Our client, a real-time payment services company established under the National Payment System (NPS) Act, to address the challenge of inter-bank money transfers in the country and beyond, is seeking to onboard a Manager - Enterprise Risk & Governance.
- The Manager - Enterprise Risk & Governance is responsible for leading enterprise risk management, third-party risk management, audit coordination, operational quality assurance, policy governance, and enterprise risk culture initiatives. S/he will serve as a key second line of oversight to the business, ensuring that enterprise risks are identified, assessed, monitored, mitigated, and reported effectively while supporting regulatory compliance and sound governance practices. The Manager - Enterprise Risk & Governance will need to have strong partnership management ability in order to engage both internal and external stakeholders.
DUTIES & RESPONSIBILITIES
Enterprise Risk Management & Operational Risk
- Operationalize the enterprise risk management framework and Risk Appetite Statement (RAS).
- Conduct quarterly departmental risk register revalidations with business unit heads
- Maintain the enterprise risk heat map and monitor Key Risk Indicators (KRIs)
- Conduct operational procedure quality assurance reviews across key business functions
- Facilitate quarterly enterprise risk deep-dive sessions with business unit heads.
- Establish real-time risk tracking and reporting interfaces across operational units.
- Support identification, assessment, treatment, monitoring, and escalation of enterprise and operational risks.
Third-Party Risk Management & Vendor Governance
- Manage the end-to-end Third-Party Risk Management (TPRM) lifecycle
- Conduct initial and annual risk due diligence assessments for key vendors and third-party partners
- Monitor vendor compliance with contractual Service Level Agreements (SLAs) and applicable security standards
- Maintain an up-to-date TPRM inventory and continuous vendor risk scorecards
- Ensure material third-party risks are appropriately escalated and mitigated.
Audit Liaison & Second-Line Oversight
- Coordinate internal, external, and Central Bank of Kenya (CBK) supervisory audit engagements
- Coordinate audit planning, onsite activities, document requests, interviews, and management responses
- Maintain a centralized audit issue and remediation tracking register
- Monitor business-unit remediation timelines
- Conduct post-remediation validation testing to confirm closure of audit findings.
Policy Governance & Compliance Excellence
- Conduct enterprise-wide policy gap assessments
- Establish baseline compliance maturity assessments across operational units
- Review and remediate outdated, incomplete, or missing enterprise policies
- Coordinate company-wide policy attestation exercises
- Support policy harmonization and legal governance
- Support migration of contract administration to an automated Contract Lifecycle Management (CLM) platform integrated with TPRM processes
Enterprise Risk Culture & Awareness
- Design and deliver annual risk management training covering ERM, AML/CFT, data privacy, and related risk areas
- Establish and coordinate departmental risk champions
- Develop risk accountability and micro-training initiatives
- Conduct quarterly risk awareness and accountability sessions.
Cross-Border & Virtual Asset Risk
- Develop risk controls for regional remittance and cross-border payment channels
- Establish sanctions screening, FX liquidity, credit, and settlement risk controls
- Develop due diligence and vetting frameworks for Virtual Asset Service Providers (VASPs)
- Monitor regional regulatory developments affecting virtual assets and cross-border financial flows.
Risk Appetite & Management Reporting
- Facilitate Management Committee (MCT) calibration workshops on enterprise risks.
- Support identification and prioritization of the Top 5 Enterprise Risks.
- Develop quantitative risk metrics and Green/Amber/Red risk thresholds.
- Back test proposed risk thresholds against historical incident data.
- Establish automated escalation triggers for emerging risk exposures.
- Coordinate the governance process for formal RAS endorsement and Board Audit & Risk Committee (BARC) approval.
- Maintain knowledge of the function, stay abreast with the latest practices, trends, and technologies
- Model best practices in enterprise risk and governance operations and activities in order to ensure maintenance of quality performance
- Update job knowledge by participating in conferences and educational opportunities, reading professional publications, maintaining personal networks, and participating in relevant professional associations
- Maintain quality service and partnerships by establishing and enforcing company policies, procedures, standards, and values
- Put in place proper quality control checks and balances within each operational activity assigned to the function
- Regularly report on key performance indicators (KPIs) for all enterprise risk & governance-led projects and operations, demonstrating progress towards established goals and identifying areas for improvement.
Any other duties as required.
EDUCATION, SKILLS, KNOWLEDGE & EXPERIENCE REQUIRED
- Bachelor's Degree in Risk Management, Finance, Accounting, Business Administration, Economics, Law, Information Systems, or any other related discipline
- Professional qualification in risk, audit, compliance, governance, or a related field.
- Relevant professional certifications such as CRMA, CERM, FRM, CIA, CISA, CPA/ACCA, or equivalent is desirable
- Enterprise risk management and risk framework implementation.
- Operational risk assessment and mitigation.
- Third-Party Risk Management (TPRM) and vendor due diligence.
- Audit coordination, engagement management, and remediation tracking.
- Policy governance, gap assessment, and compliance maturity frameworks.
- Risk appetite and KRI/KPI development and backtesting.
- Regulatory and compliance risk awareness across virtual assets, cross-border channels, and payment systems
- Contract and SLA governance (including CLM platform integration)
- Proficiency in risk management, reporting, GRC, and data-analysis tools
- Risk reporting and executive-level presentation
- Facilitation, workshop delivery, and training skills
- Project and change management skills
- Attention to detail, and sound professional judgment
- Ability to work across multiple business functions and influence stakeholders without direct authority.
- A collaborative working style and a strong business partnering orientation
- Knowledge of applicable laws and regulations within the field of enterprise risk and governance with a strong understanding of business issues and opportunities
- High level of integrity, confidentiality, trust, and dependability with a strong sense of urgency
- Results-oriented, entrepreneurial, self-motivated, self-starter, who is flexible and adaptable to rapid change and has the ability to work in a fast-paced, high-demand environment
- Experience translating KPIs to teams to get buy-in and results
- Strong interpersonal, communication, and presentation skills with a good focus on organization and enhanced multitasking abilities
- Ability to leverage AI systems and tools with a good grasp of enterprise risk & governance management systems
- Ability to communicate information, whether technical or non-technical to stakeholders in a clear and concise manner
- Highly analytical with quantitative risk assessment and strong problem-solving skills.