ROLE
OVERVIEW
The Group Chief Risk & Compliance Officer is
responsible for establishing and leading the Group's integrated Cybersecurity, Enterprise
Risk, Business and Regulatory Compliance functions to safeguard the
organisation's assets, reputation, operations, and long-term sustainability.
The incumbent provides strategic leadership in
developing enterprise-wide governance frameworks that proactively identify,
assess, mitigate, monitor, and report risks across the organisation while
ensuring full compliance with applicable laws, regulations, industry standards,
and internal policies.
This role will lead the Risk Management Committee and
partner closely with the Board, regulators, and business leaders to strengthen
organisational resilience, cybersecurity posture, governance standards, and
regulatory compliance.
KEY
RESPONSIBILITIES
Enterprise
Risk Management
·
Develop and execute the Group's Enterprise Risk
Management (ERM) strategy and framework.
·
Establish enterprise risk governance, policies,
methodologies, and risk appetite aligned with business objectives.
·
Oversee strategic, operational, financial, technology,
legal, and emerging risks across the Group.
·
Ensure consistent risk identification, assessment,
mitigation, monitoring, and reporting across all business functions.
·
Drive a proactive risk culture through effective
governance, education, and accountability.
·
Present enterprise risk reports, emerging risks, and
mitigation strategies to the Risk Management Committee and Board Risk
Committee.
·
Ensure business continuity planning and crisis
management frameworks remain effective and regularly tested.
Cybersecurity
& Information Security
·
Provide executive oversight of the Group's cybersecurity
strategy, governance, and operational resilience.
·
Ensure cybersecurity frameworks align with recognised
industry standards (e.g. ISO 27001, NIST, CIS Controls).
·
Oversee cyber risk management, security operations,
vulnerability management, identity and access management, and threat
intelligence.
·
Ensure effective incident response, cyber crisis
management, disaster recovery, and post-incident reviews.
·
Monitor emerging cyber threats and technology risks,
recommending strategic initiatives to strengthen the organisation's security
posture.
·
Oversee cybersecurity awareness programmes to foster a
security-conscious culture across the organisation.
·
Report cybersecurity risks, key metrics, and incidents
to senior management and the Board.
Compliance
Management
·
Lead the Group's compliance function covering business,
regulatory, and corporate compliance.
·
Develop and maintain enterprise-wide compliance
frameworks, policies, and governance standards.
·
Ensure compliance with all applicable laws, regulations,
licensing obligations, and industry requirements.
·
Oversee regulatory engagement, inspections, audits, and
reporting obligations.
·
Monitor regulatory developments and assess business
impact.
·
Establish compliance monitoring, investigations, and
remediation programmes.
·
Ensure appropriate governance over conflicts of
interest, ethical conduct, anti-bribery, whistleblowing, and corporate
governance practices.
Governance
& Board Advisory
·
Advise the CEO, Executive Leadership Team, and Board on
enterprise risks, cybersecurity, governance, and regulatory matters.
·
Serve as the management liaison to the Board Risk
Committee and other governance committees.
·
Ensure Board reporting provides meaningful insights into
the Group's overall risk profile.
·
Recommend strategic improvements to governance
frameworks, internal controls, and organisational resilience.
·
Promote strong risk governance and accountability across
all business units.
Internal
Controls & Assurance
·
Strengthen enterprise-wide internal control frameworks
to minimise operational and compliance risks.
·
Oversee risk and compliance monitoring activities and
ensure timely remediation of identified gaps.
·
Collaborate closely with Internal Audit while
maintaining appropriate independence of assurance functions.
·
Ensure corrective action plans are effectively
implemented and monitored.
Regulatory
& Stakeholder Management
·
Build and maintain trusted relationships with
regulators, industry bodies, auditors, external advisors, and key stakeholders.
·
Represent the organisation during regulatory reviews,
audits, and compliance assessments.
·
Support regulatory submissions, licensing requirements,
and governance reporting.
Strategic
Leadership
·
Develop and execute the Group Risk & Compliance
strategic roadmap aligned with corporate objectives.
·
Lead organisational transformation initiatives relating
to governance, risk, compliance, and cybersecurity maturity.
·
Drive continuous improvement through digitalisation,
automation, data analytics, and emerging technologies.
·
Establish enterprise risk indicators (KRIs), compliance
metrics, and cybersecurity performance dashboards.
·
Foster collaboration across business units to embed
effective risk management and compliance practices.
Leadership
& People Management
·
Lead, mentor, and develop high-performing Risk,
Compliance, and Cybersecurity teams.
·
Build organisational capabilities through succession
planning, coaching, and continuous learning.
·
Promote a culture of integrity, accountability,
transparency, and responsible risk-taking.
·
Manage departmental budgets, resources, and strategic
priorities to ensure effective delivery
WHAT
DOES IT TAKE TO BE SUCCESSFUL
Qualifications
·
Bachelor's Degree or higher in
Risk Management, Information Security, Cybersecurity, Business, Finance, Law,
Accounting, or a related discipline.
·
Professional certifications
such as CRISC, CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, CPA, CA,
CIA, CAMS, or equivalent are advantageous.
Work
Experience
·
15+ years of progressive
leadership experience in Enterprise Risk Management, Cybersecurity, Compliance,
or Governance.
·
8+ years in a senior
leadership or executive role.
·
Experience leading
enterprise-wide governance programmes within a large corporate, financial
services, technology, fintech, or regulated industry.
·
Proven experience engaging
Boards, Executive Committees, regulators, and external auditors.
·
Strong understanding of
cybersecurity governance, enterprise risk management, regulatory compliance,
and corporate governance frameworks.
·
Experience leading
organisational transformation and enterprise-wide change initiatives.
Skills
& Competencies
·
Demonstrates strong strategic
leadership with the ability to align enterprise risk, cybersecurity, and
compliance strategies with the Group's business objectives.
·
Possesses deep expertise in
enterprise risk management, cybersecurity governance, regulatory compliance,
corporate governance, and internal control frameworks.
·
Exhibits sound commercial
acumen and exercises independent judgment in managing complex risks and making
strategic decisions.
·
Builds trusted relationships
and effectively influences the Board, Executive Management, regulators,
auditors, and key stakeholders.
·
Leads and inspires
high-performing teams while fostering a culture of integrity, accountability,
collaboration, and continuous improvement.
·
Communicates complex risk and
compliance matters clearly and effectively to both technical and non-technical
audiences.
·
Demonstrates resilience,
adaptability, and sound crisis management capabilities in a dynamic and
evolving business environment.
·
Upholds the highest standards
of ethics, professionalism, and governance while driving sustainable business
performance.