Internal Controls & Risk Management
Internal Controls & Risk Management
NTUC First Campus6-10 Years
- Posted 33 minutes ago
- Be among the first 10 applicants
Job Description
The Assistant Manager / Manager, Internal Controls & Risk Management is an execution-focused role responsible for driving the day-to-day operation of the organisation's Internal Controls and Enterprise Risk Management (ERM) frameworks. Given NFC's expansive footprint as a leading early childhood education social enterprise, this role ensures the proactive identification, testing, and tracking of financial, operational, IT, and regulatory compliance risks across both Corporate HQ and our network of preschool centres.
Acting as a second-line Internal Controls function, you will identify and execute structured reviews over the organisation's Internal Controls. You will also play a role in executing the organisation's Enterprise Risk Management (ERM) framework while playing a critical collaborative and administrative role in supporting the annual Control Self-Assessment (CSA) and Business Continuity Planning (BCP) programmes. You will also manage the organisation's data governance processes. The ideal candidate translates complex governance policies into practical, center-friendly risk practices—balancing institutional safeguarding and regulatory compliance without disrupting operational speed or childcare service delivery excellence.
Depending on relevant experience and capabilities, the candidate may be assigned to lead or support roles in the following functions:
Internal Controls
Acting as a second-line Internal Controls function, you will identify and execute structured reviews over the organisation's Internal Controls. You will also play a role in executing the organisation's Enterprise Risk Management (ERM) framework while playing a critical collaborative and administrative role in supporting the annual Control Self-Assessment (CSA) and Business Continuity Planning (BCP) programmes. You will also manage the organisation's data governance processes. The ideal candidate translates complex governance policies into practical, center-friendly risk practices—balancing institutional safeguarding and regulatory compliance without disrupting operational speed or childcare service delivery excellence.
Depending on relevant experience and capabilities, the candidate may be assigned to lead or support roles in the following functions:
Internal Controls
- Execute the daily operational activities of the internal control framework across HQ corporate functions and preschool centres.
- Conduct regular control testing and compliance assurance reviews to evaluate control designs and operating effectiveness (e.g., centre fee collections, decentralized procurement workflows, government grant/subsidy reconciliations, vendor management).
- Identify operational gaps and process vulnerabilities, offering pragmatic recommendations for control enhancements that consider the challenges of frontline educators.
- Monitor, log, and track the remediation of identified control deficiencies internally and by independent auditors, collaborating closely with business unit process owners to ensure timely resolution.
- Support coordination efforts with internal and external auditors to streamline regulatory, compliance, and financial statement audits.
- Facilitate the ongoing operationalisation of the Enterprise Risk Management framework across all corporate functions and business units.
- Maintain and systematically update enterprise and department-level risk registers, ensuring emerging risks (e.g child safety hazards, operational data leaks, and macroeconomic shifts) are accurately captured.
- Perform risk assessments and analyse residual risk levels against established corporate risk appetites and tolerances.
- Conduct root-cause analyses on key operational risk incidents, tracking the implementation and progress of management action plans.
- Drive and execute the annual Control Self-Assessment (CSA) framework rolled out across various business units and departments to ensure robust management control attestations.
- Review, validate, and critically challenge the completeness and accuracy of CSA submissions provided by HQ teams and center leaders.
- Identify systemic control gaps from CSA data and partner with business unit process owners to establish and track formal remediation plans.
- Design, maintain, and own the documentation of the organisation's Business Continuity Planning (BCP) framework and operational resilience strategies.
- Plan, lead, and execute BCP tabletop exercises and crisis simulation programmes, proactively identifying and logging operational bottlenecks or recovery gaps.
- Lead fact finding, report drafting, and operational coordination during crisis management activation as a core executor of the organisation's Crisis Management Plan.
- Maintain the Data Governance framework, ensuring alignment with ethical guidelines, applicable data privacy laws, and NFC's corporate values.
- Maintain the enterprise-wide data inventory
- Provide oversight of NFC's Data Governance Committee and provide regular trainings and updates to Data Champions
- Lead investigations and draft reports on data-related (including personal data) incidents.
- Assist in compiling high-quality data insights, metrics, and progress materials for executive reporting to the Risk Management Committee and Audit & Risk Committee.
- Collaborate closely with business units and functional teams to build risk culture, operational compliance, and awareness across all levels.
- Conduct localised briefings and assist in updating training materials related to internal controls, ERM, data protection, CSA and BCP protocols.
- And other duties where required.
- Bachelor's degree in Accounting, Finance, Business Administration or a related discipline.
- Minimum 6 to 10 years of professional experience in internal controls, risk management, internal/external audit, or operational compliance roles.
- Prior experience working within a professional services firm or the education/preschool sector is highly advantageous.
- Strong understanding of internal control frameworks (e.g., COSO) and Enterprise Risk Management guidelines (e.g., ISO 31000).
- Familiarity with the regulatory landscapes impacting social enterprises and the education sector in Singapore, including the Personal Data Protection Act (PDPA) and Early Childhood Development Agency (ECDA) operational parameters.
- Basic understanding of GRC (Governance, Risk, and Compliance) platforms or structured digital tracking workflows.
- Ability to interpret regulatory changes and translate risks into clear, center-appropriate business documentation and control requirements.
- Analytical Rigor: Ability to analyze diverse operational workflows, identify underlying control gaps, and map them to business risk scenarios.
- Collaborative Problem Solving: Strong capability to drive the adoption of risk policies while maintaining supportive, constructive, and effective relationships with cross-functional business units.
- Clear Communication: Ability to articulate risk impacts and control parameters in simple, accessible, and non-technical narratives to non-financial operators and center staff.
- Professional qualifications such as Certified Internal Auditor (CIA), Certified Public Accountant (CPA / CA), Certified Information Systems Auditor (CISA), or foundational business continuity certifications (e.g., ABCP / AMBCI) are a plus.
- Desired Skills, Experience and Qualities
- High EQ & De-escalation: Exceptional emotional intelligence to handle stakeholder resistance smoothly during control rollouts, compliance tracking, and policy updates.
- The Enabling Mindset: A functional focus on being an enabler of innovation—providing the clear guardrails that allow operational and center teams to move fast safely, rather than acting as an administrative roadblock.
More Info
Key Skills
Control Self-Assessment
ISO 31000
