CDAIO
Chief Data & AI Officer Certificate
The Chief Data & AI Officer (CDAIO) Certificate program provides you with emerging AI knowledge that you need to set up a 21st century data utilization and responsible AI program.
Risk is a fact of doing business. Be a CRO who can see the big picture.
For leaders in risk management to gain the latest skills and best practices impacting their domain, including strategies to address emerging cyber risk challenges.
This six-month program, co-administered by the CERT Division of CMU’s Software Engineering Institute (SEI), blends on-campus and synchronous distance learning. It is designed to deliver what CROs need to flourish in their current positions and further develop their careers through comprehensive risk management training. The Chief Risk Officer curriculum includes strategies for effectively communicating risks to executive leadership professionals and tools for analyzing and addressing enterprise risks.
The Chief Risk Officer (CRO) Certificate Program provides you with applicable training, including topical discussion on current cyber risk challenges and mitigation practices. Learning objectives are met through a combination of expert faculty instruction, business case analyses, and active exchanges with thought leaders in the field. As part of this certificate program, you will develop or enhance a risk plan for an organization. This plan is designed for you to apply several of the methods, tools, and techniques taught during the program modules.
The CRO Certificate Program is developed and delivered by Carnegie Mellon University's Heinz College of Information Systems and Public Policy, CMU's Digital Transformation and Innovation Center, and the CERT Division of the Software Engineering Institute (SEI). These cutting-edge entities ensure the program addresses the evolving landscape of cyber risk and enterprise risk management.
All students admitted to the CRO Certificate Program will have at least seven years of relevant experience, giving you the chance to collaborate with similarly experienced peers and build exciting new relationships and networks with your cohort.
I can’t say enough about the amazing experience I had attending these programs and the value it has provided me over the past several years. I completed the CISO certificate program and it was so helpful that I went back for the CRO program. As many of us have seen over the past decade, cyber threats are an enterprise risk and the education, relationships, and insight I received from both programs at CMU has been invaluable.Jim Trainor | Senior Vice President, Aon | Former Asst. Director, FBI Cyber Division
The program covered a comprehensive range of risk management topics that provided sufficient breadth and depth to prepare me for the CRO role. The practicum was extremely beneficial as it pushed me to apply the knowledge and role play the CRO function for an organization. Working for a CRO for the last several years had given me a strong foundation for this program. However, after completing the program I feel that I am infinitely more knowledgeable, prepared and confident in assuming the role and function of the CRO.Sukhinder Jaaj | SVP, Enterprise Risk Director | Comerica Bank
Please note: Due to the non-credit bearing nature of the CRO Certificate Program, students are unable to apply for tuition assistance, scholarship, or VA benefits. Program costs cannot be itemized.
Applications are currently being accepted for Cohort 11, which begins February 2025.
Virtual Orientation: 12:00 - 5:00 p.m. EST
November 12-14, 2025
Virtual Modules: 4:00 - 9:00 p.m. EST/EDT
(Note: all virtual class dates are Tuesdays)
December 2, 16 (2025)
January 6, 13, 27 (2026)
February 10 (2026)
Mid-Session: 9:00 - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
February 18-20, 2026
Virtual Modules: 4:00 - 9:00 p.m. EDT
(Note: all virtual class dates are Tuesdays)
March 10, 24 (2026)
April 7, 21 (2026)
May 5 (2026)
Practicum: 9:00 a.m. - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
May 19-20, 2026
Virtual Orientation: 12:00 - 5:00 p.m. EST
February 12-14, 2025
Virtual Modules: 4:00 - 9:00 p.m. EST/EDT
(Note: all virtual class dates are Tuesdays)
February 25 (2025)
March 18, 25 (2025)
April 8, 15 (2025)
May 6 (2025)
Mid-Session: 9:00 - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
May 13-15, 2025
Virtual Modules: 4:00 - 9:00 p.m. EDT
(Note: all virtual class dates are Tuesdays)
June 3, 10, 17 (2025)
July 15, 22 (2025)
Practicum: 9:00 a.m. - 5:00 p.m. EDT (Pittsburgh, PA; virtual option available)
August 11-12, 2025
Earning your executive education certificate is just the beginning of a lifelong relationship with CMU; we're here to help you advance your career throughout your professional life. The Heinz College Executive Advantage program is meant for people who always want to be ahead of the curve—those who want to lead the conversation, not just be a part of it.
Executive Advantage was designed with you—C-suite executives and lifelong learners—in mind. In addition to the valuable skills you gain through our executive certificate programs, you now have access to workshops, leadership summits, and conferences.
Instructors:
Brian Schwartz | Lead Client Partner and Enterprise Risk Management Leader, PwC
Jonathan Schwartz | Vice President, Internal Audit, Compass
In today’s global business environment, risk management must be aligned to business strategy. The CRO role is an important catalyst in this process so that a company can realize its long-term strategic objectives. This module focuses on discussing CRO roles and responsibilities; how the CRO integrates effectively in organizational governance and operations; and leadership and management practices that enhance the ability of today’s CRO to succeed in any organization.
This session sets the stage for the overall CRO certificate program and the subsequent modules.
Instructor:
Brett Tucker | Technical Manager, Cyber Risk Management, SEI
This module will define the baseline components of an enterprise risk management program, develop a risk appetite statement, and work to establish the governance and policy framework for the organization. This module will also provide practical guidance on available models, standards, and frameworks that can be tailored to your organization’s needs. Students will also discuss how to implement a model within an organization.
Instructors:
David Lassman | Distinguished Service Professor, Carnegie Mellon University's Heinz College
Chris Labash | Assistant Teaching Professor, Carnegie Mellon University's Heinz College
This module is designed to improve your effectiveness as a leader by introducing you to frameworks for understanding organizations and organizational processes.
This session will focus on how to effectively lead and inspire, foster teamwork, and create a culture that helps better manage risk. This module will also discuss effective ways to communicate risk related organizational goals to the board and senior management.
Instructor:
James Quinn | Co-Founder, Q9 Capital
This module is focused on discussing a major component within the landscape of enterprise risks—financial risk. It will help to set the stage for an overall understanding of the components of financial risk including market and credit risk. The module will also provide a baseline for students on GRC best practices, risk taxonomy, and issues management.
Instructor:
David Dunn | Chief Risk Officer, FIS
Understanding how to identify, measure, and manage operational risk commensurate with one’s specific business, industry, or sector is a primary objective of any enterprise risk framework, and consequently, of any CRO.
This module will provide a comprehensive overview of operational risk concepts, including common frameworks and activities, and provide practical guidance and techniques to implement and manage an operational risk management function. The module will conclude with a guest lecture on privacy risk management issues from a Chief Privacy Officer
Instructor:
James Lam | President, James Lam & Associates, Inc.
The intersection of ERM and strategy is arguably one of the most important areas where the CRO can add value. As such, strategic risk should be a key focus area in any ERM program.
What is the role of the CRO in strategic risk management? How should the CRO support the CEO and the Board and collaborate with the CFO and head of strategy? What are best practice strategic risk frameworks that companies can consider? This module will address and explore these questions.
Instructor:
Shaun Khalfan | SVP, CISO, PayPal
Today’s businesses face an array of potential disruptions from digital-based threats, such as denial-of-service attacks or the proliferation of ransomware. To effectively manage risk-based operations, an organization must become adept at preventing disruptions whenever possible and ensuring continuity of operations when a disruption occurs.
This module discusses the necessary steps to enhance existing cyber risk management processes, and examines the role that the CRO can play.
Instructor:
K.C. Turan | Executive Vice President, Chief Risk, Compliance & Ethics Officer, Commonwealth Care Alliance
Compliance risk management is the process of identifying, assessing and mitigating potential losses that may arise from an organization’s noncompliance with laws, regulations, standards, and both internal and external policies and procedures. Organizations must have compliance risk management policies and procedures, which are the framework and mechanisms they implement to control compliance risk. This module will cover the compliance risk landscape organizations are facing today (including privacy and ESG), and will discuss the needed policies, procedures and training programs to stay in compliance with key organizational directives and regulations.
Instructor:
Dr. Earl Crane | Risk Executive Strategic Advisor, Earl Crane, LLC
This module will discuss the importance of risk assessment to the ERM program and the Chief Risk Officer in risk governance and management and decision making. Risk assessments are critical to effective risk management, reporting issues, and designing internal controls.
This module will also focus on developing risk appetite statements (qualitative and quantitative). Students will be led through a design workshop to understand the details of this important tool for risk-informed decision making.
Instructor:
James Lam | President, James Lam & Associates
This module will discuss how organizations can cope and overcome disruptive risks to minimize impact to business operations and discuss best practices for using scenario analysis to not only manage the expected risks that their organizations may face in the course of daily operations, but now also the unexpected risks that would have a potential, material impact.
Instructor:
Spyro Karetsos | Chief Compliance Officer, Remitly
This module is an overview of practical “day-to-day” operations. Students will learn how to properly plan, structure, finance, and obtain “buy-in” from the organization and report on your risk team. This clear outline of the risk team structure and operations will better enable CROs to demonstrate the charter and effectiveness of the team to their organizations.
Instructor:
Summer Fowler | CISO, Torc Robotics
This module will discuss important tips on how to build useful meaningful, strategic metrics, communicate the effectiveness of the program, and establish effective communication links with the C-suite and Board.
This module will also cover how to develop more effective risk visualizations to enhance reporting effectiveness.
Instructor:
Matt Butkovic | Technical Director of Cyber Risk and Resilience, CERT Division of SEI
This module provides a comprehensive overview of organizational resilience management and its related subjects and challenges.
This session will also cover best practices for developing comprehensive business continuity and disaster recovery plans in order to manage the impact of today’s risk landscape efficiently and effectively. The module will end with a guest lecture to discuss how to implement and operate an effective BC/DR plan in times of uncertainty.
Instructor:
Laurie Champion | Managing Director & Global Client Executive, Marsh & McLennan Companies
The CRO plays an important role in encouraging understanding of potential trade-offs between pre-event planning and post-event response, as well as how a combination of Risk Response techniques can offer the best solution.
This module discusses the key characteristics of an effective Risk Response capability, along with the role the CRO plays in building Risk Response capability across the organization. Discussion will provide practical insight into best practices, including risk control, supply chain and contract management, insurance, and related matters. The module will conclude with a guest lecture on Risk Engineering from an insurance carrier.
Instructor:
Ryan Zanin | Chief Risk Officer, Westpac
In this module, students will discuss the aspirations, efforts, methods, and challenges involved in maturing your risk operations to be a highly respected contributor to the overall success of the enterprise.
This module will cover how to build and evolve risk organizations from a “must have” speed bump on the highway of corporate ambition to becoming an invaluable contributor to the successful realization of corporate strategy and a leader setting table stakes for the corporate culture. The module will also include a guest lecture from a Chief Audit Executive to provide some insight into how a mature organization works with this function.
Instructor:
Denise Letcher | Executive Vice President, Chief Data Officer, PNC Financial Services Group, Inc.
With the rise of new risks, the use of data analytics and other advanced technologies has become more important than ever. The risk management approach must embed these technologies across the entire risk management process, starting from identification to assessment to mitigation to monitoring. This module will discuss how an analytics-driven approach can be used to measure the risk characteristics of a unit, as well as define common metrics for measuring an enterprise-wide risk profile.
Graduates of the Chief Risk Officer Certificate Program will have access to new CRO Program modules created in the future, providing you with continuing education after the program ends. Approval is required.
Please note: This benefit does not extend to future CIO, CISO, CDAIO, or CDigitalO program modules, unless the student is also a graduate of those programs.
Students who complete the CRO Certificate Program and who subsequently apply for and are admitted into the Heinz College MSIT Degree Program are eligible for a tuition discount scholarship. Program costs that have been paid for completing any or all of the Heinz College Executive Education certificate programs (up to $40,000) by the individual student or their sponsor/employer will be matched with a tuition discount from the MSIT program—reducing the cost to complete the MSIT degree by up to $40,000.
In order to be considered, applicants to the MSIT program should indicate their enrollment status with the CIO, CISO, CRO, CDAIO, and/or CDigitalO program(s) on the Application for Admission.
Please note: The tuition discount is only available once a student has completed all of the certificate program’s requirements. Completion of a certificate program does not guarantee admission to the MSIT program.
A Chief Risk Officer serves as the senior leader charged with identifying, analyzing, and mitigating risk to ensure organizational success.
CROs must be equipped to understand the risk landscape at an enterprise level. Typical responsibilities include:
Explore our suite of executive education programs to find the one that's best for you:
Chief Data & AI Officer Certificate
The Chief Data & AI Officer (CDAIO) Certificate program provides you with emerging AI knowledge that you need to set up a 21st century data utilization and responsible AI program.
Chief Information and Digital Officer Certificate
The Chief Information & Digital Officer (CIDO) Certificate program takes an interdisciplinary approach to information and technology management for executives with IT oversight responsibilities.
Chief Information Security Officer Certificate
The Chief Information Security Officer (CISO) Certificate program equips cyber leaders with enhanced capabilities in cybersecurity, information assurance, and modern threats.
Master of Science in Information Technology (Online)
The Master of Science in Information Technology (MSIT) is our part-time online program for professionals seeking graduate degrees in IT; Heinz certificate program graduates are eligible for a MSIT tuition discount.
Have questions? Reach out to us to find out more:
Check out our detailed program guide.
Ready to apply?