Chief Risk Officer

Position Summary

  • Build and maintain an Enterprise Risk Management and Governance Framework to identify, monitor, manage, and report risks proactively.
  • Provide a forward-looking perspective on risk to local management and the Regional CRO.
  • Analyze complex, multi-source data, recognizing limitations and modelling constraints, to identify critical facts for strategic decision-making.
  • Support profitable and sustainable business growth through risk-informed recommendations.
  • Deliver an integrated view of key risks across all business activities.
  • Translate risk data into actionable insights for senior management, including the CEO and Regional CRO.
Main Responsibilities:

Enterprise Risk Management

  • Responsible for all local and Group regulatory risk topics, including reporting, implementing new regulations, and advising management on implications and value-add opportunities arising from regulatory changes.
  • Adopt Group Risk Management frameworks, with emphasis on Risk Guidelines, to provide an integrated view of financial, investment, technology, operational & insurance risks and recommend mitigation strategies.
  • Conduct ongoing risk self-assessments and maintain the country’s risk profile.
  • Supports the Board of Directors in evaluating the adequacy and effectiveness of the internal control and risk management system, providing appropriate information and assessments, as well as recommendations for suitable mitigation of current or forward‑looking risks.
  • Coordinate & conduct risk management process & dialogue by liaising with risk owners i.e. senior management to ensure the main risks are identified and assessed & reported based on Main Risk Self-Assessment (MRSA) which is part of the Own Risk & Solvency Assessment (ORSA) Guideline
Operational Risk Management
  • Coordinate & conduct regular operational risk management process by liaising with risk owners (i.e. senior management) to ensure effective risk management.
ICT Risk Management
  • Coordinate & conduct technology risk management process across the organisation by implementing BNM Risk Management in Technology & GIMB Technology Risk Management Framework & localised Group Information, Communication & Technology (ICT) Risk Management Framework and ensuring robust controls.
  • Coordinate & conduct risk analysis by liaising with risk owners i.e. senior management to determine Information, Communication & Technology (ICT) risk.
Sustainability
  • Ensure that proposed sustainability & climate-related risk governance enhancements are embedded within control systems.
  • Coordinate & conduct Sustainability risk identification within the MRSA process and provide the GCRO function by means of the BU CRO functions with the related results for Group aggregation purposes as set out in the ORSA Reporting Group Guidelines
Stakeholder Management
  • Lead Board and Executive-level Risk Management Committees by preparing high-quality presentation materials, steering discussions, and ensuring timely follow-up on agreed actions.
Managerial Responsibilities
  • Lead, develop, and retain a high-performing team to achieve productivity and quality standards
  • Promote a performance-driven culture and provide guidance to enable team excellence.
Committee Responsibilities
  • Chairman of Local Risk Management Committee: -
  • Review risk management matters and challenges faced by the Company
  • Ensure the ongoing effectiveness of risk management activities in alignment with the Board's Risk Appetite and endorse and recommend related matters to the Board Risk Management Committee and other appropriate sub-committees.
  • Ensures consistency and continued alignment amongst the control functions and management on transversal topics
  • Oversees deliberation and formalization risk-based decisions within the mandates assigned to Management
  • Member of Business Continuity Management & Occupational Safety & Health Committee
  • Permanent Invitee to Claims Committee
  • Member of Data Governance Committee
  • Permanent Invitee to Executive Committee
  • Permanent Invitee to IT Steering Committee
  • Member of Local Management Audit and Compliance Committee
  • Permanent Invitee to Company Investment Committee
  • Member of Outsourcing & Technology Risk Governance Committee
  • Permanent Invitee to Product & Pricing Committee
  • Member of Reserving Committee
  • Permanent Invitee to Underwriting Committee
  • The Chief Risk Officer is also responsible for
Back to blog