Co-Chief Risk Officer
Malaysia
Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region. SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network. We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.
With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.
SUMITOMO MITSUI BANKING CORPORATION MALAYSIA BERHAD
Job Purpose & Summary
The Co-Chief Risk Officer ("CRO") is accountable for the Bank’s overall risk management framework, the leadership and effective operation of the risk management function, and the provision of independent second-line oversight and challenge of material risk-taking activities across the Bank.
The Risk Management function acts as the Second Line of Defence and provides independent oversight, review and challenge of risk-taking and risk management activities conducted by the First Line of Defence. It develops and maintains relevant risk management policies, frameworks, standards and methodologies, provides guidance and training to the First Line of Defence, and reports material risk matters to Senior Management, the President/Chief Executive Officer("CEO"), the Board Risk Management Committee and the Board, as appropriate.
Ownership and primary accountability for risks and controls remain with the relevant business and support functions. The Co-CRO’s oversight responsibility does not transfer, replace or diminish the First Line of Defence’s accountability for identifying, assessing, managing and controlling the risks arising from its activities.
Job Responsibilities
The responsibilities of Co-CRO include the following:
- Individual Responsibility
- Be accountable for the development, implementation, maintenance and effectiveness of the Bank’s overall risk management framework, under which material risks are identified, assessed, measured, monitored, controlled, mitigated and reported in a proactive, comprehensive and timely manner.
- Lead the development, implementation and ongoing management of the Bank’s Risk Appetite Framework, including the Risk Appetite Statement, risk appetite metrics, early warning thresholds and risk limits, and monitor the Bank’s actual and projected risk profile against the approved risk appetite.
- Oversee the Bank’s management of material risks, including credit, concentration, market, liquidity, operational, technology, cyber, third-party, outsourcing, reputational, Shariah non-compliance, environmental, climate-related and other material or emerging risks identified under the Bank’s risk management framework.
- Oversee the establishment by relevant business and support functions of appropriate control and risk mitigation measures aligned with the Bank’s approved Risk Appetite Statement.
- Independently assess and challenge the risk implications of the Bank’s business plan, risk-taking strategy, material new products, investments, transactions and strategic initiatives, and support the sustainable achievement of the Bank’s business objectives within the approved risk appetite.
- Oversee the identification of the Bank’s top and emerging risks, the development of appropriate stress scenarios, and the Bank’s stress-testing and reverse stress-testing processes. Review and challenge key assumptions and results, and ensure that material vulnerabilities identified are appropriately addressed.
- Maintain the adequacy, accuracy and reliability of risk measurement methodologies, models, management information systems and reporting processes, including appropriate validation and ongoing performance monitoring of material models and methodologies.
- Be responsible for the quality, integrity and appropriate protection of risk data used by the Risk Management function.
- Take reasonable steps to ensure that the risk management function complies with applicable laws, regulations, regulatory requirements and internal policies and procedures.
- Monitor developments in laws, regulations, regulatory expectations and supervisory findings relevant to risk management, assess their impact on the Bank, and oversee the implementation of appropriate responses to material regulatory findings.
- Oversee the Bank’s response to unusual or stressed circumstances, the risk management aspects of recovery and contingency arrangements, and the Bank’s credit rating, asset classification, impairment and provisioning frameworks.
- Maintain regular, direct, open and timely communication with regulatory authorities, the Board of Directors, the Board Risk Management Committee, the President/CEO, Senior Management, the Regional CRO, Key Responsible Persons and relevant internal departments on material risk matters. Work with the President/CEO, Senior Management and the Regional CRO to facilitate a common understanding of material risk matters and support timely, informed and effective management action.
- Provide independent risk advice and challenge to the President/CEO and Senior Management, and independent risk assessments, advice and reporting to the Board Risk Management Committee and the Board.
- Promote a sound risk culture across the Bank that supports prudent risk-taking, accountability, transparency and timely escalation.
- Supervise and manage the departments reporting to the Co-CRO and ensure that the Risk Management function has appropriate authority, independence, personnel, expertise, systems and infrastructure to discharge its responsibilities effectively. Develop and maintain a sustainable talent pipeline and succession arrangements for key roles within the Risk Management function.
- Responsibilities Shared with Other Senior Officers or Control Functions
- Oversee the development and effective implementation of the Bank’s credit risk strategy and framework in coordination with the President/CEO and other relevant Senior Officers and control functions.
- As a member of the Crisis Management Team, discharge the responsibilities assigned to the Co-CRO under the applicable Crisis Management framework and Terms of Reference, provide independent risk advice, and coordinate with the Head of Internal Control, the CISO and other relevant functions in managing the risk implications of a crisis.
- Assist the President/CEO, Deputy CEO and Deputy President in setting and reinforcing the tone from the top on Anti-Bribery and Anti-Corruption. Proactively identify and escalate material corruption risk concerns and support initiatives to enhance the effectiveness of the corruption risk management framework, relevant controls, review and monitoring arrangements, training and communication across SMBCMY. This responsibility is shared with all Senior Officers.
- Support the President/CEO and the Board in promoting a sound corporate culture within SMBCMY that reinforces integrity and ethical, prudent and professional behaviour. This responsibility is shared with all Senior Officers.
- Responsibilities in Committee - The Co-CRO is a member of the following management committees:
- Asset and Liability Management Committee
- Risk Management Committee
- Credit Committee
- Operations Planning Committee
- Business Continuity Management Committee
- Sustainability Committee
Job Requirements
- Academic and Overall Experience
- Bachelor's Degree in Finance, Banking, Economics, Accounting, Business Administration, Risk Management or a related discipline.
- Professional certifications such as AICB , Certified Credit Professional(CCP), Financial Risk Manager (FRM), Professional Risk Manager (PRM), Chartered Financial Analyst (CFA), Certified Public Accountant (CPA) or equivalent risk and banking-related qualifications will be added advantage.
- Minimum 15 years of relevant experience in banking, financial services, risk management, credit risk, enterprise risk management, compliance, audit, treasury risk, operational risk, or related disciplines.
- Proven experience in a senior leadership role for minimum 5 years with responsibility for enterprise-wide risk management, risk governance, and regulatory engagement.
- Strong experience in developing, implementing and enhancing risk management frameworks, policies, methodologies, risk appetite frameworks, risk limits, stress testing and risk reporting.
- Demonstrated experience overseeing a broad range of risk types, including credit, market, liquidity, operational, technology, cyber, outsourcing, reputational, environmental and emerging risks.
- Experience in engaging with regulators, Board Committees, Senior Management and external stakeholders on risk-related matters.
- Sound understanding of regulatory requirements, corporate governance standards, and risk management best practices applicable to the banking industry.
- Experience in leading, developing and managing high-performing risk management teams and building strong succession pipelines.
2. Technical Knowledge
- In-depth knowledge of risk management principles, frameworks and governance practices.
- Strong understanding of banking products, financial markets, and risk measurement methodologies.
- Familiarity with stress testing, scenario analysis, capital management, impairment and provisioning frameworks.
- Strong knowledge of regulatory expectations, prudential standards, and risk-related reporting requirements applicable to financial institutions.
- Ability to assess the risk implications of strategic initiatives, new products, investments and material transactions.
3. Competencies and Personal Attributes
- Strong expertise in enterprise risk management, risk governance, risk appetite frameworks, stress testing and regulatory engagement.
- Proven ability to oversee a broad spectrum of risks, including credit, market, liquidity, operational, technology and emerging risks.
- Committed to fostering a strong risk culture that promotes prudent risk-taking, transparency and accountability.
- Experience interacting with regulators, Board Committees and Senior Management.
- Excellent leadership, stakeholder management, communication and influencing skills.
- Strategic Thinking, Resilience and Ability to Perform Under Pressure
- Strong analytical capability, sound judgment, and the ability to provide independent and effective challenge.
- Demonstrates the highest standards of ethics, integrity, accountability and fostering a strong risk culture.