Risk & Compliance Specialist
REF: KK698
Market Related Salary
Observatory, Western Cape
The successful candidate will be responsible for supporting the Group’s enterprise risk management (ERM) and compliance oversight model. The role facilitates Group-wide risk assessments and registers, monitors the legislative and regulatory landscape, coordinates combined assurance, and drives a culture of compliance across the company’s South African, Namibian and US operations.
RESPONSIBILITIES INCLUDE:
Risk management:
- Supporting the annual review and updating the ERM Policy, Framework and Compliance Policy and Framework for RiskCom approval, and helping to ensure they are consistently followed
- Facilitating divisional and functional risk assessments, monitoring the implementation and effectiveness of mitigation actions and KRIs, preparing risk reporting for governance forums, and supporting the continuous improvement and maturity of the company’s Enterprise Risk Management framework.
- Reviewing and amending risk registers and mitigation plans and monitoring the applicable risk landscape and context changes (PESTLE)
- Tracking the completion of risk actions and reporting on implementation progress
- Owning the data quality and governance of risk registers — including the consistency, completeness and accuracy of risk descriptions, ratings and mitigation status — in addition to facilitating its update
- Identifying emerging risks arising from legislative impacts, regulatory developments and PESTLE analysis, and incorporating relevant findings into risk registers, mitigation plans and reporting
- Providing guidance and training to risk owners on risk management methodologies and requirements
- Supporting with updating and enhancing the Risk Management tools as implemented from time to time – including rolling-out any training where required
Compliance management:
- Monitoring the legislative and regulatory landscape for changes and assessing their implications for the Group
- Supporting divisions and functions in assessing implications and developing action plans and monitoring closure of new legislative requirements
- Acting as convenor of the Compliance Forum and developing and implementing the annual compliance and risk training and awareness plan (SRC policies, online compliance training)
- Compiling input into the quarterly Risk and Compliance Board reports (legislative updates, Compliance Forum feedback, health and safety incidents and legislative non-conformances)
- Promoting a culture of compliance through awareness campaigns, communications and targeted training initiatives
- Developing and distributing regular compliance updates and guidance material on emerging legislative and regulatory developments
- Coordinating the review, update and implementation of compliance-related policies, standards and procedures to ensure alignment with regulatory requirements and leading practice
- Investigating incidents and instances of non-compliance with applicable legislation, policies and procedures
- Maintaining the Group legislative universe and compliance obligations register, coordinating compliance risk assessments and monitoring activities, and trackig remediation actions arising from compliance reviews, investigations and regulatory changes
Assurance and risk-control coordination:
- Supporting the drafting of the Combined Assurance Plan (CAP) and evaluating the effectiveness of the CAP quarterly
- Completing second-level compliance assurance (i.e. compliance with policies and standards)
- Tracking the completion of property risk recommendations arising from underwriting surveys
Business continuity planning (BCP):
- Responsible for amending, updating, training and scenario planning of the BCP
- Monitoring the readiness and applicability of the Divisional BCP
- Developing and maintaining the Group wide BCP standards and management system
REQUIREMENTS:
- A relevant bachelor’s degree in risk management, Law, Commerce, Internal Auditing or a related field
- A postgraduate qualification or professional certification in risk or compliance management (e.g. IRMSA, Compliance Institute of South Africa, or equivalent) is advantageous
- 3–5 years’ experience in enterprise risk management and/or regulatory compliance, ideally within a JSE-listed or similarly governed organisation
- Demonstrated experience facilitating risk assessments, maintaining risk registers and supporting combined assurance processes
- Strong analytical skills, with the ability to apply structured frameworks such as PESTLE to identify emerging and evolving risks
- Sound understanding of the three-lines-of-defence model and combined assurance principles
- Excellent facilitation and stakeholder-engagement skills across Group and divisional teams
- Strong written and verbal communication skills for board- and committee-level reporting
- High attention to detail, sound judgement, and the ability to manage multiple concurrent workstreams and deadlines
- Working knowledge of a GRC or enterprise risk management system/tool for risk register maintenance, data quality management and reporting
- Ability to interpret and apply legislation to real-world business scenarios