Head Governance ,Risk - Compliance

Carsome

Selangor

On-site

MYR 300,000 - 600,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Carsome is seeking a Head of Governance, Risk & Compliance to design, implement and maintain an integrated framework across the Group’s second line of defence. You will oversee governance, risk, compliance, internal control, reporting to the Board and committees, and drive an effective risk culture across multiple jurisdictions.

You will lead a team, manage budget, and work with Legal, Finance and external advisers to ensure regulatory compliance and ethical conduct at scale.

Qualifications

  • Demonstrated experience designing and implementing enterprise risk management and compliance frameworks.
  • Sound knowledge of corporate governance codes, listing requirements and relevant legislation.
  • Experience reporting to board level and board committees.
  • Experience operating across multiple jurisdictions or legal entities.
  • Strong written and verbal communication skills, including report drafting.
  • Experience in regulated industries, particularly financial services.
  • Familiarity with governance, risk and compliance technology platforms and data analytics.
  • Experience managing investigations and forensic engagements.
  • Regional or multinational experience relevant to the Group’s footprint.

Responsibilities

  • Lead the governance, risk & compliance framework across the Group’s second line of defence.
  • Maintain governance framework, delegation of authority, and policy framework.
  • Develop and operate enterprise risk management aligned with COSO ERM or ISO 31000.
  • Prepare periodic risk reporting to management, Risk Committee, and the Board.
  • Own the anti-bribery, AML/CTF, data protection, whistleblowing, and related programmes.
  • Coordinate regulatory engagement and compliance monitoring across jurisdictions.
  • Lead governance, risk and compliance team and manage budget.
  • Promote integrity and accountable risk-taking culture.

Education

Bachelor’s degree in law, accounting, finance, business or a related discipline

Tools

CIA/CRMA/CPA/CA/ACCA/CCEP/CRISC/CISA/CIPP qualifications

Job description

The Head of Governance, Risk & Compliance leads the Group’s second line of defence. The role is responsible for designing, implementing and maintaining an integrated governance, risk management and compliance framework that enables the organisation to achieve its objectives within an agreed level of risk, in accordance with applicable laws, regulations and corporate governance standards.

The role provides independent oversight and challenge to the first line, which retains ownership of risks and controls, and operates separately from internal audit, which provides independent assurance as the third line.

Your Day-to-Day
Corporate Governance
  • Maintain the Group governance framework, including board and committee terms of reference, meeting calendars and standards for papers, minutes and decision records.
  • Maintain the delegation of authority and approval matrix and cascade it to subsidiaries and joint ventures.
  • Administer the conflicts of interest and related party transaction regime, including registers, declarations and pre-approval processes.
  • Maintain the Group policy framework, including ownership, review cycles, version control, communication and attestation.
  • Support the Company Secretary on subsidiary governance and statutory compliance.
  • Design and operate the enterprise risk management framework in line with recognised standards such as COSO ERM or ISO 31000.
  • Maintain the risk taxonomy, risk register and risk assessment methodology, and facilitate risk identification across business units and functions.
  • Develop and maintain the risk appetite statement and associated tolerance thresholds, and monitor performance against them.
  • Prepare periodic risk reporting to executive management, the Risk Committee and the Board, including principal and emerging risks.
  • Maintain the business continuity management and crisis management framework, including testing and post-incident review.
  • Coordinate the Group insurance programme in conjunction with Finance.
Regulatory Compliance
  • Maintain the regulatory obligations register and licence inventory across all jurisdictions and business lines, with assigned accountable owners.
  • Design and operate the compliance monitoring and testing programme, including exception reporting and remediation tracking.
  • Own the anti-bribery and corruption programme, including risk assessment, third-party due diligence, gifts and hospitality, and adequate procedures documentation.
  • Own anti-money-laundering and counter-terrorist financing compliance where applicable to the Group’s activities.
  • Own the data protection and privacy programme, including data protection officer duties, records of processing, breach response and cross-border transfer controls.
  • Own the whistleblowing framework, including intake, triage, investigation protocol, case management and reporting.
  • Design and deliver the compliance training and awareness curriculum, and track completion.
  • Manage regulatory engagement, notifications and correspondence in coordination with Legal.
Internal Control
  • Maintain the internal control framework and control library across key business processes.
  • Coordinate management self-assessment of controls and the annual internal control representation process.
  • Track remediation of control deficiencies identified by internal audit, external audit, regulators and management, and report status to the relevant committee.
  • Support preparation of the annual internal control and risk management statement and related disclosures.
Reporting and Committee Support
  • Prepare governance, risk and compliance reporting to executive management, the Audit Committee, the Risk Committee and the Board.
  • Act as secretariat to the management risk and compliance committee where one exists.
  • Escalate material risk, compliance and conduct matters in accordance with the escalation protocol.
Leadership and Culture
  • Lead, develop and resource the governance, risk and compliance team, and manage the function’s budget.
  • Build risk and compliance capability in the first line, including a business partner or champion network.
  • Promote a culture of integrity, accountability and appropriate risk-taking across the organisation.
  • Manage external advisers and co-sourced specialists engaged by the function.
Your Know-How
  • Bachelor’s degree in law, accounting, finance, business or a related discipline.
  • Ten to fifteen years of relevant experience in governance, risk management, compliance, internal audit or regulatory practice, including at least five years in a leadership role.
  • Demonstrated experience designing and implementing enterprise risk management and compliance frameworks.
  • Sound knowledge of applicable corporate governance codes, listing requirements and relevant legislation, including anti-bribery, anti-money-laundering and data protection.
  • Experience reporting to board level and to board committees.
  • Experience operating across multiple jurisdictions or legal entities.
  • Strong written and verbal communication skills, including report and paper drafting.
  • Professional certification such as CIA, CRMA, CPA, CA, ACCA, CCEP, CRISC, CISA, CIPP or a recognised risk management qualification.
  • Experience in a listed environment or in a company undergoing an initial public offering.
  • Experience in a regulated industry, particularly financial services.
  • Experience with governance, risk and compliance technology platforms and data analytics.
  • Experience managing investigations and forensic engagements.
  • Regional or multinational experience relevant to the Group’s footprint.

Be careful - Don’t provide your bank or credit card details when applying for jobs. Don't transfer any money or complete suspicious online surveys. If you see something suspicious, report this job ad .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Compliance
Business Compliance

OCBC • Cyberjaya

On-site
MYR 60,000 - 110,000
Head of Governance, Risk & Compliance
Head of Governance, Risk & Compliance

Carsome Sdn Bhd • Petaling Jaya

On-site
MYR 240,000 - 480,000
Senior Manager, Group Compliance
Senior Manager, Group Compliance

SD Guthrie International • Malaysia

Remote
MYR 180,000 - 260,000
Senior Manager, Group Integrity & Governance
Senior Manager, Group Integrity & Governance

sdguthrie • Petaling Jaya

On-site
MYR 180,000 - 300,000
Compliance, CoSec & Legal Executive
Compliance, CoSec & Legal Executive

vertexsolutions • Kuala Lumpur

On-site
MYR 180,000 - 300,000
Legal Counsel I, Compliance
Legal Counsel I, Compliance

Vantris Energy Berhad • Kuala Lumpur

On-site
MYR 120,000 - 240,000
Assistant Manager, Internal Audit & Risk Management
Assistant Manager, Internal Audit & Risk Management

Cyberjaya • Cyberjaya

On-site
MYR 110,000 - 170,000
Chief Risk Officer
Chief Risk Officer

Generali Malaysia • Kuala Lumpur

On-site
MYR 260,000 - 420,000
Assistant Manager/ Manager, Compliance Reporting
Assistant Manager/ Manager, Compliance Reporting

Maybank Investment Banking Group • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Regulatory Compliance Lead
Regulatory Compliance Lead

Boost Holdings Sdn Bhd • Kuala Lumpur

On-site
MYR 180,000 - 320,000