Chief Governance, Risk & Compliance Officer (CGRCO)

Translated
On-site Part Time
Saudi , Riyadh
--

Job Details

Position Summary

The Chief Governance, Risk & Compliance Officer will provide executive leadership and strategic oversight of the organization’s governance, enterprise risk management, compliance, and internal control frameworks. The role is responsible for ensuring that the organization operates with strong governance, effective risk management, regulatory compliance, and appropriate controls while supporting sustainable business growth and the achievement of strategic objectives.

The CGRCO will advise the Board of Directors, Board Committees, CEO, and Executive Management on key governance, risk, and compliance matters and will establish a robust GRC framework aligned with the organization’s strategy, regulatory requirements, risk appetite, and industry best practices.

Key Responsibilities

1. Governance

  • Establish and maintain a comprehensive corporate governance framework.

  • Develop and maintain governance policies, procedures, authorities, and decision-making frameworks.

  • Support the Board and its committees on governance matters.

  • Ensure appropriate delegation of authority and accountability across the organization.

  • Monitor compliance with corporate governance requirements and internal policies.

  • Promote a culture of transparency, accountability, ethics, and responsible decision-making.

2. Enterprise Risk Management

  • Develop and lead the organization’s Enterprise Risk Management (ERM) framework.

  • Establish risk appetite, risk tolerances, risk policies, and reporting mechanisms.

  • Identify, assess, monitor, and report strategic, operational, financial, legal, regulatory, technology, reputational, and emerging risks.

  • Maintain the corporate risk register and oversee mitigation plans.

  • Provide executive management and the Board with independent assessment of the organization's risk profile.

  • Integrate risk management into strategic planning, investment decisions, major projects, and business operations.

3. Compliance

  • Establish and oversee the organization-wide compliance framework.

  • Monitor compliance with applicable laws, regulations, contractual obligations, and internal policies.

  • Develop compliance policies, procedures, standards, and controls.

  • Oversee regulatory reporting and compliance monitoring.

  • Identify and address compliance gaps and potential violations.

  • Lead or oversee compliance investigations, remediation, and corrective actions where appropriate.

  • Promote a strong culture of ethical and compliant business conduct.

4. Internal Controls

  • Establish and maintain an effective internal control framework.

  • Assess the effectiveness of key business and financial controls.

  • Identify control deficiencies and oversee remediation.

  • Coordinate with Internal Audit and external auditors where appropriate.

  • Ensure management has appropriate controls over financial, operational, and strategic risks.

5. Business Continuity & Resilience

  • Oversee business continuity, crisis management, and organizational resilience frameworks.

  • Ensure critical business processes have appropriate continuity and recovery plans.

  • Monitor organizational preparedness for major disruptions and emerging risks.

6. Risk & Compliance Reporting

  • Develop executive and Board-level GRC dashboards and reports.

  • Provide regular reporting on key risks, compliance issues, control deficiencies, and mitigation actions.

  • Establish appropriate Key Risk Indicators (KRIs), Key Control Indicators (KCIs), and compliance metrics.

  • Escalate material risks and compliance matters to the CEO and Board as appropriate.

7. Strategic Advisory

  • Act as a trusted advisor to the CEO and Executive Management on governance, risk, and compliance matters.

  • Provide GRC input into acquisitions, investments, major contracts, projects, and strategic initiatives.

  • Assess the risk implications of major business decisions.

  • Balance risk management with commercial objectives and business growth.

  • Ensure GRC considerations are incorporated into the organization's strategic planning and decision-making.

8. Leadership

  • Lead and develop the Governance, Risk & Compliance function.

  • Establish clear objectives, performance measures, and operating standards for the GRC team.

  • Build strong relationships with business leaders and promote risk ownership throughout the organization.

  • Develop a culture in which risk and compliance are viewed as business responsibilities rather than solely as control functions.

Key Skills & Competencies

  • Excellent command of written and spoken English.

  • Executive-level leadership and strategic thinking.

  • Strong knowledge of corporate governance, ERM, compliance, and internal controls.

  • Strong understanding of regulatory and legal environments.

  • Risk assessment and risk modelling.

  • Policy and framework development.

  • Business continuity and crisis management.

  • Strong analytical and problem-solving skills.

  • Excellent communication and presentation skills.

  • Strong negotiation and stakeholder management.

  • Board and executive-level reporting.

  • High level of integrity, independence, and professional judgment.

  • Ability to influence senior stakeholders and challenge decisions constructively.

  • Strong commercial and business acumen.

Typical Qualifications & Experience

  • Bachelor’s degree in Business, Finance, Risk Management, Law, Accounting, Economics, or a related discipline.

  • Master’s degree/MBA or relevant postgraduate qualification preferred.

  • Typically 15+ years of relevant professional experience, with significant experience in senior GRC, risk, compliance, governance, audit, or related leadership roles.

  • Proven experience developing and implementing enterprise-wide GRC frameworks.

  • Experience advising Boards, Board Committees, CEOs, and Executive Management.

  • Experience managing complex organizations and multiple stakeholders.

  • Relevant professional certifications would be advantageous, such as CRMA, CIA, CISA, CCEP, CGEIT, FRM, CPA/ACCA, or equivalent, depending on the organization's requirements.

Key Success Measures

The CGRCO's performance could be measured through:

  • Maturity and effectiveness of the organization's GRC framework.

  • Reduction in material and unmanaged risks.

  • Compliance with applicable regulatory and internal requirements.

  • Timely closure of risk and control remediation actions.

  • Effectiveness of Board and executive risk reporting.

  • Improvement in risk culture and accountability.

  • Effectiveness of business continuity and resilience.

  • Reduction in significant compliance breaches and control failures.

  • Successful integration of GRC into strategic and investment decisions.

In short: the CGRCO is the organization's senior independent advisor and leader for governance, enterprise risk, and compliance, ensuring that the company can pursue its strategic and commercial objectives while understanding, managing, and controlling the risks associated with those objectives.

Requirements

  • 15+ years of progressive experience in governance, enterprise risk management, compliance, internal controls, audit, or related fields, including significant senior leadership experience.

  • Bachelor’s degree in Business, Finance, Risk Management, Law, Accounting, or related discipline; Master’s degree/MBA preferred.

  • Proven experience developing and implementing enterprise-wide GRC frameworks, policies, and risk management strategies.

  • Strong knowledge of corporate governance, ERM, regulatory compliance, internal controls, business continuity, and risk assurance.

  • Demonstrated experience advising Boards, Board Committees, CEOs, and Executive Management on significant governance, risk, and compliance matters.

  • Strong understanding of risk identification, assessment, mitigation, monitoring, and reporting.

  • Proven ability to establish and monitor risk appetite, KRIs, compliance metrics, and control frameworks.

  • Excellent strategic thinking, analytical, problem-solving, and decision-making skills.

  • Strong leadership, stakeholder management, negotiation, and influencing skills.

  • Excellent written and spoken English, with strong executive-level communication and presentation capabilities.

  • High level of integrity, independence, professional judgment, and confidentiality.

  • Relevant professional certifications such as CIA, CRMA, CISA, FRM, CCEP, CPA/ACCA, or equivalent are desirable.

  • Experience in a large, complex, regulated, or multinational organization is highly desirable.

Similar Jobs