To lead the establishment, maintenance, and continuous enhancement of the Enterprise Risk Management (ERM) Framework across e& Afghanistan by providing independent risk oversight, challenge, monitoring, reporting, and advisory support to promote effective management of risks within the approved risk appetite. The role serves as a second-line risk oversight function, promoting a strong risk culture and informed decision-making. In addition, the role provides independent oversight of the Internal Controls Framework and coordinates and monitors risk-based control review, testing, and remediation activities in alignment with e& Group requirements.
• Lead and coordinate enterprise-wide risk identification, assessment, evaluation, monitoring, and reporting activities covering strategic, operational, financial, regulatory, compliance, fraud, cybersecurity, technology, business continuity, and reputational risks.
• Facilitate periodic risk assessments and Risk C Control Self-Assessments (RCSA) across business functions to identify emerging risks, assess control effectiveness, and evaluate residual risk exposure.
• Maintain the Enterprise Risk Register, ensuring significant risks are appropriately documented, assessed, assigned to risk owners, and supported by mitigation plans.
• Develop, maintain, and monitor risk appetite statements, risk tolerance thresholds, Key Risk Indicators (KRIs), and Key Control Indicators (KCIs), and escalate significant breaches and exposures to management.
• Facilitate and oversee the documentation and periodic review of risks, controls, control ownership, testing procedures, and remediation plans for critical business processes.
• Coordinate and oversee the annual Internal Controls Review and Testing Program to assess the design adequacy and operating effectiveness of key controls.
• Identify control deficiencies, process weaknesses, and governance gaps through risk and control assessments, and provide independent recommendations to management to strengthen the effectiveness of the control environment.
• Monitor and report the implementation status of risk mitigation actions, control remediation plans, and risk-related recommendations arising from Internal Audit, External Audit, regulatory reviews, and management assessments.
• Prepare and present periodic risk and internal control reports to the VP Risk C Assurance, Executive Risk Management Committee (ERMC), and the Audit C Risk Management Committee (ARMC), highlighting key risk exposures, emerging risks, control weaknesses, trends, and mitigation progress.
• Collaborate with Internal Audit, Compliance, Legal, Regulatory Affairs, Information Security, Finance, Technology, Human Resources, and business functions to enhance enterprise-wide risk and control management practices.
• Act as Secretary to the Executive Risk Management Committee (ERMC) chaired by the CEO by coordinating meetings, preparing agendas and risk reports, recording minutes, tracking action items, and facilitating timely closure of agreed actions.
• Assess and monitor regulatory and compliance risks and coordinate with relevant stakeholders to support adherence to telecommunications regulations, license obligations, corporate policies, and applicable laws.
• Provide independent oversight of Business Continuity Management (BCM) and Disaster Recovery (DR) testing exercises and monitor implementation of agreed improvement actions.
• Evaluate cybersecurity, information security, data privacy, technology, and network resilience risks in collaboration with relevant stakeholders and ensure such risks are appropriately reflected in the Enterprise Risk Register.
• Provide risk advisory support for strategic initiatives, major projects, investments, new products, digital transformation programs, outsourcing arrangements, and other significant business decisions.
• Promote a strong risk-aware and control-conscious culture through communication, training, awareness initiatives, and stakeholder engagement activities.
• Monitor industry trends, emerging risks, geopolitical developments, regulatory changes, and market conditions that may impact eC Afghanistan's objectives and operations.