Durban, South Africa | Posted on 08/28/2026
We offer comprehensive services in Recruitment(Permanent, Temporary, Fixed-term Contracts), Payroll Administration, andLabour Relations.
Job Description
The Senior Manager: Non-Financial Risk isresponsible for supporting the Chief Risk Officer in establishing,implementing, enhancing and overseeing the Bank's Non-Financial Risk ManagementFramework.
The role serves as a key member of theEnterprise Risk Management function and provides independent second-lineoversight, challenge and strategic guidance across operational andnon-financial risk disciplines, including Operational Risk, Operational Resilience,Business Continuity Management, Third-Party Risk, Information Security Risk,Information and Communication Technology (ICT) Risk, Digital Fraud Risk andother emerging risks.
The incumbent will work closely withbusiness management, control functions and specialist risk teams to ensure thatnon-financial risks are effectively identified, assessed, monitored, managedand reported, while supporting the Bank's strategic objectives, operationalresilience and regulatory obligations.
The role will also assist the CRO inproviding senior management, Board committees and regulators with acomprehensive view of the Bank's non-financial risk profile and theeffectiveness of related risk management practices.
Requirements
Non-Financial Risk Strategy andGovernance
- Support the CRO in developing and maintaining the Bank'sNon-Financial Risk Management Framework, policies, standards andmethodologies.
- Drive the continuous enhancement of the Bank's non-financialrisk management capabilities and maturity.
- Assist in the development and monitoring of risk appetitestatements, tolerance levels, key risk indicators and governancereporting.
- Monitor emerging regulatory requirements, industry developmentsand evolving risk trends.
- Provide strategic advice and independent challenge tomanagement regarding significant non-financial risk exposures and controlweaknesses.
- Support the preparation of risk management papers andpresentations for Executive Management, Board Committees and regulators.
- Oversee the implementation and ongoing effectiveness of theOperational Risk Management Framework.
- Coordinate and challenge Risk and Control Self-Assessments(RCSA), risk assessments and control effectiveness reviews across theBank.
- Oversee operational risk event and incident managementprocesses, including root-cause analysis, lessons learned and remediationtracking.
- Monitor operational loss events, risk trends and controlweaknesses and ensure material issues are appropriately escalated.
- Facilitate the development and monitoring of operational riskindicators and early warning metrics.
- Provide independent review and challenge regarding risktreatment plans and risk acceptance decisions.
Operational Resilience and BusinessContinuity
- Support the design, implementation and continuous enhancementof the Bank's Operational Resilience Framework.
- Lead the Bank's Business Continuity Management programme,including business impact assessments, continuity planning, testing andrecovery exercises.
- Coordinate resilience assessments covering critical businessservices, key processes and material dependencies.
- Facilitate severe but plausible scenario analysis andresilience testing exercises.
- Monitor resilience vulnerabilities and support management inimplementing corrective actions.
- Promote integration between operational risk management,business continuity, crisis management and technology resilienceactivities.
Information Security and ICT RiskOversight
- Provide independent oversight and challenge of informationsecurity and ICT risk management practices.
- Review and assess material technology, cyber security anddigital transformation initiatives from a risk perspective.
- Monitor significant technology and cyber security riskexposures and ensure timely escalation of material concerns.
- Support the assessment of technology resilience, informationsecurity controls and cyber preparedness.
- Ensure technology and information security risks areappropriately incorporated into the Bank's risk profile and governancereporting.
Third-Party Risk Management
- Oversee the implementation and effectiveness of the Third-PartyRisk Management Framework.
- Review and challenge risk assessments relating to outsourcingarrangements, service providers and strategic partnerships.
- Monitor critical supplier dependencies, concentration risks andresilience capabilities.
- Ensure third-party risks are appropriately considered inoperational resilience, business continuity and risk assessmentactivities.
- Support governance oversight of material outsourcing and vendorrelationships.
Digital Fraud and Financial Crime RiskSupport
- Support the development and enhancement of the Bank's digitalfraud risk management capability.
- Monitor emerging fraud threats, attack trends andtechnology-enabled fraud risks.
- Coordinate with business, technology, operations and securityteams to strengthen fraud prevention, detection and response capabilities.
- Analyse fraud events and trends and support the identificationof strategic risk mitigation initiatives.
- Provide oversight and reporting of fraud-related risks withinthe broader non-financial risk framework.
- Monitor internal and external developments that may give riseto emerging non-financial risks.
- Assess the risk implications of digital transformation,changing business models, regulatory developments, geopolitical events andevolving threat landscapes.
- Support the development of risk assessments and mitigationstrategies for emerging risk themes.
- Provide forward-looking analysis and insight to supportstrategic decision making.
Regulatory, Audit and CommitteeEngagement
- Support the CRO in engagements with regulators, externalauditors and other assurance providers.
- Coordinate responses to regulatory reviews, thematicassessments and audit findings.
- Monitor the implementation and closure of agreed remediationactions.
- Prepare high-quality risk reports and management informationfor governance committees and senior management forums.
- Act as a trusted adviser to management on non-financial riskmatters.
Risk Culture and Capability Development
- Promote a strong and sustainable risk culture across theorganisation.
- Facilitate risk awareness and training initiatives relating tooperational and non-financial risks.
- Encourage proactive identification, escalation and managementof risks and control issues.
- Support management in embedding risk-based decision makingthroughout the organisation.
Non-Financial Risk Strategy andGovernance
- Support the CRO in developing and maintaining the Bank'sNon-Financial Risk Management Framework, policies, standards andmethodologies.
- Drive the continuous enhancement of the Bank's non-financialrisk management capabilities and maturity.
- Assist in the development and monitoring of risk appetitestatements, tolerance levels, key risk indicators and governancereporting.
- Monitor emerging regulatory requirements, industry developmentsand evolving risk trends.
- Provide strategic advice and independent challenge tomanagement regarding significant non-financial risk exposures and controlweaknesses.
- Support the preparation of risk management papers andpresentations for Executive Management, Board Committees and regulators.
- Oversee the implementation and ongoing effectiveness of theOperational Risk Management Framework.
- Coordinate and challenge Risk and Control Self-Assessments(RCSA), risk assessments and control effectiveness reviews across theBank.
- Oversee operational risk event and incident managementprocesses, including root-cause analysis, lessons learned and remediationtracking.
- Monitor operational loss events, risk trends and controlweaknesses and ensure material issues are appropriately escalated.
- Facilitate the development and monitoring of operational riskindicators and early warning metrics.
- Provide independent review and challenge regarding risktreatment plans and risk acceptance decisions.
Operational Resilience and BusinessContinuity
- Support the design, implementation and continuous enhancementof the Bank's Operational Resilience Framework.
- Lead the Bank's Business Continuity Management programme,including business impact assessments, continuity planning, testing andrecovery exercises.
- Coordinate resilience assessments covering critical businessservices, key processes and material dependencies.
- Facilitate severe but plausible scenario analysis andresilience testing exercises.
- Monitor resilience vulnerabilities and support management inimplementing corrective actions.
- Promote integration between operational risk management,business continuity, crisis management and technology resilienceactivities.
Information Security and ICT RiskOversight
- Provide independent oversight and challenge of informationsecurity and ICT risk management practices.
- Review and assess material technology, cyber security anddigital transformation initiatives from a risk perspective.
- Monitor significant technology and cyber security riskexposures and ensure timely escalation of material concerns.
- Support the assessment of technology resilience, informationsecurity controls and cyber preparedness.
- Ensure technology and information security risks areappropriately incorporated into the Bank's risk profile and governancereporting.
Third-Party Risk Management
- Oversee the implementation and effectiveness of the Third-PartyRisk Management Framework.
- Review and challenge risk assessments relating to outsourcingarrangements, service providers and strategic partnerships.
- Monitor critical supplier dependencies, concentration risks andresilience capabilities.
- Ensure third-party risks are appropriately considered inoperational resilience, business continuity and risk assessmentactivities.
- Support governance oversight of material outsourcing and vendorrelationships.
Digital Fraud and Financial Crime RiskSupport
- Support the development and enhancement of the Bank's digitalfraud risk management capability.
- Monitor emerging fraud threats, attack trends andtechnology-enabled fraud risks.
- Coordinate with business, technology, operations and securityteams to strengthen fraud prevention, detection and response capabilities.
- Analyse fraud events and trends and support the identificationof strategic risk mitigation initiatives.
- Provide oversight and reporting of fraud-related risks withinthe broader non-financial risk framework.
- Monitor internal and external developments that may give riseto emerging non-financial risks.
- Assess the risk implications of digital transformation,changing business models, regulatory developments, geopolitical events andevolving threat landscapes.
- Support the development of risk assessments and mitigationstrategies for emerging risk themes.
- Provide forward-looking analysis and insight to supportstrategic decision making.
Regulatory, Audit and CommitteeEngagement
- Support the CRO in engagements with regulators, externalauditors and other assurance providers.
- Coordinate responses to regulatory reviews, thematicassessments and audit findings.
- Monitor the implementation and closure of agreed remediationactions.
- Prepare high-quality risk reports and management informationfor governance committees and senior management forums.
- Act as a trusted adviser to management on non-financial riskmatters.
Risk Culture and Capability Development
- Promote a strong and sustainable risk culture across theorganisation.
- Facilitate risk awareness and training initiatives relating tooperational and non-financial risks.
- Encourage proactive identification, escalation and managementof risks and control issues.
- Support management in embedding risk-based decision makingthroughout the organisation.