Job Summary
•This role could be based in India and Malaysia. When you start the application process you will be presented with a drop down menu showing all countries, Please ensure that you select a country where the role is based.
•The T&O Risk & Governance (R&G) team has dedicated, client-centric R&G expertise to drive proactive risk identification and remediation outcomes for critical domain areas across T&O and also specialised capabilities to provide streamlined risk management support, ensuring that risks are governed, assessed, mitigated, and reported consistently.
•The Head of Risk Management is a senior leadership role within the T&O R&G function, accountable for leading the Technology & Architecture risk management portfolio and delivering a proactive, forward-looking risk and control agenda across the supported domains, in line with the T&O risk strategy.
•This role ensures that risk frameworks, governance routines, and control programmes are effectively embedded within the First Line of Defence across Technology & Architecture, enabling the organisation to anticipate, assess, and mitigate risks. The role provides oversight and effective challenge, drives timely issue identification and remediation, and escalates material risks as required, in alignment with the Enterprise Risk Management Framework (ERMF), Principal Risk Type Frameworks, and the Group’s risk appetite.
•The role supports proactive identification of emerging and horizon risks, governs risk exposure, drives issue remediation, and leads portfolio-level audit and regulatory engagement for Technology & Architecture. The individual partners closely with Technology & Architecture leadership teams and key stakeholders across Technology and Operations (T&O), as well as first- and second-line risk functions and relevant governance bodies, to ensure risk considerations are embedded into transformation initiatives and operational decision-making.
Strategy
•Set the Technology & Architecture risk management direction and priorities, aligned to the T&O R&G strategy, ensuring risks are identified, assessed, mitigated, and governed effectively.
•Ensure effective implementation of the Enterprise Risk Management Framework (ERMF) and Principal Risk Type Frameworks across Technology & Architecture, in line with the Group’s risk appetite, policy requirements, and governance standards.
•Drive the proactive identification and assessment of emerging and horizon risks, ensuring timely escalation and coordinated mitigation plans with Technology & Architecture stakeholders.
•Provide risk oversight and effective challenge to key transformation and modernisation efforts Technology & Architecture, ensuring risk management is embedded into delivery governance and key decisions.
•Champion risk-informed decision-making by leveraging risk insights, metrics, and analytics to improve risk awareness, prioritisation, and responsiveness across Technology & Architecture.
Business
•Partner with Technology & Architecture leadership teams to strengthen risk culture and ensure risk considerations are integrated into day-to-day operations, strategic change, and key delivery decisions.
•Oversee risk assessments and control testing processes, ensuring that risks are appropriately identified, evaluated, and addressed:
•Risk and Control Self-Assessments (RCSAs): Ensure timely completion of annual RCSA reviews and top-down risk assessments, ensuring an accurate reflection of the risk landscape.
•Threat Scenario Led Risk Assessments (TSRAs): Drive structured TSRAs to evaluate risks across Technology & Architecture.
•Provide risk-based advice and challenge to senior stakeholders, enabling effective risk mitigation and well-informed decision-making.
•Partner with first- and second-line risk functions to ensure a coordinated approach to risk management, risk mitigation, and remediation.
•Lead and coordinate audit and regulatory engagements, ensuring timely and high-quality responses to internal audit, external assurance reviews, and regulatory inquiries, with escalation and alignment as required.
•Oversee the risk-driven management of transformation programmes, ensuring that change risk is effectively governed and mitigated across major initiatives.
Processes
•End to End Risk Management: Lead execution of end-to-end risk management activities across supported domains, including RCSA execution, control mapping, ERR lifecycle management, and risk appetite monitoring. Support the proactive identification, assessment, and treatment of risk and control gaps, strengthening self-identification of issues and improving Issues Known to Management (IKTM) and Non-Financial Risk Index (NFRI) performance.
•Risk Governance & Committee Management: Provide facilitation and support for relevant T&O risk forums and committees, including preparation and socialization of committee materials, paper development support, and tracking of actions and outcomes.
•Risk Insights & Decision Support: Produce key risk and control MI, analytics, and dashboards. Support development and refinement of KCIs, KRIs, and other key metrics and associated risk data taxonomies and schemas.
•Incident, Crisis & Disruption Risk Support: Provide comprehensive risk management support during operational incidents, crisis situations, and service disruptions across supported domains. Activities include conducting incident risk assessments and managing escalation protocols, crisis governance participation, post-incident reviews, and supporting regulatory notification and reporting efforts.
•Risk Advisory: Provide ongoing checking and challenge of risk and control posture across supported domains. Support the development and refinement of control standards, provide control design guidance and quality assurance, and promote consistent adoption of risk and control practices across 1LoD.
•Material Change & Programme Risk Assurance: Provide key risk oversight and assurance for material change initiatives, technology programmes, and strategic platform and infrastructure initiatives across supported CIO domains. Activities include diagnostic reviews, programme and change risk assessments, operational readiness, cutover assurance, and risk support.
•Regulatory & Audit Risk Management: Provide support for regulatory engagements, audit readiness, and remediation activities across supported domains. Includes provision of domain subject-matter expertise into regulatory responses, RFIs, issue and action tracking across regulatory, GIA, and 2LoD findings, and monitoring of regulatory obligations to support timely closure of issues and sustained compliance.
People & Talent
•Lead and develop a high-performing team (and/or team of managers), with clear accountabilities and effective coverage.
•Drive a culture of accountability, risk awareness, and continuous improvement across risk teams, ensuring alignment with Group risk expectations.
•Develop and retain talent through coaching, performance management, and development planning, ensuring strong succession and capability within the portfolio.
•Champion diversity and inclusion, ensuring that risk teams reflect a broad range of perspectives and experiences.
Risk Management
•Embed proactive risk identification and mitigation practices, ensuring risk is managed at both a structural and operational level.
•Ensure risk frameworks and risk appetite parameters are well understood and applied within risk management activities.
•Drive the zero overdue mandate for risk remediation, ensuring that all high-risk issues are addressed and closed within agreed timelines.
•Partner with key leaders across Technology and Operations (T&O) to ensure that risk considerations are embedded into all business decisions.
•Ensure that key risks are monitored, measured, and reported in a structured, transparent manner, enabling senior leadership and governance bodies to take appropriate risk-based decisions.
Governance
•Oversee risk governance structures, ensuring that Technology & Architecture’s risk exposure is well-managed within governance forums.
•Provide transparent and high-quality risk reporting to governance committees, senior leadership, and regulatory bodies, ensuring clear visibility into the risk landscape.
•Ensure that risk forums and governance activities align with the Group’s broader risk governance framework
•Lead and oversee function-specific risk governance forums, ensuring risk issues, control gaps, and remediation plans are actively monitored and actioned.
Regulatory & Business Conduct
•Display exemplary conduct and live by the Group’s Values and Code of Conduct.
•Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
•Lead the function to achieve the outcomes set out in the Bank’s Conduct Principles: [Fair Outcomes for Clients; Effective Financial Markets; Financial Crime Compliance; The Right Environment.] *
•Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters
•Provide timely and accurate risk & control information to support regulatory meetings and RFIs.
Key stakeholders
•Group Head, Technology & Operations
•CIO, Technology & Architecture
•Domain CIOs
•Global Head, T&O Risk & Governance and Management Team
•Group and Functional Risk leadership (including GCRO organisation, as required)
•Global Head of OTCR and Management Team
•T&O Management Team (MT) Members and their teams
•Risk Officers across all businesses and functions
•Group Internal Audit (GIA)
•Regulatory Liaison Team