|
|
Responsible coordinating and executing the enterprise risk management cycle: risk assessment, risk and control self-assessment, risk register maintenance, risk appetite monitoring, incident management and key risk indicator reporting across all departments.
Enterprise Risk Management
- Coordinate and execute risk assessments across all business functions, applying the company risk management process (Communication & Consultation, Establish Context, Risk Assessment, Risk Treatment, Monitoring & Review, Recording & Reporting) exactly as defined in the ERM Framework.
- Act as custodian of the enterprise risk register: maintain, update and control version integrity, ensuring all risk categories are captured with appropriate risk indicators, inherent and residual ratings against the approved 5x5 matrix (Impact: Minor to Critical; Likelihood: Unlikely to Almost Certain) and control effectiveness ratings (Effective to No Controls).
- Quality-assure risk register submissions received from risk owners, applying the standards set in the ERM Framework, and require rework where submissions do not meet those standards.
- Facilitate risk and control self-assessments (RCSAs) across business processes and departments, and track actions to address identified control deficiencies through to closure.
- Execute the risk escalation process as defined in the ERM Framework, including escalation where risk owners fail to advance, manage or provide assurance on mitigation of assigned risks.
- Maintain and report on key risk indicators (KRIs) and key control indicators (KCIs) against thresholds approved by the Manager: Risk and Compliance, providing early warning of emerging risk trends.
- Plan, schedule, facilitate and document risk workshops and risk assessment sessions across the annual assessment calendar.
Incident and Risk Event management
- Coordinate the incident management process end to end, ensuring timely identification, logging, escalation, root cause analysis and remediation tracking of risk events.
- Maintain the incident register as the system of record, ensuring all risk events are accurately recorded with corrective actions and closure evidence.
- Analyse incident trends to identify systemic risks, recurring failures or process weaknesses, and submit recommendations to the Manager: Risk and Compliance.
- Facilitate and document post-incident reviews and lessons-learned exercises, and ensure findings are reflected in the risk register. Reviews of material incidents are chaired by the Manager: Risk and Compliance.
- Collate risk events and corrective actions taken for inclusion in governance
Business Continuity Management
- Coordinate the operational delivery of the BCM programme under the direction of the Manager: Risk and Compliance, who owns the BCM framework.
- Conduct and coordinate Business Impact Analyses (BIA) across critical business functions, including pension payments, benefit lump sum processing, data and contributions collection and member records maintenance.
- Draft and maintain the Business Continuity Plan (BCP) and, in collaboration with the IT department, the Disaster Recovery Plan (DRP), for review and approval by the Manager: Risk and Compliance.
Risk Information Management and Reporting
- Consolidate risk information across functions and governance structures, identifying priority focus areas and tracking progress against agreed actions.
- Produce internal risk reports to the cadence defined in the ERM Framework, ensuring information is timely, accurate and decision useful.
- Prepare risk inputs for monthly EXCO reporting, RMC meetings, and quarterly ARC and Board reporting, for consolidation and sign-off by the Manager: Risk and Compliance.
- Analyse new and amended legislation to determine impact on the risk profile, and report findings to the Manager: Risk and Compliance.
Stakeholder Support, Training and Risk Awareness
- Provide technical direction and day-to-day guidance to the risk champion network across all departments, including risk register updating, action plan coordination and application of escalation procedures.
- Deliver risk awareness and capacity-building sessions to staff and risk owners against the awareness calendar and using material owned and approved by the Manager: Risk and Compliance.
- Build and maintain constructive working relationships with business units, acting as the first point of contact for operational risk queries.
- Respond to operational information, evidence and data requests from Internal Audit and External Audit.
- Planning-level engagement and management of the combined assurance model rest with the Manager: Risk and Compliance.
To apply immediately for this position click here.
|
|
|
Minimum Requirements
- A relevant Degree in Risk Management, Commerce, Finance, Internal Audit, Governance or a related discipline (NQF Level 7 minimum).
- An Honours degree or Postgraduate Diploma in Risk Management, Governance or Internal Auditing is advantageous.
- Professional membership or certification — IRMSA, Certified Internal Auditor (CIA) or CISA (ISACA) — is advantageous.
- Minimum 3 to 5 years’ experience in risk management, governance and/or internal audit within financial services, preferably pension fund administration or the retirement fund industry.
- Demonstrated experience conducting risk assessments, maintaining risk registers and producing risk reporting.
- Experience in business continuity management (BIA, BCP, DRP testing) is advantageous.
Knowledge & Skills
- Strong knowledge of FAIS, FICA, POPIA, Pension Funds Act, and regulatory frameworks
- ISO 31000 / SANS 31000:2018 principles and their practical application.
- Enterprise risk management methodologies, including RCSA, incident management, KRI/KCI frameworks, risk appetite and tolerance models, and combined assurance.
- King V governance principles as applied to risk management.
- Strong stakeholder engagement and interpersonal skills
- Ability to work independently and within a team environment
- Data analysis and interpretation for risk reporting.
- Report writing — clear, concise risk reports and dashboards suited to varied audiences.
- Planning, scheduling and coordination of concurrent workstreams across multiple departments.
- Analytical thinking and attention to detail.
- Computer literacy, including the MS Office Suite.
|