Operational Risk Partner Senior Manager (Quản lý cấp cao Quản Lý Rủi Ro Hoạt Động)
Description
Prudential’s purpose is to be partners for every life and protectors for every future. Our purpose encourages everything we do by creating a culture in which diversity is celebrated and inclusion assured, for our people, customers, and partners. We provide a platform for our people to do their best work and make an impact to the business, and we support our people’s career ambitions. We pledge to make Prudential a place where you can Connect, Grow, and Succeed.
Compliance Assurance is to provide assurance to the Group and Local Business Unit [LBU]’s Management on the compliance status of LBU with Group’s, Regional Office’s standards and local government regulations.
The job holder is required is to conduct the Compliance Quality Assurance reviews as per the risk based plan which ensures the Compliance risks are adequately assessed.
The Operational Risk Partner Senior Manager acts as a trusted and independent Second Line of Defence risk partner to assigned business functions.
The role provides risk expertise, oversight and constructive challenge to support sound business decisions, effective risk management and sustainable customer outcomes. It ensures that material operational and non-financial risks are appropriately identified, assessed, managed, monitored, reported and escalated in line with the Group Risk Framework, PVA requirements and applicable Vietnamese regulations.
The role also leads or supports enterprise-wide risk management activities, strengthens the quality of risk and control information, and builds the capability of business teams to take effective ownership of their risks.
Key Accountabilities / Trách nhiệm chính
A. Risk Business Partnering and Advisory
- Act as the primary 2LOD risk partner for assigned business functions, developing a strong understanding of their business objectives, processes, customers, risks and control environment.
- Provide timely, practical and principle-based risk advice to support business decisions, new initiatives, process changes, projects and transformation activities.
- Bring an independent risk perspective while working constructively with management to identify commercially practical and sustainable risk-management solutions.
- Support senior management in understanding material risk exposures, emerging risks, control weaknesses and potential impacts on customers and the Company.
- Promote clear ownership by the business for its risks, controls, incidents, issues and remediation actions.
B. Risk Identification and Assessment
- Lead and challenge Risk and Control Self-Assessments for assigned functions to ensure risks, controls and associated assessments are complete, accurate and supported by appropriate evidence.
- Oversee the identification and assessment of material operational and non-financial risks in alignment with the Group Risk Taxonomy and relevant risk appetite requirements.
- Provide independent challenge on inherent risk, control effectiveness and residual risk assessments.
- Support the identification and assessment of risks arising from business-as-usual activities, strategic initiatives, products, projects, process changes, third parties and emerging developments.
- Facilitate appropriate escalation and management attention where risks are outside appetite or not adequately controlled.
.
C. Controls, Key Indicators and Risk Monitoring
- Provide oversight and challenge on the design and effectiveness of key controls.
- Support the business in developing meaningful Key Indicators and thresholds that enable timely and forward-looking risk monitoring.
- Review risk trends, control performance, incidents, issues, audit findings and other available information to form an integrated view of the risk profile.
- Identify recurring weaknesses, systemic themes and areas where further assessment or management action may be required.
- Conduct or lead thematic reviews, risk deep dives and targeted assessments under the annual risk plan or in response to emerging concerns.
- Monitor the progress and effectiveness of risk-treatment and remediation plans, while maintaining clear accountability with the relevant business owners.
D. Incident, Issue and Action Management
- Provide 2LOD oversight, guidance and challenge throughout the incident and issue management lifecycle.
- Challenge the completeness and quality of incident impact assessments, issue statements, root-cause analysis and remediation plans.
- Ensure material incidents, issues and overdue actions are appropriately escalated to senior management and relevant governance forums.
- Monitor remediation progress and assess whether actions address the underlying risk and root cause in a sustainable manner.
- Review and approve relevant incident, issue and action records in accordance with assigned 2LOD responsibilities and applicable standards.
- Support consistent and high-quality recording of incidents, issues, actions and approvals in PRISM.
E. Risk Governance and Reporting
- Prepare and provide clear, concise and forward-looking risk insights for senior management, the Risk Committee and other governance forums.
- Ensure that risk reporting accurately reflects material exposures, control effectiveness, emerging concerns, remediation progress and management actions.
- Coordinate inputs from relevant stakeholders and challenge the quality and consistency of information before submission.
- Support the preparation of regular and ad hoc risk reports, including enterprise risk, operational risk, business control, incident and issue, project risk, business continuity and management reports.
- Escalate material risks, control deficiencies and delays in remediation in a timely manner.
- Maintain appropriate documentation and evidence to support key risk assessments, decisions, challenges and governance outcomes.
F. Risk Framework and PRISM
- Lead and support the implementation of relevant Group and PVA risk frameworks, policies, standards, methodologies and risk-management exercises.
- Translate framework requirements into practical guidance for assigned business functions.
- Oversee the quality, completeness and timeliness of risk information recorded in PRISM.
- Challenge inconsistencies between business assessments, supporting evidence, reported risk profiles and actual incidents or control performance.
- Support users in understanding and applying PRISM and relevant risk-management requirements effectively.
- Contribute to enhancements of risk methodologies, processes, governance arrangements, systems and reporting tools.
G. Risk Culture and Capability
- Build effective working relationships with Risk Owners, Control Owners, Incident Owners, Issue Owners, Risk Champions and other key stakeholders.
- Develop and deliver guidance, training and risk-awareness sessions to strengthen business risk-management capability.
- Encourage open discussion, timely escalation and constructive challenge without transferring accountability away from the business.
- Promote a risk culture based on accountability, curiosity, collaboration and sustainable action.
- Coach team members and business stakeholders to improve the quality of risk assessments, controls, risk data and decision-making.
H. Team Leadership and Management
- Lead, coach and develop assigned team members to deliver high-quality and timely risk oversight.
- Set clear priorities, allocate resources flexibly and monitor delivery against the OERM plan.
- Review and challenge work performed by team members, ensuring consistency of approach and quality of outcomes.
- Support succession planning, capability development and effective knowledge sharing across the Risk Partner team.
- Collaborate with other 2LOD teams to provide coordinated risk advice and avoid gaps or duplication in oversight.
Education
- Bachelor’s degree in Risk Management, Finance, Accounting, Business Administration, Economics, Law, Insuranc