Job Description
Role: Head of Group Risk & Internal Control
Duration: Full Time – 40 hours per week (09:00 to 18:00)
Department: Risk, Regulation and Governance & Controls
Reports to: Executive Managing Director, Risk, Regulation and Governance & Controls
Location: London – Onsite (4 days per week in the office; WFH on Tuesdays, Wednesdays, or Thursdays)
--------------------------------------------------------------------
ROLE PURPOSE
MNK Group is seeking a senior, technically strong Head of Group Risk & Internal Control to lead the design, implementation, and embedding of a robust Group-wide Internal Control Framework (ICF) across its international (re)insurance business.
This is a critical second-line leadership role with full accountability for ensuring that risks are identified, assessed, controlled, monitored, and reported in a consistent, effective, and proportionate manner. The role holder will act as the Group’s subject matter expert on operational risk and internal controls, with a strong focus on practical implementation, first-line ownership, and capability uplift.
The role combines strategic oversight with hands-on technical delivery, requiring deep experience in internal control frameworks, control design, roll-out programmes, training delivery, and regulatory engagement.
--------------------------------------------------------------------
KEY ACCOUNTABILITIES
Enterprise Risk Management Framework (ERMF)
• Own and continuously enhance the Group Enterprise Risk Management Framework, ensuring alignment with business strategy, regulatory expectations, and best practice.
• Lead the end-to-end Risk and Control Self-Assessment (RCSA) process, ensuring strong linkage between risks, controls, incidents, KRIs, and risk appetite.
• Provide effective second-line challenge to the first line, ensuring risks are appropriately identified, assessed, and mitigated.
• Oversee risk incident management, including root cause analysis, thematic reviews, and embedding lessons learned into control enhancements.
• Design and maintain the Group emerging risk framework, including horizon scanning, external research, and senior management reporting.
• Lead stress testing and scenario analysis to support strategic decision-making and risk appetite monitoring.
--------------------------------------------------------------------
Internal Control Framework (ICF)
• Design, implement, and maintain a comprehensive Group Internal Control Framework aligned to regulatory expectations and industry standards (e.g. COSO or equivalent).
• Define and maintain control standards, control taxonomies, documentation requirements, and minimum control expectations.
• Lead the roll-out and embedding of the ICF across all business units, functions, and jurisdictions.
• Ensure controls are clearly articulated, risk-aligned, appropriately designed, and operationally effective.
• Establish and oversee control design and operating effectiveness testing methodologies.
• Drive remediation of control deficiencies, ensuring timely closure and sustainable improvements.
• Act as the Group technical authority on internal controls, advising senior stakeholders on control design and operational risk matters.
--------------------------------------------------------------------
Governance, Risk & Compliance (GRC) Systems
• Own the configuration and ongoing enhancement of the Group GRC system.
• Ensure full integration of ERMF and ICF components within the GRC tool, including RCSAs, control testing, incidents, KRIs, and action tracking.
• Drive first-line and second-line adoption of the GRC system through training, guidance, and ongoing support.
• Ensure data quality, consistency, and integrity across all risk and control reporting.
--------------------------------------------------------------------
Training, Awareness & Culture
• Design and deliver structured training programmes on internal controls, RCSA methodology, and operational risk management.
• Develop detailed guidance materials, playbooks, control design standards, and training content.
• Lead workshops and deep-dive sessions to support ICF roll-out, regulatory change, and control uplift initiatives.
• Embed a strong risk and control culture by building capability and accountability across the Group.
--------------------------------------------------------------------
Governance, MI & Reporting
• Prepare high-quality MI and reporting for Boards, Committees, and Senior Management.
• Maintain the Group risk and control governance calendar and ensure effective tracking of actions.
• Support Board and Committee education on risk and internal control matters.
• Contribute to wider governance initiatives, including Operational Resilience and Business Continuity Planning.
--------------------------------------------------------------------
Regulatory & External Engagement
• Monitor regulatory developments across relevant jurisdictions (PRA, FCA, and overseas regulators).
• Assess and communicate regulatory impacts to senior stakeholders.
• Support regulatory interactions, reviews, and audits relating to risk management and internal controls.
-------------------------------------------------------------------
People & Leadership
• Act as a senior leader within the Risk, Regulation and Governance function.
• Mentor and develop junior risk team members.
• Build strong, trusted relationships with first-line and executive stakeholders.
• Promote collaboration and continuous improvement across the Group.
--------------------------------------------------------------------
QUALIFICATIONS, SKILLS & EXPERIENCE
Essential:
• 10+ years’ experience in risk management and internal controls within regulated financial services or (re)insurance.
• Demonstrable hands-on experience designing, implementing, and embedding Internal Control Frameworks.
• Strong technical knowledge of operational risk and control best practice.
• Experience leading large-scale ICF roll-outs and training programmes.
• Excellent stakeholder management and influencing skills.
Desirable:
• Professional qualifications such as ACII, IRM, or equivalent.
• Experience engaging with regulators on risk and control matters.
• Hands-on experience with GRC systems.
--------------------------------------------------------------------
PERSONAL ATTRIBUTES
• Highly organised, proactive, and delivery focused.
• Technically credible and confident acting as a subject matter expert.
• Strong attention to detail with strategic perspective.
• Commercially aware and pragmatic.
• Resilient and adaptable in a fast-paced environment.