Turn this role into an interview — a resume and cover letter built around what this employer wants.
National Payments Corporation of India (NPCI) in Mumbai seeks a senior risk professional to lead identification, assessment, and monitoring of operational and IT risks across business processes, applications, infrastructure, and projects.
You will define risk indicators, escalate findings, and collaborate with Technology, Compliance, Internal Audit to strengthen controls and governance, enabling NPCI to mitigate material risks effectively.
National Payments Corporation of India (NPCI) | Full Time
The National Payments Corporation of India (NPCI) is a pivotal institution in India's digital payments ecosystem, established by the Reserve Bank of India (RBI) and the Indian Banks’ Association (IBA). It operates under the Payment and Settlement Systems Act, 2007, and is incorporated as a “Not for Profit” company under Section 25 of the Companies Act 1956 (now Section 8 of the Companies Act 2013). NPCI is dedicated to building world-class digital payment infrastructure through innovative and efficient retail payment platforms. As an Equal Opportunity Employer, NPCI is committed to fostering an inclusive workplace culture, with zero tolerance for discrimination based on race, ethnicity, disability, gender identity, or sexual orientation, including support for the LGBTQ+ community.
At NPCI, we foster a culture of Inclusion, Innovation, and a High- Performance Workplace .
The NPCIWAY isnotjustaframework - it’sasharedcommitmentbyevery individual to align with our evolving business needs, dynamic market conditions, and workforce expectations.
Insurance&Wellness:
At NPCI, you’ll be part of a purpose-driven organization shaping the future of digital payments in India and beyond. NPCI offers a unique opportunity to work on cutting-edge projects that directly impact millions. We foster a culture of innovation, inclusion, and high performance, where every individual is empowered to lead with purpose and deliver with passion. With a strong focus on employee wellbeing, continuous learning, and collaborative success, NPCI is more than just a workplace - it’s a platform to grow, contribute, and make a meaningful difference.
Lead the identification, assessment and monitoring of operational and information technology risks across business processes, applications, infrastructure, projects and strategic initiatives. Ensure material risks are evaluated consistently and escalated to the appropriate authority.Drive the enterprise-wide Risk and Control Self-Assessment process in coordination with business, operations and technology functions. Review the completeness and quality of assessments and ensure that risk registers are accurate, current and supported by appropriate evidence.Define, review and monitor Key Risk Indicators for material risk areas. Analyse trends, challenge threshold levels and ensure breaches or adverse movements are promptly reported, escalated and addressed through time-bound corrective actions.Conduct process walkthroughs and detailed risk assessments to understand workflows, dependencies, failure points and existing controls. Recommend improvements to strengthen control design, operating effectiveness and accountability across relevant functions.Oversee the operational risk incident management process, including incident identification, classification, impact assessment, reporting and closure. Review root cause analysis, challenge corrective and preventive actions, track action items and escape delays or recurring incidents.Assess operational and technology risks associated with new products, system implementations, major enhancements, process changes, outsourcing arrangements and other business initiatives. Ensure identified risks are addressed before implementation or formally accepted by the appropriate authority.Develop risk mitigation plans jointly with business, operations and technology teams. Define clear actions, owners and target dates, monitor progress and escape overdue or ineffective actions to senior management and relevant governance forums.Partner with Technology, Information Security, Compliance, Internal Audit and other control functions to promote a coordinated approach to risk management. Facilitate information sharing, avoid duplication and ensure consistent assessment and treatment of interrelated risks.Support the development, implementation and periodic review of the enterprise Risk Appetite Framework. Assist in defining suitable risk appetite statements, metrics, thresholds and escalation requirements for operational and technology risks, aligned with the organisation’s objectives and regulatory expectations.Prepare accurate and timely risk reports, dashboards and management updates for senior management and relevant committees. Provide clear analysis of the organisation’s risk profile, significant incidents, emerging risks, KRI breaches, control weaknesses and mitigation status to support informed decision-making. Maintain appropriate records of assessments, findings, approvals and closures to demonstrate effective oversight, traceability and compliance with the organisation’s risk management framework.