> job detail
S
👽Other
Analyst, Risk Management
Standard Chartered · Bukit Jalil KL, MY
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
Bukit Jalil KL, MY
languages
—
tools
—
> education
bachelors
> description
<div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Job Summary</b></H2>
</div><div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"><strong>This role could be based in Malaysia or India. When you start the application process you will be presented with a drop down menu showing all countries, please ensure that you select a country where the role is based.</strong></span></p>
<p> </p>
<p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• The role is responsible for supporting, coordinating, and strengthening the Bank’s control environment for AI-amplified risks across key risk domains, including Technology, Cyber, Data & Privacy, Compliance & Conduct, Operational Risk, and Third-Party & Concentration Risk. The objective is to ensure that AI-enabled products, platforms, processes, tools, and ways of working are assessed, governed, monitored, and controlled in line with the Bank’s risk appetite, Group policies and standards, applicable AI requirements, regulatory expectations and external obligations.<br>• The role operates as a key member of the Risk Management - AI function within the Technology and Operations (T&O) division and works in close partnership with stakeholders across existing risk domains, First Line process and control owners, and central AI Governance teams. The role is focused on ensuring AI risk considerations are embedded into existing risk management processes and control environments and is accountable for driving execution across assigned domains. This includes supporting maintaining trackers, coordinating workstream activities, preparing governance materials, collecting evidence, supporting control gap analysis, maintaining issue and action logs, assisting with RCSA readiness, supporting MI / KRI / KPI production, and coordinating information required for audit, assurance, regulatory, and RFI responses.<br>• The role is expected to support the mobilisation and embedding of sustainable AI risk management practices into BAU. This includes helping domain teams understand AI-amplified risks, translating AI-related control requirements into practical operating processes, supporting governance and reporting, and driving continuous improvement of the control environment as the Bank’s use of AI evolves.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Key Responsibilities</b></H2>
</div><div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• This role is involved in supporting the execution of the Bank’s AI-amplified risk management agenda and assisting with the coordination of activities across existing risk domains impacted by AI. Reporting to the Lead, Risk Management - AI, the primary roles is focused on:</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"> • Supporting AI-amplified risk discovery, baselines assessment, control gap analysis, control uplift tracking, and BAU monitoring activities.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"> • Assisting domain teams in documenting AI-related risk impacts, controls, actions, issues, dependencies, and evidence.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"> • Supporting governance routines, workstream coordination, progress reporting, and committee material preparation.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"> • Maintaining accurate trackers, logs, repositories, management information, and evidence packs for AI risk activities.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"> • Supporting RCSA, control testing, assurance, audit, regulatory, and RFI related activities relating to AI-amplified risks.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black"> • Helping ensure that AI-related risk information is complete, consistent, timely, and escalated where required.</span><br><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Processes</span></strong><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Embed AI-amplified risk considerations into existing domain processes, standards, and control routines.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Assess were AI adoption changes processes and relevant control expectations, ownership, evidence, or escalation requirements.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support process owners in uplifting controls, and procedures for AI-impacted activities</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Coordinate dependencies between AI Governance, Technology, Cyber, Data, Compliance, and Third-Party risk teams.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Track delivery of agreed process and control uplift actions</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b></b></H2>
</div><div><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Risk Management</span></strong><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Identify, assess, and challenge AI-amplified risks across existing risk domains.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support materiality assessments, control gap reviews, and residual risk assessments for AI-impacted processes, tools, platforms, vendors, and use cases.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Provide clear risk opinions and recommendations to support control uplift, risk acceptance, remediation, and escalation decisions.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Monitor AI-related issues, control gaps, incidents, risk acceptances, and management actions.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support integration of AI-amplified risks into RCSA, control testing, MI, KRIs, KCIs, and BAU risk reporting.</span><br><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Governance </span></strong><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Manage AI risk workstreams and ensure delivery remains aligned to agreed scope, timelines, and governance expectations in partnership with central AI Risk governance teams.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Prepare governance updates, executive summaries, committee materials, and decision papers on AI-amplified risk topics.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Escalate material risks, blockers, dependencies, and unresolved control gaps through appropriate governance forums.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support clear ownership across domain teams, control owners, AI governance, and Risk Management.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Maintain auditable records of key decisions, actions, issues, and escalations.</span><br><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">Regulatory & Business Conduct </span></strong><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Ensure activities are aligned to Group policies, AI standards, regulatory expectations, and applicable conduct requirements.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support mapping of AI-amplified risks to relevant regulatory, policy, and control obligations.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Promote responsible AI adoption by escalating risks of unfair, inappropriate, opaque, or poorly controlled outcomes.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support audit, assurance, regulatory, and RFI responses relating to AI-amplified risks.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Display exemplary conduct and uphold the Group’s Values, Code of Conduct, and risk management standards.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b></b></H2>
</div><div><p><span style="font-family:arial, helvetica, sans-serif;color:black"><strong><span style="font-size:10.0pt">Key Stakeholders</span></strong></span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• AI Leadership Team</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• T&O Management Team</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Central AI Governance and AI Enablement Teams</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• 2nd Line of Defence functions</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Governance & Optimisation teams</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Group Internal Audit</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• T&O Risk Management Teams </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• T&O Technology Process Owners</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Regulators and their appointed auditors (where applicable)</span><br><span style="font-family:arial, helvetica, sans-serif;color:black"><strong><span style="font-size:10.0pt">Other Responsibilities</span></strong></span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Support ad-hoc tactical and strategic risk initiatives to meet business and operational demands through thoughtful partnership.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Skills and Experience</b></H2>
</div><div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Experience in AI Risk Management within a large, regulated financial services environment.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Preferably experience in one or more of the following risk domains within a large, regulated, financial services environment: Technology, Cyber, Compliance, Conduct, Data, and Third Party</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Strong understanding of technology control environments (people, process, and technology) and their application within software engineering and technology delivery domains.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Experience conducting or supporting deep‑dive risk reviews of emerging technologies, new platforms, or material technology changes.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Ability to provide clear, defensible risk opinions and effective challenge to senior stakeholders across Technology & Operations, and Risk Management functions.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Strong written and verbal communication skills, with the ability to produce concise, high‑quality risk documentation suitable for audit, regulatory, and governance review.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Strong analytical skills, detail-focused with the ability to interpret large volume of information.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Problem solving skills with ability to influence across all levels of business.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Ability to independently drive initiatives with minimum hands-on supervision.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b></b></H2>
</div><div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• AI Risk</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Technology Risk </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Cybersecurity Risk</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Compliance Risk</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Risk and Control Self-Assessment (RCSA)</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• IT Standards, Procedures & Policies</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Controls Design and Assessment</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• Process Improvement</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt;color:black">• IT Audit and Control</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Qualifications</b></H2>
</div><div><p><span style="font-size:10.0pt;color:black;font-family:arial, helvetica, sans-serif">• Bachelor’s degree or equivalent in Engineering, Computer Science, Information Technology, Risk Management, or a related discipline.</span><br><span style="font-size:10.0pt;color:black;font-family:arial, helvetica, sans-serif">• Post‑graduate qualification (e.g. MBA, PGDM, M.Tech, or equivalent) is preferred but not mandatory.</span><br><span style="font-size:10.0pt;color:black;font-family:arial, helvetica, sans-serif">• Relevant professional certifications in Technology Risk, Information Security, Audit, or Risk Management (e.g. CISA, CRISC, CISSP or equivalent) are desirable.</span><br><span style="font-size:10.0pt;color:black;font-family:arial, helvetica, sans-serif">• Ideally 5+ years of experience in banking, analytical or another relevant environment</span><br><span style="font-size:10.0pt;color:black;font-family:arial, helvetica, sans-serif">• Languages: English and/or local language skills as relevant to country requirements</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>About Standard Chartered</b></H2>
</div><div><p>We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.</p>
<p>Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.</p>
<p>Together we:</p>
<ul>
<li><b>Do the right thing</b> and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do</li>
<li><b>Never settle,</b> continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well</li>
<li><b>Are better together,</b> we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term</li>
</ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:14.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>What we offer</b></H2>
</div><div><p><b>In line with our Fair Pay Charter,</b> we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.</p>
<ul>
<li><b>Core bank funding for retirement savings, medical and life insurance,</b> with flexible and voluntary benefits available in some locations.</li>
<li><b>Time-off</b> including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.</li>
<li><b>Flexible working</b> options based around home and office locations, with flexible working patterns.</li>
<li><b>Proactive wellbeing support</b> through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits</li>
<li><b>A continuous learning culture</b> to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.</li>
<li><b>Being part of an inclusive and values driven organisation,</b> one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.</li>
</ul></div></div></div>