Risk Management Officer

roomDar es Salaam

business_centerFull Time

book1 Direct Reports

bookmark Intermediate

directions_carDriving License Not Required

flagOnly Open to Tanzanian Nationals

access_timeExpiring in 6 Days

businessTelecommunication

Summary

The Risk Management Officer is responsible for supporting the identification, assessment, monitoring and management of risks that may affect company's operations, financial performance, customers, systems, products and strategic objectives. 

The position will maintain the company's enterprise risk management framework, coordinate risk assessments across departments, monitor agreed mitigation actions and provide 
management with timely information on significant and emerging risks. 


The role will help ensure that risks are identified early, assigned to responsible owners and effectively managed within acceptable levels. 

Responsibilities

Enterprise Risk Management 

  •  Support implementation and continuous improvement of the company's Enterprise Risk Management framework. 
  •  Coordinate risk identification and assessment activities across all departments. 
  •  Maintain a comprehensive and updated enterprise risk register. 
  •  Ensure each identified risk has a clearly assigned risk owner and mitigation plan. 
  •  Monitor risk exposure and changes in the company's risk profile. 
  •  Escalate significant and emerging risks to the Head of Internal Control and management. 
  •  Support departments in understanding and applying risk-management requirements. 

 Risk Identification & Assessment 

  •  Conduct periodic risk assessments across departments, products, processes and projects. 
  •  Identify operational, financial, strategic, regulatory, technology, fraud and third-party 
    risks. 
  •  Evaluate identified risks based on likelihood and potential impact. 
  •  Support departments in determining appropriate risk treatment and mitigation measures. 
  •  Conduct risk assessments for significant business or operational changes. 
  •  Identify emerging risks that may affect HaloPesa's business objectives.

 Risk Register Management 

  •  Maintain and regularly update the company risk register. 
  •  Record identified risks, risk ratings, controls, owners and mitigation actions. 
  •  Follow up risk owners on outstanding mitigation activities. 
  •  Review overdue risk-treatment actions and escalate delays. 
  •  Ensure closed risks have sufficient evidence demonstrating that agreed actions have been implemented. 
  •  Prepare departmental and company-wide risk summaries. 

Key Risk Indicators – KRIs 

  •  Develop and maintain Key Risk Indicators for major risk areas. 
  •  Establish appropriate thresholds for monitoring risk exposure. 
  •  Collect and analyse KRI information from relevant departments. 
  •  Identify breaches or negative trends requiring management attention. 
  •  Escalate significant KRI breaches. 
  •  Continuously review KRIs to ensure they remain relevant to company's operations.

 Operational Risk Management 

  • Monitor risks arising from daily business and operational activities. 
  •  Review operational incidents, process failures and control weaknesses. 
  •  Identify root causes of significant operational incidents. 
  •  Recommend preventive and corrective measures. 
  •  Maintain an operational loss and incident database where applicable. 
  •  Identify recurring incidents and recommend long-term solutions. 

 Operational Risk Management 

  •  Monitor risks arising from daily business and operational activities. 
  •  Review operational incidents, process failures and control weaknesses. 
  •  Identify root causes of significant operational incidents. 
  •  Recommend preventive and corrective measures. 
  •  Maintain an operational loss and incident database where applicable. 
  •  Identify recurring incidents and recommend long-term solutions.

Third-Party & Partner Risk 

  •  Support risk assessment of important vendors, service providers and business partners.
  •  Identify financial, operational, compliance, technology and continuity risks arising from 
    third-party relationships.
  •  Monitor high-risk third parties where required. 
  •  Work with relevant departments to ensure appropriate mitigation measures are implemented. 
  •  Escalate significant third-party risk exposures to management.

 Incident & Loss Event Monitoring 

  • Maintain records of significant operational and risk incidents.
  • Coordinate investigation and analysis of risk events. 
  •  Assess the business impact of identified incidents. 
  •  Track corrective actions arising from incidents. 
  •  Analyse incident trends and recurring control weaknesses. 
  •  Prepare risk incident reports for management. 

Business Continuity Risk 

  •  Support assessment of risks that may disrupt critical company services. 
  •  Participate in Business Continuity and Disaster Recovery risk assessments. 
  •  Identify critical business processes and dependencies. 
  •  Support periodic testing of business continuity arrangements. 
  •  Track identified gaps and corrective actions. 

 Risk Reporting 

  • Prepare monthly, quarterly and periodic risk-management reports. 
  •  Provide management with clear information on: 
    o Top company risks 
    o Emerging risks 
    o Risk trends 
    o KRI status 
    o Outstanding mitigation actions 
    o Significant incidents 
  •  Prepare risk dashboards for management review. 
  •  Immediately escalate critical risks requiring urgent management attention. 

 KEY PERFORMANCE INDICATORS (KPIs) 

Performance will be measured against: 

  •  Percentage of departments completing scheduled risk assessments. 
  •  Percentage of identified risks with assigned owners and mitigation plans. 
  •  Percentage of mitigation actions completed within agreed deadlines. 
  •  Number of overdue high-risk mitigation actions. 
  •  Timeliness and accuracy of risk reports. 
  •  Percentage of significant projects and products assessed before implementation. 
  •  Effectiveness of KRI monitoring. 
  •  Number of recurring operational incidents. 
  •  Timely escalation of critical and emerging risks. 
  •  Accuracy and completeness of the enterprise risk register. 
  •  Closure rate of risk findings and corrective actions.

EXPECTED RESULT 
The Risk Management Officer is expected to establish a proactive risk-management culture where significant risks are identified early, properly assessed, assigned to responsible 
owners and mitigated within agreed timelines.

Education and Qualifications

  • Bachelor's Degree in Risk Management, Finance, Accounting, Business Administration, Economics, Banking or a related field.
  • Professional certification in Risk Management, Internal Audit, Compliance or a related field will 
    be an added advantage.

Requirements

  •  Minimum of 2–4 years of relevant experience in risk management, internal control, audit, compliance, banking or financial services. 
  •  Experience within mobile money, fintech, telecommunications or banking will be an added advantage. 
  •  Experience in risk assessment, risk registers and mitigation tracking is desirable. 

Characteristics

 KNOWLEDGE & SKILLS 

The job holder should have: 

  •  Good understanding of enterprise and operational risk management. 
  •  Strong risk-identification and assessment skills. 
  •  Understanding of internal controls. 
  •  Good analytical and problem-solving skills. 
  •  Ability to analyses risk trends and incidents. 
  •  Strong Excel, reporting and presentation skills. 
  •  Good documentation skills. 
  •  Strong communication and stakeholder-management skills. 
  •  Ability to challenge control weaknesses professionally. 
  •  Strong follow-up and deadline-management skills. 

CORE COMPETENCIES 

  •  Analytical thinking. 
  •  High integrity. 
  •  Risk awareness. 
  •  Attention to detail. 
  •  Independent judgment. 
  •  Accountability. 
  •  Problem-solving. 
  •  Strong follow-up. 
  •  Results orientation. 
  •  Professional communication. 
  •  Ability to work across different departments. 
  •  Ability to work under pressure. 

 

Reporting To

Head of Internal Control 

-

-

-

Telecommunication: 4 Years

-

-

-

-