organisations with different origins and business models. I want to explore how technology helps them perform their roles, where it creates additional challenges and what that means from a compliance perspective.
What are you most looking forward to, and what do you hope the event will achieve?
First of all, bringing CROs together. Last year’s event was mainly focused on banking and payments. This year, I hope we will also welcome more people from insurers and pension funds. Their roles differ, but they face many of the same questions. I also value DNB’s active contribution. The regulator will not only attend, but also present and take part in the conversation.
I hope the technology discussions show how better data and analysis can support resilience in a changing world. Regulators also have a role in enabling a stable and sustainable financial system, alongside supervision. On Protiviti’s global calls, colleagues from around forty countries recognise the same challenges among financial-services clients. I want to encourage CROs to compare not only their risks, but also how they are changing their own role and decision-making model.
Owen Strijland is Managing Director at Protiviti. He will moderate a technology panel and present recent research conducted with Vrije Universiteit Amsterdam at the Leaders in Finance CRO Risk Event on 29 October 2026 in Amsterdam.
Uniting the financial sector by discussing pressing topics and enhancing cooperation. That’s what we love to do at Leaders in Finance. By listening, learning, and connecting with others, we accelerate the sharing of ideas, thus powering (upcoming) leaders and organizations to shape the future of financial services.
Each part of the Leaders in Finance Group – Podcasts, Events, Lunches, Academy – has its unique approach. Want to explore how we can benefit your organizational goals? We’re happy to meet and discuss opportunities.
We’d love to keep you informed on the next iterations of this event. Please enter your details below, and we’ll keep you posted!
