The Head, Enterprise Risk & Audit is responsible for overseeing and strengthening Risk Management & Internal Audit across regional operations. This senior leadership role ensures operational excellence, regulatory compliance, and effective risk mitigation at a regional level.
The role focuses on driving process optimization, enhancing internal control frameworks, and fostering a strong risk-aware culture across the organisation. It requires close collaboration with regional leadership teams and global stakeholders to ensure alignment with organisational objectives while addressing region-specific challenges and regulatory requirements.
PRIMARY DUTIES AND RESPONSIBILITIES
1. Risk Management
- Develop and execute an integrated risk management strategy providing regional oversight of operational, regulatory, financial, and strategic risks. Ensure alignment with global risk governance standards and embed risk awareness into day-to-day decision-making processes.
- Identify, assess, and monitor key risks across the region, enabling timely escalation and mitigation. Drive forward-looking risk intelligence through data analysis, scenario planning, and stakeholder engagement to support proactive decision-making and business continuity.
- Promote a risk-aware culture by embedding accountability at all levels of the organisation. Provide guidance, tools, and training to enable leaders and teams to manage risk effectively.
- Maintain close oversight of the evolving regulatory landscape across jurisdictions. Ensure timely updates to policies and procedures in line with legal requirements and corporate standards. Represent the region in risk-related reviews, audits, and regulatory engagements.
- Identify opportunities to improve efficiency and reduce costs across risk management activities. Ensure risk management is value-adding, data-driven, and aligned with broader business objectives.
- Ensure compliance with applicable data protection regulations such as PDPA and GDPR. Oversee data governance, privacy impact assessments, policy development, staff training, incident response, and engagement with regulators and data subjects.
2. Internal Audit
- Design and implement effective internal control frameworks to ensure regulatory compliance, safeguard organisational assets, and reduce exposure to risk.
- Lead and coordinate internal audit activities across the region, ensuring audits are conducted effectively, independently, and in accordance with internal audit standards.
- Streamline audit and compliance processes to eliminate inefficiencies and enhance consistency across the organisation.
- Leverage integrated assurance processes such as internal audits, risk assessments, compliance reviews, and certification management (e.g., ISO 27001 where applicable) to strengthen governance and control environments.
- Collaborate with internal audit and compliance teams to identify gaps, assess control effectiveness, and drive remediation actions.
- Ensure timely closure of audit findings and monitor implementation of corrective and preventive actions.
- Provide independent assurance to senior management and support audit committee reporting as required.
JOB REQUIREMENTS
- Bachelor’s degree in Engineering, Finance, Risk Management, Business, or a related field; Master’s degree or MBA preferred.
- Minimum 10 years of experience in senior leadership roles within Risk Management and/or Internal Audit, including regional exposure.
- Proven track record in developing and executing risk management frameworks, strengthening internal controls, and ensuring regulatory compliance.
- Strong knowledge of regional regulatory frameworks, governance standards, and internal audit best practices.
- Demonstrated leadership experience in managing cross-functional teams, driving cultural change, and influencing stakeholders.
- Excellent communication, presentation, and analytical skills, with strong problem-solving capabilities.
- Relevant certifications are highly desirable (e.g., CPA, CIA, CISA, CRMA, or ISO-related certifications).
- Flexibility to work beyond regular hours when required.