Title: Head of Risk Management Framework
Department: Risk Management
Location: Riyadh
Core Responsibilities:
- Ensures that Operational Risk and Resilience Risk is integrated into the Risk Management and Governance process of the Bank by ensuring that SAB’s Operational Risk Management Framework (ORMF) is fully in line with “Three Lines of Defence ‘Model prescribed by the Basel Committee on Banking Supervision (‘Basel Committee). To ensure that this model is continually effective so that it promotes an operational and resilience risk culture through transparency, ownership and accountability, identifies and mitigates material risks, creates an environment to immediately recognize emerging risks at every level of the organisation that meets local regulator, expectations and SAB standards.
- The Head of ORR plays a critical role in developing, implementing, and overseeing the non-financial risk framework and core elements of the enterprise-wide risk management program for SAB. This role is responsible for identifying, assessing, and mitigating risks that may impact the organization's financial stability, reputation, operational and strategic objectives. The Head of ORR is responsible for leading the CRO updates at the Audit Committee, presenting papers at the Board and Risk Management Committee and chairing the Operational Risk Committee. This role will have significant responsibility for developing Risk Management tools, practices, and policies to analyse and report enterprise risks, and to manage risks according to an enterprise risk management framework. The role holder will be expected to establish the Risk Management architecture for the firm as well as oversee and monitor operational risk management activities.
-
The role holder will be experienced in engaging with senior business leaders by monitoring and analysing risks and reporting these risks as well as providing key input to ensure alignment with the firm's objectives.
-
The purpose of the role is to direct effective identification, assessment, management, monitoring, and mitigation of risk across all current and potential future risk types within SAB by ensuring the ‘Three Lines of Defence’ model is adopted. The Head of ORR is responsible for protecting the business through appropriate risk management discipline; ensuring risks are captured, understood and clearly communicated to key internal and external stakeholders, as required. The role is responsible for enabling the business to execute growth strategies within the Risk Appetite of the Bank, acting as the single point of contact on all risk issues for the SAB Chief Risk Officer.
-
The role has been recently expanded to include Management of Insurable risks bank-wide and establishment of Data Protection Office to comply with SDAIA’s Personal Data Protection Law (PDPL) requirements.
- Insurable Risk – Insurable Risk Unit will work with First line risk owners and understand their specific insurable risk needs e.g. HR for employee medical and life cover, COO for property and liability cover, Company secretary for Director coverage and WBP for retail product mandated cover.
- Insurable Risk Function will manage insurance provider selection and contract negotiation, claim management, invoice processes.
- Second line Risk steward to maintain insurable risk policy, review and challenge appropriateness of business cover and analysis to insure/self-insure. Steward views to be incorporated into business submissions of insurance coverage needs for approval. They will coordinate an insurance coverage review to ensure the appropriateness and adequacy of insurance coverage for SAB, highlighting gaps for review (e.g. Marsh review) as per SAMA regulation of ‘Management of Operational Risk through Insurance schemes’. The review output will form part of the annual review of bank-wide insurable risk activities that feeds into RMC, Board Risk Committee and Board of Directors Meeting.
- The Operational and Resilience Risk (ORR) Department are accountable for managing and overseeing the PDPL compliance and enforcement bank-wide for SAB customers, employees, and operations. The ORR Team have appointed a Data Protection Officer (DPO) who is accountable for monitoring the implementation of PDPL requirements.
- Global privacy concerns, alongside increased regulations and public awareness, are shaping a new standard of privacy compliance in the KSA, driven by the Personal Data Protection Law (PDPL). This law appoints the Saudi Authority for Data and Artificial Intelligence (SDAIA) as the regulatory body for Personal Data protection. This law applies to all organizations established in the kingdom that process Personal Data of individuals and all organizations established the kingdom that processes Personal Data of individuals residing in the kingdom. The Law & implementation was published based on the Royal Decree no. (m/19) / Royal Decree no. (m/148).
- The Saudi data protection regulatory environment has experienced significant changes over the past 5-year period. In support of the Kingdom’s Vision 2030, a national data and Artificial Intelligence (AI) strategy has been developed and the National Data Protection Laws were published in September 2021. Following amendments to the regulation, PDPL and its Implementing Regulation have been in effect on September 14, 2023. Organizations have a one-year grace period to comply with the KSA PDPL prior to September 15, 2024. This law aims to protect individuals' personal data, guarantee their rights, and defines the obligations controllers must fulfill to comply with its provisions.
Qualifications and Requirements:
- Bachelor’s degree in Business Administration, Finance or a related field.
- 10 years of relevant experience