← WorkMundi · 1M+ jobs from around the world, liveSign inCreate free account

Vice President, ERM Governance & Reporting

Bursa Malaysia Berhad · Kuala Lumpur City Centre, Kuala Lumpur

📅 12/08/2026
🔔 Alert me about jobs like this
No password, no sign-up. Just the email — and you can leave the list anytime.
🔓 Apply — free →
Opens this job on WorkMundi. The account is free and takes under a minute.

See the other 3,702 jobs in Malaysia →

🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
To drive and continuously enhance organisation-wide risk governance through effective implementation of the Enterprise Risk Management (ERM) framework, Corporate Risk Profile, risk monitoring, and reporting. The role acts as a trusted advisor to business and project teams, while driving continuous improvement in risk management practices to support informed decision-making. It supports the implementation of ERM frameworks and methodologies, Third-Party Risk Management (TPRM), Risk and Control Self-Assessment (RCSA), risk capability and culture, legal risk monitoring, SORMIC, regulatory requirements, and other enterprise risk initiatives, ensuring consistency, accountability, and timely execution across divisions. 1. Enterprise Risk Management: Assessment, Monitoring, Reporting and Communication Lead the implementation and execution of the Corporate Risk Profile process, ensuring alignment with the established ERM framework, organisational objectives, and risk appetite. Manage the preparation and delivery of Corporate Risk Profile reports, ensuring timely, accurate, and insightful reporting to management and governing bodies. Oversee the monitoring of enterprise risk exposures and KRIs, including timely escalation of significant risk movements, breaches, and key risk insights. Assess risk exposures and mitigation effectiveness, while tracking mitigation actions and outstanding commitments to ensure timely follow-up and closure. Manage stakeholder engagement across divisions to ensure alignment, completeness, and quality of risk inputs and outputs. Provide independent challenge and quality assurance over risk assessments and Corporate Risk Profile outputs to ensure robustness, completeness, and consistency. Drive continuous improvement of Corporate Risk Profile processes, methodologies, and reporting to enhance consistency and quality across divisions. Coordinate organisation-wide risk assessment and reporting activities, ensuring timely submission and effective execution across divisions. Manage the end-to-end review and approval process for SORMIC, ensuring stakeholder feedback, regulatory requirements, and governance expectations are addressed prior to inclusion in the Annual Report. Provide risk advisory support on strategic initiatives and projects, embedding risk considerations into decision-making. 2. Risk Framework, Policy, Procedures and Methodology Lead the implementation and continuous improvement of the organisation’s ERM framework, policies, procedures, methodologies, and guidelines to support effective and consistent risk management practices across divisions. Manage the periodic review and enhancement of risk-related governance documents, ensuring they remain relevant, practical, and aligned with organisational objectives and regulatory requirements. Oversee the consistent application of risk assessment methodologies, criteria, rating scales, and risk taxonomy across the organisation. Provide guidance and advisory support to business units on the interpretation and application of ERM frameworks, policies, procedures, methodologies, and guidelines. Review the effectiveness of existing risk management processes and methodologies, identifying gaps and recommending improvements to strengthen overall risk management practices. Coordinate enhancements to the organisation’s risk appetite framework, risk assessment criteria, KRIs, and related risk management methodologies. Ensure changes to ERM frameworks and methodologies are effectively communicated and implemented across divisions. Provide independent review and challenge on the application of risk methodologies to ensure consistency, completeness, and quality of risk assessments and outputs. Monitor developments in risk management practices, regulatory requirements, and industry standards, and recommend appropriate enhancements to existing frameworks and methodologies. 3. RCR Management Lead and drive proactive engagement of Risk & Compliance Representatives (RCRs) to strengthen risk awareness, ownership, and accountability across divisions, fostering a consistent and embedded risk culture. Plan, organise, and deliver structured RCR capability development programmes, including education, workshops, training, and refresher sessions. Conduct targeted ad hoc engagements to address emerging risks and reinforce effective and consistent risk management practices across divisions. Define and reinforce RCR roles, responsibilities, and expectations. Gather feedback from RCRs and refine tools, templates, and processes Provide ongoing guidance and advisory support to RCRs on risk matters. Align RCR activities with RCSA, KRI, incident management, and reporting cycles. 4. Risk Culture and Awareness Drive the implementation of organisation-wide risk capability and culture initiatives to strengthen risk awareness, ownership, and accountability across divisions. Develop and execute structured risk capability development programmes, including education, workshops, training, awareness campaigns, and engagement initiatives. Drive proactive engagement of Risk & Compliance Representatives (RCRs) and other relevant stakeholders to strengthen risk awareness, ownership, and accountability, and support effective implementation of risk management practices across the organisation. Assess risk capability and culture through surveys, assessments, feedback mechanisms, and other appropriate measures to identify gaps and opportunities for improvement. Develop and maintain risk management learning materials, communication content, tools, and guidance to support consistent understanding of risk management practices. Conduct targeted awareness and engagement initiatives to address key risk themes, organisational priorities, regulatory developments, and identified capability gaps. Monitor the effectiveness of risk capability and culture initiatives and recommend appropriate actions to strengthen overall risk management maturity. Collaborate with Human Resources, Compliance, business units, and relevant stakeholders to integrate risk considerations into organisational learning and employee engagement initiatives. Promote the sharing of risk insights, lessons learned, case studies, and good practices to strengthen organisational learning and awareness. Drive continuous improvement of risk capability and culture programmes, tools, and engagement approaches to enhance effectiveness and participation across divisions. 5. Risk and Control Self-Assessment (RCSA) Support the end-to-end execution of the RCSA process to ensure consistency, accuracy, and quality of outputs across divisions. Support robust risk identification, assessment, and documentation, including challenge and quality assurance of RCSA outputs. Support the tracking and monitoring of mitigation actions to ensure timely follow-up and closure. Support continuous improvement of RCSA frameworks, methodologies, procedures, questionnaires, and risk registers. Support cross-divisional coordination and stakeholder engagement to ensure alignment, completeness, and quality of risk inputs and outputs. 6. Third Party Risk Management Support the implementation and execution of the TPRM framework, ensuring alignment with organisational risk appetite, regulatory requirements, and internal governance standards. Support third-party risk assessments and due diligence to ensure key risks, control gaps, and mitigation measures are appropriately identified and assessed. Monitor third-party risk exposures and mitigation actions, ensuring timely follow-up, escalation, and closure of identified risks and control gaps. Support stakeholder engagement and reporting to ensure effective oversight, accountability, and ownership of third-party risks across the organisation. Support continuous enhancement of TPRM processes, methodologies, and tools to improve consistency, efficiency, and overall effectiveness. Academic qualifications & professional certificates Bachelor’s degree in business, Finance, Accounting, Risk Management, Information Technology or related discipline. Minimum 8–12 years of relevant experience in risk management, compliance, audit or related functions, preferably within a financial services or regulated environment Strong understanding of Enterprise Risk Management (ERM), risk governance principles, frameworks and practices. Hands-on experience in core Enterprise Risk Management areas, including Corporate Risk Profile, RCSA support, KRI monitoring, risk appetite, risk reporting and SORMIC. Proven experience in engaging with business units and stakeholders to support risk identification, assessment and mitigation Experience in preparing risk reports for Management or committees Strong analytical, communication and stakeholder management skills
Read the rest of the job →

Similar jobs

Job on WorkMundi — the world's largest job board. See more jobs from every continent, updated live.

📢
🎁

Before you apply, rehearse this interview.

Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card.

I want my training →