Security and compliance

10 risk management consultants

These ten risk management consultants advise organizations on enterprise, operational and regulatory risk, and several of them have also led risk functions as chief risk officers or heads of operational risk. A reader can learn how to build a risk framework, strengthen operational and third-party risk programs, and prepare for regulatory scrutiny.

10 professionals10 companiesData retrieved September 29, 2026

Professionals to explore

01—10
  1. Denise Rinear

    LinkedIn

    Experience: Managing Principal - Enterprise Risk Management · Capco

    Former Managing Principal - Enterprise Risk Management at Capco (2018–2024); her profile describes advising banks on their enterprise risk management and how it connects to their strategic objectives. She was Chief Risk Officer at Bryn Mawr Trust (2016–2017), Chief Compliance Officer at JG Wentworth (2015–2016) and Enterprise Operational Risk Officer Chief Operational Risk Officer at Ally (2007–2011).

  2. Iain Felstead

    LinkedIn

    Experience: Founder Managing Director · Erasmus Risk Consulting

    Founder Managing Director of Erasmus Risk Consulting since 2023; his headline lists enterprise and operational risk, risk consulting, ESG risk management and risk management training. He has been a Tutor on ESG Risk Management course at University of Cambridge Online since 2023, and was Head of Operational Risk at Tandem Bank (2022) and Head of Operational Risk (Interim) at Brown Shipley (2021–2022).

  3. Jacqueline Hirschkop, MBA, NCRM, CBCI, SOX SME

    LinkedIn

    Experience: Risk Management Consultant · Freelance | Self-Employed

    Freelance, self-employed Risk Management Consultant since 2025, and former Director, Enterprise and Operational Risk, Third-Party Risk Management at Navy Federal Credit Union (2021–2025). She was Risk Management Program Architect Vendor Risk & Business Continuity and Disaster Recovery Manager at the FDIC (2016–2018). Her profile cites operational, financial, technology and vendor risk program design and automation.

  4. James W. Kiburz

    LinkedIn

    Experience: Managing Director · Risk Knowledge BV

    Managing Director at Risk Knowledge BV since 2014. He was SME Service Line Lead, Credit & Regulatory Risk at North Highland (2013–2014), Sr Vice President-Enterprise Risk Management at UMB Bank (2006–2007) and Director, Risk Consulting at Arthur Andersen (1994–2002). His profile cites enterprise, operational and credit risk work as a bank executive, management consultant and bank regulator.

  5. Jon Reeder

    LinkedIn

    Experience: Principal & Enterprise Risk Management Consultant · Principal and Enterprise Risk Consultant Self Employeed

    Self-employed Principal & Enterprise Risk Management Consultant since 2020. His profile describes building and transforming risk management frameworks that strengthen organizational resilience, drawing on Fortune 50 and global consulting experience. He was Risk Management Executive at Truist (2017–2019), Vice President at Marsh Risk (2016–2017) and Area Vice President at Gallagher (2014–2016).

  6. Kate Sylvis

    LinkedIn

    Experience: Enterprise Risk Management Practice Leader · Guidehouse

    Founder and Principal of KS Advisory LLC since 2026 and former Enterprise Risk Management Practice Leader at Guidehouse (2021–2025), where she was also Director (2018–2021). She was Director Risk Advisory Services at PwC (2016–2018). Her profile describes helping organizations navigate complex regulatory environments, operational crises and large-scale transformation by building risk and governance ecosystems.

  7. Ken Baker

    LinkedIn

    Experience: Principal · Enterprise Risk Consulting

    Principal of Enterprise Risk Consulting since 2016 and Enterprise Risk Management Consultant at Risk & Recovery Inc. since 2020. He was Corporate Manager, ERM at the City of Edmonton (2012–2019), and his profile describes him as a Chartered Professional Accountant and ERM practitioner with municipal government, private and public sector experience.

  8. Keri Hillerman Gormley

    LinkedIn

    Experience: Executive Advisor · Keri Gormley Executive Consulting

    Executive Advisor at Keri Gormley Executive Consulting since 2024 and former Chief Operational Risk Officer at State Street (2023–2024). She was Executive Vice President- Operational Risk at Wells Fargo (2019–2023) and Global Head of Operational Risk Assurance at BNY (2016–2019). She describes helping organizations navigate complex regulatory landscapes and manage large-scale remediation programs.

  9. Norwin Estrada

    LinkedIn

    Experience: Risk Management Practice Leader · Clarendon Partners, LLC

    Risk Management Practice Leader at Clarendon Partners, LLC since 2025, where he says he and his team help clients through complex compliance landscapes. He was a Managing Director at EY (2010–2026), Principal Consultant at Capco (2009–2010) and Business Advisor at BearingPoint (2004–2009). He describes his management consulting career as focused on enterprise risk management and complex regulatory projects in financial services.

  10. Patricia Jalleh

    LinkedIn

    Experience: Founder · Enterprise Risk Associates

    Founder of Enterprise Risk Associates since 2012 and Trainer on Operational Risk at the National University of Singapore since 2009; she describes herself as a trainer, speaker and consultant on operational risk and other non-financial risks. She was Executive Director, Head, Risk Strategy, Group Risk Management at United Overseas Bank (2010–2011) and First Vice President, Head, Group Operational Risk Management there (2004–2010).

Choose the right perspective

Match the consultant's background to your organization: former financial-services risk officers suit regulated institutions, while consultants with public sector or broader ERM practice experience suit other organizations. Ask whether they designed frameworks, ran remediation programs or both, since those are different engagements.

Questions to take into the conversation

  1. 01How do you set a risk appetite that the board can actually use to make decisions?
  2. 02What does a practical operational risk and control self-assessment process look like for a mid-sized firm?
  3. 03How should third-party and vendor risk be folded into an enterprise risk framework?

About this directory

This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.

Request a correction or removal

Other perspectives in Security and compliance