Job Description
The role is responsible for implementing the organization’s Anti-Bribery & Corruption (ABC) and financial crime compliance activities by assisting in the monitoring, and continuous improvement of relevant programs and controls. The role preforms ABC risk assessments, whistleblowing activities, financial crime reporting, and related compliance initiatives. The Officer works with relevant internal and external stakeholders to support regulatory compliance, identify potential risks, and promote a culture of integrity and ethical conduct across the organization.
ABC Risk Assessment Methodology
- Own, maintain, and periodically review the ABC Risk Assessment Methodology, including the risk taxonomy, inherent risk factors, control effectiveness criteria, scoring model, risk appetite thresholds, and residual risk rating scale, and obtain approval of material changes through the applicable governance route.
- Define the annual assessment scope and coverage across business units, products, services, delivery channels, processes, geographies, and third-party relationships, applying a documented risk-based rationale for inclusion, exclusion, and assessment depth.
- Ensure the methodology remains aligned with applicable laws, SAMA requirements, the Counter-Fraud Framework, and the Bank's enterprise risk management framework, and document the basis of alignment.
Execution of the Annual Risk Assessment Cycle
- Plan and deliver the ABC risk assessment cycle in accordance with the Annual Compliance Program, including the assessment calendar, resourcing, milestones, and dependencies, and report progress against plan.
- Design and issue assessment questionnaires, control self-assessment templates, and data requests to business units, and lead assessment workshops and interviews with business and control function representatives.
- Challenge business unit self-assessment responses and asserted control ratings, and validate them against independent evidence including policies and procedures, system configurations, testing results, audit findings, incident and investigation history, gifts and hospitality and conflict of interest registers, and third-party due diligence records.
- Determine inherent risk, control effectiveness, and residual risk ratings for each assessed unit, and document the rationale, evidence relied upon, and any assumptions or limitations supporting each rating.
Analysis & Reporting
- Analyze assessment results to identify the Bank's material bribery and corruption exposures, control gaps, concentration areas, and residual risks exceeding risk appetite, and identify trends against prior assessment cycles.
- Prepare the final ABC Risk Assessment Report, including the assessment scope and methodology, risk profile and heat map, key findings, control weaknesses, residual risk position against appetite, and recommended mitigation actions.
- Present assessment outcomes to senior management and the relevant governance committees, and obtain the required approvals and acceptance of residual risk where applicable.
- Agree remediation actions with the accountable business owners, including action definition, ownership, and target dates, and track implementation through to closure with verification of closure evidence.
- Prepare periodic management information on assessment coverage, risk profile movement, open findings, and the status of remediation actions.
Internal Fraud Risk Assessment
- Conduct Internal Fraud risk assessments across the Bank's departments in alignment with the Counter-Fraud Framework, covering fraud typologies and scenarios, inherent fraud exposure, the design and operating effectiveness of preventive and detective controls, and residual fraud risk.
- Assess coverage of Internal Fraud scenarios against existing controls, systems, and detection capabilities, identify uncovered or partially covered scenarios, and document the resulting control gaps.
- Coordinate with Counter-Fraud, Information Security, Internal Audit, Operational Risk, and Human Resources on assessment scope, evidence, and findings, and maintain a clear demarcation of ownership between the ABC and Counter-Fraud mandates.
- Issue final Internal Fraud risk assessment reports and manage the formal closure process, including validation that agreed actions have been implemented, verification of closure evidence, and documented sign-off by the accountable owner and the applicable approving authority.
- Maintain the Internal Fraud risk register and ensure identified risks, controls, and actions are reflected consistently in the Bank's risk records.
Governance, Assurance & Continuous Improvement
- Maintain complete and auditable assessment working papers, evidence files, and version-controlled documentation sufficient to support independent re-performance by internal audit, external audit, and SAMA examination teams.
- Support internal and external audits, compliance reviews, and regulatory examinations on matters relating to ABC and Internal Fraud risk assessment, and prepare responses to observations and findings.
- Incorporate lessons learned from investigations, incidents, audit findings, regulatory developments, and emerging typologies into the methodology, scenario coverage, and subsequent assessment cycles.
- Supervise, review, and quality-assure the work of ABC officers and analysts supporting the assessment cycle, and provide technical guidance and development.
- Perform any other duties assigned to by line manager related to the nature of the work
- Enforce, incorporate, and comply with all necessary controls and related information security policies, procedures, practices, training, reporting, personal due diligence and vigilance, within departmental/unit activities and operations.
Preferred Qualifications
- Have a tertiary level qualification from a recognized institution in Law, Business, Finance, or a related field.
Years & Nature of Experience
- Recommended 3 to 5 years of equivalent experience where required competencies and experience have been demonstrated
- If with experience would have been accountable a Demonstrated expertise in conducting risk assessments, managing investigations, and delivering training related to ABC, financial crimes, and whistle-blowing programs.
- Familiarity with financial crimes regulations, including anti-money laundering (AML), fraud prevention, and sanctions compliance.
Technical Competencies
- Risk Assessment & Due Diligence
- Investigation & Case Management
- Data analytics
Behavioural Competencies
- Decision Making
- Communication
- Teamwork
- Problem solving