Job Summary:
Provide a high-level overview of the role and its scope.
- Drive technology, data, and product innovation from a risk perspective.
- Play a key role in identifying, assessing, and governing technology, data, and product risk.
- Operate within the 2nd Line Group Risk function, guiding first-line stakeholders on their approach to risk across IT infrastructure, AI, cloud, emerging technologies, and product lifecycle.
- Advise stakeholders at all levels on control effectiveness, providing independent challenge, oversight, and clear risk insight in decision-making related to digitalisation, data, and products.
- Highlight both risks and opportunities in how the business can take informed risks in these areas.
- Act as a trusted business partner, building strong relationships across the organisation as a go-to expert for technology, data, and product risk.
- Collaborate closely with associated business areas and 2nd and 3rd line functions to ensure effective engagement and alignment.
Key Responsibilities:
- Challenge, support, and work with 1st Line teams on risk identification, assessment, and control adequacy across digital and technology processes, as well as data and products.
- Act as a key point of contact for the business, effectively engaging with the 1st Line as a Risk Business Partner.
- Work with the 1st Line to collate and coordinate updates on risk profiles, ensuring aligned reporting for technology, data, and product risk within Group Risk Reporting.
- Support, challenge, and guide the 1st Line through the RCSA process across technology, data, and product risk.
- Act as Group Risk representative on business projects and initiatives, providing challenge and advice as a Risk Business Partner.
- Attend relevant working groups and committees as required.
- Partner with the 1st Line on operational risk event processes, providing guidance, training, and awareness, and ensuring robust remediation actions to strengthen the control environment.
- Support enhancements to the Technology, Data, and Product Risk Control Framework by identifying and embedding key controls across the lifecycle.
- Monitor the implementation of risk controls across business units and functions, gathering feedback to support continuous improvement.
- Coordinate and prepare reports and presentations for governance forums as part of Group Risk Reporting.
- Stay up to date with regulatory developments and wider industry changes, engaging with Group Risk and the wider business to assess impact and implications.
…
