03 Sep
|
Atain
|
Gurugram
Lead - Risk &
- Compliance
Job Responsibilities
- Conduct contractual and client-specific audits across business processes to assess adherence to defined contractual, regulatory, and organizational requirements.
- Conduct detailed internal audits for the BPO vertical, covering ISO 27001, ISO 9001, data protection and information security requirements.
- Support and drive the implementation, maintenance and certification requirements for ISO 27001, ISO 9001, and PCI DSS.
- Collaborate with process owners to identify audit gaps, define corrective actions and drive timely closure of audit findings.
- Establish and maintain a regular Risk &
- Compliance (R&C;) governance cadence with business leaders, including dashboards, reports, and management reviews.
- Analyze operational and compliance data to identify trends, recurring issues, emerging risks, and control weaknesses, and incorporate relevant insights into management reports.
- Proactively identify process improvement opportunities and recommend appropriate controls to mitigate operational, compliance, information security, and other business risks.
- Participate in client calls, meetings, and governance reviews and present R&C-related; updates during weekly, monthly, and ad-hoc client interactions.
- Independently conduct fraud and financial irregularity investigations, using appropriate investigation techniques, evidence-gathering methodologies, and analytical approaches.
- Prepare comprehensive investigation reports covering the background, methodology, findings, root cause, financial impact, control gaps, and recommended corrective actions.
- Develop, implement and maintain processes, policies, and controls under the Privacy and Security Management System to support compliance with applicable data protection requirements.
- Support periodic risk and control assessments, including identification, assessment, documentation, and monitoring of key risks and controls.
- Maintain risk registers and track mitigation plans,
control gaps and remediation activities through to closure.
- Monitor adherence to internal policies, procedures, contractual obligations, and applicable regulatory requirements.
- Conduct compliance reviews, control testing and ongoing monitoring activities to assess the effectiveness of established controls.
- Prepare risk and compliance dashboards, management reports, presentations, and other governance materials for leadership and clients.
- Maintain accurate and up-to-date documentation relating to policies, procedures, controls, audits, risk assessments, investigations, and compliance activities.
- Identify and escalate material risk, compliance, control, or policy concerns to relevant stakeholders in a timely manner.
- Partner with business and support functions to strengthen internal controls, improve processes, and enhance the overall risk and compliance environment.
- Support risk, compliance, information security, data privacy, and ethics awareness/training initiatives across the organization.
- Stay informed of relevant regulatory developments, industry practices, and changes to applicable standards and incorporate them into the organizations risk and compliance framework where required.
Skills &
- Competencies
- Strong analytical, investigative, and problem-solving capabilities.
- Good understanding of risk management, internal controls, audit, compliance, information security, and data protection principles.
- Working knowledge of ISO 27001, ISO 9001, PCI DSS, and data protection requirements.
- Robust attention to detail with the ability to analyze large volumes of information and identify trends and exceptions.
- Excellent written and verbal communication skills, with the ability to present findings and recommendations to senior stakeholders and clients.
- Ability to interpret policies, procedures, contracts, regulatory requirements, and control frameworks.
- Strong report-writing and documentation skills.
- Good organizational and time-management skills, with the ability to manage multiple audits, investigations, and compliance activities simultaneously.
- Proficiency in Microsoft Excel, PowerPoint and Word, strong data analysis and presentation skills will be an advantage.
- Ability to handle confidential and sensitive information with a high degree of integrity and professionalism.
- Strong stakeholder-management and collaboration skills.
- Proactive approach to identifying risks, control weaknesses, and process improvement opportunities.
- Willingness to travel to other operational sites for audit, compliance, investigation, and Risk &
- Compliance activities.
Qualifications &
- Experience
- Graduate in any discipline from a recognized university/institution.
- 2–5 years of relevant experience in Risk &
- Compliance, Internal Audit, Operational Risk, Information Security, Data Privacy, Fraud Investigation or related functions.
- Experience in a BPO/operations environment will be preferred.
- Relevant certifications such as CISA, CIA, CAMS, FRM, ISO 27001/ISO 9001 Lead Auditor/Implementer, or other compliance-related certifications will be an advantage.
- Travel industry/domain knowledge will be preferred.
- Candidates should be willing to travel to other operational sites as required for Risk &
- Compliance activities.
- This role will be office/site-based and will require regular interaction with operational and support teams.
Interested Candidates share resume- Sonam Singh- (phone hidden)
📌 Lead - Risk & Compliance (Gurugram)
🏢 Atain
📍 Gurugram