We are looking for an Operational Risk professional who can drive ORM frameworks and lead implementation of Indias Digital Personal Data Protection requirements. The role will work closely with Risk, Legal, Tech, and Product teams to ensure robust risk governance, data privacy compliance, and control effectiveness.
Key Responsibilities
Operational Risk Management (ORM) :
Develop and maintain RCSA framework, risk registers, and control libraries
Define and monitor KRIs/KPIs across underwriting, collections, technology, and vendor risk
Conduct risk assessments, control testing, and gap analysis
Track incident management (fraud, tech failures, process breaches) and drive root-cause closure
Support Board / Risk Committee reporting and governance
Data Privacy & DPDP Implementation
Lead implementation of the Digital Personal Data Protection (DPDP) Act across business functions
Design And Operationalize
Data inventory & data flow mapping
Consent management framework
Data retention & deletion policies
Work with Legal/Tech to ensure privacy-by-design in systems and processes
Manage data subject rights (access, correction, erasure) workflows
Conduct privacy risk assessments and audits
Policy & Governance
Draft and update :
ORM policy
Data privacy policy
Vendor / outsourcing risk frameworks
Ensure alignment with regulatory expectations (RBI, data protection norms)
Drive policy adherence and exception management
Cross-Functional Collaboration
Work with :
Tech (data pipelines, access control)
Product (customer journey compliance)
Legal (regulatory interpretation)
Support regulatory audits and inspections
Key Skills & Qualifications
Must Have :
4 to 5 years experience in :
Operational Risk / Risk Analytics / Compliance
Preferably in NBFC / fintech / banking
Robust Understanding Of
ORM frameworks (RCSA, KRIs, incident management)
Data privacy principles & DPDP requirements
Experience in policy drafting and control frameworks