Strengthen our ERM approach
Develop and improve GovTech’s enterprise risk framework, methodology and governance arrangements.
Clarify who owns each risk, how issues should be escalated and where decisions should sit.
Make sure the approach works for a modern technology organisation rather than forcing teams into processes that add little value.
Build a forward-looking view of risk
Maintain a current view of GovTech’s key risks across strategy, technology, operations, delivery, vendors, regulation, data, reputation and organisational capability.
Look beyond known issues and past incidents. Identify emerging threats, dependencies and concentrations of risk before they become larger problems.
Keep GovTech’s enterprise risk profile, register and monitoring approach relevant and useful to decision-makers.
Support better leadership decisions
Provide clear and practical advice to senior leadership, Board-level committees, auditors and oversight bodies, including SNDGO and relevant central agencies.
Turn complex risk issues into straightforward choices, trade-offs and recommendations.
Help leaders understand what matters most, what needs to be done, who should act and where attention is required.
Modernise how risk management is done
Improve processes that are too manual, retrospective or disconnected from day-to-day operations.
Use data, AI, automation and emerging technologies to improve the timeliness and quality of risk information.
Run practical experiments, test new approaches and turn successful ideas into reusable capabilities.
Develop tools and guidance that help teams manage risk as part of their work, not as a separate compliance exercise.
Partner with product, engineering, cybersecurity, operations, policy, procurement and corporate functions.
Help leaders balance delivery speed, resilience, governance and risk appetite.
Build trusted relationships and support honest conversations, especially where risks or accountabilities are unclear or contested.
Represent GovTech in relevant cross-agency risk and governance forums.
Success will not be measured by the number of reports produced.
You will know the role is making a difference when:
•
leadership has a clearer view of GovTech’s most important risks
•
risks are surfaced earlier and acted on faster
•
ownership and accountability are clear
•
risk insight improves strategic and operational decisions
•
governance supports responsible delivery rather than slowing it down
•
manual reporting is reduced
•
successful experiments lead to better ways of working
•
teams see ERM as a practical partner
•
GovTech is better prepared for disruption and emerging risks