Senior Operational Risk Officer, China Region, Retail Banking recruitment

Scope of Role:

•Ensure the operational risk appetite is understood by the country business unit
•Ensure the country business unit is proactively identifying, registering, measuring, accepting and monitoring risk
•Ensure the country business unit’s control environment is effective in:
o Reducing gross operational risk exposure to acceptable levels of target residual risk commensurate with the risk appetite
o Obtaining a favourable audit outcome
•Ensure appropriate consideration is given to operational risk versus return prior to launching new products in country
•Maintain an optimal balance between risk and the cost of control
•Communicate with both external stakeholders to demonstrate compliance with their requirements and with internal stakeholders to highlight critical operational risk issues
•Help develop an operational risk culture by ensuring compliance with operational risk governance procedures and policies and by delivering training

Key Responsibilities/Challenges:

Risk Appetite
•Communicate business risk appetite for country business units to Unit Operational Risk Managers (UORMs) and country business management as defined in the Operational Risk Assessment Matrix
•Review and challenge country business unit strategy and plans in line with risk appetite and ensure alignment with operational risk capabilities and control environment

Risk  Identification
•Ensure sufficient ongoing review is being performed by UORMs and country business management to review its processes and identify BAU gross operational risks
•Ensure UORMs and country business management are proactively identifying potential new gross operational risks through:
o Reviewing country addenda to ensure processes are understood and associated risks are identified
o Analysis of new country business unit level projects
o Analysis of country business unit level mergers and acquisitions
o Analysis of root causes of country business unit level internal incidents for incidents below the Senior Operational Risk Officers level of delegated authority
oAnalysis of root causes of significant external incidents
•Proactively identify new gross operational risks through analysis of country business unit level internal incidents for incidents within or above the Senior Operational Risk Officers level of delegated authority

Risk Assessment and Measurement
•Ensure UORMs review risk assessment of new gross risks identified by the business (at Group level) and determine if amendments are needed to the country risk register
•Ensure UORMs and country business management have incorporated new gross risks to the country business unit into the country risk register and validate and challenge:
o Assessment of gross risk against the Operational Risk Assessment Matrix
o Identification of existing risk treatment plans (including  the identification of existing controls)
o Assessment of resultant residual risk against the Operational Risk Assessment Matrix
Risk Monitoring
•Ensure country business management, UORMs and the Business Operational Risk Committee (BORC):
o Update and ensure the country risk register is an accurate reflection of the risk profile of the business unit within the context of the business strategy
o Have developed effective risk monitoring mechanisms (e.g. key risk indicators, KRIs)
o Regularly monitor country risk registers, key risk indicators (KRIs), key control indicators (KCIs), key control self assessment (KCSA) results, assurance and audit results and determine actions required
o Identify systemic and aggregate risks impacting the country business unit
Risk Acceptance (where risk is not acceptable, refer to Control section)
•Ensure UORM has adequately completed a Risk Record Template for acceptance of medium, high and extreme residual risks
•Ensure all low and medium residual risks are approved at the BORC
•Ensure all high and extreme residual risks are escalated to both the Country Operational Risk Committee (CORC) and relevant business/ functional operational risk committee in accordance with the Delegated Authorities Matrix
•Approve country addenda if risks are adequately identified, assessed and considered acceptable

Stress Testing
•Conduct stress testing on operational risk scenarios for country risk appetite reviews and ICAAP reviews

Risk Reporting
•Manage event reporting:
oEnsure UORMs and Responsible Persons (RP) capture risk events (losses and near misses) in Phoenix
oApprove operational risk losses in Phoenix according to delegated authority
oEscalate significant operational risk events (SORE) in accordance with OR procedures
oPrepare material loss reports and SORE reports as required
oInvestigate and report root causes of events (near misses and losses) for incidents within and above the SOROs level of delegated approval authority

•Perform periodic risk and event reporting:
oPrepare and present OR reports (ensuring accurate and reliable information) to country BORCs
oPrepare and present OR reports (ensuring accurate and reliable information) to CORCs
oPrepare and present OR components (ensuring accurate and reliable information) to other committees as required

Risk Treatment (where residual risk is in excess of country business unit risk appetite)
•Constrain business to avoid excessive risk as per delegated authority
•Review and approve new country business unit level risk treatment plans including key control standards (KCS) and key control indicators (KCIs)
•Ensure UORMs periodically review existing country business unit level risk treatment plans
•Ensure UORMs review and update target residual risk grading in the country risk register by understanding the impact of any risk treatment plans
•Monitor country business unit level risk treatment plans to ensure they are implemented by the business

Control Testing
•Review and update country business unit key control testing plan
•Develop country business unit assurance plans (in conjunction with GIA)
•Ensure control treatment plans are developed by the UORM in response to KCSA, assurance and audit results
•Ensure control treatment plans are implemented and control issues are addressed
•Ensure country business management consider operational risk appetite and existing residual risks, as identified in the risk registers, prior to the approval of new products through the country addenda process

•Regularly assess existing local key control standards (LKCSs) against the risk registers to ensure the level of control remains cost effective, efficient and relevant
•Support the Country Chief Risk Officer to conduct country risk appetite reviews

Communicate to External Stakeholders
•Participate in ICAAP reviews
•Prepare quarterly Basel data submission
•Support the Country Chief Risk Officer to communicate with local regulators
Communicte to Internal Stakeholders
•Communicate critical OR issues to key internal stakeholders in a timely manner

Policies Procedures
•Ensure compliance with operational risk governance procedures:
oEnsure BORC complies with its governance requirements as stated in the Terms of Reference, including use of the standard BORC pack
oAdhere to operational risk authorities
•Ensure compliance with operational risk policies:
oUnderstand  all changes to operational risk policies and  ensure they are implemented
oEnsure UORM monitors OR policy compliance and develops remediation plans
oReview deviations from OR policies and procedures to meet local business requirements and obtain approval from the Group Operational Risk Committee

People Skills
•Obtain operational risk certification
•Ensure UORM’s conduct RP training
•Conduct UORM training
•Conduct systems training (Phoenix and Optial)
•Ensure completion of mandatory operational risk e-Learning by the business

Qualifications Skills

Relevant business/function experience, including experience within business/function operations
•Operational risk management experience
•Operational risk accreditation
•A clear understanding of the Bank’s approach to the management of operational risk, or equivalent experience gained in other organisations
•Ability to work in a matrixed organisation, leveraging resources across the organisation to complete deliverables
•The sound judgement and courage necessary to perform a control role and maintain effective working relationships