All open roles
Open role

Manager – Enterprise Risk & Governance at MAL Consultancy

MAL Consultancy · Nairobi

MAL ConsultancyNairobiPosted 7 October 2026Apply by 17 October 2026

INTRODUCTION

Our client, a real-time payment services company established under the National Payment System (NPS) Act, to address the challenge of inter-bank money transfers in the country and beyond, is seeking to onboard a Manager – Enterprise Risk & Governance.

JOB SUMMARY

The Manager – Enterprise Risk & Governance is responsible for leading enterprise risk management, third-party risk management, audit coordination, operational quality assurance, policy governance, and enterprise risk culture initiatives. S/he will serve as a key second line of oversight to the business, ensuring that enterprise risks are identified, assessed, monitored, mitigated, and reported effectively while supporting regulatory compliance and sound governance practices. The Manager – Enterprise Risk & Governance will need to have strong partnership management ability in order to engage both internal and external stakeholders.

DUTIES & RESPONSIBILITIES

Enterprise Risk Management & Operational Risk

Operationalize the enterprise risk management framework and Risk Appetite Statement (RAS).

Conduct quarterly departmental risk register revalidations with business unit heads

Maintain the enterprise risk heat map and monitor Key Risk Indicators (KRIs)

Conduct operational procedure quality assurance reviews across key business functions

Facilitate quarterly enterprise risk deep-dive sessions with business unit heads.

Establish real-time risk tracking and reporting interfaces across operational units.

Support identification, assessment, treatment, monitoring, and escalation of enterprise and operational risks.

Third-Party Risk Management & Vendor Governance

Manage the end-to-end Third-Party Risk Management (TPRM) lifecycle

Conduct initial and annual risk due diligence assessments for key vendors and third-party partners

Monitor vendor compliance with contractual Service Level Agreements (SLAs) and applicable security standards

Maintain an up-to-date TPRM inventory and continuous vendor risk scorecards

Ensure material third-party risks are appropriately escalated and mitigated.

Audit Liaison & Second-Line Oversight

Coordinate internal, external, and Central Bank of Kenya (CBK) supervisory audit engagements

Coordinate audit planning, onsite activities, document requests, interviews, and management responses

Maintain a centralized audit issue and remediation tracking register

Monitor business-unit remediation timelines

Conduct post-remediation validation testing to confirm closure of audit findings.

Policy Governance & Compliance Excellence

Conduct enterprise-wide policy gap assessments

Establish baseline compliance maturity assessments across operational units

Review and remediate outdated, incomplete, or missing enterprise policies

Coordinate company-wide policy attestation exercises

Support policy harmonization and legal governance

Support migration of contract administration to an automated Contract Lifecycle Management (CLM) platform integrated with TPRM processes

Enterprise Risk Culture & Awareness

Design and deliver annual risk management training covering ERM, AML/CFT, data privacy, and related risk areas

Establish and coordinate departmental risk champions

Develop risk accountability and micro-training initiatives

Conduct quarterly risk awareness and accountability sessions.

Cross-Border & Virtual Asset Risk

Develop risk controls for regional remittance and cross-border payment channels

Establish sanctions screening, FX liquidity, credit, and settlement risk controls

Develop due diligence and vetting frameworks for Virtual Asset Service Providers (VASPs)

Monitor regional regulatory developments affecting virtual assets and cross-border financial flows.

Risk Appetite & Management Reporting

Facilitate Management Committee (MCT) calibration workshops on enterprise risks.

Support identification and prioritization of the Top 5 Enterprise Risks.

Develop quantitative risk metrics and Green/Amber/Red risk thresholds.

Back test proposed risk thresholds against historical incident data.

Establish automated escalation triggers for emerging risk exposures.

Coordinate the governance process for formal RAS endorsement and Board Audit & Risk Committee (BARC) approval.

Operational Excellence

Maintain knowledge of the function, stay abreast with the latest practices, trends, and technologies

Model best practices in enterprise risk and governance operations and activities in order to ensure maintenance of quality performance

Update job knowledge by participating in conferences and educational opportunities, reading professional publications, maintaining personal networks, and participating in relevant professional associations

Maintain quality service and partnerships by establishing and enforcing company policies, procedures, standards, and values

Put in place proper quality control checks and balances within each operational activity assigned to the function

Regularly report on key performance indicators (KPIs) for all enterprise risk & governance

–

led projects and operations, demonstrating progress towards established goals and identifying areas for improvement.

Any other duties as required.

EDUCATION, SKILLS, KNOWLEDGE & EXPERIENCE REQUIRED

B

achelor’s Degree in Risk Management, Finance, Accounting, Business Administration, Economics, Law, Information Systems, or any other related discipline

Professional qualification in risk, audit, compliance, governance, or a related field.

Relevant professional certifications such as CRMA, CERM, FRM, CIA, CISA, CPA/ACCA, or equivalent is desirable

Enterprise risk management and risk framework implementation.

Operational risk assessment and mitigation.

Third-Party Risk Management (TPRM) and vendor due diligence.

Audit coordination, engagement management, and remediation tracking.

Policy governance, gap assessment, and compliance maturity frameworks.

Risk appetite and KRI/KPI development and backtesting.

Regulatory and compliance risk awareness across virtual assets, cross-border channels, and payment systems

Contract and SLA governance (including CLM platform integration)

Proficiency in risk management, reporting, GRC, and data-analysis tools

Risk reporting and executive-level presentation

Facilitation, workshop delivery, and training skills

Project and change management skills

Attention to detail, and sound professional judgment

Ability to work across multiple business functions and influence stakeholders without direct authority.

A collaborative working style and a strong business partnering orientation

Knowledge of applicable laws and regulations within the field of enterprise risk and governance with a strong understanding of business issues and opportunities

High level of integrity, confidentiality, trust, and dependability with a strong sense of urgency

Results-oriented, entrepreneurial, self-motivated, self-starter, who is flexible and adaptable to rapid change and has the ability to work in a fast-paced, high-demand environment

Experience translating KPIs to teams to get buy-in and results

Strong interpersonal, communication, and presentation skills with a good focus on organization and enhanced multitasking abilities

Ability to leverage AI systems and tools with a good grasp of enterprise risk & governance management systems

Ability to communicate information, whether technical or non-technical to stakeholders in a clear and concise manner

Highly analytical with quantitative risk assessment and strong problem-solving skills.

Let RezSync handle this application.

Sign up, upload your resume, and RezSync tailors your documents to roles like this one and applies for you — with a full log and a pause switch you own.

Prefer to apply yourself? Apply on jobwebkenya.com