The Chief Risk Officer must report directly to the Chief Executive Officer and must have regular and unfettered access to the Board and the Board Risk Committee.
What else in your programme already covers this
This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-2 Information Security Program Leadership Role. Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program
NIST800-PM-29 Risk Management Program Leadership Roles. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and Establish a Risk Executive
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties