Director of Risk, Audit and Compliance
Location:
Kigali, Rwanda
Reports to:
Chief Executive Officer
Department:
Office of the Chief Executive Officer
Supervises:
-
Internal
Audit Manager
-
Risk
and Compliance Manager
-
Security
Manager
About Rwanda Medical Supply (RMS)
Rwanda Medical Supply (RMS) is a state-owned
company established by the Government of Rwanda with a mandate of managing end
to end health supply chain for Rwanda.
RMS Ltd mission is to be the leading health supply
chain institution in Africa which ensures availability and affordability of
quality assured health commodities by 2030. RMS Ltd’s vision is a thriving
Rwanda: Where everyone has the health resources, they need to live a long and
fulfilling life. Our comprehensive supply chain management ensures that
healthcare providers have the resources they need to deliver quality care.
Job Purpose
The Director of Risk, Audit and Compliance is
responsible for providing strategic leadership in the development,
implementation, and continuous improvement of the organization's enterprise
risk management, internal audit, governance, compliance, and internal control
frameworks. The role ensures that RMS operates within applicable laws,
regulations, policies, and best practices while safeguarding organizational
assets, promoting accountability, and supporting informed decision-making by
Executive Management and the Board.
The position also provides independent assurance
regarding the effectiveness of governance processes, risk management systems,
and internal controls while fostering a strong culture of compliance and
ethical conduct across the organization.
Key Responsibilities
The successful candidate will be responsible for:
Strategic Leadership
-
Develop
and implement the organization's Enterprise Risk Management (ERM)
framework aligned with RMS strategic objectives.
-
Provide
strategic leadership in strengthening governance, accountability,
compliance, and internal control systems.
-
Advise
Executive Management and the Board on strategic risks, emerging risks, and
mitigation measures.
-
Promote
a proactive risk management culture throughout the organization.
-
Develop
departmental strategic plans, annual work plans, budgets, and performance
targets.
Internal Audit Management
-
Lead
the development and execution of the annual risk-based internal audit
plan.
-
Oversee
internal audits to assess operational efficiency, financial integrity,
compliance, and effectiveness of internal controls.
-
Ensure
audits are completed within agreed timelines and according to professional
auditing standards.
-
Review
audit findings and recommend practical improvements to strengthen internal
controls.
-
Monitor
implementation of audit recommendations across all directorates.
-
Coordinate
internal and external audit activities to ensure effective collaboration.
Risk Management and Organizational Resilience
• Develop and implement integrated risk management
frameworks and systems.
• Identify organizational areas requiring enhanced
risk, compliance, or security assessments.
• Conduct risk assessments and provide
recommendations to mitigate operational, financial, and strategic risks.
• Establish mechanisms to monitor and report
organizational risks.
• Support departments in developing risk
mitigation strategies and action plans.
• Promote risk awareness and accountability
throughout RMS.
Enterprise Risk Management
-
Develop
and maintain the organization's enterprise risk register.
-
Conduct
organization-wide risk assessments and identify strategic, operational,
financial, compliance, and reputational risks.
-
Establish
risk assessment methodologies and risk reporting mechanisms.
-
Monitor
the effectiveness of risk mitigation strategies.
-
Prepare
periodic risk reports for Executive Management and the Board.
Compliance and Governance
-
Ensure
compliance with applicable laws, government regulations, organizational
policies, and international standards.
-
Develop
and regularly review compliance policies, procedures, and governance
frameworks.
-
Monitor
regulatory developments and advise management on emerging compliance
requirements.
-
Coordinate
compliance assessments and recommend corrective actions where necessary.
-
Promote
ethical business practices and institutional integrity.
Internal Control Enhancement
-
Evaluate
the adequacy and effectiveness of internal control systems.
-
Recommend
improvements to strengthen financial, operational, and administrative
controls.
-
Monitor
implementation of control improvement initiatives.
-
Ensure
proper segregation of duties and accountability mechanisms across the
organization.
Advisory Services
-
Provide
independent advisory services to Executive Management on governance, risk,
and compliance matters.
-
Support
management in developing risk mitigation strategies for major
organizational initiatives.
-
Participate
in strategic projects by providing governance and control perspectives.
Security Oversight
-
Provide
strategic oversight of corporate security operations.
-
Ensure
appropriate measures are implemented to safeguard organizational assets,
staff, facilities, and information.
-
Monitor
organizational preparedness for security risks and emergencies.
Leadership and People Management
-
Provide
leadership, coaching, mentoring, and performance management for staff
within the directorate.
-
Foster
a culture of continuous improvement, accountability, integrity, and high
performance.
-
Identify
training and capacity-building needs within the department.
-
Promote
collaboration across departments in managing organizational risks.
Reporting
-
Prepare
and present periodic audit, risk, and compliance reports to Executive
Management and the Board.
-
Monitor
departmental performance against approved Key Performance Indicators.
-
Ensure
timely submission of statutory, regulatory, and management reports.
Other Duties
-
Perform
any other duties assigned by the Chief Executive Officer in line with the
organization's objectives.
Academic Qualifications
Applicants must possess:
-
Master's
Degree in Accounting, Finance, Business Administration, Risk Management,
Auditing, Economics, or another related discipline from a recognized
institution.
Professional Qualifications
Candidates must possess at least one of the
following professional certifications:
-
ACCA
-
CPA
-
CIA
(Certified Internal Auditor)
-
CISA
(Certified Information Systems Auditor)
-
CRMA/CRA
(Certified Risk Management Assurance or equivalent)
-
Any
other internationally recognized professional qualification in Audit,
Risk, or Compliance will be an added advantage.
Experience
Applicants should demonstrate:
-
Minimum
of seven (10) years of progressive professional experience in Internal
Audit, Enterprise Risk Management, Compliance, Governance, or Financial
Control.
-
At
least three (5) years in a senior management or leadership role within a
large and complex organization.
-
Proven
experience developing and implementing enterprise risk management
frameworks.
-
Demonstrated
experience managing internal and external audits.
-
Experience
within State owned entities, healthcare sector, development organizations,
or highly regulated industries will be an added advantage.
-
Strong
knowledge of corporate governance principles and regulatory compliance
frameworks.
Competencies and Skills
The ideal candidate should demonstrate:
Leadership Competencies
-
Strategic
leadership and vision
-
Strong
decision-making ability
-
Results-oriented
mindset
-
Ability
to influence senior stakeholders
-
Change
management capability
-
High
ethical standards and professional integrity
Technical Competencies
-
Enterprise
Risk Management
-
Internal
Auditing Standards (IIA Standards)
-
Corporate
Governance
-
Compliance
Management
-
Internal
Control Frameworks (COSO)
-
Fraud
Risk Management
-
Financial
Analysis
-
Regulatory
Compliance
-
Business
Process Improvement
-
Policy
Development
Behavioral Competencies
-
Excellent
analytical and critical thinking skills
-
Exceptional
report writing and presentation abilities
-
Strong
communication and interpersonal skills
-
Negotiation
and influencing skills
-
Problem-solving
capability
-
Attention
to detail
-
High
level of confidentiality
-
Ability
to work under pressure and meet deadlines
-
Stakeholder
management
-
Team
leadership and coaching
Digital Competencies
-
Proficiency
in Microsoft Office Suite
-
Knowledge
of ERP systems
-
Experience
with audit management and risk management software is an added advantage.
-
Strong
data analysis and reporting skills.
Key Performance Indicators (KPIs)
Performance will be evaluated based on:
-
Completion
of the approved annual audit plan within agreed timelines.
-
Timely
submission of accurate audit, risk, and compliance reports.
-
Percentage
implementation of audit recommendations.
-
Reduction
in repeat audit findings.
-
Improvement
in the organization's internal control environment.
-
Compliance
with applicable laws, regulations, and internal policies.
-
Effectiveness
of enterprise risk management processes.
-
Timely
identification and mitigation of strategic and operational risks.
-
Stakeholder
satisfaction with audit and advisory services.
-
Departmental
budget utilization and operational efficiency.
-
Staff
performance, engagement, and professional development.
Q-Sourcing
Servtec is an equal opportunity employer.
Deadline: 31st July
2026. Only shortlisted candidates will be contacted. Solicitation will
lead to disqualification.