Position Summary
The Chief Governance, Risk & Compliance Officer will provide executive leadership and strategic oversight of the organization’s governance, enterprise risk management, compliance, and internal control frameworks. The role is responsible for ensuring that the organization operates with strong governance, effective risk management, regulatory compliance, and appropriate controls while supporting sustainable business growth and the achievement of strategic objectives.
The CGRCO will advise the Board of Directors, Board Committees, CEO, and Executive Management on key governance, risk, and compliance matters and will establish a robust GRC framework aligned with the organization’s strategy, regulatory requirements, risk appetite, and industry best practices.
Key Responsibilities
1. Governance
Establish and maintain a comprehensive corporate governance framework.
Develop and maintain governance policies, procedures, authorities, and decision-making frameworks.
Support the Board and its committees on governance matters.
Ensure appropriate delegation of authority and accountability across the organization.
Monitor compliance with corporate governance requirements and internal policies.
Promote a culture of transparency, accountability, ethics, and responsible decision-making.
2. Enterprise Risk Management
Develop and lead the organization’s Enterprise Risk Management (ERM) framework.
Establish risk appetite, risk tolerances, risk policies, and reporting mechanisms.
Identify, assess, monitor, and report strategic, operational, financial, legal, regulatory, technology, reputational, and emerging risks.
Maintain the corporate risk register and oversee mitigation plans.
Provide executive management and the Board with independent assessment of the organization's risk profile.
Integrate risk management into strategic planning, investment decisions, major projects, and business operations.
3. Compliance
Establish and oversee the organization-wide compliance framework.
Monitor compliance with applicable laws, regulations, contractual obligations, and internal policies.
Develop compliance policies, procedures, standards, and controls.
Oversee regulatory reporting and compliance monitoring.
Identify and address compliance gaps and potential violations.
Lead or oversee compliance investigations, remediation, and corrective actions where appropriate.
Promote a strong culture of ethical and compliant business conduct.
4. Internal Controls
Establish and maintain an effective internal control framework.
Assess the effectiveness of key business and financial controls.
Identify control deficiencies and oversee remediation.
Coordinate with Internal Audit and external auditors where appropriate.
Ensure management has appropriate controls over financial, operational, and strategic risks.
5. Business Continuity & Resilience
Oversee business continuity, crisis management, and organizational resilience frameworks.
Ensure critical business processes have appropriate continuity and recovery plans.
Monitor organizational preparedness for major disruptions and emerging risks.
6. Risk & Compliance Reporting
Develop executive and Board-level GRC dashboards and reports.
Provide regular reporting on key risks, compliance issues, control deficiencies, and mitigation actions.
Establish appropriate Key Risk Indicators (KRIs), Key Control Indicators (KCIs), and compliance metrics.
Escalate material risks and compliance matters to the CEO and Board as appropriate.
7. Strategic Advisory
Act as a trusted advisor to the CEO and Executive Management on governance, risk, and compliance matters.
Provide GRC input into acquisitions, investments, major contracts, projects, and strategic initiatives.
Assess the risk implications of major business decisions.
Balance risk management with commercial objectives and business growth.
Ensure GRC considerations are incorporated into the organization's strategic planning and decision-making.
8. Leadership
Lead and develop the Governance, Risk & Compliance function.
Establish clear objectives, performance measures, and operating standards for the GRC team.
Build strong relationships with business leaders and promote risk ownership throughout the organization.
Develop a culture in which risk and compliance are viewed as business responsibilities rather than solely as control functions.
Key Skills & Competencies
Excellent command of written and spoken English.
Executive-level leadership and strategic thinking.
Strong knowledge of corporate governance, ERM, compliance, and internal controls.
Strong understanding of regulatory and legal environments.
Risk assessment and risk modelling.
Policy and framework development.
Business continuity and crisis management.
Strong analytical and problem-solving skills.
Excellent communication and presentation skills.
Strong negotiation and stakeholder management.
Board and executive-level reporting.
High level of integrity, independence, and professional judgment.
Ability to influence senior stakeholders and challenge decisions constructively.
Strong commercial and business acumen.
Typical Qualifications & Experience
Bachelor’s degree in Business, Finance, Risk Management, Law, Accounting, Economics, or a related discipline.
Master’s degree/MBA or relevant postgraduate qualification preferred.
Typically 15+ years of relevant professional experience, with significant experience in senior GRC, risk, compliance, governance, audit, or related leadership roles.
Proven experience developing and implementing enterprise-wide GRC frameworks.
Experience advising Boards, Board Committees, CEOs, and Executive Management.
Experience managing complex organizations and multiple stakeholders.
Relevant professional certifications would be advantageous, such as CRMA, CIA, CISA, CCEP, CGEIT, FRM, CPA/ACCA, or equivalent, depending on the organization's requirements.
Key Success Measures
The CGRCO's performance could be measured through:
Maturity and effectiveness of the organization's GRC framework.
Reduction in material and unmanaged risks.
Compliance with applicable regulatory and internal requirements.
Timely closure of risk and control remediation actions.
Effectiveness of Board and executive risk reporting.
Improvement in risk culture and accountability.
Effectiveness of business continuity and resilience.
Reduction in significant compliance breaches and control failures.
Successful integration of GRC into strategic and investment decisions.
In short: the CGRCO is the organization's senior independent advisor and leader for governance, enterprise risk, and compliance, ensuring that the company can pursue its strategic and commercial objectives while understanding, managing, and controlling the risks associated with those objectives.
Requirements
15+ years of progressive experience in governance, enterprise risk management, compliance, internal controls, audit, or related fields, including significant senior leadership experience.
Bachelor’s degree in Business, Finance, Risk Management, Law, Accounting, or related discipline; Master’s degree/MBA preferred.
Proven experience developing and implementing enterprise-wide GRC frameworks, policies, and risk management strategies.
Strong knowledge of corporate governance, ERM, regulatory compliance, internal controls, business continuity, and risk assurance.
Demonstrated experience advising Boards, Board Committees, CEOs, and Executive Management on significant governance, risk, and compliance matters.
Strong understanding of risk identification, assessment, mitigation, monitoring, and reporting.
Proven ability to establish and monitor risk appetite, KRIs, compliance metrics, and control frameworks.
Excellent strategic thinking, analytical, problem-solving, and decision-making skills.
Strong leadership, stakeholder management, negotiation, and influencing skills.
Excellent written and spoken English, with strong executive-level communication and presentation capabilities.
High level of integrity, independence, professional judgment, and confidentiality.
Relevant professional certifications such as CIA, CRMA, CISA, FRM, CCEP, CPA/ACCA, or equivalent are desirable.
Experience in a large, complex, regulated, or multinational organization is highly desirable.
ملخص المنصب
سيقدم مسؤول الحوكمة والمخاطر والامتثال التنفيذي القيادة والرقابة الاستراتيجية على أطر الحوكمة ومخاطر المؤسسة والامتثال والضوابط الداخلية في المنظمة. وسيكون الدور مسؤولاً عن ضمان أن تعمل المنظمة بحوكمة قوية، وإدارة مخاطر فعالة، والامتثال التنظيمي، والضوابط الملائمة مع دعم نمو الأعمال المستدام وتحقيق الأهداف الاستراتيجية.
سيقدم CGRCO النصح إلى مجلس الإدارة واللجان التابعة للمجلس والرئيس التنفيذي والإدارة التنفيذية بشأن القضايا الرئيسية للحوكمة والمخاطر والامتثال وسيضع إطار GRC قوي يتماشى مع استراتيجية المنظمة والمتطلبات التنظيمية وشهية المخاطر وأفضل الممارسات في الصناعة.
المسؤوليات الرئيسية
1. الحوكمة
إنشاء إطار حوكمة الشركات الشامل والصيانته.
تطوير وصيانة سياسات الحوكمة والإجراءات والسلطات وأطر اتخاذ القرار.
دعم المجلس ولجانه في قضايا الحوكمة.
ضمان تفويض السلطة والمسؤولية بشكل مناسب عبر المنظمة.
رصد الامتثال لمتطلبات حوكمة الشركات والسياسات الداخلية.
تعزيز ثقافة الشفافية والمساءلة والأخلاقيات واتخاذ القرار المسؤول.
2. إدارة مخاطر المؤسسة
تطوير وقيادة إطار إدارة مخاطر المؤسسة (ERM) للمنظمة.
تحديد شهية المخاطر tolerances والPolicies وآليات الإبلاغ.
تحديد وتقييم ومراقبة والإبلاغ عن المخاطر الاستراتيجية والتشغيلية والمالية والقانونية والتنظيمية والتقنية والسمعة والمخاطر الناشئة.
الحفاظ على سجل مخاطر الشركة والإشراف على خطط التخفيف.
تقديم تقييم مستقل لإدارة المنظمة وملف المخاطر للمجلس التنفيذي.
دمج إدارة المخاطر في التخطيط الاستراتيجي وقرارات الاستثمار والمشاريع الكبرى وعمليات الأعمال.
3. الامتثال
إنشاء والإشراف على إطار الامتثال على مستوى المنظمة.
رصد الامتثال للقوانين المعمول بها واللوائح والالتزامات التعاقدية والسياسات الداخلية.
تطوير سياسات、إجراءات、معايير وضوابط الامتثال.
الإشراف على التقارير التنظيمية ورصد الامتثال.
تحديد ومعالجة فجوات الامتثال والانتهاكات المحتملة.
قيادة أو الإشراف على التحقيقات في الامتثال والتصحيح والإجراءات التصحيحية عند الاقتضاء.
تعزيز ثقافة قوية من الأخلاق والسلوك التجاري المطابق.
4. الضوابط الداخلية
إنشاء والحفاظ على إطار ضوابط داخلية فعّال.
تقييم فعالية الضوابط الرئيسية للأعمال والمالية.
تحديد عيوب الرقابة والإشراف على معالجتها.
التنسيق مع التدقيق الداخلي والمدققين الخارجيين حيثما كان مناسباً.
ضمان أن للإدارة ضوابط مناسبة على المخاطر المالية والتشغيلية والاستراتيجية.
5. استمرارية الأعمال والمرونة
الإشراف على استمرارية الأعمال وإدارة الأزمات وأطر المرونة التنظيمية.
ضمان وجود خطط استمرارية واسترجاع مناسبة للعمليات الحيوية.
مراقبة جاهزية المنظمة للاضطرابات الكبرى والمخاطر الناشئة.
6. تقارير المخاطر والامتثال
تطوير لوحات وقوائم تقارير GRC على مستوى القيادة ومجلس الإدارة.
تقديم تقارير دورية عن المخاطر الرئيسية ومشاكل الامتثال ونقاط العجز في الضوابط وإجراءات التخفيف.
إرساء مؤشرات مخاطر رئيسية (KRIs) ومؤشرات ضوابط رئيسية (KCIs) وملامح امتثال مناسبة.
تصعيد المخاطر والامتثال المادية إلى الرئيس التنفيذي والمجلس حسب الاقتضاء.
7. الاستشارة الاستراتيجية
العمل كمستشار موثوق للرئيس التنفيذي والإدارة التنفيذية في مسائل الحوكمة والمخاطر والامتثال.
تقديم مدخلات GRC في الاستحواذات والاستثمارات والعقود الرئيسية والمشروعات والمبادرات الاستراتيجية.
تقييم تبعات المخاطر لقرارات الأعمال الكبرى.
موازنة إدارة المخاطر مع الأهداف التجارية ونمو الأعمال.
ضمان إدراج اعتبارات GRC في التخطيط الاستراتيجي واتخاذ القرار في المنظمة.
8. القيادة
قيادة وتطوير وظيفة الحوكمة والمخاطر والامتثال.
تحديد أهداف واضحة ومقاييس أداء ومعايير تشغيل لفريق GRC.
بناء علاقات قوية مع قادة الأعمال وتعزيز ملكية المخاطر عبر المنظمة.
تطوير ثقافة ترى أن المخاطر والامتثال هي مسؤوليات أعمال وليست وظائف تحكم فقط.
المهارات والكفاءات الأساسية
إتقان ممتاز للغة الإنجليزيةالمكتوبة والمحكية.
قيادة على مستوى التنفيذيين والتفكير الاستراتيجي.
معرفة قوية بـحوكمة الشركات، ERM، الامتثال، والضوابط الداخلية.
فهم قوي للبيئات التنظيمية والقانونية.
تقييم المخاطر ونمذجة المخاطر.
تطوير السياسات والأطر.
استمرارية الأعمال وإدارة الأزمات.
مهارات تحليلية ومهارات حل المشكلات قوية.
مهارات اتصال وتقديم عروض ممتازة.
مهارات تفاوض وإدارة أصحاب المصالح قوية.
تقارير إلى المجلس ومستوى التنفيذي.
مستوى عالٍ من النزاهة والاستقلالية والحكم المهني.
إمكانية التأثير في أصحاب المصلحة الكبار وتحدي القرارات بشكل بنّاء.
فهم تجاري وعملي قوي.
المؤهلات والخبرة المعتادة
درجة البكالوريوس في الأعمال، المالية، إدارة المخاطر، القانون، المحاسبة، الاقتصاد، أو تخصص ذات صلة.
يفضل الحصول على درجة الماجستير/MBA أو مؤهل دراسي عالٍ ذي صلة.
عادةً خبرة مهنية 15+ عامًا ذات صلة، مع خبرة كبيرة في مناصب قيادية عليا في GRC، المخاطر، الامتثال، الحوكمة، التدقيق، أو قيادات مشابهة.
خبرة موثقة في تطوير وتنفيذ أطر GRC على مستوى المؤسسة.
خبرة في تقديم المشورة إلى Boards، لجان المجلس، الرؤساء التنفيذيين، والإدارة التنفيذية.
خبرة في إدارة منظمات معقدة وعدة أصحاب مصلحة.
شهادات مهنية ذات صلة ستكون ميزة، مثل CRMA، CIA، CISA، CCEP، CGEIT، FRM، CPA/ACCA، أو ما يعادلها، حسب متطلبات المنظمة.
مقاييس النجاح الأساسية
يمكن قياس أداء CGRCO من خلال:
نضوج وفعالية إطار GRC الخاص بالمنظمة.
انخفاض المخاطر المادية وغير المحكومة.
الامتثال للمتطلبات التنظيمية والداخلية المعمول بها.
إغلاق في الوقت المناسب لإجراءات التخفيف من المخاطر والضوابط.
فعالية تقارير المخاطر للمجلس والتنفيذيين.
تحسن ثقافة المخاطر والمسؤولية.
فعالية استمرارية الأعمال والمرونة.
انخفاض الانتهاكات الكبيرة للامتثال وفشل الضوابط.
الدمج الناجح لـ GRC في القرارات الاستراتيجية والقرارات الاستثمارية.
مختصر: يعد CGRCO المستشار المستقل الأول ورائد المؤسسة في الحوكمة والمخاطر المؤسسية والامتثال، مما يضمن أن الشركة يمكنها متابعة أهدافها الاستراتيجية والتجارية مع فهم وإدارة والسيطرة على المخاطر المرتبطة بتلك الأهداف.
المتطلبات
15+ سنة من الخبرة التقدمية في الحوكمة وإدارة مخاطر المؤسسة والامتثال والضوابط الداخلية والتدقيق أو مجالات ذات صلة، بما في ذلك خبرة قيادية عليا كبيرة.
درجة البكالوريوس في الأعمال، المالية، إدارة المخاطر، القانون، المحاسبة، أو تخصص ذو صلة; يفضل الحصول على درجة الماجستير/MBA.
خبرة موثقة في تطوير وتنفيذ أطر GRC على مستوى المؤسسة والسياسات واستراتيجيات إدارة المخاطر.
معرفة قوية بـ الحوكمة المؤسسية، ERM، الامتثال التنظيمي، الضوابط الداخلية، استمرارية الأعمال، وضمان المخاطر.
خبرة مثبتة في تقديم المشورة إلى Boards وBoards Committees والرؤساء التنفيذيين والإدارة التنفيذية في مسائل حوكمة ومخاطر وامتثال مهمة.
فهم قوي لـالتعرف والتقييم والحد والمراقبة والإبلاغ عن المخاطر.
القدرة على وضع ومراقبة شهية المخاطر ومؤشرات KRIs والامتثال ونُظُم الضبط.
تفكير استراتيجي وتحليل وحل مشكلات واتخاذ قرارات ممتازة.
قيادة قوية وإدارة أصحاب المصلحة والتفاوض ومهارات التأثير.
إتقان ممتاز للغة الإنجليزية مكتوبة ومحادثة، مع قدرات تواصل وعرض على مستوى التنفيذيين.
مستوى عالٍ من النزاهة والاستقلالية والحكم المهني والسرية.
شهادات مهنية ذات صلة مثل CIA، CRMA، CISA، FRM، CCEP، CPA/ACCA، أو ما يعادلها مرغوبة.
الخبرة في منظمة كبيرة ومعقدة ومنظمة مُ solicited وصفة تنظيمية كبيرة مرغوبة للغاية.