At the Aditya Birla Group, our Corporate Vision is aligned and intricately woven with our People Vision.
Basic Details
Business: (Fill the required information about business, unit, location, position, reports to position and date of updation of JD)
Health Insurance: (Fill the required information about business, unit, location, position, reports to position and date of updation of JD)
Unit: Aditya Birla Health Insurance Company Ltd
Location: GCorp - Thane
Poornata Position Number of the job: (Fill the required information)
Reports to: Poornata Position Number: (Fill the required information)
Poornata Position Title of the job: (Fill the required information)
Reports to: Poornata Position Title: (Fill the required information)
Function: (Fill the required information)
Reports to: Function: (Fill the required information)
Department: (Fill the required information)
Reports to: Department: (Fill the required information)
Designation of the Employee: (Fill the required information)
Designation of the Manager: (Fill the required information)
RLC-5 Head Risk
Date of writing/updation of JD: March 10, 2026
Job Purpose
The purpose of the role is to implement risk management framework for efficient and effective governance and management of significant risks and related opportunities, to the business and its various segments with an objective to ensure that the business is conducted in compliance with regulatory and internal norms and within the accepted risk appetite. The role also acts as a coordinator between auditee function and Internal Auditor for effective, efficient and timely implementation of Internal Audit Plan.
Responsibilities
- Third Party Risk Governance & Framework
- Design, implement, and maintain the Third-Party Risk Management framework aligned to regulatory and enterprise risk standards
- Define risk taxonomy for third-party risks (operational, financial, cyber, legal, reputational, ESG, concentration)
- Establish governance structures, roles, risk ownership, and approval thresholds
- Ensure alignment with ERM, Outsourcing Risk, and Vendor Management policies
- Third Party Risk Identification & Classification
- Identify all third parties, vendors, suppliers, outsourcing partners, and service providers
- Classify third parties based on criticality, materiality, and inherent risk
- Maintain an enterprise-wide third-party inventory and risk register
- Due Diligence and Risk Assessment
- Conduct initial and ongoing risk assessments across financial, operational, cyber, legal, regulatory, and ESG factors
- Review due diligence artifacts (financials, SOC reports, ISO certifications, licenses, insurance)
- Coordinate enhanced due diligence for critical or high-risk vendors
- Ensure risk scoring methodologies are consistent and defensible
- Regulatory and Compliance Risk Management
- Ensure third-party arrangements comply with applicable regulatory requirements and industry guidelines
- Support regulatory inspections, audits, and supervisory reviews related to outsourcing and third parties
- Track regulatory changes impacting third-party risk requirements
- Ensure contractual clauses meet regulatory expectations (audit rights, exit clauses, SLAs)
- Ongoing monitoring and Risk Mitigation
- Track and manage risk issues, control deficiencies, and remediation actions
- Ensure timely closure of gaps identified during due diligence or monitoring
- Escalate unresolved or material risks to senior management and risk committees
- Validate effectiveness of mitigation actions
- Reporting & Management Information (MI)
- Develop dashboards and risk reports for senior management, risk committees, and the Board
- Provide insights on risk trends, concentration risk, and emerging threats
- Support enterprise risk reporting and stress scenarios involving third parties
- Ensure data accuracy and audit-ready documentation
- Stakeholder and Cross Functional Co-ordination
- Act as the central risk liaison between Procurement, Legal, IT, Compliance, Business, and Audit teams
- Educate stakeholders on third-party risk requirements and responsibilities
- Support onboarding, renewal, and exit processes from a risk perspective
- Drive risk culture awareness across first and second lines of defence.
- Continuous Improvement & Maturity Enhancement
- Periodically assess TPRM maturity against industry benchmarks
- Automate risk assessments and monitoring where feasible
- Introduce enhancements based on regulatory feedback, incidents, or lessons learned
- Drive efficiency, consistency, and scalability of the TPRM program
Relationships
- Internal – Regular Interaction
- Risk management initiatives (risk assessments, RCSA, etc.) undertaken by the risk management team
- Senior Management Team (SMT) – periodic basis for various risk initiatives
- Function Heads / CEO/CRO – monthly or quarterly meetings for policy framework approval and updates on key risks and initiatives
- Internal audit report closure and escalation discussions – quarterly
- External – Regular Interaction
- Internal Auditors – regular intervals for smooth execution of internal audit procedures
- Business Partners / Outsourced vendors – ad-hoc for consultancy, benchmarking, updates, and technology advances in risk/internal audit field