Be part of CIBI Information Inc., a purpose-driven company at the forefront of enabling better credit decisions in the Philippines and beyond.
ROLE OVERVIEW:
The GRC Manager will be responsible for the design, implementation, and operationalization of CIBI’s integrated governance, risk, and compliance frameworks. This is a high-impact, individual contributor-plus role focused on ensuring that CIBI’s operations remain resilient, audit-ready, and fully aligned with the mandates of the Credit Information Corporation (CIC), the Data Privacy Act (DPA), and international standards (ISO/SOC 2).
DUTIES AND RESPONSIBILITIES:
Governance Framework & Strategy
- Operationalize the Enterprise Risk Management (ERM) and Governance frameworks to align with CIBI’s mission and vision and strategic objectives;
- Advisory on best industry practice in governance and regulatory compliance;
- Draft and maintain the repository of corporate policies, ensuring they are not merely documented but functionally embedded into departmental workflows.
- Evaluate the effectiveness of internal controls and provide technical recommendations to the Board and Senior Management on daily operations towards promotion of a culture of integrity, accountability and compliance by design.
Enterprise Risk & Internal Controls
- Assist in the assessment, and prioritization of potential risks, including operational, compliance, financial, reputational, and strategic risks and the creation of risk mitigation plans through deep-dive risk assessments across all business units (Operational, Financial, Reputational, and Strategic).
- Develop and monitor Key Risk Indicators (KRIs) and control metrics to provide early-warning signals to the Risk Management Committee.
- Audit and test the efficacy of internal controls, ensuring the safeguarding of CIBI’s data assets and the reliability of reporting.
Regulatory Compliance Management
- Monitor adherence to all relevant laws pertinent to the operations of CIBI and internal policies, including the Data Privacy Act of 2012, BSP regulations, Anti-Money Laundering (AML) and CIC Circulars, serving as a primary point of contact for regulatory inquiries.
- Conduct regular compliance "health checks" and gap analyses to ensure the organization maintains its "Advanced Tier" standing.
- Manage the end-to-back compliance lifecycle, from detection of potential non-compliance to the implementation of remedial actions.
Technical Collaboration (ISO & SOC 2)
- Serve as the GRC lead in partnership with Internal Audit for ISO 27001 and SOC 2 Type 2 certifications and collaboration in all governance and compliance audit
- Map GRC requirements against technical security controls, ensuring that governance documentation matches technical implementation.
- Work with Lead Internal Auditor in remediating findings from ISO/SOC 2 audits by redesigning processes to meet international security and availability standards.
Incident Response & Institutional Resilience
- Lead the GRC component of the Incident Response Plan, ensuring that compliance breaches are detected, reported, and mitigated within statutory timelines.
- Design Business Continuity and Crisis Management protocols focused on maintaining the integrity of CIBI’s credit database during unforeseen events.
- Coordinate with other departments, including Internal Audit and IT, for incident investigations and risk assessments.
Reporting, Documentation & Training
- Document and maintain a centralized repository for all GRC policies, procedures, risk registers, and compliance reports.
- Ensure all GRC documentation aligns with regulatory and organizational standards, facilitating easy access for audits and regulatory reviews.
- Assist in the development and delivery of GRC training programs on compliance, risks and governance policies and the creation of awareness initiatives to promote ethical and compliance by design practices.
- Maintain up-to-date training materials that reflect regulatory changes and align with CIBI’s policies and procedures.
JOB SPECIFICATIONS
Educational Background
- Bachelor’s degree in Finance, Accounting, Law, Business Administration, or a related field. Master’s degree or equivalent preferred.
- Professional certifications (e.g., Certified Risk Manager, Certified Compliance Professional, or Certified Internal Auditor) are highly desirable.
Experience
- 2-3 years of experience in governance, risk, compliance, or audit functions, with at least 1 year in a supervisorial or managerial role, preferably in financial services, banking, or credit bureau, audit compliance industries.
- Strong knowledge of relevant regulatory frameworks, particularly BSP and CIC regulations, Anti-Money Laundering (AML) laws, data privacy laws (e.g., Data Privacy Act of the Philippines).
- Deep understanding of governance, risk management, and compliance frameworks.
- Proven leadership and team management skills, with the ability to foster a collaborative and ethical work environment.
- Excellent analytical and problem-solving abilities, with a strategic mindset and attention to detail.
- Effective communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels.
- Strong organizational and project management skills, with the ability to prioritize and manage multiple tasks.
- High ethical standards and integrity, with a commitment to upholding the company’s values and promoting a compliance-oriented culture.
- Ability to handle sensitive and confidential information with discretion.
- Proactive, resourceful, and self-motivated with a results-oriented approach.