M
Manager âÃÂàEnterprise Risk & Governance at MAL Consultancy
MAL Consultancy
October 6, 2026
Full-time
On-site
INTRODUCTION
Our client, a real-time payment services company established under the National Payment System (NPS) Act, to address the challenge of inter-bank money transfers in the country and beyond, is seeking to onboard a Manager - Enterprise Risk & Governance.
JOB SUMMARY
The Manager - Enterprise Risk & Governance is responsible for leading enterprise risk management, third-party risk management, audit coordination, operational quality assurance, policy governance, and enterprise risk culture initiatives. S/he will serve as a key second line of oversight to the business, ensuring that enterprise risks are identified, assessed, monitored, mitigated, and reported effectively while supporting regulatory compliance and sound governance practices. The Manager - Enterprise Risk & Governance will need to have strong partnership management ability in order to engage both internal and external stakeholders.
DUTIES & RESPONSIBILITIES
Enterprise Risk Management & Operational Risk
Operationalize the enterprise risk management framework and Risk Appetite Statement (RAS).
Conduct quarterly departmental risk register revalidations with business unit heads
Maintain the enterprise risk heat map and monitor Key Risk Indicators (KRIs)
Conduct operational procedure quality assurance reviews across key business functions
Facilitate quarterly enterprise risk deep-dive sessions with business unit heads.
Establish real-time risk tracking and reporting interfaces across operational units.
Support identification, assessment, treatment, monitoring, and escalation of enterprise and operational risks.
Third-Party Risk Management & Vendor Governance
Manage the end-to-end Third-Party Risk Management (TPRM) lifecycle
Conduct initial and annual risk due diligence assessments for key vendors and third-party partners
Monitor vendor compliance with contractual Service Level Agreements (SLAs) and applicable security standards
Maintain an up-to-date TPRM inventory and continuous vendor risk scorecards
Ensure material third-party risks are appropriately escalated and mitigated.
Audit Liaison & Second-Line Oversight
Coordinate internal, external, and Central Bank of Kenya (CBK) supervisory audit engagements
Coordinate audit planning, onsite activities, document requests, interviews, and management responses
Maintain a centralized audit issue and remediation tracking register
Monitor business-unit remediation timelines
Conduct post-remediation validation testing to confirm closure of audit findings.
Policy Governance & Compliance Excellence
Conduct enterprise-wide policy gap assessments
Establish baseline compliance maturity assessments across operational units
Review and remediate outdated, incomplete, or missing enterprise policies
Coordinate company-wide policy attestation exercises
Support policy harmonization and legal governance
Support migration of contract administration to an automated Contract Lifecycle Management (CLM) platform integrated with TPRM processes
Enterprise Risk Culture & Awareness
Design and deliver annual risk management training covering ERM, AML/CFT, data privacy, and related risk areas
Establish and coordinate departmental risk champions
Develop risk accountability and micro-training initiatives
Conduct quarterly risk awareness and accountability sessions.
Cross-Border & Virtual Asset Risk
Develop risk controls for regional remittance and cross-border payment channels
Establish sanctions screening, FX liquidity, credit, and settlement risk controls
Develop due diligence and vetting frameworks for Virtual Asset Service Providers (VASPs)
Monitor regional regulatory developments affecting virtual assets and cross-border financial flows.
Risk Appetite & Management Reporting
Facilitate Management Committee (MCT) calibration workshops on enterprise risks.
Support identification and prioritization of the Top 5 Enterprise Risks.
Develop quantitative risk metrics and Green/Amber/Red risk thresholds.
Back test proposed risk thresholds against historical incident data.
Establish automated escalation triggers for emerging risk exposures.
Coordinate the governance process for formal RAS endorsement and Board Audit & Risk Committee (BARC) approval.
Operational Excellence
Maintain knowledge of the function, stay abreast with the latest practices, trends, and technologies
Model best practices in enterprise risk and governance operations and activities in order to ensure maintenance of quality performance
Update job knowledge by participating in conferences and educational opportunities, reading professional publications, maintaining personal networks, and participating in relevant professional associations
Maintain quality service and partnerships by establishing and enforcing company policies, procedures, standards, and values
Put in place proper quality control checks and balances within each operational activity assigned to the function
Regularly report on key performance indicators (KPIs) for all enterprise risk & governance-led projects and operations, demonstrating progress towards established goals and identifying areas for improvement.
Any other duties as required.
EDUCATION, SKILLS, KNOWLEDGE & EXPERIENCE REQUIRED
Bachelor's Degree in Risk Management, Finance, Accounting, Business Administration, Economics, Law, Information Systems, or any other related discipline
Professional qualification in risk, audit, compliance, governance, or a related field.
Relevant professional certifications such as CRMA, CERM, FRM, CIA, CISA, CPA/ACCA, or equivalent is desirable
Enterprise risk management and risk framework implementation.
Operational risk assessment and mitigation.
Third-Party Risk Management (TPRM) and vendor due diligence.
Audit coordination, engagement management, and remediation tracking.
Policy governance, gap assessment, and compliance maturity frameworks.
Risk appetite and KRI/KPI development and backtesting.
Regulatory and compliance risk awareness across virtual assets, cross-border channels, and payment systems
Contract and SLA governance (including CLM platform integration)
Proficiency in risk management, reporting, GRC, and data-analysis tools
Risk reporting and executive-level presentation
Facilitation, workshop delivery, and training skills
Project and change management skills
Attention to detail, and sound professional judgment
Ability to work across multiple business functions and influence stakeholders without direct authority.
A collaborative working style and a strong business partnering orientation
Knowledge of applicable laws and regulations within the field of enterprise risk and governance with a strong understanding of business issues and opportunities
High level of integrity, confidentiality, trust, and dependability with a strong sense of urgency
Results-oriented, entrepreneurial, self-motivated, self-starter, who is flexible and adaptable to rapid change and has the ability to work in a fast-paced, high-demand environment
Experience translating KPIs to teams to get buy-in and results
Strong interpersonal, communication, and presentation skills with a good focus on organization and enhanced multitasking abilities
Ability to leverage AI systems and tools with a good grasp of enterprise risk & governance management systems
Ability to communicate information, whether technical or non-technical to stakeholders in a clear and concise manner
Highly analytical with quantitative risk assessment and strong problem-solving skills.
Our client, a real-time payment services company established under the National Payment System (NPS) Act, to address the challenge of inter-bank money transfers in the country and beyond, is seeking to onboard a Manager - Enterprise Risk & Governance.
JOB SUMMARY
The Manager - Enterprise Risk & Governance is responsible for leading enterprise risk management, third-party risk management, audit coordination, operational quality assurance, policy governance, and enterprise risk culture initiatives. S/he will serve as a key second line of oversight to the business, ensuring that enterprise risks are identified, assessed, monitored, mitigated, and reported effectively while supporting regulatory compliance and sound governance practices. The Manager - Enterprise Risk & Governance will need to have strong partnership management ability in order to engage both internal and external stakeholders.
DUTIES & RESPONSIBILITIES
Enterprise Risk Management & Operational Risk
Operationalize the enterprise risk management framework and Risk Appetite Statement (RAS).
Conduct quarterly departmental risk register revalidations with business unit heads
Maintain the enterprise risk heat map and monitor Key Risk Indicators (KRIs)
Conduct operational procedure quality assurance reviews across key business functions
Facilitate quarterly enterprise risk deep-dive sessions with business unit heads.
Establish real-time risk tracking and reporting interfaces across operational units.
Support identification, assessment, treatment, monitoring, and escalation of enterprise and operational risks.
Third-Party Risk Management & Vendor Governance
Manage the end-to-end Third-Party Risk Management (TPRM) lifecycle
Conduct initial and annual risk due diligence assessments for key vendors and third-party partners
Monitor vendor compliance with contractual Service Level Agreements (SLAs) and applicable security standards
Maintain an up-to-date TPRM inventory and continuous vendor risk scorecards
Ensure material third-party risks are appropriately escalated and mitigated.
Audit Liaison & Second-Line Oversight
Coordinate internal, external, and Central Bank of Kenya (CBK) supervisory audit engagements
Coordinate audit planning, onsite activities, document requests, interviews, and management responses
Maintain a centralized audit issue and remediation tracking register
Monitor business-unit remediation timelines
Conduct post-remediation validation testing to confirm closure of audit findings.
Policy Governance & Compliance Excellence
Conduct enterprise-wide policy gap assessments
Establish baseline compliance maturity assessments across operational units
Review and remediate outdated, incomplete, or missing enterprise policies
Coordinate company-wide policy attestation exercises
Support policy harmonization and legal governance
Support migration of contract administration to an automated Contract Lifecycle Management (CLM) platform integrated with TPRM processes
Enterprise Risk Culture & Awareness
Design and deliver annual risk management training covering ERM, AML/CFT, data privacy, and related risk areas
Establish and coordinate departmental risk champions
Develop risk accountability and micro-training initiatives
Conduct quarterly risk awareness and accountability sessions.
Cross-Border & Virtual Asset Risk
Develop risk controls for regional remittance and cross-border payment channels
Establish sanctions screening, FX liquidity, credit, and settlement risk controls
Develop due diligence and vetting frameworks for Virtual Asset Service Providers (VASPs)
Monitor regional regulatory developments affecting virtual assets and cross-border financial flows.
Risk Appetite & Management Reporting
Facilitate Management Committee (MCT) calibration workshops on enterprise risks.
Support identification and prioritization of the Top 5 Enterprise Risks.
Develop quantitative risk metrics and Green/Amber/Red risk thresholds.
Back test proposed risk thresholds against historical incident data.
Establish automated escalation triggers for emerging risk exposures.
Coordinate the governance process for formal RAS endorsement and Board Audit & Risk Committee (BARC) approval.
Operational Excellence
Maintain knowledge of the function, stay abreast with the latest practices, trends, and technologies
Model best practices in enterprise risk and governance operations and activities in order to ensure maintenance of quality performance
Update job knowledge by participating in conferences and educational opportunities, reading professional publications, maintaining personal networks, and participating in relevant professional associations
Maintain quality service and partnerships by establishing and enforcing company policies, procedures, standards, and values
Put in place proper quality control checks and balances within each operational activity assigned to the function
Regularly report on key performance indicators (KPIs) for all enterprise risk & governance-led projects and operations, demonstrating progress towards established goals and identifying areas for improvement.
Any other duties as required.
EDUCATION, SKILLS, KNOWLEDGE & EXPERIENCE REQUIRED
Bachelor's Degree in Risk Management, Finance, Accounting, Business Administration, Economics, Law, Information Systems, or any other related discipline
Professional qualification in risk, audit, compliance, governance, or a related field.
Relevant professional certifications such as CRMA, CERM, FRM, CIA, CISA, CPA/ACCA, or equivalent is desirable
Enterprise risk management and risk framework implementation.
Operational risk assessment and mitigation.
Third-Party Risk Management (TPRM) and vendor due diligence.
Audit coordination, engagement management, and remediation tracking.
Policy governance, gap assessment, and compliance maturity frameworks.
Risk appetite and KRI/KPI development and backtesting.
Regulatory and compliance risk awareness across virtual assets, cross-border channels, and payment systems
Contract and SLA governance (including CLM platform integration)
Proficiency in risk management, reporting, GRC, and data-analysis tools
Risk reporting and executive-level presentation
Facilitation, workshop delivery, and training skills
Project and change management skills
Attention to detail, and sound professional judgment
Ability to work across multiple business functions and influence stakeholders without direct authority.
A collaborative working style and a strong business partnering orientation
Knowledge of applicable laws and regulations within the field of enterprise risk and governance with a strong understanding of business issues and opportunities
High level of integrity, confidentiality, trust, and dependability with a strong sense of urgency
Results-oriented, entrepreneurial, self-motivated, self-starter, who is flexible and adaptable to rapid change and has the ability to work in a fast-paced, high-demand environment
Experience translating KPIs to teams to get buy-in and results
Strong interpersonal, communication, and presentation skills with a good focus on organization and enhanced multitasking abilities
Ability to leverage AI systems and tools with a good grasp of enterprise risk & governance management systems
Ability to communicate information, whether technical or non-technical to stakeholders in a clear and concise manner
Highly analytical with quantitative risk assessment and strong problem-solving skills.