Assistant Manager, Enterprise Risk Management
Touch 'n Go Group · Federal Territory of Kuala Lumpur, Malaysia
Apply & track with Apply EdgeWe fuel the ideas and ambitions of our people with an environment built on Our DNA of Love, Entrepreneurship, Agility, and Passion – LEAPWe are a culture that empowers everyone to innovate and create solutions that will leave a positive impact on our communities and our nation, Touch ‘n Go will always be here to inspire our talents to grow as leaders and innovators giving you the power to make a difference.What would you do?Enterprise Risk Management (ERM)Support the implementation, enhancement and continuous enhancement of the Company's Enterprise Risk Management Framework, policies, standards, methodologies and practices.Facilitate enterprise-wide risk identification, assessment, monitoring and reporting activities to ensure key risks are effectively managed.Assist business units in conducting Risk and Control Self-Assessment (RCSA) and provide independent challenge on identified risks, controls and mitigation plans.Conduct risk profiling, trend analysis and thematic reviews to identify emerging, strategic and cross-functional risks that may impact the Company's objectives.Perform assessment and periodic review of Emerging Risks and Strategic Risks and provide recommendations to Management on risk treatment strategies.Prepare, consolidate and analyse risk reports, dashboards and presentations for Management, MARCC and Board Committees.Support the periodic review and enhancement of risk management policies, procedures, guidelines and governance documents.Operational Risk Management (ORM)Support the implementation and administration of Operational Risk Management processes, tools and methodologies.Oversee and monitor ORM activities including Risk and Control Self-Assessment (RCSA), Control Effectiveness Testing (CET), Control Issue Management (CIM), Loss Event Data (LED) and Incident Management.Review and validate operational risk data submissions to ensure completeness, accuracy and quality of information reported by business units.Conduct independent Control Effectiveness Testing (CET) and validation exercises as part of the second line of defence.Monitor operational risk incidents, losses, control weaknesses and remediation actions, and escalate significant concerns to Management where necessary.Analyse operational risk trends, root causes and key risk indicators to support proactive risk management and decision-making.Support regulatory and management reporting requirements relating to operational risk and loss event reporting.Project Risk Management & AssessmentAct as the Second Line of Defence in reviewing and challenging Risk Assessments for new products, projects, system implementations, strategic initiatives, process changes and significant business activities.Facilitate and review project risk assessments to ensure key legal, regulatory, operational, technology, cybersecurity, data privacy, financial, reputational risks and other relevant risks are adequately identified and assessed.Evaluate the adequacy of existing and proposed mitigating controls and provide recommendations to strengthen risk management controls and governance.Perform Pre-validation reviews prior to project or product implementation to assess readiness, completeness and effectiveness of approved risk mitigation actions before Go-Live.Perform Post-Implementation Reviews (PIR) for approved Risk Assessments to validate implementation status and effectiveness of mitigating controls, identify control gaps and recommend corrective actions where necessary.Monitor and track implementation of risk treatment actions arising from approved Risk Assessments.Maintain and monitor the Risk Assessment repository and ensure timely review, reporting and escalation of key project risk issues.Risk Governance & MARCC SecretariatServe as Secretariat for the Management Audit, Risk and Compliance Committee (MARCC) and any special MARCC meetings.Coordinate MARCC meetings, including annual meeting schedules, meeting logistics and stakeholder engagement.Prepare meeting agendas and coordinate submission and circulation of papers, risk reports and presentation materials for MARCC review with business units.Record, prepare and finalise accurate meeting minutes, resolutions, decisions and action items arising from MARCC meetings.Ensure timely circulation of meeting notices, papers, minutes and action trackers to committee members and relevant stakeholders.Monitor and track closure of MARCC action items and provide status updates to Management and the Committee.Prepare briefing notes and key risk insights for the Chief Risk, Regulatory and Compliance (CRCGO) Officer highlighting significant discussions, decisions, risk concerns and key takeaways arising from MARCC meetings, and present the updates during the monthly Risk Management Division (RMD) post-mortem meeting.Risk Culture, Awareness & TransformationDevelop and conduct risk awareness programmes, workshops, training sessions and knowledge-sharing initiatives to strengthen risk culture across the organization.Provide guidance and advisory support to business units on risk management methodologies, tools and best practices.Promote risk awareness and the consistent application of risk management practices across the organisation.Support risk transformation and continuous improvement initiatives aimed at strengthening risk management capabilities, governance and reporting effectiveness.Monitoring, Reporting & AdministrationMonitor and track closure of audit findings, risk issues and corrective action plans relating to risk management activities.Monitor contracts, vendor arrangements and other risk-related obligations from a risk governance perspective where applicable.Maintain risk documentation, records and repositories to ensure completeness, accuracy and compliance with governance requirements.Undertake any other risk management, governance, reporting or strategic initiatives as assigned by Management from time to time.Who should join us?Bachelor's Degree in Risk Management, Finance, Banking, Accounting, Business Administration, Economics, Actuarial Science, Statistics, Data Analytics, Law, Information Technology, Computer Science or other related disciplines.Professional certification in Risk Management (e.g. ISO 31000, ERM Professional, Certified Risk Management Professional (CRMP), Professional Risk Manager (PRM), Financial Risk Manager (FRM), Certification in Risk Management Assurance (CRMA), or related disciplines would be an added advantage.Minimum 4-6 years of relevant experience in Risk Management, ERM, ORM, Internal Audit, Compliance, Governance or related fields, preferably in the financial services industry.Strong knowledge and understanding of Enterprise Risk Management (ERM), Operational Risk Management (ORM), Project Risk Assessment, risk governance principles and regulatory requirements.Strong analytical, critical thinking and problem-solving skills with the ability to identify, assess and evaluate risks and control effectiveness.Ability to conduct risk assessments, challenge risk assumptions, identify control gaps and recommend practical risk mitigation measures.Our Perks & Benefits:Hybrid work arrangement and flexi hours.e-Wallet meal allowance.Unlimited office pantry fruits, snacks and drinks.Mobile and broadband subscription reimbursement.Flexibility to opt dependents coverage (spouse, child, parents or parents-in-law) for outpatient medical benefits.Additional leave including family leave and paid care leave to care for family members.Medical coverage including dental, optometrist, mental care, maternity, registeredTraditional Chinese Medicine (“TCM”) and Chiropractic.Corporate membership discount and many more to explore.We believe that you have what it takes to fit into the Touch ‘n Go family and help revolutionize the Fintech industry by paving the way to a cashless society. If you're ready to take the next step, apply now!Touch ‘n Go is an organization that strives to provide Equal Opportunity Employment, based on merit, qualifications, capabilities, and calibre. It is Touch ‘n Go’s policy to not discriminate based on age, race, religion, colour or other personal status, identity or characteristics. Fair Opportunity is Our Value and Practice. Please advise us of any accommodations you may need by e-mailing: careers@touchngo.com.myNote: Only shortlisted candidates will be contacted.