Head: Enterprise Risk Management
Development Bank of Southern Africa DBSA · Johannesburg, Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Job Description
- The Head: Enterprise Risk is accountable for designing, implementing and continuously improving an integrated enterprise risk management framework that supports DBSA's mandate, strategy, governance and sustainable development impact. The role leads the Bank's risk appetite framework, principal and emerging risk oversight, risk culture, operational resilience, business continuity, credit and market risk monitoring, scenario analysis, and risk reporting to executive and Board governance structures. It ensures that risks are identified, assessed, treated, monitored and communicated using reliable risk intelligence, clear ownership, agreed escalation thresholds and continuous improvement practices, so that risk exposures remain within approved appetite and support informed strategic decisionmaking.
Key Responsibilities Strategic Focus
- Develop and maintain the short-, medium- and long-term Enterprise Risk strategy and execution roadmap, aligned to DBSA's mandate, corporate strategy, risk appetite and approved budget.
- Identify strategic priorities and deliverables for risk management, ensuring integration with organisational goals and regulatory requirements.
- Provide guidance and oversight on execution of the ERM strategy to support organisational resilience and sustainability.
- Lead communication, advocacy and adoption of ERM frameworks, policies, methodologies, standards and risk priorities across internal and external stakeholder groups.
Enterprise Risk Integration
- Embed consistent risk identification, assessment, treatment, monitoring and communication practices across divisions, supported by fit-for-purpose tools, policies, procedures and clear risk ownership.
- Facilitate development of risk management strategies for critical operational risks and ensure implementation of mitigation plans.
- Work with business units to identify emerging risks and design proactive solutions to minimise exposure.
- Promote a strong risk culture by integrating risk management principles into business planning and operational processes.
- Facilitate enterprise-wide risk identification, assessment and reporting processes.
- Maintain the strategic risk register, regularly reviewing the DBSA's principal risks, emerging risks and near-misses.
- Monitor adherence to the Board-approved Risk Appetite Framework, ensuring timely escalation of exposures outside appetite, allocation of accountable owners and tracking of remediation actions to closure.
- Lead emerging risk, stress-testing and scenario analysis to assess interconnected risks, inform strategic choices and strengthen operational and financial resilience.
- Conduct risk awareness and training programmes to enhance organisational capability in managing non-financial risks.
Risk Management, Reporting and Governance
- Monitor and report on risk levels against approved risk appetite across the organisation.
- Oversee timely, accurate and insight-led risk reporting to ExCo, Board Risk Committee and other governance forums, highlighting risk profile movements, appetite breaches, key risk indicators, emerging risks and management actions.
- Develop dashboards and reporting tools to provide clear visibility of risk trends and mitigation progress.
- Ensure policy compliance, effective control remediation and timely closure of material audit findings, with clear accountability and monitoring of control improvement actions.
Business Continuity Management
- Design and oversee implementation of BCM processes, including disaster recovery, crisis management, and emergency response protocols.
- Ensure business impact analyses, business continuity plans, crisis management arrangements and disaster recovery dependencies are reviewed, tested and updated in line with organisational, technology and external environment changes.
- Coordinate crisis and incident management, recovery strategies and resilience programmes to minimise operational disruption and protect critical services.
Credit and Market Risk Monitoring
- Establish policies and methodologies for effective counterparty monitoring and management of market and credit risk, including liquidity risk management.
- Establish and maintain the DBSA prudential limit framework, including limit setting, monitoring, early-warning indicators, breach escalation, remediation tracking and governance reporting.
- Regularly review limit setting against risk-adjusted changes in counterparties and obligors risk profiles.
Model Risk Management
- Own and maintain the organisation's Model Risk Management Framework, ensuring alignment with regulatory and governance standards.
- Chair and lead the Model Governance Committee, driving oversight, accountability, and decision-making.
- Provide independent oversight and challenge to strengthen governance and mitigate risk.
- Manage the enterprise model inventory, ensuring completeness, accuracy, and compliance with governance requirements.
- Oversee validation processes, track remediation actions, and ensure timely resolution of deficiencies.
- Engage with regulators and ensure full compliance with model risk regulatory requirements.
- Deliver structured reports to Executive Management and the Board, providing insights on model risk exposures and governance outcomes.
- Establish governance for AI and advanced analytics models, ensuring ethical use, transparency, and risk mitigation.
- Integrate model risk into enterprise risk ER processes to strengthen organisational resilience.
- Drive continuous improvement of model risk practices, embedding innovation, efficiency, and best practice standards.
Stakeholder Management
- Build and maintain strong relationships with internal stakeholders, including ExCo and divisional leadership, to embed risk management practices.
- Engage with regulators, industry bodies, shareholder representatives, development partners and external assurance providers to benchmark DBSA's risk practices against applicable standards and emerging market practice.
- Represent DBSA in risk-related forums and contribute to shaping industry-wide risk management practices.
Digital Transformation
- Champion digital risk transformation, data quality, analytics, automation and dashboarding to improve risk visibility, early-warning capability and evidence-based decision-making.
- Identify and adopt emerging technologies to modernise risk management practices and improve organisational resilience.
People Management
- Lead, mentor, and develop a high-performing team, fostering a culture of collaboration, accountability, and continuous learning to maximise individual and collective potential.
- Drive talent development initiatives, including coaching, performance management, and career pathing, to build and retain a skilled and motivated team.
- Provide direction and management to the Division, to enable strategy execution.
- Attract, retain, develop talent and ensure succession planning and sufficient capacity and capability in all critical functions, supporting diversity strategies and initiatives as well.
- Promote DBSA values and a culture of high performance through implementing performance management in line with the planned strategic objectives, goals, quality standards and agreed key performance measures using sound performance management principles.
- Contribute to building synergies & cooperation across functions in the DBSA.
- Embed the DBSA values, ethics and culture.
Key Measurements of Outputs
- Risk appetite framework, ER policies and methodologies reviewed, approved and embedded annually, with evidence of continuous improvement and alignment to DBSA's strategy and governance requirements.
- Risk and control self-assessments, key risk indicators, control adequacy reviews and action plans completed within agreed timelines and reported to relevant governance structures.
- Business continuity framework, BIAs, crisis management plans, disaster recovery dependencies and BCM testing outcomes revie