Central Data Transformation Oversight Head
CitiAbout the role
Operational Risk Management (ORM) is an enterprise level independent risk management function responsible for enterprise-wide oversight and aggregation of operational risk. Its mandate covers all business lines (US Personal Banking, Global Wealth Management, Markets, Services, Banking, Global Functions & EO&T) spanning all geographies.
The ORM function oversees the design and implementation of the non-financial risk management framework. Key objectives of the risk management framework are:
Operating model, staffing and culture: Ensure the operating model across lines of defense is clear and consistent with sufficient resources, expertise, accountability, and stature, and that it is enabled by structured training and awareness program to effectively manage and oversee operational risk.
Operational risk appetite: Clearly articulate risk definitions and appetite and make sure they are aligned against the most critical business outcomes to ensure strategic relevance and application at business, country and entity levels and that Citi operates within its set risk appetite.
Control objectives and standards: Ensure Enterprise Control Standard and controls design requirements are clearly articulated and implemented, and that control objectives and requirements are defined at appropriate risk category and sub-category levels to ensure consistent control design and effectiveness. Operational risk and control assessments and reporting: Oversee that MCA is fit for purpose and is owned with full buy-in from the 1st line, and that it is supplemented by a suite of other fit-for-purpose assessments (e.g., risk category specific assessments, scenario analysis, lessons learned, and targeted deep dives/peer reviews). Ensure assessment results are communicated through clear reporting with thematic and actionable insights.
Strategic decision making: Oversee that Risk Management practices, insights and tools are consistently embedded in day-to-day business processes and strategic decision-making to enable proactive issue identification and comprehensive remediation.
In addition to overseeing the compliance against ORM frameworks, Data Risk Management has the added complexity of overseeing the effective execution of the Enterprise Data transformation. This transformation cuts across the enterprise and is multi-disciplinary in nature. In light of this, a “Hub and Spoke” approach is being adopted as ORM’s oversight operating model. Under this approach, this role will face off with 1LoD enterprise data roles and will work closely with Business/Region/LV Global Op Risk Officers and other relevant independent risk functions in dispensing the appropriate key second Line of defense (2LOD) risk oversight responsibilities to ensure well- coordinated risk assessments, risk identification, measurement/monitoring and timely remediation of key gaps, including appropriate enterprise-level aggregation aligned with defined target state of Data Transformation.
Separately, this role will also support Citi’s Chief Risk officer by serving as the day to day point of contact for the Enterprise Data Office’s Risk Functional Data Officer in delivering Independent Risk Management’s (IRM) data related obligations under the Citi Data Transformation.
Key Responsibilities
ORM Framework Execution Oversight:
- Define the Operational Risk Framework for Risk Category in sync with Global Operational Risk Policy
- Approve Risk Category Appetite and associated metrics, with input from Business/Global Operational Risk Officers
- Manage the adherence to the approved Data Risk Appetite. In case of Risk Appetite potential and/or breaches, ensure risk exposure is well understood and there is a robust Path to Green to avert/remediate breach within an acceptable time frame.
- Approve new products/services and major initiatives as required by policy
- Conduct independent second line risk assessments and in coordination with other ORM teams where needed (e.g., reviewing control design and effectives of key processes, end to end review of significant control breaks that impact multiple risk categories, lessons learned and near misses) and root cause assessments (e.g., reviewing themes of issues across multiple businesses/ regions)
- Create aggregated risk profile picture for the risk category at the enterprise, business/function levels and LV levels using a combination of first line and independent second line assessments
- In partnership with Business/ Region/ LV risk officers, approve significant exceptions to the Global Operational Risk Policy for the risk category and conduct periodic review of exceptions/ waivers
- Serve as the primary coverage lead for the 1LOD Enterprise Data office and 1LOD Risk category owner in terms of compliance to the ORM
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s