About You
The Head of Governance, Risk & Compliance leads the Group's second line of defence. The role is responsible for designing, implementing and maintaining an integrated governance, risk management and compliance framework that enables the organisation to achieve its objectives within an agreed level of risk, in accordance with applicable laws, regulations and corporate governance standards.
The role provides independent oversight and challenge to the first line, which retains ownership of risks and controls, and operates separately from internal audit, which provides independent assurance as the third line.
Your Day-to-Day
Corporate Governance
- Maintain the Group governance framework, including board and committee terms of reference, meeting calendars and standards for papers, minutes and decision records.
- Maintain the delegation of authority and approval matrix and cascade it to subsidiaries and joint ventures.
- Administer the conflicts of interest and related party transaction regime, including registers, declarations and pre-approval processes.
- Maintain the Group policy framework, including ownership, review cycles, version control, communication and attestation.
- Support the Company Secretary on subsidiary governance and statutory compliance.
Enterprise Risk Management
- Design and operate the enterprise risk management framework in line with recognised standards such as COSO ERM or ISO 31000.
- Maintain the risk taxonomy, risk register and risk assessment methodology, and facilitate risk identification across business units and functions.
- Develop and maintain the risk appetite statement and associated tolerance thresholds, and monitor performance against them.
- Prepare periodic risk reporting to executive management, the Risk Committee and the Board, including principal and emerging risks.
- Maintain the business continuity management and crisis management framework, including testing and post-incident review.
- Coordinate the Group insurance programme in conjunction with Finance.
Regulatory Compliance
- Maintain the regulatory obligations register and licence inventory across all jurisdictions and business lines, with assigned accountable owners.
- Design and operate the compliance monitoring and testing programme, including exception reporting and remediation tracking.
- Own the anti-bribery and corruption programme, including risk assessment, third-party due diligence, gifts and hospitality, and adequate procedures documentation.
- Own anti-money-laundering and counter-terrorist financing compliance where applicable to the Group's activities.
- Own the data protection and privacy programme, including data protection officer duties, records of processing, breach response and cross-border transfer controls.
- Own the whistleblowing framework, including intake, triage, investigation protocol, case management and reporting.
- Design and deliver the compliance training and awareness curriculum, and track completion.
- Manage regulatory engagement, notifications and correspondence in coordination with Legal.
Internal Control
- Maintain the internal control framework and control library across key business processes.
- Coordinate management self-assessment of controls and the annual internal control representation process.
- Track remediation of control deficiencies identified by internal audit, external audit, regulators and management, and report status to the relevant committee.
- Support preparation of the annual internal control and risk management statement and related disclosures.
Reporting and Committee Support
- Prepare governance, risk and compliance reporting to executive management, the Audit Committee, the Risk Committee and the Board.
- Act as secretariat to the management risk and compliance committee where one exists.
- Escalate material risk, compliance and conduct matters in accordance with the escalation protocol.
Leadership and Culture
- Lead, develop and resource the governance, risk and compliance team, and manage the function's budget.
- Build risk and compliance capability in the first line, including a business partner or champion network.
- Promote a culture of integrity, accountability and appropriate risk-taking across the organisation.
- Manage external advisers and co-sourced specialists engaged by the function.
Your Know-How
Essential
- Bachelor's degree in law, accounting, finance, business or a related discipline.
- Ten to fifteen years of relevant experience in governance, risk management, compliance, internal audit or regulatory practice, including at least five years in a leadership role.
- Demonstrated experience designing and implementing enterprise risk management and compliance frameworks.
- Sound knowledge of applicable corporate governance codes, listing requirements and relevant legislation, including anti-bribery, anti-money-laundering and data protection.
- Experience reporting to board level and to board committees.
- Experience operating across multiple jurisdictions or legal entities.
- Strong written and verbal communication skills, including report and paper drafting.
Desirable
- Professional certification such as CIA, CRMA, CPA, CA, ACCA, CCEP, CRISC, CISA, CIPP or a recognised risk management qualification.
- Experience in a listed environment or in a company undergoing an initial public offering.
- Experience in a regulated industry, particularly financial services.
- Experience with governance, risk and compliance technology platforms and data analytics.
- Experience managing investigations and forensic engagements.
- Regional or multinational experience relevant to the Group's footprint.