Head, Group Enterprise Risk

ICHX TECH PTE. LTD.Singaporemycareersfuturepublished 10/01/2026
Must-have:FinTechSecuritySeniorLeadPrincipal

Role Summary

The ICHX Tech group operates regulated and non-regulated businesses across Singapore and the region. These include ADDX Pte Ltd, which is licensed by the Monetary Authority of Singapore (MAS) as a Recognised Market Operator and Capital Markets Services licensee and gives accredited investors access to private markets and alternatives.

The Head, Group Enterprise Risk is the senior second-line risk leader for every group entity. The role has four parts:

  • Own the group risk management framework and risk appetite.
  • Provide independent opinions and challenge on new products, deals and outsourcing arrangements.
  • Be accountable to the Board and Senior Management for how well risk management works across the group.
  • Lead and manage the Enterprise Risk team.

Key Responsibilities

Risk Framework and Risk Appetite

  • Own the group enterprise risk management framework, including the risk taxonomy, risk register and risk policy suite, keeping each proportionate to the nature, scale and complexity of each entity.
  • Develop group and entity-level risk appetite statements and translate them into key risk indicators (KRIs), limits and tolerances.
  • Own and periodically review the enterprise risk, outsourcing/TPRM, BCM and credit risk policies and procedures, keeping them aligned with applicable MAS requirements and guidelines.
  • Oversee the RCSA programme across all departments and entities, ensuring first-line assessments are validated and challenged, not just administered.
  • Oversee the outsourcing framework end to end, from materiality assessment and service provider due diligence to the outsourcing register and ongoing monitoring, including intragroup arrangements between ICHX Tech entities.

Governance and Reporting

  • Report regularly to Senior Management on top risks, performance against risk appetite, material incidents and open issues.
  • Escalate material risks and breaches promptly to Senior Management.
  • Oversee the incident and loss-event process, including root-cause analysis and tracking of remediation. Decide, together with Legal & Compliance, whether any regulatory notification is needed.
  • Oversee the BCM programme, including the annual business impact analysis, continuity plan testing and crisis-management exercises. Ensure gaps are tracked to closure and recovery arrangements meet applicable regulations.
  • Work with the Technology department, which owns technology risk management under the MAS Technology Risk Management Guidelines, on shared areas such as disaster recovery, technology outsourcing and cyber incidents. Ensure disaster recovery arrangements and recovery objectives match the business impact analysis.

Regulatory and Audit Engagement

  • Act as the principal risk counterpart to MAS for inspections, thematic reviews and supervisory queries, working together with Legal & Compliance.
  • Be accountable for remediating risk-related findings from MAS inspections, Internal Audit and external reviews. Ensure remediation actions are tracked to closure and open items are reported to Senior Management.
  • Track regulatory developments that affect risk management, such as outsourcing and third-party risk guidelines and assess their impact on the group.

Risk Culture

  • Build risk ownership in the first line: nominate risk owners, deliver risk training, and embed risk thinking into business decision-making.

Must-Have

  • 8–10 years of experience in risk in financial services. Fintech experience is an advantage.
  • Hands-on experience applying the MAS Guidelines on Outsourcing, including material outsourcing and intragroup arrangements and MAS expectations on business continuity management.
  • Familiarity with the MAS Technology Risk Management Guidelines, sufficient to work effectively with the Technology department that owns technology risk management.
  • Demonstrated experience presenting to senior stakeholders and managing MAS inspections or supervisory engagement.
  • Strong stakeholder management, communication and influencing skills.
  • Creativity and an appetite for continuous improvement.
  • Experience building or scaling a risk function in a growth-stage company or a group with multiple entities.