About the role
Enterprise Risk Management
Own and maintain the enterprise risk register and departmental risk registers, ensuring risks are identified, assessed, owned, and managed across financial, operational, regulatory, and technology domains.
Facilitate risk and control discussions with business unit and function heads; challenge risk ratings and mitigation plans.
Support the Director of Risk & Control in setting and monitoring the Board-approved risk appetite framework and key risk indicators (KRIs).
Prepare risk MI and reporting packs for senior management.
Internal Control Framework
Design, document, and test the internal control framework across key financial and operational processes, aligned to a recognised model (e.g. COSO Internal Control – Integrated Framework).
Lead control testing cycles, track deficiencies, and manage remediation plans to closure with clear ownership and deadlines.
Act as the primary control-function liaison for the reporting accountant and external auditors on control matters, coordinating information requests and walkthroughs.
Team & Stakeholder Leadership
Line-manage the Risk & Control Manager, setting objectives, reviewing output quality, and building technical capability within the team.
Act as a trusted second-line partner to Finance, Legal, and Commercial leadership, providing pragmatic, risk-based advice rather than pure gatekeeping.
Maintain a clear and cooperative interface with the Head of Internal Audit (third line), respecting the independence of the audit function while ensuring management actions on audit findings are tracked through the risk and control framework.