Confidential mandate
Principal Enterprise Risk Assessment Architect — RCSA Calibration
Planned Hiring / New
Principal Enterprise Risk Assessment Architect mandate in Mumbai, India · Investment Operations Risk Methodology
Establish a reproducible risk-assessment method across investment operations, replacing incomparable self-assessment scores with calibrated scenarios, control-effectiveness evidence and clear uncertainty treatment through a six-month, independently accepted consulting programme.
The mandate
Investment operations teams assess comparable risks with different scoring conventions. One rates a process by incident history, another by transaction volume, and a third lowers its residual rating because a control has been described. The assignment is to create a defensible calibration architecture for selected risk and control self-assessments, making the reasoning comparable without pretending that every business carries the same exposure or that a numerical score supplies a board decision.
The principal will reserve four working days weekly from 26 October 2026 for six months. By 30 November 2026, the first milestone must provide a diagnostic of eight selected processes, a scenario library and an agreed record of material differences in current rating logic. By 12 February 2027, the second will supply calibrated assessment rules, evidence standards and results from blind cross-team scoring. The final milestone on 26 April 2027 comprises owner-led assessment replay, a versioned methodology and an operating maintenance pack.
Inherent exposure must be described before claimed control benefit is applied. The method will distinguish plausible event frequency from impact severity, identify the operational assumptions behind each assessment and retain uncertainty where evidence is weak. A preventive control, a late detective control and an action promised for next quarter cannot all receive the same risk-reduction credit. The assessment should explain which scenario component a control changes, whether its operating evidence supports that claim and how dependencies or common failures affect the conclusion.
Acceptance belongs jointly to the Chief Risk Officer and Risk Assurance Head. Internal reviewers must independently score an agreed sample, explain material differences using the documented method and reproduce the result after controlled evidence changes. Acceptance does not require identical scores where facts differ; it requires disagreements to be intelligible, unjustified control credit to be removed and missing evidence to remain visible. Process owners must also replay an assessment without the consultant interpreting its fields for them.
The sponsor supplies existing assessments, process maps, incident records, available control-test evidence and four risk analysts, with access to relevant operating owners. Fees are allocated 30%, 35% and 35% to accepted artifacts, not to lower reported risk. The scope excludes remediation delivery, audit opinions, regulatory certification and risk-system implementation. Additional businesses, a software build or a changed scoring perimeter require a priced change signed by both acceptors; the principal has methodological standing but no delegated approval of business risk acceptance.
What you will own
- Diagnose how the eight selected processes currently define events, frequency, impact and control benefit, recording incompatible assumptions before recommending any replacement rating framework.
- Construct scenario narratives that connect an operational failure to exposure and consequence, separating transaction scale, customer impact, recoverability and timing rather than merging them into unexplained labels.
- Define evidence requirements for preventive, detective and corrective controls, specifying when absence of operating proof prevents a reduction in the residual assessment.
- Facilitate blind scoring of common scenarios by separate teams, tracing disagreements to fact interpretation, ambiguous guidance or unsupported judgement and revising the method accordingly.
- Test correlated-control failure and dependency scenarios, making shared providers, manual workarounds and delayed detection visible without presenting the exercise as quantitative capital modelling.
- Present milestone artifacts for joint acceptance with reviewer replay files, exception records and explicit unresolved policy choices that belong to the internal risk leadership.
- Transfer version control, assessment maintenance and calibration-review routines to sponsor analysts, demonstrating that changed evidence produces a reasoned change rather than an automatic score adjustment.
Candidate qualifications
- Bring senior enterprise or investment-services risk experience with direct involvement in RCSA design, risk challenge or control-assessment governance. Explain how you personally distinguished an exposed process from an ineffective control and from a missing assessment record. Evidence must show reasoning that operating owners and risk committees could examine, including a case where a well-written self-assessment did not justify the claimed residual position.
- Demonstrate a practical calibration method rather than reliance on a proprietary scorecard. Show how you define a scenario, locate the relevant population, judge plausible consequences and reconcile differences between assessors. You should be able to preserve legitimate business differences while detecting inconsistent scales, retrospective incident bias and control credit based on design alone. Numerical precision must not conceal unresolved facts or an untested dependency.
- Understand the separate responsibilities of process management, independent risk, internal audit and formal risk-acceptance bodies. Describe how your methodology treats audit evidence without taking over audit's opinions, and how a material disagreement reaches the authorised policy owner. Investment operations familiarity should include service, transaction and third-party failure modes; banking capital-model expertise is not a condition of this engagement.
- Provide proof of transferring an analytical method to internal practitioners through observed use, documented maintenance and reproducible review. Identify the artifacts you left behind, how assessors handled a new scenario and which defects remained open at acceptance. Reserve four days weekly for the six-month term, disclose competing risk-system or assessor relationships, and maintain evidence access according to the sponsor's approved information controls.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 15 October 2026. Mandate reference CVU-CON-2026-IND-080.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.