Purpose of the role
The purpose of this position ( VP or Director of RISK ORM territory, “ORO” hereafter) is to ensure effective LoD2 oversight of operational risk in territory. The role provides RISK ORM APAC, Territory Management and senior stakeholders with transparent and forward-looking view of territory’s operational risk profile. The scope covers all relevant business lines and legal entities. This primarily includes key activities across Global Banking, Global Markets, ALMT, Functions and other activities wherever deemed applicable.
The RISK ORM territory mandate is to follow the Mission Statement of RISK ORM APAC and to independently challenge and supervise the operational risk management framework of BNPP in territory. This mandate is defined in the level 2 procedure “Organizational framework and governance for Operational Risk Management & Permanent Control Framework”.
The role also ensures the consistent application of Group RISK ORM governance, methodologies and procedures in territory, with appropriate local adaptation where required.
Under a joint accountability model, RISK ORM territory ORO works closely with Regional OROs, Regional Transversal OROs, the territory CRO and relevant stakeholders to ensure coherent operational risk supervision across territory.
The RISK ORM territory ORO is a member of the RISK ORM APAC Management Committee. He / she reports regionally to the Head of RISK ORM APAC and locally to the territory CRO.
Role and Responsibilities:
The RISK ORM territory ORO has the following roles and responsibilities in territory as the leading LoD2 person in managing operational risks within the scope of RISK ORM APAC, including but not limited to, anti-fraud, third-party risk management, ICT risk management, operational resilience and personal data protection, etc.
1. Be the Risk Officer with expertise and hands-on skills in ORM
· Understand how key business and support processes operate in practice, beyond a purely theoretical or governance perspective.
· Maintain sufficient knowledge of end-to-end processes flows to develop an informed and independent view of operational risks.
· Maintain regular engagement with LoD1 stakeholders to understand process changes, control weaknesses and emerging risks.
· Use territory-level process knowledge to support deep dives, RCSA challenge, incident analysis and governance discussions.
· Develop an independent view of operational risks based on direct understanding of activities rather than relying solely on reports, dashboards or self-assessments prepared by LoD1.
· Maintain coverage across all relevant business lines, activities and legal entities within the territory.
2. Implement Operational Risk Framework and Provide Independent Challenges
· Ensure consistent implementation and application of the Group ORM Framework, governance, methodologies, policies and procedures across all local business lines and legal entities.
· Adapt the framework locally where required, in liaison with relevant RISK ORM APAC teams.
· Maintain appropriate proximity with the businesses while preserving independent LoD2 challenge.
· Conduct hands-on process reviews and engage in deep dives with LoD1 for each business line.
· Review and challenge RCSA outcomes, risk assessments, control environment assessments, action plans and remediation measures.
3. Monitor, Report and Escalate
· Monitor operational risk events, material incidents, emerging risks and technology-related risks.
· Provide timely risk assessments, alerts and escalation, remedial plan to territory Management, RISK ORM APAC and relevant stakeholders regarding material operational risk matters.
· Contribute to the identification, assessment and follow-up of remediation actions addressing material operational risk issues jointly with regional ORM teams.
· Support crisis management and incident management activities following significant operational risk events, where required.
4. Ensure Governance and Control and Operational Resilience
· Act as the primary LoD2 interlocutor for local management, local control functions, LoD1 teams on operational risk and local regulatory matters.
· Provide a consolidated, transparent and forward-looking view of territory operational risk profile through appropriate reporting, dashboards and governance forums.
· Represent RISK ORM in local and regional governance committees, including NAC, TAC, Internal Control Committees and other relevant operational risk forums.
· Contribute to the sign-off process on key decisions, exemptions and remediation plans where operational risk and permanent control aspects are involved.
· Support local regulatory inspections, reviews and requests relating to operational risk management.
· Work jointly with regional ORM teams and territory management teams on operational resilience.
5. Coordinate Transversal Risk Themes and Framework Enhancement
· Act as local correspondent for transversal themes under the responsibility of RISK ORM, including anti-fraud, third-party risk management, ICT risk, operational resilience, and personal data protection
· Operate under the Joint Accountability Model with Regional OROs, Regional Transversal OROs and the territory CRO to combine local oversight with regional expertise.
· Contribute to RISK ORM APAC and global initiatives, including projects, methodology enhancements and continuous improvement of operational risk management practices.
· Assist other independent LoD2 functions, including Compliance, Legal and Finance risk management, where expertise on RISK ORM themes or processes is required or requested.
6. Promote Risk Culture, Knowledge Sharing and Professionalization
· Promote operational risk awareness and disseminate a strong operational risk culture across all relevant business lines and functions in territory.
· Support relevant training, read across, and interpretation of ORM framework.
· Build strong partnerships with LoD1 stakeholders while maintaining independent challenges.
· Support knowledge sharing, harmonization of practices, continuous enhancement and professionalization of Operational Risk Management across territory and APAC.
Competencies (Technical / Behavioural)
Technical:
· Strong analytical skills & synthesis ability
· In-depth CIB-metier products and processes knowledge
· Sensitivity and/or experience in operational risk
· Working knowledge of other business domains will be an advantage.
Soft skills:
· Strong interpersonal skills in communication, negotiation, influencing skills, teamwork
· Excellent verbal and written communication skills
· English: fluent speaking, reading and writing
· Local language: fluent speaking, reading and writing preferred.
Specific Qualifications Required
· At least 10 years of relevant experience in risk management, or other control functions, or relevant exposures to operations and controls background.
· Knowledge of key territory regulatory requirements is required.
· Knowledge and experience in end-to-end process flows and associate risks and controls in the area of Front/Middle/Back Office, Operations or Functional role(s) are desired.
· Robust knowledge of banking products in Corporate & Institutional Banking is an advantage.