Confidential mandate

Regional Operational Risk Chief — Investment and Insurance Service Continuity

Planned Hiring / New

Regional Operational Risk Chief mandate in Mumbai, India · Investment and Insurance Servicing Platforms

Build continuing operational risk leadership for investment and insurance servicing, connecting third-party dependencies, degraded operations and customer obligations through an initial twenty-four-month agenda that strengthens regional resilience governance without assuming technology engineering or actuarial policy ownership.

The mandate

A regional financial-services platform depends on common administrators and information providers across investment and insurance servicing. Its continuity plans demonstrate recovery of individual systems, but do not adequately test whether critical customer obligations can still be met when several external services degrade together. The Regional Operational Risk Chief will establish independent risk leadership for that service continuity question.

The role must connect operating dependencies to what customers and governing bodies reasonably require during disruption. An administrator's technical recovery can leave unreconciled transactions or delayed service decisions behind; a manual workaround may preserve activity while weakening verification and access controls. Risk will challenge the proposed degraded operation using supplied service evidence, ensuring management knows both what can continue and the exposure created by choosing to continue it.

Nineteen practitioners support the chief across regional service interfaces. A twenty-four-month initial agenda establishes dependency evidence, realistic disruption tests and accountable residual-risk decisions. This is permanent, open-ended employment, with continuing responsibility for regional operational challenge and leadership development. The framework must reflect distinct investment and insurance obligations rather than treat all work as a generic queue that can safely wait until every supplier recovers.

Within approved delegation, the executive sets independent continuity-risk test standards and escalates insufficient recovery or degraded-operation evidence. Operating management owns crisis execution, technology teams own system engineering and qualified compliance owners determine applicable service obligations. Material risk appetite or exceptional customer-response decisions require authorised committees. The chief does not prescribe cyber incident remediation, approve actuarial assumptions or certify that a supplier's technical restoration meets every regulatory requirement.

An effective first-year result will show the actual dependencies of critical services and the conditions under which an approved workaround remains defensible. During the second year, joint exercises should test decision timing, reconciliation backlog and return to controlled operation. Continuing risk accountability maintains those capabilities as providers and service models change, helping the board distinguish resilience demonstrated through realistic evidence from confidence founded on a completed recovery-plan document.

What you will own

  • Establish a critical-service dependency map linking external providers, operating decisions and customer obligations, validating the connection through source evidence rather than accepting each department's continuity inventory without challenge.
  • Decide independent disruption test priorities through shared dependencies and service consequence, requiring scenarios that stress several related operating conditions instead of only demonstrating recovery of one isolated system.
  • Challenge degraded-operation proposals for verification, access and reconciliation weaknesses, making the residual risk visible before management assumes that manual processing is an adequate substitute for controlled service.
  • Govern risk assessment of supplier recovery evidence with operating and technology owners, distinguishing restored technical availability from the ability to complete the customer service and control obligations that depend on it.
  • Build return-to-normal review requirements covering backlog, duplicate actions and unresolved transactions, ensuring a declared recovery does not conceal the exposure accumulated during a prolonged workaround.
  • Present regional board risk challenge on continuity choices and accepted limitations, preserving specialist conclusions and management's decision authority while making unsupported resilience assertions explicitly contestable.
  • Develop operational risk leaders through joint service exercises and post-event reviews, strengthening their capacity to question recovery assumptions constructively without taking over crisis command or technical engineering.

Candidate qualifications

  • Demonstrate senior independent operational risk, enterprise risk or continuity governance leadership in investment, insurance or comparable regulated financial services. Describe a dependency that several apparently separate service plans shared, the evidence inspected and the governance decision changed. The appointment requires judgement about actual service consequences and risk ownership, not solely coordination of a successful technology recovery exercise.
  • Bring applied competence in business continuity, crisis management and third-party risk, including degraded operations and return-to-normal controls. Relevant proof should show how you tested manual workarounds, transaction reconciliation and decision timing. Explain a plan that restored activity but did not adequately restore controlled service, and how you made the remaining risk visible to the authorised operating and risk decision makers.
  • Show strong control-assessment methods and specialist boundary discipline. You must recognise when technical, compliance or actuarial owners need to establish facts beyond the risk function's expertise. Describe how you challenged a supplier recovery claim, which evidence each owner provided and why an apparent system restoration did not automatically satisfy the relevant financial-service obligation or eliminate the need for accepted residual risk.
  • Establish a record of developing regional risk practitioners and influencing operating leaders under disruption pressure. The chief must sustain constructive independence without becoming the incident commander. Provide a difficult continuity recommendation, the governing authority that accepted the trade-off and the later exercise or event evidence used to test whether the proposed service conditions and return controls remained realistic.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 12 October 2026. Mandate reference CVU-PER-2026-IND-077.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.